Stránka 1 z 2

Prosim o kontrolu logu

Napsal: 16 kvě 2011 13:21
od vadimek
Tak měl jsem problem s nejakym virem jmenem server.exe a "nehorázné" mi to spomaluje pc tady je test log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Vadim at 2011-05-16 14:16:28
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 122 GB (80%) free of 153 GB
Total RAM: 1278 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:16:38, on 16.5.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Vadim\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Vadim\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\Vadim\Local Settings\Data aplikací\Google\Update\1.3.21.53\GoogleCrashHandler.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Vadim\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Vadim.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\system32\install\server.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Vadim\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [HKCU] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Run: [MicrosoftWindows] C:\WINDOWS\system32\Microsoft\Microsoft.exe
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\install\server.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: YoWindow.lnk = C:\Program Files\YoWindow\yowindow.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\WINDOWS\System32\appdrvrem01.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 5866 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-27 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-03-27 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-08-03 53248]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2010-07-04 17408]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2006-03-02 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC []
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC []
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName []
"PAC7302_Monitor"=C:\WINDOWS\PixArt\PAC7302\Monitor.exe [2006-11-03 319488]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-07-10 176128]
"HKLM"=C:\WINDOWS\system32\install\server.exe [2005-09-02 415236]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-05-10 3459712]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-11-14 16270848]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Policies"=C:\WINDOWS\system32\install\server.exe [2005-09-02 415236]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2006-03-02 15360]
"Google Update"=C:\Documents and Settings\Vadim\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-02-28 136176]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-02 203928]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-04-09 399736]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"HKCU"=C:\WINDOWS\system32\install\server.exe [2005-09-02 415236]
"MicrosoftWindows"=C:\WINDOWS\system32\Microsoft\Microsoft.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Policies"=C:\WINDOWS\system32\install\server.exe [2005-09-02 415236]

C:\Documents and Settings\Vadim\Nabídka Start\Programy\Po spuštění
YoWindow.lnk - C:\Program Files\YoWindow\yowindow.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-30 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\ICQ7.4\ICQ.exe"="C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe"="C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe:*:Enabled:SAMBC"
"C:\Program Files\SHOUTcast\sc_serv.exe"="C:\Program Files\SHOUTcast\sc_serv.exe:*:Enabled:sc_serv"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Documents and Settings\Vadim\Plocha\Skype\Plugin Manager\skypePM.exe"="C:\Documents and Settings\Vadim\Plocha\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Documents and Settings\Vadim\Plocha\Skype\Phone\Skype.exe"="C:\Documents and Settings\Vadim\Plocha\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2011-05-16 14:16:28 ----D---- C:\rsit
2011-05-16 14:16:28 ----D---- C:\Program Files\trend micro
2011-05-16 08:46:56 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2011-05-16 08:46:47 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2011-05-16 08:46:38 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2011-05-16 08:46:15 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2011-05-16 08:46:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2011-05-16 08:45:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2011-05-16 08:45:48 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2011-05-16 08:45:37 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2011-05-16 08:45:25 ----HDC---- C:\WINDOWS\$NtUninstallKB935448$
2011-05-16 08:45:17 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2011-05-16 08:45:07 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2011-05-16 08:44:58 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2011-05-16 08:44:46 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2011-05-16 08:44:36 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2011-05-16 08:44:27 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2011-05-16 08:44:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-05-16 08:44:08 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2011-05-16 08:43:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2011-05-16 08:43:51 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-05-16 08:43:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2011-05-16 08:43:32 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-05-16 08:43:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2011-05-16 08:43:07 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2011-05-16 08:42:59 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2011-05-16 08:42:49 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2011-05-16 08:42:35 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2011-05-16 08:42:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2011-05-16 08:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2011-05-16 08:42:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2011-05-16 08:41:52 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2011-05-16 08:41:40 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2011-05-16 08:41:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2011-05-16 08:41:16 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2011-05-16 08:41:07 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2011-05-16 08:40:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-05-16 08:40:47 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2011-05-16 08:40:38 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-05-16 08:40:28 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2011-05-16 08:40:18 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2011-05-16 08:40:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-05-16 08:39:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2011-05-16 08:39:49 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2011-05-16 08:39:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2011-05-16 08:39:24 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2011-05-16 08:39:13 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2011-05-16 08:39:03 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-05-16 08:38:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2011-05-16 08:38:37 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2011-05-16 08:38:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-05-16 08:38:18 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2011-05-16 08:38:09 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-05-16 08:37:55 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-05-16 08:37:46 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2011-05-16 08:37:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2011-05-16 08:37:26 ----HDC---- C:\WINDOWS\$NtUninstallKB901190$
2011-05-16 08:37:16 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2011-05-16 08:37:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2011-05-16 08:36:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2011-05-16 08:36:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2011-05-16 08:36:38 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2011-05-16 08:36:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2011-05-16 08:36:05 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2011-05-16 08:35:52 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2011-05-16 08:35:42 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2011-05-16 08:35:33 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2011-05-16 08:35:21 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2011-05-15 20:33:51 ----ASH---- C:\pagefile.sys
2011-05-15 19:05:56 ----D---- C:\WINDOWS\Prefetch
2011-05-15 18:59:56 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2011-05-15 18:58:55 ----D---- C:\Program Files\ComPlus Applications
2011-05-15 18:45:10 ----A---- C:\WINDOWS\system32\spxcoins.dll
2011-05-15 18:45:10 ----A---- C:\WINDOWS\system32\irclass.dll
2011-05-15 18:44:52 ----RA---- C:\WINDOWS\SETC7.tmp
2011-05-15 18:44:42 ----RA---- C:\WINDOWS\SET9C.tmp
2011-05-15 18:44:39 ----RA---- C:\WINDOWS\SET90.tmp
2011-05-15 18:44:37 ----RA---- C:\WINDOWS\SET8D.tmp
2011-05-15 18:26:44 ----D---- C:\WINDOWS\setup.pss
2011-05-15 18:26:27 ----D---- C:\WINDOWS\setupupd
2011-05-15 03:28:41 ----D---- C:\Program Files\thriXXX
2011-05-13 16:00:49 ----D---- C:\Program Files\Metin2
2011-05-13 15:34:30 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Skype Extras
2011-05-11 22:15:06 ----D---- C:\Program Files\AbiWord
2011-05-09 20:35:58 ----HD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CanonBJ
2011-05-09 20:35:46 ----A---- C:\WINDOWS\system32\CNMLM7X.DLL
2011-05-09 20:34:29 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2011-05-08 22:25:41 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-05-08 22:25:40 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-05-08 22:25:38 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-05-08 22:25:38 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-05-08 22:25:37 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-05-08 22:25:36 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-05-08 22:25:36 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-05-08 22:25:35 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-05-08 22:25:20 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-05-08 22:25:11 ----D---- C:\Program Files\AVAST Software
2011-05-08 22:25:11 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVAST Software
2011-05-08 21:55:26 ----D---- C:\Program Files\Microsoft.NET
2011-05-08 20:23:18 ----A---- C:\Documents and Settings\Vadim\Data aplikací\Steam.vbs
2011-05-08 19:12:51 ----D---- C:\Program Files\Common Files\Steam
2011-05-06 08:42:15 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Top Evidence
2011-05-06 08:42:05 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2011-05-06 08:37:37 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Big Fish Games
2011-05-06 08:36:36 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\BigFishGamesCache
2011-05-03 13:12:56 ----D---- C:\Program Files\MSI
2011-05-03 13:12:45 ----A---- C:\WINDOWS\IsUninst.exe
2011-05-03 12:48:04 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\s3graphics
2011-04-30 19:22:51 ----D---- C:\Program Files\Eidos
2011-04-29 14:58:56 ----D---- C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2011-04-29 14:51:47 ----A---- C:\WINDOWS\game.ini
2011-04-29 14:35:03 ----SHD---- C:\WINDOWS\ftpcache
2011-04-28 16:19:51 ----D---- C:\Program Files\4game
2011-04-27 16:03:58 ----D---- C:\Documents and Settings\Vadim\Data aplikací\GetRightToGo
2011-04-25 18:23:43 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2011-04-25 18:23:15 ----D---- C:\Program Files\DAEMON Tools Lite
2011-04-25 18:23:08 ----D---- C:\Documents and Settings\Vadim\Data aplikací\DAEMON Tools Lite
2011-04-25 18:22:57 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2011-04-23 12:34:06 ----D---- C:\Program Files\MSXML 4.0
2011-04-22 11:40:00 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Nokia
2011-04-22 11:37:45 ----A---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2011-04-22 11:33:54 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\PC Suite
2011-04-22 11:33:51 ----D---- C:\Documents and Settings\Vadim\Data aplikací\PC Suite
2011-04-22 11:31:37 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2011-04-22 11:31:37 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2011-04-22 11:31:37 ----A---- C:\WINDOWS\system32\ccdcmbwu.dll
2011-04-22 11:31:36 ----A---- C:\WINDOWS\system32\nmwcdcls.dll
2011-04-22 11:31:02 ----D---- C:\Program Files\Nokia
2011-04-22 11:31:02 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NokiaInstallerCache
2011-04-20 16:23:06 ----D---- C:\Documents and Settings\Vadim\Data aplikací\Cambridge Silicon Radio
2011-04-20 16:22:49 ----D---- C:\Program Files\DIFX
2011-04-20 16:20:44 ----A---- C:\WINDOWS\eSellerateEngine.dll
2011-04-20 16:20:42 ----D---- C:\Program Files\PuppetMaster
2011-04-20 16:12:14 ----D---- C:\Program Files\Sony Ericsson
2011-04-18 10:41:37 ----D---- C:\WINDOWS\system32\CatRoot_bak
2011-04-17 19:46:45 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Blizzard

======List of files/folders modified in the last 1 months======

2011-05-16 14:16:28 ----RD---- C:\Program Files
2011-05-16 14:14:57 ----D---- C:\WINDOWS\system32
2011-05-16 14:14:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-05-16 14:11:06 ----D---- C:\WINDOWS\Temp
2011-05-16 14:10:56 ----D---- C:\Documents and Settings\Vadim\Data aplikací\uTorrent
2011-05-16 14:08:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-05-16 14:08:13 ----D---- C:\WINDOWS
2011-05-16 14:03:53 ----D---- C:\WINDOWS\system32\wbem
2011-05-16 14:03:53 ----D---- C:\WINDOWS\AppPatch
2011-05-16 14:03:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-05-16 08:46:59 ----HD---- C:\WINDOWS\inf
2011-05-16 08:46:50 ----A---- C:\WINDOWS\imsins.BAK
2011-05-16 08:46:49 ----D---- C:\WINDOWS\system32\drivers
2011-05-16 08:44:44 ----D---- C:\WINDOWS\system32\CatRoot2
2011-05-16 08:43:27 ----D---- C:\WINDOWS\system32\CatRoot
2011-05-16 08:42:05 ----D---- C:\Program Files\Movie Maker
2011-05-16 08:38:30 ----D---- C:\Program Files\Outlook Express
2011-05-16 08:36:14 ----D---- C:\Program Files\Internet Explorer
2011-05-16 07:18:00 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2011-05-16 06:46:15 ----D---- C:\WINDOWS\SoftwareDistribution
2011-05-16 06:46:12 ----D---- C:\WINDOWS\Help
2011-05-15 23:57:45 ----D---- C:\WINDOWS\security
2011-05-15 23:03:56 ----D---- C:\Program Files\Valve
2011-05-15 20:40:51 ----D---- C:\WINDOWS\system
2011-05-15 20:40:50 ----D---- C:\WINDOWS\system32\Setup
2011-05-15 20:40:42 ----D---- C:\WINDOWS\system32\usmt
2011-05-15 20:40:32 ----D---- C:\WINDOWS\ime
2011-05-15 20:40:31 ----RSD---- C:\WINDOWS\Fonts
2011-05-15 20:40:30 ----D---- C:\WINDOWS\Media
2011-05-15 20:40:19 ----D---- C:\WINDOWS\PeerNet
2011-05-15 20:40:08 ----D---- C:\WINDOWS\system32\npp
2011-05-15 20:40:02 ----D---- C:\WINDOWS\msagent
2011-05-15 20:37:05 ----D---- C:\WINDOWS\system32\1029
2011-05-15 20:36:33 ----D---- C:\WINDOWS\twain_32
2011-05-15 20:35:39 ----D---- C:\WINDOWS\system32\icsxml
2011-05-15 20:35:07 ----D---- C:\WINDOWS\system32\ias
2011-05-15 20:35:02 ----D---- C:\WINDOWS\system32\1033
2011-05-15 20:33:52 ----D---- C:\WINDOWS\Driver Cache
2011-05-15 19:10:18 ----D---- C:\WINDOWS\Registration
2011-05-15 19:09:30 ----A---- C:\WINDOWS\setuplog.txt
2011-05-15 19:08:11 ----SHD---- C:\System Volume Information
2011-05-15 19:08:11 ----D---- C:\WINDOWS\system32\Restore
2011-05-15 19:05:09 ----D---- C:\WINDOWS\system32\config
2011-05-15 19:00:52 ----A---- C:\WINDOWS\OEWABLog.txt
2011-05-15 19:00:46 ----A---- C:\WINDOWS\ODBCINST.INI
2011-05-15 19:00:28 ----ASH---- C:\WINDOWS\fonts\desktop.ini
2011-05-15 18:59:59 ----RD---- C:\WINDOWS\Web
2011-05-15 18:59:51 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2011-05-15 18:59:39 ----A---- C:\WINDOWS\win.ini
2011-05-15 18:59:34 ----D---- C:\WINDOWS\system32\oobe
2011-05-15 18:59:09 ----D---- C:\WINDOWS\system32\Com
2011-05-15 18:57:19 ----SH---- C:\boot.ini
2011-05-15 18:45:16 ----A---- C:\WINDOWS\system.ini
2011-05-15 18:45:02 ----ASH---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\desktop.ini
2011-05-15 18:26:46 ----A---- C:\WINDOWS\UPGRADE.TXT
2011-05-14 21:20:05 ----D---- C:\Documents and Settings\Vadim\Data aplikací\Skype
2011-05-14 18:48:14 ----D---- C:\Documents and Settings\Vadim\Data aplikací\skypePM
2011-05-13 15:33:57 ----SHD---- C:\WINDOWS\Installer
2011-05-13 15:33:57 ----SHD---- C:\Config.Msi
2011-05-13 15:33:30 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Skype
2011-05-13 14:39:45 ----SD---- C:\Documents and Settings\Vadim\Data aplikací\Microsoft
2011-05-11 23:33:23 ----D---- C:\Program Files\Common Files
2011-05-11 22:15:21 ----D---- C:\WINDOWS\WinSxS
2011-05-11 14:46:04 ----A---- C:\WINDOWS\system32\MRT.exe
2011-05-10 17:16:33 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-05-10 12:22:05 ----D---- C:\Program Files\AlienGUIse
2011-05-09 23:16:40 ----SD---- C:\WINDOWS\Tasks
2011-05-09 23:07:32 ----D---- C:\Program Files\Notepad++
2011-05-09 23:07:32 ----D---- C:\Documents and Settings\Vadim\Data aplikací\Notepad++
2011-05-09 23:05:20 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-05-09 17:00:33 ----D---- C:\WINDOWS\Microsoft.NET
2011-05-09 17:00:22 ----RSD---- C:\WINDOWS\assembly
2011-05-08 22:41:24 ----RSHD---- C:\WINDOWS\system32\Microsoft
2011-05-08 22:36:23 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2011-05-08 21:55:38 ----D---- C:\WINDOWS\system32\en-US
2011-05-03 20:01:28 ----D---- C:\Documents and Settings\Vadim\Data aplikací\ICQ
2011-05-03 18:10:11 ----D---- C:\WINDOWS\system32\DirectX
2011-05-03 13:28:13 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-05-03 12:59:10 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-29 15:42:48 ----D---- C:\Program Files\Mozilla Firefox
2011-04-29 15:25:26 ----A---- C:\WINDOWS\ultimatecd.ini
2011-04-28 20:53:14 ----D---- C:\Documents and Settings\Vadim\Data aplikací\vlc
2011-04-27 16:07:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\firebird
2011-04-27 16:06:08 ----D---- C:\Program Files\SpacialAudio
2011-04-25 18:03:46 ----D---- C:\WINDOWS\system32\drivers\UMDF
2011-04-17 12:42:34 ----HD---- C:\WINDOWS\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 gagp30kx;Filtr Microsoft Generic AGPv3.0 pro procesorovou platformu K8; C:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2004-08-03 46464]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 9728]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
R0 xfilt;VIA SATA IDE Hot-plug Driver; C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 11264]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-05-10 30808]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 appdrv01;Application Driver (01); C:\WINDOWS\System32\Drivers\appdrv01.sys [2011-03-06 2915944]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-05-10 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-05-10 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-05-10 307928]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-05-10 49240]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-04-25 218688]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2006-03-02 14848]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-05-10 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-05-10 102616]
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2006-03-02 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-15 4225920]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 PAC7302;Messenger 310; C:\WINDOWS\system32\DRIVERS\PAC7302.SYS [2007-06-14 457856]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-09-12 659456]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2006-03-02 31616]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-03-02 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-03-02 20480]
S0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-04-09 717296]
S2 StudioPro;StudioPro webcam; C:\WINDOWS\system32\DRIVERS\StudioPro.sys [2006-12-03 124416]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 cpuz135;cpuz135; \??\C:\WINDOWS\TEMP\cpuz135\cpuz135_x32.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 injectDLL;injectDLL; \??\C:\Documents and Settings\Vadim\Plocha\M2Fish 3.0.8\injectDLL.sys []
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\C:\PROGRA~1\MSI\MSIWDev\msibios32_100507.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2006-03-02 10880]
S3 NTIOLib_1_0_8;NTIOLib_1_0_8; \??\C:\PROGRA~1\MSI\MSIWDev\NTIOLib.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 sermouse;Ovladač sériové myši; C:\WINDOWS\system32\DRIVERS\sermouse.sys [2006-03-02 17664]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2006-03-02 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2006-03-02 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2006-03-02 25600]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2009-01-30 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-05-10 42184]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-03-27 153376]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2006-03-02 14336]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\WINDOWS\System32\appdrvrem01.exe [2011-03-06 304528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
Děkují za pomoc

Re: Prosim o kontrolu logu

Napsal: 16 kvě 2011 13:55
od vyosek
Zdravim a pekny den preji :)

:arrow: Ono je tam toho vic - cela zoo i s babkou pokladni

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Prosim o kontrolu logu

Napsal: 16 kvě 2011 14:25
od vadimek
ComboFix 11-05-15.04 - Vadim 16.05.2011 15:09:08.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.1278.545 [GMT 2:00]
Spuštěný z: c:\documents and settings\Vadim\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\install
c:\windows\system32\install\server.exe
c:\windows\system32\paypal.url
c:\windows\system32\winx.url
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-16 do 2011-05-16 )))))))))))))))))))))))))))))))
.
.
2011-05-16 12:16 . 2011-05-16 12:16 -------- d-----w- C:\rsit
2011-05-16 12:16 . 2011-05-16 12:16 -------- d-----w- c:\program files\trend micro
2011-05-16 05:44 . 2008-06-14 18:00 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-05-16 05:43 . 2010-02-24 12:31 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-05-16 05:42 . 2010-02-16 19:34 2060544 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-05-16 05:42 . 2010-02-16 19:34 2183552 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-05-16 05:42 . 2010-02-16 19:34 2018816 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-05-16 05:42 . 2010-02-16 19:34 2139136 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-05-15 17:11 . 2011-05-15 17:11 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 17:02 . 2001-10-24 10:25 57856 -c--a-w- c:\windows\system32\dllcache\EXCH_scripto.dll
2011-05-15 17:01 . 2006-03-02 12:00 18944 -c--a-w- c:\windows\system32\dllcache\cprofile.exe
2011-05-15 16:45 . 2006-03-02 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-05-15 16:45 . 2006-03-02 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-05-15 16:45 . 2006-03-02 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-05-15 16:45 . 2006-03-02 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-05-15 16:44 . 2006-03-02 12:00 14573 ----a-r- c:\windows\SETC7.tmp
2011-05-15 16:44 . 2006-03-02 12:00 14043 ----a-r- c:\windows\SET9C.tmp
2011-05-15 16:44 . 2006-03-02 12:00 1086058 ----a-r- c:\windows\SET90.tmp
2011-05-15 16:44 . 2006-03-02 12:00 1014483 ----a-r- c:\windows\SET8D.tmp
2011-05-15 01:28 . 2011-05-15 01:29 -------- d-----w- c:\program files\thriXXX
2011-05-13 14:00 . 2011-05-13 21:43 -------- d-----w- c:\program files\Metin2
2011-05-13 13:34 . 2011-05-13 13:34 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Skype Extras
2011-05-13 12:39 . 2011-05-13 12:39 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\Identities
2011-05-11 20:16 . 2011-05-12 20:22 -------- d-----w- c:\documents and settings\Vadim\AbiSuite
2011-05-11 20:15 . 2011-05-11 20:15 -------- d-----w- c:\program files\AbiWord
2011-05-09 18:35 . 2011-05-09 18:35 -------- d--h--w- c:\documents and settings\All Users.WINDOWS\Data aplikací\CanonBJ
2011-05-09 18:35 . 2006-07-31 03:00 65024 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP7X.DLL
2011-05-09 18:35 . 2006-07-31 03:00 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD7X.DLL
2011-05-09 18:35 . 2006-07-31 03:00 161792 ----a-w- c:\windows\system32\CNMLM7X.DLL
2011-05-09 18:34 . 2004-08-03 21:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-05-08 20:25 . 2011-05-10 11:59 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-05-08 20:25 . 2011-05-10 12:03 307928 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-05-08 20:25 . 2011-05-10 12:02 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-05-08 20:25 . 2011-05-10 11:59 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-05-08 20:25 . 2011-05-10 12:03 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-08 20:25 . 2011-05-10 12:02 102616 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-05-08 20:25 . 2011-05-10 12:02 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-05-08 20:25 . 2011-05-10 11:59 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-05-08 20:25 . 2011-05-10 12:10 40112 ----a-w- c:\windows\avastSS.scr
2011-05-08 20:25 . 2011-05-10 12:10 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-05-08 20:25 . 2011-05-08 20:25 -------- d-----w- c:\program files\AVAST Software
2011-05-08 20:25 . 2011-05-08 20:25 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\AVAST Software
2011-05-08 19:55 . 2011-05-08 19:55 -------- d-----w- c:\program files\Microsoft.NET
2011-05-08 18:23 . 2011-05-08 18:24 250 ----a-w- c:\documents and settings\Vadim\Data aplikací\Steam.vbs
2011-05-08 17:12 . 2011-05-08 17:12 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Nabdka Start
2011-05-08 17:12 . 2011-05-08 20:01 -------- d-----w- c:\program files\Common Files\Steam
2011-05-08 16:04 . 2011-05-08 16:04 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\AOL
2011-05-06 06:42 . 2011-05-06 06:42 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\Top Evidence
2011-05-06 06:42 . 2011-05-06 06:42 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Top Evidence
2011-05-06 06:42 . 2011-05-06 07:42 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Data aplikací\TEMP
2011-05-06 06:37 . 2011-05-09 21:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Big Fish Games
2011-05-06 06:36 . 2011-05-09 21:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\BigFishGamesCache
2011-05-03 11:35 . 2011-05-03 11:35 -------- d-----w- c:\documents and settings\Vadim\SystemRequirementsLab
2011-05-03 11:12 . 2011-05-03 11:27 -------- d-----w- c:\program files\MSI
2011-05-03 11:12 . 1998-10-02 17:00 327168 ----a-w- c:\windows\IsUninst.exe
2011-05-03 11:05 . 2011-05-09 21:05 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\eSupport.com
2011-05-03 10:48 . 2011-05-03 10:48 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\s3graphics
2011-04-30 17:22 . 2011-04-30 17:22 -------- d-----w- c:\program files\Eidos
2011-04-29 18:33 . 2011-04-29 18:33 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Uniblue
2011-04-29 12:58 . 2011-05-09 21:10 -------- d-----w- c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2011-04-29 12:35 . 2011-04-29 12:35 -------- d-sh--w- c:\windows\ftpcache
2011-04-28 14:20 . 2011-04-28 14:20 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\4GameZapuskatr
2011-04-28 14:19 . 2011-05-09 21:03 -------- d-----w- c:\program files\4game
2011-04-27 14:07 . 2011-05-11 21:39 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\SpacialAudio
2011-04-27 14:03 . 2011-04-27 14:04 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\GetRightToGo
2011-04-25 16:23 . 2011-04-25 16:23 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-04-25 16:23 . 2011-04-25 16:23 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-04-25 16:23 . 2011-04-29 12:34 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\DAEMON Tools Lite
2011-04-25 16:22 . 2011-04-25 16:23 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2011-04-24 00:22 . 2011-04-24 00:22 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\PC Suite
2011-04-23 10:34 . 2011-04-23 10:34 -------- d-----w- c:\program files\MSXML 4.0
2011-04-22 09:40 . 2011-04-22 09:40 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikacĂ­
2011-04-22 09:40 . 2011-04-22 09:40 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Nokia
2011-04-22 09:37 . 2008-11-07 16:55 16928 ----a-w- c:\windows\system32\spmsgXP_2k3.dll
2011-04-22 09:34 . 2011-04-22 09:36 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\Nokia
2011-04-22 09:33 . 2011-04-25 16:03 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\PC Suite
2011-04-22 09:33 . 2011-04-22 09:39 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\PC Suite
2011-04-22 09:31 . 2010-07-30 12:17 111104 ----a-w- c:\windows\system32\ccdcmbwu.dll
2011-04-22 09:31 . 2010-07-30 12:17 604160 ----a-w- c:\windows\system32\nmwcdcocls.dll
2011-04-22 09:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-22 09:31 . 2010-07-30 12:17 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2011-04-22 09:31 . 2011-05-10 15:16 -------- d-----w- c:\program files\Nokia
2011-04-22 05:25 . 2011-04-22 05:25 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY.000\Data aplikací\TuneUp Software
2011-04-20 14:23 . 2011-04-20 14:23 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\Cambridge Silicon Radio
2011-04-20 14:22 . 2011-04-22 09:32 -------- d-----w- c:\program files\DIFX
2011-04-20 14:20 . 2011-04-20 14:20 356352 ----a-w- c:\windows\eSellerateEngine.dll
2011-04-20 14:20 . 2011-05-09 21:08 -------- d-----w- c:\program files\PuppetMaster
2011-04-20 14:12 . 2011-05-09 21:12 -------- d-----w- c:\program files\Sony Ericsson
2011-04-18 13:38 . 2011-04-18 13:38 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\AbsoluteTelnet
2011-04-18 08:41 . 2011-04-18 08:46 -------- d-----w- c:\windows\system32\CatRoot_bak
2011-04-17 21:23 . 2011-04-17 21:23 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY.000\Plocha
2011-04-17 17:46 . 2011-04-17 17:46 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Blizzard
2011-04-17 10:33 . 2011-04-17 10:33 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\InstallShield
2011-04-16 17:31 . 2006-11-03 08:59 48128 ----a-w- c:\windows\system32\Remove.exe
2011-04-16 17:31 . 2011-04-16 17:31 -------- d-----w- c:\windows\PixArt
2011-04-16 17:31 . 2011-04-16 17:31 -------- d-----w- c:\program files\Common Files\PAC7302
2011-04-16 17:30 . 2011-04-16 17:30 -------- d-----w- c:\windows\Downloaded Installations
2011-04-16 17:28 . 2005-04-03 18:56 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-04-16 17:28 . 2003-03-19 10:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-04-16 17:28 . 2003-02-21 18:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-04-16 17:25 . 2011-04-16 17:26 -------- d-----w- c:\windows\Album
2011-04-16 17:25 . 2011-04-16 17:25 -------- d-----w- c:\program files\KYE
2011-04-16 17:25 . 2011-04-16 17:25 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\InstallShield
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-08 23:26 . 2011-04-08 23:26 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-03-27 18:02 . 2011-03-27 18:02 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-03-27 18:02 . 2011-03-27 18:02 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-13 11:49 . 2011-03-13 11:58 219648 -c--a-w- c:\windows\system32\uxtheme.dll.backup
2011-03-11 13:48 . 2011-03-11 13:48 687104 ----a-w- c:\windows\system32\yowindow.scr
2011-03-06 12:33 . 2011-03-06 12:33 2915944 ----a-w- c:\windows\system32\drivers\appdrv01.sys
2011-03-06 12:33 . 2011-03-06 12:33 304528 ----a-w- c:\windows\system32\appdrvrem01.exe
2011-02-17 12:54 . 2008-05-05 06:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2011-04-29 13:42 . 2011-03-31 13:38 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-02 203928]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-04-08 399736]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-08-03 53248]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"S3Trayp"="S3trayp.exe" [2006-07-10 176128]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
.
c:\documents and settings\Vadim\Nabˇdka Start\Programy\Po spuçtŘnˇ\
YoWindow.lnk - c:\program files\YoWindow\yowindow.exe [2011-3-11 742912]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Vadim\\Plocha\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Documents and Settings\\Vadim\\Plocha\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1386:TCP"= 1386:TCP:1386
"21:TCP"= 21:TCP:FTP
"21:UDP"= 21:UDP:FTP2
"27015:TCP"= 27015:TCP:27015
"27015:UDP"= 27015:UDP:27015
.
R1 appdrv01;Application Driver (01);c:\windows\system32\drivers\appdrv01.sys [6.3.2011 14:33 2915944]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [8.5.2011 22:25 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.5.2011 22:25 307928]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [25.4.2011 18:23 218688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.5.2011 22:25 19544]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.4.2011 1:26 717296]
S2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc --> c:\windows\System32\appdrvrem01.exe svc [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 StudioPro;StudioPro webcam;c:\windows\system32\drivers\StudioPro.sys [3.3.2011 18:50 124416]
S3 cpuz135;cpuz135;\??\c:\windows\TEMP\cpuz135\cpuz135_x32.sys --> c:\windows\TEMP\cpuz135\cpuz135_x32.sys [?]
S3 injectDLL;injectDLL;c:\documents and settings\Vadim\Plocha\M2Fish 3.0.8\injectDLL.sys [13.5.2011 15:41 28944]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\progra~1\MSI\MSIWDev\msibios32_100507.sys [10.5.2010 10:44 25912]
S3 NTIOLib_1_0_8;NTIOLib_1_0_8;c:\progra~1\MSI\MSIWDev\NTIOLib.sys [27.1.2011 14:43 7680]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
.
------- Doplňkový sken -------
.
uStart Page = my.daemon-search.com
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
FF - ProfilePath - c:\documents and settings\Vadim\Data aplikací\Mozilla\Firefox\Profiles\ru51zpwh.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://my.daemon-search.com/startpage
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-MicrosoftWindows - c:\windows\system32\Microsoft\Microsoft.exe
HKLM-Run-MSPY2002 - c:\windows\system32\IME\PINTLGNT\ImScInst.exe
HKLM-Run-PHIME2002ASync - c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
HKLM-Run-PHIME2002A - c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Valve_0 - c:\program files\Valve\Uninstall.exe
AddRemove-VLC media player - c:\program files\VideoLAN\VLC\uninstall.exe
AddRemove-Counter-Strike 1.6_is1 - c:\counter-strike 1.6\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-16 15:19
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\docume~1\Vadim\LOCALS~1\Temp\Vadim7 8 bytes
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1004336348-1202660629-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
[HKEY_USERS\S-1-5-21-1004336348-1202660629-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{45EE8B65-EB6C-897C-39DA-0CFC22DCF8A6}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iamamlepemnmhgndeh"=hex:69,61,69,70,63,62,6c,6f,6e,65,6f,65,6e,6b,69,68,69,68,
00,00
"hacacemfgaffbnmm"=hex:6a,61,69,70,68,6c,6c,6f,6e,66,62,6a,6d,61,67,67,6a,67,
6b,6c,00,61
"iaibmjlagbgmhhlfom"=hex:63,61,69,70,6b,6c,00,7c
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2011-05-16 15:23:32
ComboFix-quarantined-files.txt 2011-05-16 13:23
.
Před spuštěním: Volných bajtů: 129 507 086 336
Po spuštění: Volných bajtů: 132 242 923 520
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - F0276F302EEF8B5A52719087E5BB0281

Re: Prosim o kontrolu logu

Napsal: 16 kvě 2011 14:37
od vyosek
:arrow: Nasledujici soubory otestujte na VirusTotalu (viz muj podpis)
  • c:\windows\IME\imjp8_1\IMJPMIG.EXE
    c:\documents and settings\Vadim\Plocha\M2Fish 3.0.8\injectDLL.sys
    c:\windows\System32\appdrvrem01.exe
  • Kliknete na Prochazet
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Kliknete na Send File
  • Pokud na Vas vyskoci obrazovka jako je nize, tak kliknete na ReAnalyse
    Obrázek
  • Vysledek analyzy sem vlozte (jako odkaz)

Re: Prosim o kontrolu logu

Napsal: 16 kvě 2011 14:48
od vadimek

Re: Prosim o kontrolu logu

Napsal: 16 kvě 2011 15:27
od vyosek
:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Rootkit::
    c:\documents and settings\Vadim\Plocha\M2Fish 3.0.8\injectDLL.sys
    
    Driver::
    injectDLL
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "1386:TCP"=-
    "21:TCP"=-
    "21:UDP"=-
    "27015:TCP"=-
    "27015:UDP"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AlcoholAutomount"=-
    "uTorrent"=-
    "DAEMON Tools Lite"=-
    
    File::
    C:\WINDOWS\system32\install\server.exe
    
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Vadim\Data aplikací\Mozilla\Firefox\Profiles\ru51zpwh.default\
    FF - prefs.js: browser.search.selectedEngine - DAEMON Search
    FF - prefs.js: browser.startup.homepage - hxxp://my.daemon-search.com/startpage
    
    Folder::
    c:\docume~1\Vadim\LOCALS~1\Temp
    
    RegLock::
    [HKEY_USERS\S-1-5-21-1004336348-1202660629-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    [HKEY_USERS\S-1-5-21-1004336348-1202660629-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{45EE8B65-EB6C-897C-39DA-0CFC22DCF8A6}*]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-1004336348-1202660629-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{45EE8B65-EB6C-897C-39DA-0CFC22DCF8A6}*]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci

Re: Prosim o kontrolu logu

Napsal: 16 kvě 2011 16:11
od vadimek
Děkuju sekaní je pryč pc je zase v pohodiče diky (:

Re: Prosim o kontrolu logu

Napsal: 16 kvě 2011 17:20
od vyosek
Poprosim o ten skript po aplikovani CFka - mozna bude treba jeste neco docistit

Re: Prosim o kontrolu logu

Napsal: 17 kvě 2011 09:41
od vadimek
ComboFix 11-05-15.04 - Vadim 16.05.2011 16:51:44.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.1278.902 [GMT 2:00]
Spuštěný z: c:\documents and settings\Vadim\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Vadim\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\windows\system32\install\server.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\Vadim\LOCALS~1\Temp
c:\docume~1\Vadim\LOCALS~1\Temp\Arabic.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Av-test.txt
c:\docume~1\Vadim\LOCALS~1\Temp\Czech.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Danish.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Dutch.bin
c:\docume~1\Vadim\LOCALS~1\Temp\English.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Finnish.bin
c:\docume~1\Vadim\LOCALS~1\Temp\French.bin
c:\docume~1\Vadim\LOCALS~1\Temp\German.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Greek.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Hebrew.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Hungarian.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Italian.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Japanese.bin
c:\docume~1\Vadim\LOCALS~1\Temp\jusched.log
c:\docume~1\Vadim\LOCALS~1\Temp\Korean.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Norwegian.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Polish.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Portuguese(Brazil).bin
c:\docume~1\Vadim\LOCALS~1\Temp\Portuguese.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Russian.bin
c:\docume~1\Vadim\LOCALS~1\Temp\SimChin.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Spanish.bin
c:\docume~1\Vadim\LOCALS~1\Temp\SWEDISH.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Thai.bin
c:\docume~1\Vadim\LOCALS~1\Temp\TradChin.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Turkish.bin
c:\docume~1\Vadim\LOCALS~1\Temp\Vadim7
c:\docume~1\Vadim\LOCALS~1\Temp\Vadim8
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_INJECTDLL
-------\Service_injectDLL
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-16 do 2011-05-16 )))))))))))))))))))))))))))))))
.
.
2011-05-16 12:16 . 2011-05-16 12:16 -------- d-----w- C:\rsit
2011-05-16 12:16 . 2011-05-16 12:16 -------- d-----w- c:\program files\trend micro
2011-05-16 05:44 . 2008-06-14 18:00 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-05-16 05:43 . 2010-02-24 12:31 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-05-16 05:42 . 2010-02-16 19:34 2060544 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-05-16 05:42 . 2010-02-16 19:34 2183552 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-05-16 05:42 . 2010-02-16 19:34 2018816 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-05-16 05:42 . 2010-02-16 19:34 2139136 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-05-15 17:11 . 2011-05-15 17:11 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-15 17:02 . 2001-10-24 10:25 57856 -c--a-w- c:\windows\system32\dllcache\EXCH_scripto.dll
2011-05-15 17:01 . 2006-03-02 12:00 18944 -c--a-w- c:\windows\system32\dllcache\cprofile.exe
2011-05-15 16:45 . 2006-03-02 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-05-15 16:45 . 2006-03-02 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-05-15 16:45 . 2006-03-02 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-05-15 16:45 . 2006-03-02 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-05-15 16:44 . 2006-03-02 12:00 14573 ----a-r- c:\windows\SETC7.tmp
2011-05-15 16:44 . 2006-03-02 12:00 14043 ----a-r- c:\windows\SET9C.tmp
2011-05-15 16:44 . 2006-03-02 12:00 1086058 ----a-r- c:\windows\SET90.tmp
2011-05-15 16:44 . 2006-03-02 12:00 1014483 ----a-r- c:\windows\SET8D.tmp
2011-05-15 01:28 . 2011-05-15 01:29 -------- d-----w- c:\program files\thriXXX
2011-05-13 14:00 . 2011-05-13 21:43 -------- d-----w- c:\program files\Metin2
2011-05-13 13:34 . 2011-05-13 13:34 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Skype Extras
2011-05-13 12:39 . 2011-05-13 12:39 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\Identities
2011-05-11 20:16 . 2011-05-12 20:22 -------- d-----w- c:\documents and settings\Vadim\AbiSuite
2011-05-11 20:15 . 2011-05-11 20:15 -------- d-----w- c:\program files\AbiWord
2011-05-09 18:35 . 2011-05-09 18:35 -------- d--h--w- c:\documents and settings\All Users.WINDOWS\Data aplikací\CanonBJ
2011-05-09 18:35 . 2006-07-31 03:00 65024 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP7X.DLL
2011-05-09 18:35 . 2006-07-31 03:00 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD7X.DLL
2011-05-09 18:35 . 2006-07-31 03:00 161792 ----a-w- c:\windows\system32\CNMLM7X.DLL
2011-05-09 18:34 . 2004-08-03 21:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-05-08 20:25 . 2011-05-10 11:59 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-05-08 20:25 . 2011-05-10 12:03 307928 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-05-08 20:25 . 2011-05-10 12:02 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-05-08 20:25 . 2011-05-10 11:59 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-05-08 20:25 . 2011-05-10 12:03 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-08 20:25 . 2011-05-10 12:02 102616 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-05-08 20:25 . 2011-05-10 12:02 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-05-08 20:25 . 2011-05-10 11:59 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-05-08 20:25 . 2011-05-10 12:10 40112 ----a-w- c:\windows\avastSS.scr
2011-05-08 20:25 . 2011-05-10 12:10 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-05-08 20:25 . 2011-05-08 20:25 -------- d-----w- c:\program files\AVAST Software
2011-05-08 20:25 . 2011-05-08 20:25 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\AVAST Software
2011-05-08 19:55 . 2011-05-08 19:55 -------- d-----w- c:\program files\Microsoft.NET
2011-05-08 18:23 . 2011-05-08 18:24 250 ----a-w- c:\documents and settings\Vadim\Data aplikací\Steam.vbs
2011-05-08 17:12 . 2011-05-08 17:12 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Nabdka Start
2011-05-08 17:12 . 2011-05-08 20:01 -------- d-----w- c:\program files\Common Files\Steam
2011-05-08 16:04 . 2011-05-08 16:04 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\AOL
2011-05-06 06:42 . 2011-05-06 06:42 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\Top Evidence
2011-05-06 06:42 . 2011-05-06 06:42 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Top Evidence
2011-05-06 06:42 . 2011-05-06 07:42 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Data aplikací\TEMP
2011-05-06 06:37 . 2011-05-09 21:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Big Fish Games
2011-05-06 06:36 . 2011-05-09 21:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\BigFishGamesCache
2011-05-03 11:35 . 2011-05-03 11:35 -------- d-----w- c:\documents and settings\Vadim\SystemRequirementsLab
2011-05-03 11:12 . 2011-05-03 11:27 -------- d-----w- c:\program files\MSI
2011-05-03 11:12 . 1998-10-02 17:00 327168 ----a-w- c:\windows\IsUninst.exe
2011-05-03 11:05 . 2011-05-09 21:05 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\eSupport.com
2011-05-03 10:48 . 2011-05-03 10:48 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\s3graphics
2011-04-30 17:22 . 2011-04-30 17:22 -------- d-----w- c:\program files\Eidos
2011-04-29 18:33 . 2011-04-29 18:33 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Uniblue
2011-04-29 12:58 . 2011-05-09 21:10 -------- d-----w- c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2011-04-29 12:35 . 2011-04-29 12:35 -------- d-sh--w- c:\windows\ftpcache
2011-04-28 14:20 . 2011-04-28 14:20 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\4GameZapuskatr
2011-04-28 14:19 . 2011-05-09 21:03 -------- d-----w- c:\program files\4game
2011-04-27 14:07 . 2011-05-11 21:39 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\SpacialAudio
2011-04-27 14:03 . 2011-04-27 14:04 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\GetRightToGo
2011-04-25 16:23 . 2011-04-25 16:23 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-04-25 16:23 . 2011-04-25 16:23 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-04-25 16:23 . 2011-04-29 12:34 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\DAEMON Tools Lite
2011-04-25 16:22 . 2011-04-25 16:23 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
2011-04-24 00:22 . 2011-04-24 00:22 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\PC Suite
2011-04-23 10:34 . 2011-04-23 10:34 -------- d-----w- c:\program files\MSXML 4.0
2011-04-22 09:40 . 2011-04-22 09:40 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikacĂ­
2011-04-22 09:40 . 2011-04-22 09:40 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Nokia
2011-04-22 09:37 . 2008-11-07 16:55 16928 ----a-w- c:\windows\system32\spmsgXP_2k3.dll
2011-04-22 09:34 . 2011-04-22 09:36 -------- d-----w- c:\documents and settings\Vadim\Local Settings\Data aplikací\Nokia
2011-04-22 09:33 . 2011-04-25 16:03 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\PC Suite
2011-04-22 09:33 . 2011-04-22 09:39 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\PC Suite
2011-04-22 09:31 . 2010-07-30 12:17 111104 ----a-w- c:\windows\system32\ccdcmbwu.dll
2011-04-22 09:31 . 2010-07-30 12:17 604160 ----a-w- c:\windows\system32\nmwcdcocls.dll
2011-04-22 09:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-22 09:31 . 2010-07-30 12:17 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2011-04-22 09:31 . 2011-05-10 15:16 -------- d-----w- c:\program files\Nokia
2011-04-22 05:25 . 2011-04-22 05:25 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY.000\Data aplikací\TuneUp Software
2011-04-20 14:23 . 2011-04-20 14:23 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\Cambridge Silicon Radio
2011-04-20 14:22 . 2011-04-22 09:32 -------- d-----w- c:\program files\DIFX
2011-04-20 14:20 . 2011-04-20 14:20 356352 ----a-w- c:\windows\eSellerateEngine.dll
2011-04-20 14:20 . 2011-05-09 21:08 -------- d-----w- c:\program files\PuppetMaster
2011-04-20 14:12 . 2011-05-09 21:12 -------- d-----w- c:\program files\Sony Ericsson
2011-04-18 13:38 . 2011-04-18 13:38 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\AbsoluteTelnet
2011-04-18 08:41 . 2011-04-18 08:46 -------- d-----w- c:\windows\system32\CatRoot_bak
2011-04-17 21:23 . 2011-04-17 21:23 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY.000\Plocha
2011-04-17 17:46 . 2011-04-17 17:46 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Blizzard
2011-04-17 10:33 . 2011-04-17 10:33 -------- d-----w- c:\documents and settings\Doma.VADIMEK\Data aplikací\InstallShield
2011-04-16 17:31 . 2006-11-03 08:59 48128 ----a-w- c:\windows\system32\Remove.exe
2011-04-16 17:31 . 2011-04-16 17:31 -------- d-----w- c:\windows\PixArt
2011-04-16 17:31 . 2011-04-16 17:31 -------- d-----w- c:\program files\Common Files\PAC7302
2011-04-16 17:30 . 2011-04-16 17:30 -------- d-----w- c:\windows\Downloaded Installations
2011-04-16 17:28 . 2005-04-03 18:56 1060864 ----a-w- c:\windows\system32\mfc71.dll
2011-04-16 17:28 . 2003-03-19 10:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-04-16 17:28 . 2003-02-21 18:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-04-16 17:25 . 2011-04-16 17:26 -------- d-----w- c:\windows\Album
2011-04-16 17:25 . 2011-04-16 17:25 -------- d-----w- c:\program files\KYE
2011-04-16 17:25 . 2011-04-16 17:25 -------- d-----w- c:\documents and settings\Vadim\Data aplikací\InstallShield
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-08 23:26 . 2011-04-08 23:26 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-03-27 18:02 . 2011-03-27 18:02 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-03-27 18:02 . 2011-03-27 18:02 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-13 11:49 . 2011-03-13 11:58 219648 -c--a-w- c:\windows\system32\uxtheme.dll.backup
2011-03-11 13:48 . 2011-03-11 13:48 687104 ----a-w- c:\windows\system32\yowindow.scr
2011-03-06 12:33 . 2011-03-06 12:33 2915944 ----a-w- c:\windows\system32\drivers\appdrv01.sys
2011-02-17 12:54 . 2008-05-05 06:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2011-04-29 13:42 . 2011-03-31 13:38 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-16_13.19.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-16 15:04 . 2011-05-16 15:04 16384 c:\windows\Temp\Perflib_Perfdata_1d0.dat
- 2006-03-02 12:00 . 2011-05-16 12:14 87486 c:\windows\system32\perfc009.dat
+ 2006-03-02 12:00 . 2011-05-16 14:18 87486 c:\windows\system32\perfc009.dat
+ 2006-03-02 12:00 . 2011-05-16 14:18 509540 c:\windows\system32\perfh009.dat
- 2006-03-02 12:00 . 2011-05-16 12:14 509540 c:\windows\system32\perfh009.dat
- 2006-03-02 12:00 . 2011-05-16 12:14 505268 c:\windows\system32\perfh005.dat
+ 2006-03-02 12:00 . 2011-05-16 14:18 505268 c:\windows\system32\perfh005.dat
+ 2006-03-02 12:00 . 2011-05-16 14:18 102690 c:\windows\system32\perfc005.dat
- 2006-03-02 12:00 . 2011-05-16 12:14 102690 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-08-03 53248]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"S3Trayp"="S3trayp.exe" [2006-07-10 176128]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
.
c:\documents and settings\Vadim\Nabˇdka Start\Programy\Po spuçtŘnˇ\
YoWindow.lnk - c:\program files\YoWindow\yowindow.exe [2011-3-11 742912]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Vadim\\Plocha\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Documents and Settings\\Vadim\\Plocha\\Skype\\Phone\\Skype.exe"=
.
R1 appdrv01;Application Driver (01);c:\windows\system32\drivers\appdrv01.sys [6.3.2011 14:33 2915944]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [8.5.2011 22:25 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.5.2011 22:25 307928]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [25.4.2011 18:23 218688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.5.2011 22:25 19544]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.4.2011 1:26 717296]
S2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc --> c:\windows\System32\appdrvrem01.exe svc [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 StudioPro;StudioPro webcam;c:\windows\system32\drivers\StudioPro.sys [3.3.2011 18:50 124416]
S3 cpuz135;cpuz135;\??\c:\windows\TEMP\cpuz135\cpuz135_x32.sys --> c:\windows\TEMP\cpuz135\cpuz135_x32.sys [?]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\progra~1\MSI\MSIWDev\msibios32_100507.sys [10.5.2010 10:44 25912]
S3 NTIOLib_1_0_8;NTIOLib_1_0_8;c:\progra~1\MSI\MSIWDev\NTIOLib.sys [27.1.2011 14:43 7680]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
.
------- Doplňkový sken -------
.
uStart Page = my.daemon-search.com
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
FF - ProfilePath - c:\documents and settings\Vadim\Data aplikací\Mozilla\Firefox\Profiles\ru51zpwh.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-16 17:05
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2924)
c:\windows\system32\MSCTF.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\VTTimer.exe
c:\windows\system32\S3trayp.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-05-16 17:09:46 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-16 15:09
ComboFix2.txt 2011-05-16 13:23
.
Před spuštěním: Volných bajtů: 132 266 119 168
Po spuštění: Volných bajtů: 132 194 627 584
.
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - F9CF0A1592A30F538FAC28240D092D60

Re: Prosim o kontrolu logu

Napsal: 17 kvě 2011 11:28
od vyosek
:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte

Re: Prosim o kontrolu logu

Napsal: 17 kvě 2011 15:21
od vadimek
All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\system32\SETA0.tmp moved successfully.
C:\WINDOWS\system32\SETA1.tmp moved successfully.
C:\WINDOWS\system32\SETA2.tmp moved successfully.
C:\WINDOWS\system32\SETA7.tmp moved successfully.
C:\WINDOWS\002612_.tmp moved successfully.
C:\WINDOWS\msdownld.tmp folder moved successfully.
C:\WINDOWS\SET21.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\SET8D.tmp moved successfully.
C:\WINDOWS\SET90.tmp moved successfully.
C:\WINDOWS\SET9C.tmp moved successfully.
C:\WINDOWS\SETBD.tmp moved successfully.
C:\WINDOWS\SETC0.tmp moved successfully.
C:\WINDOWS\SETC7.tmp moved successfully.
C:\WINDOWS\SETCC.tmp moved successfully.
C:\WINDOWS\SETF7.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 3615328 bytes

User: Administrator.VADIMEK
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 7438767 bytes

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Doma
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 119696507 bytes
->Flash cache emptied: 20050 bytes

User: Doma.VADIMEK
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 5342533 bytes
->FireFox cache emptied: 240372540 bytes
->Flash cache emptied: 55686 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService.NT AUTHORITY.000
->Temp folder emptied: 65716 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: NetworkService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Vadim
->Temp folder emptied: 1391394 bytes
->Temporary Internet Files folder emptied: 4834072 bytes
->Java cache emptied: 4637782 bytes
->FireFox cache emptied: 124543143 bytes
->Google Chrome cache emptied: 375453951 bytes
->Flash cache emptied: 71174 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 68040 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 847,00 mb


OTM by OldTimer - Version 3.1.17.2 log created on 05172011_161248

Files moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Prosim o kontrolu logu

Napsal: 17 kvě 2011 15:32
od vyosek
Jak se chova PC :???:

Re: Prosim o kontrolu logu

Napsal: 17 kvě 2011 17:19
od vadimek
Docela vporadku ale když pouštim vice lišt třeba youtube a facebook najednou tak se to seka ale pc mam dostí vykonny dive mi tohle nedelalo

Re: Prosim o kontrolu logu

Napsal: 17 kvě 2011 17:26
od vyosek
Tak jeste uklidime :James008:

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /Uninstall
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Napiste ci se chovani zlepsilo

Re: Prosim o kontrolu logu

Napsal: 17 kvě 2011 22:48
od vadimek
Mno je to o trochu lepší ale jěště pořád to není ono :/