Zavirovaný počítač,možná falešná detekce MBAM
Napsal: 28 bře 2011 20:10
Dobrý den,
Měl bych tu jeden problém s počítačem.
Dne 26.3.2011 jsem provedl rychlý sken programem MBAM a po skončení, MBAM detekoval 23 infikovaných souborů. Dal jsem tedy odstranit všechny infikované objekty a restartoval počítač. Poté jsem znovu provedl rychlý sken MBAM a opět detekoval 23 infikovaných souborů. Rozhodl jsem se tedy,použít Avenger ,po restartu pc vyšel log Avengera,že tyto objekty nebyli nalezeny,proto nemohli být smazány..divné je,že tyto soubory se nedají vyhledat.
Dne 27.3.2011 jsem provedl rychlý sken se SuperAntispyware - detekoval pouze Tracking Cookie..
Dnes 28.3.2011 - Jsem provedl opět sken s MBAM a detekoval tentokrát 24 infikovaných souborů. Přibyl Backdoor.bot.
BTW: Vůbec netuším,jak se to tam mohlo dostat,..Nebyl jsem za poslední týden na stránkách,které by vyhodnotil Web of Trust jako nedůvěryhodné..
PS2: Také jsem zapoměl dodat,že jsem jednou použil Combofix..po restartu se počítač nenabootoval a hlásil poškozený registr..tak jsem provedl opravu MBR a pak se PC nabootoval.
Můj počítač:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Martin MTA at 2011-03-28 21:09:52
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 62 GB (62%) free of 100 GB
Total RAM: 1022 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:11:31, on 28.3.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\Explorer.EXE
D:\My Folder\foldrs-slozky-install-portable\Everything-1.2.1.371.exe
C:\program files\coode software\shortcutor\shortcutor.exe
C:\Program Files\AnVir Task Manager Free\AnVir.exe
C:\program files\robotask\robotask.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
C:\Program Files\AIMP2\AIMP2.exe
C:\Program Files\KeyScrambler\KeyScrambler.exe
C:\Program Files\Window HTS\svchost.exe
C:\Program Files\PicPick\picpick.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\QIP 2010\qip.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\The KMPlayer\KMPlayer.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
D:\My Folder\My ! Eflax\sprava pocitace - PC\Malware\RSIT.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Martin MTA.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: CBZurlmon Object - {311BA51F-64F2-439D-9A4A-772373D77312} - C:\Program Files\BufferZone\BZbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Everything] "D:\My Folder\foldrs-slozky-install-portable\Everything-1.2.1.371.exe" -startup
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKCU\..\Run: [Shortcutor] "C:\program files\coode software\shortcutor\shortcutor.exe"
O4 - HKCU\..\Run: [AnVir Task Manager Free] "C:\Program Files\AnVir Task Manager Free\AnVir.exe" Minimized
O4 - HKCU\..\Run: [RoboTask] "C:\program files\robotask\robotask.exe"
O4 - Startup: Find And Run Robot.lnk = C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0016624250
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5FE0D22F-FFC7-4B63-8B3E-9C6CABE5F365}: NameServer = 10.0.82.65,62.240.184.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{9385D163-2321-4B16-8B94-F14A20F7EFD7}: NameServer = 10.0.82.65,62.240.184.2
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
--
End of file - 7404 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-03-10 381656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{311BA51F-64F2-439D-9A4A-772373D77312}]
CBZurlmon Object - C:\Program Files\BufferZone\BZbho.dll [2010-11-29 225056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-25 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-25 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Everything"=D:\My Folder\foldrs-slozky-install-portable\Everything-1.2.1.371.exe [2009-03-13 602624]
"StartupDelayer"=C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe [2009-03-08 73728]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Shortcutor"=C:\program files\coode software\shortcutor\shortcutor.exe [2010-12-15 3975680]
"AnVir Task Manager Free"=C:\Program Files\AnVir Task Manager Free\AnVir.exe [2010-04-02 1733856]
"RoboTask"=C:\program files\robotask\robotask.exe [2011-03-01 706560]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartupDelayer]
C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe [2009-03-08 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"odserv"=3
"HideMyIpSRV"=3
"WMPNetworkSvc"=3
"Secunia Update Agent"=2
"Secunia PSI Agent"=2
"ose"=3
"Microsoft Office Groove Audit Service"=3
"JavaQuickStarterService"=2
"iPod Service"=3
"idsvc"=3
"Bonjour Service"=2
"Ati HotKey Poller"=2
"Apple Mobile Device"=2
"cmdAgent"=2
"StarWindServiceAE"=2
"IDriverT"=3
"ocster_backup"=3
"SolutoService"=2
"Steam Client Service"=3
"MatSvc"=3
"Cleaner_Validator"=3
C:\Documents and Settings\Martin MTA\Nabídka Start\Po spuštění
Find And Run Robot.lnk - C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-04 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-05-27 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=1
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoLogoff"=0
"MaxRecentDocs"=15
"DisableMyMusicDirChange"=1
"DisableMyPicturesDirChange"=1
"NoUserNameInStartMenu"=1
"NoCommonGroups"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\Opera 11.00 beta\opera.exe"="C:\Program Files\Opera 11.00 beta\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Foxreal\YouTube FLV Downloader Pro\Foxreal YouTube FLV Downloader Pro.exe"="C:\Program Files\Foxreal\YouTube FLV Downloader Pro\Foxreal YouTube FLV Downloader Pro.exe:*:Enabled:Foxreal YouTube FLV Downloader Pro"
"C:\Program Files\1AVCenter\1AVCenter.exe"="C:\Program Files\1AVCenter\1AVCenter.exe:*:Enabled:1AVCenter "
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe:*:Enabled:ElcomSoft Distributed Password Recovery Server"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe:*:Enabled:ElcomSoft Distributed Password Recovery Console"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe:*:Enabled:ElcomSoft Distributed Agent"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"C:\Program Files\QIP 2010\qip.exe"="C:\Program Files\QIP 2010\qip.exe:*:Enabled:QIP 2010"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Disabled:Průvodce přenesením souborů a nastavení"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\My Folder\foldrs-slozky-install-portable\TeamViewerPortable_en\TeamViewer.exe"="D:\My Folder\foldrs-slozky-install-portable\TeamViewerPortable_en\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe:*:Enabled:Counter-Strike"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe"="C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe:*:Enabled:PotPlayer"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe:*:Enabled:ElcomSoft Distributed Password Recovery Server"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe:*:Enabled:ElcomSoft Distributed Password Recovery Console"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe:*:Enabled:ElcomSoft Distributed Agent"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
======List of files/folders created in the last 1 months======
2011-03-28 17:37:10 ----D---- C:\Program Files\AutoSizer
2011-03-28 17:29:14 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\FDRLab
2011-03-27 22:42:56 ----D---- C:\Program Files\DropMyRights
2011-03-27 17:13:30 ----A---- C:\WINDOWS\system32\mfc45.dll
2011-03-27 17:13:27 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\iolo
2011-03-27 17:13:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\iolo
2011-03-27 13:43:37 ----D---- C:\WINDOWS\system32\drivers\NBRTWizard
2011-03-27 13:43:25 ----D---- C:\Program Files\Norton Bootable Recovery Tool Wizard
2011-03-27 12:40:20 ----D---- C:\Program Files\AnVir Task Manager Free
2011-03-27 12:35:44 ----D---- C:\Program Files\EULAlyzer
2011-03-27 12:34:13 ----D---- C:\Program Files\VirusTotalUploader2
2011-03-27 00:39:36 ----D---- C:\Program Files\NortonInstaller
2011-03-27 00:39:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2011-03-26 22:14:03 ----D---- C:\Program Files\COMODO
2011-03-26 20:49:05 ----A---- C:\WINDOWS\system32\drivers\vde3mjk4.sys
2011-03-26 15:01:19 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2011-03-26 15:01:19 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2011-03-26 15:01:18 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2011-03-26 15:01:16 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2011-03-26 15:01:15 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2011-03-26 15:01:14 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2011-03-26 15:01:13 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2011-03-26 15:01:11 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2011-03-26 15:01:09 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2011-03-26 15:01:09 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2011-03-26 15:01:06 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2011-03-26 15:01:05 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2011-03-26 15:01:03 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2011-03-26 15:01:01 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2011-03-26 15:00:59 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2011-03-26 15:00:50 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2011-03-26 15:00:49 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2011-03-26 15:00:48 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2011-03-26 15:00:44 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2011-03-26 15:00:43 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2011-03-26 15:00:42 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2011-03-26 15:00:41 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2011-03-26 15:00:40 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2011-03-26 15:00:38 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2011-03-26 15:00:36 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2011-03-26 15:00:35 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2011-03-26 15:00:35 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2011-03-26 15:00:33 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2011-03-26 15:00:32 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2011-03-26 15:00:32 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2011-03-26 15:00:30 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2011-03-26 15:00:29 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2011-03-26 15:00:27 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2011-03-26 15:00:27 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2011-03-26 15:00:26 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2011-03-26 15:00:25 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2011-03-26 15:00:25 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2011-03-26 15:00:24 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2011-03-26 15:00:22 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2011-03-26 15:00:22 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2011-03-26 15:00:18 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2011-03-26 15:00:18 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2011-03-26 15:00:16 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2011-03-26 15:00:16 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2011-03-26 15:00:15 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2011-03-26 15:00:13 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2011-03-26 15:00:12 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2011-03-26 15:00:11 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2011-03-26 15:00:09 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2011-03-26 15:00:09 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2011-03-26 15:00:08 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2011-03-26 15:00:06 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2011-03-26 15:00:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2011-03-26 15:00:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2011-03-26 15:00:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2011-03-26 15:00:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2011-03-26 14:59:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2011-03-26 14:59:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2011-03-26 14:59:58 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2011-03-26 14:59:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2011-03-26 14:59:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2011-03-26 14:59:55 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2011-03-26 14:59:55 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2011-03-26 14:59:53 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2011-03-26 14:59:52 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2011-03-26 14:59:50 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2011-03-26 14:59:48 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2011-03-26 14:59:48 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2011-03-26 14:59:43 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2011-03-26 14:59:42 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2011-03-26 14:59:41 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2011-03-26 14:59:40 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2011-03-26 14:59:39 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2011-03-26 14:59:39 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2011-03-26 14:59:37 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2011-03-26 14:59:36 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2011-03-26 14:59:35 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2011-03-26 14:59:34 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2011-03-26 14:59:33 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2011-03-26 14:59:19 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2011-03-26 14:59:18 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2011-03-26 14:59:18 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2011-03-26 14:59:16 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2011-03-26 14:59:14 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2011-03-26 14:59:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2011-03-26 14:59:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2011-03-26 14:59:10 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2011-03-26 14:59:06 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2011-03-26 14:49:27 ----D---- C:\Program Files\Daum
2011-03-26 11:50:51 ----D---- C:\Program Files\KeyScrambler
2011-03-26 11:50:51 ----A---- C:\WINDOWS\system32\drivers\keyscrambler.sys
2011-03-26 10:52:51 ----SHD---- C:\RECYCLER
2011-03-26 09:15:44 ----ASH---- C:\pagefile.sys
2011-03-25 22:20:36 ----A---- C:\ComboFix.txt
2011-03-25 07:55:32 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\TuneUp Software
2011-03-25 07:44:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-03-23 22:37:52 ----D---- C:\Program Files\QTTabBar_1.2.2.1_glb
2011-03-23 21:28:24 ----D---- C:\Program Files\Poznámky.be
2011-03-22 22:17:29 ----D---- C:\Program Files\Common Files\Skype
2011-03-22 22:17:05 ----RD---- C:\Program Files\Skype
2011-03-21 21:57:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\RoboTask
2011-03-21 21:51:20 ----D---- C:\Program Files\RoboTask
2011-03-21 19:45:01 ----D---- C:\Program Files\Google Hacks
2011-03-20 12:51:33 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\TeamViewer
2011-03-20 11:39:46 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Beenokle
2011-03-20 11:39:45 ----D---- C:\Unfiled Notes
2011-03-20 11:39:22 ----D---- C:\Program Files\ZenWriter
2011-03-19 15:45:05 ----D---- C:\Program Files\Common Files\Steam
2011-03-19 15:45:02 ----AD---- C:\Program Files\Steam
2011-03-18 16:28:31 ----D---- C:\WINDOWS\Prefetch
2011-03-18 08:27:22 ----A---- C:\Documents and Settings\All Users\Data aplikací\Microsoft.SqlServer.Compact.351.32.bc
2011-03-18 08:23:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Soluto
2011-03-17 20:29:27 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Winsplit Revolution
2011-03-17 20:29:18 ----D---- C:\Program Files\WinSplit Revolution
2011-03-17 20:26:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Crystal Office
2011-03-17 20:26:17 ----D---- C:\Program Files\Maple Professional
2011-03-17 19:59:12 ----A---- C:\WINDOWS\vncutil.exe
2011-03-17 19:59:12 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2011-03-17 19:59:12 ----A---- C:\WINDOWS\SkyTel.exe
2011-03-17 19:59:12 ----A---- C:\WINDOWS\RtlUpd.exe
2011-03-17 19:59:12 ----A---- C:\WINDOWS\RTLCPL.EXE
2011-03-17 19:59:11 ----A---- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011-03-17 19:59:10 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2011-03-17 19:59:10 ----A---- C:\WINDOWS\RtkAudioService.exe
2011-03-17 19:59:09 ----A---- C:\WINDOWS\system32\drivers\Monfilt.sys
2011-03-17 19:59:09 ----A---- C:\WINDOWS\RTHDCPL.EXE
2011-03-17 19:59:09 ----A---- C:\WINDOWS\MicCal.exe
2011-03-17 19:59:05 ----A---- C:\WINDOWS\system32\drivers\Ambfilt.sys
2011-03-17 19:59:03 ----D---- C:\Program Files\Realtek
2011-03-17 19:59:03 ----A---- C:\WINDOWS\ALCWZRD.EXE
2011-03-17 19:59:03 ----A---- C:\WINDOWS\ALCMTR.EXE
2011-03-17 19:58:47 ----A---- C:\WINDOWS\RtlExUpd.dll
2011-03-17 15:26:47 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\OpenCandy
2011-03-17 15:26:36 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2011-03-17 15:26:31 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2011-03-17 15:26:10 ----D---- C:\WINDOWS\Logs
2011-03-17 15:24:57 ----D---- C:\Program Files\Winamp
2011-03-17 15:24:57 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Winamp
2011-03-16 15:36:23 ----AD---- C:\Program Files\ICQ7.4
2011-03-15 22:31:24 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\DonationCoder
2011-03-15 22:30:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\DonationCoder
2011-03-15 22:30:25 ----D---- C:\Program Files\FindAndRunRobot
2011-03-15 21:46:19 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\Trillian
2011-03-15 21:45:23 ----D---- C:\Program Files\Trillian
2011-03-13 22:01:52 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\Mozilla
2011-03-13 22:01:34 ----D---- C:\Program Files\Mozilla Firefox
2011-03-13 13:30:23 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Gmail Backup
2011-03-13 09:59:27 ----D---- C:\Program Files\GmailBackup
2011-03-13 09:55:01 ----D---- C:\Shoty
2011-03-13 09:48:29 ----D---- C:\Program Files\ScreenShots
2011-03-12 14:14:59 ----D---- C:\Program Files\ElcomSoft
2011-03-12 12:09:30 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Hornil
2011-03-12 12:08:26 ----D---- C:\Program Files\Two Pilots
2011-03-12 12:08:24 ----D---- C:\Program Files\Cosmetic Guide
2011-03-11 17:46:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\backup
2011-03-11 15:03:21 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Google Chrome Backup
2011-03-11 15:01:00 ----D---- C:\Program Files\Google Chrome Backup
2011-03-10 18:15:55 ----A---- C:\WINDOWS\wcx_ftp.ini
2011-03-10 14:40:21 ----D---- C:\Program Files\Common Files\xing shared
2011-03-10 10:30:02 ----D---- C:\Program Files\iResizer
2011-03-08 18:50:51 ----D---- C:\RECYCLER(2)
2011-03-08 08:31:31 ----D---- C:\WINDOWS\system32\Program Files
2011-03-07 22:14:40 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\FreeHideIP
2011-03-07 22:14:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\FreeHideIP
2011-03-07 22:13:29 ----D---- C:\Program Files\FreeHideIP
2011-03-06 21:49:40 ----D---- C:\Virtual
2011-03-06 21:43:49 ----AD---- C:\Documents and Settings\All Users\Data aplikací\BufferZone
2011-03-06 21:43:32 ----D---- C:\Program Files\BufferZone
2011-03-06 09:32:28 ----A---- C:\Documents and Settings\Martin MTA\Data aplikací\vispa.ini
2011-03-05 17:09:22 ----D---- C:\Program Files\Cain
2011-03-05 08:41:28 ----HD---- C:\WINDOWS\PIF
2011-03-05 08:35:49 ----D---- C:\WINDOWS\ERDNT
2011-03-05 08:27:20 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\JPEGsnoop
2011-03-03 20:36:58 ----D---- C:\Program Files\Common Files\Akamai
2011-03-02 20:27:51 ----D---- C:\Program Files\DAEMON Tools Lite
2011-03-02 20:27:14 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\DAEMON Tools Lite
2011-03-02 20:27:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2011-03-02 19:33:52 ----A---- C:\WINDOWS\system32\drivers\sptd.sys
======List of files/folders modified in the last 1 months======
2011-03-28 21:10:19 ----D---- C:\Program Files\trend micro
2011-03-28 20:48:50 ----D---- C:\WINDOWS\temp
2011-03-28 20:32:41 ----D---- C:\WINDOWS\system32\drivers
2011-03-28 20:30:08 ----D---- C:\WINDOWS\system32\CatRoot2
2011-03-28 20:10:55 ----RD---- C:\Program Files
2011-03-28 18:18:44 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\AIMP
2011-03-28 18:02:10 ----AD---- C:\Program Files\QIP 2010
2011-03-28 17:49:20 ----ASD---- C:\WINDOWS\Tasks
2011-03-28 17:48:34 ----RASH---- C:\boot.ini
2011-03-28 17:48:34 ----A---- C:\WINDOWS\win.ini
2011-03-28 17:48:34 ----A---- C:\WINDOWS\system.ini
2011-03-28 17:44:31 ----D---- C:\Program Files\Everything
2011-03-28 17:44:10 ----AD---- C:\WINDOWS
2011-03-28 17:33:18 ----AD---- C:\Program Files\Sandboxie
2011-03-28 07:36:57 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-03-28 07:36:33 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2011-03-28 07:30:04 ----D---- C:\WINDOWS\Registration
2011-03-27 22:58:12 ----AD---- C:\WINDOWS\system32
2011-03-27 22:58:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-27 22:43:01 ----SHD---- C:\WINDOWS\Installer
2011-03-27 22:42:57 ----D---- C:\Config.Msi
2011-03-27 19:22:01 ----D---- C:\Program Files\Window HTS
2011-03-27 18:37:59 ----D---- C:\Program Files\SUPERAntiSpyware
2011-03-27 18:04:32 ----D---- C:\Program Files\Microsoft Bootvis
2011-03-27 17:58:27 ----D---- C:\WINDOWS\security
2011-03-27 17:42:51 ----AD---- C:\Program Files\IrfanView
2011-03-27 17:20:37 ----D---- C:\WINDOWS\system32\config
2011-03-27 13:46:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2011-03-27 13:31:36 ----HD---- C:\WINDOWS\msdownld.tmp
2011-03-27 12:29:38 ----D---- C:\WINDOWS\system32\drivers\etc
2011-03-26 22:12:36 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Media Player Classic
2011-03-26 20:19:14 ----ASHD---- C:\System Volume Information
2011-03-26 19:51:28 ----D---- C:\WINDOWS\system32\Restore
2011-03-26 18:02:43 ----HD---- C:\WINDOWS\inf
2011-03-26 17:41:59 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-26 17:41:57 ----RSD---- C:\WINDOWS\assembly
2011-03-26 17:32:21 ----D---- C:\WINDOWS\Performance
2011-03-26 17:17:29 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Audacity
2011-03-26 15:01:23 ----D---- C:\WINDOWS\system32\DirectX
2011-03-26 13:56:19 ----D---- C:\WINDOWS\WinSxS
2011-03-26 13:49:10 ----D---- C:\WINDOWS\system32\en-US
2011-03-26 12:22:43 ----AD---- C:\Program Files\Valve
2011-03-26 11:03:44 ----AD---- C:\WINDOWS\system32\wbem
2011-03-26 09:45:19 ----D---- C:\WINDOWS\addins
2011-03-25 22:03:59 ----D---- C:\WINDOWS\AppPatch
2011-03-25 22:03:50 ----D---- C:\Program Files\Common Files
2011-03-25 21:27:05 ----D---- C:\Program Files\Common Files\Windows Live
2011-03-24 23:14:17 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\ICQ
2011-03-24 23:03:40 ----D---- C:\Program Files\CCleaner
2011-03-24 22:42:53 ----D---- C:\ProgramData
2011-03-24 17:48:37 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\Skype
2011-03-24 17:48:34 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\skypePM
2011-03-22 22:17:04 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-03-22 22:11:40 ----D---- C:\Program Files\Defraggler
2011-03-22 14:21:20 ----D---- C:\Program Files\Opera 11.00 beta
2011-03-20 11:39:22 ----RSD---- C:\WINDOWS\Fonts
2011-03-20 09:32:14 ----D---- C:\Program Files\Unlocker
2011-03-20 09:31:54 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Ventrilo
2011-03-18 18:42:16 ----D---- C:\WINDOWS\Minidump
2011-03-18 17:47:57 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\uTorrent
2011-03-18 14:22:45 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-03-17 23:44:50 ----D---- C:\WINDOWS\Debug
2011-03-17 19:59:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-17 19:59:46 ----D---- C:\WINDOWS\system32\RTCOM
2011-03-17 19:59:39 ----D---- C:\WINDOWS\system32\CatRoot
2011-03-17 19:59:02 ----HD---- C:\Program Files\InstallShield Installation Information
2011-03-17 19:58:02 ----D---- C:\Program Files\Driver Cleaner
2011-03-13 17:43:44 ----D---- C:\Program Files\Google
2011-03-13 09:39:36 ----AD---- C:\Documents and Settings
2011-03-12 21:45:10 ----D---- C:\Program Files\Boxoft Screen OCR
2011-03-12 21:10:11 ----D---- C:\Program Files\WinRAR
2011-03-12 11:48:46 ----D---- C:\Program Files\XnView
2011-03-10 20:54:09 ----RD---- C:\WINDOWS\Web
2011-03-10 20:53:00 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2011-03-10 18:08:46 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\KeePass
2011-03-10 17:35:25 ----A---- C:\WINDOWS\Sandboxie.ini
2011-03-10 14:40:39 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Real
2011-03-10 14:40:35 ----D---- C:\Program Files\Real
2011-03-10 14:39:52 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2011-03-10 14:38:50 ----A---- C:\WINDOWS\system32\pndx5032.dll
2011-03-10 14:38:50 ----A---- C:\WINDOWS\system32\pndx5016.dll
2011-03-10 14:38:40 ----A---- C:\WINDOWS\system32\pncrt.dll
2011-03-10 14:38:28 ----A---- C:\WINDOWS\system32\msvcr71.dll
2011-03-10 14:38:28 ----A---- C:\WINDOWS\system32\msvcp71.dll
2011-03-10 14:32:49 ----D---- C:\Program Files\Safari
2011-03-09 15:57:35 ----D---- C:\Program Files\iTunes
2011-03-09 08:24:42 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-09 08:24:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hotcore3;hc3ServiceName; C:\WINDOWS\system32\DRIVERS\hotcore3.sys [2010-09-15 40560]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 REDLIGHT;REDLIGHT; C:\WINDOWS\System32\drivers\REDLIGHT.SYS [2010-11-29 378144]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-03-02 431672]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R0 videX32;videX32; C:\WINDOWS\System32\DRIVERS\videX32.sys [2009-05-05 13976]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R0 xfilt;VIA SATA IDE Hot-plug Driver; C:\WINDOWS\System32\DRIVERS\xfilt.sys [2009-05-05 22168]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-02-23 30680]
R1 AntiLog32;AntiLog32; \??\C:\Program Files\AntiLogger\AntiLog32.sys []
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 BIOS;BIOS; \??\C:\WINDOWS\system32\drivers\BIOS.sys []
R1 CFRMD;CFRMD; C:\WINDOWS\system32\DRIVERS\CFRMD.sys [2010-12-09 66584]
R1 CFRPD;CFRPD; C:\WINDOWS\system32\DRIVERS\CFRPD.sys [2010-12-09 33232]
R1 cpuidlep;CpuIdle Pro System Driver; C:\WINDOWS\system32\drivers\cpuidlep.sys [2010-12-09 4484]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2010-12-19 231248]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-02-23 102232]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-05-27 4830720]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdXP3.sys [2010-08-19 101904]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [2009-06-16 46592]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-06-12 26600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-02-24 6340200]
R3 KeyScrambler;KeyScrambler; C:\WINDOWS\System32\drivers\keyscrambler.sys [2010-02-11 114952]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys []
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S0 fdulmsko;fdulmsko; C:\WINDOWS\System32\drivers\mavecg.sys []
S3 a24fz05j;a24fz05j; C:\WINDOWS\system32\drivers\a24fz05j.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 ampa;ampa; \??\C:\WINDOWS\system32\ampa.sys []
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-10-31 93184]
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 cpuz134;cpuz134; \??\C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys []
S3 esihdrv;esihdrv; \??\C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\esihdrv.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-06-25 35088]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2009-11-20 25984]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Akamai;Akamai NetSession Interface; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-02-23 42184]
R2 BufferZoneSvc;BufferZone Service; C:\Program Files\BufferZone\CLNTSVC.EXE [2010-11-29 802888]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2011-03-24 72936]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-05-27 602112]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
S4 Cleaner_Validator;COMODO System - Cleaner Service; C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [2010-12-09 305600]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-03-07 820520]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-25 153376]
S4 MatSvc;Microsoft Automated Troubleshooting Service; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-11-16 267568]
S4 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 ocster_backup;Ocster Backup; c:\Program Files\Ocster Backup\bin\backupService-ox.exe [2010-11-26 18200]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S4 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org
Verze databáze: 6198
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
28.3.2011 20:50:00
mbam-log-2011-03-28 (20-49-49).txt
Typ kontroly: Rychlý test
Testované objekty: 207075
Uplynulý čas: 11 minut, 40 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 24
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\_ocster_backup_\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator.butterfl-3jcaic.000\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator.butterfl-3jcaic\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\all users\application data\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\all users\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\default user\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\localservice\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\martin mta\application data\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\martin mta\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\mta 2\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\mta 3\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\networkservice\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\windows\system32\config\systemprofile\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\windows\system32\keygen.exe (Backdoor.Bot) -> No action taken.
c:\documents and settings\localservice\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\documents and settings\martin mta\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\documents and settings\mta 2\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\documents and settings\networkservice\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\windows\system32\config\systemprofile\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\windows\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\windows\microsoft.net\keygen.exe (Worm.Rebhip) -> No action taken.
c:\windows\virus.exe (Worm.AutoRun) -> No action taken.
c:\program files\msnmsgr\crack.exe (Backdoor.Bifrose) -> No action taken.
Měl bych tu jeden problém s počítačem.
Dne 26.3.2011 jsem provedl rychlý sken programem MBAM a po skončení, MBAM detekoval 23 infikovaných souborů. Dal jsem tedy odstranit všechny infikované objekty a restartoval počítač. Poté jsem znovu provedl rychlý sken MBAM a opět detekoval 23 infikovaných souborů. Rozhodl jsem se tedy,použít Avenger ,po restartu pc vyšel log Avengera,že tyto objekty nebyli nalezeny,proto nemohli být smazány..divné je,že tyto soubory se nedají vyhledat.
Dne 27.3.2011 jsem provedl rychlý sken se SuperAntispyware - detekoval pouze Tracking Cookie..
Dnes 28.3.2011 - Jsem provedl opět sken s MBAM a detekoval tentokrát 24 infikovaných souborů. Přibyl Backdoor.bot.
BTW: Vůbec netuším,jak se to tam mohlo dostat,..Nebyl jsem za poslední týden na stránkách,které by vyhodnotil Web of Trust jako nedůvěryhodné..
PS2: Také jsem zapoměl dodat,že jsem jednou použil Combofix..po restartu se počítač nenabootoval a hlásil poškozený registr..tak jsem provedl opravu MBR a pak se PC nabootoval.
Můj počítač:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Martin MTA at 2011-03-28 21:09:52
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 62 GB (62%) free of 100 GB
Total RAM: 1022 MB (29% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:11:31, on 28.3.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BufferZone\CLNTSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\Explorer.EXE
D:\My Folder\foldrs-slozky-install-portable\Everything-1.2.1.371.exe
C:\program files\coode software\shortcutor\shortcutor.exe
C:\Program Files\AnVir Task Manager Free\AnVir.exe
C:\program files\robotask\robotask.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
C:\Program Files\AIMP2\AIMP2.exe
C:\Program Files\KeyScrambler\KeyScrambler.exe
C:\Program Files\Window HTS\svchost.exe
C:\Program Files\PicPick\picpick.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\QIP 2010\qip.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\The KMPlayer\KMPlayer.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
D:\My Folder\My ! Eflax\sprava pocitace - PC\Malware\RSIT.exe
C:\Documents and Settings\Martin MTA\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Martin MTA.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: CBZurlmon Object - {311BA51F-64F2-439D-9A4A-772373D77312} - C:\Program Files\BufferZone\BZbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Everything] "D:\My Folder\foldrs-slozky-install-portable\Everything-1.2.1.371.exe" -startup
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKCU\..\Run: [Shortcutor] "C:\program files\coode software\shortcutor\shortcutor.exe"
O4 - HKCU\..\Run: [AnVir Task Manager Free] "C:\Program Files\AnVir Task Manager Free\AnVir.exe" Minimized
O4 - HKCU\..\Run: [RoboTask] "C:\program files\robotask\robotask.exe"
O4 - Startup: Find And Run Robot.lnk = C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0016624250
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5FE0D22F-FFC7-4B63-8B3E-9C6CABE5F365}: NameServer = 10.0.82.65,62.240.184.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{9385D163-2321-4B16-8B94-F14A20F7EFD7}: NameServer = 10.0.82.65,62.240.184.2
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
--
End of file - 7404 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-03-10 381656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{311BA51F-64F2-439D-9A4A-772373D77312}]
CBZurlmon Object - C:\Program Files\BufferZone\BZbho.dll [2010-11-29 225056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-25 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-25 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Everything"=D:\My Folder\foldrs-slozky-install-portable\Everything-1.2.1.371.exe [2009-03-13 602624]
"StartupDelayer"=C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe [2009-03-08 73728]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Shortcutor"=C:\program files\coode software\shortcutor\shortcutor.exe [2010-12-15 3975680]
"AnVir Task Manager Free"=C:\Program Files\AnVir Task Manager Free\AnVir.exe [2010-04-02 1733856]
"RoboTask"=C:\program files\robotask\robotask.exe [2011-03-01 706560]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartupDelayer]
C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe [2009-03-08 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"odserv"=3
"HideMyIpSRV"=3
"WMPNetworkSvc"=3
"Secunia Update Agent"=2
"Secunia PSI Agent"=2
"ose"=3
"Microsoft Office Groove Audit Service"=3
"JavaQuickStarterService"=2
"iPod Service"=3
"idsvc"=3
"Bonjour Service"=2
"Ati HotKey Poller"=2
"Apple Mobile Device"=2
"cmdAgent"=2
"StarWindServiceAE"=2
"IDriverT"=3
"ocster_backup"=3
"SolutoService"=2
"Steam Client Service"=3
"MatSvc"=3
"Cleaner_Validator"=3
C:\Documents and Settings\Martin MTA\Nabídka Start\Po spuštění
Find And Run Robot.lnk - C:\Program Files\FindAndRunRobot\FindAndRunRobot.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-04 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-05-27 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=1
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoLogoff"=0
"MaxRecentDocs"=15
"DisableMyMusicDirChange"=1
"DisableMyPicturesDirChange"=1
"NoUserNameInStartMenu"=1
"NoCommonGroups"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\Opera 11.00 beta\opera.exe"="C:\Program Files\Opera 11.00 beta\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Foxreal\YouTube FLV Downloader Pro\Foxreal YouTube FLV Downloader Pro.exe"="C:\Program Files\Foxreal\YouTube FLV Downloader Pro\Foxreal YouTube FLV Downloader Pro.exe:*:Enabled:Foxreal YouTube FLV Downloader Pro"
"C:\Program Files\1AVCenter\1AVCenter.exe"="C:\Program Files\1AVCenter\1AVCenter.exe:*:Enabled:1AVCenter "
"C:\Program Files\HLSW\hlsw.exe"="C:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe:*:Enabled:ElcomSoft Distributed Password Recovery Server"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe:*:Enabled:ElcomSoft Distributed Password Recovery Console"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe:*:Enabled:ElcomSoft Distributed Agent"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
"C:\Program Files\QIP 2010\qip.exe"="C:\Program Files\QIP 2010\qip.exe:*:Enabled:QIP 2010"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Disabled:Průvodce přenesením souborů a nastavení"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"D:\My Folder\foldrs-slozky-install-portable\TeamViewerPortable_en\TeamViewer.exe"="D:\My Folder\foldrs-slozky-install-portable\TeamViewerPortable_en\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\cleverboy\counter-strike\hl.exe:*:Enabled:Counter-Strike"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe"="C:\Program Files\Daum\PotPlayer\PotPlayerMini.exe:*:Enabled:PotPlayer"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdprs.exe:*:Enabled:ElcomSoft Distributed Password Recovery Server"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esdpr.exe:*:Enabled:ElcomSoft Distributed Password Recovery Console"
"C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe"="C:\Program Files\ElcomSoft\Distributed Password Recovery\esda.exe:*:Enabled:ElcomSoft Distributed Agent"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"
======List of files/folders created in the last 1 months======
2011-03-28 17:37:10 ----D---- C:\Program Files\AutoSizer
2011-03-28 17:29:14 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\FDRLab
2011-03-27 22:42:56 ----D---- C:\Program Files\DropMyRights
2011-03-27 17:13:30 ----A---- C:\WINDOWS\system32\mfc45.dll
2011-03-27 17:13:27 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\iolo
2011-03-27 17:13:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\iolo
2011-03-27 13:43:37 ----D---- C:\WINDOWS\system32\drivers\NBRTWizard
2011-03-27 13:43:25 ----D---- C:\Program Files\Norton Bootable Recovery Tool Wizard
2011-03-27 12:40:20 ----D---- C:\Program Files\AnVir Task Manager Free
2011-03-27 12:35:44 ----D---- C:\Program Files\EULAlyzer
2011-03-27 12:34:13 ----D---- C:\Program Files\VirusTotalUploader2
2011-03-27 00:39:36 ----D---- C:\Program Files\NortonInstaller
2011-03-27 00:39:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2011-03-26 22:14:03 ----D---- C:\Program Files\COMODO
2011-03-26 20:49:05 ----A---- C:\WINDOWS\system32\drivers\vde3mjk4.sys
2011-03-26 15:01:19 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2011-03-26 15:01:19 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2011-03-26 15:01:18 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2011-03-26 15:01:16 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2011-03-26 15:01:15 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2011-03-26 15:01:14 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2011-03-26 15:01:13 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2011-03-26 15:01:11 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2011-03-26 15:01:09 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2011-03-26 15:01:09 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2011-03-26 15:01:06 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2011-03-26 15:01:05 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2011-03-26 15:01:03 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2011-03-26 15:01:01 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2011-03-26 15:00:59 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2011-03-26 15:00:50 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2011-03-26 15:00:49 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2011-03-26 15:00:48 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2011-03-26 15:00:44 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2011-03-26 15:00:43 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2011-03-26 15:00:42 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2011-03-26 15:00:41 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2011-03-26 15:00:40 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2011-03-26 15:00:38 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2011-03-26 15:00:36 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2011-03-26 15:00:35 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2011-03-26 15:00:35 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2011-03-26 15:00:33 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2011-03-26 15:00:32 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2011-03-26 15:00:32 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2011-03-26 15:00:30 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2011-03-26 15:00:29 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2011-03-26 15:00:27 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2011-03-26 15:00:27 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2011-03-26 15:00:26 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2011-03-26 15:00:25 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2011-03-26 15:00:25 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2011-03-26 15:00:24 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2011-03-26 15:00:22 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2011-03-26 15:00:22 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2011-03-26 15:00:18 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2011-03-26 15:00:18 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2011-03-26 15:00:16 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2011-03-26 15:00:16 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2011-03-26 15:00:15 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2011-03-26 15:00:13 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2011-03-26 15:00:12 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2011-03-26 15:00:11 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2011-03-26 15:00:09 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2011-03-26 15:00:09 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2011-03-26 15:00:08 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2011-03-26 15:00:06 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2011-03-26 15:00:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2011-03-26 15:00:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2011-03-26 15:00:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2011-03-26 15:00:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2011-03-26 14:59:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2011-03-26 14:59:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2011-03-26 14:59:58 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2011-03-26 14:59:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2011-03-26 14:59:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2011-03-26 14:59:55 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2011-03-26 14:59:55 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2011-03-26 14:59:53 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2011-03-26 14:59:52 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2011-03-26 14:59:50 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2011-03-26 14:59:48 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2011-03-26 14:59:48 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2011-03-26 14:59:43 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2011-03-26 14:59:42 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2011-03-26 14:59:41 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2011-03-26 14:59:40 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2011-03-26 14:59:39 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2011-03-26 14:59:39 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2011-03-26 14:59:37 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2011-03-26 14:59:36 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2011-03-26 14:59:35 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2011-03-26 14:59:34 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2011-03-26 14:59:33 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2011-03-26 14:59:19 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2011-03-26 14:59:18 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2011-03-26 14:59:18 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2011-03-26 14:59:16 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2011-03-26 14:59:14 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2011-03-26 14:59:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2011-03-26 14:59:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2011-03-26 14:59:10 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2011-03-26 14:59:06 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2011-03-26 14:49:27 ----D---- C:\Program Files\Daum
2011-03-26 11:50:51 ----D---- C:\Program Files\KeyScrambler
2011-03-26 11:50:51 ----A---- C:\WINDOWS\system32\drivers\keyscrambler.sys
2011-03-26 10:52:51 ----SHD---- C:\RECYCLER
2011-03-26 09:15:44 ----ASH---- C:\pagefile.sys
2011-03-25 22:20:36 ----A---- C:\ComboFix.txt
2011-03-25 07:55:32 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\TuneUp Software
2011-03-25 07:44:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-03-23 22:37:52 ----D---- C:\Program Files\QTTabBar_1.2.2.1_glb
2011-03-23 21:28:24 ----D---- C:\Program Files\Poznámky.be
2011-03-22 22:17:29 ----D---- C:\Program Files\Common Files\Skype
2011-03-22 22:17:05 ----RD---- C:\Program Files\Skype
2011-03-21 21:57:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\RoboTask
2011-03-21 21:51:20 ----D---- C:\Program Files\RoboTask
2011-03-21 19:45:01 ----D---- C:\Program Files\Google Hacks
2011-03-20 12:51:33 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\TeamViewer
2011-03-20 11:39:46 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Beenokle
2011-03-20 11:39:45 ----D---- C:\Unfiled Notes
2011-03-20 11:39:22 ----D---- C:\Program Files\ZenWriter
2011-03-19 15:45:05 ----D---- C:\Program Files\Common Files\Steam
2011-03-19 15:45:02 ----AD---- C:\Program Files\Steam
2011-03-18 16:28:31 ----D---- C:\WINDOWS\Prefetch
2011-03-18 08:27:22 ----A---- C:\Documents and Settings\All Users\Data aplikací\Microsoft.SqlServer.Compact.351.32.bc
2011-03-18 08:23:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Soluto
2011-03-17 20:29:27 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Winsplit Revolution
2011-03-17 20:29:18 ----D---- C:\Program Files\WinSplit Revolution
2011-03-17 20:26:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Crystal Office
2011-03-17 20:26:17 ----D---- C:\Program Files\Maple Professional
2011-03-17 19:59:12 ----A---- C:\WINDOWS\vncutil.exe
2011-03-17 19:59:12 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2011-03-17 19:59:12 ----A---- C:\WINDOWS\SkyTel.exe
2011-03-17 19:59:12 ----A---- C:\WINDOWS\RtlUpd.exe
2011-03-17 19:59:12 ----A---- C:\WINDOWS\RTLCPL.EXE
2011-03-17 19:59:11 ----A---- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011-03-17 19:59:10 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2011-03-17 19:59:10 ----A---- C:\WINDOWS\RtkAudioService.exe
2011-03-17 19:59:09 ----A---- C:\WINDOWS\system32\drivers\Monfilt.sys
2011-03-17 19:59:09 ----A---- C:\WINDOWS\RTHDCPL.EXE
2011-03-17 19:59:09 ----A---- C:\WINDOWS\MicCal.exe
2011-03-17 19:59:05 ----A---- C:\WINDOWS\system32\drivers\Ambfilt.sys
2011-03-17 19:59:03 ----D---- C:\Program Files\Realtek
2011-03-17 19:59:03 ----A---- C:\WINDOWS\ALCWZRD.EXE
2011-03-17 19:59:03 ----A---- C:\WINDOWS\ALCMTR.EXE
2011-03-17 19:58:47 ----A---- C:\WINDOWS\RtlExUpd.dll
2011-03-17 15:26:47 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\OpenCandy
2011-03-17 15:26:36 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2011-03-17 15:26:31 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2011-03-17 15:26:10 ----D---- C:\WINDOWS\Logs
2011-03-17 15:24:57 ----D---- C:\Program Files\Winamp
2011-03-17 15:24:57 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Winamp
2011-03-16 15:36:23 ----AD---- C:\Program Files\ICQ7.4
2011-03-15 22:31:24 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\DonationCoder
2011-03-15 22:30:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\DonationCoder
2011-03-15 22:30:25 ----D---- C:\Program Files\FindAndRunRobot
2011-03-15 21:46:19 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\Trillian
2011-03-15 21:45:23 ----D---- C:\Program Files\Trillian
2011-03-13 22:01:52 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\Mozilla
2011-03-13 22:01:34 ----D---- C:\Program Files\Mozilla Firefox
2011-03-13 13:30:23 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Gmail Backup
2011-03-13 09:59:27 ----D---- C:\Program Files\GmailBackup
2011-03-13 09:55:01 ----D---- C:\Shoty
2011-03-13 09:48:29 ----D---- C:\Program Files\ScreenShots
2011-03-12 14:14:59 ----D---- C:\Program Files\ElcomSoft
2011-03-12 12:09:30 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Hornil
2011-03-12 12:08:26 ----D---- C:\Program Files\Two Pilots
2011-03-12 12:08:24 ----D---- C:\Program Files\Cosmetic Guide
2011-03-11 17:46:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\backup
2011-03-11 15:03:21 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Google Chrome Backup
2011-03-11 15:01:00 ----D---- C:\Program Files\Google Chrome Backup
2011-03-10 18:15:55 ----A---- C:\WINDOWS\wcx_ftp.ini
2011-03-10 14:40:21 ----D---- C:\Program Files\Common Files\xing shared
2011-03-10 10:30:02 ----D---- C:\Program Files\iResizer
2011-03-08 18:50:51 ----D---- C:\RECYCLER(2)
2011-03-08 08:31:31 ----D---- C:\WINDOWS\system32\Program Files
2011-03-07 22:14:40 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\FreeHideIP
2011-03-07 22:14:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\FreeHideIP
2011-03-07 22:13:29 ----D---- C:\Program Files\FreeHideIP
2011-03-06 21:49:40 ----D---- C:\Virtual
2011-03-06 21:43:49 ----AD---- C:\Documents and Settings\All Users\Data aplikací\BufferZone
2011-03-06 21:43:32 ----D---- C:\Program Files\BufferZone
2011-03-06 09:32:28 ----A---- C:\Documents and Settings\Martin MTA\Data aplikací\vispa.ini
2011-03-05 17:09:22 ----D---- C:\Program Files\Cain
2011-03-05 08:41:28 ----HD---- C:\WINDOWS\PIF
2011-03-05 08:35:49 ----D---- C:\WINDOWS\ERDNT
2011-03-05 08:27:20 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\JPEGsnoop
2011-03-03 20:36:58 ----D---- C:\Program Files\Common Files\Akamai
2011-03-02 20:27:51 ----D---- C:\Program Files\DAEMON Tools Lite
2011-03-02 20:27:14 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\DAEMON Tools Lite
2011-03-02 20:27:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2011-03-02 19:33:52 ----A---- C:\WINDOWS\system32\drivers\sptd.sys
======List of files/folders modified in the last 1 months======
2011-03-28 21:10:19 ----D---- C:\Program Files\trend micro
2011-03-28 20:48:50 ----D---- C:\WINDOWS\temp
2011-03-28 20:32:41 ----D---- C:\WINDOWS\system32\drivers
2011-03-28 20:30:08 ----D---- C:\WINDOWS\system32\CatRoot2
2011-03-28 20:10:55 ----RD---- C:\Program Files
2011-03-28 18:18:44 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\AIMP
2011-03-28 18:02:10 ----AD---- C:\Program Files\QIP 2010
2011-03-28 17:49:20 ----ASD---- C:\WINDOWS\Tasks
2011-03-28 17:48:34 ----RASH---- C:\boot.ini
2011-03-28 17:48:34 ----A---- C:\WINDOWS\win.ini
2011-03-28 17:48:34 ----A---- C:\WINDOWS\system.ini
2011-03-28 17:44:31 ----D---- C:\Program Files\Everything
2011-03-28 17:44:10 ----AD---- C:\WINDOWS
2011-03-28 17:33:18 ----AD---- C:\Program Files\Sandboxie
2011-03-28 07:36:57 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-03-28 07:36:33 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2011-03-28 07:30:04 ----D---- C:\WINDOWS\Registration
2011-03-27 22:58:12 ----AD---- C:\WINDOWS\system32
2011-03-27 22:58:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-27 22:43:01 ----SHD---- C:\WINDOWS\Installer
2011-03-27 22:42:57 ----D---- C:\Config.Msi
2011-03-27 19:22:01 ----D---- C:\Program Files\Window HTS
2011-03-27 18:37:59 ----D---- C:\Program Files\SUPERAntiSpyware
2011-03-27 18:04:32 ----D---- C:\Program Files\Microsoft Bootvis
2011-03-27 17:58:27 ----D---- C:\WINDOWS\security
2011-03-27 17:42:51 ----AD---- C:\Program Files\IrfanView
2011-03-27 17:20:37 ----D---- C:\WINDOWS\system32\config
2011-03-27 13:46:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2011-03-27 13:31:36 ----HD---- C:\WINDOWS\msdownld.tmp
2011-03-27 12:29:38 ----D---- C:\WINDOWS\system32\drivers\etc
2011-03-26 22:12:36 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Media Player Classic
2011-03-26 20:19:14 ----ASHD---- C:\System Volume Information
2011-03-26 19:51:28 ----D---- C:\WINDOWS\system32\Restore
2011-03-26 18:02:43 ----HD---- C:\WINDOWS\inf
2011-03-26 17:41:59 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-26 17:41:57 ----RSD---- C:\WINDOWS\assembly
2011-03-26 17:32:21 ----D---- C:\WINDOWS\Performance
2011-03-26 17:17:29 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Audacity
2011-03-26 15:01:23 ----D---- C:\WINDOWS\system32\DirectX
2011-03-26 13:56:19 ----D---- C:\WINDOWS\WinSxS
2011-03-26 13:49:10 ----D---- C:\WINDOWS\system32\en-US
2011-03-26 12:22:43 ----AD---- C:\Program Files\Valve
2011-03-26 11:03:44 ----AD---- C:\WINDOWS\system32\wbem
2011-03-26 09:45:19 ----D---- C:\WINDOWS\addins
2011-03-25 22:03:59 ----D---- C:\WINDOWS\AppPatch
2011-03-25 22:03:50 ----D---- C:\Program Files\Common Files
2011-03-25 21:27:05 ----D---- C:\Program Files\Common Files\Windows Live
2011-03-24 23:14:17 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\ICQ
2011-03-24 23:03:40 ----D---- C:\Program Files\CCleaner
2011-03-24 22:42:53 ----D---- C:\ProgramData
2011-03-24 17:48:37 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\Skype
2011-03-24 17:48:34 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\skypePM
2011-03-22 22:17:04 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-03-22 22:11:40 ----D---- C:\Program Files\Defraggler
2011-03-22 14:21:20 ----D---- C:\Program Files\Opera 11.00 beta
2011-03-20 11:39:22 ----RSD---- C:\WINDOWS\Fonts
2011-03-20 09:32:14 ----D---- C:\Program Files\Unlocker
2011-03-20 09:31:54 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\Ventrilo
2011-03-18 18:42:16 ----D---- C:\WINDOWS\Minidump
2011-03-18 17:47:57 ----AD---- C:\Documents and Settings\Martin MTA\Data aplikací\uTorrent
2011-03-18 14:22:45 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-03-17 23:44:50 ----D---- C:\WINDOWS\Debug
2011-03-17 19:59:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-17 19:59:46 ----D---- C:\WINDOWS\system32\RTCOM
2011-03-17 19:59:39 ----D---- C:\WINDOWS\system32\CatRoot
2011-03-17 19:59:02 ----HD---- C:\Program Files\InstallShield Installation Information
2011-03-17 19:58:02 ----D---- C:\Program Files\Driver Cleaner
2011-03-13 17:43:44 ----D---- C:\Program Files\Google
2011-03-13 09:39:36 ----AD---- C:\Documents and Settings
2011-03-12 21:45:10 ----D---- C:\Program Files\Boxoft Screen OCR
2011-03-12 21:10:11 ----D---- C:\Program Files\WinRAR
2011-03-12 11:48:46 ----D---- C:\Program Files\XnView
2011-03-10 20:54:09 ----RD---- C:\WINDOWS\Web
2011-03-10 20:53:00 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2011-03-10 18:08:46 ----D---- C:\Documents and Settings\Martin MTA\Data aplikací\KeePass
2011-03-10 17:35:25 ----A---- C:\WINDOWS\Sandboxie.ini
2011-03-10 14:40:39 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Real
2011-03-10 14:40:35 ----D---- C:\Program Files\Real
2011-03-10 14:39:52 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2011-03-10 14:38:50 ----A---- C:\WINDOWS\system32\pndx5032.dll
2011-03-10 14:38:50 ----A---- C:\WINDOWS\system32\pndx5016.dll
2011-03-10 14:38:40 ----A---- C:\WINDOWS\system32\pncrt.dll
2011-03-10 14:38:28 ----A---- C:\WINDOWS\system32\msvcr71.dll
2011-03-10 14:38:28 ----A---- C:\WINDOWS\system32\msvcp71.dll
2011-03-10 14:32:49 ----D---- C:\Program Files\Safari
2011-03-09 15:57:35 ----D---- C:\Program Files\iTunes
2011-03-09 08:24:42 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-09 08:24:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hotcore3;hc3ServiceName; C:\WINDOWS\system32\DRIVERS\hotcore3.sys [2010-09-15 40560]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 REDLIGHT;REDLIGHT; C:\WINDOWS\System32\drivers\REDLIGHT.SYS [2010-11-29 378144]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-03-02 431672]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R0 videX32;videX32; C:\WINDOWS\System32\DRIVERS\videX32.sys [2009-05-05 13976]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R0 xfilt;VIA SATA IDE Hot-plug Driver; C:\WINDOWS\System32\DRIVERS\xfilt.sys [2009-05-05 22168]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-02-23 30680]
R1 AntiLog32;AntiLog32; \??\C:\Program Files\AntiLogger\AntiLog32.sys []
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 BIOS;BIOS; \??\C:\WINDOWS\system32\drivers\BIOS.sys []
R1 CFRMD;CFRMD; C:\WINDOWS\system32\DRIVERS\CFRMD.sys [2010-12-09 66584]
R1 CFRPD;CFRPD; C:\WINDOWS\system32\DRIVERS\CFRPD.sys [2010-12-09 33232]
R1 cpuidlep;CpuIdle Pro System Driver; C:\WINDOWS\system32\drivers\cpuidlep.sys [2010-12-09 4484]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2010-12-19 231248]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-02-23 102232]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-05-27 4830720]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdXP3.sys [2010-08-19 101904]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service; C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [2009-06-16 46592]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-06-12 26600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-02-24 6340200]
R3 KeyScrambler;KeyScrambler; C:\WINDOWS\System32\drivers\keyscrambler.sys [2010-02-11 114952]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys []
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S0 fdulmsko;fdulmsko; C:\WINDOWS\System32\drivers\mavecg.sys []
S3 a24fz05j;a24fz05j; C:\WINDOWS\system32\drivers\a24fz05j.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 ampa;ampa; \??\C:\WINDOWS\system32\ampa.sys []
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-10-31 93184]
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 cpuz134;cpuz134; \??\C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys []
S3 esihdrv;esihdrv; \??\C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\esihdrv.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-06-25 35088]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2009-11-20 25984]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Akamai;Akamai NetSession Interface; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-02-23 42184]
R2 BufferZoneSvc;BufferZone Service; C:\Program Files\BufferZone\CLNTSVC.EXE [2010-11-29 802888]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2011-03-24 72936]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-05-27 602112]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
S4 Cleaner_Validator;COMODO System - Cleaner Service; C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [2010-12-09 305600]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-03-07 820520]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-25 153376]
S4 MatSvc;Microsoft Automated Troubleshooting Service; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-11-16 267568]
S4 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 ocster_backup;Ocster Backup; c:\Program Files\Ocster Backup\bin\backupService-ox.exe [2010-11-26 18200]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S4 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org
Verze databáze: 6198
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
28.3.2011 20:50:00
mbam-log-2011-03-28 (20-49-49).txt
Typ kontroly: Rychlý test
Testované objekty: 207075
Uplynulý čas: 11 minut, 40 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 24
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\_ocster_backup_\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator.butterfl-3jcaic.000\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator.butterfl-3jcaic\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\all users\application data\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\all users\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\default user\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\localservice\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\martin mta\application data\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\martin mta\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\mta 2\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\mta 3\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\networkservice\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\windows\system32\config\systemprofile\data aplikací\local\microsoft\windows\explorer\keygen.exe (Trojan.Agent) -> No action taken.
c:\windows\system32\keygen.exe (Backdoor.Bot) -> No action taken.
c:\documents and settings\localservice\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\documents and settings\martin mta\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\documents and settings\mta 2\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\documents and settings\networkservice\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\windows\system32\config\systemprofile\local settings\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\windows\temp\ixp000.tmp\keygen.exe (Trojan.Agent.CK) -> No action taken.
c:\windows\microsoft.net\keygen.exe (Worm.Rebhip) -> No action taken.
c:\windows\virus.exe (Worm.AutoRun) -> No action taken.
c:\program files\msnmsgr\crack.exe (Backdoor.Bifrose) -> No action taken.