Stránka 1 z 2

Vir MS Removal Tool

Napsal: 08 kvě 2011 13:28
od Fers
Prosím o pomoc s virem co se tváří jako antivir MS Removal Tool. Zablokoval mi spustěni počitače v nouzovém režimu a pokud chci něco stáhnout, tak to hned vymaže, ještě zkusím do počítače dostat něco před flash disk, ale obávám se, že to provede to samé. :boxed:

Chtěl sem postupovat podle http://www.viry.cz/forum/viewtopic.php?f=13&t=111479

Re: Vir MS Removal Tool

Napsal: 08 kvě 2011 14:02
od Fers
Tak flashka naštěstí zabrala.

Tady jsou logy z RK a asw:

"
RogueKiller V5.1.1 [05/05/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: josef [Admin rights]
Mode: Scan -- Date : 05/08/2011 14:50:28

Bad processes: 0

Registry Entries: 5
[APPDT/TMP/DESKTOP] HKCU\[...]\RunOnce : fK32001NlLaL32001 (C:\ProgramData\fK32001NlLaL32001\fK32001NlLaL32001.exe) -> FOUND
[APPDT/TMP/DESKTOP] HKUS\S-1-5-21-901558432-514748668-1761453714-1000[...]\RunOnce : fK32001NlLaL32001 (C:\ProgramData\fK32001NlLaL32001\fK32001NlLaL32001.exe) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{9CDFF654-D60B-4FF4-B9DE-6C53503B724F} : NameServer (192.168.0.254,62.240.178.250) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{9CDFF654-D60B-4FF4-B9DE-6C53503B724F} : NameServer (192.168.0.254,62.240.178.250) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND

HOSTS File:
127.0.0.1 localhost
::1 localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt
"

"
aswMBR version 0.9.5.256 Copyright(c) 2011 AVAST Software
Run date: 2011-05-08 14:51:32
-----------------------------
14:51:32.711 OS Version: Windows 6.0.6002 Service Pack 2
14:51:32.711 Number of processors: 2 586 0xF0D
14:51:32.711 ComputerName: NTB-PC UserName: josef
14:51:34.021 Initialize success
14:51:43.163 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
14:51:43.163 Disk 0 Vendor: WDC_WD2500BEVS-22UST0 01.01A01 Size: 238475MB BusType: 3
14:51:45.191 Disk 0 MBR read successfully
14:51:45.191 Disk 0 MBR scan
14:51:45.191 Disk 0 unknown MBR code
14:51:47.203 Disk 0 scanning sectors +488394752
14:51:47.234 Disk 0 scanning C:\Windows\system32\drivers
14:51:54.020 Service scanning
14:51:55.721 Disk 0 trace - called modules:
14:51:55.736 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x85d251f8]<<
14:51:55.736 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x867ccac8]
14:51:55.736 3 CLASSPNP.SYS[8adc88b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x84f44b98]
14:51:55.736 \Driver\atapi[0x85df3f10] -> IRP_MJ_CREATE -> 0x85d251f8
14:51:55.752 Scan finished successfully
14:52:21.086 Disk 0 MBR has been saved successfully to "C:\Users\josef\Desktop\MBR.dat"
14:52:21.086 The log file has been saved successfully to "C:\Users\josef\Desktop\aswMBR.txt"
"
Povoleno je pouze tlačítko FixMBR (Fix ne), jak mám prosím postupovat dále?

Re: Vir MS Removal Tool

Napsal: 08 kvě 2011 21:06
od motji
Dobrý večer :)

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.

Pokud nepujde, napište :)

Re: Vir MS Removal Tool

Napsal: 09 kvě 2011 11:28
od Fers
Prosím neděste se, už sem provedl i promazání, vádal sem si dobrý pozor na to, co sme mazal, zde je log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 6531

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

8.5.2011 17:58:42
mbam-log-2011-05-08 (17-58-42).txt

Typ kontroly: Úplný test (C:\|D:\|)
Testované objekty: 698260
Uplynulý čas: 2 hodin, 22 minut, 25 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 2
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 13

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\fK32001NlLaL32001 (Trojan.FakeAlert) -> Value: fK32001NlLaL32001 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{B922D405-6D13-4A2B-AE89-08A030DA4402}\COMPONENTS\PDFFORGETOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: PDFFORGETOOLBARFF.DLL -> Quarantined and deleted successfully.

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\programdata\fk32001nllal32001\fk32001nllal32001.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\program files\KLC\SMAC\patch.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\program files\mozilla firefox\extensions\{b922d405-6d13-4a2b-ae89-08a030da4402}\components\pdfforgetoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\Users\josef\AppData\LocalLow\Sun\Java\deployment\cache\6.0\3\17427443-76534c55 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\josef\Desktop\rk_quarantine\fk32001nllal32001.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Windows\System32\02BED.tmp (Worm.Conficker) -> Quarantined and deleted successfully.
c:\Windows\System32\083C2.tmp (Worm.Conficker) -> Quarantined and deleted successfully.
c:\Windows\System32\0A3DA.tmp (Worm.Conficker) -> Quarantined and deleted successfully.
d:\Programy\pro-e wildfire 4.0\dsrc\i486_nt\obj\ptc.distributed.services.generic-patch.exe (Riskware.Tool.CK) -> Quarantined and deleted successfully.
d:\Programy\pro-e wildfire 4.0\i486_nt\obj\ptc.pro engineer.wildfire.4.0.generic-patch.exe (Riskware.Tool.CK) -> Quarantined and deleted successfully.
d:\Programy\pro-e wildfire 4.0\i486_nt\obj\ptc.pro mechanica.wildfire.4.0.generic-patch.exe (Riskware.Tool.CK) -> Quarantined and deleted successfully.
d:\Programy\pro-e wildfire 4.0\mech\i486_nt\bin\ptc.pro mechanica.wildfire.4.0.generic-patch.exe (Riskware.Tool.CK) -> Quarantined and deleted successfully.
c:\Users\josef\Desktop\Winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

Re: Vir MS Removal Tool

Napsal: 09 kvě 2011 12:32
od motji
Já se neděsím, ale ten winlogon byl pěkný chyták :D .

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
-přejmenujte combofix na cokoliv.com

Re: Vir MS Removal Tool

Napsal: 09 kvě 2011 15:59
od Fers
Měl sem pocit, že "winlog" už nepotřebuju :)

Po litém boji s AVG, které sem sice vypl včetně všech služeb a firewallu (nakonec pomohl až úspěšný uninstall) vkládám log z combofix:

ComboFix 11-05-08.04 - josef 09.05.2011 16:35:39.2.2 - x86
Microsoft® Windows Vista™ Enterprise 6.0.6002.2.1250.420.1033.18.3069.1896 [GMT 2:00]
Spuštěný z: c:\users\josef\Desktop\cokoliv.com
AV: AVG Anti-Virus Free *Disabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}
SP: AVG Anti-Virus Free *Disabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\pdfforge Toolbar\WiDGitoolbarie.dll
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\StdKeyPad.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-09 do 2011-05-09 )))))))))))))))))))))))))))))))
.
.
2011-05-09 14:45 . 2011-05-09 14:45 -------- d-----w- c:\users\josef\AppData\Local\temp
2011-05-09 14:45 . 2011-05-09 14:45 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-05-09 14:45 . 2011-05-09 14:45 -------- d-----w- c:\users\Desktop\AppData\Local\temp
2011-05-09 14:45 . 2011-05-09 14:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-08 13:25 . 2011-05-08 13:25 -------- d-----w- c:\users\josef\AppData\Roaming\Malwarebytes
2011-05-08 13:24 . 2011-05-08 13:24 -------- d-----w- c:\programdata\Malwarebytes
2011-05-08 13:24 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-08 13:24 . 2011-05-08 13:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-08 13:24 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-08 10:42 . 2011-05-08 15:58 -------- d-----w- c:\programdata\fK32001NlLaL32001
2011-05-07 07:39 . 2011-04-11 07:04 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{60F9F5D4-6733-4AD8-AF54-D3F0F3E74736}\mpengine.dll
2011-05-01 07:39 . 2011-04-14 16:38 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-01 07:39 . 2011-04-14 16:38 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-01 07:39 . 2011-04-14 16:38 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-01 07:39 . 2011-04-14 16:38 465880 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-01 07:39 . 2011-04-14 16:38 1874904 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-01 07:39 . 2011-04-14 16:38 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-01 07:39 . 2010-01-01 08:00 1974616 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-05-01 07:39 . 2010-01-01 08:00 1892184 ----a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-29 13:40 . 2011-04-29 13:40 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-04-29 13:39 . 2011-04-29 13:42 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-04-27 08:50 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-04-27 08:50 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 08:50 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-21 17:27 . 2011-04-21 17:27 -------- d--h--w- c:\programdata\CanonIJScan
2011-04-21 17:27 . 2011-04-21 17:27 -------- d-----w- c:\users\josef\AppData\Roaming\Canon
2011-04-13 06:51 . 2011-03-03 13:25 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-04-13 06:51 . 2011-02-16 16:21 430080 ----a-w- c:\windows\system32\vbscript.dll
2011-04-13 06:51 . 2011-03-03 15:42 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-13 06:51 . 2011-03-03 10:50 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-04-12 17:18 . 2011-04-12 17:18 -------- d-----w- c:\users\josef\AppData\Local\Canon Easy-PhotoPrint EX
2011-04-12 17:17 . 2011-04-12 17:17 -------- d--h--w- c:\programdata\CanonIJEPPEX2
2011-04-12 17:17 . 2011-04-12 17:17 -------- d--h--w- c:\programdata\CanonEPP
2011-04-12 17:15 . 2011-04-12 17:15 -------- d--h--w- c:\programdata\CanonIJFAX
2011-04-12 17:10 . 2011-04-12 17:10 -------- d-----w- c:\program files\Common Files\CANON
2011-04-12 17:10 . 2011-04-12 17:10 -------- d-----w- c:\programdata\CanonIJWSpt
2011-04-12 17:06 . 2011-04-12 17:06 -------- d--h--w- c:\programdata\CanonBJ
2011-04-12 17:06 . 2010-09-20 03:00 74752 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAM.DLL
2011-04-12 17:06 . 2010-09-20 03:00 28672 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAM.DLL
2011-04-12 17:05 . 2011-04-12 17:05 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2011-04-12 17:04 . 2010-09-13 12:44 106496 ----a-w- c:\windows\system32\CNC420U.dll
2011-04-12 17:04 . 2010-09-13 12:42 1347584 ----a-w- c:\windows\system32\CNC420C.dll
2011-04-12 17:04 . 2010-09-13 12:42 114688 ----a-w- c:\windows\system32\CNC420I.dll
2011-04-12 17:04 . 2010-09-06 15:03 315392 ----a-w- c:\windows\system32\CNC420L.dll
2011-04-12 17:04 . 2008-08-25 16:02 15872 ----a-w- c:\windows\system32\CNHMCA.dll
2011-04-12 17:03 . 2010-09-20 03:00 303104 ----a-w- c:\windows\system32\CNMLMAM.DLL
2011-04-12 17:02 . 2010-10-21 03:00 257024 ----a-w- c:\windows\system32\CNCALAM.DLL
2011-04-12 17:02 . 2010-06-03 06:11 94208 ----a-w- c:\windows\system32\CNC420O.dll
2011-04-12 17:02 . 2010-09-07 01:58 180224 ----a-w- c:\windows\system32\CNMIUAM.DLL
2011-04-12 17:02 . 2011-04-12 17:02 -------- d-----w- c:\windows\system32\STRING
2011-04-12 17:02 . 2010-09-08 07:26 34816 ----a-w- c:\windows\system32\CNMNPUI.DLL
2011-04-12 16:59 . 2011-04-12 17:12 -------- d-----w- c:\program files\Canon
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\system32\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-03 15:40 . 2011-04-27 08:50 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-27 08:50 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-27 08:50 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-27 08:50 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-02-22 14:13 . 2011-03-23 08:03 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-23 08:03 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-23 08:03 797696 ----a-w- c:\windows\system32\FntCache.dll
2007-02-08 09:48 . 2007-02-08 09:48 133920 ----a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2011-04-14 16:38 . 2011-05-01 07:39 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-02-21 4333568]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-11 5296128]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-09-23 413696]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-03-13 805384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2009-03-30 970240]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-27 13781536]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-07-25 2569616]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 1213848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-24 723760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^josef^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 14:50 54576 ----a-w- c:\program files\Hp\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 14:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2005-12-07 20:57 30208 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TO2SSM_McciTrayApp]
2008-08-15 16:33 1473536 ----a-w- c:\program files\TO2SSM\McciTrayApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2008-08-03 23:02 36352 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-901558432-514748668-1761453714-1000]
"EnableNotificationsRef"=dword:00000004
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 kpqpgczf;Update Monitor;c:\windows\system32\svchost.exe [2008-01-21 21504]
R2 mitsijm2011;Správce úloh aplikace Autodesk Moldflow Inventor Tool Suite Integration 2011;d:\programy\Autodesk\Autodesk Inventor 2011\Moldflow\bin\mitsijm.exe [2010-01-23 462336]
R2 tvebjmqr;dsvnsg;c:\windows\system32\svchost.exe [2008-01-21 21504]
R2 vhtpccz;Update Monitor;c:\windows\system32\svchost.exe [2008-01-21 21504]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-03-13 80912]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
R3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
R3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
R3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
R3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
R3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [2009-05-28 23600]
R3 USBNUMP;USBNUMP;c:\windows\system32\DRIVERS\USBNUMP.sys [2006-10-20 10760]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-06-07 721904]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-29 218688]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
S2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [2008-03-28 208896]
S2 NfsClnt;Client for NFS;c:\windows\system32\nfsclnt.exe [2009-04-10 50688]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-02-15 595248]
S3 i8042HDR;Keyboard Filter Driver;c:\windows\system32\DRIVERS\i8042HDR.sys [2006-10-20 13224]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
S3 NfsRdr;Client for NFS Redirector;c:\windows\system32\drivers\nfsrdr.sys [2009-04-10 195584]
S3 RpcXdr;Server for NFS Open RPC (ONCRPC);c:\windows\system32\drivers\rpcxdr.sys [2009-04-10 76800]
S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-02-15 40752]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
Akamai REG_MULTI_SZ Akamai
LPDService REG_MULTI_SZ LPDSVC
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vhtpccz
tvebjmqr
kpqpgczf
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000Core.job
- c:\users\josef\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-30 12:14]
.
2011-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000UA.job
- c:\users\josef\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-30 12:14]
.
.
------- Doplňkový sken -------
.
uStart Page = my.daemon-search.com
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
FF - ProfilePath - c:\users\josef\AppData\Roaming\Mozilla\Firefox\Profiles\6pev6r70.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8 ... &gfns=1&q=
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-CHotkey - mHotkey.exe
MSConfigStartUp-KeyPad - StdKeyPad.exe
MSConfigStartUp-NUMCHK - NumpChk.exe
MSConfigStartUp-NUMPADL - USBNUMP.exe
AddRemove-AutoCAD 2010 - English - d:\programy\Autodesk\AutoCAD 2010\Setup\Setup.exe
AddRemove-AVerMedia A309 (MiniCard, DVB-T) - c:\program files\AVerMedia\AVerMedia A309 (MiniCard
AddRemove-OpenTTD - d:\hry - nainstalované\OpenTTD\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-09 16:45
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kpqpgczf]
"ServiceDll"="c:\windows\system32\kqrqubm.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tvebjmqr]
"ServiceDll"="c:\windows\system32\kqrqubm.dll"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vhtpccz]
"ServiceDll"="c:\windows\system32\kqrqubm.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-901558432-514748668-1761453714-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:12,d8,6d,f7,68,69,25,37,f1,9b,a7,ec,6c,ba,7d,f5,3f,18,82,8d,c5,07,ba,
d5,92,8a,dc,cd,b8,08,3a,8c,52,69,65,f3,6d,62,19,9b,ad,aa,3d,d2,17,d5,c7,be,\
"??"=hex:7d,20,75,a5,b7,0c,20,9a,38,ac,13,89,55,d4,65,7c
.
[HKEY_USERS\S-1-5-21-901558432-514748668-1761453714-1000\Software\SecuROM\License information*]
"datasecu"=hex:cc,d8,63,5d,29,4a,32,1c,b7,64,7b,0b,12,16,c9,e7,54,62,4c,fa,a7,
2a,c7,de,17,33,be,4a,17,52,bc,f1,ee,de,30,0f,15,fc,c9,de,57,6d,9f,63,83,39,\
"rkeysecu"=hex:08,c2,9f,58,eb,ea,f4,31,1c,6b,7e,b5,6f,15,d7,e2
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2011-05-09 16:48:57
ComboFix-quarantined-files.txt 2011-05-09 14:48
ComboFix2.txt 2009-10-01 15:59
.
Před spuštěním: 9 592 795 136
Po spuštění: 9 160 421 376
.
- - End Of File - - C611AE5128ED373B05CA1F7E8E99A957

Re: Vir MS Removal Tool

Napsal: 09 kvě 2011 19:58
od motji
:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

KillAll::

Driver::
kpqpgczf
tvebjmqr
vhtpccz
Akamai

Netsvc::
kpqpgczf
tvebjmqr
vhtpccz
Akamai

Collect::
c:\windows\system32\kqrqubm.dll
-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci

Re: Vir MS Removal Tool

Napsal: 09 kvě 2011 22:32
od Fers
Tady je log:

ComboFix 11-05-08.04 - josef 09.05.2011 22:59:03.3.2 - x86
Microsoft® Windows Vista™ Enterprise 6.0.6002.2.1250.420.1033.18.3069.1662 [GMT 2:00]
Spuštěný z: c:\users\josef\Desktop\cokoliv.com
Použité ovládací přepínače :: c:\users\josef\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Akamai
-------\Service_kpqpgczf
-------\Service_tvebjmqr
-------\Service_vhtpccz
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-09 do 2011-05-09 )))))))))))))))))))))))))))))))
.
.
2011-05-09 21:09 . 2011-05-09 21:11 -------- d-----w- c:\users\josef\AppData\Local\temp
2011-05-09 21:09 . 2011-05-09 21:09 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-05-09 21:09 . 2011-05-09 21:09 -------- d-----w- c:\users\Desktop\AppData\Local\temp
2011-05-09 21:09 . 2011-05-09 21:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-09 16:28 . 2011-05-09 16:47 -------- d-----w- C:\Downloads
2011-05-09 14:31 . 2011-05-09 14:49 -------- d-----w- C:\cokoliv
2011-05-08 13:25 . 2011-05-08 13:25 -------- d-----w- c:\users\josef\AppData\Roaming\Malwarebytes
2011-05-08 13:24 . 2011-05-08 13:24 -------- d-----w- c:\programdata\Malwarebytes
2011-05-08 13:24 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-08 13:24 . 2011-05-08 13:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-08 13:24 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-08 10:42 . 2011-05-08 15:58 -------- d-----w- c:\programdata\fK32001NlLaL32001
2011-05-07 07:39 . 2011-04-11 07:04 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{60F9F5D4-6733-4AD8-AF54-D3F0F3E74736}\mpengine.dll
2011-05-01 07:39 . 2011-04-14 16:38 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-01 07:39 . 2011-04-14 16:38 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-01 07:39 . 2011-04-14 16:38 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-01 07:39 . 2011-04-14 16:38 465880 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-01 07:39 . 2011-04-14 16:38 1874904 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-01 07:39 . 2011-04-14 16:38 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-01 07:39 . 2010-01-01 08:00 1974616 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-05-01 07:39 . 2010-01-01 08:00 1892184 ----a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-29 13:40 . 2011-04-29 13:40 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-04-29 13:39 . 2011-04-29 13:42 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-04-27 08:50 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-04-27 08:50 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 08:50 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-21 17:27 . 2011-04-21 17:27 -------- d--h--w- c:\programdata\CanonIJScan
2011-04-21 17:27 . 2011-04-21 17:27 -------- d-----w- c:\users\josef\AppData\Roaming\Canon
2011-04-13 06:51 . 2011-03-03 13:25 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-04-13 06:51 . 2011-02-16 16:21 430080 ----a-w- c:\windows\system32\vbscript.dll
2011-04-13 06:51 . 2011-03-03 15:42 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-13 06:51 . 2011-03-03 10:50 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-04-12 17:18 . 2011-04-12 17:18 -------- d-----w- c:\users\josef\AppData\Local\Canon Easy-PhotoPrint EX
2011-04-12 17:17 . 2011-04-12 17:17 -------- d--h--w- c:\programdata\CanonIJEPPEX2
2011-04-12 17:17 . 2011-04-12 17:17 -------- d--h--w- c:\programdata\CanonEPP
2011-04-12 17:15 . 2011-04-12 17:15 -------- d--h--w- c:\programdata\CanonIJFAX
2011-04-12 17:10 . 2011-04-12 17:10 -------- d-----w- c:\program files\Common Files\CANON
2011-04-12 17:10 . 2011-04-12 17:10 -------- d-----w- c:\programdata\CanonIJWSpt
2011-04-12 17:06 . 2011-04-12 17:06 -------- d--h--w- c:\programdata\CanonBJ
2011-04-12 17:06 . 2010-09-20 03:00 74752 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAM.DLL
2011-04-12 17:06 . 2010-09-20 03:00 28672 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAM.DLL
2011-04-12 17:05 . 2011-04-12 17:05 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2011-04-12 17:04 . 2010-09-13 12:44 106496 ----a-w- c:\windows\system32\CNC420U.dll
2011-04-12 17:04 . 2010-09-13 12:42 1347584 ----a-w- c:\windows\system32\CNC420C.dll
2011-04-12 17:04 . 2010-09-13 12:42 114688 ----a-w- c:\windows\system32\CNC420I.dll
2011-04-12 17:04 . 2010-09-06 15:03 315392 ----a-w- c:\windows\system32\CNC420L.dll
2011-04-12 17:04 . 2008-08-25 16:02 15872 ----a-w- c:\windows\system32\CNHMCA.dll
2011-04-12 17:03 . 2010-09-20 03:00 303104 ----a-w- c:\windows\system32\CNMLMAM.DLL
2011-04-12 17:02 . 2010-10-21 03:00 257024 ----a-w- c:\windows\system32\CNCALAM.DLL
2011-04-12 17:02 . 2010-06-03 06:11 94208 ----a-w- c:\windows\system32\CNC420O.dll
2011-04-12 17:02 . 2010-09-07 01:58 180224 ----a-w- c:\windows\system32\CNMIUAM.DLL
2011-04-12 17:02 . 2011-04-12 17:02 -------- d-----w- c:\windows\system32\STRING
2011-04-12 17:02 . 2010-09-08 07:26 34816 ----a-w- c:\windows\system32\CNMNPUI.DLL
2011-04-12 16:59 . 2011-04-12 17:12 -------- d-----w- c:\program files\Canon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-09 16:55 . 2011-04-09 16:55 15453336 ----a-w- c:\windows\system32\xlive.dll
2011-04-09 16:55 . 2011-04-09 16:55 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
2011-03-03 15:40 . 2011-04-27 08:50 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-27 08:50 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-27 08:50 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-27 08:50 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-02-22 14:13 . 2011-03-23 08:03 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-23 08:03 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-23 08:03 797696 ----a-w- c:\windows\system32\FntCache.dll
2007-02-08 09:48 . 2007-02-08 09:48 133920 ----a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2011-04-14 16:38 . 2011-05-01 07:39 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-02-21 4333568]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-11 5296128]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-09-23 413696]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-03-13 805384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2009-03-30 970240]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-27 13781536]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-07-25 2569616]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 1213848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-24 723760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^josef^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 14:50 54576 ----a-w- c:\program files\Hp\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 14:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2005-12-07 20:57 30208 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TO2SSM_McciTrayApp]
2008-08-15 16:33 1473536 ----a-w- c:\program files\TO2SSM\McciTrayApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2008-08-03 23:02 36352 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-901558432-514748668-1761453714-1000]
"EnableNotificationsRef"=dword:00000004
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-03-13 80912]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
R3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
R3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
R3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
R3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
R3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
R3 TVICHW32;TVICHW32;c:\windows\system32\DRIVERS\TVICHW32.SYS [2009-05-28 23600]
R3 USBNUMP;USBNUMP;c:\windows\system32\DRIVERS\USBNUMP.sys [2006-10-20 10760]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-06-07 721904]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-29 218688]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
S2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [2008-03-28 208896]
S2 mitsijm2011;Správce úloh aplikace Autodesk Moldflow Inventor Tool Suite Integration 2011;d:\programy\Autodesk\Autodesk Inventor 2011\Moldflow\bin\mitsijm.exe [2010-01-23 462336]
S2 NfsClnt;Client for NFS;c:\windows\system32\nfsclnt.exe [2009-04-10 50688]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-02-15 595248]
S3 i8042HDR;Keyboard Filter Driver;c:\windows\system32\DRIVERS\i8042HDR.sys [2006-10-20 13224]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
S3 NfsRdr;Client for NFS Redirector;c:\windows\system32\drivers\nfsrdr.sys [2009-04-10 195584]
S3 RpcXdr;Server for NFS Open RPC (ONCRPC);c:\windows\system32\drivers\rpcxdr.sys [2009-04-10 76800]
S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-02-15 40752]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
Akamai REG_MULTI_SZ Akamai
LPDService REG_MULTI_SZ LPDSVC
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000Core.job
- c:\users\josef\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-30 12:14]
.
2011-05-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000UA.job
- c:\users\josef\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-30 12:14]
.
.
------- Doplňkový sken -------
.
uStart Page = my.daemon-search.com
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
FF - ProfilePath - c:\users\josef\AppData\Roaming\Mozilla\Firefox\Profiles\6pev6r70.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8 ... &gfns=1&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
.
.
.
**************************************************************************
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory:
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-901558432-514748668-1761453714-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:12,d8,6d,f7,68,69,25,37,f1,9b,a7,ec,6c,ba,7d,f5,3f,18,82,8d,c5,07,ba,
d5,92,8a,dc,cd,b8,08,3a,8c,52,69,65,f3,6d,62,19,9b,ad,aa,3d,d2,17,d5,c7,be,\
"??"=hex:7d,20,75,a5,b7,0c,20,9a,38,ac,13,89,55,d4,65,7c
.
[HKEY_USERS\S-1-5-21-901558432-514748668-1761453714-1000\Software\SecuROM\License information*]
"datasecu"=hex:cc,d8,63,5d,29,4a,32,1c,b7,64,7b,0b,12,16,c9,e7,54,62,4c,fa,a7,
2a,c7,de,17,33,be,4a,17,52,bc,f1,ee,de,30,0f,15,fc,c9,de,57,6d,9f,63,83,39,\
"rkeysecu"=hex:08,c2,9f,58,eb,ea,f4,31,1c,6b,7e,b5,6f,15,d7,e2
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4192)
c:\windows\system32\btmmhook.dll
c:\windows\System32\SysHook.dll
c:\program files\Altap Salamander 2.5\plugins\salamext.dll
c:\windows\system32\btncopy.dll
d:\programy\Virtual PC\VPCShExH.DLL
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\users\josef\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
c:\program files\Mouse Driver\KMConfig.exe
c:\program files\Mouse Driver\KMProcess.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\System32\tcpsvcs.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
.
**************************************************************************
.
Celkový čas: 2011-05-09 23:19:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-09 21:18
ComboFix2.txt 2011-05-09 14:48
ComboFix3.txt 2009-10-01 15:59
.
Před spuštěním: 9 487 454 208
Po spuštění: 8 769 699 840
.
- - End Of File - - 5A5F4B451290955E302747E842EB60F8

Re: Vir MS Removal Tool

Napsal: 10 kvě 2011 05:50
od motji
Měl jste tam confickera, pokud nejste proti, ráda bych provedla ještě pár testů, něco si musím ověřit.

:arrow: Stáhněte Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
- rozbalte a spusťte
-proběhne sken, po skončení se otevře okno s výsledky, klikněte na Save a tím si uložíte log,který sem vložíte

-Podle návodu v odkazu provedete druhý sken a log sem také vložíte.



:arrow: Stahněte z mého podpisu AVPTOOl http://www.viry.cz/forum/viewtopic.php?f=29&t=58179

-Podle návodu nainstalujte a proveďte sken
-co najde nechejte léčit, mazat
-sken může trvat několik hodin
-vložte zde log z výsledky

Re: Vir MS Removal Tool

Napsal: 10 kvě 2011 19:00
od Fers
Proti rozhodně nejsem, jen ty testy trvaly opravdu "pár hodin" :)

Tady jsou logy:

GMER 1.0.15.15627 - http://www.gmer.net

Rootkit quick scan 2011-05-10 09:12:52
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 WDC_WD2500BEVS-22UST0 rev.01.01A01
Running: gmer.exe; Driver: C:\Users\josef\AppData\Local\Temp\uwldqpow.sys


---- Devices - GMER 1.0.15 ----

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85D241F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-4 85D241F8
Device \Driver\atapi \Device\Ide\IdePort0 85D241F8
Device \Driver\atapi \Device\Ide\IdePort1 85D241F8
Device \Driver\atapi \Device\Ide\IdePort2 85D241F8
Device \Driver\atapi \Device\Ide\IdePort3 85D241F8
Device \Driver\atapi \Device\Ide\IdePort4 85D241F8
Device \Driver\msahci \Device\Ide\PciIde1Channel0 85D251F8
Device \Driver\msahci \Device\Ide\PciIde1Channel1 85D251F8
Device \Driver\msahci \Device\Ide\PciIde1Channel2 85D251F8
Device \FileSystem\Ntfs \Ntfs 85D261F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-10 10:49:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 WDC_WD2500BEVS-22UST0 rev.01.01A01
Running: gmer.exe; Driver: C:\Users\josef\AppData\Local\Temp\uwldqpow.sys


---- System - GMER 1.0.15 ----

INT 0x52 ? 86CCEF00
INT 0x62 ? 84F63BF8
INT 0x72 ? 84F63BF8
INT 0x82 ? 84F63BF8
INT 0x82 ? 84F63BF8
INT 0x82 ? 84F63BF8
INT 0x82 ? 86CCEF00
INT 0x82 ? 84F63BF8
INT 0x92 ? 86CCEF00
INT 0xA3 ? 86CCEF00
INT 0xB2 ? 86CCEF00
INT 0xB2 ? 86CCEF00

---- Kernel code sections - GMER 1.0.15 ----

? System32\Drivers\splf.sys Systém nemůže nalézt uvedenou cestu. !
.text USBPORT.SYS!DllUnload 8F7B841B 5 Bytes JMP 86CCE4E0
init C:\Windows\system32\DRIVERS\i8042HDR.sys entry point in "init" section [0x8FCADC00]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Mozilla Firefox\firefox.exe[4388] ntdll.dll!LdrLoadDll 771B93A8 5 Bytes JMP 009E1410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[5508] kernel32.dll!SetUnhandledExceptionFilter 76C2A84F 5 Bytes JMP 5E215436 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[5548] USER32.dll!SetWindowLongA 772DE7CD 5 Bytes JMP 5C528DD9 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[5548] USER32.dll!SetWindowLongW 772E13B4 5 Bytes JMP 5C528D6B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[5548] USER32.dll!GetWindowInfo 772E428E 5 Bytes JMP 5C357187 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[5548] USER32.dll!TrackPopupMenu 772F14F3 5 Bytes JMP 5C357781 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [830916D6] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [83091042] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [83091800] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [830910C0] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8309113E] \SystemRoot\System32\Drivers\splf.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [830A0E9C] \SystemRoot\System32\Drivers\splf.sys

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [733A7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [733FA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [733ABB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7339F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [733A75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7339E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [733D8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [733ADA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7339FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7339FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [733971CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7342CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [733CC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7339D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73396853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7339687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2236] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [733A2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 85D261F8
Device \Driver\netbt \Device\NetBT_Tcpip_{1B2D3E9C-9D0A-4538-BFA8-45D6BD38B95A} 8A1441F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 85D221F8
Device \Driver\usbuhci \Device\USBPDO-0 86DE81F8
Device \Driver\usbuhci \Device\USBPDO-1 86DE81F8
Device \Driver\usbehci \Device\USBPDO-2 86DE91F8
Device \Driver\usbuhci \Device\USBPDO-3 86DE81F8
Device \Driver\usbuhci \Device\USBPDO-4 86DE81F8
Device \Driver\usbuhci \Device\USBPDO-5 86DE81F8
Device \Driver\usbehci \Device\USBPDO-6 86DE91F8
Device \Driver\volmgr \Device\HarddiskVolume1 85D221F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\volmgr \Device\HarddiskVolume2 85D221F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom0 86D351F8
Device \Driver\volmgr \Device\HarddiskVolume3 85D221F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85D241F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-4 85D241F8
Device \Driver\atapi \Device\Ide\IdePort0 85D241F8
Device \Driver\atapi \Device\Ide\IdePort1 85D241F8
Device \Driver\atapi \Device\Ide\IdePort2 85D241F8
Device \Driver\atapi \Device\Ide\IdePort3 85D241F8
Device \Driver\atapi \Device\Ide\IdePort4 85D241F8
Device \Driver\msahci \Device\Ide\PciIde1Channel0 85D251F8
Device \Driver\msahci \Device\Ide\PciIde1Channel1 85D251F8
Device \Driver\msahci \Device\Ide\PciIde1Channel2 85D251F8
Device \Driver\cdrom \Device\CdRom1 86D351F8
Device \Driver\volmgr \Device\HarddiskVolume4 85D221F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\netbt \Device\NetBt_Wins_Export 8A1441F8
Device \Driver\Smb \Device\NetbiosSmb 8A1331F8
Device \Driver\netbt \Device\NetBT_Tcpip_{9CDFF654-D60B-4FF4-B9DE-6C53503B724F} 8A1441F8
Device \Driver\iScsiPrt \Device\RaidPort0 86D861F8
Device \Driver\usbuhci \Device\USBFDO-0 86DE81F8
Device \Driver\usbuhci \Device\USBFDO-1 86DE81F8
Device \Driver\usbehci \Device\USBFDO-2 86DE91F8
Device \Driver\usbuhci \Device\USBFDO-3 86DE81F8
Device \Driver\usbuhci \Device\USBFDO-4 86DE81F8
Device \Driver\usbuhci \Device\USBFDO-5 86DE81F8
Device \Driver\usbehci \Device\USBFDO-6 86DE91F8
Device \FileSystem\cdfs \Cdfs 8A296500

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cf053a5
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cf053a5@001b5955372a 0x93 0xC3 0xCF 0xD2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cf053a5@0016b8c5314c 0x74 0x55 0x68 0xB4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cf053a5@00254729c153 0x4D 0x80 0x43 0x17 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e4cf053a5@0017cdc42818 0xD6 0x5D 0x2D 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x45 0xCC 0x2E 0xAC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xAA 0x28 0x98 0xFF ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x0B 0x6F 0xA8 0x7D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xEC 0xA0 0x26 0x2D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8C 0xF0 0x04 0x65 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x99 0x53 0x63 0x3B ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e4cf053a5 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e4cf053a5@001b5955372a 0x93 0xC3 0xCF 0xD2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e4cf053a5@0016b8c5314c 0x74 0x55 0x68 0xB4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e4cf053a5@00254729c153 0x4D 0x80 0x43 0x17 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001e4cf053a5@0017cdc42818 0xD6 0x5D 0x2D 0xC1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x45 0xCC 0x2E 0xAC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xAA 0x28 0x98 0xFF ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x0B 0x6F 0xA8 0x7D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xEC 0xA0 0x26 0x2D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x8C 0xF0 0x04 0x65 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x99 0x53 0x63 0x3B ...

---- EOF - GMER 1.0.15 ----

Log z AVPTool
Automatická kontrola: dokončeno před 9 min. (události: 4, objekty: 1383851, čas: 08:21:40)
10.5.2011 11:25:01 Úloha byla spuštěna
10.5.2011 12:08:28 Zjištěno: Exploit.Java.CVE-2010-4452.a C:\Documents and Settings\josef\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\32e44eaf-12a05ca2
10.5.2011 12:08:51 Odstraněno: Exploit.Java.CVE-2010-4452.a C:\Documents and Settings\josef\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\32e44eaf-12a05ca2
10.5.2011 19:46:41 Úloha byla dokončena

Re: Vir MS Removal Tool

Napsal: 10 kvě 2011 19:57
od motji
Fajn, jak je na tom počítač?

Re: Vir MS Removal Tool

Napsal: 10 kvě 2011 20:39
od Fers
Tváří se, že funguje, sice při tvorbě druhého logu nastala modrá smrt, ale předpokládám, že to způsobil GMER a snad už s tím nebude problém :).

Re: Vir MS Removal Tool

Napsal: 10 kvě 2011 20:53
od motji
:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?

Re: Vir MS Removal Tool

Napsal: 10 kvě 2011 22:03
od Fers
Chová se už jako dřív (nic nikde nevyskakuje a nekřičí) :D

Zde je log z RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by josef at 2011-05-10 22:46:00
Microsoft® Windows Vista™ Enterprise Service Pack 2
System drive C: has 8 GB (14%) free of 60 GB
Total RAM: 3069 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:46:07, on 10.5.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Mouse Driver\StartAutorun.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\setup_9.0.0.722_10.05.2011_11-39.exe
C:\Program Files\Mouse Driver\KMConfig.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\josef\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Mouse Driver\KMProcess.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Altap Salamander 2.5\SALAMAND.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Users\josef\Desktop\RSIT.exe
C:\Program Files\trend micro\josef.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Mouse Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: setup_9.0.0.722_10.05.2011_11-39.lnk = C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\startup.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Autodesk Data Management Job Dispatch - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
O23 - Service: Autodesk EDM Server - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Mouse Driver\KMWDSrv.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Správce úloh aplikace Autodesk Moldflow Inventor Tool Suite Integration 2011 (mitsijm2011) - Unknown owner - D:\Programy\Autodesk\Autodesk Inventor 2011\Moldflow\bin\mitsijm.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe

--
End of file - 10327 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-901558432-514748668-1761453714-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2011-01-05 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08 1619352]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2011-01-20 988480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-11 5296128]
"PLFSetI"=C:\Windows\PLFSetI.exe [2007-10-23 200704]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-01-18 1033512]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-09-23 413696]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2008-03-13 805384]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"KMCONFIG"=C:\Program Files\Mouse Driver\StartAutorun.exe [2007-03-06 212992]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2009-03-30 970240]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-05-27 13781536]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-04-13 49152]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-10 932288]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-07-25 2569616]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-09-14 1213848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"=C:\Program Files\Rainlendar2\Rainlendar2.exe [2009-02-21 4333568]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-12-07 30208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TO2SSM_McciTrayApp]
C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\Hp\DIGITA~1\bin\hpqtra08.exe [2009-05-21 275768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
C:\PROGRA~1\RALINK\Common\RaUI.exe -s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^josef^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MICROS~1\Office12\ONENOTEM.EXE [2008-10-25 98696]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
setup_9.0.0.722_10.05.2011_11-39.lnk - C:\Users\josef\Desktop\Virus Removal Tool\setup_9.0.0.722_10.05.2011_11-39\startup.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2008-03-18 233888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit -
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-05-10 22:46:01 ----D---- C:\Program Files\trend micro
2011-05-10 22:46:00 ----D---- C:\rsit
2011-05-10 11:21:44 ----D---- C:\ProgramData\Kaspersky Lab
2011-05-10 11:20:42 ----A---- C:\Windows\system32\drivers\25645022.sys
2011-05-10 11:20:42 ----A---- C:\Windows\system32\drivers\25645021.sys
2011-05-10 11:20:42 ----A---- C:\Windows\system32\drivers\2564502.sys
2011-05-09 23:19:02 ----D---- C:\Windows\temp
2011-05-09 23:11:19 ----SHD---- C:\$RECYCLE.BIN
2011-05-09 18:28:24 ----D---- C:\Downloads
2011-05-09 16:31:07 ----D---- C:\cokoliv
2011-05-08 15:25:01 ----D---- C:\Users\josef\AppData\Roaming\Malwarebytes
2011-05-08 15:24:45 ----D---- C:\ProgramData\Malwarebytes
2011-05-08 15:24:45 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-05-08 15:24:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-05-08 15:24:42 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-05-08 14:32:59 ----ASH---- C:\hiberfil.sys
2011-05-08 12:42:15 ----D---- C:\ProgramData\fK32001NlLaL32001
2011-04-29 15:40:19 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-04-29 15:39:27 ----D---- C:\Program Files\DAEMON Tools Lite
2011-04-27 10:50:22 ----A---- C:\Windows\system32\Apphlpdm.dll
2011-04-27 10:50:21 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2011-04-27 10:50:18 ----A---- C:\Windows\system32\XpsPrint.dll
2011-04-21 19:27:17 ----HD---- C:\ProgramData\CanonIJScan
2011-04-21 19:27:16 ----D---- C:\Users\josef\AppData\Roaming\Canon
2011-04-13 08:52:31 ----A---- C:\Windows\system32\atmlib.dll
2011-04-13 08:52:31 ----A---- C:\Windows\system32\atmfd.dll
2011-04-13 08:52:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-04-13 08:52:28 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-04-13 08:52:28 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-04-13 08:52:28 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-13 08:52:23 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-13 08:52:23 ----A---- C:\Windows\system32\mfc42.dll
2011-04-13 08:52:20 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-04-13 08:52:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-04-13 08:52:20 ----A---- C:\Windows\system32\drivers\srv.sys
2011-04-13 08:52:17 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-13 08:52:17 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-13 08:52:17 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-13 08:52:12 ----A---- C:\Windows\system32\mshtml.dll
2011-04-13 08:52:11 ----A---- C:\Windows\system32\urlmon.dll
2011-04-13 08:52:11 ----A---- C:\Windows\system32\mshtmled.dll
2011-04-13 08:52:10 ----A---- C:\Windows\system32\wininet.dll
2011-04-13 08:52:10 ----A---- C:\Windows\system32\ieframe.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\mstime.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\msfeeds.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\iepeers.dll
2011-04-13 08:52:09 ----A---- C:\Windows\system32\ieencode.dll
2011-04-13 08:52:08 ----A---- C:\Windows\system32\ieapfltr.dll
2011-04-13 08:51:50 ----A---- C:\Windows\system32\win32k.sys
2011-04-13 08:51:48 ----A---- C:\Windows\system32\vbscript.dll
2011-04-13 08:51:48 ----A---- C:\Windows\system32\jscript.dll
2011-04-13 08:51:45 ----A---- C:\Windows\system32\inetcomm.dll
2011-04-12 19:17:25 ----HD---- C:\ProgramData\CanonIJEPPEX2
2011-04-12 19:17:25 ----HD---- C:\ProgramData\CanonEPP
2011-04-12 19:15:13 ----HD---- C:\ProgramData\CanonIJFAX
2011-04-12 19:10:26 ----D---- C:\Program Files\Common Files\CANON
2011-04-12 19:10:19 ----D---- C:\ProgramData\CanonIJWSpt
2011-04-12 19:06:25 ----HD---- C:\ProgramData\CanonBJ
2011-04-12 19:05:51 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNHMCA.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420U.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420L.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420I.dll
2011-04-12 19:04:44 ----A---- C:\Windows\system32\CNC420C.dll
2011-04-12 19:03:24 ----A---- C:\Windows\system32\CNMLMAM.DLL
2011-04-12 19:02:43 ----A---- C:\Windows\system32\CNCALAM.DLL
2011-04-12 19:02:37 ----A---- C:\Windows\system32\CNC420O.dll
2011-04-12 19:02:30 ----A---- C:\Windows\system32\CNMIUAM.DLL
2011-04-12 19:02:15 ----HD---- C:\Program Files\CanonBJ
2011-04-12 19:02:01 ----D---- C:\Windows\system32\STRING
2011-04-12 19:02:01 ----A---- C:\Windows\system32\CNMNPUI.DLL
2011-04-12 18:59:53 ----D---- C:\Program Files\Canon

======List of files/folders modified in the last 1 months======

2011-05-10 22:46:07 ----D---- C:\Windows\Prefetch
2011-05-10 22:46:01 ----RD---- C:\Program Files
2011-05-10 22:44:00 ----D---- C:\Windows\system32\Tasks
2011-05-10 22:42:45 ----SHD---- C:\System Volume Information
2011-05-10 22:38:57 ----D---- C:\Windows
2011-05-10 22:29:26 ----D---- C:\Program Files\Mozilla Firefox
2011-05-10 22:26:58 ----D---- C:\Windows\System32
2011-05-10 22:24:47 ----D---- C:\Windows\system32\drivers
2011-05-10 21:52:28 ----D---- C:\Users\josef\AppData\Roaming\PrimoPDF
2011-05-10 21:46:23 ----A---- C:\Windows\system32\~.tmp
2011-05-10 18:04:29 ----SHD---- C:\Windows\Installer
2011-05-10 13:46:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-05-10 13:46:01 ----D---- C:\Windows\inf
2011-05-10 11:21:44 ----D---- C:\ProgramData
2011-05-10 10:52:32 ----D---- C:\Users\josef\AppData\Roaming\Free Download Manager
2011-05-10 10:52:30 ----D---- C:\Windows\Minidump
2011-05-09 23:11:07 ----A---- C:\Windows\system.ini
2011-05-09 23:11:00 ----D---- C:\Windows\system32\drivers\etc
2011-05-09 23:09:37 ----D---- C:\Windows\system32\config
2011-05-09 23:05:15 ----D---- C:\Windows\AppPatch
2011-05-09 23:05:14 ----D---- C:\Program Files\Common Files
2011-05-09 19:53:45 ----D---- C:\Users\josef\AppData\Roaming\GHISLER
2011-05-09 16:45:15 ----SD---- C:\Windows\Downloaded Program Files
2011-05-09 16:45:15 ----D---- C:\Program Files\pdfforge Toolbar
2011-05-09 16:34:56 ----D---- C:\Windows\system32\catroot2
2011-05-09 16:28:31 ----D---- C:\Program Files\Common Files\Akamai
2011-05-09 16:26:43 ----D---- C:\ProgramData\avg8
2011-05-08 18:38:16 ----D---- C:\Users\josef\AppData\Roaming\Winamp
2011-05-08 18:38:16 ----D---- C:\Users\josef\AppData\Roaming\Media Player Classic
2011-05-08 18:38:15 ----D---- C:\Users\josef\AppData\Roaming\uTorrent
2011-05-08 18:38:15 ----D---- C:\Users\josef\AppData\Roaming\BitTorrent
2011-05-08 18:38:04 ----D---- C:\Windows\Debug
2011-05-08 18:27:25 ----D---- C:\Program Files\CCleaner
2011-05-08 18:03:16 ----D---- C:\Windows\Provisioning
2011-05-06 18:02:52 ----D---- C:\Config.Msi
2011-05-05 09:20:13 ----D---- C:\$AVG8.VAULT$
2011-05-01 09:39:10 ----A---- C:\Windows\MAILTRAN.INI
2011-04-29 15:41:53 ----D---- C:\Windows\system32\catroot
2011-04-29 15:40:10 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-04-29 15:39:14 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-04-27 18:05:37 ----D---- C:\Windows\winsxs
2011-04-18 15:46:44 ----A---- C:\Windows\system32\mrt.exe
2011-04-15 15:54:55 ----D---- C:\Windows\Microsoft.NET
2011-04-15 15:53:15 ----RSD---- C:\Windows\assembly
2011-04-14 20:40:19 ----D---- C:\Program Files\Windows Mail
2011-04-12 19:13:35 ----RSD---- C:\Windows\Media
2011-04-12 19:13:28 ----D---- C:\Windows\twain_32

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 25645022;25645022 Boot Guard Driver; C:\Windows\system32\DRIVERS\25645022.sys [2009-10-22 37392]
R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2009-04-11 143848]
R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2005-11-17 20640]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-06-07 721904]
R1 25645021;25645021; C:\Windows\system32\DRIVERS\25645021.sys [2009-09-25 128016]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [2006-11-02 20112]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-29 218688]
R1 setup_9.0.0.722_10.05.2011_11-39drv;setup_9.0.0.722_10.05.2011_11-39drv; C:\Windows\system32\DRIVERS\2564502.sys [2009-10-09 311312]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2009-10-30 229208]
R2 cvintdrv;cvintdrv; C:\Windows\system32\drivers\cvintdrv.sys [2007-02-21 4096]
R2 Int15;int15; \??\C:\Windows\System32\drivers\int15.sys [2008-08-19 15392]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 i8042HDR;Keyboard Filter Driver; C:\Windows\system32\DRIVERS\i8042HDR.sys [2006-10-20 13224]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-03-11 2077080]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E60x86.sys [2009-08-05 48640]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 NfsRdr;@%windir%\system32\nfsrc.dll,-5003; C:\Windows\system32\drivers\nfsrdr.sys [2009-04-10 195584]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-05-27 9850240]
R3 RpcXdr;@%windir%\system32\nfsrc.dll,-5011; C:\Windows\system32\drivers\rpcxdr.sys [2009-04-10 76800]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-01-18 196784]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 vfs101x;vfs101x; C:\Windows\system32\drivers\vfs101x.sys [2008-02-15 40752]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-10 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-04-10 507904]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-10 29696]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-03-30 79664]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 81200]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 16432]
S3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-02 21264]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-03-13 80912]
S3 KMWDFilter;KMWDFilter; \??\C:\Windows\System32\Drivers\KMWDFilter.SYS [2008-03-22 17024]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-03-29 21248]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-03-29 20096]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\Windows\system32\NSNDIS5.SYS [2004-03-24 17280]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-10 148992]
S3 RT73;RT73 USB Wireless LAN Card Driver; C:\Windows\system32\DRIVERS\rt73.sys []
S3 s115bus;Sony Ericsson Device 115 driver (WDM); C:\Windows\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS [2009-05-28 23600]
S3 USBNUMP;USBNUMP; C:\Windows\system32\DRIVERS\USBNUMP.sys [2006-10-20 10760]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-10-16 37664]
R2 Autodesk Data Management Job Dispatch;Autodesk Data Management Job Dispatch; C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe [2008-02-18 32768]
R2 Autodesk EDM Server;Autodesk EDM Server; C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe [2008-02-18 57344]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2008-01-09 823296]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service; C:\Program Files\Mouse Driver\KMWDSrv.exe [2008-03-28 208896]
R2 LPDSVC;@%systemroot%\system32\lpdsvc.dll,-500; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 mitsijm2011;Správce úloh aplikace Autodesk Moldflow Inventor Tool Suite Integration 2011; D:\Programy\Autodesk\Autodesk Inventor 2011\Moldflow\bin\mitsijm.exe [2010-01-23 462336]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 NfsClnt;@%windir%\system32\nfsrc.dll,-5001; C:\Windows\system32\nfsclnt.exe [2009-04-11 50688]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-05-27 211488]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2008-01-09 483328]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2005-08-08 167936]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-08-14 9728]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 vfsFPService;Validity Fingerprint Service; C:\Windows\system32\vfsFPService.exe [2008-02-15 595248]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-05-04 85096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-13 1045256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2005-08-02 86016]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Vir MS Removal Tool

Napsal: 11 kvě 2011 20:03
od motji
:arrow: Odinstalujte C:\Program Files\pdfforge Toolbar\



:arrow:Stáhněte OTM http://oldtimer.geekstogo.com/OTM.exe
Stáhněte na plochu Otm, 2krát klikněte na Otm,spustí se program,
Do levého okna "Paste Instructions for Items to be Moved" pod žlutou čáru zkopírujete skript

Kód: Vybrat vše

:processes
explorer.exe
 
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Program Files\DAEMON Tools Toolbar
C:\Program Files\pdfforge Toolbar
C:\Users\josef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
setup_9.0.0.722_10.05.2011_11-39.lnk 
C:\Users\josef\Desktop\Virus Removal Tool\

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"=-

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]
-klikněte na červené tlačítko Moveit!
-sem vložte obsah zeleného okénka
-Pokud se bude chtít restartovat pc, dejte YES,log pak najdete C:\_OTM\MovedFiles. Log vložte sem