Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pravidelná kontrola

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Pravidelná kontrola

#1 Příspěvek od Gizmof »

Zdravím, prosím o kontrolu logu kvôli pravidelnej kontrole. Diky :) .

Logfile of random's system information tool 1.08 (written by random/random)
Run by Správca at 2010-11-13 09:30:15
Microsoft Windows 7 Home Premium
System drive C: has 150 GB (49%) free of 305 GB
Total RAM: 2047 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:31:34, on 13. 11. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\KeePass Password Safe 2\KeePass.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Windows Live\Mesh\WLSync.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Windows Live\Mesh\MOE.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Filip\Downloads\RSIT.exe
C:\Program Files\trend micro\Správca.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 74.208.10.249 gs.apple.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KeePass 2 PreLoad] "C:\Program Files\KeePass Password Safe 2\KeePass.exe" --preload
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [KeePass Password Safe 2] "C:\Program Files\KeePass Password Safe 2\KeePass.exe" (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [JustVoip] "C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe" -nosplash -minimized (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [WLSync] "C:\Program Files\Windows Live\Mesh\WLSync.exe" /background (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe" (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Filip')
O4 - S-1-5-21-3520075864-464996501-2728924925-1003 Startup: Dropbox.lnk = Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Filip')
O4 - S-1-5-21-3520075864-464996501-2728924925-1003 User Startup: Dropbox.lnk = Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Filip')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.co ... .3.1.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{326FCDFB-A140-400D-BB34-4FD88DD5B4BA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{326FCDFB-A140-400D-BB34-4FD88DD5B4BA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{326FCDFB-A140-400D-BB34-4FD88DD5B4BA}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 9928 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3520075864-464996501-2728924925-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3520075864-464996501-2728924925-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-28 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-05-22 7514656]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-05-22 1833504]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"KeePass 2 PreLoad"=C:\Program Files\KeePass Password Safe 2\KeePass.exe [2010-07-09 1548288]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-08-10 421888]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-09-01 421160]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\Steam.exe [2010-08-28 1242448]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-10-11 14940040]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-11-13 09:30:16 ----D---- C:\Program Files\trend micro
2010-11-13 09:30:15 ----D---- C:\rsit
2010-11-09 18:52:12 ----A---- C:\Windows\system32\drivers\cpuz134_x32.sys
2010-11-09 18:52:10 ----D---- C:\Program Files\CPUID
2010-11-09 18:36:12 ----D---- C:\Program Files\Lavalys
2010-10-31 10:26:37 ----D---- C:\ProgramData\IMSIDesign
2010-10-31 10:26:37 ----D---- C:\Program Files\IMSIDesign
2010-10-31 10:24:00 ----D---- C:\Program Files\Scorpions WinCheater
2010-10-31 09:33:32 ----D---- C:\Program Files\Sweet Home 3D
2010-10-27 16:06:54 ----A---- C:\Windows\system32\msdri.dll
2010-10-27 16:06:54 ----A---- C:\Windows\system32\CPFilters.dll
2010-10-27 16:06:46 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-10-26 18:47:57 ----A---- C:\Windows\system32\drivers\sptd.sys
2010-10-26 18:47:28 ----D---- C:\Program Files\DAEMON Tools Lite
2010-10-26 18:47:15 ----D---- C:\Users\Správca\AppData\Roaming\DAEMON Tools Lite
2010-10-26 18:46:54 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-10-16 14:01:16 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2010-10-16 13:58:48 ----D---- C:\Program Files\Adobe Media Player
2010-10-16 13:55:30 ----D---- C:\Program Files\Common Files\Adobe
2010-10-15 06:11:04 ----D---- C:\Program Files\Common Files\Skype
2010-10-15 06:11:01 ----RD---- C:\Program Files\Skype

======List of files/folders modified in the last 1 months======

2010-11-13 09:31:01 ----D---- C:\Windows\Temp
2010-11-13 09:30:30 ----D---- C:\Windows\Prefetch
2010-11-13 09:30:16 ----RD---- C:\Program Files
2010-11-13 09:24:14 ----D---- C:\Windows\system32\config
2010-11-13 09:23:59 ----D---- C:\ProgramData\NVIDIA
2010-11-12 22:23:08 ----D---- C:\Program Files\Steam
2010-11-12 07:08:15 ----SHD---- C:\System Volume Information
2010-11-10 07:56:46 ----A---- C:\Windows\system32\MRT.exe
2010-11-10 07:56:41 ----SHD---- C:\Windows\Installer
2010-11-10 07:56:39 ----D---- C:\ProgramData\Microsoft Help
2010-11-10 07:56:20 ----D---- C:\Windows\system32\catroot2
2010-11-09 18:52:12 ----D---- C:\Windows\system32\drivers
2010-11-09 18:43:16 ----D---- C:\Windows\debug
2010-11-09 14:50:17 ----D---- C:\Windows\System32
2010-11-09 14:50:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-09 14:50:16 ----D---- C:\Windows\inf
2010-11-05 15:19:02 ----D---- C:\Program Files\Common Files\Steam
2010-11-03 22:48:37 ----D---- C:\Windows\rescache
2010-10-31 21:48:47 ----D---- C:\Windows\winsxs
2010-10-31 10:44:50 ----SD---- C:\Users\Správca\AppData\Roaming\Microsoft
2010-10-31 10:44:50 ----SD---- C:\ProgramData\Microsoft
2010-10-31 10:27:56 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-31 10:26:37 ----HD---- C:\ProgramData
2010-10-28 05:53:11 ----D---- C:\Windows\Microsoft.NET
2010-10-28 05:52:21 ----RSD---- C:\Windows\assembly
2010-10-27 16:12:00 ----D---- C:\Windows\ehome
2010-10-27 16:11:53 ----D---- C:\Windows\AppPatch
2010-10-27 16:06:43 ----D---- C:\Windows\system32\catroot
2010-10-23 13:11:58 ----D---- C:\Windows\system32\wdi
2010-10-19 11:41:44 ----N---- C:\Windows\system32\MpSigStub.exe
2010-10-17 09:43:47 ----D---- C:\Program Files\Sony Ericsson
2010-10-17 08:50:14 ----D---- C:\ProgramData\Adobe
2010-10-16 14:02:44 ----D---- C:\Windows\system32\Tasks
2010-10-16 14:00:55 ----D---- C:\Users\Správca\AppData\Roaming\Adobe
2010-10-16 14:00:30 ----D---- C:\Program Files\Adobe
2010-10-16 13:59:45 ----RSD---- C:\Windows\Fonts
2010-10-16 13:55:30 ----D---- C:\Program Files\Common Files
2010-10-15 06:11:01 ----D---- C:\Users\Správca\AppData\Roaming\Skype
2010-10-15 06:11:01 ----D---- C:\ProgramData\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-26 691696]
R1 AsIO;AsIO; C:\Windows\system32\drivers\AsIO.sys [2007-12-17 12400]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 46672]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-05-23 2361952]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20); C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-07-13 47104]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2010-09-15 27632]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2010-09-15 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2010-09-15 25512]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-08-13 144672]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-07-27 345376]
R2 NMSAccess;NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2010-03-04 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-09-01 820008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-05 136176]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-11-04 403240]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-28 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#2 Příspěvek od Gizmof »

Ešte jedne log

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5105

Windows 6.1.7600
Internet Explorer 9.0.7930.16406

13. 11. 2010 14:48:34
mbam-log-2010-11-13 (14-48-34).txt

Scan type: Full scan (C:\|)
Objects scanned: 230881
Time elapsed: 26 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#3 Příspěvek od Gizmof »

Nikto nič? Ak by sa niekomu nepozdával ten Photoshop tak je len trial ktorý skončil včera. Inak je tam všetko legálne :| . Alebo tam ani nič nie je a všetko je ok?
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pravidelná kontrola

#4 Příspěvek od motji »

Dobrý večer :)
když si sám odpovídáte, tak se nám ztratíte v zodpovězených topicích. :)
Máte s počítačem nějaký problém?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#5 Příspěvek od Gizmof »

Neviem či to je zrovna nejaký problém ale v poslednej dobe avast nespúšťa rezidentnú ochranu automaticky alebo ju spustí docela neskoro. Skoro ako keby sa spustil nejaký ten bordelmaker a potom až Avast aby ho nenašiel :arcisit: .
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pravidelná kontrola

#6 Příspěvek od motji »

Mrkneme na to :)

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
-přejmenujte combofix na cokoliv.com
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#7 Příspěvek od Gizmof »

ComboFix 10-11-14.04 - Správca . 11. 2010 16:59:09.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.2047.1049 [GMT 1:00]
Running from: c:\users\Filip\Downloads\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.

