Stránka 1 z 1

pro vyosek

Napsal: 08 úno 2011 17:25
od michal_smsmsm
Zdravim po delsi dobe, mam tady jeno pc ktere je takove podivne... V ruznych situacich samovole tuhne. Nejdrive vytuhne explorer.exe tznm. nejde klikat ale jde hybat mysi, nasledne PC pipne a sekne se i mys, v ten moment uz je to konecna a nic nez reset nepomuze. Bohuzel mrcha tuhne nekdy jeste pred prihlasenim uzivatele, nekdy po chvili prace, nekdy pc nestihne ani poradne nabehnout je to ruzne... Nekdy pc bezi i kolik dni bez problemu :) Provedl jsem cistku ccleanerem, mbamem, sasem a tfc. samozrejmosti bylo spousta balastu, nejaky trojanci (stacilo by to tak na Velkou Pardubickou) a kdejakej dalsi sajrajt... Nicmene pc vytuhava stejne nahodne porad... Zkuste jestli vas neco napadne ;-) Díky. Prikladam log s rsit:

Logfile of random's system information tool 1.08 (written by random/random)
Run by František at 2011-02-08 17:00:25
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 82 GB (34%) free of 238 GB
Total RAM: 2047 MB (78% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:00:36, on 8.2.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\DU Meter\DUMeter.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Documents and Settings\František\Plocha\RSIT.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\trend micro\František.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [DU Meter] C:\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\61de6be9-295b-4216-94e3-383219ea8716.com
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 9148647890
O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://83.208.144.71/bl_camera.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

--
End of file - 7070 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit []
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-21 16126464]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AdslTaskBar"=stmctrl.dll,TaskBar []
"DU Meter"=C:\DU Meter\DUMeter.exe [2005-02-01 1469952]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe [2006-06-27 1449984]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-10-23 202024]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\61de6be9-295b-4216-94e3-383219ea8716.com [2011-02-08 2424560]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

C:\Documents and Settings\František\Nabídka Start\Programy\Po spuštění
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"=C:\PROGRA~1\DVDIDL~1\DVDShell.dll [2004-10-09 49152]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\rapget140\rapget140\rapget.exe"="C:\Program Files\rapget140\rapget140\rapget.exe:*:Enabled:rapget"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:MSI starter"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox"
"E:\Netcam\EasyConfig.exe"="E:\Netcam\EasyConfig.exe:*:Enabled:Network Camera Setup Software"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Documents and Settings\František\Plocha\bulanci.exe"="C:\Documents and Settings\František\Plocha\bulanci.exe:*:Enabled:bulanci"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

======List of files/folders created in the last 1 months======

2011-02-08 17:00:26 ----D---- C:\Program Files\trend micro
2011-02-08 17:00:25 ----D---- C:\rsit
2011-02-08 14:19:06 ----D---- C:\Documents and Settings\František\Data aplikací\Genie-Soft
2011-02-07 20:22:22 ----D---- C:\Documents and Settings\František\Data aplikací\Nero
2011-02-07 20:15:31 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2011-02-07 20:14:01 ----D---- C:\Program Files\Common Files\Nero
2011-02-07 20:14:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2011-02-06 20:47:43 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-02-06 20:47:42 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-02-06 20:47:41 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-02-06 20:47:40 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-02-06 20:47:38 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-02-06 20:47:38 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-02-06 20:47:37 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-02-06 20:47:25 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-02-06 20:35:47 ----D---- C:\Documents and Settings\František\Data aplikací\Malwarebytes
2011-02-06 20:35:41 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-02-06 20:35:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-02-06 20:35:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-02-06 20:35:40 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-02-06 20:35:16 ----D---- C:\Documents and Settings\František\Data aplikací\SUPERAntiSpyware.com
2011-02-06 20:35:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2011-02-06 20:35:09 ----D---- C:\Program Files\SUPERAntiSpyware
2011-02-06 20:04:35 ----D---- C:\WINDOWS\ShellNew
2011-02-06 20:04:35 ----D---- C:\Program Files\Common Files\Designer
2011-02-06 20:04:14 ----D---- C:\Program Files\Microsoft Silverlight
2011-02-06 20:04:06 ----D---- C:\WINDOWS\screensaver-800x600 dir
2011-02-06 20:03:54 ----D---- C:\Program Files\Windows Live Safety Center
2011-02-06 20:03:52 ----D---- C:\Program Files\DVDIdle Pro
2011-02-06 19:59:47 ----D---- C:\Program Files\CCleaner
2011-02-06 19:42:09 ----A---- C:\WINDOWS\system32\OUTLWAB.DLL
2011-02-06 19:42:02 ----SHD---- C:\Config.Msi
2011-02-06 19:26:14 ----D---- C:\Program Files\Passware
2011-02-06 19:19:58 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-02-01 20:50:36 ----D---- C:\WINDOWS\ie8updates
2011-02-01 20:47:56 ----HDC---- C:\WINDOWS\ie8
2011-01-12 17:34:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$

