Stránka 1 z 1

poprosim o kontrolu logu.

Napsal: 11 dub 2011 06:32
od ringov
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-11 07:23:59
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (36%) free of 8 GB
Total RAM: 511 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 07:26, on 11.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
E:\rsit\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60076
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download with Star Downloader - E:\My Download Files\ACCELELATOR PLUS\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 4903 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
&Crawler Toolbar Helper - C:\PROGRA~1\Crawler\ctbr.dll [2011-04-08 1236104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler Toolbar - C:\PROGRA~1\Crawler\ctbr.dll [2011-04-08 1236104]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^setup_9.0.0.722_09.04.2011_10-43.lnk]
E:\kasper\VIRUSR~1\SETUP_~1.20~\startup.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"D:\hry\Nová složka (2)\age2_x1.exe"="D:\hry\Nová složka (2)\age2_x1.exe:*:Enabled:Age of Empires II Expansion"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-04-11 07:05:07 ----D---- C:\Program Files\Crawler
2011-04-10 23:01:44 ----SHD---- C:\RECYCLER
2011-04-10 22:52:11 ----D---- C:\WINDOWS\temp
2011-04-10 22:37:02 ----SD---- C:\ComboFix
2011-04-10 19:04:58 ----A---- C:\WINDOWS\system32\drivers\rkhdrv40.sys
2011-04-10 16:43:50 ----D---- C:\rsit
2011-04-10 14:15:05 ----A---- C:\WINDOWS\zip.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWSC.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWREG.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\sed.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\PEV.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\NIRCMD.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\MBR.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\grep.exe
2011-04-10 14:14:35 ----D---- C:\Qoobox
2011-04-10 12:36:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-04-10 09:33:06 ----D---- C:\Program Files\Defraggler
2011-04-10 07:21:49 ----D---- C:\WINDOWS\system32\PreInstall
2011-04-10 07:21:43 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-04-10 07:21:43 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-10 01:10:38 ----A---- C:\WINDOWS\system32\drivers\rootrepeal.sys
2011-04-09 09:21:29 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-09 07:25:29 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-04-09 06:46:03 ----D---- C:\WINDOWS\SxsCaPendDel
2011-04-08 13:30:36 ----D---- C:\Program Files\CCleaner
2011-04-08 13:29:03 ----D---- C:\Program Files\Google
2011-04-08 13:02:34 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-08 13:02:23 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-08 13:02:23 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-04-08 10:04:50 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-04-08 10:04:25 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-04-08 10:03:43 ----D---- C:\Program Files\Realtek AC97
2011-04-08 10:03:41 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-04-08 10:03:37 ----A---- C:\WINDOWS\soundman.exe
2011-04-08 10:03:36 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-04-08 10:03:32 ----A---- C:\WINDOWS\alcupd.exe
2011-04-08 10:03:32 ----A---- C:\WINDOWS\Alcrmv.exe
2011-04-07 11:48:26 ----D---- C:\Program Files\trend micro
2011-04-06 16:53:19 ----N---- C:\WINDOWS\cmaudio.ini
2011-04-06 16:53:19 ----D---- C:\Program Files\C-Media
2011-04-06 15:48:38 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-04-06 15:24:35 ----ASH---- C:\pagefile.sys
2011-04-06 08:49:29 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-04-06 00:05:19 ----D---- C:\Program Files\WinClamAVShield
2011-04-05 22:59:59 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-04-05 22:59:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-04-05 22:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-04-05 22:59:42 ----D---- C:\Program Files\Spyware Terminator
2011-04-05 22:50:52 ----D---- C:\Program Files\Secunia
2011-04-05 21:30:29 ----D---- C:\WINDOWS\WBEM
2011-04-05 21:28:55 ----HDC---- C:\WINDOWS\ie8
2011-04-05 21:28:55 ----D---- C:\WINDOWS\system32\cs-CZ
2011-04-04 17:15:57 ----HD---- C:\Program Files\WindowsUpdate
2011-04-04 15:56:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-04-04 15:34:35 ----N---- C:\Boot.bak
2011-04-04 15:34:26 ----RASHD---- C:\cmdcons
2011-04-04 15:29:15 ----D---- C:\WINDOWS\ERDNT
2011-04-04 13:46:48 ----D---- C:\Program Files\ESET
2011-04-01 10:37:23 ----A---- C:\WINDOWS\WEBTRANS.INI
2011-04-01 10:36:28 ----A---- C:\WINDOWS\WEBWTR.INI
2011-04-01 10:36:15 ----D---- C:\WINDOWS\XXLGS

======List of files/folders modified in the last 1 months======

2011-04-11 07:05:07 ----RD---- C:\Program Files
2011-04-11 06:46:42 ----D---- C:\WINDOWS
2011-04-11 00:13:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-11 00:11:38 ----D---- C:\WINDOWS\Minidump
2011-04-10 22:55:38 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-10 22:53:11 ----D---- C:\WINDOWS\system32\config
2011-04-10 22:51:16 ----D---- C:\WINDOWS\system32\drivers
2011-04-10 22:46:57 ----D---- C:\WINDOWS\system32
2011-04-10 22:46:56 ----D---- C:\WINDOWS\AppPatch
2011-04-10 22:46:40 ----D---- C:\Program Files\Common Files
2011-04-10 22:37:26 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-10 19:20:57 ----RSH---- C:\boot.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\win.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\system.ini
2011-04-10 15:04:41 ----D---- C:\WINDOWS\pss
2011-04-10 15:01:26 ----SHD---- C:\WINDOWS\Installer
2011-04-10 15:01:26 ----D---- C:\Config.Msi
2011-04-10 14:55:52 ----D---- C:\WINDOWS\WinSxS
2011-04-10 14:55:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-10 12:36:34 ----SD---- C:\WINDOWS\Tasks
2011-04-10 10:10:00 ----D---- C:\WINDOWS\Prefetch
2011-04-10 08:21:37 ----D---- C:\WINDOWS\SoftwareDistribution
2011-04-10 08:20:03 ----HD---- C:\WINDOWS\inf
2011-04-10 07:41:01 ----SHD---- C:\System Volume Information
2011-04-10 07:41:01 ----D---- C:\WINDOWS\system32\Restore
2011-04-09 22:43:21 ----D---- C:\Program Files\7-Zip
2011-04-09 22:43:10 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-04-09 12:02:00 ----D---- C:\Program Files\WinRAR
2011-04-09 09:26:00 ----D---- C:\WINDOWS\repair
2011-04-09 09:25:30 ----D---- C:\WINDOWS\Registration
2011-04-09 09:21:27 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-08 13:36:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IDM
2011-04-08 13:36:01 ----D---- C:\WINDOWS\Debug
2011-04-08 12:56:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-08 10:03:31 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-08 10:02:59 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-08 09:48:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-06 09:07:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-04-06 08:58:39 ----D---- C:\ProgramData
2011-04-06 08:55:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2011-04-06 08:17:50 ----D---- C:\Documents and Settings
2011-04-05 23:11:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-05 21:52:02 ----D---- C:\Program Files\Mozilla Firefox
2011-04-05 21:32:51 ----D---- C:\WINDOWS\Help
2011-04-05 21:32:51 ----D---- C:\Program Files\Internet Explorer
2011-04-05 21:30:19 ----D---- C:\WINDOWS\Media
2011-03-28 22:12:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-28 21:13:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 rkhdrv40;Rootkit Unhooker Driver; C:\WINDOWS\system32\drivers\rkhdrv40.sys [2011-04-10 24448]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-12-29 4026112]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
S1 SASDIFSV;SASDIFSV; \??\E:\My Download Files\antispywer\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\My Download Files\antispywer\SASKUTIL.sys []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 SASENUM;SASENUM; \??\E:\My Download Files\antispywer\SASENUM.SYS []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-05 496128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]

-----------------EOF-----------------

Re: poprosim o kontrolu logu.

Napsal: 11 dub 2011 07:34
od Roli
Zdravím, tyhle zbytečnosti fixni v HJT :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... p=aus&qkw=%s&tbid=60076
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R3 - URLSearchHook: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')


HJT najdeš zde :

C:\Program Files\trend micro\Administrator.exe

Fix znamená že spustíš HJT Obrázek

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Jinak nic špatného nevidím, ale měl bych dotaz, co takhle používat nějaký antivir ?

Re: poprosim o kontrolu logu.

Napsal: 11 dub 2011 08:35
od ringov
Diky za pomoc.Spyware terminator je zly?Ktory antivir je najlepsi? :) este tumam jeden problem zo Spyware terminatorom.Ked otvaram tento pocitac alebo iny subor ,spyware terminator vypise ze zablokoval tuhle akci.Prosim pomoc.

Re: poprosim o kontrolu logu.

Napsal: 11 dub 2011 09:30
od ringov
ringov píše:Diky za pomoc.Spyware terminator je zly?Ktory antivir je najlepsi? :) este tumam jeden problem zo Spyware terminatorom.Ked otvaram tento pocitac alebo iny subor ,spyware terminator vypise ze zablokoval tuhle akci.Prosim pomoc.

Re: poprosim o kontrolu logu.

Napsal: 11 dub 2011 10:26
od tuvok07
Vy jste, koukám, ani nedořešil problém kde se vám věnovala Motji
http://www.viry.cz/forum/viewtopic.php? ... 7&start=15
Zkuste být trpělivější, rádci na vás nemají celý den a nejste tu sám. :evil:

Re: poprosim o kontrolu logu.

Napsal: 11 dub 2011 10:28
od ringov
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-11 11:25:53
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (40%) free of 8 GB
Total RAM: 511 MB (23% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:26, on 11.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Plocha\programi\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download with Star Downloader - E:\My Download Files\ACCELELATOR PLUS\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3801 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"=C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^setup_9.0.0.722_09.04.2011_10-43.lnk]
E:\kasper\VIRUSR~1\SETUP_~1.20~\startup.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"D:\hry\Nová složka (2)\age2_x1.exe"="D:\hry\Nová složka (2)\age2_x1.exe:*:Enabled:Age of Empires II Expansion"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-04-11 07:05:07 ----D---- C:\Program Files\Crawler
2011-04-10 23:01:44 ----SHD---- C:\RECYCLER
2011-04-10 22:52:11 ----D---- C:\WINDOWS\temp
2011-04-10 22:37:02 ----SD---- C:\ComboFix
2011-04-10 19:04:58 ----A---- C:\WINDOWS\system32\drivers\rkhdrv40.sys
2011-04-10 16:43:50 ----D---- C:\rsit
2011-04-10 14:15:05 ----A---- C:\WINDOWS\zip.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWSC.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWREG.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\sed.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\PEV.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\NIRCMD.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\MBR.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\grep.exe
2011-04-10 14:14:35 ----D---- C:\Qoobox
2011-04-10 12:36:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-04-10 09:33:06 ----D---- C:\Program Files\Defraggler
2011-04-10 07:21:49 ----D---- C:\WINDOWS\system32\PreInstall
2011-04-10 07:21:43 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-04-10 07:21:43 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-10 01:10:38 ----A---- C:\WINDOWS\system32\drivers\rootrepeal.sys
2011-04-09 09:21:29 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-09 07:25:29 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-04-09 06:46:03 ----D---- C:\WINDOWS\SxsCaPendDel
2011-04-08 13:30:36 ----D---- C:\Program Files\CCleaner
2011-04-08 13:29:03 ----D---- C:\Program Files\Google
2011-04-08 13:02:34 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-08 13:02:23 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-08 13:02:23 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-04-08 10:04:50 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-04-08 10:04:25 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-04-08 10:03:43 ----D---- C:\Program Files\Realtek AC97
2011-04-08 10:03:41 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-04-08 10:03:37 ----A---- C:\WINDOWS\soundman.exe
2011-04-08 10:03:36 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-04-08 10:03:32 ----A---- C:\WINDOWS\alcupd.exe
2011-04-08 10:03:32 ----A---- C:\WINDOWS\Alcrmv.exe
2011-04-07 11:48:26 ----D---- C:\Program Files\trend micro
2011-04-06 16:53:19 ----N---- C:\WINDOWS\cmaudio.ini
2011-04-06 16:53:19 ----D---- C:\Program Files\C-Media
2011-04-06 15:48:38 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-04-06 15:24:35 ----ASH---- C:\pagefile.sys
2011-04-06 08:49:29 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-04-06 00:05:19 ----D---- C:\Program Files\WinClamAVShield
2011-04-05 22:59:59 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-04-05 22:59:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-04-05 22:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-04-05 22:59:42 ----D---- C:\Program Files\Spyware Terminator
2011-04-05 22:50:52 ----D---- C:\Program Files\Secunia
2011-04-05 21:30:29 ----D---- C:\WINDOWS\WBEM
2011-04-05 21:28:55 ----HDC---- C:\WINDOWS\ie8
2011-04-05 21:28:55 ----D---- C:\WINDOWS\system32\cs-CZ
2011-04-04 17:15:57 ----HD---- C:\Program Files\WindowsUpdate
2011-04-04 15:56:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-04-04 15:34:35 ----N---- C:\Boot.bak
2011-04-04 15:34:26 ----RASHD---- C:\cmdcons
2011-04-04 15:29:15 ----D---- C:\WINDOWS\ERDNT
2011-04-04 13:46:48 ----D---- C:\Program Files\ESET
2011-04-01 10:37:23 ----A---- C:\WINDOWS\WEBTRANS.INI
2011-04-01 10:36:28 ----A---- C:\WINDOWS\WEBWTR.INI
2011-04-01 10:36:15 ----D---- C:\WINDOWS\XXLGS

======List of files/folders modified in the last 1 months======

2011-04-11 11:25:49 ----D---- C:\WINDOWS\Prefetch
2011-04-11 10:46:03 ----D---- C:\WINDOWS
2011-04-11 10:45:56 ----HD---- C:\WINDOWS\inf
2011-04-11 10:45:53 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-11 10:27:33 ----SHD---- C:\System Volume Information
2011-04-11 09:55:20 ----D---- C:\WINDOWS\system32\Restore
2011-04-11 07:05:07 ----RD---- C:\Program Files
2011-04-11 00:13:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-11 00:11:38 ----D---- C:\WINDOWS\Minidump
2011-04-10 22:55:38 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-10 22:53:11 ----D---- C:\WINDOWS\system32\config
2011-04-10 22:51:16 ----D---- C:\WINDOWS\system32\drivers
2011-04-10 22:46:57 ----D---- C:\WINDOWS\system32
2011-04-10 22:46:56 ----D---- C:\WINDOWS\AppPatch
2011-04-10 22:46:40 ----D---- C:\Program Files\Common Files
2011-04-10 19:20:57 ----RSH---- C:\boot.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\win.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\system.ini
2011-04-10 15:04:41 ----D---- C:\WINDOWS\pss
2011-04-10 15:01:26 ----SHD---- C:\WINDOWS\Installer
2011-04-10 15:01:26 ----D---- C:\Config.Msi
2011-04-10 14:55:52 ----D---- C:\WINDOWS\WinSxS
2011-04-10 14:55:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-10 12:36:34 ----SD---- C:\WINDOWS\Tasks
2011-04-10 08:21:37 ----D---- C:\WINDOWS\SoftwareDistribution
2011-04-09 22:43:21 ----D---- C:\Program Files\7-Zip
2011-04-09 22:43:10 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-04-09 12:02:00 ----D---- C:\Program Files\WinRAR
2011-04-09 09:26:00 ----D---- C:\WINDOWS\repair
2011-04-09 09:25:30 ----D---- C:\WINDOWS\Registration
2011-04-09 09:21:27 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-08 13:36:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IDM
2011-04-08 13:36:01 ----D---- C:\WINDOWS\Debug
2011-04-08 12:56:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-08 10:03:31 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-08 10:02:59 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-08 09:48:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-06 09:07:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-04-06 08:58:39 ----D---- C:\ProgramData
2011-04-06 08:55:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2011-04-06 08:17:50 ----D---- C:\Documents and Settings
2011-04-05 23:11:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-05 21:52:02 ----D---- C:\Program Files\Mozilla Firefox
2011-04-05 21:32:51 ----D---- C:\WINDOWS\Help
2011-04-05 21:32:51 ----D---- C:\Program Files\Internet Explorer
2011-04-05 21:30:19 ----D---- C:\WINDOWS\Media
2011-03-28 22:12:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-28 21:13:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 rkhdrv40;Rootkit Unhooker Driver; C:\WINDOWS\system32\drivers\rkhdrv40.sys [2011-04-10 24448]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-12-29 4026112]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S1 SASDIFSV;SASDIFSV; \??\E:\My Download Files\antispywer\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\My Download Files\antispywer\SASKUTIL.sys []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 SASENUM;SASENUM; \??\E:\My Download Files\antispywer\SASENUM.SYS []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-05 496128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]

-----------------EOF-----------------

Re: poprosim o kontrolu logu.

Napsal: 11 dub 2011 10:32
od Roli
Já jsem neřekl že je Spy T. špatný jen jsi fixnul zbytečnosti které spouští v prohlížeči.

Ohledně blokování různých akcí, to máš jeho v pravidlech co a jak má s čím dělat.

Stačí to pravidlo smazat.

Také koukám, že už svoje problémy s PC řešíš TADY s motji,

tak že by bylo dobré nezakládat několik témat ohledně jednoho PC, pak je v tom hokej.

To už ti píše i tuvok07

Re: poprosim o kontrolu logu.

Napsal: 11 dub 2011 20:40
od Roli
Pokračuj s motji a zde :closed: