Stránka 1 z 2

spravce zařízení

Napsal: 03 led 2011 16:42
od brankar
Ahoj musím zase otravovat ve správce zařízení mě už dva měsíce piše chybu

Systém událostí modelu COM+ se pokusil spustit událost EventObjectChange::ChangedSubscription, ale obdržel chybný návratový kód :o


Je to nějaký problém nebo to mám nechat být :?: :cry:

DÍKY PŘEDEM ZA ODPOVĚD :worship:

Re: spravce zařízení

Napsal: 03 led 2011 17:43
od Rudy
Zde: http://support.microsoft.com/kb/916254/cs je popis řešení přímo od MS. Pak dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: spravce zařízení

Napsal: 03 led 2011 18:23
od brankar
ComboFix 11-01-02.04 - user 03.01.2011 18:00:20.55.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.511.250 [GMT 1:00]
Spuštěný z: c:\documents and settings\user\Plocha\ComboFix.exe
AV: AVG *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: COMODO Antivirus *Disabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: Microsoft Security Essentials *Enabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: Kerio WinRoute Firewall *Enabled* {916dafda-8250-4a1d-9095-000da68ac4da}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\user\Data aplikací\facemoods.com

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-03 do 2011-01-03 )))))))))))))))))))))))))))))))
.

2011-01-03 16:41 . 2011-01-03 16:42 -------- d-----w- c:\program files\trend micro
2011-01-03 16:41 . 2011-01-03 16:42 -------- d-----w- C:\rsit
2010-12-31 16:28 . 2010-12-31 16:28 -------- d-----w- c:\program files\Opera
2010-12-31 16:16 . 2010-12-31 16:16 724992 ----a-w- c:\windows\iun6002.exe
2010-12-31 16:16 . 2010-12-31 16:21 -------- d-----w- c:\program files\SpeedItUpExtreme
2010-12-30 16:10 . 2010-12-30 16:10 -------- d-----w- c:\program files\Activision
2010-12-29 17:12 . 2010-12-29 17:12 -------- d-----w- c:\program files\7-Zip
2010-12-29 15:22 . 2006-08-01 14:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
2010-12-29 15:21 . 2010-12-29 15:21 -------- d-----w- c:\program files\Realtek AC97
2010-12-27 14:51 . 2010-12-27 14:51 -------- d-----w- c:\program files\RAM Defrag V2.55
2010-12-26 16:55 . 2010-12-26 16:55 -------- d--h--w- c:\windows\msdownld.tmp
2010-12-26 06:35 . 2010-12-26 06:36 65536 ----a-w- c:\windows\IFinst27.exe
2010-12-25 18:51 . 2010-12-26 06:24 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2010-12-22 10:45 . 2011-01-03 10:07 -------- d-----w- c:\program files\Microsoft Games
2010-12-22 08:42 . 2010-12-22 08:47 -------- d-----w- c:\program files\18 WoS Pedal to the Metal
2010-12-19 14:33 . 2010-12-19 14:34 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\NFS Underground 2
2010-12-16 09:45 . 2010-12-16 09:45 -------- d-----w- c:\documents and settings\user\Data aplikací\Hoyle FaceCreator
2010-12-16 09:45 . 2010-12-16 10:49 -------- d-----w- c:\documents and settings\user\Data aplikací\Hoyle
2010-12-12 09:34 . 2010-12-12 09:35 -------- d-----w- c:\program files\EACOM

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 17:09 . 2010-02-18 11:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2010-02-18 11:21 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-03 06:00 . 2010-06-01 17:00 285480 ----a-w- c:\windows\system32\guard32.dll
2010-11-03 06:00 . 2010-06-01 17:00 91560 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-11-03 06:00 . 2010-06-04 09:55 239240 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-11-03 06:00 . 2010-06-01 17:00 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-11-03 06:00 . 2010-06-01 17:00 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-10-19 14:27 . 2010-01-29 09:38 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2010-10-19 14:27 . 2010-01-29 09:38 109144 ----a-w- c:\windows\system32\OpenAL32.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-11-03 2500552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-22 339968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2011 Russian\\fm.exe"=
"c:\\Program Files\\Opera\\opera.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [27.1.2009 10:14 64160]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [1.6.2010 18:00 15592]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [4.6.2010 10:55 239240]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO livePCsupport\CLPSLS.exe [19.2.2010 16:00 148744]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [3.2.2010 20:50 45696]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [3.2.2010 20:50 56960]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v2.6.87\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v2.6.87\ATI Tray Tools\atitray.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS --> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [24.6.2008 9:36 65024]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;c:\windows\system32\DRIVERS\kwflower.sys --> c:\windows\system32\DRIVERS\kwflower.sys [?]
S3 pbfilter;pbfilter; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.10.2009 18:15 721904]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - EverestDriver
.
Obsah adresáře 'Naplánované úlohy'

2010-11-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-26 14:23]
.
.
------- Doplňkový sken -------
.
uDefault_Search_URL = hxxp://www.google.com
uStart Page = hxxp://start.facemoods.com/?a=ppcb
mStart Page =
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: {7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7} = 10.1.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKCU-Run-SpeedItUpEX - c:\program files\SpeedItUpExtreme\SpeedItUpEx.exe
HKLM-Run-RAM_DEFRAG - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
AddRemove-DAF 95 ATI - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-DAF XF 105 - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Flight Simulator 9.0 - c:\program files\Microsoft Games\Flight Simulator 9\UNINSTAL.EXE
AddRemove-HijackThis - c:\documents and settings\user\Plocha\HijackThis.exe
AddRemove-Iveco Stralis - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Kraz 255 - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-MAZ 151v - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-MB 1934 - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-PttM 1.00-1.04 Czech patch - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\OdinstalovatCzech.exe
AddRemove-Renault Magnum - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Riava - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Scania P-340 - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Tatra 815 - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Volkswagen Constellation - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Volvo F12 - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Volvo F89 - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe
AddRemove-Wos Pack - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal wos Pack.exe
AddRemove-Zemek s.r.o - c:\documents and settings\user\Dokumenty\18 WoS Pedal to the Metal\Uninstal.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-03 18:08
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1409082233-1580818891-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b7,4a,67,15,5b,a9,6a,5b,cd,e9,29,0d,e8,6d,03,26,ab,ed,d4,03,b1,05,91,
9e,12,18,64,cd,52,6a,9b,30,35,dd,39,6d,c6,2c,07,28,e0,cc,4d,3d,fe,d3,a7,b4,\
"??"=hex:8a,95,0c,91,36,dd,90,2c,2c,e3,05,7a,7a,8f,80,cc

[HKEY_USERS\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:e3,2f,6c,87,c0,87,90,51,f5,67,ee,53,6e,2b,61,d3,8d,3b,81,4c,27,
95,df,28,c3,fe,4a,58,8b,19,0b,5b,d1,21,29,4d,0e,6c,20,5b,5a,b7,df,c4,35,e1,\
"rkeysecu"=hex:71,16,e8,e3,8c,f2,11,71,0a,3f,10,02,f2,fe,b2,bd

