Stránka 1 z 2

Neodůvodněný zvuk

Napsal: 27 úno 2011 11:43
od hoskinson
Každých cca 5 s se ozývá zvuk-loupnutí (podobný jako když v některých programech najedete myší na tlačítko).Možná s tím má spojitost i to,že ve Spybotu mi nejdou imunizovat 3 cookies v Opeře.

...takže prosím o kontrolu logu...


Logfile of random's system information tool 1.08 (written by random/random)
Run by me at 2011-02-27 11:37:21
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 212 GB (89%) free of 238 GB
Total RAM: 1023 MB (28% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:37:51, on 27.2.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\ASUS\ASUS Remote\RemoteControlAppl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\QIP\qip.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MemInfo\meminfo.exe
C:\Program Files\HDD Health\hddhealth.exe
C:\Program Files\NetMeter\netmeter.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\oodag.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\OO Software\DiskImage\oodiag.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\INTERN~2\IDMan.exe
C:\Program Files\INTERN~2\IEMonitor.exe
C:\RAR\RSIT.exe
C:\Program Files\trend micro\me.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\INTERN~2\IDMIECC.dll
O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O3 - Toolbar: (no name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - (no file)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O4 - HKLM\..\Run: [RemoteControl] C:\Program Files\ASUS\ASUS Remote\RemoteControlAppl.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MemInfo] C:\Program Files\MemInfo\meminfo.exe
O4 - HKCU\..\Run: [hddhealth] C:\Program Files\HDD Health\hddhealth.exe
O4 - HKCU\..\Run: [netmeter] C:\Program Files\NetMeter\netmeter.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O8 - Extra context menu item: Download with Rapget - C:\Program Files\RapGet141\rapget.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\INTERN~2\IEExt.htm
O8 - Extra context menu item: Stáhnout s IDM obsah FLV videa - C:\Program Files\INTERN~2\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM všechny odkazy - C:\Program Files\INTERN~2\IEGetAll.htm
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DCMessages - Global Graphics Software Ltd - C:\WINDOWS\system32\DCMessages.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MySql - Unknown owner - C:/apache/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: O&O DiskImage - Unknown owner - C:\Program Files\OO Software\DiskImage\oodiag.exe
O23 - Service: PHPGeekUtil - Unknown owner - c:\apache\APACHE.EXE (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe

--
End of file - 10029 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Automatic maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{9939AAA9-05AB-4E61-9A8A-47454B7610D1}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\INTERN~2\IDMIECC.dll [2009-04-27 169392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}]
QuickStores-Toolbar - C:\WINDOWS\system32\mscoree.dll [2009-11-07 297808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\WINDOWS\WebIE.dll [2009-11-28 491520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll [2010-01-20 378736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL [2010-01-20 107896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-30 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\WINDOWS\WebIE.dll [2009-11-28 491520]
{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - QuickStores-Toolbar - C:\WINDOWS\system32\mscoree.dll [2009-11-07 297808]
{B922D405-6D13-4A2B-AE89-08A030DA4402}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll [2010-01-20 378736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"=C:\Program Files\ASUS\ASUS Remote\RemoteControlAppl.exe [2006-02-14 69632]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"QIP2005"=C:\Program Files\QIP\qip.exe [2009-08-13 3276288]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MemInfo"=C:\Program Files\MemInfo\meminfo.exe [2005-12-13 628224]
"hddhealth"=C:\Program Files\HDD Health\hddhealth.exe [2008-06-15 1692672]
"netmeter"=C:\Program Files\NetMeter\netmeter.exe [2007-08-11 331264]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
WDDMStatus.lnk - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-02-27 11:37:25 ----D---- C:\Program Files\trend micro
2011-02-27 11:37:21 ----D---- C:\rsit
2011-02-20 09:54:21 ----D---- C:\Program Files\Sony Ericsson
2011-02-20 09:54:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson
2011-02-15 20:51:28 ----D---- C:\RLTMP
2011-02-14 20:42:26 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2011-02-14 20:42:14 ----D---- C:\Program Files\DAEMON Tools Lite
2011-02-14 20:39:36 ----D---- C:\Documents and Settings\me\Data aplikací\DAEMON Tools Lite
2011-02-14 20:39:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2011-02-13 13:34:55 ----RD---- C:\Program Files\Norton Support
2011-02-13 09:42:26 ----RASH---- C:\WINDOWS\system32\nbDX.dll
2011-02-13 09:42:26 ----RASH---- C:\WINDOWS\system32\msfDX.dll
2011-02-13 09:42:25 ----RASH---- C:\WINDOWS\system32\flvDX.dll
2011-02-13 09:40:26 ----D---- C:\Program Files\eRightSoft
2011-02-11 17:37:07 ----A---- C:\WINDOWS\system32\drivers\SCRCAMHRDRV.sys
2011-02-11 17:37:06 ----D---- C:\Program Files\ScreenCamera
2011-02-10 20:39:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-02-10 20:38:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2485376$
2011-02-10 20:38:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2479628$
2011-02-10 20:38:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-02-10 20:34:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2476687$
2011-02-10 20:34:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-02-10 20:34:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-02-05 20:42:17 ----RA---- C:\WINDOWS\system32\drivers\SymIM.sys
2011-02-05 20:42:13 ----D---- C:\Program Files\Symantec
2011-02-05 20:42:13 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-02-05 20:42:13 ----A---- C:\WINDOWS\system32\S32EVNT1.DLL
2011-02-05 20:42:13 ----A---- C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2011-02-05 20:41:43 ----D---- C:\WINDOWS\system32\drivers\NIS
2011-02-05 20:41:41 ----D---- C:\Program Files\Windows Sidebar
2011-02-05 20:41:41 ----D---- C:\Program Files\Norton Internet Security
2011-02-05 20:41:19 ----D---- C:\Program Files\NortonInstaller
2011-02-04 17:14:07 ----D---- C:\Program Files\Passware

======List of files/folders modified in the last 1 months======

2011-02-27 11:37:29 ----D---- C:\WINDOWS\Prefetch
2011-02-27 11:37:25 ----RD---- C:\Program Files
2011-02-27 11:37:24 ----D---- C:\WINDOWS\Temp
2011-02-27 11:37:15 ----D---- C:\RAR
2011-02-27 11:37:11 ----D---- C:\Documents and Settings\me\Data aplikací\IDM
2011-02-27 11:37:10 ----D---- C:\Documents and Settings\me\Data aplikací\DMCache
2011-02-27 10:38:10 ----D---- C:\WINDOWS\system32\drivers\etc
2011-02-27 10:36:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-02-27 07:55:05 ----A---- C:\WINDOWS\NeroDigital.ini
2011-02-27 07:51:38 ----D---- C:\WINDOWS
2011-02-26 18:57:48 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-02-26 09:54:56 ----A---- C:\WINDOWS\Altair.INI
2011-02-22 20:32:23 ----D---- C:\WINDOWS\system32\Restore
2011-02-22 18:21:38 ----D---- C:\WINDOWS\Microsoft.NET
2011-02-22 18:21:37 ----RSD---- C:\WINDOWS\assembly
2011-02-22 18:21:14 ----SHD---- C:\WINDOWS\Installer
2011-02-22 18:20:00 ----D---- C:\Program Files\Microsoft SQL Server
2011-02-22 18:17:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-02-22 18:08:53 ----D---- C:\WINDOWS\system32
2011-02-22 18:08:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-02-22 18:02:08 ----D---- C:\WINDOWS\Registration
2011-02-21 21:24:41 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2011-02-20 10:47:03 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-20 09:56:06 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-02-20 09:56:06 ----AD---- C:\WINDOWS\inf
2011-02-20 09:54:21 ----HD---- C:\Program Files\InstallShield Installation Information
2011-02-16 16:57:56 ----D---- C:\Program Files\Microsoft Silverlight
2011-02-15 21:26:06 ----D---- C:\WINDOWS\Debug
2011-02-15 21:23:04 ----D---- C:\WINDOWS\system32\drivers
2011-02-15 21:05:50 ----D---- C:\Program Files\Ashampoo
2011-02-15 20:57:20 ----SD---- C:\WINDOWS\Tasks
2011-02-15 20:53:12 ----D---- C:\Program Files\Common Files
2011-02-15 20:49:35 ----D---- C:\Documents and Settings\me\Data aplikací\phpDesigner
2011-02-13 09:42:34 ----RSD---- C:\WINDOWS\Fonts
2011-02-11 17:42:37 ----A---- C:\WINDOWS\win.ini
2011-02-11 17:37:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-02-10 20:35:16 ----A---- C:\WINDOWS\system32\MRT.exe
2011-02-10 20:35:03 ----D---- C:\Program Files\Internet Explorer
2011-02-10 20:34:47 ----HD---- C:\WINDOWS\$hf_mig$
2011-02-06 19:12:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2011-02-06 18:29:34 ----D---- C:\Program Files\SopCast
2011-02-05 20:44:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2011-02-05 20:42:25 ----SHD---- C:\System Volume Information
2011-02-05 15:45:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Team MediaPortal
2011-02-04 17:26:53 ----D---- C:\Documents and Settings\me\Data aplikací\FileZilla
2011-02-04 17:24:38 ----D---- C:\Program Files\bet-at-home.com Poker
2011-01-29 19:46:59 ----A---- C:\WINDOWS\WDICT32.INI
2011-01-28 17:54:24 ----D---- C:\Program Files\Opera

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 oodisr;O&O DiskImage Snapshot/Restore Driver; C:\WINDOWS\system32\DRIVERS\oodisr.sys [2009-10-24 96336]
R0 oodisrh;oodisrh; C:\WINDOWS\system32\DRIVERS\oodisrh.sys [2009-10-24 28752]
R0 oodivd;O&O DiskImage Virtual Devices Driver; C:\WINDOWS\system32\DRIVERS\oodivd.sys [2009-10-24 166992]
R0 oodivdh;oodivdh; C:\WINDOWS\system32\DRIVERS\oodivdh.sys [2009-10-24 31312]
R0 SymEFA;Symantec Extended File Attributes; C:\WINDOWS\system32\drivers\NIS\1008000.029\SYMEFA.SYS [2010-01-20 310320]
R1 bbcap;bbcap; C:\WINDOWS\system32\DRIVERS\bbcap.sys [2009-11-29 2944]
R1 BHDrvx86;Symantec Heuristics Driver; C:\WINDOWS\System32\Drivers\NIS\1008000.029\BHDrvx86.sys [2010-01-20 259632]
R1 ccHP;Symantec Hash Provider; C:\WINDOWS\System32\Drivers\NIS\1008000.029\ccHPx86.sys [2011-02-06 482432]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-02-14 218688]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 IDSxpx86;IDSxpx86; \??\C:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20110224.001\IDSxpx86.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\WINDOWS\system32\drivers\NIS\1008000.029\SRTSPX.SYS [2010-01-20 43696]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMTDI.SYS [2010-01-20 217136]
R2 dvdmmg;dvdmmg; \??\C:\WINDOWS\system32\drivers\dvdmmg.sys []
R2 SCRCAMHRDRV;ScreenCamera HR; C:\WINDOWS\system32\DRIVERS\SCRCAMHRDRV.sys [2010-11-15 232640]
R3 3xHybrid;3xHybrid service; C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-02-14 2825088]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 NAVENG;NAVENG; \??\C:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110224.038\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\Documents and Settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110224.038\NAVEX15.SYS []
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-05-28 47360]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2004-02-24 10368]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2005-08-11 393088]
R3 SRTSP;Symantec Real Time Storage Protection; C:\WINDOWS\System32\Drivers\NIS\1008000.029\SRTSP.SYS [2010-01-20 308272]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMFW;Symantec Network Filter Driver; C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMFW.SYS [2010-01-20 89904]
R3 SYMIDS;Symantec Network Filter Driver; C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMIDS.SYS [2010-01-20 33072]
R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2010-01-20 36400]
R3 SYMNDIS;Symantec Network Filter Driver; C:\WINDOWS\System32\Drivers\NIS\1008000.029\SYMNDIS.SYS [2010-01-20 36400]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2005-03-30 230400]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\me\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 epmntdrv;epmntdrv; \??\C:\WINDOWS\system32\epmntdrv.sys []
S3 EuGdiDrv;EuGdiDrv; \??\C:\WINDOWS\system32\EuGdiDrv.sys []
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2005-02-11 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys [2005-02-11 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2005-02-11 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys [2005-02-11 79488]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-07-09 15104]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NANMp50;NANMp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\NANMp50.sys []
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 pbfilter;pbfilter; \??\C:\Program Files\Peerblock\pbfilter.sys []
S3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2009-11-26 34384]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2007-05-02 10222720]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 SYMDNS;SYMDNS; \??\C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMDNS.SYS []
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2010-01-20 36400]
S3 SYMREDRV;SYMREDRV; \??\C:\WINDOWS\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS []
S3 TfBulk;TfBulk; C:\WINDOWS\system32\DRIVERS\TfBulk.sys [2007-05-31 13312]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1); C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys [2010-11-26 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2); C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys [2010-11-26 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3); C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys [2010-11-26 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4); C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys [2010-11-26 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5); C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys [2010-11-26 25704]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-12-03 717296]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-10-22 386560]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 Norton Internet Security;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2010-01-20 117640]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2007-05-11 1050120]
R2 O&O DiskImage;O&O DiskImage; C:\Program Files\OO Software\DiskImage\oodiag.exe [2009-10-24 2311496]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WDDMService;WD SmartWare Drive Manager; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-10-14 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service; C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-12-24 136176]
S2 MySql;MySql; C:/apache/mysql/bin/mysqld-nt.exe []
S2 PHPGeekUtil;PHPGeekUtil; c:\apache\APACHE.EXE --ntservice []
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
S2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DCMessages;DCMessages; C:\WINDOWS\system32\DCMessages.exe [2009-11-24 99720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe -d -f C:\Program Files\WinPcap\rpcapd.ini []
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2010-10-26 155344]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2009-11-28 435016]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 12:23
od Rudy
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 13:53
od hoskinson
...log MBAM :


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 5891

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

27.2.2011 13:51:23
mbam-log-2011-02-27 (13-51-11).txt

Typ kontroly: Úplný test (C:\|)
Testované objekty: 294752
Uplynulý čas: 55 minut, 16 sekund

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče v registru: 4
Infikované hodnoty v registru: 2
Infikované datové položky v registru: 1
Infikované složky: 0
Infikované soubory: 7

Infikované procesy v paměti:
c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> 1572 -> No action taken.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Application Updater (PUP.Dealio) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\APPLICATION UPDATER\APPLICATIONUPDATER.EXE (PUP.Dealio) -> Value: APPLICATIONUPDATER.EXE -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> No action taken.

Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> No action taken.
c:\documents and settings\me\local settings\temp\7zOAF.tmp\1box_ntr3.6a.exe (Backdoor.Agent) -> No action taken.
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\dvbviewer pro\compatibility\compatibility.exe (Trojan.Dropper) -> No action taken.
c:\program files\website x5 v8 - evolution\Stubs\82f719148bc885b56fde9d3cad72e583dd4dbf\impreview.exe (Trojan.Backdoor) -> No action taken.
c:\program files\website x5 v8 - evolution\Stubs\8fa19e28495abbbfdf801c6d96c3788489d04eda\acrord32info.exe (Trojan.Backdoor) -> No action taken.
c:\program files\oo software\oo_defrag_10_pro_v10.0.1634\oo defrag 10 keygen.exe (RiskWare.Tool.CK) -> No action taken.

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 19:01
od Rudy
Všechny nalezené položky smažte.

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 19:09
od hoskinson
...log po výmazu:


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 5891

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

27.2.2011 19:07:44
mbam-log-2011-02-27 (19-07-44).txt

Typ kontroly: Úplný test (C:\|)
Testované objekty: 294752
Uplynulý čas: 55 minut, 16 sekund

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče v registru: 4
Infikované hodnoty v registru: 2
Infikované datové položky v registru: 1
Infikované složky: 0
Infikované soubory: 7

Infikované procesy v paměti:
c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> 1572 -> Unloaded process successfully.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Application Updater (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\APPLICATION UPDATER\APPLICATIONUPDATER.EXE (PUP.Dealio) -> Value: APPLICATIONUPDATER.EXE -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.

Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\program files\application updater\applicationupdater.exe (PUP.Dealio) -> Quarantined and deleted successfully.
c:\documents and settings\me\local settings\temp\7zOAF.tmp\1box_ntr3.6a.exe (Backdoor.Agent) -> Quarantined and deleted successfully.
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\program files\dvbviewer pro\compatibility\compatibility.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\program files\website x5 v8 - evolution\Stubs\82f719148bc885b56fde9d3cad72e583dd4dbf\impreview.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\program files\website x5 v8 - evolution\Stubs\8fa19e28495abbbfdf801c6d96c3788489d04eda\acrord32info.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
c:\program files\oo software\oo_defrag_10_pro_v10.0.1634\oo defrag 10 keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 19:15
od Rudy
Smazáno. Restartujte PC a sdělte, zda se něco změnilo.

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 19:16
od hoskinson
...restartováno...zvuk stále přítomen... :all_coholic:

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 19:22
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 19:47
od hoskinson
...Combo log :



ComboFix 11-02-26.02 - me 27.02.2011 19:27:28.12.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.376 [GMT 1:00]
Spuštěný z: c:\rar\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\My.ini
c:\windows\system32\ActNAV_cltDynam.dat

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Legacy_SSHNAS


((((((((((((((((((((((((( Soubory vytvořené od 2011-01-27 do 2011-02-27 )))))))))))))))))))))))))))))))
.

2011-02-27 11:50 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-27 11:50 . 2011-02-27 11:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-27 11:50 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-27 10:37 . 2011-02-27 10:37 -------- d-----w- c:\program files\trend micro
2011-02-27 10:37 . 2011-02-27 10:39 -------- d-----w- C:\rsit
2011-02-27 06:24 . 2011-02-27 06:24 1409 ----a-w- c:\windows\QTFont.for
2011-02-20 08:54 . 2011-02-20 08:54 -------- d-----w- c:\program files\Sony Ericsson
2011-02-20 08:54 . 2011-02-20 08:54 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Sony Ericsson
2011-02-15 20:42 . 2011-02-15 20:42 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2011-02-15 20:13 . 2011-02-15 20:13 -------- d-----w- c:\documents and settings\me\Local Settings\Data aplikací\WMTools Downloaded Files
2011-02-15 19:51 . 2011-02-15 19:52 -------- d-----w- C:\RLTMP
2011-02-14 19:42 . 2011-02-14 19:42 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-02-14 19:42 . 2011-02-14 19:42 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-02-14 19:39 . 2011-02-14 19:43 -------- d-----w- c:\documents and settings\me\Data aplikací\DAEMON Tools Lite
2011-02-14 19:39 . 2011-02-14 19:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DAEMON Tools Lite
2011-02-13 12:34 . 2011-02-13 12:34 -------- d-----r- c:\program files\Norton Support
2011-02-13 08:40 . 2011-02-13 08:40 -------- d-----w- c:\program files\eRightSoft
2011-02-11 16:37 . 2011-02-05 07:50 53248 ----a-w- c:\windows\system32\BSwitch.ax
2011-02-11 16:37 . 2011-02-03 14:34 364544 ----a-w- c:\windows\system32\prScrCamFXControls.ocx
2011-02-11 16:37 . 2010-11-15 06:17 232640 ----a-w- c:\windows\system32\drivers\SCRCAMHRDRV.sys
2011-02-11 16:37 . 2011-02-11 16:44 -------- d-----w- c:\program files\ScreenCamera
2011-02-05 19:42 . 2010-01-20 21:03 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2011-02-05 19:42 . 2011-02-06 18:13 -------- d-----w- c:\program files\Symantec
2011-02-05 19:42 . 2011-02-06 18:13 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-05 19:42 . 2011-02-06 18:13 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-05 19:42 . 2011-02-05 19:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-02-05 19:41 . 2011-02-06 18:38 -------- d-----w- c:\windows\system32\drivers\NIS
2011-02-05 19:41 . 2011-02-05 19:41 -------- d-----w- c:\program files\Norton Internet Security
2011-02-05 19:41 . 2011-02-05 19:41 -------- d-----w- c:\program files\Windows Sidebar
2011-02-05 19:41 . 2011-02-05 19:41 -------- d-----w- c:\program files\NortonInstaller
2011-02-04 16:14 . 2011-02-04 16:14 -------- d-----w- c:\program files\Passware
2011-01-30 13:57 . 2011-01-30 13:57 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-01-30 13:57 . 2011-01-30 13:57 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2004-08-18 12:00 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-18 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2004-08-18 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-18 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-22 05:36 . 2011-01-01 11:11 73728 ----a-w- c:\windows\system32\TOverlay.ax
2010-12-20 23:52 . 2004-08-18 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2004-08-18 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:52 . 2004-08-18 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:25 . 2004-08-18 12:00 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-08-18 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-12-10 17:29 . 2010-12-10 17:29 64864 ----a-w- c:\windows\system32\sqlctr90.dll
2010-12-10 17:29 . 2010-12-10 17:29 2248032 ----a-w- c:\windows\system32\sqlncli.dll
2010-12-09 15:15 . 2004-08-18 12:00 713216 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2004-08-18 12:00 2194944 ------w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2004-08-17 15:45 2071552 ------w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2004-08-18 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2006-05-03 10:06 163328 --sha-r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 31232 --sha-r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 216064 --sha-r- c:\windows\system32\nbDX.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OODIIcon]
@="{14A94384-BBED-47ed-86C0-6BF63FD892D0}"
[HKEY_CLASSES_ROOT\CLSID\{14A94384-BBED-47ed-86C0-6BF63FD892D0}]
2009-10-24 01:35 111944 ----a-w- c:\program files\OO Software\DiskImage\oodishi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QIP2005"="c:\program files\QIP\qip.exe" [2009-08-13 3276288]
"MemInfo"="c:\program files\MemInfo\meminfo.exe" [2005-12-13 628224]
"hddhealth"="c:\program files\HDD Health\hddhealth.exe" [2008-06-15 1692672]
"netmeter"="c:\program files\NetMeter\netmeter.exe" [2007-08-11 331264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2006-02-14 69632]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-10-14 2049344]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" silent
"OEXPRESS"=c:\windows\OETRN.EXE
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"Boxoft Tools"="c:\documents and settings\All Users\Data aplikací\Boxtools\Boxofttoolbox.exe" -autorun
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"High Definition Audio Property Page Shortcut"=HDAShCut.exe
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"OODefragTray"=c:\windows\system32\oodtray.exe
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
"SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"tsnpstd3"=c:\windows\tsnpstd3.exe
"DocCreatorClient"="c:\program files\Global Graphics\gDoc\DocCreatorClient.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe"
"OODITRAY.EXE"=c:\program files\OO Software\DiskImage\OODITRAY.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 oodisr;O&O DiskImage Snapshot/Restore Driver;c:\windows\system32\drivers\oodisr.sys [24.10.2009 2:38 96336]
R0 oodisrh;oodisrh;c:\windows\system32\drivers\oodisrh.sys [24.10.2009 2:38 28752]
R0 oodivd;O&O DiskImage Virtual Devices Driver;c:\windows\system32\drivers\oodivd.sys [24.10.2009 2:38 166992]
R0 oodivdh;oodivdh;c:\windows\system32\drivers\oodivdh.sys [24.10.2009 2:38 31312]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [6.2.2011 19:13 310320]
R1 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [29.11.2009 21:33 2944]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [6.2.2011 19:13 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [6.2.2011 19:13 482432]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [14.2.2011 20:42 218688]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20110224.001\IDSXpx86.sys [25.2.2011 17:05 341944]
R2 dvdmmg;dvdmmg;c:\windows\system32\drivers\dvdmmg.sys [6.9.2007 12:15 5504]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [6.2.2011 19:13 117640]
R2 O&O DiskImage;O&O DiskImage;c:\program files\OO Software\DiskImage\oodiag.exe [24.10.2009 2:34 2311496]
R2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\drivers\SCRCAMHRDRV.sys [11.2.2011 17:37 232640]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [14.10.2009 14:31 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16.6.2009 9:58 20480]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [5.4.2010 22:32 2825088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5.2.2011 3:20 102448]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24.12.2010 19:02 136176]
S2 PHPGeekUtil;PHPGeekUtil;"c:\apache\APACHE.EXE" --ntservice --> c:\apache\APACHE.EXE [?]
S3 cpuz130;cpuz130;\??\c:\docume~1\me\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\me\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 DCMessages;DCMessages;c:\windows\system32\DCMessages.exe [18.1.2010 19:49 99720]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [5.7.2010 8:56 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [5.7.2010 8:56 8456]
S3 NANMp50;NANMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NANMp50.sys --> c:\windows\system32\Drivers\NANMp50.sys [?]
S3 pbfilter;pbfilter;\??\c:\program files\Peerblock\pbfilter.sys --> c:\program files\Peerblock\pbfilter.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [26.11.2009 0:06 34384]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [20.2.2011 9:54 155344]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 12:37 517096]
S3 TfBulk;TfBulk;c:\windows\system32\drivers\TfBulk.SYS [31.5.2007 21:11 13312]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [17.12.2009 16:25 11520]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [30.11.2010 17:18 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [30.11.2010 17:19 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [30.11.2010 17:19 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [30.11.2010 17:19 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [30.11.2010 17:19 25704]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3.12.2009 21:06 717296]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2011-02-25 c:\windows\Tasks\Automatic maintenance.job
- c:\program files\TuneUp Utilities 2010\OneClickStarter.exe [2009-10-29 19:46]

2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 18:02]

2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 18:02]

2011-02-27 c:\windows\Tasks\User_Feed_Synchronization-{9939AAA9-05AB-4E61-9A8A-47454B7610D1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with Rapget - c:\program files\RapGet141\rapget.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files\INTERN~2\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files\INTERN~2\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files\INTERN~2\IEGetAll.htm
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
FF - ProfilePath - c:\documents and settings\me\Data aplikací\Mozilla\Firefox\Profiles\3klt4bnl.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=302398&p=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-27 19:38
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600

CreateFile("\\.\PHYSICALDRIVE0"): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/apache/mysql/bin/mysqld-nt.exe"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/apache/mysql/bin/mysqld-nt.exe"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,64,da,19,6c,0e,a7,40,4a,af,a8,de,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,64,da,19,6c,0e,a7,40,4a,af,a8,de,\

[HKEY_USERS\S-1-5-21-1606980848-57989841-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1606980848-57989841-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:fc,0f,c9,04,0e,9a,f3,1c,e1,06,d2,2a,a6,3f,a2,34,64,a9,a0,e2,b9,
64,ec,76,a0,57,48,83,25,a4,0b,9d,7e,09,ba,c0,0a,2e,7e,41,72,df,e3,31,8d,09,\
"rkeysecu"=hex:e2,1b,b7,3f,00,5e,55,69,b2,f9,ae,20,85,d6,52,c6

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{34601407-0fc7-456d-92b4-ed0fa73d6695}]
@Denied: (Full) (Everyone)
"Model"=dword:00000118
"Therad"=dword:00000020
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8c,e3,09,fa,be,f5,5e,41,b6,d2,68,f5,c4,9a,19,89,a2,3d,ab,14,80,
8a,40,b1,b5,26,8d,9b,68,4e,67,c4,e0,a0,86,cb,24,ee,18,8b,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="38D140A9C8AA2DD0A9B3839FED7894F6A768EFF07D5F3B942D0054CD2522FA393796A30010953ED4E27A0D380E36D63319A016A1CB7C6832CFE85949938D675858B4BE5FAC359C34BCC6513637B4C78CAD7DA39FAE5EC15F05523E12E301BD34CE3127A79DA68FBD6B9A705E3B1F0746BC9DDCB5685CDE7564151196E7A12FDA93C0D50C697C7E53E8A86CC76E93D8B8DDD1700240C27BE0C7C0C719788691EB6252A81498BAF8EBF1DA2BE12BA5224E711FEAF58051F820CE1839B171BEDC1EBA03E09C365EB09087CC78EA4F5CEE8618C0C15678BCD84A5C90A3C831CB2FB8E0A7A3D4D454FB61EFCE00F73CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A6171C11EC38DE3DFEBC9E127BECC74C3B060D50980065913945AF4169ABFAC48E096D6F9E618E3074F761E2A2E07A02B0E13CA95E35C926D2876A746242FB75C17503C45B71A5641771062E51D9504ECA70EEA2C40B39CA312615CE0B5AD593C81BDB8F07452FFAD25932E7AD6989F3C226E61658015B277ACEC32E6BF61518557F014CC98C3F5F07AF85CD19885FEEC49CF8A4D7F7AA67C65421B43F851A818ECE133E7BDB3C8187193563AA125A3F73909033B6B3F83E262CEC45F8531BD00FD745EAAAA85CD11DDD09F12C47D967E2E2A8699DDF685D1970F6893B119F8BE78CDE1D17CE314704E8DC021E4C12EF1D1952336788F101975E28EF5FD784BC1A85BB63380E1ADD6B4A21E2302B08E31D5AB441A22060630958F8A97121FA709D7B498EB78A4E937836D929CA4E1853D6F4870793FAD3C4CE64F72AB2CA07B75C4E8D35F04AD6EAC18420AA0807EF512C5A98BDB2D2C06B372C48AC179703AAB6821DB177B991EA54322083360991F6781DC9DF2A45ED9F0B7E202C48AD1A61003CA4A21127AF9D2FDC1A1358EDD5DD87F8102FDAD3772D834B486BA197CD797D48E269B4C7B81248C9E07BA4B067A89AC974AF57634D65CDA921EFB3C4F2956B152CAC92B184DB85615E258533C2F6668E93A8E6BDB39C8D541B01C28532DAF7B466570BE04210C3AD0E3919393C73156FA0270511C12C57A73D2CC89108F1485F8D953433F2C854E08129336AFA49C333DE7AE2ECE2EFB5272244F0044689F06F315AD6EDEC28F8CCDB275954F82781472837E14757C8A777F65D9B5910D2FDE3F3DC70B7D94CEAEAD52A47E60542553CE9359A7B339C9DE10050DEF55F84EE5F0E16339CB6DFD6D63A6C6A76C25137C726115944DDD17E56913B021E00D6B4A849C4840BD50BDB4F6B6EE43B280F1542F0AB1C4593D5A465967E817E9409B92B07EA7D575DFC8DB95CF30DD1003C4E2874279682639ADB450E3F0FA38FDAD575B84EEC38C6E8749D96826F3AE81C3A1BED"
"OODI04.00.00.01PRO"="9D38E880FEA2605ED6099208CDAD4640145FC34BC34EA50CE032C5CAC983C7283AF48A5B58F5F943D4C395711D7B1C25AF26B2F5FB1E800A7A6480A956349D8E4C6947A2AC9010369F33A0C9883669F1B357F4F93928CDC3A4943D1E5FC26AEB6774A0714DA333A40B015A3DACA672F4D004FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794BA7FD869164D67945B53DAA5B8B2D10D90AAE0ACD5E8A27A84837066B2E0F2A1F20B76CD216C861F4B1CD7C5C13D8536198E1C9B933A0D1440866A8655DC989EFEE3D5CD359AB55C4D2E7B6A556B81E37E23EE4893500A5BBF4BF189B37866935D9E886748E9B2A0DB3BCF1A7B45D094DF2D2C531392013B68C6C7C85F9BBF72D502DBCD61E2810843F94E014F96B12E2E741F82642D8C017070A3C201F5BC91055694D81CD256102726686E046E17F8B243823EEB10FCDC64C62E9950772BABDCEAE78126CC1B9CFA7E8157DA1F262206E98894226FD565A3C905129CD40BDD21918267C4286EF68AC4F2D32DBFBAB7983C573495C3CE13E27DBA97C80810ACE91E82CECDFC20C7F2BF071EE72C6331AC128574E6C8D2C3A86AD5B64A4D237EA5EBFA9C2DAA3621263B00170A8361E4D8C6A1CB4CFE8239511FCF232BA6621B145773DD62D26B74E8838E422A28AC8E07B92DD80E2BB0188D2996B00BD91C33CAC266BF7FDB2C19D6EDDD49ED42EED0F64F9B5C09D3E36ADF200DDA9AED56D73213C294AC6F994CDBCE8975923C872FBC6ED6B9AFC6D81E209A88BD213149810633EB55A6FC892CBA031FB869C508913C03BBFB07137F03FAB6D29D78B5E0085990391CBAB5863C08672525545137C4B27C1CCE280D7ACE6F94AADD8ECE3FAA8E1CF4A7CB8F4DE3305F14F4CE9610772ECE3C83C04D211DD1D7C18A6797B50DDFCB5FDAD2C5CF6E6E51D4826291BF429071D48E91AF00E8492BBD5117EA5034D9192A3CD9D4338BD6A84ACDB07FAB1A116013096FD4D51451B9B982C8EC4A8B5C02FCF60200504ECC5247FAED6567DB3B9B9830442016E4BBB4C2943B0013E01D87F15AFB4DB5AE0B439451E1883F48ED26F9648DBA69042AD05AA2BF4E50E6A5301AD89007A4081FF06DBDE9F5B004DA87412C5C0F2AFD15C57769BD455A32518476891ABA1319EBD502CF74FAED18094BE9AD554FE746C8D184CBAE963E40509400A8893B298526EF763C07AC5F6F5302E537B3EDE5B16435DE4F21B5BB6DA9EE1F12E09E4655D74463D83A611EDBE83E19BA42249D785BB3591DB7DD47FC35AAB4CB37BE7AF2DED7D323B933F810CC985E4B636D3839F595B783280A89159E6294F9B83A0CAEECB4C83AC502F226D4AB01230D8A977451A8B6743CFCDFC0E7B1036AA472"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1100)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3004)
c:\program files\OO Software\DiskImage\oodishi.dll
c:\program files\OO Software\DiskImage\oodishrs.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\oodag.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Celkový čas: 2011-02-27 19:45:25 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-27 18:45

Před spuštěním: Volných bajtů: 222 543 515 648
Po spuštění: Volných bajtů: 222 471 725 056

- - End Of File - - AD5ABDDA360FF04FD9B674C0563A0D9D

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 19:49
od hoskinson
...možná měl být ComboFix na ploše...vadí to?

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 20:22
od Rudy
Ještě dočistíme. Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files\Common Files\Spigot

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SearchSettings"=-
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 21:06
od hoskinson
ComboFix 11-02-26.02 - me 27.02.2011 20:39:29.13.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.419 [GMT 1:00]
Spuštěný z: c:\documents and settings\me\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\me\Plocha\CFScript.txt
AV: Norton Internet Security *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\Spigot
c:\program files\Common Files\Spigot\Search Settings\config.ini
c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe
c:\program files\Common Files\Spigot\Search Settings\yahoo_ff.xml
c:\program files\Common Files\Spigot\Search Settings\yahoo_ie.xml
c:\program files\Common Files\Spigot\wtxpcom\components\IFBHOHelperWidgiToolbar.xpt
c:\program files\Common Files\Spigot\wtxpcom\components\IFBHOWidgiToolbar.xpt
c:\program files\Common Files\Spigot\wtxpcom\chrome.manifest
c:\program files\Common Files\Spigot\wtxpcom\install.rdf

.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-27 do 2011-02-27 )))))))))))))))))))))))))))))))
.

2011-02-27 11:50 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-27 11:50 . 2011-02-27 11:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-27 11:50 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-27 10:37 . 2011-02-27 10:37 -------- d-----w- c:\program files\trend micro
2011-02-27 10:37 . 2011-02-27 10:39 -------- d-----w- C:\rsit
2011-02-27 06:24 . 2011-02-27 06:24 1409 ----a-w- c:\windows\QTFont.for
2011-02-20 08:54 . 2011-02-20 08:54 -------- d-----w- c:\program files\Sony Ericsson
2011-02-20 08:54 . 2011-02-20 08:54 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Sony Ericsson
2011-02-15 20:42 . 2011-02-15 20:42 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2011-02-15 20:13 . 2011-02-15 20:13 -------- d-----w- c:\documents and settings\me\Local Settings\Data aplikací\WMTools Downloaded Files
2011-02-15 19:51 . 2011-02-15 19:52 -------- d-----w- C:\RLTMP
2011-02-14 19:42 . 2011-02-14 19:42 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-02-14 19:42 . 2011-02-14 19:42 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-02-14 19:39 . 2011-02-14 19:43 -------- d-----w- c:\documents and settings\me\Data aplikací\DAEMON Tools Lite
2011-02-14 19:39 . 2011-02-14 19:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DAEMON Tools Lite
2011-02-13 12:34 . 2011-02-13 12:34 -------- d-----r- c:\program files\Norton Support
2011-02-13 08:40 . 2011-02-13 08:40 -------- d-----w- c:\program files\eRightSoft
2011-02-11 16:37 . 2011-02-05 07:50 53248 ----a-w- c:\windows\system32\BSwitch.ax
2011-02-11 16:37 . 2011-02-03 14:34 364544 ----a-w- c:\windows\system32\prScrCamFXControls.ocx
2011-02-11 16:37 . 2010-11-15 06:17 232640 ----a-w- c:\windows\system32\drivers\SCRCAMHRDRV.sys
2011-02-11 16:37 . 2011-02-11 16:44 -------- d-----w- c:\program files\ScreenCamera
2011-02-05 19:42 . 2010-01-20 21:03 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2011-02-05 19:42 . 2011-02-06 18:13 -------- d-----w- c:\program files\Symantec
2011-02-05 19:42 . 2011-02-06 18:13 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2011-02-05 19:42 . 2011-02-06 18:13 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-05 19:42 . 2011-02-05 19:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-02-05 19:41 . 2011-02-06 18:38 -------- d-----w- c:\windows\system32\drivers\NIS
2011-02-05 19:41 . 2011-02-05 19:41 -------- d-----w- c:\program files\Norton Internet Security
2011-02-05 19:41 . 2011-02-05 19:41 -------- d-----w- c:\program files\Windows Sidebar
2011-02-05 19:41 . 2011-02-05 19:41 -------- d-----w- c:\program files\NortonInstaller
2011-02-04 16:14 . 2011-02-04 16:14 -------- d-----w- c:\program files\Passware
2011-01-30 13:57 . 2011-01-30 13:57 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-01-30 13:57 . 2011-01-30 13:57 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2004-08-18 12:00 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-18 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2004-08-18 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-18 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-22 05:36 . 2011-01-01 11:11 73728 ----a-w- c:\windows\system32\TOverlay.ax
2010-12-20 23:52 . 2004-08-18 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2004-08-18 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:52 . 2004-08-18 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:25 . 2004-08-18 12:00 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-08-18 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-12-10 17:29 . 2010-12-10 17:29 64864 ----a-w- c:\windows\system32\sqlctr90.dll
2010-12-10 17:29 . 2010-12-10 17:29 2248032 ----a-w- c:\windows\system32\sqlncli.dll
2010-12-09 15:15 . 2004-08-18 12:00 713216 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2004-08-18 12:00 2194944 ------w- c:\windows\system32\ntoskrnl.exe
2010-12-09 15:14 . 2004-08-17 15:45 2071552 ------w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 14:30 . 2004-08-18 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2006-05-03 10:06 163328 --sha-r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 31232 --sha-r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 216064 --sha-r- c:\windows\system32\nbDX.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OODIIcon]
@="{14A94384-BBED-47ed-86C0-6BF63FD892D0}"
[HKEY_CLASSES_ROOT\CLSID\{14A94384-BBED-47ed-86C0-6BF63FD892D0}]
2009-10-24 01:35 111944 ----a-w- c:\program files\OO Software\DiskImage\oodishi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QIP2005"="c:\program files\QIP\qip.exe" [2009-08-13 3276288]
"MemInfo"="c:\program files\MemInfo\meminfo.exe" [2005-12-13 628224]
"hddhealth"="c:\program files\HDD Health\hddhealth.exe" [2008-06-15 1692672]
"netmeter"="c:\program files\NetMeter\netmeter.exe" [2007-08-11 331264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\ASUS\ASUS Remote\RemoteControlAppl.exe" [2006-02-14 69632]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-10-14 2049344]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" silent
"OEXPRESS"=c:\windows\OETRN.EXE
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"Boxoft Tools"="c:\documents and settings\All Users\Data aplikací\Boxtools\Boxofttoolbox.exe" -autorun
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"High Definition Audio Property Page Shortcut"=HDAShCut.exe
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"OODefragTray"=c:\windows\system32\oodtray.exe
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
"SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"tsnpstd3"=c:\windows\tsnpstd3.exe
"DocCreatorClient"="c:\program files\Global Graphics\gDoc\DocCreatorClient.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"OODITRAY.EXE"=c:\program files\OO Software\DiskImage\OODITRAY.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 oodisr;O&O DiskImage Snapshot/Restore Driver;c:\windows\system32\drivers\oodisr.sys [24.10.2009 2:38 96336]
R0 oodisrh;oodisrh;c:\windows\system32\drivers\oodisrh.sys [24.10.2009 2:38 28752]
R0 oodivd;O&O DiskImage Virtual Devices Driver;c:\windows\system32\drivers\oodivd.sys [24.10.2009 2:38 166992]
R0 oodivdh;oodivdh;c:\windows\system32\drivers\oodivdh.sys [24.10.2009 2:38 31312]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [6.2.2011 19:13 310320]
R1 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [29.11.2009 21:33 2944]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [6.2.2011 19:13 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [6.2.2011 19:13 482432]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [14.2.2011 20:42 218688]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20110224.001\IDSXpx86.sys [25.2.2011 17:05 341944]
R2 dvdmmg;dvdmmg;c:\windows\system32\drivers\dvdmmg.sys [6.9.2007 12:15 5504]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [6.2.2011 19:13 117640]
R2 O&O DiskImage;O&O DiskImage;c:\program files\OO Software\DiskImage\oodiag.exe [24.10.2009 2:34 2311496]
R2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\drivers\SCRCAMHRDRV.sys [11.2.2011 17:37 232640]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [14.10.2009 14:31 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16.6.2009 9:58 20480]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [5.4.2010 22:32 2825088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5.2.2011 3:20 102448]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24.12.2010 19:02 136176]
S2 PHPGeekUtil;PHPGeekUtil;"c:\apache\APACHE.EXE" --ntservice --> c:\apache\APACHE.EXE [?]
S3 cpuz130;cpuz130;\??\c:\docume~1\me\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\me\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 DCMessages;DCMessages;c:\windows\system32\DCMessages.exe [18.1.2010 19:49 99720]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [5.7.2010 8:56 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [5.7.2010 8:56 8456]
S3 NANMp50;NANMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NANMp50.sys --> c:\windows\system32\Drivers\NANMp50.sys [?]
S3 pbfilter;pbfilter;\??\c:\program files\Peerblock\pbfilter.sys --> c:\program files\Peerblock\pbfilter.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [26.11.2009 0:06 34384]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [20.2.2011 9:54 155344]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 12:37 517096]
S3 TfBulk;TfBulk;c:\windows\system32\drivers\TfBulk.SYS [31.5.2007 21:11 13312]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [17.12.2009 16:25 11520]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [30.11.2010 17:18 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [30.11.2010 17:19 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [30.11.2010 17:19 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [30.11.2010 17:19 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [30.11.2010 17:19 25704]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3.12.2009 21:06 717296]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2011-02-25 c:\windows\Tasks\Automatic maintenance.job
- c:\program files\TuneUp Utilities 2010\OneClickStarter.exe [2009-10-29 19:46]

2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 18:02]

2011-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 18:02]

2011-02-27 c:\windows\Tasks\User_Feed_Synchronization-{9939AAA9-05AB-4E61-9A8A-47454B7610D1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Download with Rapget - c:\program files\RapGet141\rapget.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files\INTERN~2\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files\INTERN~2\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files\INTERN~2\IEGetAll.htm
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
FF - ProfilePath - c:\documents and settings\me\Data aplikací\Mozilla\Firefox\Profiles\3klt4bnl.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=302398&p=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-27 20:52
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600

CreateFile("\\.\PHYSICALDRIVE0"): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/apache/mysql/bin/mysqld-nt.exe"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/apache/mysql/bin/mysqld-nt.exe"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,64,da,19,6c,0e,a7,40,4a,af,a8,de,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,64,da,19,6c,0e,a7,40,4a,af,a8,de,\

[HKEY_USERS\S-1-5-21-1606980848-57989841-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1606980848-57989841-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:fc,0f,c9,04,0e,9a,f3,1c,e1,06,d2,2a,a6,3f,a2,34,64,a9,a0,e2,b9,
64,ec,76,a0,57,48,83,25,a4,0b,9d,7e,09,ba,c0,0a,2e,7e,41,72,df,e3,31,8d,09,\
"rkeysecu"=hex:e2,1b,b7,3f,00,5e,55,69,b2,f9,ae,20,85,d6,52,c6

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{34601407-0fc7-456d-92b4-ed0fa73d6695}]
@Denied: (Full) (Everyone)
"Model"=dword:00000118
"Therad"=dword:00000020
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8c,e3,09,fa,be,f5,5e,41,b6,d2,68,f5,c4,9a,19,89,a2,3d,ab,14,80,
8a,40,b1,b5,26,8d,9b,68,4e,67,c4,e0,a0,86,cb,24,ee,18,8b,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="38D140A9C8AA2DD0A9B3839FED7894F6A768EFF07D5F3B942D0054CD2522FA393796A30010953ED4E27A0D380E36D63319A016A1CB7C6832CFE85949938D675858B4BE5FAC359C34BCC6513637B4C78CAD7DA39FAE5EC15F05523E12E301BD34CE3127A79DA68FBD6B9A705E3B1F0746BC9DDCB5685CDE7564151196E7A12FDA93C0D50C697C7E53E8A86CC76E93D8B8DDD1700240C27BE0C7C0C719788691EB6252A81498BAF8EBF1DA2BE12BA5224E711FEAF58051F820CE1839B171BEDC1EBA03E09C365EB09087CC78EA4F5CEE8618C0C15678BCD84A5C90A3C831CB2FB8E0A7A3D4D454FB61EFCE00F73CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A6171C11EC38DE3DFEBC9E127BECC74C3B060D50980065913945AF4169ABFAC48E096D6F9E618E3074F761E2A2E07A02B0E13CA95E35C926D2876A746242FB75C17503C45B71A5641771062E51D9504ECA70EEA2C40B39CA312615CE0B5AD593C81BDB8F07452FFAD25932E7AD6989F3C226E61658015B277ACEC32E6BF61518557F014CC98C3F5F07AF85CD19885FEEC49CF8A4D7F7AA67C65421B43F851A818ECE133E7BDB3C8187193563AA125A3F73909033B6B3F83E262CEC45F8531BD00FD745EAAAA85CD11DDD09F12C47D967E2E2A8699DDF685D1970F6893B119F8BE78CDE1D17CE314704E8DC021E4C12EF1D1952336788F101975E28EF5FD784BC1A85BB63380E1ADD6B4A21E2302B08E31D5AB441A22060630958F8A97121FA709D7B498EB78A4E937836D929CA4E1853D6F4870793FAD3C4CE64F72AB2CA07B75C4E8D35F04AD6EAC18420AA0807EF512C5A98BDB2D2C06B372C48AC179703AAB6821DB177B991EA54322083360991F6781DC9DF2A45ED9F0B7E202C48AD1A61003CA4A21127AF9D2FDC1A1358EDD5DD87F8102FDAD3772D834B486BA197CD797D48E269B4C7B81248C9E07BA4B067A89AC974AF57634D65CDA921EFB3C4F2956B152CAC92B184DB85615E258533C2F6668E93A8E6BDB39C8D541B01C28532DAF7B466570BE04210C3AD0E3919393C73156FA0270511C12C57A73D2CC89108F1485F8D953433F2C854E08129336AFA49C333DE7AE2ECE2EFB5272244F0044689F06F315AD6EDEC28F8CCDB275954F82781472837E14757C8A777F65D9B5910D2FDE3F3DC70B7D94CEAEAD52A47E60542553CE9359A7B339C9DE10050DEF55F84EE5F0E16339CB6DFD6D63A6C6A76C25137C726115944DDD17E56913B021E00D6B4A849C4840BD50BDB4F6B6EE43B280F1542F0AB1C4593D5A465967E817E9409B92B07EA7D575DFC8DB95CF30DD1003C4E2874279682639ADB450E3F0FA38FDAD575B84EEC38C6E8749D96826F3AE81C3A1BED"
"OODI04.00.00.01PRO"="9D38E880FEA2605ED6099208CDAD4640145FC34BC34EA50CE032C5CAC983C7283AF48A5B58F5F943D4C395711D7B1C25AF26B2F5FB1E800A7A6480A956349D8E4C6947A2AC9010369F33A0C9883669F1B357F4F93928CDC3A4943D1E5FC26AEB6774A0714DA333A40B015A3DACA672F4D004FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5CBA7FD869164D6794BA7FD869164D67945B53DAA5B8B2D10D90AAE0ACD5E8A27A84837066B2E0F2A1F20B76CD216C861F4B1CD7C5C13D8536198E1C9B933A0D1440866A8655DC989EFEE3D5CD359AB55C4D2E7B6A556B81E37E23EE4893500A5BBF4BF189B37866935D9E886748E9B2A0DB3BCF1A7B45D094DF2D2C531392013B68C6C7C85F9BBF72D502DBCD61E2810843F94E014F96B12E2E741F82642D8C017070A3C201F5BC91055694D81CD256102726686E046E17F8B243823EEB10FCDC64C62E9950772BABDCEAE78126CC1B9CFA7E8157DA1F262206E98894226FD565A3C905129CD40BDD21918267C4286EF68AC4F2D32DBFBAB7983C573495C3CE13E27DBA97C80810ACE91E82CECDFC20C7F2BF071EE72C6331AC128574E6C8D2C3A86AD5B64A4D237EA5EBFA9C2DAA3621263B00170A8361E4D8C6A1CB4CFE8239511FCF232BA6621B145773DD62D26B74E8838E422A28AC8E07B92DD80E2BB0188D2996B00BD91C33CAC266BF7FDB2C19D6EDDD49ED42EED0F64F9B5C09D3E36ADF200DDA9AED56D73213C294AC6F994CDBCE8975923C872FBC6ED6B9AFC6D81E209A88BD213149810633EB55A6FC892CBA031FB869C508913C03BBFB07137F03FAB6D29D78B5E0085990391CBAB5863C08672525545137C4B27C1CCE280D7ACE6F94AADD8ECE3FAA8E1CF4A7CB8F4DE3305F14F4CE9610772ECE3C83C04D211DD1D7C18A6797B50DDFCB5FDAD2C5CF6E6E51D4826291BF429071D48E91AF00E8492BBD5117EA5034D9192A3CD9D4338BD6A84ACDB07FAB1A116013096FD4D51451B9B982C8EC4A8B5C02FCF60200504ECC5247FAED6567DB3B9B9830442016E4BBB4C2943B0013E01D87F15AFB4DB5AE0B439451E1883F48ED26F9648DBA69042AD05AA2BF4E50E6A5301AD89007A4081FF06DBDE9F5B004DA87412C5C0F2AFD15C57769BD455A32518476891ABA1319EBD502CF74FAED18094BE9AD554FE746C8D184CBAE963E40509400A8893B298526EF763C07AC5F6F5302E537B3EDE5B16435DE4F21B5BB6DA9EE1F12E09E4655D74463D83A611EDBE83E19BA42249D785BB3591DB7DD47FC35AAB4CB37BE7AF2DED7D323B933F810CC985E4B636D3839F595B783280A89159E6294F9B83A0CAEECB4C83AC502F226D4AB01230D8A977451A8B6743CFCDFC0E7B1036AA472"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1100)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-02-27 21:04:28
ComboFix-quarantined-files.txt 2011-02-27 20:04
ComboFix2.txt 2011-02-27 18:45

Před spuštěním: Volných bajtů: 222 100 447 232
Po spuštění: Volných bajtů: 222 168 363 008

- - End Of File - - 8777024FD600EEEF8B8F86796D43DDD1

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 21:09
od hoskinson
...zvuk stále přítomen...

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 22:01
od Rudy
Stáhněte TDSS killer: http://support.kaspersky.com/downloads/ ... killer.exe a uložte ho na plochu. Dále postupujte podle kolegova návodu:

2x-klik na TDSSKiller.exe- spustiť aplikáciu, potom na Spustiť kontrolu-klik- Start Scan.
Ak je infikovaný súbor detekovaný, bude predvolená akcia Cure, kliknite na tlačidlo Continue.
Ak podozrivý[suspicious] súbor je detekovaný, bude predvolená akcia Skip, kliknite na Continue.
Môže vás požiadať, aby ste reštartovali počítač na dokončenie procesu. Kliknite na Reboot Now.
Ak nevyžaduje reštart, kliknite na tlačidlo Report. Log súbor by sa mal objaviť. Prosím, skopírujte a vložte obsah súboru tu.
Ak je vyžadované reštartovanie počítača, správa je k dispozícii vo vašom koreňovom adresári (zvyčajne C:\ zložka) vo forme "TDSSKiller. _log.txt". Prosím, skopírujte a vložte obsah súboru tu.

Re: Neodůvodněný zvuk

Napsal: 27 úno 2011 22:13
od hoskinson
...z toho odkazu to stáhnout nejde...ale mám ho...