((((((((((((((((((((((((( Files Created from 2010-10-15 to 2010-11-15 )))))))))))))))))))))))))))))))
.

2010-11-15 16:03 . 2010-11-15 16:03 -------- d-----w- c:\users\Rodičia\AppData\Local\temp
2010-11-15 16:03 . 2010-11-15 16:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-11-15 15:56 . 2010-11-15 15:56 -------- d-----w- C:\32788R22FWJFW
2010-11-13 13:21 . 2010-11-13 13:21 -------- d-----w- c:\users\Filip\AppData\Roaming\Malwarebytes
2010-11-13 13:20 . 2010-11-13 13:20 -------- d-----w- c:\users\Správca\AppData\Roaming\Malwarebytes
2010-11-13 13:20 . 2010-11-13 13:20 -------- d-----w- c:\programdata\Malwarebytes
2010-11-13 13:20 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-13 13:20 . 2010-11-13 13:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-13 13:20 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-13 08:30 . 2010-11-13 08:31 -------- d-----w- c:\program files\trend micro
2010-11-13 08:30 . 2010-11-13 08:31 -------- d-----w- C:\rsit
2010-11-12 06:08 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F1ACB26-ACA8-4E79-ACD3-88C8783294FD}\mpengine.dll
2010-11-09 17:52 . 2010-07-09 12:18 20328 ----a-w- c:\windows\system32\drivers\cpuz134_x32.sys
2010-11-09 17:52 . 2010-11-09 17:52 -------- d-----w- c:\program files\CPUID
2010-11-09 17:36 . 2010-11-09 17:36 -------- d-----w- c:\program files\Lavalys
2010-11-07 08:40 . 2010-11-07 08:40 -------- d-----w- c:\users\Filip\psychostats3.1
2010-10-31 09:26 . 2010-11-14 14:46 -------- d-----w- c:\programdata\IMSIDesign
2010-10-31 09:24 . 2010-10-31 09:24 -------- d-----w- c:\program files\Scorpions WinCheater
2010-10-27 15:06 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-27 15:06 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-27 15:06 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-27 15:06 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-27 15:06 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-26 17:47 . 2010-10-26 17:47 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-26 17:47 . 2010-10-26 17:47 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-10-26 17:47 . 2010-10-26 17:47 -------- d-----w- c:\users\Správca\AppData\Roaming\DAEMON Tools Lite
2010-10-26 17:46 . 2010-10-26 17:47 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-10-24 14:53 . 2010-10-24 14:53 -------- d-----w- c:\users\Rodičia\AppData\Local\Adobe
2010-10-20 19:37 . 2010-10-20 19:37 -------- d-----w- c:\users\Filip\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 10:41 . 2010-08-28 13:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-07 18:51 . 2010-10-07 18:51 731640 ----a-w- c:\windows\P5Q-ASUS-2208.zip
2010-09-22 22:47 . 2010-09-22 22:47 49016 ----a-w- c:\windows\system32\sirenacm.dll
2010-09-22 22:32 . 2010-09-22 22:32 301936 ----a-w- c:\windows\WLXPGSS.SCR
2010-09-21 12:03 . 2010-09-21 12:03 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-15 17:00 . 2010-09-15 17:00 27632 ----a-w- c:\windows\system32\drivers\seehcri.sys
2010-09-15 16:59 . 2010-09-15 16:59 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2010-09-15 16:59 . 2010-09-15 16:59 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2010-09-15 16:59 . 2010-09-15 16:59 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-09-07 15:12 . 2010-08-28 13:58 38848 ----a-w- c:\windows\avastSS.scr
2010-09-07 15:11 . 2010-08-28 13:58 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-07 14:52 . 2010-08-28 13:59 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 14:52 . 2010-08-28 13:59 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 14:47 . 2010-08-28 13:59 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 14:47 . 2010-08-28 13:59 50768 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-09-07 14:47 . 2010-08-28 13:59 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-01 04:23 . 2010-10-13 04:51 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-01 02:34 . 2010-10-13 04:51 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 22:46 . 2010-09-16 05:46 1355264 ----a-w- c:\windows\system32\jscript9.dll
2010-08-31 22:44 . 2010-09-16 05:46 367104 ----a-w- c:\windows\system32\html.iec
2010-08-31 22:44 . 2010-09-16 05:46 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2010-08-31 22:44 . 2010-09-16 05:46 1122304 ----a-w- c:\windows\system32\wininet.dll
2010-08-31 22:44 . 2010-09-16 05:46 424960 ----a-w- c:\windows\system32\vbscript.dll
2010-08-31 22:43 . 2010-09-16 05:46 23552 ----a-w- c:\windows\system32\licmgr10.dll
