Stránka 1 z 1

Eset zklamal prosím o pomoc

Napsal: 19 lis 2011 21:14
od e_mysak
zasílám log.txt z RSIT a výpis z MBAM, nedovolil jsem si nic smazat prosím o radu jak dál

Logfile of random's system information tool 1.09 (written by random/random)
Run by Masek at 2011-11-19 20:52:27
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 60 GB (38%) free of 156 GB
Total RAM: 2047 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:52:55, on 19.11.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTSvcCDA.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ping.exe
C:\Install\RSIT.exe
C:\Program Files\trend micro\Masek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=66022
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://atlas.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66022
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=66022
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66022
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=66022
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Svátky a narozeniny.lnk = ?
O4 - Global Startup: Pinnacle Streaming Server.lnk = C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microso ... 0814754359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0814741296
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8569 bytes

======Scheduled tasks folder======

Malwarebytes' Anti-Malware
www.malwarebytes.org

Verze databáze:

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

19.11.2011 15:18:05
mbam-log-2011-11-19 (15-17-45).txt

Typ: Rychlá kontrola
Kontrolované objekty: 197850
Uplynulý čas: 3 minut, 38 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 1
Infikované hodnoty v registru: 1
Infikované datové položky v registru: 3
Infikované složky: 0
Infikované soubory: 3

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> No action taken.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Value: Regedit32 -> No action taken.

Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\RECYCLER\s-1-5-21-583907252-117609710-1801674531-1004\Dc62138.exe (Trojan.Proxy) -> No action taken.
c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> No action taken.
c:\WINDOWS\Tasks\{35dc3473-a719-4d14-b7c1-fd326ca84a0c}.job (Trojan.Downloader) -> No action taken.

eset zhruba před týdnem vytvořil hlášku že je napadena paměť ale vir nedokázal odstranit,mám podezdření že se jedná o viry dva tada na foru jsem o nich četl měl to tu kolega ze slovenska jednalo se o něco nového

Re: Eset zklamal prosím o pomoc

Napsal: 19 lis 2011 22:23
od e_mysak
Zdravím a děkuji za snahu pomoci,zasílám žádané,vytáhl jsem z esetu část protokolů,alespon za poslední tři dni tak vše zde posílám. Stalo se ale že když jsem spustil výmaz v mbam tak během chvilky po výmazu eset znovu zobrazil hlášku ve výpisu jsou to ty dvě poslední

Pokusil jsem se vytáhnout info z protokolů Eset snad to napoví více, z 16.11. jsem vypsal i protokol z firevalu zde to ukazuje na útok ze dvou adres

16.11.2011 10:16:49 Detekován útok DNS cache poisoning 216.69.185.35:53 192.168.1.3:40052 UDP
16.11.2011 10:16:43 Detekován útok DNS cache poisoning 208.109.255.35:53 192.168.1.3:39619 UDP

-------------------------------------------------------------------------------------------------------------------------------
19.11.2011 21:37:58 Kontrola při startu soubor Operační paměť » svchost.exe(1428) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit PC-
MASEK\Masek

19.11.2011 21:37:57 Kontrola při startu soubor Operační paměť » \GLOBAL??\3435c2ca\WINDOWS\$NtUninstallKB63231$\875938506\Desktop.ini varianta infiltrace Win32/Sirefef.DN trojský kůň vyléčen smazáním PC-MASEK\Masek

19.11.2011 21:28:06 Rezidentní ochrana soubor C:\DOCUMENTS AND SETTINGS\ALL USERS\aqev4zvigy.xxx Win32/Wigon.OW trojský kůň vyléčen smazáním - uložen do karantény PC-MASEK\Masek Tato skutečnost byla zjištěna při pokusu o přístup k souboru aplikací: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe.

19.11.2011 14:54:18 Kontrola při startu soubor Operační paměť » svchost.exe(1424) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit PC-MASEK\Masek
19.11.2011 14:54:17 Kontrola při startu soubor Operační paměť » \GLOBAL??\3435c2ca\WINDOWS\$NtUninstallKB63231$\875938506\Desktop.ini varianta infiltrace Win32/Sirefef.DN trojský kůň vyléčen smazáním PC-MASEK\Masek

19.11.2011 14:17:12 Kontrola při startu soubor Operační paměť » svchost.exe(1424) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit

19.11.2011 14:17:11 Kontrola při startu soubor Operační paměť » \GLOBAL??\3435c2ca\WINDOWS\$NtUninstallKB63231$\875938506\Desktop.ini varianta infiltrace Win32/Sirefef.DN trojský kůň vyléčen smazáním

19.11.2011 9:22:28 Kontrola při startu soubor Operační paměť » svchost.exe(1424) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit

18.11.2011 22:10:32 Kontrola při startu soubor Operační paměť » svchost.exe(1432) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit PC-MASEK\Masek
18.11.2011 20:36:35 Kontrola při startu soubor Operační paměť » svchost.exe(1432) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit PC-MASEK\Masek

18.11.2011 20:13:40 Kontrola při startu soubor Operační paměť » svchost.exe(1428) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit PC-MASEK\Masek
18.11.2011 16:34:46 Kontrola při startu soubor Operační paměť » svchost.exe(1428) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit

18.11.2011 10:20:51 Rezidentní ochrana soubor C:\WINDOWS\TEMP\bygkjm\setup.exe varianta infiltrace Win32/Kryptik.VNY trojský kůň smazán - uložen do karantény NT AUTHORITY\SYSTEM Tato skutečnost byla zjištěna na nově vytvořeném souboru aplikací: C:\WINDOWS\system32\svchost.exe.

18.11.2011 6:58:29 Rezidentní ochrana soubor C:\WINDOWS\TEMP\nyaspt\setup.exe varianta infiltrace Win32/Kryptik.VNY trojský kůň smazán - uložen do karantény NT AUTHORITY\SYSTEM Tato skutečnost byla zjištěna na nově vytvořeném souboru aplikací: C:\WINDOWS\system32\svchost.exe.

18.11.2011 6:57:36 Rezidentní ochrana soubor C:\WINDOWS\TEMP\pamibw\setup.exe Win32/Wigon.OW trojský kůň vyléčen smazáním - uložen do karantény PC-MASEK\Masek Tato skutečnost byla zjištěna při pokusu o přístup k souboru aplikací: C:\Program Files\CCleaner\CCleaner.exe.

18.11.2011 6:48:28 Rezidentní ochrana soubor C:\WINDOWS\TEMP\klaxnr\setup.exe varianta infiltrace Win32/Kryptik.VNY trojský kůň smazán - uložen do karantény NT AUTHORITY\SYSTEM Tato skutečnost byla zjištěna na nově vytvořeném souboru aplikací: C:\WINDOWS\system32\svchost.exe.

17.11.2011 19:24:40 Kontrola při startu soubor Operační paměť » svchost.exe(1424) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit PC-MASEK\Masek
17.11.2011 11:03:27 Kontrola při startu soubor Operační paměť » svchost.exe(1424) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit

16.11.2011 23:06:41 Rezidentní ochrana soubor C:\WINDOWS\TEMP\rxvgfq\setup.exe varianta infiltrace Win32/Kryptik.VLO trojský kůň smazán - uložen do karantény NT AUTHORITY\SYSTEM Tato skutečnost byla zjištěna na nově vytvořeném souboru aplikací: C:\WINDOWS\system32\svchost.exe.

16.11.2011 21:51:32 Kontrola při startu soubor Operační paměť » svchost.exe(1432) pravděpodobně varianta infiltrace Win32/Sirefef.DA trojský kůň nelze léčit PC-MASEK\Masek
-------------------------

Logfile of random's system information tool 1.09 (written by random/random)
Run by Masek at 2011-11-19 22:13:58
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 60 GB (38%) free of 156 GB
Total RAM: 2047 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:14:05, on 19.11.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTSvcCDA.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\ping.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Masek\Local Settings\Temporary Internet Files\Content.IE5\UVGWZ0NL\RSIT[1].exe
C:\Program Files\trend micro\Masek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=66022
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://atlas.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66022
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=66022
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66022
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=66022
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Svátky a narozeniny.lnk = ?
O4 - Global Startup: Pinnacle Streaming Server.lnk = C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microso ... 0814754359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0814741296
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8827 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2011-03-19 798771]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
Burn4Free Toolbar Helper - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll [2009-11-10 815104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - Burn4Free Toolbar - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll [2009-11-10 815104]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2011-03-19 798771]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"Share-to-Web Namespace Daemon"=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [2001-07-03 57344]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 3080264]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
""= []
"Nektra OEAPI"= []
"OEXPRESS"=C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE [2011-03-19 26624]
"WEBTRAN"= []
"PMCRemote"=C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe [2008-11-18 226576]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Pinnacle Streaming Server.lnk - C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe

C:\Documents and Settings\Masek\Nabídka Start\Programy\Po spuštění
Svátky a narozeniny.lnk - C:\Program Files\Svátky a narozeniny\SaN.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2004-04-21 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ASUS\WL-600g Wireless Router Utilities\EZSetup.exe"="C:\Program Files\ASUS\WL-600g Wireless Router Utilities\EZSetup.exe:*:Enabled:EZSetup Wizard"
"C:\Program Files\ASUS\WL-600g Wireless Router Utilities\Discovery.exe"="C:\Program Files\ASUS\WL-600g Wireless Router Utilities\Discovery.exe:*:Enabled:ASUS Device Discovery Application"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Konzola Microsoft Management Console"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe"="C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe:LocalSubNet:Enabled:Pinnacle Streaming Server"
"C:\Games\TmNationsForever\TmForever.exe"="C:\Games\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Games\FlightGear\bin\win32\fgfs.exe"="C:\Games\FlightGear\bin\win32\fgfs.exe:*:Enabled:fgfs"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.PIM1"=PCLEPIM1.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======List of files/folders created in the last 1 month======

2011-11-19 20:52:28 ----D---- C:\Program Files\trend micro
2011-11-19 20:52:27 ----D---- C:\rsit
2011-11-19 15:09:35 ----D---- C:\Documents and Settings\Masek\Data aplikací\Malwarebytes
2011-11-19 15:09:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-11-19 15:09:22 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-19 15:09:22 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-11-16 23:42:30 ----A---- C:\WINDOWS\system32\MRT.INI
2011-11-12 08:44:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2011-11-12 08:30:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2011-10-28 19:54:38 ----D---- C:\copy-pal
2011-10-22 13:05:42 ----D---- C:\Documents and Settings\Masek\Data aplikací\ESET

======List of files/folders modified in the last 1 month======

2011-11-19 22:14:05 ----D---- C:\WINDOWS\Prefetch
2011-11-19 22:14:03 ----D---- C:\WINDOWS\Temp
2011-11-19 21:51:24 ----A---- C:\WINDOWS\WINCMD.INI
2011-11-19 21:33:29 ----D---- C:\WINDOWS\system32\drivers
2011-11-19 21:33:20 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2011-11-19 21:32:34 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-19 21:31:42 ----SD---- C:\WINDOWS\Tasks
2011-11-19 20:52:28 ----RD---- C:\Program Files
2011-11-19 20:50:33 ----D---- C:\Install
2011-11-19 15:36:13 ----D---- C:\WINDOWS\system32
2011-11-19 11:38:28 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-18 09:09:49 ----AD---- C:\WINDOWS
2011-11-18 07:01:40 ----D---- C:\WINDOWS\Debug
2011-11-16 23:42:49 ----HD---- C:\WINDOWS\inf
2011-11-16 23:42:46 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-16 23:29:16 ----A---- C:\WINDOWS\system32\MRT.exe
2011-11-16 23:28:50 ----D---- C:\WINDOWS\system32\CatRoot
2011-11-16 21:44:46 ----D---- C:\WINDOWS\system32\config
2011-11-16 21:44:27 ----D---- C:\WINDOWS\system32\wbem
2011-11-16 21:44:26 ----D---- C:\WINDOWS\Registration
2011-11-16 00:14:12 ----D---- C:\WINDOWS\system32\drivers\etc
2011-11-12 10:16:02 ----D---- C:\WINDOWS\network diagnostic
2011-11-12 08:30:12 ----HD---- C:\WINDOWS\$hf_mig$
2011-11-03 22:55:49 ----D---- C:\WINDOWS\pss
2011-10-30 07:35:23 ----ASH---- C:\boot.ini
2011-10-30 07:35:23 ----A---- C:\WINDOWS\win.ini
2011-10-30 07:35:23 ----A---- C:\WINDOWS\system.ini
2011-10-30 04:52:46 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-28 20:07:22 ----SHD---- C:\WINDOWS\Installer
2011-10-22 13:02:26 ----D---- C:\Program Files\ESET
2011-10-22 13:02:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 IdeBusDr;IdeBusDr; C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys [2002-08-14 13782]
R0 IdeChnDr;Intel(R) Ultra ATA Controller; C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys [2002-08-14 93594]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-10-07 115744]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2011-08-04 61936]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-10-07 80576]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R2 PfModNT;PfModNT; \??\C:\WINDOWS\system32\PfModNT.sys []
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-04-21 729088]
R3 bcm4sbxp;ASUSTeK/Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2002-09-10 41728]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2011-08-09 39824]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 PinnacleRoyalTS;Pinnacle Systems RoyalTS Device; C:\WINDOWS\system32\DRIVERS\RoyalTS.sys [2008-12-15 123520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 viamraid;viamraid; C:\WINDOWS\system32\DRIVERS\viamraid.sys [2007-07-17 114944]
S3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DynCal;Dynamic Calibration Service; C:\WINDOWS\system32\drivers\Dyncal.sys [2007-11-07 12928]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-07-30 18048]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-07-26 137600]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pctvvbi;PCTVVBI; C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-11-11 6400]
S3 sbpci;Sound Blaster PCI128 Audio Driver (WDM); C:\WINDOWS\system32\drivers\sbpci.sys [2002-07-11 667136]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2004-04-21 397312]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTSvcCDA.exe [1999-12-13 44032]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2011-09-22 974944]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2004-04-21 516096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-10-20 630272]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 00:14
od e_mysak
Omlouvám se jsem v práci s počitači trochu laik ale povedlo se mi tím prokousat a tak připojuji požadované, přišel jsem asi o účto ale pokud byl zásah nutný tak jej pak nainstaluji znovu.Killer ale hlásil že tam ještě nějaká drobnost zůstala?

ComboFix 11-11-18.02 - Masek 19.11.2011 23:21:08.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1674 [GMT 1:00]
Spuštěný z: c:\documents and settings\All Users\Plocha\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezidentní štít AV je zapnutý
.
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\PC Translator 2010.25 CZ\SLOVNÍK CIZÍCH SLOV.exe
c:\documents and settings\PC Translator 2010.25 CZ\Slovník ESPERANTO.exe
c:\documents and settings\PC Translator 2010.25 CZ\Slovník pro plnění vlastní slovní zásoby.exe
C:\UCTO2010
c:\ucto2010\{DATA}\ADRESY.000
c:\ucto2010\{DATA}\ADRESY.T00
c:\ucto2010\{DATA}\ADRESY.X00
c:\ucto2010\{DATA}\ARCHIVD.001
c:\ucto2010\{DATA}\ARCHIVD.T01
c:\ucto2010\{DATA}\BANKA1.008
c:\ucto2010\{DATA}\CEST_FH.006
c:\ucto2010\{DATA}\CEST_FH.T06
c:\ucto2010\{DATA}\CEST_VH.006
c:\ucto2010\{DATA}\CEST_VH.T06
c:\ucto2010\{DATA}\CISABS.004
c:\ucto2010\{DATA}\CISABS.X04
c:\ucto2010\{DATA}\CISDOKL.001
c:\ucto2010\{DATA}\CISDRUH.001
c:\ucto2010\{DATA}\CISDRUH.X01
c:\ucto2010\{DATA}\CISPOH.001
c:\ucto2010\{DATA}\CISPOH.X01
c:\ucto2010\{DATA}\CISPOZN.000
c:\ucto2010\{DATA}\CISPOZN.T00
c:\ucto2010\{DATA}\CIST.000
c:\ucto2010\{DATA}\CIST.X00
c:\ucto2010\{DATA}\CISTEXT.001
c:\ucto2010\{DATA}\CISTXT.006
c:\ucto2010\{DATA}\CISTXT.X06
c:\ucto2010\{DATA}\CISVYKON.001
c:\ucto2010\{DATA}\CISVYKON.X01
c:\ucto2010\{DATA}\DAP15.003
c:\ucto2010\{DATA}\DAP15.T03
c:\ucto2010\{DATA}\DENIK.001
c:\ucto2010\{DATA}\DENIK.T01
c:\ucto2010\{DATA}\DODL_VH.006
c:\ucto2010\{DATA}\DODL_VH.T06
c:\ucto2010\{DATA}\EDIT.000
c:\ucto2010\{DATA}\EDIT.X00
c:\ucto2010\{DATA}\EDITPAR.000
c:\ucto2010\{DATA}\EDITPAR.X00
c:\ucto2010\{DATA}\FAKT_FH.006
c:\ucto2010\{DATA}\FAKT_FH.T06
c:\ucto2010\{DATA}\FAKT_FP.006
c:\ucto2010\{DATA}\FAKT_FS.006
c:\ucto2010\{DATA}\FINANCE.001
c:\ucto2010\{DATA}\FINANCE.T01
c:\ucto2010\{DATA}\HOBAVYP.008
c:\ucto2010\{DATA}\INV_Z.007
c:\ucto2010\{DATA}\KATEG.004
c:\ucto2010\{DATA}\KATEG.X04
c:\ucto2010\{DATA}\OBJE_VH.006
c:\ucto2010\{DATA}\OBJE_VH.T06
c:\ucto2010\{DATA}\ODPISY.009
c:\ucto2010\{DATA}\ODPISY.X09
c:\ucto2010\{DATA}\PAR01A2.001
c:\ucto2010\{DATA}\PAR01A4.001
c:\ucto2010\{DATA}\PAR02A2.002
c:\ucto2010\{DATA}\PAR02A4.002
c:\ucto2010\{DATA}\PAR03A4.003
c:\ucto2010\{DATA}\PAR04A2.004
c:\ucto2010\{DATA}\PAR05A4.005
c:\ucto2010\{DATA}\PAR06A4.006
c:\ucto2010\{DATA}\PAR07A4.007
c:\ucto2010\{DATA}\PAR08A2.008
c:\ucto2010\{DATA}\PAR09A2.009
c:\ucto2010\{DATA}\PAR09A2.T09
c:\ucto2010\{DATA}\PAR09A4.009
c:\ucto2010\{DATA}\PAR97A2.097
c:\ucto2010\{DATA}\PARAM2.000
c:\ucto2010\{DATA}\PARAM2.T00
c:\ucto2010\{DATA}\PARAM4.000
c:\ucto2010\{DATA}\PARAM4.T00
c:\ucto2010\{DATA}\PARHB.008
c:\ucto2010\{DATA}\PARIMPA4.000
c:\ucto2010\{DATA}\PARZAS.001
c:\ucto2010\{DATA}\PLATBY.001
c:\ucto2010\{DATA}\PLATBY.T01
c:\ucto2010\{DATA}\POHLZAV.001
c:\ucto2010\{DATA}\POHLZAV.T01
c:\ucto2010\{DATA}\POHYBZ.001
c:\ucto2010\{DATA}\POHYBZ.X01
c:\ucto2010\{DATA}\POJIST.004
c:\ucto2010\{DATA}\POJIST.X04
c:\ucto2010\{DATA}\PRACSML.004
c:\ucto2010\{DATA}\PRACSML.T04
c:\ucto2010\{DATA}\SHIFTF3.000
c:\ucto2010\{DATA}\SHIFTF3.X00
c:\ucto2010\{DATA}\SIL.005
c:\ucto2010\{DATA}\SIL.T05
c:\ucto2010\{DATA}\SILVOZ.005
c:\ucto2010\{DATA}\SILVOZ.X05
c:\ucto2010\{DATA}\STORNA.001
c:\ucto2010\{DATA}\STORNA.T01
c:\ucto2010\{DATA}\TRIDY.004
c:\ucto2010\{DATA}\TRIDY.X04
c:\ucto2010\{DATA}\TYPDOKL.001
c:\ucto2010\{DATA}\TYPDOKL.X01
c:\ucto2010\{DATA}\UCTY.000
c:\ucto2010\{DATA}\UCTY.X00
c:\ucto2010\{DATA}\UKOLY.000
c:\ucto2010\{DATA}\UKOLY.T00
c:\ucto2010\{DATA}\UZAV.001
c:\ucto2010\{DATA}\VYKMAZA.UUU
c:\ucto2010\{DATA}\ZAOKFA.006
c:\ucto2010\{DATA}\ZAOKFA.X06
c:\ucto2010\{DATA}\ZBO_HP.007
c:\ucto2010\{DATA}\ZBO_HV.007
c:\ucto2010\{DATA}\ZBO_PV.007
c:\ucto2010\{DATA}\ZBOZI.001
c:\ucto2010\{DATA}\ZBOZI.T01
c:\ucto2010\{DATA}\ZP.009
c:\ucto2010\{DATA}\ZP.T09
c:\ucto2010\{DATA}\ZURNALD.001
c:\ucto2010\{GLOB}\ADRWEB.000
c:\ucto2010\{GLOB}\BANKY.000
c:\ucto2010\{GLOB}\BANKY.X00
c:\ucto2010\{GLOB}\BANKYHB.008
c:\ucto2010\{GLOB}\CISOKR.097
c:\ucto2010\{GLOB}\DATA.000
c:\ucto2010\{GLOB}\DATA.X00
c:\ucto2010\{GLOB}\EXPDEKLA.099
c:\ucto2010\{GLOB}\EXPDEKLA.T99
c:\ucto2010\{GLOB}\FAQ.000
c:\ucto2010\{GLOB}\FAQ.X00
c:\ucto2010\{GLOB}\FIRMY.000
c:\ucto2010\{GLOB}\FORMS.099
c:\ucto2010\{GLOB}\FORMS.T99
c:\ucto2010\{GLOB}\KODPOJ.004
c:\ucto2010\{GLOB}\MODULY.000
c:\ucto2010\{GLOB}\NAHRNEM.004
c:\ucto2010\{GLOB}\NEZDAN.000
c:\ucto2010\{GLOB}\NEZDAN.X00
c:\ucto2010\{GLOB}\OKRESY.000
c:\ucto2010\{GLOB}\OKRESY.X00
c:\ucto2010\{GLOB}\PARAM1.000
c:\ucto2010\{GLOB}\PLATIDLA.004
c:\ucto2010\{GLOB}\POSTY.000
c:\ucto2010\{GLOB}\POSTY.X00
c:\ucto2010\{GLOB}\REPORT.099
c:\ucto2010\{GLOB}\REPORT.T99
c:\ucto2010\{GLOB}\REPORT.X99
c:\ucto2010\{GLOB}\SAZDPH.000
c:\ucto2010\{GLOB}\SAZDPH.X00
c:\ucto2010\{GLOB}\SAZDZP.000
c:\ucto2010\{GLOB}\SAZDZP.X00
c:\ucto2010\{GLOB}\SAZDZPM.004
c:\ucto2010\{GLOB}\SAZODP.009
c:\ucto2010\{GLOB}\SLOVNIK.006
c:\ucto2010\{GLOB}\ZALDZP.004
c:\ucto2010\{GLOB}\ZDRSOC.004
c:\ucto2010\{GLOB}\ZUJ.097
c:\ucto2010\{INFO}\ADRZPRAV.000
c:\ucto2010\{INFO}\ADRZPRAV.T00
c:\ucto2010\{INFO}\INFOAUTO.000
c:\ucto2010\{INFO}\INFOPROB.000
c:\ucto2010\{INFO}\INFOPROB.T00
c:\ucto2010\{INFO}\INFOPROB.X00
c:\ucto2010\{INFO}\INFOTEMA.000
c:\ucto2010\{INFO}\KONFEREN.000
c:\ucto2010\{INFO}\KONFEREN.T00
c:\ucto2010\{INFO}\PGMKOD.000
c:\ucto2010\{INFO}\PROGRAMY.000
c:\ucto2010\{INFO}\PROGRAMY.T00
c:\ucto2010\{INFO}\SLUZKOD.000
c:\ucto2010\{NOVA}\ADRESY.000
c:\ucto2010\{NOVA}\ADRESY.T00
c:\ucto2010\{NOVA}\CISABS.004
c:\ucto2010\{NOVA}\CISDOKL.001
c:\ucto2010\{NOVA}\CISDRUH.001
c:\ucto2010\{NOVA}\CISPOH.001
c:\ucto2010\{NOVA}\CISPOZN.000
c:\ucto2010\{NOVA}\CISPOZN.T00
c:\ucto2010\{NOVA}\CIST.000
c:\ucto2010\{NOVA}\CISTXT.006
c:\ucto2010\{NOVA}\CISVYKON.001
c:\ucto2010\{NOVA}\KATEG.004
c:\ucto2010\{NOVA}\PARAM2.000
c:\ucto2010\{NOVA}\PARAM2.T00
c:\ucto2010\{NOVA}\PRACSML.004
c:\ucto2010\{NOVA}\PRACSML.T04
c:\ucto2010\{NOVA}\TRIDY.004
c:\ucto2010\{NOVA}\TYPDOKL.001
c:\ucto2010\{NOVA}\UKOLY.000
c:\ucto2010\{NOVA}\UKOLY.T00
c:\ucto2010\{NOVA}\UZAV.001
c:\ucto2010\{NOVA}\ZAOKFA.006
c:\ucto2010\{OBNV}.BAT
c:\ucto2010\{OBNV}\BANKYHB.008
c:\ucto2010\{OBNV}\KODPOJ.004
c:\ucto2010\{OBNV}\MODULY.000
c:\ucto2010\{OBNV}\NAHRNEM.004
c:\ucto2010\{OBNV}\NEZDAN.000
c:\ucto2010\{OBNV}\PLATIDLA.004
c:\ucto2010\{OBNV}\SAZDPH.000
c:\ucto2010\{OBNV}\SAZDZP.000
c:\ucto2010\{OBNV}\SAZDZPM.004
c:\ucto2010\{OBNV}\SAZODP.009
c:\ucto2010\{OBNV}\SLOVNIK.006
c:\ucto2010\{OBNV}\UCTO2010.CAT
c:\ucto2010\{OBNV}\UCTOOL.EX
c:\ucto2010\{OBNV}\UTISK04.EX
c:\ucto2010\{OBNV}\ZALDZP.004
c:\ucto2010\{OBNV}\ZDRSOC.004
c:\ucto2010\{PDF1}\DAVKYK2.PDF
c:\ucto2010\{PDF1}\DAVKYK3.PDF
c:\ucto2010\{PDF1}\DAVKYP2.PDF
c:\ucto2010\{PDF1}\DAVKYP3.PDF
c:\ucto2010\{PDF1}\DPH15.PDF
c:\ucto2010\{PDF1}\DPH15P.PDF
c:\ucto2010\{PDF1}\DPH16.PDF
c:\ucto2010\{PDF1}\DPH16P.PDF
c:\ucto2010\{PDF1}\DZP.PDF
c:\ucto2010\{PDF1}\DZP_1.PDF
c:\ucto2010\{PDF1}\DZP_2.PDF
c:\ucto2010\{PDF1}\DZP_3.PDF
c:\ucto2010\{PDF1}\DZP_7.PDF
c:\ucto2010\{PDF1}\DZPP.PDF
c:\ucto2010\{PDF1}\ELDP09B.PDF
c:\ucto2010\{PDF1}\ELDP09F.PDF
c:\ucto2010\{PDF1}\ELDP09K.PDF
c:\ucto2010\{PDF1}\ELDP09M.PDF
c:\ucto2010\{PDF1}\ELDP09P.PDF
c:\ucto2010\{PDF1}\ELDPF.PDF
c:\ucto2010\{PDF1}\ELDPK.PDF
c:\ucto2010\{PDF1}\ELDPM.PDF
c:\ucto2010\{PDF1}\ELDPP.PDF
c:\ucto2010\{PDF1}\HROMOZN.PDF
c:\ucto2010\{PDF1}\HROMOZNP.PDF
c:\ucto2010\{PDF1}\CHYBCAST.PDF
c:\ucto2010\{PDF1}\NEMOC.PDF
c:\ucto2010\{PDF1}\NEMOCP.PDF
c:\ucto2010\{PDF1}\ODCITPOL.PDF
c:\ucto2010\{PDF1}\ONZ.PDF
c:\ucto2010\{PDF1}\ONZK.PDF
c:\ucto2010\{PDF1}\ONZP.PDF
c:\ucto2010\{PDF1}\OSSZ.PDF
c:\ucto2010\{PDF1}\OSSZK.PDF
c:\ucto2010\{PDF1}\OSSZP.PDF
c:\ucto2010\{PDF1}\POCZAM.PDF
c:\ucto2010\{PDF1}\POJZAM.PDF
c:\ucto2010\{PDF1}\SILDAN.PDF
c:\ucto2010\{PDF1}\SILDANPO.PDF
c:\ucto2010\{PDF1}\SILDANPR.PDF
c:\ucto2010\{PDF1}\SOUHLAS.PDF
c:\ucto2010\{PDF1}\SOUHLASP.PDF
c:\ucto2010\{PDF1}\VYUCT.PDF
c:\ucto2010\{PDF1}\VYUCTP.PDF
c:\ucto2010\{PDF1}\VYUCTSRP.PDF
c:\ucto2010\{PDF1}\VYUCTSRZ.PDF
c:\ucto2010\{PDF1}\VZP.PDF
c:\ucto2010\{PDF1}\VZPP.PDF
c:\ucto2010\{PDF2}\DLBL.PDF
c:\ucto2010\{PDF2}\DLBL2.PDF
c:\ucto2010\{PDF2}\DLBW.PDF
c:\ucto2010\{PDF2}\DLBW2.PDF
c:\ucto2010\{PDF2}\DLGR.PDF
c:\ucto2010\{PDF2}\DLGR2.PDF
c:\ucto2010\{PDF2}\FABL.PDF
c:\ucto2010\{PDF2}\FABL2.PDF
c:\ucto2010\{PDF2}\FABW.PDF
c:\ucto2010\{PDF2}\FABW2.PDF
c:\ucto2010\{PDF2}\FAGR.PDF
c:\ucto2010\{PDF2}\FAGR2.PDF
c:\ucto2010\{PDF2}\OBBL.PDF
c:\ucto2010\{PDF2}\OBBL2.PDF
c:\ucto2010\{PDF2}\OBBW.PDF
c:\ucto2010\{PDF2}\OBBW2.PDF
c:\ucto2010\{PDF2}\OBGR.PDF
c:\ucto2010\{PDF2}\OBGR2.PDF
c:\ucto2010\{PDF3}\DAVKYK2X.DEF
c:\ucto2010\{PDF3}\DAVKYK2X.PDF
c:\ucto2010\{PDF3}\DAVKYK3X.DEF
c:\ucto2010\{PDF3}\DAVKYK3X.PDF
c:\ucto2010\{PDF3}\DPH15X.DEF
c:\ucto2010\{PDF3}\DPH15X.PDF
c:\ucto2010\{PDF3}\DPH16X.DEF
c:\ucto2010\{PDF3}\DPH16X.PDF
c:\ucto2010\{PDF3}\DZP_1X.DEF
c:\ucto2010\{PDF3}\DZP_1X.PDF
c:\ucto2010\{PDF3}\DZP_2X.DEF
c:\ucto2010\{PDF3}\DZP_2X.PDF
c:\ucto2010\{PDF3}\DZP_3X.DEF
c:\ucto2010\{PDF3}\DZP_3X.PDF
c:\ucto2010\{PDF3}\DZPX.DEF
c:\ucto2010\{PDF3}\DZPX.PDF
c:\ucto2010\{PDF3}\HROMOZNX.DEF
c:\ucto2010\{PDF3}\HROMOZNX.PDF
c:\ucto2010\{PDF3}\CHYBCASX.DEF
c:\ucto2010\{PDF3}\CHYBCASX.PDF
c:\ucto2010\{PDF3}\NEMOCX.DEF
c:\ucto2010\{PDF3}\NEMOCX.PDF
c:\ucto2010\{PDF3}\OSSZKX.DEF
c:\ucto2010\{PDF3}\OSSZKX.PDF
c:\ucto2010\{PDF3}\OSSZX.DEF
c:\ucto2010\{PDF3}\OSSZX.PDF
c:\ucto2010\{PDF3}\POCZAMX.DEF
c:\ucto2010\{PDF3}\POCZAMX.PDF
c:\ucto2010\{PDF3}\POJZAMX.DEF
c:\ucto2010\{PDF3}\POJZAMX.PDF
c:\ucto2010\{PDF3}\SILDANPX.DEF
c:\ucto2010\{PDF3}\SILDANPX.PDF
c:\ucto2010\{PDF3}\SILDANX.DEF
c:\ucto2010\{PDF3}\SILDANX.PDF
c:\ucto2010\{PDF3}\SOUHLASX.DEF
c:\ucto2010\{PDF3}\SOUHLASX.PDF
c:\ucto2010\{PDF3}\VYUCTSRX.DEF
c:\ucto2010\{PDF3}\VYUCTSRX.PDF
c:\ucto2010\{PDF3}\VYUCTX.DEF
c:\ucto2010\{PDF3}\VYUCTX.PDF
c:\ucto2010\{PDF3}\VZPX.DEF
c:\ucto2010\{PDF3}\VZPX.PDF
c:\ucto2010\{PRIK}\ABSENCE.004
c:\ucto2010\{PRIK}\ADRESY.000
c:\ucto2010\{PRIK}\ADRESY.T00
c:\ucto2010\{PRIK}\ADRSPEC.000
c:\ucto2010\{PRIK}\ADRSPEC.T00
c:\ucto2010\{PRIK}\ARCHIVM.004
c:\ucto2010\{PRIK}\ARCHIVM.T04
c:\ucto2010\{PRIK}\AUTA.005
c:\ucto2010\{PRIK}\AUTA.T05
c:\ucto2010\{PRIK}\BANKA1.008
c:\ucto2010\{PRIK}\CE_AUTA.006
c:\ucto2010\{PRIK}\CE_AUTA.T06
c:\ucto2010\{PRIK}\CE_TRASY.006
c:\ucto2010\{PRIK}\CEST_FH.006
c:\ucto2010\{PRIK}\CEST_FH.T06
c:\ucto2010\{PRIK}\CEST_FP.006
c:\ucto2010\{PRIK}\CEST_FS.006
c:\ucto2010\{PRIK}\CEST_VH.006
c:\ucto2010\{PRIK}\CEST_VH.T06
c:\ucto2010\{PRIK}\CEST_VP.006
c:\ucto2010\{PRIK}\CEST_VS.006
c:\ucto2010\{PRIK}\CISABS.004
c:\ucto2010\{PRIK}\CISCEST.005
c:\ucto2010\{PRIK}\CISDOKL.001
c:\ucto2010\{PRIK}\CISDRUH.001
c:\ucto2010\{PRIK}\CISPOH.001
c:\ucto2010\{PRIK}\CISPOL.006
c:\ucto2010\{PRIK}\CISPOZN.000
c:\ucto2010\{PRIK}\CISPOZN.T00
c:\ucto2010\{PRIK}\CIST.000
c:\ucto2010\{PRIK}\CISTEXT.001
c:\ucto2010\{PRIK}\CISTXT.006
c:\ucto2010\{PRIK}\CISUCEL.005
c:\ucto2010\{PRIK}\CISUKOL.004
c:\ucto2010\{PRIK}\CISVYKON.001
c:\ucto2010\{PRIK}\DAP15.003
c:\ucto2010\{PRIK}\DAP15.T03
c:\ucto2010\{PRIK}\DAP16.003
c:\ucto2010\{PRIK}\DAP16.T03
c:\ucto2010\{PRIK}\DENIK.001
c:\ucto2010\{PRIK}\DENIK.T01
c:\ucto2010\{PRIK}\DETI.004
c:\ucto2010\{PRIK}\DETI15.003
c:\ucto2010\{PRIK}\DETI16.003
c:\ucto2010\{PRIK}\DODL_AH.006
c:\ucto2010\{PRIK}\DODL_AH.T06
c:\ucto2010\{PRIK}\DODL_AP.006
c:\ucto2010\{PRIK}\DODL_AS.006
c:\ucto2010\{PRIK}\DODL_FH.006
c:\ucto2010\{PRIK}\DODL_FH.T06
c:\ucto2010\{PRIK}\DODL_FP.006
c:\ucto2010\{PRIK}\DODL_FS.006
c:\ucto2010\{PRIK}\DODL_VH.006
c:\ucto2010\{PRIK}\DODL_VH.T06
c:\ucto2010\{PRIK}\DODL_VP.006
c:\ucto2010\{PRIK}\DODL_VS.006
c:\ucto2010\{PRIK}\DOPISY.002
c:\ucto2010\{PRIK}\DOPISY.T02
c:\ucto2010\{PRIK}\DOPISYMM.002
c:\ucto2010\{PRIK}\DOPISYMM.T02
c:\ucto2010\{PRIK}\DOVROK.004
c:\ucto2010\{PRIK}\DROBMAJ.009
c:\ucto2010\{PRIK}\DROBMAJ.T09
c:\ucto2010\{PRIK}\EDIT.000
c:\ucto2010\{PRIK}\EDITPAR.000
c:\ucto2010\{PRIK}\EDITTAB.000
c:\ucto2010\{PRIK}\EDITTAB.T00
c:\ucto2010\{PRIK}\FAKT_AH.006
c:\ucto2010\{PRIK}\FAKT_AH.T06
c:\ucto2010\{PRIK}\FAKT_AP.006
c:\ucto2010\{PRIK}\FAKT_AS.006
c:\ucto2010\{PRIK}\FAKT_FH.006
c:\ucto2010\{PRIK}\FAKT_FH.T06
c:\ucto2010\{PRIK}\FAKT_FP.006
c:\ucto2010\{PRIK}\FAKT_FS.006
c:\ucto2010\{PRIK}\FAKT_VH.006
c:\ucto2010\{PRIK}\FAKT_VH.T06
c:\ucto2010\{PRIK}\FAKT_VP.006
c:\ucto2010\{PRIK}\FAKT_VS.006
c:\ucto2010\{PRIK}\FINANCE.001
c:\ucto2010\{PRIK}\FINANCE.T01
c:\ucto2010\{PRIK}\JIZDY.005
c:\ucto2010\{PRIK}\JIZDY.T05
c:\ucto2010\{PRIK}\KATEG.004
c:\ucto2010\{PRIK}\MAT_HP.007
c:\ucto2010\{PRIK}\MAT_PP.007
c:\ucto2010\{PRIK}\MATERIAL.001
c:\ucto2010\{PRIK}\MATERIAL.T01
c:\ucto2010\{PRIK}\MZDY.004
c:\ucto2010\{PRIK}\MZDY.T04
c:\ucto2010\{PRIK}\OBJE_FH.006
c:\ucto2010\{PRIK}\OBJE_FH.T06
c:\ucto2010\{PRIK}\OBJE_FP.006
c:\ucto2010\{PRIK}\OBJE_FS.006
c:\ucto2010\{PRIK}\OBJE_VH.006
c:\ucto2010\{PRIK}\OBJE_VH.T06
c:\ucto2010\{PRIK}\OBJE_VP.006
c:\ucto2010\{PRIK}\OBJE_VS.006
c:\ucto2010\{PRIK}\ODPISY.009
c:\ucto2010\{PRIK}\ODVODYM.004
c:\ucto2010\{PRIK}\OSSZ08.003
c:\ucto2010\{PRIK}\OST15.003
c:\ucto2010\{PRIK}\OST16.003
c:\ucto2010\{PRIK}\PARAM2.000
c:\ucto2010\{PRIK}\PARAM2.T00
c:\ucto2010\{PRIK}\PARHB.008
c:\ucto2010\{PRIK}\PARZAS.001
c:\ucto2010\{PRIK}\PHM.005
c:\ucto2010\{PRIK}\PLATBY.001
c:\ucto2010\{PRIK}\PLATBY.T01
c:\ucto2010\{PRIK}\POHLZAV.001
c:\ucto2010\{PRIK}\POHLZAV.T01
c:\ucto2010\{PRIK}\POHYBM.001
c:\ucto2010\{PRIK}\POHYBV.001
c:\ucto2010\{PRIK}\POHYBZ.001
c:\ucto2010\{PRIK}\POJIST.004
c:\ucto2010\{PRIK}\POSTA.002
c:\ucto2010\{PRIK}\POSTA.T02
c:\ucto2010\{PRIK}\PRACOV.004
c:\ucto2010\{PRIK}\PRACOV.T04
c:\ucto2010\{PRIK}\PRACSML.004
c:\ucto2010\{PRIK}\PRACSML.T04
c:\ucto2010\{PRIK}\PRAVJIZD.005
c:\ucto2010\{PRIK}\PRAVJIZD.T05
c:\ucto2010\{PRIK}\PRIKH.008
c:\ucto2010\{PRIK}\PRIKP.008
c:\ucto2010\{PRIK}\SCIT_H.099
c:\ucto2010\{PRIK}\SCIT_H.T99
c:\ucto2010\{PRIK}\SCIT_P.099
c:\ucto2010\{PRIK}\SHIFTF3.000
c:\ucto2010\{PRIK}\SIL.005
c:\ucto2010\{PRIK}\SIL.T05
c:\ucto2010\{PRIK}\SILDAN.005
c:\ucto2010\{PRIK}\SILVOZ.005
c:\ucto2010\{PRIK}\SRAZKY.004
c:\ucto2010\{PRIK}\SRAZKY.T04
c:\ucto2010\{PRIK}\STATY.000
c:\ucto2010\{PRIK}\STRAV.004
c:\ucto2010\{PRIK}\TECHZHOD.009
c:\ucto2010\{PRIK}\TEXTY.002
c:\ucto2010\{PRIK}\TEXTY.T02
c:\ucto2010\{PRIK}\TRIDY.004
c:\ucto2010\{PRIK}\TYPDOKL.001
c:\ucto2010\{PRIK}\UCTY.000
c:\ucto2010\{PRIK}\UKOL.004
c:\ucto2010\{PRIK}\UKOLY.000
c:\ucto2010\{PRIK}\UKOLY.T00
c:\ucto2010\{PRIK}\UPR15.003
c:\ucto2010\{PRIK}\UPR16.003
c:\ucto2010\{PRIK}\UZAV.001
c:\ucto2010\{PRIK}\VYKMAZA.UUU
c:\ucto2010\{PRIK}\VYR_HP.007
c:\ucto2010\{PRIK}\VYR_HV.007
c:\ucto2010\{PRIK}\VYR_PP.007
c:\ucto2010\{PRIK}\VYR_PV.007
c:\ucto2010\{PRIK}\VYRIZUJE.002
c:\ucto2010\{PRIK}\VYROBA.001
c:\ucto2010\{PRIK}\VYROBKY.001
c:\ucto2010\{PRIK}\VYROBKY.T01
c:\ucto2010\{PRIK}\VYUCSRAZ.097
c:\ucto2010\{PRIK}\VYUCZAL.097
c:\ucto2010\{PRIK}\VZP08.003
c:\ucto2010\{PRIK}\ZAL_H.099
c:\ucto2010\{PRIK}\ZAL_H.T99
c:\ucto2010\{PRIK}\ZAOKFA.006
c:\ucto2010\{PRIK}\ZBO_HP.007
c:\ucto2010\{PRIK}\ZBO_HV.007
c:\ucto2010\{PRIK}\ZBO_PP.007
c:\ucto2010\{PRIK}\ZBO_PV.007
c:\ucto2010\{PRIK}\ZBOZI.001
c:\ucto2010\{PRIK}\ZBOZI.T01
c:\ucto2010\{PRIK}\ZP.009
c:\ucto2010\{PRIK}\ZP.T09
c:\ucto2010\{SEST}\SEST00.TXT
c:\ucto2010\{SEST}\SEST01.TXT
c:\ucto2010\{SEST}\SEST02.TXT
c:\ucto2010\{SEST}\SEST03.TXT
c:\ucto2010\{SEST}\SEST04.TXT
c:\ucto2010\{SEST}\SEST05.TXT
c:\ucto2010\{SEST}\SEST06.TXT
c:\ucto2010\{SEST}\SEST07.TXT
c:\ucto2010\{SEST}\SEST08.TXT
c:\ucto2010\{SEST}\SEST09.TXT
c:\ucto2010\{SEST}\SEST10.TXT
c:\ucto2010\{SLOZ}\BALIK_O.HTM
c:\ucto2010\{SLOZ}\BALIK_O.JS
c:\ucto2010\{SLOZ}\BALIK_P.HTM
c:\ucto2010\{SLOZ}\BALIK_P.JS
c:\ucto2010\{SLOZ}\SLOZ_A.HTM
c:\ucto2010\{SLOZ}\SLOZ_A.JS
c:\ucto2010\{SLOZ}\SLOZ_C.HTM
c:\ucto2010\{SLOZ}\SLOZ_C.JS
c:\ucto2010\{STAN}\BACKUP.000
c:\ucto2010\{STAN}\BKPSTAT.000
c:\ucto2010\{STAN}\DANZAT.004
c:\ucto2010\{STAN}\HESLA.000
c:\ucto2010\{STAN}\HESLA.T00
c:\ucto2010\{STAN}\HOBAPZ.008
c:\ucto2010\{STAN}\HOBAPZ.T08
c:\ucto2010\{STAN}\KALEXEK.099
c:\ucto2010\{STAN}\KALSZM06.099
c:\ucto2010\{STAN}\KASA.099
c:\ucto2010\{STAN}\LEAS.099
c:\ucto2010\{STAN}\LEAS.T99
c:\ucto2010\{STAN}\PAR01A3.001
c:\ucto2010\{STAN}\PAR02A3.002
c:\ucto2010\{STAN}\PAR03A3.003
c:\ucto2010\{STAN}\PAR03A3.T03
c:\ucto2010\{STAN}\PAR06A3.006
c:\ucto2010\{STAN}\PAR07A3.007
c:\ucto2010\{STAN}\PAR08A3.008
c:\ucto2010\{STAN}\PAR09A3.009
c:\ucto2010\{STAN}\PARAM3.000
c:\ucto2010\{STAN}\PARAM3.T00
c:\ucto2010\{STAN}\PATHS.000
c:\ucto2010\{STAN}\PATHS.X00
c:\ucto2010\{STAN}\PENIZE.009
c:\ucto2010\{STAN}\PENIZED.009
c:\ucto2010\{STAN}\PGM.000
c:\ucto2010\{STAN}\SCITAC.099
c:\ucto2010\{STAN}\STAT.000
c:\ucto2010\{STAN}\TELSEZN.099
c:\ucto2010\{STAN}\VEDKALK.099
c:\ucto2010\{TISK}\ALISFAND.EXE
c:\ucto2010\{TISK}\CALLER.EXE
c:\ucto2010\{TISK}\CMDIALOG.VBX
c:\ucto2010\{TISK}\DISKSIZW.EXE
c:\ucto2010\{TISK}\DISKY.EXE
c:\ucto2010\{TISK}\ELPODPIS.EXE
c:\ucto2010\{TISK}\FAND2PDF.EXE
c:\ucto2010\{TISK}\FANDCLIP.EXE
c:\ucto2010\{TISK}\IEUCTO.EXE
c:\ucto2010\{TISK}\MSINET.OCX
c:\ucto2010\{TISK}\MSMAPI32.OCX
c:\ucto2010\{TISK}\MSVBVM60.DLL
c:\ucto2010\{TISK}\PDFTISK1.EXE
c:\ucto2010\{TISK}\PDFTISK2.EXE
c:\ucto2010\{TISK}\PDFTISK3.EXE
c:\ucto2010\{TISK}\REGISTER.EXE
c:\ucto2010\{TISK}\SETUPCP.EXE
c:\ucto2010\{TISK}\SIFRCSSZ.CER
c:\ucto2010\{TISK}\UCTOFONT.FON
c:\ucto2010\{TISK}\UCTOFT98.EXE
c:\ucto2010\{TISK}\UCTOFTP.EXE
c:\ucto2010\{TISK}\UCTOGRAF.EXE
c:\ucto2010\{TISK}\UCTOGRAF.INI
c:\ucto2010\{TISK}\UCTOLNK.EXE
c:\ucto2010\{TISK}\UCTOLNK.UUU
c:\ucto2010\{TISK}\UCTOLNK.W7
c:\ucto2010\{TISK}\UCTOLNK.WV
c:\ucto2010\{TISK}\UCTOLNK.WXP
c:\ucto2010\{TISK}\UCTOOL.EXE
c:\ucto2010\{TISK}\UEMAIL.EXE
c:\ucto2010\{TISK}\UEMAIL06.EXE
c:\ucto2010\{TISK}\UTISK01.EXE
c:\ucto2010\{TISK}\UTISK04.EXE
c:\ucto2010\{TISK}\UTISK98.EXE
c:\ucto2010\{TISK}\UTISK98.INI
c:\ucto2010\{TISK}\VBRUN300.DLL
c:\ucto2010\{TISK}\WINVERZE.EXE
c:\ucto2010\{UDOC}\CENIK.TXT
c:\ucto2010\{UDOC}\D2008.PDF
c:\ucto2010\{UDOC}\FAKTURA.TXT
c:\ucto2010\{UDOC}\INFO.TXT
c:\ucto2010\{UDOC}\LICENCE.TXT
c:\ucto2010\{UDOC}\OBJ.TXT
c:\ucto2010\{UDOC}\OBJZPR.TXT
c:\ucto2010\{UDOC}\ONAS.TXT
c:\ucto2010\{UDOC}\POUPG.TXT
c:\ucto2010\{UDOC}\PRIRUCKA.TXT
c:\ucto2010\{UDOC}\PRPRDOK.TXT
c:\ucto2010\{UDOC}\R2010.PDF
c:\ucto2010\{UDOC}\U2010.PDF
c:\ucto2010\{UDOC}\UCTOWIN7.TXT
c:\ucto2010\{UDOC}\ZPROSTRE.TXT
c:\ucto2010\{WWWW}\install.msg
c:\ucto2010\{WWWW}\komplet.exe
c:\ucto2010\{WWWW}\komplet1.pak
c:\ucto2010\{WWWW}\VERZEWWW.UUU
c:\ucto2010\{ZAL2}\{DATA}.J2B
c:\ucto2010\{ZAL2}\{DATA}.J2T
c:\ucto2010\{ZAL2}\{DATA}.J2Z
c:\ucto2010\{ZAL2}\{GLOB}.J4B
c:\ucto2010\{ZAL2}\{GLOB}.J4T
c:\ucto2010\{ZAL2}\{GLOB}.J4Z
c:\ucto2010\{ZAL2}\FIRMA2.J2B
c:\ucto2010\{ZAL2}\FIRMA2.J2T
c:\ucto2010\{ZAL2}\FIRMA2.J2Z
c:\ucto2010\{ZAL2}\FIRMA3.J2B
c:\ucto2010\{ZAL2}\FIRMA3.J2T
c:\ucto2010\{ZAL2}\FIRMA3.J2Z
c:\ucto2010\{ZAL2}\FIRMA4.J2B
c:\ucto2010\{ZAL2}\FIRMA4.J2T
c:\ucto2010\{ZAL2}\FIRMA4.J2Z
c:\ucto2010\{ZAL2}\FIRMA8.J2B
c:\ucto2010\{ZAL2}\FIRMA8.J2T
c:\ucto2010\{ZAL2}\FIRMA8.J2Z
c:\ucto2010\ÚČTO2010.W9X
c:\ucto2010\B&W.PAL
c:\ucto2010\BLUE.PAL
c:\ucto2010\BROWN.PAL
c:\ucto2010\CAT.BAT
c:\ucto2010\CISABS.UUU
c:\ucto2010\CISDRUH.UUU
c:\ucto2010\CISPOH.UUU
c:\ucto2010\CISSLOUP.000
c:\ucto2010\CISSLOUP.X00
c:\ucto2010\CONFIG.TXT
c:\ucto2010\DELFILE.EXE
c:\ucto2010\DISKSIZE.EXE
c:\ucto2010\DNY.000
c:\ucto2010\FAND.CFG
c:\ucto2010\FAND.RES
c:\ucto2010\FANDCFG.09
c:\ucto2010\FANDCFG.10
c:\ucto2010\FANDCFG.BAK
c:\ucto2010\FANDCLIP.UUU
c:\ucto2010\FANDHTML.EXE
c:\ucto2010\FANDINST.EXE
c:\ucto2010\FANDT602.EXE
c:\ucto2010\FILESIZE.EXE
c:\ucto2010\FIRMA2\ADRESY.000
c:\ucto2010\FIRMA2\ADRESY.T00
c:\ucto2010\FIRMA2\ADRESY.X00
c:\ucto2010\FIRMA2\ARCHIVD.001
c:\ucto2010\FIRMA2\ARCHIVD.T01
c:\ucto2010\FIRMA2\BANKA1.008
c:\ucto2010\FIRMA2\CISABS.004
c:\ucto2010\FIRMA2\CISABS.X04
c:\ucto2010\FIRMA2\CISDOKL.001
c:\ucto2010\FIRMA2\CISDRUH.001
c:\ucto2010\FIRMA2\CISDRUH.X01
c:\ucto2010\FIRMA2\CISPOH.001
c:\ucto2010\FIRMA2\CISPOH.X01
c:\ucto2010\FIRMA2\CISPOZN.000
c:\ucto2010\FIRMA2\CISPOZN.T00
c:\ucto2010\FIRMA2\CIST.000
c:\ucto2010\FIRMA2\CIST.X00
c:\ucto2010\FIRMA2\CISTEXT.001
c:\ucto2010\FIRMA2\CISTXT.006
c:\ucto2010\FIRMA2\CISTXT.X06
c:\ucto2010\FIRMA2\CISVYKON.001
c:\ucto2010\FIRMA2\CISVYKON.X01
c:\ucto2010\FIRMA2\DENIK.001
c:\ucto2010\FIRMA2\DENIK.T01
c:\ucto2010\FIRMA2\EDIT.000
c:\ucto2010\FIRMA2\EDIT.X00
c:\ucto2010\FIRMA2\EDITPAR.000
c:\ucto2010\FIRMA2\EDITPAR.X00
c:\ucto2010\FIRMA2\FINANCE.001
c:\ucto2010\FIRMA2\FINANCE.T01
c:\ucto2010\FIRMA2\KATEG.004
c:\ucto2010\FIRMA2\KATEG.X04
c:\ucto2010\FIRMA2\PAR01A2.001
c:\ucto2010\FIRMA2\PAR01A4.001
c:\ucto2010\FIRMA2\PAR09A2.009
c:\ucto2010\FIRMA2\PAR09A2.T09
c:\ucto2010\FIRMA2\PAR09A4.009
c:\ucto2010\FIRMA2\PARAM2.000
c:\ucto2010\FIRMA2\PARAM2.T00
c:\ucto2010\FIRMA2\PARAM4.000
c:\ucto2010\FIRMA2\PARAM4.T00
c:\ucto2010\FIRMA2\PARZAS.001
c:\ucto2010\FIRMA2\PRACSML.004
c:\ucto2010\FIRMA2\PRACSML.T04
c:\ucto2010\FIRMA2\TRIDY.004
c:\ucto2010\FIRMA2\TRIDY.X04
c:\ucto2010\FIRMA2\TYPDOKL.001
c:\ucto2010\FIRMA2\TYPDOKL.X01
c:\ucto2010\FIRMA2\UKOLY.000
c:\ucto2010\FIRMA2\UKOLY.T00
c:\ucto2010\FIRMA2\UZAV.001
c:\ucto2010\FIRMA2\VYKMAZA.UUU
c:\ucto2010\FIRMA2\ZAOKFA.006
c:\ucto2010\FIRMA2\ZAOKFA.X06
c:\ucto2010\FIRMA2\ZURNALD.001
c:\ucto2010\FIRMA3\ADRESY.000
c:\ucto2010\FIRMA3\ADRESY.T00
c:\ucto2010\FIRMA3\ADRESY.X00
c:\ucto2010\FIRMA3\ARCHIVD.001
c:\ucto2010\FIRMA3\ARCHIVD.T01
c:\ucto2010\FIRMA3\BANKA1.008
c:\ucto2010\FIRMA3\CE_AUTA.006
c:\ucto2010\FIRMA3\CE_AUTA.T06
c:\ucto2010\FIRMA3\CISABS.004
c:\ucto2010\FIRMA3\CISABS.X04
c:\ucto2010\FIRMA3\CISDOKL.001
c:\ucto2010\FIRMA3\CISDRUH.001
c:\ucto2010\FIRMA3\CISDRUH.X01
c:\ucto2010\FIRMA3\CISPOH.001
c:\ucto2010\FIRMA3\CISPOH.X01
c:\ucto2010\FIRMA3\CISPOZN.000
c:\ucto2010\FIRMA3\CISPOZN.T00
c:\ucto2010\FIRMA3\CIST.000
c:\ucto2010\FIRMA3\CIST.X00
c:\ucto2010\FIRMA3\CISTEXT.001
c:\ucto2010\FIRMA3\CISTXT.006
c:\ucto2010\FIRMA3\CISTXT.X06
c:\ucto2010\FIRMA3\CISVYKON.001
c:\ucto2010\FIRMA3\CISVYKON.X01
c:\ucto2010\FIRMA3\DAP15.003
c:\ucto2010\FIRMA3\DAP15.T03
c:\ucto2010\FIRMA3\DENIK.001
c:\ucto2010\FIRMA3\DENIK.T01
c:\ucto2010\FIRMA3\EDIT.000
c:\ucto2010\FIRMA3\EDIT.X00
c:\ucto2010\FIRMA3\EDITPAR.000
c:\ucto2010\FIRMA3\EDITPAR.X00
c:\ucto2010\FIRMA3\FINANCE.001
c:\ucto2010\FIRMA3\FINANCE.T01
c:\ucto2010\FIRMA3\KATEG.004
c:\ucto2010\FIRMA3\KATEG.X04
c:\ucto2010\FIRMA3\PAR01A2.001
c:\ucto2010\FIRMA3\PAR01A4.001
c:\ucto2010\FIRMA3\PAR03A4.003
c:\ucto2010\FIRMA3\PAR09A2.009
c:\ucto2010\FIRMA3\PAR09A2.T09
c:\ucto2010\FIRMA3\PAR09A4.009
c:\ucto2010\FIRMA3\PARAM2.000
c:\ucto2010\FIRMA3\PARAM2.T00
c:\ucto2010\FIRMA3\PARAM4.000
c:\ucto2010\FIRMA3\PARAM4.T00
c:\ucto2010\FIRMA3\PARZAS.001
c:\ucto2010\FIRMA3\POJIST.004
c:\ucto2010\FIRMA3\POJIST.X04
c:\ucto2010\FIRMA3\PRACSML.004
c:\ucto2010\FIRMA3\PRACSML.T04
c:\ucto2010\FIRMA3\SHIFTF3.000
c:\ucto2010\FIRMA3\SHIFTF3.X00
c:\ucto2010\FIRMA3\SIL.005
c:\ucto2010\FIRMA3\SIL.T05
c:\ucto2010\FIRMA3\TRIDY.004
c:\ucto2010\FIRMA3\TRIDY.X04
c:\ucto2010\FIRMA3\TYPDOKL.001
c:\ucto2010\FIRMA3\TYPDOKL.X01
c:\ucto2010\FIRMA3\UKOLY.000
c:\ucto2010\FIRMA3\UKOLY.T00
c:\ucto2010\FIRMA3\UZAV.001
c:\ucto2010\FIRMA3\VYKMAZA.UUU
c:\ucto2010\FIRMA3\VYRIZUJE.002
c:\ucto2010\FIRMA3\VYRIZUJE.X02
c:\ucto2010\FIRMA3\ZAOKFA.006
c:\ucto2010\FIRMA3\ZAOKFA.X06
c:\ucto2010\FIRMA3\ZURNALD.001
c:\ucto2010\FIRMA4\ADRESY.000
c:\ucto2010\FIRMA4\ADRESY.T00
c:\ucto2010\FIRMA4\ADRESY.X00
c:\ucto2010\FIRMA4\ARCHIVD.001
c:\ucto2010\FIRMA4\ARCHIVD.T01
c:\ucto2010\FIRMA4\AUTA.005
c:\ucto2010\FIRMA4\AUTA.T05
c:\ucto2010\FIRMA4\BANKA1.008
c:\ucto2010\FIRMA4\CE_AUTA.006
c:\ucto2010\FIRMA4\CE_AUTA.T06
c:\ucto2010\FIRMA4\CE_TRASY.006
c:\ucto2010\FIRMA4\CEST_FH.006
c:\ucto2010\FIRMA4\CEST_FH.T06
c:\ucto2010\FIRMA4\CEST_FP.006
c:\ucto2010\FIRMA4\CEST_FS.006
c:\ucto2010\FIRMA4\CEST_VH.006
c:\ucto2010\FIRMA4\CEST_VH.T06
c:\ucto2010\FIRMA4\CEST_VP.006
c:\ucto2010\FIRMA4\CEST_VS.006
c:\ucto2010\FIRMA4\CISABS.004
c:\ucto2010\FIRMA4\CISABS.X04
c:\ucto2010\FIRMA4\CISCEST.005
c:\ucto2010\FIRMA4\CISCEST.X05
c:\ucto2010\FIRMA4\CISDOKL.001
c:\ucto2010\FIRMA4\CISDRUH.001
c:\ucto2010\FIRMA4\CISDRUH.X01
c:\ucto2010\FIRMA4\CISPOH.001
c:\ucto2010\FIRMA4\CISPOH.X01
c:\ucto2010\FIRMA4\CISPOZN.000
c:\ucto2010\FIRMA4\CISPOZN.T00
c:\ucto2010\FIRMA4\CIST.000
c:\ucto2010\FIRMA4\CIST.X00
c:\ucto2010\FIRMA4\CISTEXT.001
c:\ucto2010\FIRMA4\CISTXT.006
c:\ucto2010\FIRMA4\CISTXT.X06
c:\ucto2010\FIRMA4\CISUCEL.005
c:\ucto2010\FIRMA4\CISVYKON.001
c:\ucto2010\FIRMA4\CISVYKON.X01
c:\ucto2010\FIRMA4\DENIK.001
c:\ucto2010\FIRMA4\DENIK.T01
c:\ucto2010\FIRMA4\DODL_VH.006
c:\ucto2010\FIRMA4\DODL_VH.T06
c:\ucto2010\FIRMA4\EDIT.000
c:\ucto2010\FIRMA4\EDIT.X00
c:\ucto2010\FIRMA4\EDITPAR.000
c:\ucto2010\FIRMA4\EDITPAR.X00
c:\ucto2010\FIRMA4\FAKT_VH.006
c:\ucto2010\FIRMA4\FAKT_VH.T06
c:\ucto2010\FIRMA4\FINANCE.001
c:\ucto2010\FIRMA4\FINANCE.T01
c:\ucto2010\FIRMA4\JIZDY.005
c:\ucto2010\FIRMA4\JIZDY.T05
c:\ucto2010\FIRMA4\KATEG.004
c:\ucto2010\FIRMA4\KATEG.X04
c:\ucto2010\FIRMA4\OBJE_VH.006
c:\ucto2010\FIRMA4\OBJE_VH.T06
c:\ucto2010\FIRMA4\PAR01A2.001
c:\ucto2010\FIRMA4\PAR01A4.001
c:\ucto2010\FIRMA4\PAR02A2.002
c:\ucto2010\FIRMA4\PAR02A4.002
c:\ucto2010\FIRMA4\PAR03A4.003
c:\ucto2010\FIRMA4\PAR04A2.004
c:\ucto2010\FIRMA4\PAR05A4.005
c:\ucto2010\FIRMA4\PAR06A4.006
c:\ucto2010\FIRMA4\PAR08A2.008
c:\ucto2010\FIRMA4\PAR08A4.008
c:\ucto2010\FIRMA4\PAR09A2.009
c:\ucto2010\FIRMA4\PAR09A2.T09
c:\ucto2010\FIRMA4\PAR09A4.009
c:\ucto2010\FIRMA4\PARAM2.000
c:\ucto2010\FIRMA4\PARAM2.T00
c:\ucto2010\FIRMA4\PARAM4.000
c:\ucto2010\FIRMA4\PARAM4.T00
c:\ucto2010\FIRMA4\PARHB.008
c:\ucto2010\FIRMA4\PARZAS.001
c:\ucto2010\FIRMA4\PHM.005
c:\ucto2010\FIRMA4\PHM.X05
c:\ucto2010\FIRMA4\POHLZAV.001
c:\ucto2010\FIRMA4\POHLZAV.T01
c:\ucto2010\FIRMA4\POJIST.004
c:\ucto2010\FIRMA4\POJIST.X04
c:\ucto2010\FIRMA4\PRACSML.004
c:\ucto2010\FIRMA4\PRACSML.T04
c:\ucto2010\FIRMA4\PROVOZ.005
c:\ucto2010\FIRMA4\PROVOZ.T05
c:\ucto2010\FIRMA4\SHIFTF3.000
c:\ucto2010\FIRMA4\SHIFTF3.X00
c:\ucto2010\FIRMA4\SIL.005
c:\ucto2010\FIRMA4\SIL.T05
c:\ucto2010\FIRMA4\SILDAN.005
c:\ucto2010\FIRMA4\SILDAN.X05
c:\ucto2010\FIRMA4\TRIDY.004
c:\ucto2010\FIRMA4\TRIDY.X04
c:\ucto2010\FIRMA4\TYPDOKL.001
c:\ucto2010\FIRMA4\TYPDOKL.X01
c:\ucto2010\FIRMA4\UCTY.000
c:\ucto2010\FIRMA4\UKOLY.000
c:\ucto2010\FIRMA4\UKOLY.T00
c:\ucto2010\FIRMA4\UZAV.001
c:\ucto2010\FIRMA4\VYKMAZA.UUU
c:\ucto2010\FIRMA4\VYRIZUJE.002
c:\ucto2010\FIRMA4\VYRIZUJE.X02
c:\ucto2010\FIRMA4\ZAOKFA.006
c:\ucto2010\FIRMA4\ZAOKFA.X06
c:\ucto2010\FIRMA4\ZURNALD.001
c:\ucto2010\FIRMA6\ADRESY.000
c:\ucto2010\FIRMA6\ADRESY.T00
c:\ucto2010\FIRMA6\ADRESY.X00
c:\ucto2010\FIRMA6\ARCHIVD.001
c:\ucto2010\FIRMA6\ARCHIVD.T01
c:\ucto2010\FIRMA6\AUTA.005
c:\ucto2010\FIRMA6\AUTA.T05
c:\ucto2010\FIRMA6\BANKA1.008
c:\ucto2010\FIRMA6\CE_AUTA.006
c:\ucto2010\FIRMA6\CE_AUTA.T06
c:\ucto2010\FIRMA6\CE_TRASY.006
c:\ucto2010\FIRMA6\CEST_FH.006
c:\ucto2010\FIRMA6\CEST_FH.T06
c:\ucto2010\FIRMA6\CEST_FH.X06
c:\ucto2010\FIRMA6\CEST_FP.006
c:\ucto2010\FIRMA6\CEST_FS.006
c:\ucto2010\FIRMA6\CEST_VH.006
c:\ucto2010\FIRMA6\CEST_VH.T06
c:\ucto2010\FIRMA6\CEST_VH.X06
c:\ucto2010\FIRMA6\CEST_VP.006
c:\ucto2010\FIRMA6\CEST_VS.006
c:\ucto2010\FIRMA6\CISABS.004
c:\ucto2010\FIRMA6\CISABS.X04
c:\ucto2010\FIRMA6\CISCEST.005
c:\ucto2010\FIRMA6\CISDOKL.001
c:\ucto2010\FIRMA6\CISDRUH.001
c:\ucto2010\FIRMA6\CISDRUH.X01
c:\ucto2010\FIRMA6\CISPOH.001
c:\ucto2010\FIRMA6\CISPOZN.000
c:\ucto2010\FIRMA6\CISPOZN.T00
c:\ucto2010\FIRMA6\CIST.000
c:\ucto2010\FIRMA6\CISTEXT.001
c:\ucto2010\FIRMA6\CISTXT.006
c:\ucto2010\FIRMA6\CISUCEL.005
c:\ucto2010\FIRMA6\CISVYKON.001
c:\ucto2010\FIRMA6\DENIK.001
c:\ucto2010\FIRMA6\DENIK.T01
c:\ucto2010\FIRMA6\DODL_VH.006
c:\ucto2010\FIRMA6\DODL_VH.T06
c:\ucto2010\FIRMA6\DODL_VH.X06
c:\ucto2010\FIRMA6\EDIT.000
c:\ucto2010\FIRMA6\FAKT_VH.006
c:\ucto2010\FIRMA6\FAKT_VH.T06
c:\ucto2010\FIRMA6\FAKT_VH.X06
c:\ucto2010\FIRMA6\JIZDY.005
c:\ucto2010\FIRMA6\JIZDY.T05
c:\ucto2010\FIRMA6\JIZDY.X05
c:\ucto2010\FIRMA6\KATEG.004
c:\ucto2010\FIRMA6\OBJE_VH.006
c:\ucto2010\FIRMA6\OBJE_VH.T06
c:\ucto2010\FIRMA6\OBJE_VH.X06
c:\ucto2010\FIRMA6\PAR01A2.001
c:\ucto2010\FIRMA6\PAR01A4.001
c:\ucto2010\FIRMA6\PAR02A2.002
c:\ucto2010\FIRMA6\PAR02A4.002
c:\ucto2010\FIRMA6\PAR03A4.003
c:\ucto2010\FIRMA6\PAR04A2.004
c:\ucto2010\FIRMA6\PAR05A4.005
c:\ucto2010\FIRMA6\PAR06A4.006
c:\ucto2010\FIRMA6\PAR08A4.008
c:\ucto2010\FIRMA6\PAR09A2.009
c:\ucto2010\FIRMA6\PAR09A2.T09
c:\ucto2010\FIRMA6\PAR09A4.009
c:\ucto2010\FIRMA6\PARAM2.000
c:\ucto2010\FIRMA6\PARAM2.T00
c:\ucto2010\FIRMA6\PARAM4.000
c:\ucto2010\FIRMA6\PARAM4.T00
c:\ucto2010\FIRMA6\PARZAS.001
c:\ucto2010\FIRMA6\PHM.005
c:\ucto2010\FIRMA6\PHM.X05
c:\ucto2010\FIRMA6\POJIST.004
c:\ucto2010\FIRMA6\PRACSML.004
c:\ucto2010\FIRMA6\PRACSML.T04
c:\ucto2010\FIRMA6\PROVOZ.005
c:\ucto2010\FIRMA6\PROVOZ.T05
c:\ucto2010\FIRMA6\SHIFTF3.000
c:\ucto2010\FIRMA6\SILDAN.005
c:\ucto2010\FIRMA6\SILDAN.X05
c:\ucto2010\FIRMA6\TRIDY.004
c:\ucto2010\FIRMA6\TYPDOKL.001
c:\ucto2010\FIRMA6\UKOLY.000
c:\ucto2010\FIRMA6\UKOLY.T00
c:\ucto2010\FIRMA6\UZAV.001
c:\ucto2010\FIRMA6\VYRIZUJE.002
c:\ucto2010\FIRMA6\ZAOKFA.006
c:\ucto2010\FIRMA6\ZURNALD.001
c:\ucto2010\FIRMA8\ADRESY.000
c:\ucto2010\FIRMA8\ADRESY.T00
c:\ucto2010\FIRMA8\ADRESY.X00
c:\ucto2010\FIRMA8\ARCHIVD.001
c:\ucto2010\FIRMA8\ARCHIVD.T01
c:\ucto2010\FIRMA8\BANKA1.008
c:\ucto2010\FIRMA8\CISABS.004
c:\ucto2010\FIRMA8\CISABS.X04
c:\ucto2010\FIRMA8\CISDOKL.001
c:\ucto2010\FIRMA8\CISDRUH.001
c:\ucto2010\FIRMA8\CISDRUH.X01
c:\ucto2010\FIRMA8\CISPOH.001
c:\ucto2010\FIRMA8\CISPOH.X01
c:\ucto2010\FIRMA8\CISPOZN.000
c:\ucto2010\FIRMA8\CISPOZN.T00
c:\ucto2010\FIRMA8\CIST.000
c:\ucto2010\FIRMA8\CIST.X00
c:\ucto2010\FIRMA8\CISTXT.006
c:\ucto2010\FIRMA8\CISTXT.X06
c:\ucto2010\FIRMA8\CISVYKON.001
c:\ucto2010\FIRMA8\CISVYKON.X01
c:\ucto2010\FIRMA8\DENIK.001
c:\ucto2010\FIRMA8\DENIK.T01
c:\ucto2010\FIRMA8\EDIT.000
c:\ucto2010\FIRMA8\EDIT.X00
c:\ucto2010\FIRMA8\EDITPAR.000
c:\ucto2010\FIRMA8\EDITPAR.X00
c:\ucto2010\FIRMA8\FINANCE.001
c:\ucto2010\FIRMA8\FINANCE.T01
c:\ucto2010\FIRMA8\KATEG.004
c:\ucto2010\FIRMA8\KATEG.X04
c:\ucto2010\FIRMA8\PAR01A2.001
c:\ucto2010\FIRMA8\PAR01A4.001
c:\ucto2010\FIRMA8\PAR03A4.003
c:\ucto2010\FIRMA8\PAR06A4.006
c:\ucto2010\FIRMA8\PAR08A2.008
c:\ucto2010\FIRMA8\PAR09A2.009
c:\ucto2010\FIRMA8\PAR09A2.T09
c:\ucto2010\FIRMA8\PAR09A4.009
c:\ucto2010\FIRMA8\PARAM2.000
c:\ucto2010\FIRMA8\PARAM2.T00
c:\ucto2010\FIRMA8\PARAM4.000
c:\ucto2010\FIRMA8\PARAM4.T00
c:\ucto2010\FIRMA8\PARZAS.001
c:\ucto2010\FIRMA8\PRACSML.004
c:\ucto2010\FIRMA8\PRACSML.T04
c:\ucto2010\FIRMA8\TRIDY.004
c:\ucto2010\FIRMA8\TRIDY.X04
c:\ucto2010\FIRMA8\TYPDOKL.001
c:\ucto2010\FIRMA8\TYPDOKL.X01
c:\ucto2010\FIRMA8\UKOLY.000
c:\ucto2010\FIRMA8\UKOLY.T00
c:\ucto2010\FIRMA8\UZAV.001
c:\ucto2010\FIRMA8\VYKMAZA.UUU
c:\ucto2010\FIRMA8\ZAOKFA.006
c:\ucto2010\FIRMA8\ZAOKFA.X06
c:\ucto2010\FIRMA8\ZURNALD.001
c:\ucto2010\FNDFILES.EXE
c:\ucto2010\HEAD602.UUU
c:\ucto2010\HELP.000
c:\ucto2010\HELP.T00
c:\ucto2010\HELP02.000
c:\ucto2010\HELP02.T00
c:\ucto2010\HELP03.000
c:\ucto2010\HELP03.T00
c:\ucto2010\HELP04.000
c:\ucto2010\HELP04.T00
c:\ucto2010\HELP05.000
c:\ucto2010\HELP05.T00
c:\ucto2010\HELP06.000
c:\ucto2010\HELP06.T00
c:\ucto2010\HELP08.000
c:\ucto2010\HELP08.T00
c:\ucto2010\HELP98.000
c:\ucto2010\HELP98.T00
c:\ucto2010\HELP99.000
c:\ucto2010\HELP99.T00
c:\ucto2010\IMPORT.PRO
c:\ucto2010\IMPORT.TRO
c:\ucto2010\INFOHLP.000
c:\ucto2010\INFOHLP.T00
c:\ucto2010\ISSHARE.EXE
c:\ucto2010\KALENDAR.000
c:\ucto2010\KALKDPH.000
c:\ucto2010\KALKPOJP.000
c:\ucto2010\KALKPOJZ.000
c:\ucto2010\KALKPRUM.000
c:\ucto2010\KALKPV08.000
c:\ucto2010\KALKTABD.000
c:\ucto2010\KATEG.UUU
c:\ucto2010\LASTAKT.TXT
c:\ucto2010\LCD1.PAL
c:\ucto2010\LCD2.PAL
c:\ucto2010\LKDOPL1\G.000
c:\ucto2010\LKDOPL1\LKDOPL1.RDB
c:\ucto2010\LKDOPL1\LKDOPL1.TTT
c:\ucto2010\LKDOPL1\LKHELP.000
c:\ucto2010\LKDOPL1\LKHELP.T00
c:\ucto2010\MAKEDIR.BAT
c:\ucto2010\MF5460-1.UUU
c:\ucto2010\MODUL01.PRO
c:\ucto2010\MODUL01.TRO
c:\ucto2010\MODUL02.PRO
c:\ucto2010\MODUL02.TRO
c:\ucto2010\MODUL03.PRO
c:\ucto2010\MODUL03.TRO
c:\ucto2010\MODUL04.PRO
c:\ucto2010\MODUL04.TRO
c:\ucto2010\MODUL05.PRO
c:\ucto2010\MODUL05.TRO
c:\ucto2010\MODUL06.PRO
c:\ucto2010\MODUL06.TRO
c:\ucto2010\MODUL07.PRO
c:\ucto2010\MODUL07.TRO
c:\ucto2010\MODUL08.PRO
c:\ucto2010\MODUL08.TRO
c:\ucto2010\MODUL09.PRO
c:\ucto2010\MODUL09.TRO
c:\ucto2010\MODUL97.PRO
c:\ucto2010\MODUL97.TRO
c:\ucto2010\MODUL98.PRO
c:\ucto2010\MODUL98.TRO
c:\ucto2010\MODUL99.PRO
c:\ucto2010\MODUL99.TRO
c:\ucto2010\MZDYPU.000
c:\ucto2010\NUMKB.EXE
c:\ucto2010\NUMKB3.EXE
c:\ucto2010\OPRAVY.UUU
c:\ucto2010\PGM.CAT
c:\ucto2010\PGM.RDB
c:\ucto2010\PGM.TTT
c:\ucto2010\PRINTER.TXT
c:\ucto2010\RADKY.TXT
c:\ucto2010\RENFILES.BAT
c:\ucto2010\RO.EXE
c:\ucto2010\SEARCHX.EXE
c:\ucto2010\SEST01.PRO
c:\ucto2010\SEST01.TRO
c:\ucto2010\SEST02.PRO
c:\ucto2010\SEST02.TRO
c:\ucto2010\SEST03.PRO
c:\ucto2010\SEST03.TRO
c:\ucto2010\SEST04.PRO
c:\ucto2010\SEST04.TRO
c:\ucto2010\SEST05.PRO
c:\ucto2010\SEST05.TRO
c:\ucto2010\SEST06.PRO
c:\ucto2010\SEST06.TRO
c:\ucto2010\SEST07.PRO
c:\ucto2010\SEST07.TRO
c:\ucto2010\SEST08.PRO
c:\ucto2010\SEST08.TRO
c:\ucto2010\SEST09.PRO
c:\ucto2010\SEST09.TRO
c:\ucto2010\SESTAVY.CAT
c:\ucto2010\SESTAVY.RDB
c:\ucto2010\SESTAVY.TTT
c:\ucto2010\SETDATE.EXE
c:\ucto2010\SETFILES.EXE
c:\ucto2010\SEZNTISK.000
c:\ucto2010\SEZNTISK.T00
c:\ucto2010\SLOVY.000
c:\ucto2010\SLOVY.X00
c:\ucto2010\Spec01.pro
c:\ucto2010\Spec01.tro
c:\ucto2010\SPEC011.PRO
c:\ucto2010\SPEC011.TRO
c:\ucto2010\SPEC02.PRO
c:\ucto2010\SPEC02.TRO
c:\ucto2010\SPEC03.PRO
c:\ucto2010\SPEC03.TRO
c:\ucto2010\SPEC04.PRO
c:\ucto2010\SPEC04.TRO
c:\ucto2010\SPEC05.PRO
c:\ucto2010\SPEC05.TRO
c:\ucto2010\SPEC06.PRO
c:\ucto2010\SPEC06.TRO
c:\ucto2010\SPEC07.PRO
c:\ucto2010\SPEC07.TRO
c:\ucto2010\SUBDIR.EXE
c:\ucto2010\SUDLICH.EXE
c:\ucto2010\TIPY.000
c:\ucto2010\TIPY.T00
c:\ucto2010\TIPY.X00
c:\ucto2010\TTT.CAT
c:\ucto2010\TTT.RDB
c:\ucto2010\TTT.TTT
c:\ucto2010\TTTNEW.UUU
c:\ucto2010\TXTNARTF.EXE
c:\ucto2010\U.BAT
c:\ucto2010\u10_cd.exe
c:\ucto2010\UCTO.000
c:\ucto2010\UCTO.PAL
c:\ucto2010\UCTO2010.CAT
c:\ucto2010\UCTO2010.ICO
c:\ucto2010\UCTO2010.RDB
c:\ucto2010\UCTO2010.TTT
c:\ucto2010\UCTOINFO.PRO
c:\ucto2010\UCTOINFO.TRO
c:\ucto2010\UCTOL.000
c:\ucto2010\UCTOTXT.UUU
c:\ucto2010\UCTOTXT2.UUU
c:\ucto2010\UCTOTXT3.UUU
c:\ucto2010\UFAND.EXE
c:\ucto2010\UFAND.OVR
c:\ucto2010\UFANDHLP.000
c:\ucto2010\UFANDHLP.T00
c:\ucto2010\UK.BAT
c:\ucto2010\UPG.PRO
c:\ucto2010\UPG.TRO
c:\ucto2010\UPG01.PRO
c:\ucto2010\UPG01.TRO
c:\ucto2010\UPG02.PRO
c:\ucto2010\UPG02.TRO
c:\ucto2010\UPG03.PRO
c:\ucto2010\UPG03.TRO
c:\ucto2010\UPG04.PRO
c:\ucto2010\UPG04.TRO
c:\ucto2010\UPG05.PRO
c:\ucto2010\UPG05.TRO
c:\ucto2010\UPG06.PRO
c:\ucto2010\UPG06.TRO
c:\ucto2010\UPG07.PRO
c:\ucto2010\UPG07.TRO
c:\ucto2010\UPG08.PRO
c:\ucto2010\UPG08.TRO
c:\ucto2010\UPG09.PRO
c:\ucto2010\UPG09.TRO
c:\ucto2010\UPG97.PRO
c:\ucto2010\UPG97.TRO
c:\ucto2010\UPG99.PRO
c:\ucto2010\UPG99.TRO
c:\ucto2010\UPGPAR.000
c:\ucto2010\VEDLCIN.UUU
c:\ucto2010\VERZE.UUU
c:\ucto2010\VYBERTXT.EXE
c:\ucto2010\VZORTISK.000
c:\ucto2010\zaloha\cti.mne
c:\ucto2010\zaloha\LKDOPL1\G.000
c:\ucto2010\zaloha\LKDOPL1\LKDOPL1.RDB
c:\ucto2010\zaloha\LKDOPL1\LKDOPL1.TTT
c:\ucto2010\zaloha\LKDOPL1\LKHELP.000
c:\ucto2010\zaloha\LKDOPL1\LKHELP.T00
c:\ucto2010\zaloha\SPEC01.PRO
c:\ucto2010\zaloha\Spec01.tro
c:\ucto2010\ZASTUPCE.CAT
c:\ucto2010\ZASTUPCE.INI
c:\ucto2010\ZASTUPCE.RDB
c:\ucto2010\ZASTUPCE.TTT
c:\ucto2010\ZETROZET.PAL
c:\ucto2010\Zástupce - UCTO2010.lnk
c:\ucto2010\ZZZ.BAT
c:\windows\$NtUninstallKB63231$\4042759904
c:\windows\$NtUninstallKB63231$\875938506\@
c:\windows\$NtUninstallKB63231$\875938506\bckfg.tmp
c:\windows\$NtUninstallKB63231$\875938506\cfg.ini
c:\windows\$NtUninstallKB63231$\875938506\Desktop.ini
c:\windows\$NtUninstallKB63231$\875938506\kwrd.dll
c:\windows\$NtUninstallKB63231$\875938506\L\ocxrgwsl
c:\windows\$NtUninstallKB63231$\875938506\U\00000001.@
c:\windows\$NtUninstallKB63231$\875938506\U\00000002.@
c:\windows\$NtUninstallKB63231$\875938506\U\00000004.@
c:\windows\$NtUninstallKB63231$\875938506\U\80000000.@
c:\windows\$NtUninstallKB63231$\875938506\U\80000004.@
c:\windows\$NtUninstallKB63231$\875938506\U\80000032.@
c:\windows\$NtUninstallKB63231$ . . . . nemohl být smazán
.
c:\windows\system32\drivers\prodrv06.sys . . . je infikován!! . . . Failed to find a valid replacement.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-19 do 2011-11-19 )))))))))))))))))))))))))))))))
.
.
2011-11-19 19:52 . 2011-11-19 21:14 -------- d-----w- c:\program files\trend micro
2011-11-19 19:52 . 2011-11-19 21:14 -------- d-----w- C:\rsit
2011-11-19 14:09 . 2011-11-19 14:09 -------- d-----w- c:\documents and settings\Masek\Data aplikací\Malwarebytes
2011-11-19 14:09 . 2011-11-19 14:09 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-19 14:09 . 2011-11-19 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-19 14:09 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-16 20:44 . 2011-11-16 20:44 -------- d-----w- c:\windows\system32\wbem\Repository
2011-11-15 23:13 . 2011-11-15 23:13 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-10-28 19:55 . 2011-10-28 19:55 -------- d-----w- c:\documents and settings\Patrik Netroufal\Local Settings\Data aplikací\ESET
2011-10-28 19:55 . 2011-10-28 19:55 -------- d-----w- c:\documents and settings\Patrik Netroufal\Data aplikací\ESET
2011-10-28 18:54 . 2011-11-14 19:44 -------- d-----w- c:\documents and settings\Masek\Local Settings\Data aplikací\Pinnacle
2011-10-28 18:54 . 2011-10-28 18:54 -------- d-----w- C:\copy-pal
2011-10-22 17:48 . 2011-10-22 17:48 -------- d-----w- c:\documents and settings\Patrik Netroufal\Local Settings\Data aplikací\Unity
2011-10-22 12:05 . 2011-10-22 12:05 -------- d-----w- c:\documents and settings\Masek\Data aplikací\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-19 14:44 . 2011-06-07 04:49 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2005-01-11 08:17 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-08-18 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-08-18 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32(3).dll
2011-09-06 14:10 . 2004-08-18 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:41 . 2004-08-18 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:41 . 2004-08-18 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-08-22 23:41 . 2004-08-18 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-18 12:00 385024 ----a-w- c:\windows\system32\html.iec
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
2009-11-09 23:33 815104 ----a-w- c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll" [2009-11-09 815104]
.
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll" [2009-11-09 815104]
.
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"="c:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE" [2011-03-19 26624]
"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2008-11-18 226576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 3080264]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Masek\Nabídka Start\Programy\Po spuštění\
Svátky a narozeniny.lnk - c:\program files\Svátky a narozeniny\SaN.exe [2009-10-25 693760]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Pinnacle Streaming Server.lnk - c:\program files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe [2008-3-25 603408]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Games\\TmNationsForever\\TmForever.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 118104]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [22.9.2011 11:03 974944]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [12.10.2009 21:29 14976]
R3 PinnacleRoyalTS;Pinnacle Systems RoyalTS Device;c:\windows\system32\drivers\RoyalTS.sys [10.3.2010 19:24 123520]
S3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [7.11.2007 19:15 12928]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [23.12.2010 14:37 137600]
S3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [11.1.2005 16:43 6400]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://atlas.centrum.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
TCP: DhcpNameServer = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Nektra OEAPI - (no file)
HKCU-Run-WEBTRAN - (no file)
AddRemove-Creative Installer Setup - c:\program files\Creative\Uninstall\Installer.isu
AddRemove-Creative MiniDisc Center - c:\program files\Creative\Audio\PlayCenter\MDC.isu
AddRemove-Creative Mixer - c:\program files\Creative\Audio\CTMixer.isu
AddRemove-Creative Recorder - c:\program files\Creative\Audio\Recorder\Recorder.isu
AddRemove-Creative WaveStudio - c:\program files\Creative\Audio\WaveStudio\Wstudio.isu
AddRemove-Midi Samples - c:\program files\Creative\Audio\Midi.isu
AddRemove-PC Translator - c:\docume~1\Masek\LOCALS~1\Temp\UN32.EXE
AddRemove-PlayCenter - c:\program files\Creative\Audio\PlayCenter\Player.isu
AddRemove-Sound Blaster PCI128 Drivers Online Help - c:\program files\CREATIVE\AUDIO\HELP\SBPCIDRV.isu
AddRemove-{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA} - c:\program files\InstallShield Installation Information\{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}\Setup.exeUNINSTALL
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-19 23:37
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(940)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2704)
c:\documents and settings\All Users\Data aplikací\LangSoft\TrnOEH.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\CTSvcCDA.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
.
**************************************************************************
.
Celkový čas: 2011-11-19 23:40:46 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-11-19 22:40
.
Před spuštěním: Volných bajtů: 65 952 681 984
Po spuštění: Volných bajtů: 67 765 506 048
.
- - End Of File - - 25AC15A771DFA1FC2C670C10D2764018

----------------------------------

23:59:25.0296 0432 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
23:59:25.0328 0432 ============================================================
23:59:25.0328 0432 Current date / time: 2011/11/19 23:59:25.0328
23:59:25.0328 0432 SystemInfo:
23:59:25.0328 0432
23:59:25.0328 0432 OS Version: 5.1.2600 ServicePack: 3.0
23:59:25.0328 0432 Product type: Workstation
23:59:25.0328 0432 ComputerName: PC-MASEK
23:59:25.0328 0432 UserName: Masek
23:59:25.0328 0432 Windows directory: C:\WINDOWS
23:59:25.0328 0432 System windows directory: C:\WINDOWS
23:59:25.0328 0432 Processor architecture: Intel x86
23:59:25.0328 0432 Number of processors: 1
23:59:25.0328 0432 Page size: 0x1000
23:59:25.0328 0432 Boot type: Normal boot
23:59:25.0328 0432 ============================================================
23:59:25.0640 0432 Initialize success
23:59:46.0781 0872 ============================================================
23:59:46.0781 0872 Scan started
23:59:46.0781 0872 Mode: Manual;
23:59:46.0781 0872 ============================================================
23:59:47.0093 0872 Abiosdsk - ok
23:59:47.0140 0872 abp480n5 - ok
23:59:47.0203 0872 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:59:47.0203 0872 ACPI - ok
23:59:47.0281 0872 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
23:59:47.0281 0872 ACPIEC - ok
23:59:47.0328 0872 adpu160m - ok
23:59:47.0421 0872 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
23:59:47.0421 0872 aec - ok
23:59:47.0500 0872 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
23:59:47.0515 0872 AFD - ok
23:59:47.0562 0872 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
23:59:47.0562 0872 agp440 - ok
23:59:47.0609 0872 Aha154x - ok
23:59:47.0656 0872 aic78u2 - ok
23:59:47.0687 0872 aic78xx - ok
23:59:47.0750 0872 AliIde - ok
23:59:47.0796 0872 amsint - ok
23:59:47.0843 0872 asc - ok
23:59:47.0890 0872 asc3350p - ok
23:59:47.0921 0872 asc3550 - ok
23:59:48.0000 0872 ASNDIS5 (05a56c3156e1b6cc7bbd8e1d54d491f2) C:\WINDOWS\system32\ASNDIS5.SYS
23:59:48.0000 0872 ASNDIS5 - ok
23:59:48.0109 0872 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:59:48.0109 0872 AsyncMac - ok
23:59:48.0171 0872 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
23:59:48.0171 0872 atapi - ok
23:59:48.0218 0872 Atdisk - ok
23:59:48.0343 0872 ati2mtag (4938ad74de9088f70922fabf86912eee) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
23:59:48.0343 0872 ati2mtag - ok
23:59:48.0437 0872 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:59:48.0437 0872 Atmarpc - ok
23:59:48.0546 0872 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
23:59:48.0546 0872 audstub - ok
23:59:48.0625 0872 bcm4sbxp (ba03a18635d4b0830c9262cd80d4026b) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
23:59:48.0625 0872 bcm4sbxp - ok
23:59:48.0703 0872 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
23:59:48.0703 0872 Beep - ok
23:59:48.0734 0872 catchme - ok
23:59:48.0781 0872 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
23:59:48.0781 0872 cbidf2k - ok
23:59:48.0859 0872 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
23:59:48.0859 0872 CCDECODE - ok
23:59:48.0921 0872 cd20xrnt - ok
23:59:48.0953 0872 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
23:59:48.0953 0872 Cdaudio - ok
23:59:49.0000 0872 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
23:59:49.0000 0872 Cdfs - ok
23:59:49.0046 0872 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:59:49.0046 0872 Cdrom - ok
23:59:49.0093 0872 Changer - ok
23:59:49.0171 0872 CmdIde - ok
23:59:49.0234 0872 Cpqarray - ok
23:59:49.0296 0872 dac2w2k - ok
23:59:49.0343 0872 dac960nt - ok
23:59:49.0437 0872 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
23:59:49.0437 0872 Disk - ok
23:59:49.0531 0872 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
23:59:49.0578 0872 dmboot - ok
23:59:49.0625 0872 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
23:59:49.0625 0872 dmio - ok
23:59:49.0703 0872 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
23:59:49.0703 0872 dmload - ok
23:59:49.0765 0872 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
23:59:49.0781 0872 DMusic - ok
23:59:49.0828 0872 dpti2o - ok
23:59:49.0875 0872 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
23:59:49.0875 0872 drmkaud - ok
23:59:49.0968 0872 DynCal (1d995cf2789e2844fc538c540e8563de) C:\WINDOWS\system32\drivers\Dyncal.sys
23:59:49.0968 0872 DynCal - ok
23:59:50.0062 0872 eamon (9309c5c9831203436e64cf2ae605c5d7) C:\WINDOWS\system32\DRIVERS\eamon.sys
23:59:50.0062 0872 eamon - ok
23:59:50.0156 0872 ehdrv (deff87f04ab5f6dd5edf2b80853bbe10) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
23:59:50.0156 0872 ehdrv - ok
23:59:50.0234 0872 epfw (5ba193ca0ae31209aaa39939ce6736b2) C:\WINDOWS\system32\DRIVERS\epfw.sys
23:59:50.0234 0872 epfw - ok
23:59:50.0296 0872 Epfwndis (75d3bcd3e0eded0ab0f96d9a10ff01c9) C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
23:59:50.0296 0872 Epfwndis - ok
23:59:50.0375 0872 epfwtdi (dc64f26f35e32c9472bbf8acd84060d3) C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
23:59:50.0375 0872 epfwtdi - ok
23:59:50.0453 0872 epfwtdir - ok
23:59:50.0562 0872 es1371 (a55dd7d8ced5d2624a9ee2dda7be0319) C:\WINDOWS\system32\drivers\es1371mp.sys
23:59:50.0562 0872 es1371 - ok
23:59:50.0640 0872 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
23:59:50.0656 0872 Fastfat - ok
23:59:50.0718 0872 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
23:59:50.0718 0872 Fdc - ok
23:59:50.0765 0872 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
23:59:50.0765 0872 Fips - ok
23:59:50.0828 0872 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:59:50.0828 0872 Flpydisk - ok
23:59:50.0875 0872 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
23:59:50.0875 0872 FltMgr - ok
23:59:50.0921 0872 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:59:50.0921 0872 Fs_Rec - ok
23:59:51.0000 0872 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:59:51.0000 0872 Ftdisk - ok
23:59:51.0062 0872 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
23:59:51.0062 0872 gameenum - ok
23:59:51.0109 0872 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:59:51.0109 0872 Gpc - ok
23:59:51.0203 0872 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:59:51.0203 0872 HidUsb - ok
23:59:51.0281 0872 hpn - ok
23:59:51.0359 0872 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
23:59:51.0375 0872 HTTP - ok
23:59:51.0437 0872 i2omgmt - ok
23:59:51.0484 0872 i2omp - ok
23:59:51.0531 0872 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:59:51.0531 0872 i8042prt - ok
23:59:51.0593 0872 IdeBusDr (4ec233ef7c2a2c36fa962de2ae5d982a) C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys
23:59:51.0593 0872 IdeBusDr - ok
23:59:51.0656 0872 IdeChnDr (e1b24e6478ab2e5e09c21d2028e2f208) C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys
23:59:51.0671 0872 IdeChnDr - ok
23:59:51.0734 0872 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
23:59:51.0734 0872 Imapi - ok
23:59:51.0796 0872 ini910u - ok
23:59:51.0843 0872 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
23:59:51.0859 0872 IntelIde - ok
23:59:51.0921 0872 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:59:51.0921 0872 intelppm - ok
23:59:51.0984 0872 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
23:59:51.0984 0872 Ip6Fw - ok
23:59:52.0062 0872 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:59:52.0062 0872 IpFilterDriver - ok
23:59:52.0125 0872 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:59:52.0125 0872 IpInIp - ok
23:59:52.0187 0872 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:59:52.0203 0872 IpNat - ok
23:59:52.0250 0872 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:59:52.0250 0872 IPSec - ok
23:59:52.0312 0872 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
23:59:52.0312 0872 IRENUM - ok
23:59:52.0406 0872 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:59:52.0421 0872 isapnp - ok
23:59:52.0484 0872 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:59:52.0484 0872 Kbdclass - ok
23:59:52.0546 0872 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
23:59:52.0546 0872 kmixer - ok
23:59:52.0609 0872 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
23:59:52.0609 0872 KSecDD - ok
23:59:52.0687 0872 lbrtfdc - ok
23:59:52.0750 0872 MBAMSwissArmy - ok
23:59:52.0828 0872 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
23:59:52.0843 0872 mnmdd - ok
23:59:52.0906 0872 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
23:59:52.0906 0872 Modem - ok
23:59:52.0968 0872 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:59:52.0968 0872 Mouclass - ok
23:59:53.0015 0872 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
23:59:53.0015 0872 MountMgr - ok
23:59:53.0125 0872 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys
23:59:53.0125 0872 MPE - ok
23:59:53.0203 0872 mraid35x - ok
23:59:53.0281 0872 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:59:53.0296 0872 MRxDAV - ok
23:59:53.0390 0872 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:59:53.0406 0872 MRxSmb - ok
23:59:53.0468 0872 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
23:59:53.0468 0872 Msfs - ok
23:59:53.0562 0872 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:59:53.0562 0872 MSKSSRV - ok
23:59:53.0609 0872 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:59:53.0609 0872 MSPCLOCK - ok
23:59:53.0671 0872 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
23:59:53.0671 0872 MSPQM - ok
23:59:53.0734 0872 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:59:53.0734 0872 mssmbios - ok
23:59:53.0781 0872 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
23:59:53.0781 0872 MSTEE - ok
23:59:53.0859 0872 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
23:59:53.0859 0872 Mup - ok
23:59:53.0937 0872 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
23:59:53.0937 0872 NABTSFEC - ok
23:59:54.0015 0872 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
23:59:54.0015 0872 NDIS - ok
23:59:54.0078 0872 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
23:59:54.0078 0872 NdisIP - ok
23:59:54.0156 0872 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:59:54.0156 0872 NdisTapi - ok
23:59:54.0203 0872 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:59:54.0203 0872 Ndisuio - ok
23:59:54.0250 0872 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:59:54.0250 0872 NdisWan - ok
23:59:54.0328 0872 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
23:59:54.0328 0872 NDProxy - ok
23:59:54.0375 0872 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
23:59:54.0375 0872 NetBIOS - ok
23:59:54.0453 0872 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
23:59:54.0453 0872 NetBT - ok
23:59:54.0562 0872 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\WINDOWS\system32\drivers\ccdcmb.sys
23:59:54.0578 0872 nmwcd - ok
23:59:54.0656 0872 nmwcdnsu (28d40797bcb050321fa6674b08a620c0) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
23:59:54.0671 0872 nmwcdnsu - ok
23:59:54.0718 0872 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
23:59:54.0734 0872 Npfs - ok
23:59:54.0781 0872 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
23:59:54.0796 0872 Ntfs - ok
23:59:54.0859 0872 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
23:59:54.0859 0872 Null - ok
23:59:54.0937 0872 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:59:54.0937 0872 NwlnkFlt - ok
23:59:55.0015 0872 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:59:55.0015 0872 NwlnkFwd - ok
23:59:55.0078 0872 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
23:59:55.0093 0872 Parport - ok
23:59:55.0140 0872 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
23:59:55.0140 0872 PartMgr - ok
23:59:55.0218 0872 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
23:59:55.0218 0872 ParVdm - ok
23:59:55.0296 0872 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
23:59:55.0296 0872 pccsmcfd - ok
23:59:55.0359 0872 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
23:59:55.0359 0872 PCI - ok
23:59:55.0406 0872 PCIDump - ok
23:59:55.0484 0872 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
23:59:55.0484 0872 PCIIde - ok
23:59:55.0562 0872 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
23:59:55.0562 0872 Pcmcia - ok
23:59:55.0640 0872 pctvvbi (eb7de8f91803f267e899f87197731664) C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
23:59:55.0640 0872 pctvvbi - ok
23:59:55.0687 0872 PDCOMP - ok
23:59:55.0734 0872 PDFRAME - ok
23:59:55.0781 0872 PDRELI - ok
23:59:55.0812 0872 PDRFRAME - ok
23:59:55.0859 0872 perc2 - ok
23:59:55.0906 0872 perc2hib - ok
23:59:56.0000 0872 PfModNT (b293f05ad9120b0232c28945c1e98cd0) C:\WINDOWS\system32\PfModNT.sys
23:59:56.0000 0872 PfModNT - ok
23:59:56.0078 0872 PinnacleRoyalTS (48b06eca2c2f036eb3912d816ee5941b) C:\WINDOWS\system32\DRIVERS\RoyalTS.sys
23:59:56.0078 0872 PinnacleRoyalTS - ok
23:59:56.0171 0872 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:59:56.0187 0872 PptpMiniport - ok
23:59:56.0250 0872 prodrv06 (e36105ef413861f562eb507d4f5d4744) C:\WINDOWS\System32\drivers\prodrv06.sys
23:59:56.0265 0872 prodrv06 ( Rootkit.Win32.ZAccess.k ) - infected
23:59:56.0265 0872 prodrv06 - detected Rootkit.Win32.ZAccess.k (0)
23:59:56.0328 0872 prohlp02 (2409b32e691cb5dda39ea40bd154a50b) C:\WINDOWS\system32\drivers\prohlp02.sys
23:59:56.0328 0872 prohlp02 - ok
23:59:56.0375 0872 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
23:59:56.0375 0872 PSched - ok
23:59:56.0437 0872 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:59:56.0437 0872 Ptilink - ok
23:59:56.0531 0872 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
23:59:56.0531 0872 PxHelp20 - ok
23:59:56.0578 0872 ql1080 - ok
23:59:56.0625 0872 Ql10wnt - ok
23:59:56.0671 0872 ql12160 - ok
23:59:56.0718 0872 ql1240 - ok
23:59:56.0765 0872 ql1280 - ok
23:59:56.0796 0872 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:59:56.0796 0872 RasAcd - ok
23:59:56.0859 0872 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:59:56.0859 0872 Rasl2tp - ok
23:59:56.0921 0872 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:59:56.0921 0872 RasPppoe - ok
23:59:56.0968 0872 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
23:59:56.0968 0872 Raspti - ok
23:59:57.0031 0872 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:59:57.0031 0872 Rdbss - ok
23:59:57.0078 0872 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:59:57.0078 0872 RDPCDD - ok
23:59:57.0187 0872 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
23:59:57.0187 0872 RDPWD - ok
23:59:57.0250 0872 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
23:59:57.0250 0872 redbook - ok
23:59:57.0359 0872 SBKUPNT (729248b54aff21e740054acebfdbcb1c) C:\WINDOWS\system32\Drivers\SBKUPNT.SYS
23:59:57.0375 0872 SBKUPNT - ok
23:59:57.0500 0872 sbpci (51e16b053ee28fd309beac5722bcc735) C:\WINDOWS\system32\drivers\sbpci.sys
23:59:57.0531 0872 sbpci - ok
23:59:57.0625 0872 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:59:57.0625 0872 Secdrv - ok
23:59:57.0687 0872 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
23:59:57.0687 0872 serenum - ok
23:59:57.0734 0872 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
23:59:57.0734 0872 Serial - ok
23:59:57.0828 0872 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
23:59:57.0828 0872 sfhlp01 - ok
23:59:57.0890 0872 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
23:59:57.0890 0872 Sfloppy - ok
23:59:57.0953 0872 Simbad - ok
23:59:58.0031 0872 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
23:59:58.0031 0872 SLIP - ok
23:59:58.0093 0872 Sparrow - ok
23:59:58.0171 0872 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
23:59:58.0171 0872 splitter - ok
23:59:58.0234 0872 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
23:59:58.0234 0872 sr - ok
23:59:58.0328 0872 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
23:59:58.0328 0872 Srv - ok
23:59:58.0406 0872 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
23:59:58.0406 0872 streamip - ok
23:59:58.0500 0872 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
23:59:58.0500 0872 swenum - ok
23:59:58.0546 0872 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
23:59:58.0546 0872 swmidi - ok
23:59:58.0609 0872 symc810 - ok
23:59:58.0656 0872 symc8xx - ok
23:59:58.0703 0872 sym_hi - ok
23:59:58.0750 0872 sym_u3 - ok
23:59:58.0812 0872 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
23:59:58.0812 0872 sysaudio - ok
23:59:58.0921 0872 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:59:58.0921 0872 Tcpip - ok
23:59:58.0984 0872 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
23:59:58.0984 0872 TDPIPE - ok
23:59:59.0031 0872 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
23:59:59.0046 0872 TDTCP - ok
23:59:59.0093 0872 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
23:59:59.0109 0872 TermDD - ok
23:59:59.0171 0872 TosIde - ok
23:59:59.0234 0872 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
23:59:59.0234 0872 Udfs - ok
23:59:59.0281 0872 ultra - ok
23:59:59.0343 0872 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
23:59:59.0359 0872 Update - ok
23:59:59.0453 0872 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:59:59.0453 0872 usbehci - ok
23:59:59.0500 0872 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:59:59.0500 0872 usbhub - ok
23:59:59.0546 0872 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
23:59:59.0546 0872 usbprint - ok
23:59:59.0625 0872 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:59:59.0625 0872 usbscan - ok
23:59:59.0703 0872 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:59:59.0703 0872 USBSTOR - ok
23:59:59.0765 0872 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
23:59:59.0765 0872 usbuhci - ok
23:59:59.0812 0872 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
23:59:59.0828 0872 VgaSave - ok
23:59:59.0875 0872 ViaIde - ok
23:59:59.0953 0872 viamraid (1b7b0954af54e716f697c511d68c150e) C:\WINDOWS\system32\DRIVERS\viamraid.sys
23:59:59.0953 0872 viamraid - ok
00:00:00.0000 0872 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
00:00:00.0000 0872 VolSnap - ok
00:00:00.0078 0872 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
00:00:00.0078 0872 Wanarp - ok
00:00:00.0171 0872 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
00:00:00.0203 0872 Wdf01000 - ok
00:00:00.0250 0872 WDICA - ok
00:00:00.0312 0872 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
00:00:00.0312 0872 wdmaud - ok
00:00:00.0515 0872 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
00:00:00.0515 0872 WpdUsb - ok
00:00:00.0593 0872 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
00:00:00.0609 0872 WSTCODEC - ok
00:00:00.0687 0872 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
00:00:00.0687 0872 WudfPf - ok
00:00:00.0750 0872 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
00:00:00.0750 0872 WudfRd - ok
00:00:00.0812 0872 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
00:00:00.0890 0872 \Device\Harddisk0\DR0 - ok
00:00:00.0921 0872 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
00:00:00.0937 0872 \Device\Harddisk1\DR1 - ok
00:00:00.0953 0872 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk2\DR4
00:00:06.0453 0872 \Device\Harddisk2\DR4 - ok
00:00:06.0468 0872 Boot (0x1200) (a03f13b6a216f46a3c7cc14b713c0fd7) \Device\Harddisk0\DR0\Partition0
00:00:06.0468 0872 \Device\Harddisk0\DR0\Partition0 - ok
00:00:06.0500 0872 Boot (0x1200) (01a71f063ee417857c05301a8700204c) \Device\Harddisk1\DR1\Partition0
00:00:06.0500 0872 \Device\Harddisk1\DR1\Partition0 - ok
00:00:06.0515 0872 Boot (0x1200) (3d517f70feca5ca6d06ea428822e4958) \Device\Harddisk2\DR4\Partition0
00:00:06.0515 0872 \Device\Harddisk2\DR4\Partition0 - ok
00:00:06.0515 0872 ============================================================
00:00:06.0515 0872 Scan finished
00:00:06.0515 0872 ============================================================
00:00:06.0546 0824 Detected object count: 1
00:00:06.0546 0824 Actual detected object count: 1
00:01:50.0296 0824 prodrv06 ( Rootkit.Win32.ZAccess.k ) - skipped by user
00:01:50.0296 0824 prodrv06 ( Rootkit.Win32.ZAccess.k ) - User select action: Skip
00:04:33.0031 1788 Deinitialize success

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 10:36
od e_mysak
Omlouvám se za to nedopatření s CF.Vypnul jsem u Esetu veškerou ochranu a vytáhl kabík z modemu.CF pa žádal o připojení ale když jsem vrátil kablík zpět tak PC hledal adresu a asi se to potom nesešlo,takže CF pokračoval dál.
Spustil jsem TD, vypsal tabulku s 9 problémy (PC od včera až do předchvíle nebylo zapnuté) a mezitím byl řádek s "prodrv6" to jediné mělo již nastaveno Cure,potvdil jsem a posílám výpis.

10:14:04.0171 2024 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
10:14:04.0437 2024 ============================================================
10:14:04.0437 2024 Current date / time: 2011/11/20 10:14:04.0437
10:14:04.0437 2024 SystemInfo:
10:14:04.0437 2024
10:14:04.0437 2024 OS Version: 5.1.2600 ServicePack: 3.0
10:14:04.0437 2024 Product type: Workstation
10:14:04.0437 2024 ComputerName: PC-MASEK
10:14:04.0437 2024 UserName: Masek
10:14:04.0437 2024 Windows directory: C:\WINDOWS
10:14:04.0437 2024 System windows directory: C:\WINDOWS
10:14:04.0437 2024 Processor architecture: Intel x86
10:14:04.0437 2024 Number of processors: 1
10:14:04.0437 2024 Page size: 0x1000
10:14:04.0437 2024 Boot type: Normal boot
10:14:04.0437 2024 ============================================================
10:14:04.0828 2024 Initialize success
10:14:46.0609 3116 ============================================================
10:14:46.0609 3116 Scan started
10:14:46.0609 3116 Mode: Manual; SigCheck; TDLFS;
10:14:46.0609 3116 ============================================================
10:14:46.0765 3116 Abiosdsk - ok
10:14:46.0812 3116 abp480n5 - ok
10:14:46.0875 3116 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:14:47.0843 3116 ACPI - ok
10:14:47.0953 3116 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
10:14:48.0171 3116 ACPIEC - ok
10:14:48.0218 3116 adpu160m - ok
10:14:48.0296 3116 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
10:14:48.0562 3116 aec - ok
10:14:48.0640 3116 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
10:14:48.0734 3116 AFD - ok
10:14:48.0796 3116 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
10:14:49.0046 3116 agp440 - ok
10:14:49.0093 3116 Aha154x - ok
10:14:49.0140 3116 aic78u2 - ok
10:14:49.0187 3116 aic78xx - ok
10:14:49.0250 3116 AliIde - ok
10:14:49.0281 3116 amsint - ok
10:14:49.0328 3116 asc - ok
10:14:49.0375 3116 asc3350p - ok
10:14:49.0421 3116 asc3550 - ok
10:14:49.0484 3116 ASNDIS5 (05a56c3156e1b6cc7bbd8e1d54d491f2) C:\WINDOWS\system32\ASNDIS5.SYS
10:14:49.0515 3116 ASNDIS5 ( UnsignedFile.Multi.Generic ) - warning
10:14:49.0515 3116 ASNDIS5 - detected UnsignedFile.Multi.Generic (1)
10:14:49.0593 3116 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:14:49.0828 3116 AsyncMac - ok
10:14:49.0875 3116 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:14:50.0093 3116 atapi - ok
10:14:50.0125 3116 Atdisk - ok
10:14:50.0234 3116 ati2mtag (4938ad74de9088f70922fabf86912eee) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
10:14:50.0390 3116 ati2mtag - ok
10:14:50.0437 3116 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:14:50.0671 3116 Atmarpc - ok
10:14:50.0765 3116 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:14:50.0984 3116 audstub - ok
10:14:51.0062 3116 bcm4sbxp (ba03a18635d4b0830c9262cd80d4026b) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
10:14:51.0093 3116 bcm4sbxp - ok
10:14:51.0187 3116 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:14:51.0421 3116 Beep - ok
10:14:51.0453 3116 catchme - ok
10:14:51.0500 3116 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:14:51.0718 3116 cbidf2k - ok
10:14:51.0796 3116 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:14:52.0062 3116 CCDECODE - ok
10:14:52.0125 3116 cd20xrnt - ok
10:14:52.0171 3116 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:14:52.0421 3116 Cdaudio - ok
10:14:52.0468 3116 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
10:14:52.0703 3116 Cdfs - ok
10:14:52.0765 3116 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:14:53.0046 3116 Cdrom - ok
10:14:53.0093 3116 Changer - ok
10:14:53.0187 3116 CmdIde - ok
10:14:53.0250 3116 Cpqarray - ok
10:14:53.0312 3116 dac2w2k - ok
10:14:53.0343 3116 dac960nt - ok
10:14:53.0453 3116 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
10:14:53.0687 3116 Disk - ok
10:14:53.0765 3116 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
10:14:54.0140 3116 dmboot - ok
10:14:54.0187 3116 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
10:14:54.0453 3116 dmio - ok
10:14:54.0500 3116 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:14:54.0750 3116 dmload - ok
10:14:54.0796 3116 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
10:14:55.0031 3116 DMusic - ok
10:14:55.0078 3116 dpti2o - ok
10:14:55.0125 3116 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
10:14:55.0343 3116 drmkaud - ok
10:14:55.0453 3116 DynCal (1d995cf2789e2844fc538c540e8563de) C:\WINDOWS\system32\drivers\Dyncal.sys
10:14:55.0531 3116 DynCal ( UnsignedFile.Multi.Generic ) - warning
10:14:55.0531 3116 DynCal - detected UnsignedFile.Multi.Generic (1)
10:14:55.0609 3116 eamon (9309c5c9831203436e64cf2ae605c5d7) C:\WINDOWS\system32\DRIVERS\eamon.sys
10:14:55.0812 3116 eamon - ok
10:14:55.0906 3116 ehdrv (deff87f04ab5f6dd5edf2b80853bbe10) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
10:14:55.0937 3116 ehdrv - ok
10:14:56.0015 3116 epfw (5ba193ca0ae31209aaa39939ce6736b2) C:\WINDOWS\system32\DRIVERS\epfw.sys
10:14:56.0062 3116 epfw - ok
10:14:56.0125 3116 Epfwndis (75d3bcd3e0eded0ab0f96d9a10ff01c9) C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
10:14:57.0343 3116 Epfwndis - ok
10:14:57.0468 3116 epfwtdi (dc64f26f35e32c9472bbf8acd84060d3) C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
10:14:57.0546 3116 epfwtdi - ok
10:14:57.0593 3116 epfwtdir - ok
10:14:57.0718 3116 es1371 (a55dd7d8ced5d2624a9ee2dda7be0319) C:\WINDOWS\system32\drivers\es1371mp.sys
10:14:57.0968 3116 es1371 - ok
10:14:58.0109 3116 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
10:14:58.0343 3116 Fastfat - ok
10:14:58.0421 3116 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
10:14:58.0687 3116 Fdc - ok
10:14:58.0750 3116 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
10:14:58.0968 3116 Fips - ok
10:14:59.0015 3116 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:14:59.0250 3116 Flpydisk - ok
10:14:59.0359 3116 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
10:14:59.0656 3116 FltMgr - ok
10:14:59.0718 3116 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:14:59.0937 3116 Fs_Rec - ok
10:15:00.0000 3116 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:15:00.0234 3116 Ftdisk - ok
10:15:00.0296 3116 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
10:15:00.0531 3116 gameenum - ok
10:15:00.0578 3116 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:15:00.0796 3116 Gpc - ok
10:15:00.0906 3116 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:15:01.0171 3116 HidUsb - ok
10:15:01.0218 3116 hpn - ok
10:15:01.0312 3116 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
10:15:01.0421 3116 HTTP - ok
10:15:01.0468 3116 i2omgmt - ok
10:15:01.0500 3116 i2omp - ok
10:15:01.0562 3116 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:15:01.0781 3116 i8042prt - ok
10:15:01.0875 3116 IdeBusDr (4ec233ef7c2a2c36fa962de2ae5d982a) C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys
10:15:01.0906 3116 IdeBusDr - ok
10:15:01.0968 3116 IdeChnDr (e1b24e6478ab2e5e09c21d2028e2f208) C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys
10:15:01.0984 3116 IdeChnDr - ok
10:15:02.0046 3116 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:15:02.0281 3116 Imapi - ok
10:15:02.0328 3116 ini910u - ok
10:15:02.0375 3116 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
10:15:02.0578 3116 IntelIde - ok
10:15:02.0656 3116 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:15:02.0890 3116 intelppm - ok
10:15:02.0953 3116 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
10:15:03.0156 3116 Ip6Fw - ok
10:15:03.0265 3116 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:15:03.0515 3116 IpFilterDriver - ok
10:15:03.0578 3116 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:15:03.0796 3116 IpInIp - ok
10:15:03.0859 3116 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:15:04.0078 3116 IpNat - ok
10:15:04.0140 3116 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:15:04.0390 3116 IPSec - ok
10:15:04.0437 3116 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:15:04.0578 3116 IRENUM - ok
10:15:04.0625 3116 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:15:04.0859 3116 isapnp - ok
10:15:04.0921 3116 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:15:05.0140 3116 Kbdclass - ok
10:15:05.0203 3116 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
10:15:05.0468 3116 kmixer - ok
10:15:05.0593 3116 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
10:15:05.0687 3116 KSecDD - ok
10:15:05.0765 3116 lbrtfdc - ok
10:15:05.0875 3116 MBAMSwissArmy - ok
10:15:06.0000 3116 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:15:06.0250 3116 mnmdd - ok
10:15:06.0296 3116 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
10:15:06.0562 3116 Modem - ok
10:15:06.0625 3116 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:15:06.0843 3116 Mouclass - ok
10:15:06.0921 3116 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
10:15:07.0140 3116 MountMgr - ok
10:15:07.0218 3116 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys
10:15:07.0453 3116 MPE - ok
10:15:07.0500 3116 mraid35x - ok
10:15:07.0546 3116 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:15:07.0765 3116 MRxDAV - ok
10:15:07.0859 3116 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:15:08.0031 3116 MRxSmb - ok
10:15:08.0093 3116 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
10:15:08.0343 3116 Msfs - ok
10:15:08.0421 3116 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:15:08.0625 3116 MSKSSRV - ok
10:15:08.0671 3116 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:15:08.0921 3116 MSPCLOCK - ok
10:15:08.0968 3116 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
10:15:09.0187 3116 MSPQM - ok
10:15:09.0234 3116 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:15:09.0453 3116 mssmbios - ok
10:15:09.0515 3116 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
10:15:09.0750 3116 MSTEE - ok
10:15:09.0828 3116 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
10:15:09.0906 3116 Mup - ok
10:15:09.0953 3116 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:15:10.0203 3116 NABTSFEC - ok
10:15:10.0265 3116 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
10:15:10.0515 3116 NDIS - ok
10:15:10.0562 3116 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:15:10.0796 3116 NdisIP - ok
10:15:10.0875 3116 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:15:10.0953 3116 NdisTapi - ok
10:15:11.0031 3116 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:15:11.0234 3116 Ndisuio - ok
10:15:11.0296 3116 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:15:11.0500 3116 NdisWan - ok
10:15:11.0562 3116 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
10:15:11.0625 3116 NDProxy - ok
10:15:11.0671 3116 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:15:11.0921 3116 NetBIOS - ok
10:15:11.0968 3116 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:15:12.0171 3116 NetBT - ok
10:15:12.0281 3116 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\WINDOWS\system32\drivers\ccdcmb.sys
10:15:12.0625 3116 nmwcd - ok
10:15:12.0750 3116 nmwcdnsu (28d40797bcb050321fa6674b08a620c0) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
10:15:12.0875 3116 nmwcdnsu - ok
10:15:12.0953 3116 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
10:15:13.0187 3116 Npfs - ok
10:15:13.0281 3116 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
10:15:13.0578 3116 Ntfs - ok
10:15:13.0640 3116 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:15:13.0875 3116 Null - ok
10:15:14.0015 3116 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:15:14.0281 3116 NwlnkFlt - ok
10:15:14.0359 3116 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:15:14.0625 3116 NwlnkFwd - ok
10:15:14.0781 3116 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
10:15:15.0015 3116 Parport - ok
10:15:15.0078 3116 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
10:15:15.0296 3116 PartMgr - ok
10:15:15.0375 3116 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
10:15:16.0125 3116 ParVdm - ok
10:15:16.0218 3116 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
10:15:16.0328 3116 pccsmcfd - ok
10:15:16.0421 3116 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
10:15:16.0656 3116 PCI - ok
10:15:16.0703 3116 PCIDump - ok
10:15:16.0781 3116 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:15:17.0000 3116 PCIIde - ok
10:15:17.0093 3116 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
10:15:17.0859 3116 Pcmcia - ok
10:15:17.0953 3116 pctvvbi (eb7de8f91803f267e899f87197731664) C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
10:15:17.0968 3116 pctvvbi ( UnsignedFile.Multi.Generic ) - warning
10:15:17.0968 3116 pctvvbi - detected UnsignedFile.Multi.Generic (1)
10:15:18.0015 3116 PDCOMP - ok
10:15:18.0062 3116 PDFRAME - ok
10:15:18.0125 3116 PDRELI - ok
10:15:18.0171 3116 PDRFRAME - ok
10:15:18.0218 3116 perc2 - ok
10:15:18.0265 3116 perc2hib - ok
10:15:18.0375 3116 PfModNT (b293f05ad9120b0232c28945c1e98cd0) C:\WINDOWS\system32\PfModNT.sys
10:15:18.0484 3116 PfModNT ( UnsignedFile.Multi.Generic ) - warning
10:15:18.0484 3116 PfModNT - detected UnsignedFile.Multi.Generic (1)
10:15:18.0578 3116 PinnacleRoyalTS (48b06eca2c2f036eb3912d816ee5941b) C:\WINDOWS\system32\DRIVERS\RoyalTS.sys
10:15:18.0703 3116 PinnacleRoyalTS - ok
10:15:18.0812 3116 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:15:19.0031 3116 PptpMiniport - ok
10:15:19.0109 3116 prodrv06 (e36105ef413861f562eb507d4f5d4744) C:\WINDOWS\System32\drivers\prodrv06.sys
10:15:19.0156 3116 prodrv06 ( Rootkit.Win32.ZAccess.k ) - infected
10:15:19.0156 3116 prodrv06 - detected Rootkit.Win32.ZAccess.k (0)
10:15:19.0234 3116 prohlp02 (2409b32e691cb5dda39ea40bd154a50b) C:\WINDOWS\system32\drivers\prohlp02.sys
10:15:19.0296 3116 prohlp02 ( UnsignedFile.Multi.Generic ) - warning
10:15:19.0296 3116 prohlp02 - detected UnsignedFile.Multi.Generic (1)
10:15:19.0343 3116 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
10:15:19.0546 3116 PSched - ok
10:15:19.0593 3116 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:15:19.0843 3116 Ptilink - ok
10:15:19.0906 3116 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:15:19.0937 3116 PxHelp20 - ok
10:15:19.0968 3116 ql1080 - ok
10:15:20.0000 3116 Ql10wnt - ok
10:15:20.0046 3116 ql12160 - ok
10:15:20.0078 3116 ql1240 - ok
10:15:20.0109 3116 ql1280 - ok
10:15:20.0171 3116 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:15:20.0359 3116 RasAcd - ok
10:15:20.0437 3116 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:15:20.0656 3116 Rasl2tp - ok
10:15:20.0765 3116 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:15:21.0000 3116 RasPppoe - ok
10:15:21.0046 3116 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:15:21.0250 3116 Raspti - ok
10:15:21.0312 3116 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:15:21.0546 3116 Rdbss - ok
10:15:21.0625 3116 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:15:21.0859 3116 RDPCDD - ok
10:15:21.0953 3116 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
10:15:22.0031 3116 RDPWD - ok
10:15:22.0078 3116 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:15:22.0281 3116 redbook - ok
10:15:22.0390 3116 SBKUPNT (729248b54aff21e740054acebfdbcb1c) C:\WINDOWS\system32\Drivers\SBKUPNT.SYS
10:15:22.0421 3116 SBKUPNT ( UnsignedFile.Multi.Generic ) - warning
10:15:22.0421 3116 SBKUPNT - detected UnsignedFile.Multi.Generic (1)
10:15:22.0531 3116 sbpci (51e16b053ee28fd309beac5722bcc735) C:\WINDOWS\system32\drivers\sbpci.sys
10:15:22.0640 3116 sbpci ( UnsignedFile.Multi.Generic ) - warning
10:15:22.0640 3116 sbpci - detected UnsignedFile.Multi.Generic (1)
10:15:22.0750 3116 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:15:22.0859 3116 Secdrv - ok
10:15:22.0921 3116 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:15:23.0156 3116 serenum - ok
10:15:23.0203 3116 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
10:15:23.0421 3116 Serial - ok
10:15:23.0515 3116 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
10:15:23.0562 3116 sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
10:15:23.0562 3116 sfhlp01 - detected UnsignedFile.Multi.Generic (1)
10:15:23.0609 3116 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:15:23.0828 3116 Sfloppy - ok
10:15:23.0890 3116 Simbad - ok
10:15:23.0953 3116 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:15:24.0171 3116 SLIP - ok
10:15:24.0218 3116 Sparrow - ok
10:15:24.0265 3116 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
10:15:24.0515 3116 splitter - ok
10:15:24.0578 3116 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
10:15:24.0671 3116 sr - ok
10:15:24.0781 3116 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
10:15:24.0890 3116 Srv - ok
10:15:24.0968 3116 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:15:25.0218 3116 streamip - ok
10:15:25.0265 3116 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:15:25.0468 3116 swenum - ok
10:15:25.0531 3116 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
10:15:25.0750 3116 swmidi - ok
10:15:25.0812 3116 symc810 - ok
10:15:25.0859 3116 symc8xx - ok
10:15:25.0906 3116 sym_hi - ok
10:15:25.0968 3116 sym_u3 - ok
10:15:26.0031 3116 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
10:15:26.0234 3116 sysaudio - ok
10:15:26.0328 3116 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:15:26.0437 3116 Tcpip - ok
10:15:26.0500 3116 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:15:26.0734 3116 TDPIPE - ok
10:15:26.0828 3116 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
10:15:27.0031 3116 TDTCP - ok
10:15:27.0078 3116 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:15:27.0281 3116 TermDD - ok
10:15:27.0343 3116 TosIde - ok
10:15:27.0406 3116 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
10:15:27.0640 3116 Udfs - ok
10:15:27.0671 3116 ultra - ok
10:15:27.0765 3116 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
10:15:27.0968 3116 Update - ok
10:15:28.0031 3116 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:15:28.0234 3116 usbehci - ok
10:15:28.0281 3116 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:15:28.0484 3116 usbhub - ok
10:15:28.0546 3116 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:15:28.0781 3116 usbprint - ok
10:15:28.0875 3116 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:15:29.0125 3116 usbscan - ok
10:15:29.0171 3116 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:15:29.0390 3116 USBSTOR - ok
10:15:29.0437 3116 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:15:29.0625 3116 usbuhci - ok
10:15:29.0703 3116 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
10:15:29.0921 3116 VgaSave - ok
10:15:29.0953 3116 ViaIde - ok
10:15:30.0046 3116 viamraid (1b7b0954af54e716f697c511d68c150e) C:\WINDOWS\system32\DRIVERS\viamraid.sys
10:15:30.0109 3116 viamraid - ok
10:15:30.0171 3116 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
10:15:30.0390 3116 VolSnap - ok
10:15:30.0484 3116 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:15:30.0687 3116 Wanarp - ok
10:15:30.0796 3116 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
10:15:30.0890 3116 Wdf01000 - ok
10:15:30.0953 3116 WDICA - ok
10:15:31.0000 3116 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
10:15:31.0218 3116 wdmaud - ok
10:15:31.0406 3116 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
10:15:31.0484 3116 WpdUsb - ok
10:15:31.0562 3116 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:15:31.0765 3116 WSTCODEC - ok
10:15:31.0859 3116 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:15:31.0968 3116 WudfPf - ok
10:15:32.0046 3116 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:15:32.0078 3116 WudfRd - ok
10:15:32.0140 3116 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
10:15:32.0265 3116 \Device\Harddisk0\DR0 - ok
10:15:32.0296 3116 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
10:15:32.0359 3116 \Device\Harddisk1\DR1 - ok
10:15:32.0375 3116 Boot (0x1200) (a03f13b6a216f46a3c7cc14b713c0fd7) \Device\Harddisk0\DR0\Partition0
10:15:32.0375 3116 \Device\Harddisk0\DR0\Partition0 - ok
10:15:32.0375 3116 Boot (0x1200) (01a71f063ee417857c05301a8700204c) \Device\Harddisk1\DR1\Partition0
10:15:32.0390 3116 \Device\Harddisk1\DR1\Partition0 - ok
10:15:32.0390 3116 ============================================================
10:15:32.0390 3116 Scan finished
10:15:32.0390 3116 ============================================================
10:15:32.0515 3108 Detected object count: 9
10:15:32.0515 3108 Actual detected object count: 9
10:18:57.0531 3108 ASNDIS5 ( UnsignedFile.Multi.Generic ) - skipped by user
10:18:57.0531 3108 ASNDIS5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:18:57.0531 3108 DynCal ( UnsignedFile.Multi.Generic ) - skipped by user
10:18:57.0531 3108 DynCal ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:18:57.0531 3108 pctvvbi ( UnsignedFile.Multi.Generic ) - skipped by user
10:18:57.0531 3108 pctvvbi ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:18:57.0531 3108 PfModNT ( UnsignedFile.Multi.Generic ) - skipped by user
10:18:57.0531 3108 PfModNT ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:18:57.0625 3108 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\prodrv06.sys) error 1813
10:18:58.0250 3108 Backup copy not found, trying to cure infected file..
10:18:58.0390 3108 C:\WINDOWS\System32\drivers\prodrv06.sys - Cure failed (FFFFFFFF)
10:18:58.0390 3108 C:\WINDOWS\System32\drivers\prodrv06.sys - processing error
10:19:02.0250 3108 prodrv06 ( Rootkit.Win32.ZAccess.k ) - User select action: Cure
10:19:02.0250 3108 prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
10:19:02.0250 3108 prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:19:02.0265 3108 SBKUPNT ( UnsignedFile.Multi.Generic ) - skipped by user
10:19:02.0265 3108 SBKUPNT ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:19:02.0265 3108 sbpci ( UnsignedFile.Multi.Generic ) - skipped by user
10:19:02.0265 3108 sbpci ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:19:02.0265 3108 sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
10:19:02.0265 3108 sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:20:10.0562 2528 ============================================================
10:20:10.0562 2528 Scan started
10:20:10.0562 2528 Mode: Manual; SigCheck; TDLFS;
10:20:10.0562 2528 ============================================================
10:20:10.0687 2528 Abiosdsk - ok
10:20:10.0734 2528 abp480n5 - ok
10:20:10.0781 2528 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:20:11.0078 2528 ACPI - ok
10:20:11.0156 2528 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
10:20:11.0375 2528 ACPIEC - ok
10:20:11.0421 2528 adpu160m - ok
10:20:11.0500 2528 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
10:20:11.0718 2528 aec - ok
10:20:11.0796 2528 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
10:20:11.0843 2528 AFD - ok
10:20:11.0906 2528 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
10:20:12.0093 2528 agp440 - ok
10:20:12.0140 2528 Aha154x - ok
10:20:12.0187 2528 aic78u2 - ok
10:20:12.0234 2528 aic78xx - ok
10:20:12.0281 2528 AliIde - ok
10:20:12.0328 2528 amsint - ok
10:20:12.0375 2528 asc - ok
10:20:12.0421 2528 asc3350p - ok
10:20:12.0468 2528 asc3550 - ok
10:20:12.0531 2528 ASNDIS5 (05a56c3156e1b6cc7bbd8e1d54d491f2) C:\WINDOWS\system32\ASNDIS5.SYS
10:20:12.0546 2528 ASNDIS5 ( UnsignedFile.Multi.Generic ) - warning
10:20:12.0546 2528 ASNDIS5 - detected UnsignedFile.Multi.Generic (1)
10:20:12.0625 2528 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:20:12.0890 2528 AsyncMac - ok
10:20:12.0937 2528 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:20:13.0125 2528 atapi - ok
10:20:13.0171 2528 Atdisk - ok
10:20:13.0281 2528 ati2mtag (4938ad74de9088f70922fabf86912eee) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
10:20:13.0375 2528 ati2mtag - ok
10:20:13.0437 2528 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:20:13.0671 2528 Atmarpc - ok
10:20:13.0765 2528 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:20:13.0968 2528 audstub - ok
10:20:14.0046 2528 bcm4sbxp (ba03a18635d4b0830c9262cd80d4026b) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
10:20:14.0093 2528 bcm4sbxp - ok
10:20:14.0140 2528 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:20:14.0359 2528 Beep - ok
10:20:14.0390 2528 catchme - ok
10:20:14.0453 2528 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:20:14.0687 2528 cbidf2k - ok
10:20:14.0781 2528 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:20:15.0000 2528 CCDECODE - ok
10:20:15.0046 2528 cd20xrnt - ok
10:20:15.0093 2528 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:20:15.0296 2528 Cdaudio - ok
10:20:15.0328 2528 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
10:20:15.0531 2528 Cdfs - ok
10:20:15.0609 2528 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:20:15.0812 2528 Cdrom - ok
10:20:15.0859 2528 Changer - ok
10:20:15.0937 2528 CmdIde - ok
10:20:16.0000 2528 Cpqarray - ok
10:20:16.0062 2528 dac2w2k - ok
10:20:16.0109 2528 dac960nt - ok
10:20:16.0171 2528 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
10:20:16.0375 2528 Disk - ok
10:20:16.0468 2528 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
10:20:16.0718 2528 dmboot - ok
10:20:16.0765 2528 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
10:20:17.0000 2528 dmio - ok
10:20:17.0062 2528 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:20:17.0265 2528 dmload - ok
10:20:17.0343 2528 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
10:20:17.0531 2528 DMusic - ok
10:20:17.0593 2528 dpti2o - ok
10:20:17.0640 2528 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
10:20:17.0859 2528 drmkaud - ok
10:20:17.0953 2528 DynCal (1d995cf2789e2844fc538c540e8563de) C:\WINDOWS\system32\drivers\Dyncal.sys
10:20:17.0984 2528 DynCal ( UnsignedFile.Multi.Generic ) - warning
10:20:17.0984 2528 DynCal - detected UnsignedFile.Multi.Generic (1)
10:20:18.0046 2528 eamon (9309c5c9831203436e64cf2ae605c5d7) C:\WINDOWS\system32\DRIVERS\eamon.sys
10:20:18.0093 2528 eamon - ok
10:20:18.0171 2528 ehdrv (deff87f04ab5f6dd5edf2b80853bbe10) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
10:20:18.0187 2528 ehdrv - ok
10:20:18.0250 2528 epfw (5ba193ca0ae31209aaa39939ce6736b2) C:\WINDOWS\system32\DRIVERS\epfw.sys
10:20:18.0265 2528 epfw - ok
10:20:18.0328 2528 Epfwndis (75d3bcd3e0eded0ab0f96d9a10ff01c9) C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
10:20:18.0343 2528 Epfwndis - ok
10:20:18.0406 2528 epfwtdi (dc64f26f35e32c9472bbf8acd84060d3) C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
10:20:18.0453 2528 epfwtdi - ok
10:20:18.0500 2528 epfwtdir - ok
10:20:18.0578 2528 es1371 (a55dd7d8ced5d2624a9ee2dda7be0319) C:\WINDOWS\system32\drivers\es1371mp.sys
10:20:18.0781 2528 es1371 - ok
10:20:18.0875 2528 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
10:20:19.0093 2528 Fastfat - ok
10:20:19.0140 2528 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
10:20:19.0375 2528 Fdc - ok
10:20:19.0406 2528 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
10:20:19.0609 2528 Fips - ok
10:20:19.0656 2528 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:20:19.0859 2528 Flpydisk - ok
10:20:19.0906 2528 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
10:20:20.0125 2528 FltMgr - ok
10:20:20.0187 2528 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:20:20.0390 2528 Fs_Rec - ok
10:20:20.0437 2528 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:20:20.0656 2528 Ftdisk - ok
10:20:20.0718 2528 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
10:20:20.0937 2528 gameenum - ok
10:20:20.0984 2528 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:20:21.0187 2528 Gpc - ok
10:20:21.0281 2528 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:20:21.0500 2528 HidUsb - ok
10:20:21.0546 2528 hpn - ok
10:20:21.0625 2528 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
10:20:21.0671 2528 HTTP - ok
10:20:21.0734 2528 i2omgmt - ok
10:20:21.0781 2528 i2omp - ok
10:20:21.0828 2528 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:20:22.0031 2528 i8042prt - ok
10:20:22.0062 2528 IdeBusDr (4ec233ef7c2a2c36fa962de2ae5d982a) C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys
10:20:22.0078 2528 IdeBusDr - ok
10:20:22.0125 2528 IdeChnDr (e1b24e6478ab2e5e09c21d2028e2f208) C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys
10:20:22.0156 2528 IdeChnDr - ok
10:20:22.0218 2528 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:20:22.0421 2528 Imapi - ok
10:20:22.0468 2528 ini910u - ok
10:20:22.0500 2528 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
10:20:22.0734 2528 IntelIde - ok
10:20:22.0812 2528 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:20:23.0015 2528 intelppm - ok
10:20:23.0078 2528 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
10:20:23.0296 2528 Ip6Fw - ok
10:20:23.0343 2528 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:20:23.0546 2528 IpFilterDriver - ok
10:20:23.0578 2528 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:20:23.0796 2528 IpInIp - ok
10:20:23.0859 2528 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:20:24.0062 2528 IpNat - ok
10:20:24.0093 2528 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:20:24.0312 2528 IPSec - ok
10:20:24.0359 2528 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:20:24.0437 2528 IRENUM - ok
10:20:24.0500 2528 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:20:24.0703 2528 isapnp - ok
10:20:24.0734 2528 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:20:24.0984 2528 Kbdclass - ok
10:20:25.0015 2528 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
10:20:25.0203 2528 kmixer - ok
10:20:25.0250 2528 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
10:20:25.0296 2528 KSecDD - ok
10:20:25.0359 2528 lbrtfdc - ok
10:20:25.0421 2528 MBAMSwissArmy - ok
10:20:25.0484 2528 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:20:25.0671 2528 mnmdd - ok
10:20:25.0734 2528 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
10:20:25.0921 2528 Modem - ok
10:20:25.0968 2528 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:20:26.0187 2528 Mouclass - ok
10:20:26.0234 2528 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
10:20:26.0437 2528 MountMgr - ok
10:20:26.0515 2528 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys
10:20:26.0703 2528 MPE - ok
10:20:26.0750 2528 mraid35x - ok
10:20:26.0796 2528 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:20:26.0984 2528 MRxDAV - ok
10:20:27.0046 2528 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:20:27.0093 2528 MRxSmb - ok
10:20:27.0140 2528 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
10:20:27.0343 2528 Msfs - ok
10:20:27.0406 2528 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:20:27.0609 2528 MSKSSRV - ok
10:20:27.0640 2528 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:20:27.0843 2528 MSPCLOCK - ok
10:20:27.0906 2528 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
10:20:28.0093 2528 MSPQM - ok
10:20:28.0125 2528 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:20:28.0328 2528 mssmbios - ok
10:20:28.0375 2528 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
10:20:28.0578 2528 MSTEE - ok
10:20:28.0640 2528 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
10:20:28.0671 2528 Mup - ok
10:20:28.0734 2528 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:20:28.0953 2528 NABTSFEC - ok
10:20:29.0015 2528 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
10:20:29.0203 2528 NDIS - ok
10:20:29.0250 2528 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:20:29.0421 2528 NdisIP - ok
10:20:29.0500 2528 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:20:29.0531 2528 NdisTapi - ok
10:20:29.0578 2528 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:20:29.0765 2528 Ndisuio - ok
10:20:29.0812 2528 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:20:30.0000 2528 NdisWan - ok
10:20:30.0062 2528 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
10:20:30.0093 2528 NDProxy - ok
10:20:30.0125 2528 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:20:30.0328 2528 NetBIOS - ok
10:20:30.0375 2528 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:20:30.0562 2528 NetBT - ok
10:20:30.0671 2528 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\WINDOWS\system32\drivers\ccdcmb.sys
10:20:30.0796 2528 nmwcd - ok
10:20:30.0859 2528 nmwcdnsu (28d40797bcb050321fa6674b08a620c0) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
10:20:30.0984 2528 nmwcdnsu - ok
10:20:31.0031 2528 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
10:20:31.0234 2528 Npfs - ok
10:20:31.0296 2528 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
10:20:31.0531 2528 Ntfs - ok
10:20:31.0593 2528 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:20:31.0765 2528 Null - ok
10:20:31.0843 2528 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:20:32.0062 2528 NwlnkFlt - ok
10:20:32.0125 2528 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:20:32.0296 2528 NwlnkFwd - ok
10:20:32.0375 2528 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
10:20:32.0546 2528 Parport - ok
10:20:32.0593 2528 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
10:20:32.0796 2528 PartMgr - ok
10:20:32.0859 2528 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
10:20:33.0062 2528 ParVdm - ok
10:20:33.0125 2528 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
10:20:33.0140 2528 pccsmcfd - ok
10:20:33.0203 2528 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
10:20:33.0421 2528 PCI - ok
10:20:33.0453 2528 PCIDump - ok
10:20:33.0515 2528 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:20:33.0718 2528 PCIIde - ok
10:20:33.0781 2528 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
10:20:33.0984 2528 Pcmcia - ok
10:20:34.0062 2528 pctvvbi (eb7de8f91803f267e899f87197731664) C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
10:20:34.0062 2528 pctvvbi ( UnsignedFile.Multi.Generic ) - warning
10:20:34.0062 2528 pctvvbi - detected UnsignedFile.Multi.Generic (1)
10:20:34.0109 2528 PDCOMP - ok
10:20:34.0140 2528 PDFRAME - ok
10:20:34.0171 2528 PDRELI - ok
10:20:34.0218 2528 PDRFRAME - ok
10:20:34.0250 2528 perc2 - ok
10:20:34.0281 2528 perc2hib - ok
10:20:34.0375 2528 PfModNT (b293f05ad9120b0232c28945c1e98cd0) C:\WINDOWS\system32\PfModNT.sys
10:20:34.0406 2528 PfModNT ( UnsignedFile.Multi.Generic ) - warning
10:20:34.0406 2528 PfModNT - detected UnsignedFile.Multi.Generic (1)
10:20:34.0484 2528 PinnacleRoyalTS (48b06eca2c2f036eb3912d816ee5941b) C:\WINDOWS\system32\DRIVERS\RoyalTS.sys
10:20:34.0515 2528 PinnacleRoyalTS - ok
10:20:34.0593 2528 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:20:34.0796 2528 PptpMiniport - ok
10:20:34.0875 2528 prodrv06 (e36105ef413861f562eb507d4f5d4744) C:\WINDOWS\System32\drivers\prodrv06.sys
10:20:34.0875 2528 prodrv06 ( Rootkit.Win32.ZAccess.k ) - infected
10:20:34.0875 2528 prodrv06 - detected Rootkit.Win32.ZAccess.k (0)
10:20:34.0921 2528 prohlp02 (2409b32e691cb5dda39ea40bd154a50b) C:\WINDOWS\system32\drivers\prohlp02.sys
10:20:34.0953 2528 prohlp02 ( UnsignedFile.Multi.Generic ) - warning
10:20:34.0953 2528 prohlp02 - detected UnsignedFile.Multi.Generic (1)
10:20:35.0000 2528 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
10:20:35.0171 2528 PSched - ok
10:20:35.0203 2528 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:20:35.0390 2528 Ptilink - ok
10:20:35.0453 2528 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:20:35.0468 2528 PxHelp20 - ok
10:20:35.0515 2528 ql1080 - ok
10:20:35.0546 2528 Ql10wnt - ok
10:20:35.0609 2528 ql12160 - ok
10:20:35.0656 2528 ql1240 - ok
10:20:35.0718 2528 ql1280 - ok
10:20:35.0765 2528 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:20:35.0953 2528 RasAcd - ok
10:20:36.0000 2528 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:20:36.0203 2528 Rasl2tp - ok
10:20:36.0234 2528 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:20:36.0437 2528 RasPppoe - ok
10:20:36.0484 2528 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:20:36.0671 2528 Raspti - ok
10:20:36.0765 2528 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:20:36.0984 2528 Rdbss - ok
10:20:37.0015 2528 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:20:37.0203 2528 RDPCDD - ok
10:20:37.0296 2528 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
10:20:37.0328 2528 RDPWD - ok
10:20:37.0375 2528 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:20:37.0562 2528 redbook - ok
10:20:37.0656 2528 SBKUPNT (729248b54aff21e740054acebfdbcb1c) C:\WINDOWS\system32\Drivers\SBKUPNT.SYS
10:20:37.0671 2528 SBKUPNT ( UnsignedFile.Multi.Generic ) - warning
10:20:37.0671 2528 SBKUPNT - detected UnsignedFile.Multi.Generic (1)
10:20:37.0796 2528 sbpci (51e16b053ee28fd309beac5722bcc735) C:\WINDOWS\system32\drivers\sbpci.sys
10:20:37.0859 2528 sbpci ( UnsignedFile.Multi.Generic ) - warning
10:20:37.0859 2528 sbpci - detected UnsignedFile.Multi.Generic (1)
10:20:37.0937 2528 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:20:38.0046 2528 Secdrv - ok
10:20:38.0125 2528 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:20:38.0312 2528 serenum - ok
10:20:38.0359 2528 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
10:20:38.0546 2528 Serial - ok
10:20:38.0640 2528 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
10:20:38.0640 2528 sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
10:20:38.0640 2528 sfhlp01 - detected UnsignedFile.Multi.Generic (1)
10:20:38.0734 2528 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:20:38.0921 2528 Sfloppy - ok
10:20:38.0968 2528 Simbad - ok
10:20:39.0015 2528 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:20:39.0218 2528 SLIP - ok
10:20:39.0250 2528 Sparrow - ok
10:20:39.0296 2528 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
10:20:39.0500 2528 splitter - ok
10:20:39.0546 2528 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
10:20:39.0640 2528 sr - ok
10:20:39.0718 2528 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
10:20:39.0750 2528 Srv - ok
10:20:39.0843 2528 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:20:40.0031 2528 streamip - ok
10:20:40.0062 2528 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:20:40.0265 2528 swenum - ok
10:20:40.0312 2528 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
10:20:40.0500 2528 swmidi - ok
10:20:40.0546 2528 symc810 - ok
10:20:40.0609 2528 symc8xx - ok
10:20:40.0656 2528 sym_hi - ok
10:20:40.0718 2528 sym_u3 - ok
10:20:40.0812 2528 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
10:20:41.0031 2528 sysaudio - ok
10:20:41.0109 2528 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:20:41.0171 2528 Tcpip - ok
10:20:41.0218 2528 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:20:41.0421 2528 TDPIPE - ok
10:20:41.0468 2528 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
10:20:41.0671 2528 TDTCP - ok
10:20:41.0734 2528 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:20:41.0921 2528 TermDD - ok
10:20:41.0984 2528 TosIde - ok
10:20:42.0046 2528 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
10:20:42.0265 2528 Udfs - ok
10:20:42.0296 2528 ultra - ok
10:20:42.0359 2528 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
10:20:42.0578 2528 Update - ok
10:20:42.0640 2528 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:20:42.0812 2528 usbehci - ok
10:20:42.0859 2528 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:20:43.0062 2528 usbhub - ok
10:20:43.0109 2528 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:20:43.0281 2528 usbprint - ok
10:20:43.0359 2528 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:20:43.0531 2528 usbscan - ok
10:20:43.0593 2528 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:20:43.0781 2528 USBSTOR - ok
10:20:43.0843 2528 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:20:44.0031 2528 usbuhci - ok
10:20:44.0078 2528 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
10:20:44.0265 2528 VgaSave - ok
10:20:44.0296 2528 ViaIde - ok
10:20:44.0375 2528 viamraid (1b7b0954af54e716f697c511d68c150e) C:\WINDOWS\system32\DRIVERS\viamraid.sys
10:20:44.0406 2528 viamraid - ok
10:20:44.0437 2528 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
10:20:44.0625 2528 VolSnap - ok
10:20:44.0718 2528 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:20:44.0906 2528 Wanarp - ok
10:20:44.0984 2528 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
10:20:45.0015 2528 Wdf01000 - ok
10:20:45.0062 2528 WDICA - ok
10:20:45.0109 2528 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
10:20:45.0296 2528 wdmaud - ok
10:20:45.0468 2528 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
10:20:45.0500 2528 WpdUsb - ok
10:20:45.0562 2528 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:20:45.0765 2528 WSTCODEC - ok
10:20:45.0843 2528 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:20:45.0890 2528 WudfPf - ok
10:20:45.0921 2528 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:20:45.0953 2528 WudfRd - ok
10:20:46.0015 2528 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
10:20:46.0156 2528 \Device\Harddisk0\DR0 - ok
10:20:46.0187 2528 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
10:20:46.0250 2528 \Device\Harddisk1\DR1 - ok
10:20:46.0265 2528 Boot (0x1200) (a03f13b6a216f46a3c7cc14b713c0fd7) \Device\Harddisk0\DR0\Partition0
10:20:46.0265 2528 \Device\Harddisk0\DR0\Partition0 - ok
10:20:46.0281 2528 Boot (0x1200) (01a71f063ee417857c05301a8700204c) \Device\Harddisk1\DR1\Partition0
10:20:46.0281 2528 \Device\Harddisk1\DR1\Partition0 - ok
10:20:46.0281 2528 ============================================================
10:20:46.0281 2528 Scan finished
10:20:46.0281 2528 ============================================================
10:20:46.0312 2520 Detected object count: 9
10:20:46.0312 2520 Actual detected object count: 9
10:23:52.0218 2520 ASNDIS5 ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:52.0218 2520 ASNDIS5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:52.0218 2520 DynCal ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:52.0218 2520 DynCal ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:52.0234 2520 pctvvbi ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:52.0234 2520 pctvvbi ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:52.0234 2520 PfModNT ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:52.0234 2520 PfModNT ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:52.0343 2520 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\prodrv06.sys) error 1813
10:23:52.0406 2520 Backup copy not found, trying to cure infected file..
10:23:52.0406 2520 C:\WINDOWS\System32\drivers\prodrv06.sys - Cure failed (FFFFFFFF)
10:23:52.0406 2520 C:\WINDOWS\System32\drivers\prodrv06.sys - processing error
10:23:56.0218 2520 prodrv06 ( Rootkit.Win32.ZAccess.k ) - User select action: Cure
10:23:56.0218 2520 prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:56.0218 2520 prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:56.0234 2520 SBKUPNT ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:56.0234 2520 SBKUPNT ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:56.0234 2520 sbpci ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:56.0234 2520 sbpci ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:23:56.0234 2520 sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
10:23:56.0234 2520 sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:24:09.0250 4084 Deinitialize success

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 16:44
od e_mysak
Připravil jsem vše dle návodu, rc.exe do c: a vytvořil textový soubor CFScript také na plochu. CF se spustil vypnul eset a žádal o připojení na internet.Nevím čím ale než se spustil CF tak přihlášení na net fungovalo a po spuštění CF jako když vypne a nebylo možno se na net přihlásit takže se kozole zas nespustila? Připojuji výpis CF


ComboFix 11-11-18.02 - Masek 20.11.2011 16:09:22.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1604 [GMT 1:00]
Spuštěný z: c:\documents and settings\All Users\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Masek\Plocha\CFScript.txt
AV: ESET Smart Security 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_prodrv06
-------\Service_prodrv06
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-20 do 2011-11-20 )))))))))))))))))))))))))))))))
.
.
2011-11-19 19:52 . 2011-11-19 21:14 -------- d-----w- c:\program files\trend micro
2011-11-19 19:52 . 2011-11-19 21:14 -------- d-----w- C:\rsit
2011-11-19 14:09 . 2011-11-19 14:09 -------- d-----w- c:\documents and settings\Masek\Data aplikací\Malwarebytes
2011-11-19 14:09 . 2011-11-19 14:09 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-19 14:09 . 2011-11-19 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-19 14:09 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-16 20:44 . 2011-11-16 20:44 -------- d-----w- c:\windows\system32\wbem\Repository
2011-11-15 23:13 . 2011-11-15 23:13 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-10-28 19:55 . 2011-10-28 19:55 -------- d-----w- c:\documents and settings\Patrik Netroufal\Local Settings\Data aplikací\ESET
2011-10-28 19:55 . 2011-10-28 19:55 -------- d-----w- c:\documents and settings\Patrik Netroufal\Data aplikací\ESET
2011-10-28 18:54 . 2011-11-14 19:44 -------- d-----w- c:\documents and settings\Masek\Local Settings\Data aplikací\Pinnacle
2011-10-28 18:54 . 2011-10-28 18:54 -------- d-----w- C:\copy-pal
2011-10-22 17:48 . 2011-10-22 17:48 -------- d-----w- c:\documents and settings\Patrik Netroufal\Local Settings\Data aplikací\Unity
2011-10-22 12:05 . 2011-10-22 12:05 -------- d-----w- c:\documents and settings\Masek\Data aplikací\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-19 14:44 . 2011-06-07 04:49 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2005-01-11 08:17 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-08-18 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-08-18 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32(3).dll
2011-09-06 14:10 . 2004-08-18 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:41 . 2004-08-18 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:41 . 2004-08-18 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-08-22 23:41 . 2004-08-18 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
2009-11-09 23:33 815104 ----a-w- c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll" [2009-11-09 815104]
.
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll" [2009-11-09 815104]
.
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"="c:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE" [2011-03-19 26624]
"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2008-11-18 226576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-09-22 3080264]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Masek\Nabídka Start\Programy\Po spuštění\
Svátky a narozeniny.lnk - c:\program files\Svátky a narozeniny\SaN.exe [2009-10-25 693760]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Pinnacle Streaming Server.lnk - c:\program files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe [2008-3-25 603408]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Games\\TmNationsForever\\TmForever.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 118104]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [22.9.2011 11:03 974944]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [12.10.2009 21:29 14976]
R3 PinnacleRoyalTS;Pinnacle Systems RoyalTS Device;c:\windows\system32\drivers\RoyalTS.sys [10.3.2010 19:24 123520]
S3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [7.11.2007 19:15 12928]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [23.12.2010 14:37 137600]
S3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [11.1.2005 16:43 6400]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://atlas.centrum.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-20 16:19
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(936)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(4016)
c:\documents and settings\All Users\Data aplikací\LangSoft\TrnOEH.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\windows\system32\CTSvcCDA.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-11-20 16:22:09 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-11-20 15:22
ComboFix2.txt 2011-11-19 22:40
.
Před spuštěním: Volných bajtů: 67 670 274 048
Po spuštění: Volných bajtů: 67 589 263 360
.
- - End Of File - - 93CC965282C06E689580907E0C59D776

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 18:03
od e_mysak
Tak jsem to připravil a posílám výpis z TDSS, účto se bohužel neobjevilo. Všiml jsem si pouze že Eset při vypnutí ochran zablokuje přístup na net.zazipovaný Qoobox.zip mám ale když to chci poslat tady joko přílohu tak mi po cca 1 min vypadne spojení na net.Jinak net funguje dobře.Myslím že i přesto je ten soubor nějak velký (cca 70 Mb) asi to budem muset poslat jinak? prosím o radu.

17:18:28.0796 1872 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
17:18:28.0828 1872 ============================================================
17:18:28.0828 1872 Current date / time: 2011/11/20 17:18:28.0828
17:18:28.0828 1872 SystemInfo:
17:18:28.0828 1872
17:18:28.0828 1872 OS Version: 5.1.2600 ServicePack: 3.0
17:18:28.0828 1872 Product type: Workstation
17:18:28.0828 1872 ComputerName: PC-MASEK
17:18:28.0828 1872 UserName: Masek
17:18:28.0828 1872 Windows directory: C:\WINDOWS
17:18:28.0828 1872 System windows directory: C:\WINDOWS
17:18:28.0828 1872 Processor architecture: Intel x86
17:18:28.0828 1872 Number of processors: 1
17:18:28.0828 1872 Page size: 0x1000
17:18:28.0828 1872 Boot type: Normal boot
17:18:28.0828 1872 ============================================================
17:18:29.0093 1872 Initialize success
17:18:40.0609 2644 ============================================================
17:18:40.0609 2644 Scan started
17:18:40.0609 2644 Mode: Manual; SigCheck; TDLFS;
17:18:40.0609 2644 ============================================================
17:18:40.0875 2644 Abiosdsk - ok
17:18:40.0921 2644 abp480n5 - ok
17:18:40.0984 2644 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:18:41.0921 2644 ACPI - ok
17:18:41.0984 2644 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
17:18:42.0218 2644 ACPIEC - ok
17:18:42.0250 2644 adpu160m - ok
17:18:42.0328 2644 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:18:42.0546 2644 aec - ok
17:18:42.0609 2644 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
17:18:42.0671 2644 AFD - ok
17:18:42.0718 2644 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
17:18:42.0937 2644 agp440 - ok
17:18:42.0984 2644 Aha154x - ok
17:18:43.0015 2644 aic78u2 - ok
17:18:43.0062 2644 aic78xx - ok
17:18:43.0125 2644 AliIde - ok
17:18:43.0156 2644 amsint - ok
17:18:43.0203 2644 asc - ok
17:18:43.0234 2644 asc3350p - ok
17:18:43.0265 2644 asc3550 - ok
17:18:43.0328 2644 ASNDIS5 (05a56c3156e1b6cc7bbd8e1d54d491f2) C:\WINDOWS\system32\ASNDIS5.SYS
17:18:43.0343 2644 ASNDIS5 ( UnsignedFile.Multi.Generic ) - warning
17:18:43.0343 2644 ASNDIS5 - detected UnsignedFile.Multi.Generic (1)
17:18:43.0421 2644 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:18:43.0640 2644 AsyncMac - ok
17:18:43.0687 2644 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:18:43.0890 2644 atapi - ok
17:18:43.0921 2644 Atdisk - ok
17:18:44.0031 2644 ati2mtag (4938ad74de9088f70922fabf86912eee) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
17:18:44.0109 2644 ati2mtag - ok
17:18:44.0171 2644 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:18:44.0390 2644 Atmarpc - ok
17:18:44.0453 2644 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:18:44.0671 2644 audstub - ok
17:18:44.0750 2644 bcm4sbxp (ba03a18635d4b0830c9262cd80d4026b) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
17:18:44.0781 2644 bcm4sbxp - ok
17:18:44.0828 2644 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:18:45.0046 2644 Beep - ok
17:18:45.0078 2644 catchme - ok
17:18:45.0125 2644 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:18:45.0343 2644 cbidf2k - ok
17:18:45.0406 2644 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:18:45.0640 2644 CCDECODE - ok
17:18:45.0687 2644 cd20xrnt - ok
17:18:45.0718 2644 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:18:45.0953 2644 Cdaudio - ok
17:18:45.0984 2644 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:18:46.0203 2644 Cdfs - ok
17:18:46.0265 2644 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:18:46.0500 2644 Cdrom - ok
17:18:46.0531 2644 Changer - ok
17:18:46.0609 2644 CmdIde - ok
17:18:46.0656 2644 Cpqarray - ok
17:18:46.0718 2644 dac2w2k - ok
17:18:46.0750 2644 dac960nt - ok
17:18:46.0796 2644 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:18:47.0015 2644 Disk - ok
17:18:47.0125 2644 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
17:18:47.0437 2644 dmboot - ok
17:18:47.0468 2644 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
17:18:47.0687 2644 dmio - ok
17:18:47.0734 2644 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:18:47.0937 2644 dmload - ok
17:18:48.0000 2644 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:18:48.0218 2644 DMusic - ok
17:18:48.0296 2644 dpti2o - ok
17:18:48.0328 2644 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:18:48.0546 2644 drmkaud - ok
17:18:48.0609 2644 DynCal (1d995cf2789e2844fc538c540e8563de) C:\WINDOWS\system32\drivers\Dyncal.sys
17:18:48.0640 2644 DynCal ( UnsignedFile.Multi.Generic ) - warning
17:18:48.0640 2644 DynCal - detected UnsignedFile.Multi.Generic (1)
17:18:48.0703 2644 eamon (9309c5c9831203436e64cf2ae605c5d7) C:\WINDOWS\system32\DRIVERS\eamon.sys
17:18:48.0765 2644 eamon - ok
17:18:48.0843 2644 ehdrv (deff87f04ab5f6dd5edf2b80853bbe10) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
17:18:48.0859 2644 ehdrv - ok
17:18:48.0906 2644 epfw (5ba193ca0ae31209aaa39939ce6736b2) C:\WINDOWS\system32\DRIVERS\epfw.sys
17:18:48.0921 2644 epfw - ok
17:18:48.0984 2644 Epfwndis (75d3bcd3e0eded0ab0f96d9a10ff01c9) C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
17:18:49.0000 2644 Epfwndis - ok
17:18:49.0078 2644 epfwtdi (dc64f26f35e32c9472bbf8acd84060d3) C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
17:18:49.0078 2644 epfwtdi - ok
17:18:49.0125 2644 epfwtdir - ok
17:18:49.0187 2644 es1371 (a55dd7d8ced5d2624a9ee2dda7be0319) C:\WINDOWS\system32\drivers\es1371mp.sys
17:18:49.0406 2644 es1371 - ok
17:18:49.0500 2644 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:18:49.0734 2644 Fastfat - ok
17:18:49.0781 2644 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
17:18:49.0984 2644 Fdc - ok
17:18:50.0031 2644 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
17:18:50.0234 2644 Fips - ok
17:18:50.0296 2644 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
17:18:50.0515 2644 Flpydisk - ok
17:18:50.0546 2644 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
17:18:50.0765 2644 FltMgr - ok
17:18:50.0796 2644 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:18:51.0015 2644 Fs_Rec - ok
17:18:51.0078 2644 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:18:51.0312 2644 Ftdisk - ok
17:18:51.0359 2644 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
17:18:51.0562 2644 gameenum - ok
17:18:51.0609 2644 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:18:51.0796 2644 Gpc - ok
17:18:51.0875 2644 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:18:52.0109 2644 HidUsb - ok
17:18:52.0171 2644 hpn - ok
17:18:52.0234 2644 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:18:52.0296 2644 HTTP - ok
17:18:52.0343 2644 i2omgmt - ok
17:18:52.0375 2644 i2omp - ok
17:18:52.0421 2644 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:18:52.0625 2644 i8042prt - ok
17:18:52.0671 2644 IdeBusDr (4ec233ef7c2a2c36fa962de2ae5d982a) C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys
17:18:52.0703 2644 IdeBusDr - ok
17:18:52.0750 2644 IdeChnDr (e1b24e6478ab2e5e09c21d2028e2f208) C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys
17:18:52.0765 2644 IdeChnDr - ok
17:18:52.0828 2644 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:18:53.0046 2644 Imapi - ok
17:18:53.0093 2644 ini910u - ok
17:18:53.0140 2644 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
17:18:53.0343 2644 IntelIde - ok
17:18:53.0421 2644 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:18:53.0609 2644 intelppm - ok
17:18:53.0656 2644 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
17:18:53.0875 2644 Ip6Fw - ok
17:18:53.0937 2644 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:18:54.0140 2644 IpFilterDriver - ok
17:18:54.0203 2644 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:18:54.0406 2644 IpInIp - ok
17:18:54.0453 2644 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:18:54.0671 2644 IpNat - ok
17:18:54.0718 2644 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:18:54.0937 2644 IPSec - ok
17:18:54.0984 2644 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:18:55.0062 2644 IRENUM - ok
17:18:55.0125 2644 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:18:55.0312 2644 isapnp - ok
17:18:55.0359 2644 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:18:55.0562 2644 Kbdclass - ok
17:18:55.0609 2644 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:18:55.0796 2644 kmixer - ok
17:18:55.0859 2644 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:18:55.0906 2644 KSecDD - ok
17:18:55.0953 2644 lbrtfdc - ok
17:18:56.0031 2644 MBAMSwissArmy - ok
17:18:56.0125 2644 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:18:56.0343 2644 mnmdd - ok
17:18:56.0406 2644 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
17:18:56.0593 2644 Modem - ok
17:18:56.0640 2644 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:18:56.0859 2644 Mouclass - ok
17:18:56.0890 2644 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:18:57.0078 2644 MountMgr - ok
17:18:57.0156 2644 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys
17:18:57.0343 2644 MPE - ok
17:18:57.0406 2644 mraid35x - ok
17:18:57.0453 2644 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:18:57.0640 2644 MRxDAV - ok
17:18:57.0734 2644 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:18:57.0796 2644 MRxSmb - ok
17:18:57.0843 2644 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:18:58.0046 2644 Msfs - ok
17:18:58.0109 2644 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:18:58.0343 2644 MSKSSRV - ok
17:18:58.0375 2644 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:18:58.0562 2644 MSPCLOCK - ok
17:18:58.0609 2644 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:18:58.0812 2644 MSPQM - ok
17:18:58.0843 2644 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:18:59.0046 2644 mssmbios - ok
17:18:59.0125 2644 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
17:18:59.0343 2644 MSTEE - ok
17:18:59.0421 2644 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
17:18:59.0453 2644 Mup - ok
17:18:59.0515 2644 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:18:59.0718 2644 NABTSFEC - ok
17:18:59.0765 2644 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:18:59.0953 2644 NDIS - ok
17:19:00.0015 2644 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:19:00.0218 2644 NdisIP - ok
17:19:00.0296 2644 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:19:00.0312 2644 NdisTapi - ok
17:19:00.0359 2644 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:19:00.0546 2644 Ndisuio - ok
17:19:00.0578 2644 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:19:00.0781 2644 NdisWan - ok
17:19:00.0843 2644 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:19:00.0890 2644 NDProxy - ok
17:19:00.0937 2644 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:19:01.0140 2644 NetBIOS - ok
17:19:01.0203 2644 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:19:01.0406 2644 NetBT - ok
17:19:01.0515 2644 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\WINDOWS\system32\drivers\ccdcmb.sys
17:19:01.0750 2644 nmwcd - ok
17:19:01.0828 2644 nmwcdnsu (28d40797bcb050321fa6674b08a620c0) C:\WINDOWS\system32\drivers\nmwcdnsu.sys
17:19:01.0937 2644 nmwcdnsu - ok
17:19:01.0984 2644 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:19:02.0171 2644 Npfs - ok
17:19:02.0234 2644 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:19:02.0484 2644 Ntfs - ok
17:19:02.0546 2644 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:19:02.0734 2644 Null - ok
17:19:02.0812 2644 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:19:03.0031 2644 NwlnkFlt - ok
17:19:03.0093 2644 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:19:03.0281 2644 NwlnkFwd - ok
17:19:03.0375 2644 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\DRIVERS\parport.sys
17:19:03.0562 2644 Parport - ok
17:19:03.0593 2644 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:19:03.0781 2644 PartMgr - ok
17:19:03.0843 2644 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
17:19:04.0031 2644 ParVdm - ok
17:19:04.0125 2644 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
17:19:04.0171 2644 pccsmcfd - ok
17:19:04.0218 2644 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
17:19:04.0437 2644 PCI - ok
17:19:04.0468 2644 PCIDump - ok
17:19:04.0531 2644 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:19:04.0718 2644 PCIIde - ok
17:19:04.0765 2644 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:19:04.0984 2644 Pcmcia - ok
17:19:05.0062 2644 pctvvbi (eb7de8f91803f267e899f87197731664) C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
17:19:05.0062 2644 pctvvbi ( UnsignedFile.Multi.Generic ) - warning
17:19:05.0062 2644 pctvvbi - detected UnsignedFile.Multi.Generic (1)
17:19:05.0109 2644 PDCOMP - ok
17:19:05.0140 2644 PDFRAME - ok
17:19:05.0171 2644 PDRELI - ok
17:19:05.0218 2644 PDRFRAME - ok
17:19:05.0250 2644 perc2 - ok
17:19:05.0281 2644 perc2hib - ok
17:19:05.0375 2644 PfModNT (b293f05ad9120b0232c28945c1e98cd0) C:\WINDOWS\system32\PfModNT.sys
17:19:05.0390 2644 PfModNT ( UnsignedFile.Multi.Generic ) - warning
17:19:05.0390 2644 PfModNT - detected UnsignedFile.Multi.Generic (1)
17:19:05.0468 2644 PinnacleRoyalTS (48b06eca2c2f036eb3912d816ee5941b) C:\WINDOWS\system32\DRIVERS\RoyalTS.sys
17:19:05.0500 2644 PinnacleRoyalTS - ok
17:19:05.0578 2644 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:19:05.0765 2644 PptpMiniport - ok
17:19:05.0843 2644 prohlp02 (2409b32e691cb5dda39ea40bd154a50b) C:\WINDOWS\system32\drivers\prohlp02.sys
17:19:05.0859 2644 prohlp02 ( UnsignedFile.Multi.Generic ) - warning
17:19:05.0859 2644 prohlp02 - detected UnsignedFile.Multi.Generic (1)
17:19:05.0906 2644 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:19:06.0140 2644 PSched - ok
17:19:06.0171 2644 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:19:06.0375 2644 Ptilink - ok
17:19:06.0421 2644 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
17:19:06.0437 2644 PxHelp20 - ok
17:19:06.0484 2644 ql1080 - ok
17:19:06.0515 2644 Ql10wnt - ok
17:19:06.0546 2644 ql12160 - ok
17:19:06.0578 2644 ql1240 - ok
17:19:06.0625 2644 ql1280 - ok
17:19:06.0656 2644 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:19:06.0859 2644 RasAcd - ok
17:19:06.0921 2644 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:19:07.0125 2644 Rasl2tp - ok
17:19:07.0171 2644 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:19:07.0375 2644 RasPppoe - ok
17:19:07.0406 2644 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:19:07.0593 2644 Raspti - ok
17:19:07.0640 2644 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:19:07.0828 2644 Rdbss - ok
17:19:07.0875 2644 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:19:08.0062 2644 RDPCDD - ok
17:19:08.0156 2644 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
17:19:08.0187 2644 RDPWD - ok
17:19:08.0234 2644 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:19:08.0437 2644 redbook - ok
17:19:08.0515 2644 SBKUPNT (729248b54aff21e740054acebfdbcb1c) C:\WINDOWS\system32\Drivers\SBKUPNT.SYS
17:19:08.0531 2644 SBKUPNT ( UnsignedFile.Multi.Generic ) - warning
17:19:08.0531 2644 SBKUPNT - detected UnsignedFile.Multi.Generic (1)
17:19:08.0625 2644 sbpci (51e16b053ee28fd309beac5722bcc735) C:\WINDOWS\system32\drivers\sbpci.sys
17:19:08.0703 2644 sbpci ( UnsignedFile.Multi.Generic ) - warning
17:19:08.0703 2644 sbpci - detected UnsignedFile.Multi.Generic (1)
17:19:08.0781 2644 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:19:08.0890 2644 Secdrv - ok
17:19:08.0953 2644 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:19:09.0156 2644 serenum - ok
17:19:09.0203 2644 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
17:19:09.0406 2644 Serial - ok
17:19:09.0484 2644 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
17:19:09.0484 2644 sfhlp01 ( UnsignedFile.Multi.Generic ) - warning
17:19:09.0484 2644 sfhlp01 - detected UnsignedFile.Multi.Generic (1)
17:19:09.0531 2644 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:19:09.0734 2644 Sfloppy - ok
17:19:09.0781 2644 Simbad - ok
17:19:09.0828 2644 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:19:10.0046 2644 SLIP - ok
17:19:10.0093 2644 Sparrow - ok
17:19:10.0125 2644 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:19:10.0343 2644 splitter - ok
17:19:10.0390 2644 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
17:19:10.0484 2644 sr - ok
17:19:10.0562 2644 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
17:19:10.0625 2644 Srv - ok
17:19:10.0687 2644 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:19:10.0890 2644 streamip - ok
17:19:10.0953 2644 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:19:11.0156 2644 swenum - ok
17:19:11.0218 2644 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:19:11.0421 2644 swmidi - ok
17:19:11.0468 2644 symc810 - ok
17:19:11.0500 2644 symc8xx - ok
17:19:11.0531 2644 sym_hi - ok
17:19:11.0562 2644 sym_u3 - ok
17:19:11.0609 2644 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:19:11.0812 2644 sysaudio - ok
17:19:11.0906 2644 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:19:11.0968 2644 Tcpip - ok
17:19:12.0031 2644 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:19:12.0250 2644 TDPIPE - ok
17:19:12.0312 2644 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:19:12.0515 2644 TDTCP - ok
17:19:12.0562 2644 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:19:12.0750 2644 TermDD - ok
17:19:12.0796 2644 TosIde - ok
17:19:12.0859 2644 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:19:13.0062 2644 Udfs - ok
17:19:13.0109 2644 ultra - ok
17:19:13.0156 2644 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:19:13.0375 2644 Update - ok
17:19:13.0437 2644 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:19:13.0640 2644 usbehci - ok
17:19:13.0671 2644 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:19:13.0875 2644 usbhub - ok
17:19:13.0921 2644 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
17:19:14.0125 2644 usbprint - ok
17:19:14.0218 2644 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:19:14.0421 2644 usbscan - ok
17:19:14.0468 2644 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:19:14.0687 2644 USBSTOR - ok
17:19:14.0718 2644 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:19:14.0921 2644 usbuhci - ok
17:19:14.0968 2644 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:19:15.0187 2644 VgaSave - ok
17:19:15.0218 2644 ViaIde - ok
17:19:15.0281 2644 viamraid (1b7b0954af54e716f697c511d68c150e) C:\WINDOWS\system32\DRIVERS\viamraid.sys
17:19:15.0312 2644 viamraid - ok
17:19:15.0359 2644 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
17:19:15.0546 2644 VolSnap - ok
17:19:15.0609 2644 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:19:15.0812 2644 Wanarp - ok
17:19:15.0890 2644 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
17:19:15.0937 2644 Wdf01000 - ok
17:19:15.0984 2644 WDICA - ok
17:19:16.0062 2644 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:19:16.0265 2644 wdmaud - ok
17:19:16.0437 2644 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
17:19:16.0468 2644 WpdUsb - ok
17:19:16.0546 2644 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:19:16.0750 2644 WSTCODEC - ok
17:19:16.0812 2644 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:19:16.0859 2644 WudfPf - ok
17:19:16.0921 2644 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:19:16.0953 2644 WudfRd - ok
17:19:17.0015 2644 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
17:19:17.0171 2644 \Device\Harddisk0\DR0 - ok
17:19:17.0203 2644 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
17:19:17.0265 2644 \Device\Harddisk1\DR1 - ok
17:19:17.0281 2644 Boot (0x1200) (a03f13b6a216f46a3c7cc14b713c0fd7) \Device\Harddisk0\DR0\Partition0
17:19:17.0281 2644 \Device\Harddisk0\DR0\Partition0 - ok
17:19:17.0296 2644 Boot (0x1200) (01a71f063ee417857c05301a8700204c) \Device\Harddisk1\DR1\Partition0
17:19:17.0296 2644 \Device\Harddisk1\DR1\Partition0 - ok
17:19:17.0312 2644 ============================================================
17:19:17.0312 2644 Scan finished
17:19:17.0312 2644 ============================================================
17:19:17.0437 3492 Detected object count: 8
17:19:17.0437 3492 Actual detected object count: 8
17:23:13.0562 3492 ASNDIS5 ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0562 3492 ASNDIS5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:13.0562 3492 DynCal ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0562 3492 DynCal ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:13.0578 3492 pctvvbi ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0578 3492 pctvvbi ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:13.0578 3492 PfModNT ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0578 3492 PfModNT ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:13.0578 3492 prohlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0578 3492 prohlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:13.0578 3492 SBKUPNT ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0578 3492 SBKUPNT ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:13.0578 3492 sbpci ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0578 3492 sbpci ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:13.0578 3492 sfhlp01 ( UnsignedFile.Multi.Generic ) - skipped by user
17:23:13.0578 3492 sfhlp01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:23:21.0828 2884 Deinitialize success

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 18:20
od e_mysak
složku jsem udělal jak píši v předchozím ale je asi nějak velká (cca 70Mb), jako příloha mi nejde tady odeslat,budem muset nějak jinak když ji dám jako přílohu tak mi po cca 1 min vypadne internet. jinak funguje bez problémů prosím o radu jak

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 20:20
od e_mysak
Velmi se omlouvám,že to trvalo déle. Doufal jsem když se zaregistruji tak to bude rychleji nahrávat ale bylo to stejné (39Kb/s). Zde je okaz kde soubor vyzvednout.

Odkaz na soubor: Qoobox.zip
stahnout: http://www.edisk.cz/stahni/92087/Qoobox.zip_68MB.html
smazat : . . . /smazat/2f951ec72e4bd1cc0bf04bae7e66006b

Ještě bych se mimo hlavní problém zeptal, nyní po provedené očistě se z hlaního panelu-lišty vpravo ztratil znak reproduktor, zvuk funguje, skryté záložky žádné.Teď je tam pouze Eset,internet a červený štítek který občas vyskakuje, že není zapnuta aut.aktualizace ve Win.(rozčiluje mne rád bych ji vymázl) aktualizaci Win si dělám sám když o to žádá Eset.(cca 1x 14 dní).Počitač se zatím chová normálně internet teď chodí cca 620Kb/s.

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 20:59
od e_mysak
dávám nejdříve RSIT a mezitím se mrknu na účto

Logfile of random's system information tool 1.09 (written by random/random)
Run by Masek at 2011-11-20 20:55:53
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 64 GB (41%) free of 156 GB
Total RAM: 2047 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:55:57, on 20.11.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTSvcCDA.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Install\RSIT.exe
C:\Program Files\trend micro\Masek.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://atlas.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66022
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=66022
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Svátky a narozeniny.lnk = ?
O4 - Global Startup: Pinnacle Streaming Server.lnk = C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microso ... 0814754359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0814741296
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7805 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2011-03-19 798771]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
Burn4Free Toolbar Helper - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll [2009-11-10 815104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - Burn4Free Toolbar - C:\Program Files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll [2009-11-10 815104]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2011-03-19 798771]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"Share-to-Web Namespace Daemon"=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [2001-07-03 57344]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 3080264]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"=C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE [2011-03-19 26624]
"PMCRemote"=C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe [2008-11-18 226576]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Pinnacle Streaming Server.lnk - C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe

C:\Documents and Settings\Masek\Nabídka Start\Programy\Po spuštění
Svátky a narozeniny.lnk - C:\Program Files\Svátky a narozeniny\SaN.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2004-04-21 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Konzola Microsoft Management Console"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe"="C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe:LocalSubNet:Enabled:Pinnacle Streaming Server"
"C:\Games\TmNationsForever\TmForever.exe"="C:\Games\TmNationsForever\TmForever.exe:*:Enabled:TmForever"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.PIM1"=PCLEPIM1.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======List of files/folders created in the last 1 month======

2011-11-20 19:12:25 ----SHD---- C:\RECYCLER
2011-11-20 17:18:28 ----A---- C:\TDSSKiller.2.6.19.0_20.11.2011_17.18.28_log.txt
2011-11-20 16:35:13 ----D---- C:\UCTO2010
2011-11-20 16:22:12 ----D---- C:\WINDOWS\temp
2011-11-20 16:22:10 ----A---- C:\ComboFix.txt
2011-11-20 15:43:57 ----A---- C:\rc.exe
2011-11-20 10:14:04 ----A---- C:\TDSSKiller.2.6.19.0_20.11.2011_10.14.04_log.txt
2011-11-19 23:59:25 ----A---- C:\TDSSKiller.2.6.19.0_19.11.2011_23.59.25_log.txt
2011-11-19 23:06:25 ----A---- C:\WINDOWS\zip.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\SWSC.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\SWREG.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\sed.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\PEV.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\NIRCMD.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\MBR.exe
2011-11-19 23:06:25 ----A---- C:\WINDOWS\grep.exe
2011-11-19 23:06:19 ----D---- C:\WINDOWS\ERDNT
2011-11-19 23:06:14 ----D---- C:\Qoobox
2011-11-19 20:52:28 ----D---- C:\Program Files\trend micro
2011-11-19 20:52:27 ----D---- C:\rsit
2011-11-19 15:09:35 ----D---- C:\Documents and Settings\Masek\Data aplikací\Malwarebytes
2011-11-19 15:09:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-11-19 15:09:22 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-19 15:09:22 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-11-16 23:42:30 ----A---- C:\WINDOWS\system32\MRT.INI
2011-11-12 08:44:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2011-11-12 08:30:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2011-10-28 19:54:38 ----D---- C:\copy-pal
2011-10-22 13:05:42 ----D---- C:\Documents and Settings\Masek\Data aplikací\ESET

======List of files/folders modified in the last 1 month======

2011-11-20 20:54:51 ----A---- C:\WINDOWS\WINCMD.INI
2011-11-20 19:22:24 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-20 19:15:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-20 18:06:33 ----D---- C:\WINDOWS\Prefetch
2011-11-20 18:06:32 ----D---- C:\WINDOWS\network diagnostic
2011-11-20 17:18:28 ----D---- C:\WINDOWS\system32\drivers
2011-11-20 16:22:12 ----AD---- C:\WINDOWS
2011-11-20 16:18:34 ----A---- C:\WINDOWS\system.ini
2011-11-20 16:18:23 ----D---- C:\WINDOWS\system32\drivers\etc
2011-11-20 16:17:04 ----D---- C:\WINDOWS\system32\config
2011-11-20 16:14:06 ----D---- C:\WINDOWS\system32
2011-11-20 16:14:06 ----D---- C:\WINDOWS\AppPatch
2011-11-20 16:14:04 ----D---- C:\Program Files\Common Files
2011-11-20 15:41:24 ----D---- C:\Install
2011-11-19 23:39:58 ----SD---- C:\WINDOWS\Tasks
2011-11-19 23:33:59 ----DC---- C:\WINDOWS\$NtUninstallKB63231$
2011-11-19 21:33:20 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2011-11-19 20:52:28 ----RD---- C:\Program Files
2011-11-18 07:01:40 ----D---- C:\WINDOWS\Debug
2011-11-16 23:42:49 ----HD---- C:\WINDOWS\inf
2011-11-16 23:42:46 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-16 23:29:16 ----A---- C:\WINDOWS\system32\MRT.exe
2011-11-16 23:28:50 ----D---- C:\WINDOWS\system32\CatRoot
2011-11-16 21:44:27 ----D---- C:\WINDOWS\system32\wbem
2011-11-16 21:44:26 ----D---- C:\WINDOWS\Registration
2011-11-12 08:30:12 ----HD---- C:\WINDOWS\$hf_mig$
2011-11-03 22:55:49 ----D---- C:\WINDOWS\pss
2011-10-30 07:35:23 ----ASH---- C:\boot.ini
2011-10-30 07:35:23 ----A---- C:\WINDOWS\win.ini
2011-10-30 04:52:46 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-10-28 20:07:22 ----SHD---- C:\WINDOWS\Installer
2011-10-22 13:02:26 ----D---- C:\Program Files\ESET
2011-10-22 13:02:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 IdeBusDr;IdeBusDr; C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys [2002-08-14 13782]
R0 IdeChnDr;Intel(R) Ultra ATA Controller; C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys [2002-08-14 93594]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-10-07 115744]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 viamraid;viamraid; C:\WINDOWS\system32\DRIVERS\viamraid.sys [2007-07-17 114944]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2011-08-04 61936]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R2 PfModNT;PfModNT; \??\C:\WINDOWS\system32\PfModNT.sys []
R2 SBKUPNT;SBKUPNT; \??\C:\WINDOWS\system32\Drivers\SBKUPNT.SYS []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-04-21 729088]
R3 bcm4sbxp;ASUSTeK/Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2002-09-10 41728]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2011-08-09 39824]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 PinnacleRoyalTS;Pinnacle Systems RoyalTS Device; C:\WINDOWS\system32\DRIVERS\RoyalTS.sys [2008-12-15 123520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\system32\ASNDIS5.SYS []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DynCal;Dynamic Calibration Service; C:\WINDOWS\system32\drivers\Dyncal.sys [2007-11-07 12928]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-07-30 18048]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-07-26 137600]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pctvvbi;PCTVVBI; C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-11-11 6400]
S3 sbpci;Sound Blaster PCI128 Audio Driver (WDM); C:\WINDOWS\system32\drivers\sbpci.sys [2002-07-11 667136]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2004-04-21 397312]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTSvcCDA.exe [1999-12-13 44032]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2011-09-22 974944]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2004-04-21 516096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-10-20 630272]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Eset zklamal prosím o pomoc

Napsal: 20 lis 2011 22:41
od e_mysak
Účto - teoreticky ano ale po nezdařené obnově jsem si do c: zapsal prázdný adresář a ten se asi objevil v některé hlášce.Pokud mohu poslední dotaz mám od Esetu Security 5 koupenou (upgrade) před měsícem,před tím jsem používal NOD32 Antivirus nevím zda jsem neměl zůstat u Antiviru.Zároveň používám velmi často CCleaner, snad to je dostačující.Ten problém co jsme odstraňovali vznikl po návštěvě vnuka bohužel bez dohledu tak asi kouk kam zatím neměl.Je mi ale divné že Esetu vir Sirefef.DA prošel až do paměti. Pokud bude vše vpořádku prosím o sdělení zda budem rušit použité prográmky MBAM, TDSS a CF.

Re: Eset zklamal prosím o pomoc

Napsal: 23 lis 2011 20:19
od e_mysak
Tak jsem konečně zmákl účto a zkusil zadat jak jste napsal pro výmaz ComboFix ale vypsalo mi to hlášku že systém nemůže najít příkaz Combofix/uninstall takže se neprovedl.S dalším mazáním počkám až jak. :(

Eset se včera trochu plašil a vypsalo to:
objekt : c:\SystemVolumeInformation\_restore{1375444F-A743-4BC5-B042-DFE9A6E573D9}\RP614\A017
hrozba : Varianta infiltrace Win32/Toollbar.Cravler nechtěná aplikace
chyba při léčení: Tato skutečnost zjištěna na modifikovaném souboru aplikací
c:\WINDOWS\System32\svchost.exe
zabarvení rámce bylo oranžové,dál a ani dnes se nic nedělo, včera to nabídlo léčit - storno
léčit nešlo dal jsem storno

Re: Eset zklamal prosím o pomoc

Napsal: 24 lis 2011 22:50
od e_mysak
Když jsem zapsal přesně ComboFix /Uninstall tak se snažil CF spustit stejně tak jak jsme jej pouštěli,došel k hlášce zda má vypnout ESET překvapilo mne to a nebyl jsem jist jak dál tak jsem pro jistotu vypnul síťový vypinač.Připadá mi že mi tam někde ten Uninstall chybí.

Re: Eset zklamal prosím o pomoc

Napsal: 26 lis 2011 22:23
od e_mysak
Teprve dnes jsem se dostal k PC, udělal jsem dle pokynu, vše proběhlo správně CF je odinstalován. Pokud se mohu ještě zeptat,po našem nahánění a odstranění breberek z PC se mi nyní stává dost pravidelně, pracujeli se na PC krátkou dobu do cca 5 min tak odhlášení a vypnutí proběhne normálně ale jeli PC v provozu déle cca hodinu i více tak po potvrzení příkazu vypnout PC se vypne pouze monitor (připadá mi ale že přejde pouze do režimu spanku) a zbytek PC běží dále.(není v některém registru nějaká drobnost která to způsobuje?)Před problémem to fungovalo normálně.

Re: Eset zklamal prosím o pomoc

Napsal: 27 lis 2011 18:05
od e_mysak
Zdravím, u tlačítka napájení je zvolen povel "vypnout". Jenom tak na okraj, myslím že to sem do rubliky již nepatří. Pokud si matně vzpomínám tak podobný problém se mi vyskytl cca před čtyřmi roky začlo to tehdy zlobit když jsem měl spuštěn TV program (používám kartu PCTV a program TVCenter Pro od Pinnacle) večír šel nějaký program a nastavil jsem nahrávání s tím aby se PC vyplo po ukončení.Bohužel PC zůstalo zaplé až do rána a napravo v hlavním panelu se objevila malá ikonka od Pinnacle.Pokud tam byla tak PC vypnout běžným postupem nešlo.Když jsem ji zrušil tak vypnutí proběhlo, ale po opětovném zapnutí PC se vždy vytvořila znovu.Povedlo se mi ji tenkrát odstranit v registru.Nyní v hlavním panelu napravo ale nic co tam nepatří není.Zkusím také zapátrat.
Jinak děkuji moc za pomoc s hlavním problémem.Nyní se PC chová normálně,ještě jsem vyházel pomocí CCl pár zbytečností které se spouštěly při zapnutí a tak se i toto zrychlilo.Pokud by Vás přeci jenom něco napadlo dejte vědět.

Re: Eset zklamal prosím o pomoc

Napsal: 26 pro 2011 10:11
od e_mysak
Tak jsem hledal příčinu proč se PC nechtělo vypnout.Moc nic jsem neobjevil,pouze drobný poznatek.Dříve jsem spouštěl vypnutí bez ohledu zda jsem byl já i další uživatel řádně odhlášen a v podstatě to šlo, potom po vyčištění PC již ne.Tak jsem se vrátil k vypínání až po řádném odhlášení a to funguje bez problému.
Takže ještě jednou velké díky za pomoc a přeji hezké vánoce, úspěšný zbytek roku,jiskru v oku,sílu v rozkroku,jistotu ve skoku,nebýt bez floku,střílet od boku a nebát se roku 2012.
Vše nej Mašek J. :)