======List of files/folders modified in the last 1 months======

2011-02-08 17:00:26 ----RD---- C:\Program Files
2011-02-08 16:59:50 ----D---- C:\WINDOWS\Prefetch
2011-02-08 15:46:46 ----D---- C:\WINDOWS
2011-02-08 15:40:44 ----D---- C:\WINDOWS\system32\drivers
2011-02-08 15:40:44 ----D---- C:\WINDOWS\system32
2011-02-08 14:20:30 ----SHD---- C:\WINDOWS\Installer
2011-02-08 14:19:49 ----D---- C:\WINDOWS\Temp
2011-02-08 14:16:37 ----D---- C:\WINDOWS\WinSxS
2011-02-08 14:00:53 ----SHD---- C:\System Volume Information
2011-02-08 14:00:53 ----D---- C:\WINDOWS\system32\Restore
2011-02-08 09:32:22 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2011-02-08 08:38:53 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-08 08:07:28 ----D---- C:\Documents and Settings\František\Data aplikací\Skype
2011-02-08 08:04:36 ----D---- C:\Documents and Settings\František\Data aplikací\skypePM
2011-02-07 20:14:01 ----D---- C:\Program Files\Nero
2011-02-07 20:14:01 ----D---- C:\Program Files\Common Files
2011-02-07 20:14:00 ----D---- C:\WINDOWS\Cursors
2011-02-07 20:13:42 ----D---- C:\Program Files\Mozilla Firefox
2011-02-07 20:05:53 ----D---- C:\Program Files\Common Files\Ahead
2011-02-07 20:05:53 ----D---- C:\Program Files\Ahead
2011-02-07 18:55:36 ----D---- C:\WINDOWS\Microsoft.NET
2011-02-06 20:47:32 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-02-06 20:47:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2011-02-06 20:16:42 ----RSD---- C:\WINDOWS\assembly
2011-02-06 20:16:37 ----D---- C:\Program Files\Windows Live
2011-02-06 20:15:39 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-02-06 20:13:38 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-02-06 20:13:20 ----D---- C:\totalcmd
2011-02-06 20:11:42 ----D---- C:\Program Files\Internet Explorer
2011-02-06 20:05:43 ----D---- C:\WINDOWS\system32\config
2011-02-06 20:05:25 ----D---- C:\WINDOWS\system32\wbem
2011-02-06 20:05:24 ----D---- C:\WINDOWS\Registration
2011-02-06 20:05:05 ----HD---- C:\Program Files\InstallShield Installation Information
2011-02-06 20:05:04 ----D---- C:\Program Files\Common Files\InstallShield
2011-02-06 20:04:33 ----D---- C:\WINDOWS\Media
2011-02-06 20:04:33 ----D---- C:\Program Files\Microsoft Office
2011-02-06 20:03:57 ----D---- C:\Program Files\VideoLAN
2011-02-06 19:47:07 ----SD---- C:\WINDOWS\Tasks
2011-02-06 19:47:07 ----HD---- C:\WINDOWS\inf
2011-02-06 19:37:38 ----D---- C:\Documents and Settings\František\Data aplikací\Vso
2011-02-06 19:16:25 ----D---- C:\WINDOWS\Debug
2011-02-06 19:16:23 ----D---- C:\WINDOWS\Minidump
2011-02-06 19:16:22 ----SHD---- C:\RECYCLER
2011-02-03 19:11:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-02-03 19:11:27 ----HD---- C:\WINDOWS\$hf_mig$
2011-02-01 20:53:19 ----D---- C:\WINDOWS\system32\cs-cz
2011-02-01 20:53:18 ----D---- C:\WINDOWS\Help
2011-02-01 20:39:45 ----D---- C:\Documents and Settings
2011-01-27 12:00:01 ----D---- C:\WINDOWS\system32\DirectX
2011-01-12 17:35:33 ----A---- C:\WINDOWS\system32\MRT.exe
2011-01-12 17:34:28 ----D---- C:\WINDOWS\system32\CatRoot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-19 691696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-01-13 29392]
R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [2002-07-17 16877]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-01-13 23632]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-01-13 294608]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-01-13 47440]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-01-13 17744]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-01-13 100176]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller; C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 38656]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-26 4395008]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2007-09-08 47360]
R3 Stmatm;ATM/ADSL miniport; C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-08-12 60255]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R4 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S3 a1ciy5oy;a1ciy5oy; C:\WINDOWS\system32\drivers\a1ciy5oy.sys []
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2006-05-29 8704]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2006-05-29 13312]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2006-05-29 127488]
S3 Nokia USB Port;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2006-05-29 13312]
S3 TaurusUsb;ADSL Modem USB Service; C:\WINDOWS\system32\DRIVERS\torususb.sys [2003-12-23 549421]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-09-04 241664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-10-23 382248]
R3 ServiceLayer;ServiceLayer; C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe [2006-06-05 174080]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-10-18 72704]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: pro vyosek

Napsal: 08 úno 2011 17:30
od vyosek
Zdravim a pekny vecer preji :)

:arrow: Podivejte se, jestli nejsou vetraky a vetraci pruduchy ucpane prachem - to by mohlo byt to mrznuti...

:arrow: Po jistotu tam pustime CFko jestli tam neni neco zazraneho :?:

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: pro vyosek

Napsal: 08 úno 2011 18:15
od michal_smsmsm
ComboFix 11-02-07.05 - František 08.02.2011 18:06:58.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1573 [GMT 1:00]
Spuštěný z: c:\documents and settings\František\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((( Soubory vytvořené od 2011-01-08 do 2011-02-08 )))))))))))))))))))))))))))))))
.

2011-02-08 16:29 . 2011-02-08 16:29 -------- d-----w- c:\program files\Common Files\Skype
2011-02-08 16:00 . 2011-02-08 16:00 -------- d-----w- c:\program files\trend micro
2011-02-08 16:00 . 2011-02-08 16:00 -------- d-----w- C:\rsit
2011-02-08 13:19 . 2011-02-08 13:19 -------- d-----w- c:\documents and settings\František\Data aplikací\Genie-Soft
2011-02-07 19:22 . 2011-02-07 19:22 -------- d-----w- c:\documents and settings\František\Data aplikací\Nero
2011-02-07 19:14 . 2011-02-07 19:14 -------- d-----w- c:\program files\Common Files\Nero
2011-02-07 19:14 . 2011-02-07 19:14 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Nero
2011-02-07 19:13 . 2011-02-07 19:13 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-02-07 19:13 . 2011-02-07 19:13 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2011-02-06 19:47 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-06 19:47 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-06 19:47 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-06 19:47 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-06 19:47 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-06 19:47 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-06 19:47 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-06 19:47 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-06 19:47 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\František\Data aplikací\Malwarebytes
2011-02-06 19:35 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-06 19:35 . 2011-02-08 07:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-06 19:35 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\František\Data aplikací\SUPERAntiSpyware.com
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2011-02-06 19:35 . 2011-02-08 15:52 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-02-06 19:05 . 2011-02-06 19:05 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-06 19:04 . 2011-02-06 19:04 -------- d-----w- c:\windows\ShellNew
2011-02-06 19:04 . 2011-02-06 19:04 -------- d-----w- c:\program files\Microsoft Silverlight
2011-02-06 19:04 . 2011-02-06 19:04 -------- d-----w- c:\windows\screensaver-800x600 dir
2011-02-06 19:03 . 2011-02-06 19:03 -------- d-----w- c:\program files\Windows Live Safety Center
2011-02-06 19:03 . 2011-02-06 19:04 -------- d-----w- c:\program files\DVDIdle Pro
2011-02-06 18:59 . 2011-02-08 14:46 -------- d-----w- c:\program files\CCleaner
2011-02-06 18:42 . 1999-04-14 12:09 550912 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\OMIPSTNT.DLL
2011-02-06 18:42 . 2000-05-15 10:32 540944 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\EXSEC32.DLL
2011-02-06 18:42 . 2000-01-11 07:33 65586 ----a-w- c:\windows\system32\OUTLWAB.DLL
2011-02-06 18:42 . 2000-05-15 10:33 368691 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\PSTPRX32.DLL
2011-02-06 18:42 . 1999-04-14 12:09 536576 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\OMINT.DLL
2011-02-06 18:26 . 2011-02-06 18:59 -------- d-----w- c:\program files\Passware
2011-02-03 18:05 . 2011-02-03 18:05 -------- d-sh--w- c:\documents and settings\František\PrivacIE
2011-02-01 19:53 . 2011-02-01 19:53 -------- d-sh--w- c:\documents and settings\František\IETldCache
2011-02-01 19:51 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-01 19:49 . 2010-11-06 00:23 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-01 19:49 . 2010-11-06 00:23 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-01 19:49 . 2010-11-06 00:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-01 19:47 . 2011-02-01 19:49 -------- dc-h--w- c:\windows\ie8
2011-02-01 19:39 . 2011-02-06 19:05 -------- d-----w- c:\documents and settings\Administrator
2011-01-27 12:32 . 2011-01-27 12:33 -------- d-----w- c:\documents and settings\František\Local Settings\Data aplikací\Temp
2011-01-27 12:32 . 2011-02-06 19:10 -------- d-----w- c:\documents and settings\František\Local Settings\Data aplikací\Google
2011-01-27 10:56 . 2011-01-27 10:57 83008360 ----a-w- c:\program files\Common Files\Windows Live\.cache\wlcB.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:15 . 2007-09-06 12:25 81920 ----a-w- c:\windows\system32\isign32.dll
2008-04-21 14:51 . 2008-04-21 14:50 60776535 ----a-w- c:\program files\Money_S3_11001_CZ.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 202024]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\61de6be9-295b-4216-94e3-383219ea8716.com" [2011-02-08 2424560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"nwiz"="nwiz.exe" [2006-08-11 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-08-11 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"AdslTaskBar"="stmctrl.dll" [2003-12-03 155648]
"DU Meter"="c:\du meter\DUMeter.exe" [2005-02-01 1469952]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Frantiçek\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\progra~1\DVDIDL~1\DVDShell.dll" [2004-10-09 49152]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\František\\Plocha\\bulanci.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.5.2010 13:20 691696]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6.2.2011 20:47 294608]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 19:41 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.2.2011 20:47 17744]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [6.9.2007 13:50 38656]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [8.9.2007 22:07 60255]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 19:25 12872]
S3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [8.9.2007 22:07 549421]

--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - WMIAPSRV
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q=
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: České slovníky pro kontrolu pravopisu: cs@dictionaries.addons.mozilla.org - %profile%\extensions\cs@dictionaries.addons.mozilla.org
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-08 18:10
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(752)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL

- - - - - - - > 'explorer.exe'(2528)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2011-02-08 18:11:28
ComboFix-quarantined-files.txt 2011-02-08 17:11

Před spuštěním: Volných bajtů: 85 851 856 896
Po spuštění: Volných bajtů: 86 627 213 312

Current=4 Default=4 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 1723F2D48C5CC03E5F31AB18276D589A

Re: pro vyosek

Napsal: 08 úno 2011 18:24
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "PcSync"=-
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"=-
    "NeroFilterCheck"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000000
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
    FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
    FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... r=1.1.7&q=
    FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: pro vyosek

Napsal: 08 úno 2011 18:54
od michal_smsmsm
Pocitac po resetu zapnout sel ;)

ComboFix 11-02-07.05 - František 08.02.2011 18:46:47.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1545 [GMT 1:00]
Spuštěný z: c:\documents and settings\František\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\František\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components\ITB_History.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\prefs.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\user.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome.manifest
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\about.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\about.xul
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\autocomplete.xml
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\exitobserver.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\globals.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\highlight.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtabs.css
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtabs.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtoolbar.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtoolbar.xul
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\bgLarge.gif
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\bgSmall.gif
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\buttonBlue.gif
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\buttonGreen.gif
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\searchLogo.gif
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\localfileupdate.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\menu-button.xml
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_bg.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_cz.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_de.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_en.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_es.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_fr.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_he.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_it.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_ru.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_sk.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_tr.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_uk.html
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\options.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\options.xul
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\parsegamesxml.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\parsemenuxml.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\peoplesearch.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\peoplesearch.xul
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\prefutils.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\search.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\splitter.xml
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\statistics.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\tabcontext.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\utilities.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\voucher.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\zoom.js
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\icq_locale.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\itb.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\itb_options.dtd
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\options.properties
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\about.css
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\abt.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\ain.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\ang.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\default.css
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\dis.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\dropmarker.css
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\hide.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\icons.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\logo_small.gif
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\more_vouchers_r.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\more_vouchers_y.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\options.css
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\peoplesearch.css
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\voucher_bg.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\voucher_bg_y.png
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\install.rdf
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\manifest.mf
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.rsa
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.sf
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.gif
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.src
c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.xml
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components\ITB_History.js
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\prefs.js
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\user.js
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\icqtoolbar.jar
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\install.rdf
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\manifest.mf
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.rsa
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.sf
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.gif
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.src
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.xml

.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-08 do 2011-02-08 )))))))))))))))))))))))))))))))
.