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="94BC918E2C4269FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D6794FEBC9E127BECC74CBA7FD869164D67943A9DAF0BB27E5CA0871BA1BF258214A2B46CC3317BD969CA7D9109AEE3ACC44C0854D43EAFD1CD2ED18D3AE9FE39AEF52B2BCC4B0A24F0A43E1AFA766FAE5E05ACF200AB17257CC5BAFAE25A25B10D678773827BFECD2AF8563CB22FD613E8A3EEC370B6D8CB930681441CB251616BE423DA46BFF91203A2DA62945546F8238FBA25A879C7E9C183095EA6C91F14094EF90C3C4C82806BEE000A43174BD7CC231E0B6F411BF8B947D8D08BA80F68A9792EC1CC0901FCD89F9F4628DB5876AD2F4D7DCC11EE4932CA9E37151086CF142E04CDA211C2BFC2EAB73CF13A42F18E759C958F9C437A6501A944D3F1CB9316AB659730337854A6FB6A27110046BB3C2E09854B4E798292CB6EB919F20ECC7C215D952774391B846F7D563A2D81170981B18E5544DAABFA0583F0FBEFDA6A9DB39ED6028A7D47E158DAA8E675F59F4C91D78847CE911467F6A4D5D8F6A82FCFFD7C7C7A63A2DF473B1197D3428A3FDBF064DE00F32EACA0E1B268CE494EB1ED0B71BB131C6B41C015D0AC82B0893899A4DF1121ED223B767B32BE40DE0A5E59DC985D0F897A1CDF5070853910221F64A97B3191A947D9BA6A49FED4627B71F4E834BEF5335B73B751EA54FE66E45C226E8868F9C75777C44AC566F630A57F2897A9D115D37A1EE26DDB60A16949ACBD56FE704A9FF2546FAC1545575DF26F5FC57F1BFA5CAAC9FB6E08833488AA2223B7791934B81C859894CD0067AEAEFA0945E4347DEE1FF4A51353AB8864C59FC6DD36462D533B77A379A50E5F200AB11A592AC9B36373F3838B47DABA4E3E5F1B08196D6FDD9B65F5497AFCBA5F98F4893E449EF946236E3E011428A5D1196C9B68289C7A00EB62FB624BEB37CED2FC539D4B867156915F028A893DECAB422AC5280F700F1240D42419BB8FD98496D4751AFC6BFC86821881389E59F349874B9B5F1C9D33228F745FB5932F67CC225AF5C83BCA457F1F3B6E0BEC4EE3521AD9A01F42EAB1F1B5D025733FA96D249ABFDB3208B5B51CF6C0847932012A9D92B161E999B498F6F2CA7084CE6C393E098D32D38ED1FE6B79757E6D506DF8396A036936DA683A5BE819C08A75FEDE02D99D099E1BD696B1FCF69C444D22C3E300D44C70660AACF920C4961F0BF536095C1E73F71F1333E6BA3BA450533F4592957D9D76BFB1C967032BFACC8CFED82246130A372EE850B54F885F58AF7DF86E512C779B8B8AB068627E761598DB2650AFD268AB034CAF7E3DFB9895D526A1D33E5FF82797D2C1F4EF45996BF4DE42C993072D9479C655546984A1B659964453C96DC2D3D05FA43C4558F5B707"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(836)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
Celkový čas: 2011-01-03 18:13:46
ComboFix-quarantined-files.txt 2011-01-03 17:13

Před spuštěním: Volných bajtů: 98 986 496 000
Po spuštění: Volných bajtů: 98 932 514 816

Current=6 Default=6 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 8E2754BD0B4F68F9BBB437B4A8865363

Re: spravce zařízení

Napsal: 03 led 2011 19:00
od Rudy
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files\Ask.com

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
[-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: spravce zařízení

Napsal: 03 led 2011 19:48
od brankar
ComboFix 11-01-02.04 - user 03.01.2011 19:37:58.56.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.511.300 [GMT 1:00]
Spuštěný z: c:\documents and settings\user\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\user\Plocha\CFScript.txt..txt
AV: AVG *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: COMODO Antivirus *Disabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: Microsoft Security Essentials *Enabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: Kerio WinRoute Firewall *Enabled* {916dafda-8250-4a1d-9095-000da68ac4da}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_d3.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-03 do 2011-01-03 )))))))))))))))))))))))))))))))
.

2011-01-03 16:41 . 2011-01-03 16:42 -------- d-----w- c:\program files\trend micro
2011-01-03 16:41 . 2011-01-03 16:42 -------- d-----w- C:\rsit
2010-12-31 16:28 . 2010-12-31 16:28 -------- d-----w- c:\program files\Opera
2010-12-31 16:16 . 2010-12-31 16:16 724992 ----a-w- c:\windows\iun6002.exe
2010-12-31 16:16 . 2010-12-31 16:21 -------- d-----w- c:\program files\SpeedItUpExtreme
2010-12-30 16:10 . 2010-12-30 16:10 -------- d-----w- c:\program files\Activision
2010-12-29 17:12 . 2010-12-29 17:12 -------- d-----w- c:\program files\7-Zip
2010-12-29 15:22 . 2006-08-01 14:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
2010-12-29 15:21 . 2010-12-29 15:21 -------- d-----w- c:\program files\Realtek AC97
2010-12-27 14:51 . 2010-12-27 14:51 -------- d-----w- c:\program files\RAM Defrag V2.55
2010-12-26 16:55 . 2010-12-26 16:55 -------- d--h--w- c:\windows\msdownld.tmp
2010-12-26 06:35 . 2010-12-26 06:36 65536 ----a-w- c:\windows\IFinst27.exe
2010-12-25 18:51 . 2010-12-26 06:24 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2010-12-22 10:45 . 2011-01-03 10:07 -------- d-----w- c:\program files\Microsoft Games
2010-12-22 08:42 . 2010-12-22 08:47 -------- d-----w- c:\program files\18 WoS Pedal to the Metal
2010-12-19 14:33 . 2010-12-19 14:34 -------- d-----w- c:\documents and settings\user\Local Settings\Data aplikací\NFS Underground 2
2010-12-16 09:45 . 2010-12-16 09:45 -------- d-----w- c:\documents and settings\user\Data aplikací\Hoyle FaceCreator
2010-12-16 09:45 . 2010-12-16 10:49 -------- d-----w- c:\documents and settings\user\Data aplikací\Hoyle
2010-12-12 09:34 . 2010-12-12 09:35 -------- d-----w- c:\program files\EACOM

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 17:09 . 2010-02-18 11:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2010-02-18 11:21 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-03 06:00 . 2010-06-01 17:00 285480 ----a-w- c:\windows\system32\guard32.dll
2010-11-03 06:00 . 2010-06-01 17:00 91560 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-11-03 06:00 . 2010-06-04 09:55 239240 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-11-03 06:00 . 2010-06-01 17:00 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-11-03 06:00 . 2010-06-01 17:00 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-10-19 14:27 . 2010-01-29 09:38 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2010-10-19 14:27 . 2010-01-29 09:38 109144 ----a-w- c:\windows\system32\OpenAL32.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-11-03 2500552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-22 339968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2011 Russian\\fm.exe"=
"c:\\Program Files\\Opera\\opera.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [27.1.2009 10:14 64160]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [1.6.2010 18:00 15592]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [4.6.2010 10:55 239240]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO livePCsupport\CLPSLS.exe [19.2.2010 16:00 148744]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [3.2.2010 20:50 45696]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [3.2.2010 20:50 56960]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v2.6.87\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v2.6.87\ATI Tray Tools\atitray.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS --> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [24.6.2008 9:36 65024]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;c:\windows\system32\DRIVERS\kwflower.sys --> c:\windows\system32\DRIVERS\kwflower.sys [?]
S3 pbfilter;pbfilter; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.10.2009 18:15 721904]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - EverestDriver
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uDefault_Search_URL = hxxp://www.google.com
uStart Page = hxxp://start.facemoods.com/?a=ppcb
mStart Page =
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: {7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7} = 10.1.1.1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-03 19:46
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1409082233-1580818891-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b7,4a,67,15,5b,a9,6a,5b,cd,e9,29,0d,e8,6d,03,26,ab,ed,d4,03,b1,05,91,
9e,12,18,64,cd,52,6a,9b,30,35,dd,39,6d,c6,2c,07,28,e0,cc,4d,3d,fe,d3,a7,b4,\
"??"=hex:8a,95,0c,91,36,dd,90,2c,2c,e3,05,7a,7a,8f,80,cc

[HKEY_USERS\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:e3,2f,6c,87,c0,87,90,51,f5,67,ee,53,6e,2b,61,d3,8d,3b,81,4c,27,
95,df,28,c3,fe,4a,58,8b,19,0b,5b,d1,21,29,4d,0e,6c,20,5b,5a,b7,df,c4,35,e1,\
"rkeysecu"=hex:71,16,e8,e3,8c,f2,11,71,0a,3f,10,02,f2,fe,b2,bd

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="94BC918E2C4269FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808BA7FD869164D6794FEBC9E127BECC74CBA7FD869164D67943A9DAF0BB27E5CA0871BA1BF258214A2B46CC3317BD969CA7D9109AEE3ACC44C0854D43EAFD1CD2ED18D3AE9FE39AEF52B2BCC4B0A24F0A43E1AFA766FAE5E05ACF200AB17257CC5BAFAE25A25B10D678773827BFECD2AF8563CB22FD613E8A3EEC370B6D8CB930681441CB251616BE423DA46BFF91203A2DA62945546F8238FBA25A879C7E9C183095EA6C91F14094EF90C3C4C82806BEE000A43174BD7CC231E0B6F411BF8B947D8D08BA80F68A9792EC1CC0901FCD89F9F4628DB5876AD2F4D7DCC11EE4932CA9E37151086CF142E04CDA211C2BFC2EAB73CF13A42F18E759C958F9C437A6501A944D3F1CB9316AB659730337854A6FB6A27110046BB3C2E09854B4E798292CB6EB919F20ECC7C215D952774391B846F7D563A2D81170981B18E5544DAABFA0583F0FBEFDA6A9DB39ED6028A7D47E158DAA8E675F59F4C91D78847CE911467F6A4D5D8F6A82FCFFD7C7C7A63A2DF473B1197D3428A3FDBF064DE00F32EACA0E1B268CE494EB1ED0B71BB131C6B41C015D0AC82B0893899A4DF1121ED223B767B32BE40DE0A5E59DC985D0F897A1CDF5070853910221F64A97B3191A947D9BA6A49FED4627B71F4E834BEF5335B73B751EA54FE66E45C226E8868F9C75777C44AC566F630A57F2897A9D115D37A1EE26DDB60A16949ACBD56FE704A9FF2546FAC1545575DF26F5FC57F1BFA5CAAC9FB6E08833488AA2223B7791934B81C859894CD0067AEAEFA0945E4347DEE1FF4A51353AB8864C59FC6DD36462D533B77A379A50E5F200AB11A592AC9B36373F3838B47DABA4E3E5F1B08196D6FDD9B65F5497AFCBA5F98F4893E449EF946236E3E011428A5D1196C9B68289C7A00EB62FB624BEB37CED2FC539D4B867156915F028A893DECAB422AC5280F700F1240D42419BB8FD98496D4751AFC6BFC86821881389E59F349874B9B5F1C9D33228F745FB5932F67CC225AF5C83BCA457F1F3B6E0BEC4EE3521AD9A01F42EAB1F1B5D025733FA96D249ABFDB3208B5B51CF6C0847932012A9D92B161E999B498F6F2CA7084CE6C393E098D32D38ED1FE6B79757E6D506DF8396A036936DA683A5BE819C08A75FEDE02D99D099E1BD696B1FCF69C444D22C3E300D44C70660AACF920C4961F0BF536095C1E73F71F1333E6BA3BA450533F4592957D9D76BFB1C967032BFACC8CFED82246130A372EE850B54F885F58AF7DF86E512C779B8B8AB068627E761598DB2650AFD268AB034CAF7E3DFB9895D526A1D33E5FF82797D2C1F4EF45996BF4DE42C993072D9479C655546984A1B659964453C96DC2D3D05FA43C4558F5B707"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(836)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
Celkový čas: 2011-01-03 19:51:06
ComboFix-quarantined-files.txt 2011-01-03 18:51
ComboFix2.txt 2011-01-03 17:13

Před spuštěním: Volných bajtů: 98 970 898 432
Po spuštění: Volných bajtů: 98 943 516 672

Current=6 Default=6 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 19D03A20FF9DFA86C6FB6297E6139B6A

Re: spravce zařízení

Napsal: 03 led 2011 20:50
od Rudy
Log již vypadá čistý. Nastala nějaká změna?

Re: spravce zařízení

Napsal: 04 led 2011 08:49
od brankar
Zdravím Rudy děkuji za ochotu a čas a pročištěni PC :)

Re: spravce zařízení

Napsal: 04 led 2011 19:12
od Rudy
Nemáte zač!

Re: spravce zařízení

Napsal: 09 led 2011 22:07
od brankar
Ahoj Rudy dnes jsem zapnul PC a plocha je bez icon a lista start žádná zkrátka jenom čista tapeta ,ale v nouzáku vše v pohodě nevíš co by to mohlo dělat díky předem za radu :x

Re: spravce zařízení

Napsal: 09 led 2011 22:30
od Rudy
Zkusíme ještě jednou RSIT. Pokud to jinak nepůjde, spusťte v nouz. režimu. Spíše si ale myslím, že to bude problém samotného systému.

Re: spravce zařízení

Napsal: 10 led 2011 11:59
od brankar
Ahoj Rudy udělal jsem obnovu systému tak se to chytlo ale je to stejnak divný ,nelibý se mi ten atiptaxx.exe na netu to řeší jako virus.

tady log

Logfile of random's system information tool 1.08 (written by random/random)
Run by user at 2011-01-10 11:54:55
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 69 GB (45%) free of 153 GB
Total RAM: 511 MB (29% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:55:27, on 10.1.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\user\Plocha\RSIT.exe
C:\Program Files\trend micro\user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=ppcb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O17 - HKLM\System\CS4\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O17 - HKLM\System\CS5\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O17 - HKLM\System\CS6\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O17 - HKLM\System\CS7\Services\Tcpip\..\{7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7}: NameServer = 10.1.1.1
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Microsoft Antimalware Service (MsMpSvc) - Unknown owner - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 6133 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}]
QuickStores-Toolbar - C:\WINDOWS\system32\mscoree.dll [2009-11-07 297808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - QuickStores-Toolbar - C:\WINDOWS\system32\mscoree.dll [2009-11-07 297808]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-11-03 2500552]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-02-22 339968]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-02-23 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro35.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro35Crusader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoResolveTrack"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoResolveTrack"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Ares\Ares.exe"="C:\Program Files\Ares\Ares.exe:*:Disabled:Ares p2p for windows"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Sports Interactive\Football Manager 2011 Russian\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2011 Russian\fm.exe:*:Enabled:Football Manager 2011"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-01-10 11:54:55 ----D---- C:\rsit
2011-01-09 21:01:34 ----SD---- C:\ComboFix(2)
2011-01-09 20:04:10 ----A---- C:\WINDOWS\ntbtlog.txt
2011-01-05 13:09:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Test Drive Unlimited
2011-01-03 19:55:15 ----SHD---- C:\RECYCLER
2011-01-03 17:41:44 ----D---- C:\Program Files\trend micro
2010-12-31 17:28:28 ----D---- C:\Program Files\Opera
2010-12-31 17:16:49 ----A---- C:\WINDOWS\iun6002.exe
2010-12-31 17:16:47 ----D---- C:\Program Files\SpeedItUpExtreme
2010-12-30 17:21:59 ----A---- C:\WINDOWS\game.ini
2010-12-30 17:10:59 ----D---- C:\Program Files\Activision
2010-12-29 18:12:52 ----D---- C:\Program Files\7-Zip
2010-12-29 16:22:14 ----A---- C:\WINDOWS\system32\ChCfg.exe
2010-12-29 16:21:22 ----D---- C:\Program Files\Realtek AC97
2010-12-28 18:45:16 ----D---- C:\Program Files\Mozilla Firefox
2010-12-27 15:51:28 ----D---- C:\Program Files\RAM Defrag V2.55
2010-12-26 17:55:54 ----HD---- C:\WINDOWS\msdownld.tmp
2010-12-26 07:35:22 ----A---- C:\WINDOWS\IFinst27.exe
2010-12-25 19:51:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2010-12-22 11:45:20 ----D---- C:\Program Files\Microsoft Games
2010-12-22 09:42:23 ----D---- C:\Program Files\18 WoS Pedal to the Metal
2010-12-16 10:45:29 ----D---- C:\Documents and Settings\user\Data aplikací\Hoyle FaceCreator
2010-12-16 10:45:13 ----D---- C:\Documents and Settings\user\Data aplikací\Hoyle
2010-12-12 10:34:41 ----D---- C:\Program Files\EACOM

======List of files/folders modified in the last 1 months======

2011-01-10 11:51:02 ----D---- C:\WINDOWS\temp
2011-01-10 11:49:15 ----SHD---- C:\System Volume Information
2011-01-10 11:49:15 ----D---- C:\WINDOWS\system32\Restore
2011-01-10 11:46:12 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-10 11:43:36 ----D---- C:\WINDOWS\system32\config
2011-01-10 11:43:20 ----D---- C:\WINDOWS\system32\wbem
2011-01-10 11:43:19 ----D---- C:\WINDOWS\Registration
2011-01-10 11:43:03 ----RD---- C:\Program Files
2011-01-09 22:45:32 ----D---- C:\WINDOWS
2011-01-09 22:45:11 ----D---- C:\Qoobox
2011-01-09 22:38:40 ----A---- C:\WINDOWS\wincmd.ini
2011-01-09 22:32:53 ----D---- C:\WINDOWS\system32\DirectX
2011-01-09 22:32:45 ----SHD---- C:\WINDOWS\Installer
2011-01-09 22:32:41 ----D---- C:\Documents and Settings\user\Data aplikací\uTorrent
2011-01-09 21:50:40 ----A---- C:\WINDOWS\win.ini
2011-01-09 21:50:40 ----A---- C:\WINDOWS\system.ini
2011-01-09 21:04:42 ----D---- C:\WINDOWS\system32
2011-01-09 21:03:53 ----D---- C:\WINDOWS\system32\drivers
2011-01-09 20:27:14 ----D---- C:\Program Files\ATI Technologies
2011-01-09 18:26:11 ----D---- C:\WINDOWS\system32\drivers\etc
2011-01-04 13:02:17 ----D---- C:\Config.Msi
2011-01-04 12:40:18 ----HD---- C:\WINDOWS\inf
2011-01-04 12:40:13 ----RSD---- C:\WINDOWS\assembly
2011-01-04 12:39:51 ----D---- C:\Program Files\EA Sports
2011-01-03 19:48:54 ----SD---- C:\WINDOWS\Tasks
2011-01-03 19:42:35 ----D---- C:\WINDOWS\AppPatch
2011-01-03 19:42:29 ----D---- C:\Program Files\Common Files
2011-01-02 21:30:06 ----SD---- C:\Documents and Settings\user\Data aplikací\Microsoft
2010-12-31 17:23:58 ----D---- C:\Program Files\Java
2010-12-30 17:22:08 ----HD---- C:\Program Files\InstallShield Installation Information
2010-12-29 16:21:42 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-29 16:21:30 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-12-27 16:35:48 ----D---- C:\Program Files\Virtual Makeover 2
2010-12-26 17:20:35 ----D---- C:\WINDOWS\Help
2010-12-24 14:01:42 ----D---- C:\Program Files\EA GAMES
2010-12-24 13:38:58 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-12-22 17:25:51 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-12-22 16:48:10 ----D---- C:\WINDOWS\WinSxS
2010-12-21 08:31:40 ----A---- C:\WINDOWS\AviSplitter.INI
2010-12-20 19:59:43 ----D---- C:\Documents and Settings
2010-12-12 18:11:57 ----D---- C:\Program Files\uTorrent

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys [2009-03-05 64160]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-01-14 47616]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2004-12-03 20544]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2010-09-15 27904]
R1 ATITool;ATITool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\ATITool.sys [2006-11-10 24064]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2010-11-03 15592]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-11-03 239240]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2009-03-15 56268]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service; C:\WINDOWS\System32\Drivers\ousbehci.sys [2005-07-15 45696]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-02-23 986624]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support; C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2005-07-15 56960]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2010-09-15 130432]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 atitray;atitray; \??\C:\Program Files\Radeon Omega Drivers\v2.6.87\ATI Tray Tools\atitray.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-06-02 25280]
S3 kvpndev;Kerio VPN adapter; C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2008-06-24 65024]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer; C:\WINDOWS\system32\DRIVERS\kwflower.sys []
S3 pbfilter;pbfilter; C:\WINDOWS\system32\drivers\pbfilter.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-10-10 721904]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-02-23 352256]
R2 CLPSLS;COMODO livePCsupport Service; C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe [2010-02-19 148744]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-11-03 1901056]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-07-16 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-07-16 189744]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-02-22 516096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------


A pořad stejná chyba

Source Name: DCOM
Time Written: 20101210134853.000000+060
Event Type: Chyba
User: NT AUTHORITY\SYSTEM

Computer Name: VLASTN-81FD8C78
Event Code: 10005
Message: Služba DCOM zjistila chybu %1058 při pokusu o spuštění služby SENS s argumenty
za účelem spuštění serveru:
{D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Record Number: 122867
Source Name: DCOM
Time Written: 20101210134853.000000+060
Event Type: Chyba
User: NT AUTHORITY\SYSTEM

Re: spravce zařízení

Napsal: 10 led 2011 18:24
od Rudy
atiptaxx.exe je legitimní součást ovladačů gr. karty ATI: http://www.liutilities.com/products/win ... /atiptaxx/ . Log vypadá čistý.

Re: spravce zařízení

Napsal: 10 led 2011 19:14
od brankar
tak zatím :wink: snad to pošlape :D

Re: spravce zařízení

Napsal: 10 led 2011 19:27
od Rudy
Mějte se! :bye:

Re: spravce zařízení

Napsal: 23 led 2011 00:36
od brankar
Ahoj Rudy posílám tady scan z rotkit reve. je tam něco špatného. A dále nemohu odstranit microsoft Antimalware

HKU\.DEFAULT\Control Panel\International 8.6.2009 7:34 0 bytes Security mismatch.
HKU\.DEFAULT\Control Panel\International\Geo 8.6.2009 7:34 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Console 14.1.2011 13:27 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Control Panel\International 1.1.2010 0:01 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Control Panel\International\Geo 8.6.2009 7:34 0 bytes Security mismatch.
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY* 31.8.2009 9:59 0 bytes Key name contains embedded nulls (*)
HKU\S-1-5-21-1409082233-1580818891-839522115-1004\Software\SecuROM\License information* 28.12.2010 16:30 0 bytes Key name contains embedded nulls (*)
HKU\S-1-5-18\Control Panel\International 8.6.2009 7:34 0 bytes Security mismatch.
HKU\S-1-5-18\Control Panel\International\Geo 8.6.2009 7:34 0 bytes Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC* 17.10.2008 22:28 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 17.10.2008 22:28 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Microsoft\MSSQLServer\Client\ConnectTo\DSQUERY 24.12.2010 15:14 9 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System* 27.6.2010 15:50 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\swearware\backup\winsock2 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017 24.12.2010 15:14 0 bytes Security mismatch.
HKLM\SOFTWARE\swearware\backup\winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000018 24.12.2010 15:14 0 bytes Security mismatch.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\activity.opr 23.1.2011 0:25 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCC.tmp 23.1.2011 0:23 135.63 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCD.tmp 23.1.2011 0:23 1.06 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCE.tmp 23.1.2011 0:23 144.67 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCF.tmp 23.1.2011 0:23 102 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCG.tmp 23.1.2011 0:23 14.72 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCH.tmp 23.1.2011 0:23 55.93 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCI.tmp 23.1.2011 0:23 17.58 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCJ.tmp 23.1.2011 0:23 43.45 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCK.tmp 23.1.2011 0:23 25.44 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCL.tmp 23.1.2011 0:23 23.59 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCN.tmp 23.1.2011 0:23 50.08 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCO.tmp 23.1.2011 0:23 23.11 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCP.tmp 23.1.2011 0:23 57.70 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCQ.tmp 23.1.2011 0:23 45.59 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCR.tmp 23.1.2011 0:24 23.21 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCS.tmp 23.1.2011 0:24 18.54 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCT.tmp 23.1.2011 0:24 27.71 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCU.tmp 23.1.2011 0:25 27.53 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCV.tmp 23.1.2011 0:25 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCW.tmp 23.1.2011 0:25 22.59 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCX.tmp 23.1.2011 0:26 28.11 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCY.tmp 23.1.2011 0:26 246.55 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TCZ.tmp 23.1.2011 0:26 42.11 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TD0.tmp 23.1.2011 0:26 31.75 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TD1.tmp 23.1.2011 0:27 20.26 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TD2.tmp 23.1.2011 0:28 1.09 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TD3.tmp 23.1.2011 0:28 16.07 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\g_0015\opr01TD6.tmp 23.1.2011 0:28 0 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\sesn\opr01TCM.tmp 23.1.2011 0:23 5.61 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\sesn\opr01TD4.tmp 23.1.2011 0:28 539 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\cache\sesn\opr01TD5.tmp 23.1.2011 0:28 308 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\icons\greatis.com.idx 23.1.2011 0:25 68 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\icons\greatissoftware.com.idx 23.1.2011 0:28 91 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\icons\http%3A%2F%2Fgreatis.com%2Ffavicon.ico 23.1.2011 0:25 1.05 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\icons\http%3A%2F%2Fgreatissoftware.com%2Ffavicon.ico 23.1.2011 0:28 1.05 KB Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\icons\http%3A%2F%2Fwww.f-secure.com%2Ffavicon.ico 23.1.2011 0:23 1.12 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\Data aplikací\Opera\Opera\icons\www.f-secure.com.idx 23.1.2011 0:23 82 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\temp\Rar$EX00.610 23.1.2011 0:26 0 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\temp\Rar$EX00.610\license.txt 23.1.2011 0:26 924 bytes Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\temp\Rar$EX00.610\readme.txt 23.1.2011 0:26 2.88 KB Hidden from Windows API.
C:\Documents and Settings\user\Local Settings\temp\Rar$EX00.610\TDLdetect.exe 23.1.2011 0:26 514.00 KB Hidden from Windows API.
C:\Documents and Settings\user\Plocha\tdl-detector.zip 23.1.2011 0:26 246.55 KB Hidden from Windows API.
C:\Documents and Settings\user\Recent\tdl-detector.lnk 23.1.2011 0:26 423 bytes Hidden from Windows API.