Stránka 1 z 1

Prosim o kontrolu logu: mozny keylogger v PC

Napsal: 27 led 2011 16:21
od onimo
Dobry den dnes mi vykradli moj battlenet ucet. Takze ocakavam ze mam na pocitaci kaylogger a poprosil by som o pomoc pri odstraneni.

Logfile of random's system information tool 1.08 (written by random/random)
Run by mINo at 2011-01-27 16:19:05
Microsoft Windows XP Professional Service Pack 3
System drive C: has 33 GB (65%) free of 50 GB
Total RAM: 3327 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:19:07, on 27.1.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20861)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Razer\Abyssus\razerhid.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe
C:\Program Files\Razer\Abyssus\razertra.exe
C:\Program Files\Razer\Abyssus\razerofa.exe
F:\mIRC\mirc.exe
F:\VentriloMIX\Ventrilo 2.1.4.exe
F:\mirandaIM\miranda32.exe
F:\pacmod\PacMod.exe
F:\World of Warcraft\WoW.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\mINo\Desktop\RSIT.exe
C:\Program Files\trend micro\mINo.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2786678
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Abyssus] C:\Program Files\Razer\Abyssus\razerhid.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PWRISOVM.EXE] F:\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Documents and Settings\mINo\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1960408961-1284227242-682003330-1004\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'postgres')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: NST ToolTipFixer (TTFixerService) - NeoSmart Technologies - C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe

--
End of file - 5719 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngin0.dll [2010-12-26 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTo1.dll [2010-12-26 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-09-15 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTo1.dll [2010-12-26 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngin0.dll [2010-12-26 3911776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"Abyssus"=C:\Program Files\Razer\Abyssus\razerhid.exe [2010-05-10 223744]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-07-03 16876032]
"PWRISOVM.EXE"=F:\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-09-08 421888]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-10-16 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-10-16 13851752]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-08-26 1753192]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Octoshape Streaming Services"=C:\Documents and Settings\mINo\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [2009-01-08 70936]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-27 200064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"F:\steam\steamapps\mino_o\counter-strike\hl.exe"="F:\steam\steamapps\mino_o\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"F:\steam\steamapps\common\left 4 dead 2\left4dead2.exe"="F:\steam\steamapps\common\left 4 dead 2\left4dead2.exe:*:Enabled:Left 4 Dead 2"
"F:\steam\steamapps\common\command and conquer red alert 3\runme.exe"="F:\steam\steamapps\common\command and conquer red alert 3\runme.exe:*:Enabled:Command and Conquer: Red Alert 3"
"F:\steam\steamapps\common\command and conquer red alert 3\Support\EA Help\Electronic_Arts_Technical_Support.htm"="F:\steam\steamapps\common\command and conquer red alert 3\Support\EA Help\Electronic_Arts_Technical_Support.htm:*:Enabled:Command and Conquer: Red Alert 3"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"F:\steam\steamapps\mino_o\day of defeat source\hl2.exe"="F:\steam\steamapps\mino_o\day of defeat source\hl2.exe:*:Enabled:Day of Defeat: Source"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

======File associations======

.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-01-22 01:07:49 ----D---- C:\Documents and Settings\mINo\Application Data\vlc
2011-01-03 18:41:30 ----A---- C:\Documents and Settings\All Users\Application Data\ra3.ini
2011-01-03 05:28:09 ----D---- C:\Documents and Settings\mINo\Application Data\Red Alert 3

======List of files/folders modified in the last 1 months======

2011-01-27 16:19:06 ----D---- C:\Program Files\trend micro
2011-01-27 15:49:50 ----D---- C:\WINDOWS\Prefetch
2011-01-27 13:48:21 ----D---- C:\WINDOWS\system32
2011-01-27 13:48:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-01-27 13:44:22 ----D---- C:\WINDOWS\Temp
2011-01-26 21:27:05 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-01-26 05:39:47 ----D---- C:\Documents and Settings\mINo\Application Data\uTorrent
2011-01-19 04:45:56 ----A---- C:\WINDOWS\avisplitter.ini
2011-01-18 22:50:44 ----D---- C:\Documents and Settings\mINo\Application Data\PriceGong
2011-01-14 00:22:09 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-14 00:16:27 ----D---- C:\Documents and Settings\mINo\Application Data\TeamViewer
2011-01-04 02:35:52 ----RD---- C:\Program Files
2011-01-04 02:35:52 ----D---- C:\Program Files\Common Files
2011-01-04 02:35:52 ----D---- C:\Documents and Settings\mINo\Application Data\Skype
2011-01-04 02:35:50 ----SHD---- C:\WINDOWS\Installer
2011-01-04 02:35:05 ----D---- C:\WINDOWS
2011-01-04 01:22:52 ----D---- C:\Documents and Settings\mINo\Application Data\skypePM
2011-01-04 01:22:23 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2011-01-03 05:25:12 ----HD---- C:\WINDOWS\inf
2011-01-03 05:25:01 ----RSD---- C:\WINDOWS\assembly
2011-01-03 05:24:46 ----D---- C:\WINDOWS\system32\DirectX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 mv61xx;mv61xx; C:\WINDOWS\system32\DRIVERS\mv61xx.sys [2007-10-18 143360]
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-06-19 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2008-05-29 62848]
R3 Abyssus03;Razer Abyssus USB Filter Driver; C:\WINDOWS\System32\Drivers\Abyssus.sys [2009-10-30 9216]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-03 4745216]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2009-08-05 39424]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-10-16 9623680]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 vHidDev;Razer Gaming Device; C:\WINDOWS\system32\DRIVERS\vHidDev.sys [2009-12-21 5760]
S3 catchme;catchme; \??\C:\DOCUME~1\mINo\LOCALS~1\Temp\catchme.sys []
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\WudfPf.sys []
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\wudfrd.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-09-15 153376]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-10-16 156776]
R2 pgsql-8.3;PostgreSQL Database Server 8.3; C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe [2009-03-13 65536]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-10-29 75064]
R2 TTFixerService;NST ToolTipFixer; C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe [2007-06-26 10240]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-07-11 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prosim o kontrolu logu: mozny keylogger v PC

Napsal: 27 led 2011 19:10
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Prosim o kontrolu logu: mozny keylogger v PC

Napsal: 28 led 2011 00:59
od onimo
ComboFix 11-01-27.01 - mINo 27.01.2011 19:51:32.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.3327.2760 [GMT 1:00]
Running from: c:\documents and settings\mINo\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\mINo\Application Data\PriceGong
c:\documents and settings\mINo\Application Data\PriceGong\Data\1.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\a.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\b.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\c.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\d.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\e.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\f.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\g.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\h.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\i.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\J.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\k.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\l.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\m.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\n.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\o.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\p.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\q.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\r.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\s.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\t.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\u.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\v.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\w.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\x.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\y.xml
c:\documents and settings\mINo\Application Data\PriceGong\Data\z.xml

.
((((((((((((((((((((((((( Files Created from 2010-12-27 to 2011-01-27 )))))))))))))))))))))))))))))))
.

2011-01-22 00:07 . 2011-01-22 17:21 -------- d-----w- c:\documents and settings\mINo\Application Data\vlc
2011-01-03 04:28 . 2011-01-03 17:50 -------- d-----w- c:\documents and settings\mINo\Application Data\Red Alert 3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-14 15:42 . 2010-07-07 21:39 137960 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-12-14 15:42 . 2010-07-07 21:39 235248 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-12-14 15:42 . 2010-07-07 16:12 235248 ----a-w- c:\windows\system32\PnkBstrB.exe
.

------- Sigcheck -------

[-] 2008-08-27 . DF70435F3D17C40D5CB15E6DC918342E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[-] 2008-08-27 . 3122DAF86B33ED8AC4662D07593025D7 . 501760 . . [1.0626.6001.18000] . . c:\windows\system32\usp10.dll

[-] 2008-08-27 . F2DF0FDBD41B34112EE05ED04258F052 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-11-30_21.07.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-27 12:44 . 2011-01-27 12:44 16384 c:\windows\Temp\Perflib_Perfdata_58c.dat
+ 2008-04-14 12:00 . 2005-12-05 17:07 61136 c:\windows\system32\xinput9_1_0.dll
- 2008-04-14 12:00 . 2005-12-05 16:07 61136 c:\windows\system32\xinput9_1_0.dll
- 2008-04-14 12:00 . 2006-07-28 07:30 62744 c:\windows\system32\xinput1_2.dll
+ 2008-04-14 12:00 . 2006-07-28 08:30 62744 c:\windows\system32\xinput1_2.dll
- 2008-04-14 12:00 . 2006-03-31 10:39 62672 c:\windows\system32\xinput1_1.dll
+ 2008-04-14 12:00 . 2006-03-31 11:39 62672 c:\windows\system32\xinput1_1.dll
- 2008-04-14 12:00 . 2008-06-05 13:53 65032 c:\windows\system32\XAPOFX1_0.dll
+ 2008-04-14 12:00 . 2008-05-30 13:17 65032 c:\windows\system32\XAPOFX1_0.dll
+ 2008-04-14 12:00 . 2008-05-30 13:17 25608 c:\windows\system32\X3DAudio1_4.dll
- 2008-04-14 12:00 . 2008-06-05 13:53 25608 c:\windows\system32\X3DAudio1_4.dll
- 2008-04-14 12:00 . 2008-03-05 14:00 25608 c:\windows\system32\X3DAudio1_3.dll
+ 2008-04-14 12:00 . 2008-03-05 15:00 25608 c:\windows\system32\X3DAudio1_3.dll
- 2008-04-14 12:00 . 2007-10-22 01:37 17928 c:\windows\system32\X3DAudio1_2.dll
+ 2008-04-14 12:00 . 2007-10-22 02:37 17928 c:\windows\system32\X3DAudio1_2.dll
+ 2008-04-14 12:00 . 2007-03-05 11:42 15128 c:\windows\system32\x3daudio1_1.dll
- 2008-04-14 12:00 . 2007-03-05 10:42 15128 c:\windows\system32\x3daudio1_1.dll
- 2008-04-14 12:00 . 2006-02-03 06:41 14032 c:\windows\system32\x3daudio1_0.dll
+ 2008-04-14 12:00 . 2006-02-03 07:41 14032 c:\windows\system32\x3daudio1_0.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 61440 c:\windows\system32\ReinstallBackups\0017\DriverFiles\OpenCL.dll
- 2008-04-14 12:00 . 2010-11-30 19:59 71138 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2011-01-27 12:48 71138 c:\windows\system32\perfc009.dat
+ 2010-07-07 12:56 . 2010-10-16 18:55 61440 c:\windows\system32\OpenCL.dll
- 2010-07-07 12:56 . 2010-06-07 23:57 61440 c:\windows\system32\OpenCL.dll
- 2010-06-07 15:34 . 2010-06-07 15:34 81920 c:\windows\system32\nvwddi.dll
+ 2010-10-16 11:04 . 2010-10-16 11:04 81920 c:\windows\system32\nvwddi.dll
+ 2010-06-15 02:16 . 2010-06-15 02:16 86016 c:\windows\system32\frapsvid.dll
+ 2010-12-19 13:38 . 2008-04-13 23:15 15104 c:\windows\system32\drivers\usbscan.sys
+ 2010-12-19 13:38 . 2008-04-13 23:15 15104 c:\windows\system32\dllcache\usbscan.sys
+ 2011-01-03 04:25 . 2011-01-03 04:25 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-12-19 13:38 . 2001-08-17 21:36 5632 c:\windows\system32\ptpusb.dll
- 2008-04-14 12:00 . 2008-06-05 13:53 507400 c:\windows\system32\XAudio2_1.dll
+ 2008-04-14 12:00 . 2008-05-30 13:19 507400 c:\windows\system32\XAudio2_1.dll
+ 2008-04-14 12:00 . 2008-03-05 15:03 479752 c:\windows\system32\XAudio2_0.dll
- 2008-04-14 12:00 . 2008-03-05 14:03 479752 c:\windows\system32\XAudio2_0.dll
+ 2008-04-14 12:00 . 2008-05-30 13:18 238088 c:\windows\system32\xactengine3_1.dll
- 2008-04-14 12:00 . 2008-06-05 13:53 238088 c:\windows\system32\xactengine3_1.dll
- 2008-04-14 12:00 . 2008-03-05 14:03 238088 c:\windows\system32\xactengine3_0.dll
+ 2008-04-14 12:00 . 2008-03-05 15:03 238088 c:\windows\system32\xactengine3_0.dll
+ 2008-04-14 12:00 . 2007-07-19 23:57 267112 c:\windows\system32\xactengine2_9.dll
- 2008-04-14 12:00 . 2007-07-19 22:57 267112 c:\windows\system32\xactengine2_9.dll
+ 2008-04-14 12:00 . 2007-06-20 19:46 266088 c:\windows\system32\xactengine2_8.dll
- 2008-04-14 12:00 . 2007-06-20 18:46 266088 c:\windows\system32\xactengine2_8.dll
- 2008-04-14 12:00 . 2007-04-04 16:55 261480 c:\windows\system32\xactengine2_7.dll
+ 2008-04-14 12:00 . 2007-04-04 17:55 261480 c:\windows\system32\xactengine2_7.dll
- 2008-04-14 12:00 . 2007-01-24 13:27 255848 c:\windows\system32\xactengine2_6.dll
+ 2008-04-14 12:00 . 2007-01-24 14:27 255848 c:\windows\system32\xactengine2_6.dll
+ 2008-04-14 12:00 . 2006-12-08 11:02 251672 c:\windows\system32\xactengine2_5.dll
- 2008-04-14 12:00 . 2006-12-08 10:02 251672 c:\windows\system32\xactengine2_5.dll
+ 2008-04-14 12:00 . 2006-09-28 15:05 237848 c:\windows\system32\xactengine2_4.dll
- 2008-04-14 12:00 . 2006-09-28 14:05 237848 c:\windows\system32\xactengine2_4.dll
+ 2008-04-14 12:00 . 2006-07-28 08:30 236824 c:\windows\system32\xactengine2_3.dll
- 2008-04-14 12:00 . 2006-07-28 07:30 236824 c:\windows\system32\xactengine2_3.dll
+ 2008-04-14 12:00 . 2006-05-31 06:24 230168 c:\windows\system32\xactengine2_2.dll
- 2008-04-14 12:00 . 2006-05-31 05:24 230168 c:\windows\system32\xactengine2_2.dll
- 2008-04-14 12:00 . 2007-10-22 01:39 267272 c:\windows\system32\xactengine2_10.dll
+ 2008-04-14 12:00 . 2007-10-22 02:39 267272 c:\windows\system32\xactengine2_10.dll
- 2008-04-14 12:00 . 2006-03-31 10:39 229584 c:\windows\system32\xactengine2_1.dll
+ 2008-04-14 12:00 . 2006-03-31 11:39 229584 c:\windows\system32\xactengine2_1.dll
- 2008-04-14 12:00 . 2006-02-03 06:42 230096 c:\windows\system32\xactengine2_0.dll
+ 2008-04-14 12:00 . 2006-02-03 07:42 230096 c:\windows\system32\xactengine2_0.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 600680 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvudisp.exe
+ 2010-12-17 18:04 . 2010-06-07 23:57 217180 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvdrsdb.bin
+ 2010-12-17 18:04 . 2010-06-07 23:57 232040 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvcod.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 139776 c:\windows\system32\ReinstallBackups\0017\DriverFiles\dbInstaller.exe
+ 2010-12-19 13:38 . 2008-04-14 04:42 159232 c:\windows\system32\ptpusd.dll
- 2008-04-14 12:00 . 2010-11-30 19:59 440820 c:\windows\system32\perfh009.dat
+ 2008-04-14 12:00 . 2011-01-27 12:48 440820 c:\windows\system32\perfh009.dat
+ 2010-10-16 11:04 . 2010-10-16 11:04 156776 c:\windows\system32\nvsvc32.exe
+ 2010-10-16 11:04 . 2010-10-16 11:04 110696 c:\windows\system32\nvmctray.dll
- 2010-06-07 15:34 . 2010-06-07 15:34 110696 c:\windows\system32\nvmctray.dll
+ 2010-10-16 11:04 . 2010-10-16 11:04 277608 c:\windows\system32\nvmccs.dll
- 2010-06-07 15:34 . 2010-06-07 15:34 277608 c:\windows\system32\nvmccs.dll
+ 2010-12-17 18:04 . 2010-10-16 18:55 813672 c:\windows\system32\nvgenco32.dll
+ 2010-07-07 12:57 . 2010-12-17 18:04 240592 c:\windows\system32\nvdrsdb1.bin
+ 2010-07-07 12:57 . 2010-12-17 18:04 240592 c:\windows\system32\nvdrsdb0.bin
+ 2010-12-17 18:04 . 2010-10-16 18:55 888424 c:\windows\system32\nvdispco32.dll
- 2010-06-07 15:34 . 2010-06-07 15:34 145000 c:\windows\system32\nvcolor.exe
+ 2010-10-16 11:04 . 2010-10-16 11:04 145000 c:\windows\system32\nvcolor.exe
+ 2008-04-14 12:00 . 2008-02-05 22:07 462864 c:\windows\system32\d3dx10_37.dll
- 2008-04-14 12:00 . 2008-02-05 21:07 462864 c:\windows\system32\d3dx10_37.dll
- 2008-04-14 12:00 . 2007-10-02 07:56 444776 c:\windows\system32\d3dx10_36.dll
+ 2008-04-14 12:00 . 2007-10-02 08:56 444776 c:\windows\system32\d3dx10_36.dll
- 2008-04-14 12:00 . 2007-07-19 16:14 444776 c:\windows\system32\d3dx10_35.dll
+ 2008-04-14 12:00 . 2007-07-19 17:14 444776 c:\windows\system32\d3dx10_35.dll
+ 2008-04-14 12:00 . 2007-05-16 15:45 443752 c:\windows\system32\d3dx10_34.dll
- 2008-04-14 12:00 . 2007-05-16 14:45 443752 c:\windows\system32\d3dx10_34.dll
- 2008-04-14 12:00 . 2007-03-15 14:57 443752 c:\windows\system32\d3dx10_33.dll
+ 2008-04-14 12:00 . 2007-03-15 15:57 443752 c:\windows\system32\d3dx10_33.dll
- 2006-03-31 09:27 . 2006-03-31 09:27 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-03-31 09:27 . 2006-03-31 10:27 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
- 2006-02-03 05:40 . 2006-02-03 05:40 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-02-03 05:40 . 2006-02-03 06:40 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
- 2005-12-05 15:20 . 2005-12-05 15:20 577536 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 15:20 . 2005-12-05 16:20 577536 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
- 2005-09-28 12:11 . 2005-09-28 12:11 577536 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-09-28 12:11 . 2005-09-28 13:11 577536 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
- 2005-07-22 15:21 . 2005-07-22 15:21 577024 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 15:21 . 2005-07-22 16:21 577024 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-05-26 13:15 . 2005-05-26 14:15 576000 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
- 2005-05-26 13:15 . 2005-05-26 13:15 576000 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
- 2005-03-18 15:23 . 2005-03-18 15:23 567296 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 15:23 . 2005-03-18 16:23 567296 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 17:32 . 2005-02-05 18:32 563712 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
- 2005-02-05 17:32 . 2005-02-05 17:32 563712 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2011-01-03 04:25 . 2011-01-03 04:25 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2011-01-03 04:25 . 2011-01-03 04:25 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2011-01-03 04:25 . 2011-01-03 04:25 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2011-01-03 04:25 . 2011-01-03 04:25 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2011-01-03 04:25 . 2011-01-03 04:25 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:25 . 2011-01-03 04:25 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2010-07-11 17:52 . 2010-07-11 17:52 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 2186342 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvdata.bin
+ 2010-12-17 18:04 . 2010-06-07 23:57 2165352 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvcuvid.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 2632296 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvcuvenc.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 4554752 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvcuda.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 1359872 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvapi.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 6300544 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nv4_disp.dll
+ 2010-07-07 12:56 . 2010-10-16 18:55 2293194 c:\windows\system32\nvdata.bin
+ 2010-07-07 12:56 . 2010-10-16 18:55 2932840 c:\windows\system32\nvcuvid.dll
+ 2010-07-07 12:56 . 2010-10-16 18:55 2666600 c:\windows\system32\nvcuvenc.dll
+ 2010-07-07 12:56 . 2010-10-16 18:55 4882432 c:\windows\system32\nvcuda.dll
+ 2010-07-07 12:56 . 2010-10-16 18:55 1462272 c:\windows\system32\nvapi.dll
+ 2010-07-07 12:56 . 2010-10-16 18:55 6359552 c:\windows\system32\nv4_disp.dll
+ 2010-07-07 12:56 . 2010-10-16 18:55 9623680 c:\windows\system32\drivers\nv4_mini.sys
+ 2010-07-07 12:56 . 2010-10-16 18:55 9623680 c:\windows\system32\dllcache\nv4_mini.sys
- 2008-03-05 13:56 . 2008-03-05 13:56 3786760 c:\windows\system32\D3DX9_37.dll
+ 2008-03-05 13:56 . 2008-03-05 14:56 3786760 c:\windows\system32\D3DX9_37.dll
+ 2007-10-12 13:14 . 2007-10-12 14:14 3734536 c:\windows\system32\d3dx9_36.dll
- 2007-10-12 13:14 . 2007-10-12 13:14 3734536 c:\windows\system32\d3dx9_36.dll
+ 2007-07-19 16:14 . 2007-07-19 17:14 3727720 c:\windows\system32\d3dx9_35.dll
- 2007-07-19 16:14 . 2007-07-19 16:14 3727720 c:\windows\system32\d3dx9_35.dll
+ 2007-05-16 14:45 . 2007-05-16 15:45 3497832 c:\windows\system32\d3dx9_34.dll
- 2007-05-16 14:45 . 2007-05-16 14:45 3497832 c:\windows\system32\d3dx9_34.dll
- 2006-11-29 11:06 . 2006-11-29 11:06 3426072 c:\windows\system32\d3dx9_32.dll
+ 2006-11-29 11:06 . 2006-11-29 12:06 3426072 c:\windows\system32\d3dx9_32.dll
- 2006-03-31 10:40 . 2006-03-31 10:40 2388176 c:\windows\system32\d3dx9_30.dll
+ 2006-03-31 10:40 . 2006-03-31 11:40 2388176 c:\windows\system32\d3dx9_30.dll
+ 2006-02-03 06:43 . 2006-02-03 07:43 2332368 c:\windows\system32\d3dx9_29.dll
- 2006-02-03 06:43 . 2006-02-03 06:43 2332368 c:\windows\system32\d3dx9_29.dll
- 2005-12-05 16:09 . 2005-12-05 16:09 2323664 c:\windows\system32\d3dx9_28.dll
+ 2005-12-05 16:09 . 2005-12-05 17:09 2323664 c:\windows\system32\d3dx9_28.dll
+ 2005-07-22 17:59 . 2005-07-22 18:59 2319568 c:\windows\system32\d3dx9_27.dll
- 2005-07-22 17:59 . 2005-07-22 17:59 2319568 c:\windows\system32\d3dx9_27.dll
+ 2005-05-26 13:34 . 2005-05-26 14:34 2297552 c:\windows\system32\d3dx9_26.dll
- 2005-05-26 13:34 . 2005-05-26 13:34 2297552 c:\windows\system32\d3dx9_26.dll
- 2005-03-18 15:19 . 2005-03-18 15:19 2337488 c:\windows\system32\d3dx9_25.dll
+ 2005-03-18 15:19 . 2005-03-18 16:19 2337488 c:\windows\system32\d3dx9_25.dll
+ 2005-02-05 17:45 . 2005-02-05 18:45 2222800 c:\windows\system32\d3dx9_24.dll
- 2005-02-05 17:45 . 2005-02-05 17:45 2222800 c:\windows\system32\d3dx9_24.dll
- 2008-04-14 12:00 . 2008-03-05 13:56 1420824 c:\windows\system32\D3DCompiler_37.dll
+ 2008-04-14 12:00 . 2008-03-05 14:56 1420824 c:\windows\system32\D3DCompiler_37.dll
- 2008-04-14 12:00 . 2007-10-12 13:14 1374232 c:\windows\system32\D3DCompiler_36.dll
+ 2008-04-14 12:00 . 2007-10-12 14:14 1374232 c:\windows\system32\D3DCompiler_36.dll
- 2008-04-14 12:00 . 2007-07-19 16:14 1358192 c:\windows\system32\D3DCompiler_35.dll
+ 2008-04-14 12:00 . 2007-07-19 17:14 1358192 c:\windows\system32\D3DCompiler_35.dll
- 2008-04-14 12:00 . 2007-05-16 14:45 1124720 c:\windows\system32\D3DCompiler_34.dll
+ 2008-04-14 12:00 . 2007-05-16 15:45 1124720 c:\windows\system32\D3DCompiler_34.dll
- 2008-04-14 12:00 . 2007-03-12 14:42 1123696 c:\windows\system32\D3DCompiler_33.dll
+ 2008-04-14 12:00 . 2007-03-12 15:42 1123696 c:\windows\system32\D3DCompiler_33.dll
- 2004-12-01 13:53 . 2004-12-01 13:53 2846720 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2004-12-01 13:53 . 2004-12-01 14:53 2846720 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
- 2005-03-18 14:23 . 2004-09-29 10:38 2676224 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 14:23 . 2004-09-29 11:38 2676224 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2010-12-17 18:05 . 2010-12-17 18:05 1598464 c:\windows\Installer\7db0c.msi
+ 2010-12-22 00:27 . 2010-12-22 00:27 2587136 c:\windows\Installer\2f0f4aa.msi
+ 2011-01-03 04:24 . 2011-01-03 04:24 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2011-01-03 04:24 . 2011-01-03 04:24 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 15192064 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvoglnt.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 24582464 c:\windows\system32\ReinstallBackups\0017\DriverFiles\NvCplSetupEng.exe
+ 2010-12-17 18:04 . 2010-06-07 23:57 10256384 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nvcompiler.dll
+ 2010-12-17 18:04 . 2010-06-07 23:57 10531200 c:\windows\system32\ReinstallBackups\0017\DriverFiles\nv4_mini.sys
+ 2010-07-07 12:56 . 2010-10-16 18:55 14532608 c:\windows\system32\nvoglnt.dll
+ 2010-10-16 11:04 . 2010-10-16 11:04 13851752 c:\windows\system32\nvcpl.dll
+ 2010-07-07 12:56 . 2010-10-16 18:55 13012992 c:\windows\system32\nvcompiler.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-26 3911776]

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-26 17:11 3911776 ----a-w- c:\program files\ConduitEngine\ConduitEngin0.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-26 17:11 3911776 ----a-w- c:\program files\uTorrentBar\tbuTo1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-26 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-12-26 3911776]

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\tbuTo1.dll" [2010-12-26 3911776]

[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Octoshape Streaming Services"="c:\documents and settings\mINo\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Abyssus"="c:\program files\Razer\Abyssus\razerhid.exe" [2010-05-10 223744]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-03 16876032]
"PWRISOVM.EXE"="f:\poweriso\PWRISOVM.EXE" [2010-04-12 180224]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-08-25 1753192]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-06-23 124928]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"f:\\steam\\steamapps\\mino_o\\counter-strike\\hl.exe"=
"f:\\steam\\steamapps\\common\\left 4 dead 2\\left4dead2.exe"=
"f:\\steam\\steamapps\\common\\command and conquer red alert 3\\runme.exe"=
"f:\\steam\\steamapps\\common\\command and conquer red alert 3\\Support\\EA Help\\Electronic_Arts_Technical_Support.htm"=
"f:\\steam\\steamapps\\mino_o\\day of defeat source\\hl2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56533:TCP"= 56533:TCP:Pando Media Booster
"56533:UDP"= 56533:UDP:Pando Media Booster

R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [27.8.2008 16:14 143360]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [13.3.2009 4:50 65536]
R2 TTFixerService;NST ToolTipFixer;c:\program files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe [7.7.2010 13:34 10240]
R3 Abyssus03;Razer Abyssus USB Filter Driver;c:\windows\system32\drivers\Abyssus.sys [7.7.2010 13:55 9216]
R3 vHidDev;Razer Gaming Device;c:\windows\system32\drivers\vHidDev.sys [7.7.2010 13:55 5760]
.
Contents of the 'Scheduled Tasks' folder

2011-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2786678
FF - ProfilePath - c:\documents and settings\mINo\Application Data\Mozilla\Firefox\Profiles\9gcy3823.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Flash and Video Download: {bee6eb20-01e0-ebd1-da83-080329fb9a3a} - %profile%\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: BlockSite: {dd3d7613-0246-469d-bc65-2a3cc1668adc} - %profile%\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Usbfix - c:\usbfix\Un-Usbfix.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-27 19:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\docume~1\mINo\LOCALS~1\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
Completion time: 2011-01-27 19:54:12
ComboFix-quarantined-files.txt 2011-01-27 18:53
ComboFix2.txt 2010-11-30 21:08

Pre-Run: 34 444 034 048 bytes free
Post-Run: 34 577 080 320 bytes free

- - End Of File - - EB42BF8A1495869350ACA892888B5A41

Re: Prosim o kontrolu logu: mozny keylogger v PC

Napsal: 28 led 2011 19:31
od Rudy
Několik položek bylo smazáno, zbytek logu vypadá čistý. Keylogger však nikde nevidím. Doporučuji změnit heslo.

Re: Prosim o kontrolu logu: mozny keylogger v PC

Napsal: 28 led 2011 19:41
od onimo
Predtym ako som sem napisal o overenie som PC prebehol spybotom a adawarom tak mozno zabralo to.
Kazdopadne velka vdaka za kontrolu a pomoc.

Re: Prosim o kontrolu logu: mozny keylogger v PC

Napsal: 28 led 2011 19:50
od Rudy
Rádo se stalo!