2011-02-08 16:29 . 2011-02-08 16:29 -------- d-----w- c:\program files\Common Files\Skype
2011-02-08 16:00 . 2011-02-08 16:00 -------- d-----w- c:\program files\trend micro
2011-02-08 16:00 . 2011-02-08 16:00 -------- d-----w- C:\rsit
2011-02-08 13:19 . 2011-02-08 13:19 -------- d-----w- c:\documents and settings\František\Data aplikací\Genie-Soft
2011-02-07 19:22 . 2011-02-07 19:22 -------- d-----w- c:\documents and settings\František\Data aplikací\Nero
2011-02-07 19:14 . 2011-02-07 19:14 -------- d-----w- c:\program files\Common Files\Nero
2011-02-07 19:14 . 2011-02-07 19:14 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Nero
2011-02-07 19:13 . 2011-02-07 19:13 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-02-07 19:13 . 2011-02-07 19:13 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2011-02-06 19:47 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-06 19:47 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-06 19:47 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-06 19:47 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-06 19:47 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-06 19:47 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-06 19:47 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-06 19:47 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-06 19:47 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\František\Data aplikací\Malwarebytes
2011-02-06 19:35 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-06 19:35 . 2011-02-08 07:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-06 19:35 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\František\Data aplikací\SUPERAntiSpyware.com
2011-02-06 19:35 . 2011-02-06 19:35 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2011-02-06 19:35 . 2011-02-08 15:52 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-02-06 19:05 . 2011-02-06 19:05 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-06 19:04 . 2011-02-06 19:04 -------- d-----w- c:\windows\ShellNew
2011-02-06 19:04 . 2011-02-06 19:04 -------- d-----w- c:\program files\Microsoft Silverlight
2011-02-06 19:04 . 2011-02-06 19:04 -------- d-----w- c:\windows\screensaver-800x600 dir
2011-02-06 19:03 . 2011-02-06 19:03 -------- d-----w- c:\program files\Windows Live Safety Center
2011-02-06 19:03 . 2011-02-06 19:04 -------- d-----w- c:\program files\DVDIdle Pro
2011-02-06 18:59 . 2011-02-08 14:46 -------- d-----w- c:\program files\CCleaner
2011-02-06 18:42 . 1999-04-14 12:09 550912 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\OMIPSTNT.DLL
2011-02-06 18:42 . 2000-05-15 10:32 540944 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\EXSEC32.DLL
2011-02-06 18:42 . 2000-01-11 07:33 65586 ----a-w- c:\windows\system32\OUTLWAB.DLL
2011-02-06 18:42 . 2000-05-15 10:33 368691 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\PSTPRX32.DLL
2011-02-06 18:42 . 1999-04-14 12:09 536576 ----a-w- c:\program files\Common Files\System\Mapi\1029\NT\OMINT.DLL
2011-02-06 18:26 . 2011-02-06 18:59 -------- d-----w- c:\program files\Passware
2011-02-03 18:05 . 2011-02-03 18:05 -------- d-sh--w- c:\documents and settings\František\PrivacIE
2011-02-01 19:53 . 2011-02-01 19:53 -------- d-sh--w- c:\documents and settings\František\IETldCache
2011-02-01 19:51 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-02-01 19:49 . 2010-11-06 00:23 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-02-01 19:49 . 2010-11-06 00:23 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-01 19:49 . 2010-11-06 00:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-01 19:47 . 2011-02-01 19:49 -------- dc-h--w- c:\windows\ie8
2011-02-01 19:39 . 2011-02-06 19:05 -------- d-----w- c:\documents and settings\Administrator
2011-01-27 12:32 . 2011-01-27 12:33 -------- d-----w- c:\documents and settings\František\Local Settings\Data aplikací\Temp
2011-01-27 12:32 . 2011-02-06 19:10 -------- d-----w- c:\documents and settings\František\Local Settings\Data aplikací\Google
2011-01-27 10:56 . 2011-01-27 10:57 83008360 ----a-w- c:\program files\Common Files\Windows Live\.cache\wlcB.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:15 . 2007-09-06 12:25 81920 ----a-w- c:\windows\system32\isign32.dll
2008-04-21 14:51 . 2008-04-21 14:50 60776535 ----a-w- c:\program files\Money_S3_11001_CZ.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\61de6be9-295b-4216-94e3-383219ea8716.com" [2011-02-08 2424560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"nwiz"="nwiz.exe" [2006-08-11 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-08-11 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"AdslTaskBar"="stmctrl.dll" [2003-12-03 155648]
"DU Meter"="c:\du meter\DUMeter.exe" [2005-02-01 1469952]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Frantiçek\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\progra~1\DVDIDL~1\DVDShell.dll" [2004-10-09 49152]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\František\\Plocha\\bulanci.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.5.2010 13:20 691696]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6.2.2011 20:47 294608]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 19:41 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.2.2011 20:47 17744]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [6.9.2007 13:50 38656]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [8.9.2007 22:07 60255]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 19:25 12872]
S3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [8.9.2007 22:07 549421]

--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - WMIAPSRV
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\František\Data aplikací\Mozilla\Firefox\Profiles\vhmlz5m1.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q=
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: České slovníky pro kontrolu pravopisu: cs@dictionaries.addons.mozilla.org - %profile%\extensions\cs@dictionaries.addons.mozilla.org
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-08 18:48
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(752)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Celkový čas: 2011-02-08 18:49:47
ComboFix-quarantined-files.txt 2011-02-08 17:49
ComboFix2.txt 2011-02-08 17:11

Před spuštěním: Volných bajtů: 86 530 101 248
Po spuštění: Volných bajtů: 86 510 903 296

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=4 Default=4 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - C2B949FE9483AB4592F6A52505363EB7

Re: pro vyosek

Napsal: 08 úno 2011 19:01
od vyosek
:arrow: Log vypada cisty

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /Uninstall
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC
:arrow: Dival jste se na ty vetraky a prach :???:

Re: pro vyosek

Napsal: 08 úno 2011 19:43
od michal_smsmsm
HW zalezitosti jsem si nechaval naposled ;) ty dve utitilky jsem spustil... Prachu jsem ted vysal hromady, tak uvidime, alespon mohu byt klidny, ze po SW strance je vse OK ;) Diky moc za pomoc ;) Preji pekny zbytek vecera.

Re: pro vyosek

Napsal: 08 úno 2011 21:40
od vyosek
Nemate zac, rad jsem opet pomohl :) Pak napiste jestli to vycisteni od prachu pomohlo :wink:

Re: pro vyosek

Napsal: 12 úno 2011 12:21
od michal_smsmsm
Vyfoukani prachu nepomohlo :-( Mam podezreni na antivirak... Pouziva se tu avast free antivir, radne aktualizovany. Pokud zakazu rezidentni ochranu antiviru system bezi bez vypinani. Pokud ochranu povolim, je vice nez pravdepodobne ze se system po resetu, nebo vypnuti/zapnuti kousne... Skoro mi to pripada, jako kdyz by bylo neco v tech souborech ktere antivir prohledava po startu a tam ze se to kousne... Pro porovnani zkousim prave instalovat nod32 se kterym mam vice nez dobre zkusenosti a uvidme jak se bude pc chovat s nim... Nejak mi dosly napady...

Re: pro vyosek

Napsal: 12 úno 2011 12:41
od vyosek
NOD je na 30 dni trial, ale muzete zkust jeste Aviru - ta je anglicky, nebo MSE od Microfostu - ten je CZ. Oba jsou zadarmo :wink:

Re: pro vyosek

Napsal: 12 úno 2011 12:51
od michal_smsmsm
jj 30 dni trial... za tech 30 dni se to urcite kousne ;-) nebo pokud se nekousne tak se za 1200 koupi to neni naprosto problem... hlavne aby to slapalo ;-) ta avira na tu jsem slysel dobre rezence, kdyz tak ji take zkusim, diky...

Re: pro vyosek

Napsal: 12 úno 2011 17:07
od vyosek
Ja osobne bych NOD nekupoval, pokud jiz chcete do zabezpeceni investovat, tak koupit balicek NIS ci KIS :wink:

Re: pro vyosek

Napsal: 14 úno 2011 08:57
od michal_smsmsm
Oki, ja dam na vase rady, hlavne aby to jelo ;-) Jako vždy, děkuji moc za pomoc a cenné informace. Chvála těm, kteří umí ;-)

Re: pro vyosek

Napsal: 14 úno 2011 10:50
od vyosek
Nemate zac, rad jsem pomohl :)