2010-08-31 22:43 . 2010-09-16 05:46 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2010-08-31 22:43 . 2010-09-16 05:46 114176 ----a-w- c:\windows\system32\iesysprep.dll
2010-08-31 22:43 . 2010-09-16 05:46 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2010-08-31 22:43 . 2010-09-16 05:46 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2010-08-31 22:42 . 2010-09-16 05:46 51200 ----a-w- c:\windows\system32\admparse.dll
2010-08-31 22:42 . 2010-09-16 05:46 75264 ----a-w- c:\windows\system32\iesetup.dll
2010-08-31 22:42 . 2010-09-16 05:46 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2010-08-31 22:42 . 2010-09-16 05:46 150016 ----a-w- c:\windows\system32\iexpress.exe
2010-08-31 22:42 . 2010-09-16 05:46 149504 ----a-w- c:\windows\system32\wextract.exe
2010-08-31 22:42 . 2010-09-16 05:46 33280 ----a-w- c:\windows\system32\imgutil.dll
2010-08-31 22:42 . 2010-09-16 05:46 48640 ----a-w- c:\windows\system32\mshtmler.dll
2010-08-31 22:42 . 2010-09-16 05:46 11264 ----a-w- c:\windows\system32\mshta.exe
2010-08-31 22:42 . 2010-09-16 05:46 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2010-08-31 22:42 . 2010-09-16 05:46 63488 ----a-w- c:\windows\system32\tdc.ocx
2010-08-31 22:41 . 2010-09-16 05:46 160768 ----a-w- c:\windows\system32\msls31.dll
2010-08-31 04:32 . 2010-10-13 04:51 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32 . 2010-10-13 04:51 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-28 14:11 . 2010-08-28 14:12 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-27 05:46 . 2010-10-13 04:51 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 03:31 . 2010-10-13 04:51 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-27 03:30 . 2010-10-13 04:51 308736 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-27 03:30 . 2010-10-13 04:51 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-26 15:23 . 2010-08-26 15:23 644400 ----a-w- c:\windows\system32\mscomct2.ocx
2010-08-26 04:39 . 2010-10-13 04:51 109056 ----a-w- c:\windows\system32\t2embed.dll
2010-08-21 05:36 . 2010-10-13 04:51 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-08-21 05:36 . 2010-10-13 04:51 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-21 05:33 . 2010-10-13 04:51 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 05:32 . 2010-09-15 08:42 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-18 13:26 . 2010-08-18 13:26 7680 ----a-w- c:\windows\system32\drivers\sk-SK\bthport.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 3584 ----a-w- c:\windows\system32\drivers\sk-SK\portcls.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 3072 ----a-w- c:\windows\system32\drivers\sk-SK\hidbth.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 3072 ----a-w- c:\windows\system32\drivers\sk-SK\ataport.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 2560 ----a-w- c:\windows\system32\drivers\sk-SK\serscan.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 2560 ----a-w- c:\windows\system32\drivers\sk-SK\BTHUSB.SYS.mui
2010-08-18 13:26 . 2010-08-18 13:26 2048 ----a-w- c:\windows\system32\drivers\sk-SK\bthenum.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 2048 ----a-w- c:\windows\system32\drivers\sk-SK\amdide.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 2560 ----a-w- c:\windows\system32\drivers\sk-SK\scfilter.sys.mui
2010-08-18 13:26 . 2010-08-18 13:26 47616 ----a-w- c:\windows\system32\drivers\sk-SK\tcpip.sys.mui
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Správca\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Správca\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\Správca\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2010-08-28 1242448]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-05-22 7514656]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-05-22 1833504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"KeePass 2 PreLoad"="c:\program files\KeePass Password Safe 2\KeePass.exe" [2010-07-09 1548288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

c:\users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Spr vca\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-05 136176]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-15 13224]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-28 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-26 691696]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2010-09-15 27632]

