Stránka 1 z 1

kontrola

Napsal: 14 bře 2011 01:19
od ados
dobry vecLogfile of random's system information tool 1.08 (written by random/random)
Run by laco at 2011-03-14 00:09:24
Microsoft Windows 7 Ultimate
System drive C: has 6 GB (19%) free of 30 GB
Total RAM: 1919 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:10:16, on 14. 3. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\EmEditor\emedtray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10m_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\laco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2DA1RIHR\RSIT[1].exe
C:\Program Files\trend micro\laco.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... nkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O2 - BHO: Norton Safe Web Lite BHO - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\coIEPlg.dll
O3 - Toolbar: Norton Safe Web Lite - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: EmEditor.lnk = C:\Program Files\EmEditor\emedtray.exe
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\HEWLET~1\IAM\bin\APSHook.dll
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AuthenTec Fingerprint Service (ATService) - AuthenTec, Inc. - C:\Program Files\Fingerprint Sensor\AtService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\Windows\system32\flcdlock.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\Windows\system32\Hpservice.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: Norton Safe Web Lite (NSL) - Symantec Corporation - C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\ccSvcHst.exe

--
End of file - 10080 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for laco.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-03-01 298160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-02-11 1246600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll [2011-03-03 848952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-21 1233288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
Credential Manager for HP ProtectTools - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll [2009-07-28 98576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3}]
Norton Safe Web Lite BHO - C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\coIEPlg.dll [2010-06-03 422768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - Norton Safe Web Lite - C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\coIEPlg.dll [2010-06-03 422768]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-03-01 298160]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-21 1233288]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2011-01-20 988480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-05-21 61440]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-11 287800]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-07-29 1545512]
"acevents"=C:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-03 153640]
""= []
"accrdsub"=C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-03 400936]
"PTHOSTTR"=C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2009-08-07 354360]
"CognizanceTS"=C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [2009-07-28 24848]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-10 932288]
"TaskTray"= []
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-01-10 1230704]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-12-20 963976]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-12-20 443728]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-02-03 39408]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-01-26 15026056]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

C:\Users\laco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
EmEditor.lnk - C:\Program Files\EmEditor\emedtray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\HEWLET~1\IAM\bin\APSHook.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\Windows\system32\DeviceNP.dll [2009-10-05 75320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files\EmEditor\EMEDITOR.EXE" "%1"

======List of files/folders created in the last 1 months======

2011-03-14 00:09:25 ----D---- C:\Program Files\trend micro
2011-03-14 00:09:24 ----D---- C:\rsit
2011-03-13 22:56:09 ----D---- C:\Users\laco\AppData\Roaming\Malwarebytes
2011-03-13 22:56:03 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-03-13 22:56:02 ----D---- C:\ProgramData\Malwarebytes
2011-03-13 22:55:58 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-03-13 22:55:58 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-03-13 15:27:10 ----D---- C:\Program Files\MSXML 4.0
2011-03-12 22:39:52 ----A---- C:\Windows\system32\msvcp71.dll
2011-03-12 22:37:03 ----A---- C:\Windows\system32\mfc71.dll
2011-03-12 22:00:45 ----D---- C:\Program Files\Common Files\InstallShield
2011-03-12 22:00:27 ----RASH---- C:\MSDOS.SYS
2011-03-12 22:00:27 ----RASH---- C:\IO.SYS
2011-03-12 14:54:32 ----D---- C:\Users\laco\AppData\Roaming\WinRAR
2011-03-12 14:07:17 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-03-12 14:07:06 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-03-12 14:06:58 ----D---- C:\Program Files\DAEMON Tools Lite
2011-03-12 13:36:42 ----D---- C:\Program Files\Common Files\Nero
2011-03-12 13:36:34 ----D---- C:\Program Files\Nero
2011-03-12 13:34:35 ----D---- C:\Program Files\Ask.com
2011-03-12 13:31:42 ----D---- C:\Program Files\WinRar
2011-03-09 07:27:26 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 07:27:25 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 07:27:25 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 07:27:23 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 07:27:23 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 07:27:22 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 07:27:20 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 07:27:19 ----A---- C:\Windows\system32\mstsc.exe
2011-03-05 22:17:58 ----D---- C:\Windows\system32\appmgmt
2011-03-03 20:44:31 ----D---- C:\Users\laco\AppData\Roaming\skypePM
2011-03-03 20:42:13 ----D---- C:\Program Files\Common Files\Skype
2011-03-03 20:42:11 ----RD---- C:\Program Files\Skype
2011-03-03 20:42:09 ----D---- C:\Users\laco\AppData\Roaming\Skype
2011-03-03 20:42:00 ----D---- C:\ProgramData\Skype
2011-02-23 13:48:01 ----A---- C:\Windows\system32\wcncsvc.dll
2011-02-22 21:12:34 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-22 21:12:33 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-19 19:42:23 ----D---- C:\Windows\system32\drivers\NST
2011-02-19 19:42:23 ----D---- C:\Program Files\Norton Safe Web Lite
2011-02-19 19:32:45 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-02-15 18:03:17 ----D---- C:\divx

======List of files/folders modified in the last 1 months======

2011-03-14 00:09:42 ----D---- C:\Windows\Prefetch
2011-03-14 00:09:25 ----RD---- C:\Program Files
2011-03-14 00:09:24 ----D---- C:\Windows\Temp
2011-03-14 00:00:01 ----D---- C:\Windows\system32\config
2011-03-13 23:48:52 ----D---- C:\Windows\system32\drivers
2011-03-13 23:32:30 ----D---- C:\Windows\Setup
2011-03-13 23:32:15 ----HD---- C:\ProgramData
2011-03-13 22:19:41 ----SHD---- C:\System Volume Information
2011-03-13 21:53:35 ----HD---- C:\Program Files\InstallShield Installation Information
2011-03-13 18:45:50 ----D---- C:\Windows\System32
2011-03-13 18:45:50 ----D---- C:\Windows\inf
2011-03-13 18:45:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-13 16:08:21 ----D---- C:\Windows\system32\Tasks
2011-03-13 15:27:33 ----D---- C:\Windows\winsxs
2011-03-13 15:27:32 ----SHD---- C:\Windows\Installer
2011-03-13 15:27:29 ----D---- C:\Windows
2011-03-12 22:00:45 ----D---- C:\Program Files\Common Files
2011-03-12 19:16:43 ----D---- C:\Windows\system32\catroot2
2011-03-12 14:41:12 ----D---- C:\Users\laco\AppData\Roaming\DAEMON Tools Lite
2011-03-12 14:07:33 ----D---- C:\Windows\system32\catroot
2011-03-12 14:07:32 ----D---- C:\Windows\system32\DriverStore
2011-03-11 21:41:44 ----D---- C:\VideoOutput
2011-03-09 23:56:55 ----D---- C:\Windows\debug
2011-03-09 23:56:53 ----A---- C:\Windows\system32\MRT.exe
2011-03-06 13:32:02 ----D---- C:\Windows\system32\wdi
2011-03-05 23:31:08 ----D---- C:\Users\laco\AppData\Roaming\DivX
2011-02-24 20:42:31 ----RD---- C:\Users
2011-02-22 09:56:58 ----D---- C:\ProgramData\hpqLog
2011-02-20 22:02:55 ----D---- C:\Windows\Tasks
2011-02-20 22:02:55 ----D---- C:\Windows\system32\wfp
2011-02-20 22:02:55 ----D---- C:\Windows\system32\wbem
2011-02-20 22:02:54 ----D---- C:\Windows\AppCompat
2011-02-20 22:02:53 ----D---- C:\Windows\registration
2011-02-19 19:42:23 ----D---- C:\ProgramData\Norton
2011-02-19 19:42:19 ----D---- C:\Program Files\NortonInstaller
2011-02-18 22:35:45 ----SD---- C:\Users\laco\AppData\Roaming\Microsoft
2011-02-17 18:49:56 ----D---- C:\Windows\system32\LogFiles
2011-02-16 11:37:07 ----D---- C:\Windows\system32\NDF
2011-02-16 11:28:27 ----D---- C:\Windows\Logs

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 dlkmdldr;dlkmdldr; C:\Windows\system32\drivers\dlkmdldr.sys [2009-10-10 13936]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SafeBoot;SafeBoot; C:\Windows\system32\drivers\SafeBoot.sys [2009-07-29 109216]
R0 SbAlg;SbAlg; C:\Windows\system32\drivers\SbAlg.sys [2009-07-29 51408]
R0 SbFsLock;SbFsLock; C:\Windows\system32\drivers\SbFsLock.sys [2009-07-29 12960]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-13 387584]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-03-12 218688]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsl3922c377;MpKsl3922c377; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{34FA8921-FD38-40B9-AD0D-5CB3D592966A}\MpKsl3922c377.sys [2011-03-13 28752]
R1 RsvLock;RsvLock; C:\Windows\system32\drivers\RsvLock.sys [2009-07-29 12528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-13 8704]
R3 Accelerometer;HP Accelerometer; C:\Windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-05-22 4450816]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver; C:\Windows\System32\Drivers\ATSwpWDF.sys [2009-07-29 482176]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
R3 BCM43XX;Broadcom 802.11 - ovládač sieťového adaptéru; C:\Windows\system32\DRIVERS\bcmwl6.sys [2011-01-22 2661368]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-13 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-13 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-13 58880]
R3 dlkmd;dlkmd; C:\Windows\system32\drivers\dlkmd.sys [2009-10-10 164976]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2009-04-20 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-13 129536]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-07-29 213680]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-13 30720]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
S1 MpKsl0323b6f3;MpKsl0323b6f3; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EDE05154-D040-4ADF-B7B3-92D3F778302B}\MpKsl0323b6f3.sys []
S1 MpKsl09e4af28;MpKsl09e4af28; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BF9D366C-F3B0-4467-BD89-1B285ABB395B}\MpKsl09e4af28.sys []
S1 MpKsl0d0f189a;MpKsl0d0f189a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6DD0FB43-C222-4C0C-80D0-8424838DC6A9}\MpKsl0d0f189a.sys []
S1 MpKsl0f356ceb;MpKsl0f356ceb; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8A384C17-06B1-466F-8F4C-FE4AECF7F454}\MpKsl0f356ceb.sys []
S1 MpKsl0f487305;MpKsl0f487305; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{476187E1-F4DC-4B1E-90D4-525E188C07A9}\MpKsl0f487305.sys []
S1 MpKsl110b4a5b;MpKsl110b4a5b; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6DD0FB43-C222-4C0C-80D0-8424838DC6A9}\MpKsl110b4a5b.sys []
S1 MpKsl1ab91949;MpKsl1ab91949; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DD6C5BB3-9680-4F60-A390-0287E28DC9C8}\MpKsl1ab91949.sys []
S1 MpKsl328a522a;MpKsl328a522a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D3F72091-98FD-41EC-88AC-29ADF844A220}\MpKsl328a522a.sys []
S1 MpKsl3445045f;MpKsl3445045f; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EC417115-987B-41C1-BEC3-93A6B921C075}\MpKsl3445045f.sys []
S1 MpKsl4e254ee4;MpKsl4e254ee4; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F826E4D7-A2A8-4889-A8D7-F7B91CC18066}\MpKsl4e254ee4.sys []
S1 MpKsl5de73522;MpKsl5de73522; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5A672000-A595-4799-AB0D-B639CD7EEA85}\MpKsl5de73522.sys []
S1 MpKsl77475f51;MpKsl77475f51; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5447FD87-08F1-469E-9951-2F6E51F8FF1E}\MpKsl77475f51.sys []
S1 MpKsl7c670295;MpKsl7c670295; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8A384C17-06B1-466F-8F4C-FE4AECF7F454}\MpKsl7c670295.sys []
S1 MpKsl8e9584ce;MpKsl8e9584ce; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D3F72091-98FD-41EC-88AC-29ADF844A220}\MpKsl8e9584ce.sys []
S1 MpKsla42848d1;MpKsla42848d1; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5447FD87-08F1-469E-9951-2F6E51F8FF1E}\MpKsla42848d1.sys []
S1 MpKsla6ae4164;MpKsla6ae4164; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{476187E1-F4DC-4B1E-90D4-525E188C07A9}\MpKsla6ae4164.sys []
S1 MpKslc31822bb;MpKslc31822bb; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6DD0FB43-C222-4C0C-80D0-8424838DC6A9}\MpKslc31822bb.sys []
S1 MpKsld61f1408;MpKsld61f1408; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5074AECB-99C6-4807-A40A-BDB4A26603E3}\MpKsld61f1408.sys []
S1 MpKsldcfabd4d;MpKsldcfabd4d; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3E0BBBAE-FA05-4941-AF0F-43E8337428D6}\MpKsldcfabd4d.sys []
S1 MpKsle082b819;MpKsle082b819; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EDE05154-D040-4ADF-B7B3-92D3F778302B}\MpKsle082b819.sys []
S1 MpKsle69489ed;MpKsle69489ed; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3E0BBBAE-FA05-4941-AF0F-43E8337428D6}\MpKsle69489ed.sys []
S1 MpKsle6dbccab;MpKsle6dbccab; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{01039C3C-DEA9-4F33-AC59-012AD4D37B02}\MpKsle6dbccab.sys []
S1 MpKslfc84737b;MpKslfc84737b; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EC417115-987B-41C1-BEC3-93A6B921C075}\MpKslfc84737b.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-13 392704]
S3 DAMDrv;DAMDrv; C:\Windows\system32\DRIVERS\DAMDrv.sys [2009-09-08 32312]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-13 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-13 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-13 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ac.sharedstore;ActivIdentity Shared Store Service; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 ASBroker;Logon Session Broker; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ASChannel;Local Communication Channel; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2009-05-21 733184]
R2 ATService;AuthenTec Fingerprint Service; C:\Program Files\Fingerprint Sensor\AtService.exe [2009-07-29 1201400]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DisplayLinkService;DisplayLinkManager; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2009-10-10 4707688]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-11-15 126520]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
R2 HpFkCryptService;Drive Encryption Service; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-07-29 256544]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2009-07-08 26168]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 NAUpdate;@C:\Program Files\Nero\Update\NASvc.exe,-200; C:\Program Files\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 NSL;Norton Safe Web Lite; C:\Program Files\Norton Safe Web Lite\Engine\1.0.1.8\ccSvcHst.exe [2010-05-23 126904]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2010-10-14 751672]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-03 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\Windows\system32\flcdlock.exe [2009-10-05 362040]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-03 182768]
S3 HP ProtectTools Service;HP ProtectTools Service; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [2009-08-07 45056]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-22 1343400]

-----------------EOF-----------------
er mbam mi nasiel asi dake infikovane subory ..poprsim o kontrolu logu lebo neviem co s tym...

Re: kontrola

Napsal: 14 bře 2011 18:02
od vyosek
Zdravim a pekny den preji :)

:arrow: Spustte MBAM, v zalozce Protokoly najdete logy z kontrol, ty mi sem vlozte, at vidim co MBAM nasel

:arrow: Jsou s PC nejake problemy :???: