Stránka 1 z 1

Avast hlásí worma na flashce :-(

Napsal: 27 čer 2011 09:58
od Serifus
Zdravím! Prosím o kontrolu. Spustil jsem RSIT s připojenou flashkou. Snad to bude mít úspěch. Hlásí mi to na ní worma. Pokaždé dám smazat a vždycky se to zase ohlásí :cry: Prosím o radu. Děkuji.

Logfile of random's system information tool 1.08 (written by random/random)
Run by Serifus at 2011-06-27 10:56:06
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 304 GB (66%) free of 462 GB
Total RAM: 3838 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:56:11, on 27.6.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\WinRAR\WinRAR.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Miranda\miranda32.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\trend micro\Serifus.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/defau ... l=cs&s=bsd
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://corp.setpac.ge.com/pac.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FAIESSO Helper Object - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O4 - HKLM\..\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files (x86)\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - http://support.euro.dell.com/systemprof ... emLite.CAB
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/xhtml+xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files (x86)\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: application/xhtml+xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files (x86)\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files (x86)\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files (x86)\Design Science\MathPlayer\MathMLMimer.dll
O20 - Winlogon Notify: FastAccess - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FAService - Sensible Vision - c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Kvaser Network Enumerator Service (KvEnumSrv) - KVASER AB, Mölndal, SWEDEN - C:\Program Files\Kvaser\Drivers\32\kvenumsrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: OpcEnum - OPC Foundation - C:\Windows\SysWOW64\OPCEnum.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\SysWOW64\rpcnet.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13602 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
winlogon.exe
"C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE" "C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 30025648
\??\C:\Windows\system32\conhost.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Kvaser\Drivers\32\kvenumsrv.exe"
"c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
C:\Windows\SysWOW64\rpcnet.exe
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2248
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE"
"C:\Program Files\Dell\QuickSet\quickset.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
"C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
"C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
FATrayAlert.exe
"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:4536 CREDAT:145409
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\System32\svchost.exe -k secsvcs
taskeng.exe {A5374763-01F5-49EC-ACEA-35EE24AB1643}
C:\Windows\System32\jusched.exe
"C:\Program Files (x86)\WinRAR\WinRAR.exe" "C:\Users\Serifus\Documents\Downloads\Plocha.rar"
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:4536 CREDAT:145410
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:4536 CREDAT:145411
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ecbf3641-2d36-4331-a899-94027d5ff6e9 -SystemEventPortName:HostProcess-70c71920-c4b5-418c-9b3f-3269c61675a0 -IoCancelEventPortName:HostProcess-f1be1be9-1e31-4029-9b30-7066570247c4 -NonStateChangingEventPortName:HostProcess-d9b95272-75f5-4a15-83df-1c7f7e56b0bf -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7f803866-00df-45e1-a060-bbe1907dc696
"C:\Miranda\miranda32.exe"
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:4536 CREDAT:79929
C:\Windows\system32\wbem\wmiprvse.exe
taskhost.exe $(Arg0)
"C:\Users\Serifus\Documents\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-20 43520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-07-05 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A2F122DA-055F-4df7-8F24-7354DBDBA85B}]
FAIESSOHelper Class - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll [2009-06-25 206088]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-05-21 1233288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-07-05 520192]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-05-21 1233288]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-06-26 1812776]
"Broadcom Wireless Manager UI"=C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [2009-07-17 4968960]
"QuickSet"=C:\Program Files\Dell\QuickSet\QuickSet.exe [2010-06-09 3216544]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-07-04 16328736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Software Informer"=C:\Program Files (x86)\Software Informer\softinfo.exe -autorun []
"OEXPRESS"= []
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2010-03-06 286720]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"FATrayAlert"=c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe [2009-06-25 95496]
"PDVDDXSrv"=C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2009-06-25 140520]
"FAStartup"= []
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2009-03-15 180224]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"NBAgent"=C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-03-26 1234216]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-05-10 3459712]
"Dell Webcam Central"=C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [2009-06-24 409744]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
FAPassSync

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-06-27 10:50:24 ----D---- C:\Program Files\trend micro
2011-06-27 10:50:23 ----D---- C:\rsit
2011-06-20 09:37:02 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-06-20 09:37:02 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-06-20 09:37:02 ----A---- C:\Windows\SYSWOW64\java.exe
2011-06-17 12:40:15 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-17 12:40:15 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-17 12:40:14 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-17 12:40:14 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-17 12:40:14 ----A---- C:\Windows\system32\iertutil.dll
2011-06-17 12:40:13 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-17 12:40:13 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-06-17 12:40:13 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-06-17 12:40:13 ----A---- C:\Windows\system32\urlmon.dll
2011-06-17 12:40:13 ----A---- C:\Windows\system32\jscript9.dll
2011-06-17 12:40:13 ----A---- C:\Windows\system32\jscript.dll
2011-06-17 12:40:13 ----A---- C:\Windows\system32\ieui.dll
2011-06-17 12:40:12 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-17 12:40:10 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-17 12:40:10 ----A---- C:\Windows\system32\mshtml.dll
2011-06-17 12:40:10 ----A---- C:\Windows\system32\ieframe.dll
2011-06-17 09:55:20 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-17 09:55:20 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-17 09:55:17 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-17 09:55:17 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-17 09:55:17 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-17 09:55:03 ----A---- C:\Windows\system32\win32k.sys
2011-06-17 09:55:01 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-17 09:55:01 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-17 09:55:00 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-17 09:55:00 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-17 09:55:00 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-17 09:54:59 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-17 09:54:59 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-17 09:54:57 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-17 09:54:57 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-15 21:18:30 ----D---- C:\ProgramData\Skype Extras
2011-06-15 21:09:05 ----D---- C:\Fotky

======List of files/folders modified in the last 1 months======

2011-06-27 10:56:10 ----D---- C:\Windows\Temp
2011-06-27 10:50:24 ----RD---- C:\Program Files
2011-06-27 10:09:44 ----D---- C:\Windows\System32
2011-06-27 10:09:44 ----D---- C:\Windows\inf
2011-06-27 10:09:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-27 10:06:44 ----D---- C:\Windows\system32\config
2011-06-27 09:53:15 ----A---- C:\Windows\system32\rpcnetp.exe
2011-06-27 09:53:13 ----A---- C:\Windows\SYSWOW64\rpcnet.dll
2011-06-24 19:09:43 ----SHD---- C:\System Volume Information
2011-06-24 19:05:55 ----D---- C:\Windows\SysWOW64
2011-06-22 11:00:09 ----D---- C:\Users\Serifus\AppData\Roaming\Adobe
2011-06-22 11:00:09 ----D---- C:\ProgramData\Adobe
2011-06-20 09:43:47 ----D---- C:\Windows\winsxs
2011-06-20 09:38:16 ----SHD---- C:\Windows\Installer
2011-06-20 09:38:16 ----D---- C:\Program Files (x86)\Common Files
2011-06-20 09:37:00 ----D---- C:\Program Files (x86)\Java
2011-06-17 12:58:42 ----D---- C:\Windows\system32\drivers
2011-06-17 12:58:42 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-17 12:58:41 ----D---- C:\Program Files\Internet Explorer
2011-06-17 12:43:13 ----A---- C:\Windows\system32\MRT.exe
2011-06-17 12:43:09 ----D---- C:\ProgramData\Microsoft Help
2011-06-17 12:41:13 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-06-17 12:40:44 ----D---- C:\Windows\system32\catroot
2011-06-17 12:40:43 ----D---- C:\Windows\system32\catroot2
2011-06-17 12:39:44 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-15 21:34:22 ----D---- C:\Users\Serifus\AppData\Roaming\Skype
2011-06-15 21:18:30 ----HD---- C:\ProgramData
2011-06-15 21:18:14 ----D---- C:\Windows\system32\Tasks
2011-06-15 21:18:11 ----D---- C:\Windows\Prefetch
2011-06-15 21:18:08 ----RD---- C:\Program Files (x86)\Skype
2011-06-15 21:18:03 ----D---- C:\ProgramData\Skype
2011-06-15 16:15:16 ----D---- C:\Users\Serifus\AppData\Roaming\skypePM
2011-06-14 10:25:35 ----D---- C:\Windows\system32\NDF
2011-06-06 09:57:07 ----D---- C:\Miranda
2011-06-04 18:08:40 ----D---- C:\Program Files (x86)\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2010-03-09 242792]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 287576]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 53592]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-03-15 85424]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 64344]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmpx64.sys [2009-06-25 67584]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimspx64.sys [2009-06-25 55296]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2009-06-25 57856]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2009-07-17 22520]
R3 BCM43XX;Ovladač bezdrátové karty Dell WLAN; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-07-17 2769400]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\Windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2009-03-09 60416]
R3 kcanv;Kvaser Virtual CAN Driver; C:\Windows\system32\DRIVERS\kcanv.sys [2009-10-22 64528]
R3 kvnetenum;Kvaser Network Enumerator; C:\Windows\system32\DRIVERS\kvnetenum.sys [2009-10-22 38928]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2009-08-21 84512]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys [2009-07-01 339744]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-28 28704]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-06-26 272432]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 RxFilter;RxFilter; C:\Windows\system32\DRIVERS\RxFilter.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 552448]
S3 BTHprint;Třída tiskárny protokolu Bluetooth (Microsoft); C:\Windows\system32\DRIVERS\bthprint.sys [2009-07-14 67072]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-02 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-02 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-07-02 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-02 21160]
S3 FACAP;facap, FastAccess Video Capture; C:\Windows\system32\DRIVERS\facap.sys [2008-09-25 238848]
S3 FTDIBUS;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2010-03-30 69704]
S3 FTSER2K;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2010-03-30 84808]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 33856]
S3 IT9135BDA;IT9135 BDA Devices; C:\Windows\System32\Drivers\IT9135BDA.sys [2010-02-03 113280]
S3 kcane;Kvaser USBcan II; C:\Windows\system32\DRIVERS\kcane.sys [2009-10-22 85520]
S3 kcanl;Kvaser Leaf Family Driver; C:\Windows\system32\DRIVERS\kcanl.sys [2009-10-22 93200]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 vpcuxd;Služba zástupné procedury virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcuxd.sys [2010-11-20 16384]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-05-10 42184]
R2 btwdins;Bluetooth Service; c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-02 864032]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 FAService;FAService; c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2009-06-25 2368776]
R2 KvEnumSrv;Kvaser Network Enumerator Service; C:\Program Files\Kvaser\Drivers\32\kvenumsrv.exe [2009-10-22 72208]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-07-04 382496]
R2 rpcnet;Remote Procedure Call (RPC) Net; C:\Windows\SysWOW64\rpcnet.exe [2011-04-22 58288]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-25 153952]
R2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-06 2002728]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [2009-07-17 33280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-10 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-10 136176]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 OpcEnum;OpcEnum; C:\Windows\SysWOW64\OPCEnum.exe [2008-06-11 81920]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 RoxMediaDB10;RoxMediaDB10; c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
S3 stllssvr;stllssvr; c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2009-04-30 74392]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-17 1255736]

-----------------EOF-----------------

Re: Avast hlásí worma na flashce :-(

Napsal: 27 čer 2011 11:07
od motji
Hezké poledne :)

:arrow: Zapojte do pc všechny usb klíče, flashky...co používáte

Použijte USB fix
http://www.viry.cz/forum/viewtopic.php?f=24&t=102308


:!: Před stažením vypněte rezidentní štít antiviru, má na Usbfix falešnou detekci
-spusťte
-klikněte na volbu deletion , potvrdte enter
- po skenu sem vložte log , pokud na Vás nevyskočí, najdete ho C:\UsbFix.txt

Re: Avast hlásí worma na flashce :-(

Napsal: 27 čer 2011 14:21
od Serifus
Milá Motji,

tak tady to je:

############################## | UsbFix 7.014 | [Deletion]

User: Serifus (Administrator) # SERIFUS-PC [Dell Inc. Studio XPS 1340]
Updated 24/06/10 by El Desaparecido / C_XX
Started at 15:00:02 | 27/06/2011
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com

CPU: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz
CPU 2: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz
Microsoft Windows 7 Ultimate (6.1.7601 64-Bit) # Service Pack 1
Internet Explorer 9.0.8112.16421

Windows Firewall: Enabled
RAM -> 3838 Mb
C:\ (%systemdrive%) -> Fixed drive # 451 Gb (297 Mb free - 66%) [OS] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
F:\ -> CD-ROM
G:\ -> CD-ROM
H:\ -> CD-ROM
I:\ -> Removable drive # 30 Gb (6 Mb free - 21%) [USB DISK] # FAT32

################## | Files # Infected Folders |

Not deleted ! E:\Autorun.inf

################## | Registry |


################## | Mountpoints2 |

Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\E
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\G
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\I
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{7d285f44-b0ae-11df-bb86-0026b92448b2}

################## | Listing |

[27/06/2011 - 15:04:10 | SHD ] C:\$Recycle.Bin
[07/04/2010 - 08:55:02 | D ] C:\dell
[20/02/2010 - 08:59:12 | RAH | 2944] C:\dell.sdr
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[24/05/2010 - 10:15:15 | D ] C:\EZChrom Elite
[17/06/2011 - 10:03:02 | D ] C:\Fotky
[27/06/2011 - 09:52:49 | ASH | 3018608640] C:\hiberfil.sys
[06/06/2011 - 09:57:07 | D ] C:\Miranda
[11/08/2010 - 22:13:38 | D ] C:\Moje
[18/04/2011 - 10:23:24 | D ] C:\MPC
[30/04/2010 - 11:07:19 | RHD ] C:\MSOCache
[27/06/2011 - 09:53:00 | ASH | 4024811520] C:\pagefile.sys
[14/07/2009 - 05:20:08 | D ] C:\PerfLogs
[27/06/2011 - 10:50:24 | RD ] C:\Program Files
[26/05/2011 - 14:07:54 | RD ] C:\Program Files (x86)
[15/06/2011 - 21:18:30 | HD ] C:\ProgramData
[27/06/2011 - 10:50:36 | D ] C:\rsit
[07/07/2010 - 00:07:40 | D ] C:\SERVICEmgr32
[18/07/2010 - 20:51:53 | D ] C:\SXG75
[27/06/2011 - 14:05:15 | SHD ] C:\System Volume Information
[08/07/2010 - 15:29:07 | D ] C:\UNICORN
[27/06/2011 - 15:04:10 | D ] C:\UsbFix
[27/06/2011 - 15:00:02 | A | 2240] C:\UsbFix.txt
[07/04/2010 - 09:22:18 | RD ] C:\Users
[02/03/2011 - 16:46:55 | D ] C:\Věci z Flashky
[13/05/2011 - 08:12:37 | D ] C:\Windows
[10/01/2001 - 16:48:42 | R | 172032] E:\AUTORUN.EXE
[09/11/2000 - 19:05:38 | R | 51] E:\AUTORUN.INF
[29/03/2001 - 14:14:36 | D ] E:\DATA
[29/03/2001 - 14:17:46 | D ] E:\DIRECTX7
[29/03/2001 - 14:17:50 | D ] E:\installer
[26/09/2010 - 11:06:20 | AH | 4096] I:\._.Trashes
[26/09/2010 - 11:06:20 | HD ] I:\.Trashes
[26/09/2010 - 11:06:20 | HD ] I:\.Spotlight-V100
[26/09/2010 - 11:06:20 | HD ] I:\.fseventsd
[03/07/2010 - 18:26:26 | D ] I:\PowerISO v4.4
[01/07/2010 - 14:42:56 | D ] I:\SERVIS
[18/08/2010 - 10:10:16 | D ] I:\Biacore od George
[27/08/2010 - 17:15:30 | D ] I:\fotky dovca
[07/09/2010 - 10:57:54 | D ] I:\Biacore Prime a System Check
[07/09/2010 - 11:00:28 | D ] I:\Bioreactor
[07/09/2010 - 11:02:18 | D ] I:\RS232toUSB
[15/09/2010 - 12:35:02 | D ] I:\Delfia
[28/09/2010 - 13:54:58 | D ] I:\AutoDELFIA Training
[05/10/2010 - 13:10:14 | D ] I:\Delfia Brno
[22/10/2010 - 13:22:34 | D ] I:\Delfia Klinlab
[10/05/2010 - 11:59:02 | D ] I:\Utilities & Drivers
[02/11/2010 - 12:38:10 | D ] I:\WinRar
[21/11/2010 - 20:49:24 | A | 70799783] I:\OdpolednĂ­ noviny - 21.11.2010 - Video ArchĂ­v _ Nova.cz.flv
[22/11/2010 - 13:48:18 | D ] I:\ÄKTA STRATEGIES
[22/11/2010 - 13:51:26 | D ] I:\Unicorn 5
[23/11/2010 - 09:18:50 | D ] I:\Výběr PDF
[01/12/2010 - 10:30:38 | RSHD ] I:\RECYCLER
[26/12/2010 - 23:50:54 | D ] I:\Kryl
[28/01/2011 - 12:31:04 | AH | 165] I:\~$Tisk.xlsx
[28/01/2011 - 13:11:58 | AH | 165] I:\~$Tisk2.xlsx
[07/02/2011 - 13:12:00 | D ] I:\Protokoly Synlab
[03/11/2010 - 11:36:22 | D ] I:\Typhoon
[02/02/2011 - 14:34:42 | D ] I:\Manuály
[12/05/2010 - 07:50:48 | D ] I:\Biochrom CD
[24/05/2010 - 08:36:46 | D ] I:\EZ Chrom CD
[26/08/2010 - 08:53:56 | D ] I:\Drivers
[06/10/2010 - 09:18:32 | D ] I:\ÄKTAs
[20/10/2010 - 10:43:54 | D ] I:\AutoDELFIA
[09/01/2011 - 18:10:54 | A | 726155264] I:\Karel Kryl - Kdo jsem (1993).avi
[16/01/2011 - 21:03:48 | A | 741900288] I:\Karel Kryl - Z mého života.AVI
[16/01/2011 - 22:10:50 | A | 383957764] I:\Karel Kryl - Koncert Maškary.avi
[16/01/2011 - 22:39:10 | A | 501277468] I:\Nevyjasněná umrtí - Občan Karel Kryl.mpg
[28/02/2011 - 09:08:10 | D ] I:\Hoodwinked[2005]DvDrip.AC3[Eng]-aXXo
[09/03/2011 - 11:00:52 | D ] I:\Delfia FNKV
[14/02/2011 - 12:27:36 | A | 12042240] I:\SecondSource.3gp
[14/02/2011 - 12:25:54 | A | 17465344] I:\FirstSource.3gp
[30/03/2011 - 12:09:38 | A | 53760] I:\KILMON.xls
[07/04/2011 - 08:41:44 | D ] I:\Pro Fáááádyjy
[12/10/2010 - 11:10:14 | A | 357596] I:\skelna_mineralni_vlakna_USA.pdf
[23/05/2011 - 11:37:46 | D ] I:\ImageQuant LAS 4000
[25/05/2011 - 13:17:18 | D ] I:\DVB-T Drivers
[26/05/2011 - 16:25:02 | D ] I:\Vizitka
[30/05/2011 - 14:22:36 | A | 30603] I:\KILMON.xlsx
[02/06/2011 - 15:44:56 | D ] I:\Licence
[15/06/2011 - 13:55:20 | A | 3932214] I:\Bez názvu.bmp

################## | Vaccin |

C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
I:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_SERIFUS-PC.zip
http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution.

################## | E.O.F |

Re: Avast hlásí worma na flashce :-(

Napsal: 27 čer 2011 18:57
od motji
Fajn, ještě Avast něco hlásí?

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Avast hlásí worma na flashce :-(

Napsal: 29 čer 2011 14:11
od Serifus
Vypadá to dobře. Jen už se nespouští Autorun :o Aspoň to nezdržuje :D

Děkuji

Re: Avast hlásí worma na flashce :-(

Napsal: 29 čer 2011 20:09
od motji
Já bych ráda viděla log z combofixu :)

Re: Avast hlásí worma na flashce :-(

Napsal: 04 črc 2011 10:45
od Serifus
A kde seženu Combofix na 64bitový systém? :?:

Re: Avast hlásí worma na flashce :-(

Napsal: 04 črc 2011 11:27
od tuvok07
Combofix by měl běžet i na 64bitovém systému. Motji by vám to nepsala kdyby tam nešel - to, jaký máte systém, je v logu vidět.

Re: Avast hlásí worma na flashce :-(

Napsal: 04 črc 2011 17:19
od motji
:o Vždyt jste ten combofix spouštěl, nebo ne?

Re: Avast hlásí worma na flashce :-(

Napsal: 08 črc 2011 09:22
od Serifus
ComboFix mi ohlásil, že nemám 32bitový systém a dále se se mnou nebavil. Toť vše. Kdyby to šlo, tak sem nepíšu :D

Re: Avast hlásí worma na flashce :-(

Napsal: 08 črc 2011 09:42
od Serifus
Už se podařilo jej sehnat :wink: Log zde:

ComboFix 11-07-07.06 - Serifus 08.07.2011 10:27:49.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3838.2240 [GMT 2:00]
Spuštěný z: c:\users\Serifus\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\jusched.exe
c:\windows\SysWow64\systeminfo.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-08 do 2011-07-08 )))))))))))))))))))))))))))))))
.
.
2011-07-08 08:33 . 2011-07-08 08:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-08 08:33 . 2011-07-08 08:33 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2011-07-08 07:51 . 2011-06-07 17:10 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2C6A04D0-C60B-417B-BD2C-59734BC17776}\mpengine.dll
2011-07-04 09:44 . 2011-07-04 09:44 302592 ----a-w- c:\windows\SysWow64\cmd.execf
2011-06-27 12:59 . 2011-06-27 13:04 -------- d-----w- C:\UsbFix
2011-06-27 08:50 . 2011-06-27 08:56 -------- d-----w- c:\program files\trend micro
2011-06-27 08:50 . 2011-06-27 08:50 -------- d-----w- C:\rsit
2011-06-24 17:05 . 2011-06-24 17:05 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-20 07:38 . 2011-06-20 07:38 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-06-17 07:55 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-17 07:55 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-17 07:55 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-17 07:55 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-17 07:55 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-17 07:55 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys
2011-06-17 07:55 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2011-06-17 07:55 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2011-06-17 07:55 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-17 07:55 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-17 07:55 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-17 07:54 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-17 07:54 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-17 07:54 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-17 07:54 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-15 19:18 . 2011-06-15 19:19 -------- d-----w- c:\programdata\Skype Extras
2011-06-15 19:18 . 2011-06-15 19:18 -------- d-----w- c:\program files (x86)\Common Files\Skype
2011-06-15 19:09 . 2011-06-17 08:03 -------- d-----w- C:\Fotky
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-08 08:35 . 2010-04-06 06:50 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2011-07-08 08:35 . 2011-04-22 17:44 58288 ----a-w- c:\windows\SysWow64\rpcnet.dll
2011-06-27 13:04 . 2011-06-27 13:04 3207 ----a-w- C:\UsbFix_Upload_Me_SERIFUS-PC.zip
2011-05-24 17:14 . 2010-04-06 12:31 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-20 18:38 . 2011-05-20 18:38 0 ---ha-w- c:\users\Serifus\AppData\Local\BIT2CEF.tmp
2011-05-11 06:26 . 2011-05-11 06:26 0 ---ha-w- c:\users\Serifus\AppData\Local\BITB1F0.tmp
2011-05-10 12:10 . 2011-01-17 08:10 40112 ----a-w- c:\windows\avastSS.scr
2011-05-10 12:10 . 2011-01-17 08:10 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-05-10 12:10 . 2011-01-17 08:11 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-05-10 12:04 . 2011-05-13 06:12 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-10 12:04 . 2011-01-17 08:11 287576 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-05-10 12:02 . 2011-01-17 08:11 53592 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-05-10 11:59 . 2011-01-17 08:11 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-05-10 11:59 . 2011-01-17 08:11 64344 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-05-10 11:59 . 2011-01-17 08:11 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-05-06 08:34 . 2011-05-06 08:34 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-06 08:34 . 2011-05-06 08:34 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-06 08:34 . 2011-05-06 08:34 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-06 08:34 . 2011-05-06 08:34 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-06 08:34 . 2011-05-06 08:34 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-06 08:34 . 2011-05-06 08:34 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-06 08:34 . 2011-05-06 08:34 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-06 08:34 . 2011-05-06 08:34 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-06 08:34 . 2011-05-06 08:34 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-06 08:34 . 2011-05-06 08:34 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-06 08:34 . 2011-05-06 08:34 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-06 08:34 . 2011-05-06 08:34 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-06 08:34 . 2011-05-06 08:34 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-06 08:34 . 2011-05-06 08:34 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-06 08:34 . 2011-05-06 08:34 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-06 08:34 . 2011-05-06 08:34 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-06 08:34 . 2011-05-06 08:34 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-06 08:34 . 2011-05-06 08:34 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-06 08:34 . 2011-05-06 08:34 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-06 08:34 . 2011-05-06 08:34 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-06 08:34 . 2011-05-06 08:34 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-06 08:34 . 2011-05-06 08:34 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-05-06 08:34 . 2011-05-06 08:34 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-06 08:34 . 2011-05-06 08:34 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-06 08:34 . 2011-05-06 08:34 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-06 08:34 . 2011-05-06 08:34 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-06 08:34 . 2011-05-06 08:34 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-06 08:34 . 2011-05-06 08:34 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-06 08:34 . 2011-05-06 08:34 448512 ----a-w- c:\windows\system32\html.iec
2011-05-06 08:34 . 2011-05-06 08:34 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-06 08:34 . 2011-05-06 08:34 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-06 08:34 . 2011-05-06 08:34 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-06 08:34 . 2011-05-06 08:34 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-06 08:34 . 2011-05-06 08:34 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-06 08:34 . 2011-05-06 08:34 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-06 08:34 . 2011-05-06 08:34 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-06 08:34 . 2011-05-06 08:34 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-06 08:34 . 2011-05-06 08:34 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-06 08:27 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-05-06 08:27 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-05-04 02:52 . 2010-04-22 11:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-04-26 07:25 . 2011-04-26 07:25 159080 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10138.bin
2011-04-22 22:15 . 2011-05-25 11:16 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-22 17:44 . 2011-04-22 17:43 13160 ----a-w- c:\windows\SysWow64\Upgrd.exe
2011-04-22 17:43 . 2011-04-22 17:44 58288 ------w- c:\windows\SysWow64\rpcnet.exe
2011-04-22 17:40 . 2010-04-06 06:52 17408 ----a-w- c:\windows\SysWow64\rpcnetp.dll
2011-04-22 17:39 . 2010-04-06 06:50 17408 ----a-w- c:\windows\SysWow64\rpcnetp.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-21 11:17 1233288 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2010-05-21 1233288]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BlazeServoTool"="c:\program files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe" [2010-03-06 286720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"FATrayAlert"="c:\program files (x86)\Sensible Vision\Fast Access\FATrayMon.exe" [2009-06-24 95496]
"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-03-26 1234216]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-1-26 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]
2009-06-24 22:31 140552 ----a-w- c:\program files (x86)\Sensible Vision\Fast Access\FALogNot.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-10 136176]
R3 FACAP;facap, FastAccess Video Capture;c:\windows\system32\DRIVERS\facap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-10 136176]
R3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys [x]
R3 kcane;Kvaser USBcan II;c:\windows\system32\DRIVERS\kcane.sys [x]
R3 kcanl;Kvaser Leaf Family Driver;c:\windows\system32\DRIVERS\kcanl.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 vpcuxd;Služba zástupné procedury virtualizace rozhraní USB;c:\windows\system32\DRIVERS\vpcuxd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 FAService;FAService;c:\program files (x86)\Sensible Vision\Fast Access\FAService.exe [2009-06-24 2368776]
S2 KvEnumSrv;Kvaser Network Enumerator Service;c:\program files\Kvaser\Drivers\32\kvenumsrv.exe [2009-10-21 72208]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-06 2002728]
S3 BTHprint;Třída tiskárny protokolu Bluetooth (Microsoft);c:\windows\system32\DRIVERS\bthprint.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [x]
S3 kcanv;Kvaser Virtual CAN Driver;c:\windows\system32\DRIVERS\kcanv.sys [x]
S3 kvnetenum;Kvaser Network Enumerator;c:\windows\system32\DRIVERS\kvnetenum.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\autorun.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
2010-11-20 12:17 302592 ----a-w- c:\windows\System32\cmd.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-10 12:47]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-10 12:47]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-747689082-1517823429-1005369232-1000Core.job
- c:\users\Serifus\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-04 11:07]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-747689082-1517823429-1005369232-1000UA.job
- c:\users\Serifus\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-04 11:07]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF24031.cfxxe" [X]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2010-06-09 3216544]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-04 16328736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
TCP: DhcpNameServer = 192.168.18.100
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-Software Informer - c:\program files (x86)\Software Informer\softinfo.exe
Wow6432Node-HKCU-Run-OEXPRESS - (no file)
Wow6432Node-HKLM-Run-FAStartup - (no file)
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\SysWOW64\rpcnet.exe
c:\program files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
c:\program files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
.
**************************************************************************
.
Celkový čas: 2011-07-08 10:40:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-08 08:40
.
Před spuštěním: Volných bajtů: 319 255 461 888
Po spuštění: Volných bajtů: 324 586 811 392
.
- - End Of File - - 1E6D69C4007ABDA164686986F2EE3346

Re: Avast hlásí worma na flashce :-(

Napsal: 08 črc 2011 10:33
od motji
:roll: combofix je jen jeden a je kompatibilní pro všechny systémy.
Co je jednotka E?

Re: Avast hlásí worma na flashce :-(

Napsal: 14 črc 2011 22:17
od Serifus
Tak tamten byl asi nějakej fake :o

Jednotka E? Nemám tušení :arcisit:

Re: Avast hlásí worma na flashce :-(

Napsal: 15 črc 2011 08:20
od motji
:arrow: Zapojte do pc všechny usb klíče, flashky...co používáte

Použijte USB fix
http://www.viry.cz/forum/viewtopic.php?f=24&t=102308


:!: Před stažením vypněte rezidentní štít antiviru, má na Usbfix falešnou detekci
-spusťte
-klikněte na volbu deletion , potvrdte enter
- po skenu sem vložte log , pokud na Vás nevyskočí, najdete ho C:\UsbFix.txt