.
Contents of the 'Scheduled Tasks' folder

2010-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-05 13:42]

2010-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-05 13:42]

2010-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3520075864-464996501-2728924925-1003Core.job
- c:\users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-28 20:19]

2010-11-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3520075864-464996501-2728924925-1003UA.job
- c:\users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-28 20:19]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: {326FCDFB-A140-400D-BB34-4FD88DD5B4BA} = 8.8.8.8,8.8.4.4
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab
FF - ProfilePath -

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe


.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(3084)
c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
Completion time: 2010-11-15 17:05:14
ComboFix-quarantined-files.txt 2010-11-15 16:05

Pre-Run: 153 916 964 864 bytes free
Post-Run: 184 273 461 248 bytes free

- - End Of File - - 4816E043098C52225C4F8BBF7968942B
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pravidelná kontrola

#8 Příspěvek od motji »

Změnilo se po použití combofixu něco?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#9 Příspěvek od Gizmof »

Nič, všetko po starom. Občas sa zapne hneď, občas po pár sekundách... asi je to normálne.
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pravidelná kontrola

#10 Příspěvek od motji »

Můžete ho zkusit přeinstalovat. Mě se také občas zapne trochu později, ale není to zas tak moc často jako u Vás. Jestli chcete, můžeme ještě udělat test přímo na rootkity.

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#11 Příspěvek od Gizmof »

Bol som pár dní bez netu kvôli sťahovaniu. PC sa chová docela normálne. A toto bol ten test na rootkity?
P.S.: Ja som pán "paranoidný" takže radšej preverím všetko :).

Logfile of random's system information tool 1.08 (written by random/random)
Run by Správca at 2010-11-20 19:03:27
Microsoft Windows 7 Home Premium
System drive C: has 176 GB (58%) free of 305 GB
Total RAM: 2047 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:03:35, on 20. 11. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\KeePass Password Safe 2\KeePass.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\Windows Live\Mesh\WLSync.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files\Windows Live\Mesh\MOE.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Filip\Downloads\RSIT.exe
C:\Program Files\trend micro\Správca.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 74.208.10.249 gs.apple.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KeePass 2 PreLoad] "C:\Program Files\KeePass Password Safe 2\KeePass.exe" --preload
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [KeePass Password Safe 2] "C:\Program Files\KeePass Password Safe 2\KeePass.exe" (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [Google Update] "C:\Users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [JustVoip] "C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe" -nosplash -minimized (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [WLSync] "C:\Program Files\Windows Live\Mesh\WLSync.exe" /background (User 'Filip')
O4 - HKUS\S-1-5-21-3520075864-464996501-2728924925-1003\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe" (User 'Filip')
O4 - S-1-5-21-3520075864-464996501-2728924925-1003 Startup: Dropbox.lnk = Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Filip')
O4 - S-1-5-21-3520075864-464996501-2728924925-1003 Startup: Obrazovková spinka a spúšťač programu OneNote 2010.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (User 'Filip')
O4 - S-1-5-21-3520075864-464996501-2728924925-1003 User Startup: Dropbox.lnk = Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Filip')
O4 - S-1-5-21-3520075864-464996501-2728924925-1003 User Startup: Obrazovková spinka a spúšťač programu OneNote 2010.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (User 'Filip')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.co ... .3.1.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{326FCDFB-A140-400D-BB34-4FD88DD5B4BA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{326FCDFB-A140-400D-BB34-4FD88DD5B4BA}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{326FCDFB-A140-400D-BB34-4FD88DD5B4BA}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 9724 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3520075864-464996501-2728924925-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3520075864-464996501-2728924925-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-28 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-05-22 7514656]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-05-22 1833504]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"KeePass 2 PreLoad"=C:\Program Files\KeePass Password Safe 2\KeePass.exe [2010-07-09 1548288]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-08-10 421888]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-09-01 421160]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\Steam.exe [2010-11-20 1242448]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-10-11 14940040]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2010-08-31 208384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-11-20 19:01:40 ----SD---- C:\ComboFix
2010-11-20 18:21:12 ----D---- C:\ProgramData\Blizzard
2010-11-16 15:00:14 ----D---- C:\Program Files\GIMP-2.0
2010-11-15 17:06:56 ----D---- C:\Windows\temp
2010-11-15 17:05:14 ----A---- C:\ComboFix.txt
2010-11-15 17:04:52 ----SHD---- C:\$RECYCLE.BIN
2010-11-15 16:56:59 ----D---- C:\Windows\ERDNT
2010-11-13 14:20:42 ----D---- C:\Users\Správca\AppData\Roaming\Malwarebytes
2010-11-13 14:20:33 ----D---- C:\ProgramData\Malwarebytes
2010-11-13 14:20:33 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-11-13 14:20:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-11-13 14:20:32 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-11-13 09:30:16 ----D---- C:\Program Files\trend micro
2010-11-13 09:30:15 ----D---- C:\rsit
2010-11-09 18:52:12 ----A---- C:\Windows\system32\drivers\cpuz134_x32.sys
2010-11-09 18:52:10 ----D---- C:\Program Files\CPUID
2010-11-09 18:36:12 ----D---- C:\Program Files\Lavalys
2010-10-31 10:26:37 ----D---- C:\ProgramData\IMSIDesign
2010-10-31 10:24:00 ----D---- C:\Program Files\Scorpions WinCheater
2010-10-27 16:06:54 ----A---- C:\Windows\system32\msdri.dll
2010-10-27 16:06:54 ----A---- C:\Windows\system32\CPFilters.dll
2010-10-27 16:06:46 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-10-26 18:47:57 ----A---- C:\Windows\system32\drivers\sptd.sys
2010-10-26 18:47:28 ----D---- C:\Program Files\DAEMON Tools Lite
2010-10-26 18:47:15 ----D---- C:\Users\Správca\AppData\Roaming\DAEMON Tools Lite
2010-10-26 18:46:54 ----D---- C:\ProgramData\DAEMON Tools Lite

======List of files/folders modified in the last 1 months======

2010-11-20 19:02:37 ----D---- C:\Windows\debug
2010-11-20 19:02:37 ----D---- C:\Windows
2010-11-20 18:40:33 ----D---- C:\Program Files\Steam
2010-11-20 18:39:07 ----D---- C:\Program Files\Common Files\Steam
2010-11-20 18:38:43 ----D---- C:\Program Files\Common Files
2010-11-20 18:21:12 ----D---- C:\ProgramData
2010-11-20 18:19:09 ----D---- C:\Windows\system32\config
2010-11-20 18:08:55 ----D---- C:\ProgramData\NVIDIA
2010-11-20 14:16:46 ----SHD---- C:\Windows\Installer
2010-11-20 14:16:41 ----D---- C:\ProgramData\Microsoft Help
2010-11-20 14:16:32 ----RD---- C:\Program Files
2010-11-20 14:16:11 ----SHD---- C:\System Volume Information
2010-11-20 12:55:02 ----D---- C:\Users\Správca\AppData\Roaming\Skype
2010-11-19 21:33:02 ----D---- C:\Windows\System32
2010-11-19 21:33:02 ----D---- C:\Windows\inf
2010-11-19 21:33:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-19 17:56:17 ----D---- C:\Program Files\Sony Ericsson
2010-11-15 22:38:58 ----D---- C:\Windows\system32\catroot2
2010-11-15 17:04:07 ----A---- C:\Windows\system.ini
2010-11-15 17:01:42 ----D---- C:\Windows\system32\drivers
2010-11-15 17:01:42 ----D---- C:\Windows\AppPatch
2010-11-14 15:56:08 ----D---- C:\Windows\winsxs
2010-11-14 15:46:23 ----HD---- C:\Program Files\InstallShield Installation Information
2010-11-14 15:40:59 ----D---- C:\Program Files\Common Files\Adobe
2010-11-14 15:40:54 ----D---- C:\ProgramData\Adobe
2010-11-14 15:40:13 ----D---- C:\Users\Správca\AppData\Roaming\Adobe
2010-11-14 15:40:05 ----D---- C:\Program Files\Adobe
2010-11-13 14:20:31 ----D---- C:\Windows\Prefetch
2010-11-10 07:56:46 ----A---- C:\Windows\system32\MRT.exe
2010-11-03 22:48:37 ----D---- C:\Windows\rescache
2010-10-31 10:44:50 ----SD---- C:\Users\Správca\AppData\Roaming\Microsoft
2010-10-31 10:44:50 ----SD---- C:\ProgramData\Microsoft
2010-10-28 05:53:11 ----D---- C:\Windows\Microsoft.NET
2010-10-28 05:52:21 ----RSD---- C:\Windows\assembly
2010-10-27 16:12:00 ----D---- C:\Windows\ehome
2010-10-27 16:06:43 ----D---- C:\Windows\system32\catroot
2010-10-23 13:11:58 ----D---- C:\Windows\system32\wdi

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-26 691696]
R1 AsIO;AsIO; C:\Windows\system32\drivers\AsIO.sys [2007-12-17 12400]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 46672]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-05-23 2361952]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20); C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-07-13 47104]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2010-09-15 27632]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 catchme;catchme; \??\C:\Users\SPRVCA~1\AppData\Local\Temp\catchme.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2010-09-15 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2010-09-15 25512]
S3 mbr;mbr; \??\C:\Users\SPRVCA~1\AppData\Local\Temp\mbr.sys []
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-08-13 144672]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-07-27 345376]
R2 NMSAccess;NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2010-03-04 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-09-01 820008]
R3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-11-20 403240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-05 136176]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-28 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#12 Příspěvek od Gizmof »

No zrovna som pustil PC, prihlásil sa a avast mal hneď žltý trojuholník.. pozrem a rezidentné štíty vypnuté. Fakt mi to pripadá divné :o .
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pravidelná kontrola

#13 Příspěvek od motji »

koukneme na ty rootkity :)

:arrow: Stáhněte Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
- rozbalte a spusťte
-proběhne sken, po skončení se otevře okno s výsledky, klikněte na Save a tím si uložíte log,který sem vložíte

-Podle návodu v odkazu provedete druhý sken a log sem také vložíte.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
Gizmof
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 08 srp 2010 21:30
Kontaktovat uživatele:

Re: Pravidelná kontrola

#14 Příspěvek od Gizmof »

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2010-11-20 21:22:07
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD3200AAKS-00VYA0 rev.12.01B02
Running: gmer.exe; Driver: C:\Users\SPRVCA~1\AppData\Local\Temp\uwldipow.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8EDB1BAE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0x8EDB19D2]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0x8EDB1B0C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

---- Devices - GMER 1.0.15 ----

Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 84E931F8
Device \Driver\atapi \Device\Ide\IdePort0 84E931F8
Device \Driver\atapi \Device\Ide\IdePort1 84E931F8
Device \Driver\atapi \Device\Ide\IdePort2 84E931F8
Device \Driver\atapi \Device\Ide\IdePort3 84E931F8
Device \Driver\atapi \Device\Ide\IdePort4 84E931F8
Device \Driver\atapi \Device\Ide\IdePort5 84E931F8
Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-3 84E931F8
Device \FileSystem\Ntfs \Ntfs 85B3A1F8

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

---- EOF - GMER 1.0.15 ----

:closed:


GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-20 21:38:25
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD3200AAKS-00VYA0 rev.12.01B02
Running: gmer.exe; Driver: C:\Users\SPRVCA~1\AppData\Local\Temp\uwldipow.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8EDB1BAE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0x8EDB19D2]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0x8EDB1B0C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C57599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C7BF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE ntkrnlpa.exe!ZwLoadDriver 82DB5291 7 Bytes JMP 8EDB1B10 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82E1CFBF 5 Bytes JMP 8EDAD5D4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 82E36CF3 5 Bytes JMP 8EDAF012 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!NtCreateSection 82E44D63 7 Bytes JMP 8EDB19D6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 82EEEEAC 7 Bytes JMP 8EDB1BB2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? System32\Drivers\spgi.sys Systém nemôže nájsť zadanú cestu. !
.text USBPORT.SYS!DllUnload 8FFAFCA0 5 Bytes JMP 862204E0

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1340] kernel32.dll!SetUnhandledExceptionFilter 756C3162 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [88CAD042] \SystemRoot\System32\Drivers\spgi.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [88CAD6D6] \SystemRoot\System32\Drivers\spgi.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [88CAD800] \SystemRoot\System32\Drivers\spgi.sys
IAT \SystemRoot\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [88CAD13E] \SystemRoot\System32\Drivers\spgi.sys

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] [6D8FA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlLockHeap] [6D8F94D8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlUnlockHeap] [6D8F94E8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlDestroyHeap] [6D8F94B8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlCreateHeap] [6D8F94A8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlExitUserProcess] [6D8FAA9E] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] [6D8FA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\NETAPI32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\NETAPI32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\IPHLPAPI.DLL [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\IPHLPAPI.DLL [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Windows Live\Messenger\msnmsgr.exe[980] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] [6D8FA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlLockHeap] [6D8F94D8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlUnlockHeap] [6D8F94E8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlDestroyHeap] [6D8F94B8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlCreateHeap] [6D8F94A8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlExitUserProcess] [6D8FAA9E] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] [6D8FA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\Iphlpapi.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\Iphlpapi.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Phone\Skype.exe[1576] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] [6D8FA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlLockHeap] [6D8F94D8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlUnlockHeap] [6D8F94E8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlDestroyHeap] [6D8F94B8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlCreateHeap] [6D8F94A8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlExitUserProcess] [6D8FAA9E] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\user32.dll [ntdll.dll!RtlSizeHeap] [6D8FA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\user32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\user32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\user32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\user32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\advapi32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\advapi32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\advapi32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\advapi32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] [6D8F9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\crypt32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\crypt32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\crypt32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\Secur32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75295E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\WS2_32.dll [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\iphlpapi.DLL [ntdll.dll!RtlFreeHeap] [6D8F9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Skype\Plugin Manager\skypePM.exe[3108] @ C:\Windows\system32\iphlpapi.DLL [ntdll.dll!RtlAllocateHeap] [6D8F92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 85B3A1F8
Device \FileSystem\fastfat \FatCdrom 850C71F8
Device \FileSystem\fastfat \FatCdrom 89529CA8
Device \Driver\volmgr \Device\VolMgrControl 84E911F8
Device \Driver\usbuhci \Device\USBPDO-0 8612B1F8
Device \Driver\usbuhci \Device\USBPDO-1 8612B1F8
Device \Driver\ACPI_HAL \Device\00000045 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBPDO-2 8612B1F8
Device \Driver\usbehci \Device\USBPDO-3 861F6500
Device \Driver\usbuhci \Device\USBPDO-4 8612B1F8

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\usbuhci \Device\USBPDO-5 8612B1F8
Device \Driver\USBSTOR \Device\00000070 869AE1F8
Device \Driver\usbuhci \Device\USBPDO-6 8612B1F8
Device \Driver\volmgr \Device\HarddiskVolume1 84E911F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\NetBT \Device\NetBT_Tcpip_{326FCDFB-A140-400D-BB34-4FD88DD5B4BA} 860C01F8
Device \Driver\USBSTOR \Device\00000071 869AE1F8
Device \Driver\usbehci \Device\USBPDO-7 861F6500
Device \Driver\volmgr \Device\HarddiskVolume2 84E911F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom0 86151470
Device \Driver\USBSTOR \Device\00000072 869AE1F8
Device \Driver\volmgr \Device\HarddiskVolume3 84E911F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\USBSTOR \Device\00000073 869AE1F8
Device \Driver\volmgr \Device\HarddiskVolume4 84E911F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\volmgr \Device\HarddiskVolume5 84E911F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\volmgr \Device\HarddiskVolume6 84E911F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\NetBT \Device\NetBt_Wins_Export 860C01F8

AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

Device \Driver\usbuhci \Device\USBFDO-0 8612B1F8
Device \Driver\usbuhci \Device\USBFDO-1 8612B1F8
Device \Driver\usbuhci \Device\USBFDO-2 8612B1F8
Device \Driver\USBSTOR \Device\0000006f 869AE1F8
Device \Driver\usbehci \Device\USBFDO-3 861F6500
Device \Driver\usbuhci \Device\USBFDO-4 8612B1F8
Device \Driver\usbuhci \Device\USBFDO-5 8612B1F8
Device \Driver\usbuhci \Device\USBFDO-6 8612B1F8
Device \Driver\usbehci \Device\USBFDO-7 861F6500
Device \FileSystem\fastfat \Fat 850C71F8
Device \FileSystem\fastfat \Fat 89529CA8

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...

---- EOF - GMER 1.0.15 ----
Top4 for Firefox: Adblock Plus | NoScript | WOT | BetterPrivacy
VirusTotal - Výborný online scaner súborov.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pravidelná kontrola

#15 Příspěvek od motji »

Nikde nic :o .
Zkuste Avast přeinstalovat a pak mi napište, zda ten Avast pořád zlobí :o
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět