Stránka 1 z 1

Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 01:57
od honzage
Děkuji předem za pomoc.

Po detekci Trojanů a léčení pomocí Eset pořád přetrvává občasná modrá smrt. Snažím se to už druhý den řešit a dochází my síly, takže uvažuji na reinstalem. Už mám vše zálohováno.
Chronologický průběh:
- počátek modrých smrtí, poměrně častých, ale spíše nahodilých
- scan na viry, nalezen trojan, ale během scanu to padlo, a pak jsem již nenašel výpis
- scan Spybot - chyba v registrech a nějakej zápis ShopHome, nebo tak něco
- marné pokusy o aktualizaci Win XP x86 SP3 - chyba
- Ccleaner
- Secunia a instalace aktualizací
- poté se již aktualizace Win povedly, ale modrá smrti pokračují

větráček mám v NTB nový ani není teplý při smrti..

Takže jestli máte někdo chuť se do tohoto pustit, tady je log z RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-03-23 01:24:58
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (3%) free of 88 GB
Total RAM: 3071 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:26:22, on 23.3.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\USBStorage\USBDetector.exe
C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe
C:\Program Files\ProtectTools\Embedded Security Software\SpTna.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTServs.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ave2.cvc.cervantes.es/login.asp?numtira=3
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ArchiBar Toolbar - {24cc1362-11c6-4918-a2c0-b9ee5a563185} - C:\Program Files\ArchiBar\prxtbArc0.dll
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)
O2 - BHO: ArchiBar - {24cc1362-11c6-4918-a2c0-b9ee5a563185} - C:\Program Files\ArchiBar\prxtbArc0.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: ArchiBar Toolbar - {24cc1362-11c6-4918-a2c0-b9ee5a563185} - C:\Program Files\ArchiBar\prxtbArc0.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [USBDetector] C:\USBStorage\USBDetector.exe
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [PCSpeedUp] "C:\Program Files\Zrychleni Pocitace\PCSpeedUp.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Secunia PSI Tray.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download All by ASUS Download - C:\Program Files\ASUS\WL-500W Wireless Router Utilities\ASDownloadAll.htm
O8 - Extra context menu item: Download using ASUS Download - C:\Program Files\ASUS\WL-500W Wireless Router Utilities\ASDownload.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.cz/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 2113394171
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} (Java Plug-in 1.6.0_15) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate1c9982d278ca9d0) (gupdate1c9982d278ca9d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: JSUERXPIDLFJ - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JSUERXPIDLFJ.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: ORD Process PDF (ORD_ProcessAcrobat) - Unknown owner - C:\Program Files\Oce\Repro Desk\ORD_ProcessAcrobat.exe (file missing)
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files\Secunia\PSI\sua.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 14152 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Driver Fetch.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-195512369-4072681304-1623108014-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-195512369-4072681304-1623108014-500UA.job
C:\WINDOWS\tasks\Norton Security Scan for Administrator.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-195512369-4072681304-1623108014-500.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-195512369-4072681304-1623108014-500.job
C:\WINDOWS\tasks\Wise Registry Cleaner 4.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2011-01-30 64928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-09-29 325000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24cc1362-11c6-4918-a2c0-b9ee5a563185}]
ArchiBar Toolbar - C:\Program Files\ArchiBar\prxtbArc0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-29 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-23 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
HP Credential Manager for ProtectTools - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll [2005-03-03 50688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-03-23 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-09-29 325000]
{24cc1362-11c6-4918-a2c0-b9ee5a563185} - ArchiBar Toolbar - C:\Program Files\ArchiBar\prxtbArc0.dll [2011-01-17 175912]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WatchDog"=C:\Program Files\InterVideo\DVD Check\DVDCheck.exe []
"USBDetector"=C:\USBStorage\USBDetector.exe [2005-04-13 53248]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]
"TkBellExe"=C:\program files\real\realplayer\update\realsched.exe -osboot []
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-03-03 761948]
"Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2008-04-14 143872]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2005-05-06 716800]
"Scheduler"=C:\WINDOWS\SMINST\Scheduler.exe [2006-02-15 892928]
"Reminder"=C:\WINDOWS\Creator\Remind_XP.exe [2006-03-09 806912]
"Recguard"=C:\WINDOWS\Sminst\Recguard.exe [2005-12-20 1187840]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2006-05-08 131072]
"PTHOSTTR"=C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE [2006-02-14 122880]
"NPSStartup"= []
"MsmqIntCert"=regsvr32 /s mqrt.dll []
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2005-02-16 221184]
"hpWirelessAssistant"=C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe [2006-02-14 454656]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2006-02-22 40960]
"CognizanceTS"=C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll [2003-12-22 17920]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-10 932288]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2007-01-05 204288]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-01-26 16945032]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-02-23 133104]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2009-10-15 323392]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2010-07-29 95576]
"PCSpeedUp"=C:\Program Files\Zrychleni Pocitace\PCSpeedUp.exe [2010-11-14 947960]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Secunia PSI Tray.lnk - C:\Program Files\Secunia\PSI\psi_tray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-10 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IfxWlxEN]
C:\WINDOWS\system32\IfxWlxEN.dll [2005-08-19 389120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OneCard]
C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll [2005-07-25 40960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\mqsvc.exe"="C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing"
"C:\WINDOWS\SMINST\Scheduler.exe"="C:\WINDOWS\SMINST\Scheduler.exe:*:Enabled:Scheduler "
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Graphisoft\ArchiCAD 10\ArchiCAD.exe"="C:\Program Files\Graphisoft\ArchiCAD 10\ArchiCAD.exe:*:Enabled:ArchiCAD 10.0.0 Component"
"C:\Program Files\Graphisoft\ArchiCAD 11\ArchiCAD.exe"="C:\Program Files\Graphisoft\ArchiCAD 11\ArchiCAD.exe:*:Enabled:ArchiCAD 11.0.0 Component"
"C:\Casino\bwin Casino\casino.exe"="C:\Casino\bwin Casino\casino.exe:*:Enabled:casino"
"C:\Program Files\wincmd\TOTALCMD.EXE"="C:\Program Files\wincmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Accord\SmartWorks48PETrial\MeetingManager\SWReminder.exe"="C:\Program Files\Accord\SmartWorks48PETrial\MeetingManager\SWReminder.exe:*:Enabled:Reminder Handler"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Google\Google Updater\GoogleUpdater.exe"="C:\Program Files\Google\Google Updater\GoogleUpdater.exe:*:Enabled:GoogleUpdater"
"C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe"="C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Konzola Microsoft Management Console"
"C:\Program Files\Graphisoft\ArchiCAD 12\ArchiCAD.exe"="C:\Program Files\Graphisoft\ArchiCAD 12\ArchiCAD.exe:*:Enabled:ArchiCAD 12.0.0 Component"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\NinjaTrader 6.5\bin\NinjaTrader.exe"="C:\Program Files\NinjaTrader 6.5\bin\NinjaTrader.exe:*:Enabled:NinjaTrader application"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\Graphisoft\ArchiCAD 13\ArchiCAD.exe"="C:\Program Files\Graphisoft\ArchiCAD 13\ArchiCAD.exe:*:Enabled:ArchiCAD 13.0.0 Component"
"C:\utorrent-lite\utorrent.exe"="C:\utorrent-lite\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\WinSCP\WinSCP.exe"="C:\Program Files\WinSCP\WinSCP.exe:*:Enabled:WinSCP: SFTP, FTP and SCP client"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\NinjaTrader 7\bin\NinjaTrader.exe"="C:\Program Files\NinjaTrader 7\bin\NinjaTrader.exe:*:Enabled:NinjaTrader application"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\mqsvc.exe"="C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-03-23 01:24:58 ----D---- C:\rsit
2011-03-23 01:24:58 ----D---- C:\Program Files\trend micro
2011-03-23 01:08:31 ----D---- C:\Program Files\Zrychleni Pocitace
2011-03-23 01:08:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\OpenCandy
2011-03-23 01:08:16 ----D---- C:\Program Files\Winamp Detect
2011-03-23 00:59:19 ----A---- C:\WINDOWS\system32\javaws.exe
2011-03-23 00:59:19 ----A---- C:\WINDOWS\system32\javaw.exe
2011-03-23 00:59:19 ----A---- C:\WINDOWS\system32\java.exe
2011-03-23 00:26:14 ----D---- C:\cfb9e6fae513ad14e6adc14a4996e99c
2011-03-23 00:16:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2011-03-23 00:16:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-03-23 00:15:56 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2011-03-23 00:15:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2476687$
2011-03-23 00:15:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2485376$
2011-03-23 00:15:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-03-23 00:14:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-03-23 00:13:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2479628$
2011-03-23 00:13:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-03-23 00:13:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-03-23 00:13:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-03-23 00:12:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-03-23 00:12:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2011-03-23 00:12:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-03-23 00:12:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-03-23 00:12:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2011-03-23 00:05:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2011-03-23 00:05:23 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-03-23 00:05:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-03-23 00:04:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-03-23 00:04:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-03-23 00:03:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-03-23 00:03:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-03-23 00:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-03-23 00:02:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-03-23 00:02:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2011-03-23 00:02:14 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-03-23 00:01:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2011-03-23 00:01:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2011-03-23 00:01:20 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2011-03-23 00:00:52 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2011-03-23 00:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2011-03-22 23:54:07 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2011-03-22 23:53:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2011-03-22 23:40:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-03-22 23:40:13 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2011-03-22 23:32:07 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-03-22 23:31:47 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2011-03-22 23:31:28 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-03-22 23:31:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-03-22 23:30:54 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-03-22 23:30:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-03-22 23:30:23 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-03-22 23:29:52 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-03-22 23:29:35 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2011-03-22 23:29:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2011-03-22 23:28:43 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-03-22 23:28:26 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-03-22 23:28:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-03-22 23:27:56 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2011-03-22 23:27:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2011-03-22 23:27:11 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2011-03-22 23:26:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2011-03-22 23:26:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2011-03-22 23:26:25 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2011-03-22 23:26:11 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2011-03-22 23:25:56 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2011-03-22 23:25:40 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2011-03-22 23:25:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2011-03-22 23:25:16 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2011-03-22 23:25:06 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2011-03-22 23:24:52 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2011-03-22 23:24:33 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2011-03-22 23:24:28 ----A---- C:\WINDOWS\imsins.BAK
2011-03-22 23:24:15 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2011-03-22 23:13:38 ----N---- C:\WINDOWS\system32\browserchoice.exe
2011-03-22 17:19:29 ----SD---- C:\ComboFix
2011-03-22 16:18:20 ----ASH---- C:\hiberfil.sys
2011-03-22 16:15:28 ----A---- C:\WINDOWS\ntbtlog.txt
2011-03-22 11:21:43 ----A---- C:\Boot.bak
2011-03-22 11:21:38 ----RASHD---- C:\cmdcons
2011-03-22 11:17:15 ----A---- C:\WINDOWS\zip.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\SWSC.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\SWREG.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\sed.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\PEV.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\NIRCMD.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\MBR.exe
2011-03-22 11:17:15 ----A---- C:\WINDOWS\grep.exe
2011-03-22 11:17:01 ----D---- C:\WINDOWS\ERDNT
2011-03-22 11:13:53 ----D---- C:\Qoobox
2011-03-22 11:07:29 ----D---- C:\WINDOWS\system32\drivers\NSS
2011-03-22 11:07:29 ----D---- C:\Program Files\Norton Security Scan
2011-03-22 11:07:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2011-03-22 11:07:26 ----D---- C:\Program Files\NortonInstaller
2011-03-22 11:07:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2011-03-22 02:32:47 ----D---- C:\Program Files\CCleaner
2011-03-22 02:14:20 ----D---- C:\Documents and Settings\Administrator\Data aplikací\WinRAR
2011-03-22 01:59:01 ----D---- C:\Program Files\Microsoft Security Client
2011-03-22 01:57:51 ----D---- C:\bf62149516fa7544be358e1a0aa004a8
2011-03-22 00:50:27 ----D---- C:\Program Files\QuickTime
2011-03-22 00:49:27 ----D---- C:\Program Files\Common Files\Apple
2011-03-22 00:49:10 ----D---- C:\Program Files\Apple Software Update
2011-03-22 00:49:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2011-03-21 23:17:36 ----D---- C:\Program Files\Secunia
2011-03-21 21:14:07 ----D---- C:\WINDOWS\pss
2011-03-21 20:57:12 ----D---- C:\Documents and Settings\All Users\Data aplikací\SecTaskMan
2011-03-21 20:57:03 ----D---- C:\Program Files\Security Task Manager
2011-03-14 12:31:54 ----A---- C:\WINDOWS\system32\drivers\ss_bmdm.sys
2011-03-14 12:31:54 ----A---- C:\WINDOWS\system32\drivers\ss_bmdfl.sys
2011-03-14 12:31:54 ----A---- C:\WINDOWS\system32\drivers\ss_bcmnt.sys
2011-03-14 12:31:53 ----A---- C:\WINDOWS\system32\drivers\ss_bwhnt.sys
2011-03-14 12:31:53 ----A---- C:\WINDOWS\system32\drivers\ss_bbus.sys
2011-03-14 12:26:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Samsung
2011-03-07 10:56:30 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IGC
2011-03-07 10:55:37 ----D---- C:\Program Files\IGC

======List of files/folders modified in the last 1 months======

2011-03-23 01:24:58 ----D---- C:\Program Files
2011-03-23 01:19:31 ----D---- C:\Documents and Settings\Administrator\Data aplikací\DNA
2011-03-23 01:14:27 ----RSD---- C:\WINDOWS\assembly
2011-03-23 01:14:19 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-23 01:08:43 ----D---- C:\Program Files\Winamp
2011-03-23 01:07:50 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Winamp
2011-03-23 01:03:34 ----SHD---- C:\WINDOWS\Installer
2011-03-23 01:02:54 ----SHD---- C:\Config.Msi
2011-03-23 01:01:39 ----RSD---- C:\WINDOWS\Fonts
2011-03-23 01:01:21 ----D---- C:\Program Files\OpenOffice.org 3
2011-03-23 00:59:19 ----D---- C:\WINDOWS\Temp
2011-03-23 00:59:19 ----D---- C:\WINDOWS\system32
2011-03-23 00:58:58 ----D---- C:\Program Files\Java
2011-03-23 00:57:56 ----D---- C:\WINDOWS\WinSxS
2011-03-23 00:48:29 ----D---- C:\Program Files\Common Files\Java
2011-03-23 00:47:55 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-03-23 00:36:32 ----D---- C:\WINDOWS\SoftwareDistribution
2011-03-23 00:34:49 ----D---- C:\Program Files\Microsoft Silverlight
2011-03-23 00:33:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-23 00:30:40 ----D---- C:\WINDOWS
2011-03-23 00:30:29 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-23 00:29:27 ----D---- C:\WINDOWS\system32\CatRoot2
2011-03-23 00:29:25 ----D---- C:\Program Files\DNA
2011-03-23 00:29:07 ----SD---- C:\WINDOWS\Tasks
2011-03-23 00:29:02 ----D---- C:\WINDOWS\SMINST
2011-03-23 00:28:52 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-03-23 00:28:38 ----D---- C:\WINDOWS\Minidump
2011-03-23 00:24:14 ----RSHD---- C:\WINDOWS\system32\dllcache
2011-03-23 00:22:13 ----D---- C:\Program Files\Internet Explorer
2011-03-23 00:22:12 ----D---- C:\WINDOWS\AppPatch
2011-03-23 00:20:26 ----A---- C:\WINDOWS\wincmd.ini
2011-03-23 00:16:43 ----D---- C:\WINDOWS\Debug
2011-03-23 00:16:34 ----HD---- C:\WINDOWS\inf
2011-03-23 00:14:59 ----HD---- C:\WINDOWS\$hf_mig$
2011-03-23 00:12:54 ----D---- C:\WINDOWS\system32\drivers
2011-03-23 00:12:25 ----D---- C:\Program Files\Outlook Express
2011-03-23 00:00:59 ----D---- C:\Program Files\Movie Maker
2011-03-22 23:30:28 ----D---- C:\WINDOWS\Prefetch
2011-03-22 22:37:57 ----RD---- C:\deel
2011-03-22 21:15:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google Updater
2011-03-22 17:27:26 ----D---- C:\Program Files\Common Files
2011-03-22 16:50:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-03-22 16:50:42 ----D---- C:\Program Files\ESET
2011-03-22 16:20:11 ----D---- C:\WINDOWS\Help
2011-03-22 11:21:43 ----RASH---- C:\boot.ini
2011-03-22 11:17:09 ----SHD---- C:\System Volume Information
2011-03-22 11:17:09 ----D---- C:\WINDOWS\system32\Restore
2011-03-22 11:07:37 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-03-22 11:04:35 ----A---- C:\WINDOWS\win.ini
2011-03-22 11:04:35 ----A---- C:\WINDOWS\system.ini
2011-03-22 02:38:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-03-22 02:38:54 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Media Player Classic
2011-03-22 01:32:07 ----A---- C:\WINDOWS\SWReminder.INI
2011-03-22 01:31:36 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-03-22 01:05:22 ----D---- C:\Program Files\WinRAR
2011-03-22 00:58:24 ----D---- C:\WINDOWS\system32\Adobe
2011-03-22 00:50:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2011-03-22 00:31:21 ----RD---- C:\Program Files\Skype
2011-03-22 00:31:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-03-21 23:14:50 ----D---- C:\Program Files\Common Files\Autodesk Shared
2011-03-21 23:14:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Autodesk
2011-03-21 23:14:49 ----D---- C:\Program Files\AutoCAD 2009
2011-03-21 23:00:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2011-03-21 23:00:38 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Real
2011-03-21 22:53:42 ----HD---- C:\Program Files\InstallShield Installation Information
2011-03-21 14:48:27 ----D---- C:\Program Files\ArchiBar
2011-03-21 14:48:23 ----D---- C:\Program Files\ConduitEngine
2011-03-21 14:48:22 ----A---- C:\WINDOWS\system32\ConduitEngine.tmp
2011-03-18 23:55:31 ----D---- C:\Documents and Settings\Administrator\Data aplikací\vlc
2011-03-18 23:47:06 ----D---- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2011-03-16 10:11:27 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM
2011-03-14 12:35:11 ----D---- C:\WINDOWS\system32\CatRoot
2011-03-14 12:33:19 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-03-14 12:33:05 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
2011-03-14 12:28:49 ----D---- C:\Program Files\Samsung
2011-03-06 15:45:28 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Abvent_Artlantis2
2011-03-05 10:01:56 ----D---- C:\Program Files\Mozilla Thunderbird
2011-03-05 00:30:52 ----A---- C:\WINDOWS\wcx_ftp.ini
2011-03-02 19:56:50 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Disk Filter Driver; C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [2006-01-10 17920]
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\System32\DRIVERS\iaStor.sys [2005-10-12 874240]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2003-02-27 63424]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2003-02-14 6432]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 eabfiltr;eabfiltr; C:\WINDOWS\system32\DRIVERS\eabfiltr.sys [2005-09-19 7808]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\WINDOWS\System32\drivers\psd.sys [2005-10-25 35488]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2003-02-27 49792]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2008-05-06 16512]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-01-30 13059]
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey.sys [2007-05-09 72704]
R3 Accelerometer;Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2006-01-10 22016]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-05-03 178176]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-10 1543168]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2006-01-12 142720]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-02-15 1342570]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 GTIPCI21;GTIPCI21; C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 87936]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2005-09-19 9344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2006-01-30 1035008]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2006-01-30 201600]
R3 IFXTPM;IFXTPM; C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-06-10 35968]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MQAC;Message Queuing access control; \??\C:\WINDOWS\system32\drivers\mqac.sys []
R3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
R3 RMCAST;Reliable Multicast Protocol driver; \??\C:\WINDOWS\system32\drivers\RMCast.sys []
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-03-03 192736]
R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-09-20 162432]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys [2006-01-19 1428096]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2006-01-30 718464]
S1 ffbe1213;ffbe1213; C:\WINDOWS\System32\drivers\ffbe1213.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
S3 ATSWPDRV;AuthenTec TruePrint USB Driver (AES2500); C:\WINDOWS\system32\DRIVERS\ATSwpDrv.sys [2006-03-30 130432]
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2006-02-15 401664]
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2006-02-15 30363]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2006-02-15 148168]
S3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2006-02-15 30189]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2006-02-16 57096]
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 eabusb;eabusb; C:\WINDOWS\system32\DRIVERS\eabusb.sys [2005-09-19 5760]
S3 IpwP;IPWireless 3G Network Adapter; C:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2008-03-27 51040]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
S3 se44bus;Sony Ericsson Device 068 driver (WDM); C:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 61536]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 9360]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 97088]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\se44mgmt.sys [2006-11-30 88624]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS); C:\WINDOWS\system32\DRIVERS\se44nd5.sys [2006-11-30 18704]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-11-30 86432]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM); C:\WINDOWS\system32\DRIVERS\se44unic.sys [2006-11-30 90800]
S3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2001-10-24 35913]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
S3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20071031.003\symidsco.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2005-10-11 110080]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2007-10-22 646392]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASChannel;Local Communication Channel; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-10 405504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-02-15 258103]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2010-07-29 238952]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 IFXSpMgtSrv;Security Platform Management Service; C:\WINDOWS\system32\IFXSPMGT.exe [2006-01-10 458752]
R2 IFXTCS;Trusted Platform Core Service; C:\WINDOWS\system32\IFXTCS.exe [2005-09-02 647168]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-03-23 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-07-20 61440]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 MSMQ;Message Queuing; C:\WINDOWS\system32\mqsvc.exe [2008-04-14 4608]
R2 MSMQTriggers;Message Queuing Triggers; C:\WINDOWS\system32\mqtgsvc.exe [2008-04-14 117248]
R2 PersonalSecureDriveService;Personal Secure Drive Service; C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE [2005-08-19 173600]
R2 ProtexisLicensing;ProtexisLicensing; C:\Program Files\Common Files\Protexis\License Service\PSIService.exe [2006-11-02 174656]
R2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [2011-01-10 993848]
R2 Secunia Update Agent;Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [2011-01-10 399416]
R2 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S2 gupdate1c9982d278ca9d0;Google Update Service (gupdate1c9982d278ca9d0); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-26 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-29 183280]
S2 ORD_ProcessAcrobat;ORD Process PDF; C:\Program Files\Oce\Repro Desk\ORD_ProcessAcrobat.exe []
S2 PCA;PC Angel; C:\WINDOWS\SMINST\PCAngel.exe [2006-01-12 294912]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Imapi Helper;Imapi Helper; C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe [2006-01-04 163840]
S3 JSUERXPIDLFJ;JSUERXPIDLFJ; C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JSUERXPIDLFJ.exe []
S3 nosGetPlusHelper;getPlus(R) Helper 3004; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 07:01
od vyosek
Zdravim a pekny den preji :)

:arrow: Jeste tam nejaka havet zustala :arcisit:

:arrow: Doporucuji odinstalovat Spybot - Search & Destroy - program ma uz nejlepsi leta davno za sebou a posledni cca 3 roky neni schopen celit aktualnim hrozbam - po ukonceni leceni tam dame neco lepcejsiho :wink:

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 10:34
od honzage
Děkuji moc za odpověď.

Nějak semi nedaří:
- pokusil jsem se odinstalovat Spybot a během toho modrá smrt s výpisem o Win32k.sys - BF8022BA
- po opětovné nastartování jsem dohledával zbytky a odinstaloval.
- Poté dle návodu spustil ComboFix a asi u 20. fáze opět smrt tentokrát s BAD_POOL_HEADER

- v C:\Combofix\Combofix.txt jsem našel pouze toto:

ComboFix 11-03-22.08 - Administrator 23.03.2011 9:44:10.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3071.2467 [GMT 1:00]
Spuštěný z: C:\Documents and Settings\Administrator\Plocha\ComboFix.exe
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

Ani jsem netušil, že tam toho Nortona mám a tak ho odinstaluji a zkusím ComboFix znovu.

Poté se ozvu, děkuji.

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 10:35
od vyosek
:arrow: Prihlaste se do nouzoveho rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)

:arrow: Prejmenujte ComboFix na Beruska.com a spusste jej

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 10:57
od honzage
Tak se opět pochlubím, ale bohužel nikoliv s úspěchem.

Po nastartování do Nouzového režimu, přejmenování ComboFixu na Beruska.com a spusteni vyskočilo okno:

Vypnutí systému, ukončete všechny programy atd........ a odpočítávání na 1 min.

Na tohle jsem zareagoval tím, že jsem chtěl spustit konzoli a napsat do ni Shutdown /a , nu ale neuvědomil jsem si, že už jedna konzola jede s Combofixem, takže jsem po dalším restartu.

Mám ke ComboFixu trošku respekt, proto se ptám, mám ho ještě nějak přejmenovat....

Děkuji HH

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 11:03
od vyosek
:arrow: CFko zatim tedy nechame

:arrow: Podivejte se do slozky c:\windows\minidump jestlitam nemate nejake soubory, pokud ano, tak je dejte do raru a uploadnete mi je sem http://www.vyosek.ic.cz/havet/uploader.php

:arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Utilitu spustte a prikazte ji, at skenuje - klik na Start Scan
  • Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
  • Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
  • Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
  • Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
  • Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 11:14
od honzage
Scanoval jsem v nouzovém režimu se sítí:

Log je tady:

2011/03/23 11:10:36.0984 0524 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/23 11:10:37.0359 0524 ================================================================================
2011/03/23 11:10:37.0359 0524 SystemInfo:
2011/03/23 11:10:37.0359 0524
2011/03/23 11:10:37.0359 0524 OS Version: 5.1.2600 ServicePack: 3.0
2011/03/23 11:10:37.0359 0524 Product type: Workstation
2011/03/23 11:10:37.0359 0524 ComputerName: HH
2011/03/23 11:10:37.0359 0524 UserName: Administrator
2011/03/23 11:10:37.0359 0524 Windows directory: C:\WINDOWS
2011/03/23 11:10:37.0359 0524 System windows directory: C:\WINDOWS
2011/03/23 11:10:37.0359 0524 Processor architecture: Intel x86
2011/03/23 11:10:37.0359 0524 Number of processors: 2
2011/03/23 11:10:37.0359 0524 Page size: 0x1000
2011/03/23 11:10:37.0359 0524 Boot type: Safe boot with network
2011/03/23 11:10:37.0359 0524 ================================================================================
2011/03/23 11:10:37.0859 0524 Initialize success
2011/03/23 11:10:45.0062 0168 ================================================================================
2011/03/23 11:10:45.0062 0168 Scan started
2011/03/23 11:10:45.0062 0168 Mode: Manual;
2011/03/23 11:10:45.0062 0168 ================================================================================
2011/03/23 11:10:46.0953 0168 Accelerometer (2ad11b75224bc6c54735fb6853105b8b) C:\WINDOWS\system32\DRIVERS\Accelerometer.sys
2011/03/23 11:10:47.0046 0168 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/03/23 11:10:47.0078 0168 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/03/23 11:10:47.0171 0168 ADIHdAudAddService (c6f1bba566dd2eef2d8fb9d25e8eb9a4) C:\WINDOWS\system32\drivers\ADIHdAud.sys
2011/03/23 11:10:47.0265 0168 AEAudioService (c984de22ed71414abc42c1e03d412e33) C:\WINDOWS\system32\drivers\AEAudio.sys
2011/03/23 11:10:47.0343 0168 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/03/23 11:10:47.0578 0168 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/03/23 11:10:47.0796 0168 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/03/23 11:10:47.0937 0168 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/03/23 11:10:48.0156 0168 ASNDIS5 (05a56c3156e1b6cc7bbd8e1d54d491f2) C:\WINDOWS\system32\ASNDIS5.SYS
2011/03/23 11:10:48.0265 0168 Aspi32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys
2011/03/23 11:10:48.0484 0168 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/03/23 11:10:48.0515 0168 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/03/23 11:10:48.0718 0168 ati2mtag (c53d41d2045f1038a185d6cc70f96b44) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2011/03/23 11:10:48.0843 0168 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/03/23 11:10:49.0031 0168 ATSWPDRV (002ecb6f1197a7754cc87f2073f41841) C:\WINDOWS\system32\DRIVERS\ATSwpDrv.sys
2011/03/23 11:10:49.0109 0168 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/03/23 11:10:49.0171 0168 b57w2k (c0acd392ece55784884cc208aafa06ce) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
2011/03/23 11:10:49.0218 0168 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/03/23 11:10:49.0281 0168 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
2011/03/23 11:10:49.0328 0168 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
2011/03/23 11:10:49.0593 0168 btaudio (df74d51ba41ad84d72b2cb844337d3ed) C:\WINDOWS\system32\drivers\btaudio.sys
2011/03/23 11:10:49.0671 0168 BTDriver (048f90a830e4dfbe050ea9f4c9f98ae3) C:\WINDOWS\system32\DRIVERS\btport.sys
2011/03/23 11:10:49.0765 0168 BTKRNL (6b6ad8cbf3984c3b39d4d06c38f52010) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
2011/03/23 11:10:50.0031 0168 BTWDNDIS (8aa19a3c1cbdfeef118f0e4ef874a8a7) C:\WINDOWS\system32\DRIVERS\btwdndis.sys
2011/03/23 11:10:50.0109 0168 btwmodem (8b17bf2af7c388a59885d147312d3945) C:\WINDOWS\system32\DRIVERS\btwmodem.sys
2011/03/23 11:10:50.0171 0168 BTWUSB (00c8988da469e4ac087539bd77420123) C:\WINDOWS\system32\Drivers\btwusb.sys
2011/03/23 11:10:50.0328 0168 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/03/23 11:10:50.0453 0168 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/03/23 11:10:50.0671 0168 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/03/23 11:10:50.0703 0168 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/03/23 11:10:50.0843 0168 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/03/23 11:10:50.0937 0168 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/03/23 11:10:51.0187 0168 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/03/23 11:10:51.0281 0168 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
2011/03/23 11:10:51.0671 0168 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
2011/03/23 11:10:51.0718 0168 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/03/23 11:10:51.0812 0168 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/03/23 11:10:51.0984 0168 DNE (2eddbb3ef1dd5a28cb07c149d36e7286) C:\WINDOWS\system32\DRIVERS\dne2000.sys
2011/03/23 11:10:52.0109 0168 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/03/23 11:10:52.0140 0168 eabfiltr (b5cb3084046146fd2587d8c9b219feb4) C:\WINDOWS\system32\DRIVERS\eabfiltr.sys
2011/03/23 11:10:52.0203 0168 eabusb (231f4547ae1e4b3e60eca66c3a96d218) C:\WINDOWS\system32\DRIVERS\eabusb.sys
2011/03/23 11:10:52.0437 0168 eeCtrl (31c959319ef45b548d2111e338412270) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2011/03/23 11:10:52.0703 0168 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/03/23 11:10:52.0765 0168 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/03/23 11:10:52.0875 0168 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
2011/03/23 11:10:52.0921 0168 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/03/23 11:10:53.0000 0168 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/03/23 11:10:53.0093 0168 FsUsbExDisk (cbe5f69a5e5b918225f420ba748f3742) C:\WINDOWS\system32\FsUsbExDisk.SYS
2011/03/23 11:10:53.0156 0168 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/03/23 11:10:53.0343 0168 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/03/23 11:10:53.0437 0168 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/03/23 11:10:53.0484 0168 GTIPCI21 (b6b1f53f585b41091eb3586f8297a379) C:\WINDOWS\system32\DRIVERS\gtipci21.sys
2011/03/23 11:10:53.0546 0168 HBtnKey (4d4d97671c63c3af869b3518e6054204) C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
2011/03/23 11:10:53.0609 0168 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/03/23 11:10:53.0687 0168 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/03/23 11:10:53.0750 0168 hpdskflt (b5e68a5d9e0aac82e4ddd340e1f0274a) C:\WINDOWS\system32\DRIVERS\hpdskflt.sys
2011/03/23 11:10:53.0859 0168 HSFHWAZL (89e256c5f5346be265d9f86ac8625d4f) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2011/03/23 11:10:53.0968 0168 HSF_DPV (0e44af3828111d4c3e73c33ac95226d8) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2011/03/23 11:10:54.0203 0168 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/03/23 11:10:54.0359 0168 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/03/23 11:10:54.0484 0168 iaStor (309c4d86d989fb1fcf64bd30dc81c51b) C:\WINDOWS\system32\DRIVERS\iaStor.sys
2011/03/23 11:10:54.0750 0168 IFXTPM (0b556e950404d90d097c687e65238730) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS
2011/03/23 11:10:54.0812 0168 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/03/23 11:10:54.0968 0168 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/03/23 11:10:55.0015 0168 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/03/23 11:10:55.0062 0168 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/03/23 11:10:55.0125 0168 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/03/23 11:10:55.0171 0168 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/03/23 11:10:55.0234 0168 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/03/23 11:10:55.0468 0168 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/03/23 11:10:55.0546 0168 IpwP (d3f6df74534cfdccf49803e739acaea0) C:\WINDOWS\system32\DRIVERS\ipw3gnet.sys
2011/03/23 11:10:55.0593 0168 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/03/23 11:10:55.0656 0168 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/03/23 11:10:55.0734 0168 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/03/23 11:10:55.0781 0168 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/03/23 11:10:55.0828 0168 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/03/23 11:10:55.0906 0168 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/03/23 11:10:56.0234 0168 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/03/23 11:10:56.0281 0168 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/03/23 11:10:56.0375 0168 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
2011/03/23 11:10:56.0453 0168 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/03/23 11:10:56.0515 0168 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/03/23 11:10:56.0578 0168 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/03/23 11:10:56.0640 0168 MQAC (70c14f5cca5cf73f8a645c73a01d8726) C:\WINDOWS\system32\drivers\mqac.sys
2011/03/23 11:10:56.0875 0168 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
2011/03/23 11:10:57.0062 0168 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
2011/03/23 11:10:57.0281 0168 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/03/23 11:10:57.0390 0168 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/03/23 11:10:57.0515 0168 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/03/23 11:10:57.0562 0168 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/03/23 11:10:57.0765 0168 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/03/23 11:10:57.0812 0168 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/03/23 11:10:57.0890 0168 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/03/23 11:10:57.0937 0168 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/03/23 11:10:58.0000 0168 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/03/23 11:10:58.0046 0168 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/03/23 11:10:58.0093 0168 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/03/23 11:10:58.0156 0168 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/03/23 11:10:58.0218 0168 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/03/23 11:10:58.0390 0168 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/03/23 11:10:58.0531 0168 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/03/23 11:10:58.0656 0168 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/03/23 11:10:58.0781 0168 nmwcd (696b37ea78f9d9767a2f18ba0304a51a) C:\WINDOWS\system32\drivers\nmwcd.sys
2011/03/23 11:10:58.0843 0168 nmwcdc (bbb6010fc01d9239d88fcdf133e03ff0) C:\WINDOWS\system32\drivers\nmwcdc.sys
2011/03/23 11:10:58.0906 0168 nmwcdcj (4c3726467d67483f054c88f058e9c153) C:\WINDOWS\system32\drivers\nmwcdcj.sys
2011/03/23 11:10:58.0968 0168 nmwcdcm (4c3726467d67483f054c88f058e9c153) C:\WINDOWS\system32\drivers\nmwcdcm.sys
2011/03/23 11:10:59.0093 0168 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/03/23 11:10:59.0203 0168 NSNDIS5 (53f7546e8daefb3a0813f5e19c4613c9) C:\WINDOWS\system32\NSNDIS5.SYS
2011/03/23 11:10:59.0296 0168 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/03/23 11:10:59.0421 0168 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/03/23 11:10:59.0484 0168 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/03/23 11:10:59.0562 0168 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/03/23 11:10:59.0640 0168 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/03/23 11:10:59.0734 0168 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/03/23 11:10:59.0812 0168 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/03/23 11:10:59.0859 0168 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/03/23 11:10:59.0968 0168 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
2011/03/23 11:11:00.0046 0168 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/03/23 11:11:00.0156 0168 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/03/23 11:11:00.0250 0168 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/03/23 11:11:00.0640 0168 PersonalSecureDrive (9f09361eeae6180ccdc8e99bac641943) C:\WINDOWS\System32\drivers\psd.sys
2011/03/23 11:11:00.0796 0168 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/03/23 11:11:00.0859 0168 prodrv06 (44486ecb7433ce606a2b3742b73a09b3) C:\WINDOWS\System32\drivers\prodrv06.sys
2011/03/23 11:11:00.0890 0168 prohlp02 (b30dfde3429418ed53b354ef7abef5b5) C:\WINDOWS\system32\drivers\prohlp02.sys
2011/03/23 11:11:00.0968 0168 prosync1 (1626f275f026fb7808de35ef0762539f) C:\WINDOWS\system32\drivers\prosync1.sys
2011/03/23 11:11:01.0062 0168 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/03/23 11:11:01.0203 0168 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\WINDOWS\system32\DRIVERS\psi_mf.sys
2011/03/23 11:11:01.0265 0168 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/03/23 11:11:01.0343 0168 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/03/23 11:11:01.0687 0168 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/03/23 11:11:01.0750 0168 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
2011/03/23 11:11:01.0812 0168 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/03/23 11:11:01.0906 0168 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/03/23 11:11:02.0000 0168 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/03/23 11:11:02.0031 0168 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/03/23 11:11:02.0109 0168 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/03/23 11:11:02.0218 0168 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/03/23 11:11:02.0312 0168 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/03/23 11:11:02.0375 0168 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/03/23 11:11:02.0500 0168 RMCAST (96f7a9a7bf0c9c0440a967440065d33c) C:\WINDOWS\system32\drivers\RMCast.sys
2011/03/23 11:11:02.0718 0168 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2011/03/23 11:11:02.0796 0168 se44bus (3097cff31374e309a8950775111a52bd) C:\WINDOWS\system32\DRIVERS\se44bus.sys
2011/03/23 11:11:02.0843 0168 se44mdfl (4a03dd4fb5b7cb2c53d8fe8848455a4e) C:\WINDOWS\system32\DRIVERS\se44mdfl.sys
2011/03/23 11:11:02.0921 0168 se44mdm (2ca2e66a945b5de1228ab5f5341d0e97) C:\WINDOWS\system32\DRIVERS\se44mdm.sys
2011/03/23 11:11:03.0000 0168 se44mgmt (1977fb3c58c7c714a0ba8ad7960efb26) C:\WINDOWS\system32\DRIVERS\se44mgmt.sys
2011/03/23 11:11:03.0031 0168 se44nd5 (9bd87c965eb93475bcbd732936f46e7c) C:\WINDOWS\system32\DRIVERS\se44nd5.sys
2011/03/23 11:11:03.0078 0168 se44obex (5eff45d05677695417c523d89c1757b6) C:\WINDOWS\system32\DRIVERS\se44obex.sys
2011/03/23 11:11:03.0125 0168 se44unic (037d2d26f91ca67bad9da36fe5c88640) C:\WINDOWS\system32\DRIVERS\se44unic.sys
2011/03/23 11:11:03.0187 0168 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/03/23 11:11:03.0390 0168 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/03/23 11:11:03.0500 0168 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/03/23 11:11:03.0640 0168 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/03/23 11:11:03.0781 0168 SMCIRDA (12224ac3a6fd3577036f038a0c03f2f5) C:\WINDOWS\system32\DRIVERS\smcirda.sys
2011/03/23 11:11:03.0890 0168 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/03/23 11:11:04.0000 0168 sptd (e8b705f9abe446aaf7a315ef8b4aea5a) C:\WINDOWS\System32\Drivers\sptd.sys
2011/03/23 11:11:04.0140 0168 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/03/23 11:11:04.0265 0168 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/03/23 11:11:04.0375 0168 ss_bbus (3f0164fbc0bd1adbd02df9759181451a) C:\WINDOWS\system32\DRIVERS\ss_bbus.sys
2011/03/23 11:11:04.0437 0168 ss_bmdfl (b89d62206034e5fe573c80a24dd55675) C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys
2011/03/23 11:11:04.0484 0168 ss_bmdm (1ed0fcea586fe2a416ee15196e5631dd) C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys
2011/03/23 11:11:04.0625 0168 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/03/23 11:11:04.0718 0168 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/03/23 11:11:05.0187 0168 SynTP (c9a1785cc0d7a040dd0fdbfeaa8be135) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/03/23 11:11:05.0234 0168 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/03/23 11:11:05.0406 0168 Tcpip (cbeebeb899e31ef52b962cb31fc8ca5c) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/03/23 11:11:05.0546 0168 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/03/23 11:11:05.0593 0168 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/03/23 11:11:05.0640 0168 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/03/23 11:11:05.0750 0168 tifm21 (9179e07503630d6fb2e4162ff0196191) C:\WINDOWS\system32\drivers\tifm21.sys
2011/03/23 11:11:05.0906 0168 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/03/23 11:11:06.0015 0168 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/03/23 11:11:06.0203 0168 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/03/23 11:11:06.0281 0168 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/03/23 11:11:06.0375 0168 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/03/23 11:11:06.0468 0168 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/03/23 11:11:06.0531 0168 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/03/23 11:11:06.0593 0168 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/03/23 11:11:06.0640 0168 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/03/23 11:11:06.0687 0168 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/03/23 11:11:06.0796 0168 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/03/23 11:11:06.0921 0168 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/03/23 11:11:07.0062 0168 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2011/03/23 11:11:07.0203 0168 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/03/23 11:11:07.0390 0168 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/03/23 11:11:07.0546 0168 WIBUKEY (afcea7939925378f867dde6af76f3924) C:\WINDOWS\system32\DRIVERS\WibuKey.sys
2011/03/23 11:11:07.0625 0168 winachsf (214bc3ad84907ad6ad655ac5465f449a) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/03/23 11:11:07.0953 0168 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
2011/03/23 11:11:08.0078 0168 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys
2011/03/23 11:11:08.0203 0168 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/03/23 11:11:08.0234 0168 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/03/23 11:11:08.0609 0168 ================================================================================
2011/03/23 11:11:08.0609 0168 Scan finished
2011/03/23 11:11:08.0609 0168 ================================================================================

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 12:35
od vyosek

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 14:06
od honzage
Tak opět jsem selhal.

AVPTool je taky nahranej.

Vypnul jsem obnovení, vyčistil CCleanem a pustil AVPTool. Po chvilce opět modrá smrt. Zkusil jsem to pak ještě jednou a opět to samé, výpis smrti s problémem ve Win32k.sys

Zpráva z AVPTool je opravdu krátká:

Automatická kontrola: selhání (události: 1, objekty: 0, čas: Neznámý)
23.3.2011 13:18:23 Úloha byla spuštěna

Tak už nevím, kdybych měl CDś, co jsem si před dvěma lety udělal pro obnovení systému udělal, tak bych do nich asi šel, ale asi by byly už dost zastaralé.

Máte pro mě ještě nějakou radu??
S pozdravem Honzage

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 15:58
od vyosek
Vydrzte prosim, poprosim kolegu aby koukl na ty minidumpy - to jsou vypisy tesne pred modrou smrti. Kolega tu byva ovsem az v noci, takze prosim o strpeni...

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 17:54
od honzage
děkuji i za tu vstříctnost
Vydržím, ted jsi jdu unavit tělo sportem, aby má skepse nepřevládla nad rozumem.

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 23 bře 2011 20:04
od vyosek
Ok, kolega na to mrkne v noci :wink:

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 24 bře 2011 13:21
od honzage
Tak jsem tento den zahájil úspěšněji.

Podíval jsem se trošku HW a myslím že veškeré modré smrti byly způsobeny vadnou pamětí, 2G jsem vyndal a už to zas jede stabilně, kdyžtak pls dejte vědět kolegovi, ať už se mnou neztrácí čas.
Ještě jsem to proskenoval pomocí AVPTool, něco to našlo, ale asi nic zásadního.
Nevím jestli ještě mám sahat na ComboFix pro dočištění ???
Jinak děkuji moc za ochotu:

Automatická kontrola: selhání (události: 1, objekty: 0, čas: Neznámý)
23.3.2011 13:18:23 Úloha byla spuštěna
Automatická kontrola: selhání (události: 1, objekty: 0, čas: Neznámý)
23.3.2011 13:46:59 Úloha byla spuštěna
Automatická kontrola: zastaveno před 21 hod. (události: 1, objekty: 3165, čas: 00:35:30)
23.3.2011 15:15:08 Úloha byla spuštěna
Automatická kontrola: selhání (události: 1, objekty: 0, čas: Neznámý)
23.3.2011 17:55:04 Úloha byla spuštěna
Automatická kontrola: dokončeno před 12 min. (události: 11, objekty: 499329, čas: 01:54:46)
24.3.2011 11:56:34 Odstraněno: Exploit.Java.CVE-2010-0840.d C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\42\38a7c66a-7fc77fd3/langdriver/translator.class
24.3.2011 11:56:32 Zjištěno: Exploit.Java.CVE-2010-0840.d C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\42\38a7c66a-7fc77fd3/langdriver/translator.class
24.3.2011 11:56:31 Odstraněno: Exploit.Java.Agent.ag C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\32\1e118a0-2d7406d1/total/Server2.class
24.3.2011 11:56:31 Zjištěno: Exploit.Java.Agent.ag C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\32\1e118a0-2d7406d1/total/Server2.class
24.3.2011 11:56:31 Odstraněno: Exploit.Java.Agent.ag C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\32\1e118a0-2d7406d1/total/Server1.class
24.3.2011 11:56:31 Zjištěno: Exploit.Java.Agent.ag C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\32\1e118a0-2d7406d1/total/Server1.class
24.3.2011 11:56:31 Odstraněno: Exploit.Java.Agent.ag C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\32\1e118a0-2d7406d1/total/AServers.class
24.3.2011 11:56:31 Odstraněno: Exploit.Java.CVE-2010-0840.c C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\16\69ac9c90-1a4e6560/plugin/sportGame.class
24.3.2011 11:56:29 Zjištěno: Exploit.Java.Agent.ag C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\32\1e118a0-2d7406d1/total/AServers.class
24.3.2011 11:56:29 Zjištěno: Exploit.Java.CVE-2010-0840.c C:\Documents and Settings\Administrator\Data aplikací\Sun\Java\Deployment\cache\6.0\16\69ac9c90-1a4e6560/plugin/sportGame.class
24.3.2011 11:06:12 Úloha byla spuštěna

Re: Neočekávané restarty po vyléčení trojanů

Napsal: 24 bře 2011 13:31
od vyosek
AVPTool nenasel nic zasadniho...

Pokud tedy nejsou problemy, je to z nase strany vse :turned: