Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vyčistenie od bordelu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Toxisteel
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 13 pro 2011 18:14

Vyčistenie od bordelu

#1 Příspěvek od Toxisteel »

Zdravím,

Po mojom predošlom vyriešeným problémom s vírusmi by som sa chcel zbaviť bordelu na notebooku mojich rodičov... a aby tento nb pracoval rýchlejšie , lebo často tu vídim program neodpovedá . Takže ak máte čas , tak mi môžte pomocť , vdaka za každú radu.
Logfile of random's system information tool 1.09 (written by random/random)
Run by admin at 2011-12-16 20:27:09
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 13 GB (44%) free of 30 GB
Total RAM: 2039 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:27:18, on 16. 12. 2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MP4 Player\mp4Player.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\eInstruction\Device Manager\Launch.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
F:\data\Preberanie\RSIT.exe
C:\Program Files\trend micro\admin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1708250
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\prxtbSof0.dll
R3 - URLSearchHook: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\prxtbFre0.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Softonic-Eng7 - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\prxtbSof0.dll
O2 - BHO: Free Lunch Design - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\prxtbFre0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O3 - Toolbar: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\prxtbSof0.dll
O3 - Toolbar: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\prxtbFre0.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TNod UP] "C:\Program Files\ESET\ESET Smart Security\T nod\TNODUP.exe" /i
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MP4 Player] "C:\Program Files\MP4 Player\mp4Player.exe" hmw
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: eInstruction Device Manager.lnk = C:\Program Files\eInstruction\Device Manager\Launch.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: bgbvzje - bgbvzje.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Plánovač úloh (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/admin/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 8763 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc8e3a33382d4e.job
C:\WINDOWS\tasks\WGASetup.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\admin\Data aplikací\Mozilla\Firefox\Profiles\zek15swz.default

prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT24052 ... hSource=13"
prefs.js - "extensions.enabledItems" - "{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}:2.0.4.1, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:2.7.1.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.16"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat

C:\Program Files\Mozilla Firefox\plugins\
npDivxPlayerPlugin.dll
npnul32.dll
nsIDivxPlayerPlugin.xpt

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Documents and Settings\admin\Data aplikací\Mozilla\Firefox\Profiles\zek15swz.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}

C:\Documents and Settings\admin\Data aplikací\Mozilla\Firefox\Profiles\zek15swz.default\searchplugins\
conduit.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\prxtbSof0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\prxtbFre0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-12-03 342192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll [2011-12-03 1003576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\prxtbSof0.dll [2011-01-17 175912]
{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\prxtbFre0.dll [2011-01-17 175912]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-12-03 342192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-05-22 137752]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-01-05 872448]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-08-12 2215064]
"TNod UP"=C:\Program Files\ESET\ESET Smart Security\T nod\TNODUP.exe [2010-04-01 1811968]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-14 39408]
"MP4 Player"=C:\Program Files\MP4 Player\mp4Player.exe [2007-09-19 639488]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-11-13 247144]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
eInstruction Device Manager.lnk - C:\Program Files\eInstruction\Device Manager\Launch.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\bgbvzje]
bgbvzje.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-03-17 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0ajxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0fnxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0kuxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0mwxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0oyxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0tbxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1ckxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2aixx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3mwxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3ryxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3whxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4jsxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4krxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4nxxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4owxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4oyxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4uexx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5blxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6ktxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6raxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6yjxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7jtxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7owxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7pxxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7tcxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8dnxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8xhxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati0ajxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati0fnxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati0kuxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati0mwxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati0oyxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati0tbxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati1ckxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati2aixx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati3mwxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati3ryxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati3whxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati4jsxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati4krxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati4nxxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati4owxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati4oyxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati4uexx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati5blxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati6ktxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati6raxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati6yjxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati7jtxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati7owxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati7pxxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati7tcxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati8dnxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati8xhxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\wininet.exe"="C:\WINDOWS\system32\wininet.exe:*:Enabled:Windows XP Update"
"C:\Program Files\eInstruction\Device Manager\Launch.exe"="C:\Program Files\eInstruction\Device Manager\Launch.exe:*:Enabled:Launcher Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"vidc.tscc"=tsccvid.dll

======File associations======

.reg - open - regedit.exe "%1" %*
.scr - open - "%1" %*

======List of files/folders created in the last 1 month======

2011-12-16 20:27:09 ----D---- C:\rsit
2011-12-16 20:27:09 ----D---- C:\Program Files\trend micro
2011-12-16 20:05:38 ----D---- C:\WINDOWS\LastGood
2011-11-29 22:11:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2011-11-23 20:57:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$

======List of files/folders modified in the last 1 month======

2011-12-16 20:27:10 ----D---- C:\WINDOWS\Temp
2011-12-16 20:27:09 ----RD---- C:\Program Files
2011-12-16 20:22:54 ----D---- C:\Program Files\Mozilla Firefox
2011-12-16 20:06:26 ----HD---- C:\WINDOWS\inf
2011-12-16 20:05:38 ----D---- C:\WINDOWS\system32\CatRoot2
2011-12-16 20:05:38 ----D---- C:\WINDOWS
2011-12-14 16:54:03 ----D---- C:\Documents and Settings\admin\Data aplikací\PriceGong
2011-12-14 16:47:40 ----HD---- C:\WINDOWS\$hf_mig$
2011-12-13 17:46:54 ----D---- C:\Program Files\Softonic-Eng7
2011-12-13 17:46:47 ----D---- C:\Program Files\Free_Lunch_Design
2011-12-03 10:42:52 ----SHD---- C:\WINDOWS\Installer
2011-11-29 22:11:35 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-29 22:11:35 ----D---- C:\WINDOWS\system32
2011-11-29 21:07:03 ----A---- C:\WINDOWS\wincmd.ini
2011-11-23 20:58:10 ----A---- C:\WINDOWS\system32\MRT.exe
2011-11-23 20:58:06 ----A---- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-11-14 43528]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2010-08-03 55256]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2010-07-29 134512]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-04-24 281600]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2007-02-14 530861]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2007-02-14 30459]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2007-02-14 868298]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-02-14 149123]
R3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2007-02-14 30285]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2007-02-14 67960]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-12 250776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2010-07-29 32608]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2008-04-28 9344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-03-17 5955872]
R3 NETw5x32;Intel(R) Wireless WiFi Link Adapter Driver for Windows XP 32 Bit ; C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2008-04-28 3626112]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S0 ati0ajxx;ati0ajxx; C:\WINDOWS\System32\Drivers\ati0ajxx.sys []
S0 ati0fnxx;ati0fnxx; C:\WINDOWS\System32\Drivers\ati0fnxx.sys []
S0 ati0mwxx;ati0mwxx; C:\WINDOWS\System32\Drivers\ati0mwxx.sys []
S0 ati0oyxx;ati0oyxx; C:\WINDOWS\System32\Drivers\ati0oyxx.sys []
S0 ati0tbxx;ati0tbxx; C:\WINDOWS\System32\Drivers\ati0tbxx.sys []
S0 ati1ckxx;ati1ckxx; C:\WINDOWS\System32\Drivers\ati1ckxx.sys []
S0 ati2aixx;ati2aixx; C:\WINDOWS\System32\Drivers\ati2aixx.sys []
S0 ati3mwxx;ati3mwxx; C:\WINDOWS\System32\Drivers\ati3mwxx.sys []
S0 ati3ryxx;ati3ryxx; C:\WINDOWS\System32\Drivers\ati3ryxx.sys []
S0 ati3whxx;ati3whxx; C:\WINDOWS\System32\Drivers\ati3whxx.sys []
S0 ati4jsxx;ati4jsxx; C:\WINDOWS\System32\Drivers\ati4jsxx.sys []
S0 ati4krxx;ati4krxx; C:\WINDOWS\System32\Drivers\ati4krxx.sys []
S0 ati4nxxx;ati4nxxx; C:\WINDOWS\System32\Drivers\ati4nxxx.sys []
S0 ati4owxx;ati4owxx; C:\WINDOWS\System32\Drivers\ati4owxx.sys []
S0 ati4oyxx;ati4oyxx; C:\WINDOWS\System32\Drivers\ati4oyxx.sys []
S0 ati4uexx;ati4uexx; C:\WINDOWS\System32\Drivers\ati4uexx.sys []
S0 ati5blxx;ati5blxx; C:\WINDOWS\System32\Drivers\ati5blxx.sys []
S0 ati6ktxx;ati6ktxx; C:\WINDOWS\System32\Drivers\ati6ktxx.sys []
S0 ati6raxx;ati6raxx; C:\WINDOWS\System32\Drivers\ati6raxx.sys []
S0 ati6yjxx;ati6yjxx; C:\WINDOWS\System32\Drivers\ati6yjxx.sys []
S0 ati7jtxx;ati7jtxx; C:\WINDOWS\System32\Drivers\ati7jtxx.sys []
S0 ati7owxx;ati7owxx; C:\WINDOWS\System32\Drivers\ati7owxx.sys []
S0 ati7pxxx;ati7pxxx; C:\WINDOWS\System32\Drivers\ati7pxxx.sys []
S0 ati7tcxx;ati7tcxx; C:\WINDOWS\System32\Drivers\ati7tcxx.sys []
S0 ati8dnxx;ati8dnxx; C:\WINDOWS\System32\Drivers\ati8dnxx.sys []
S0 ati8xhxx;ati8xhxx; C:\WINDOWS\System32\Drivers\ati8xhxx.sys []
S2 DgiVecp;DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2007-12-11 12800]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-02-06 266295]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-30 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyčistenie od bordelu

#2 Příspěvek od Rudy »

Také zdravím!
PC není odvirován ani zdaleka. Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Toxisteel
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 13 pro 2011 18:14

Re: Vyčistenie od bordelu

#3 Příspěvek od Toxisteel »

Aha trošku si to zle pochopil, myslel som to tak , že po ocistený mojho osobného PC , som chcel ocistit aj NB mojich rodičov , taže asi tak , oK začínam CLEANING :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyčistenie od bordelu

#4 Příspěvek od Rudy »

Jde o to, že PC není zcela vyčištěn. Jsou tam položky, které by tam být neměly.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Toxisteel
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 13 pro 2011 18:14

Re: Vyčistenie od bordelu

#5 Příspěvek od Toxisteel »

ComboFix 11-12-16.03 - admin . 12. 2011 21:58:57.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2039.1322 [GMT 1:00]
Spuštěný z: f:\data\Preberanie\ComboFix.exe
AV: ESET Smart Security 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezidentní štít AV je zapnutý
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\admin\LOCALS~1\Temp\abt16599\BTCheckWC.dll
c:\docume~1\admin\LOCALS~1\Temp\abt33570\BTCheckMS.dll
c:\docume~1\admin\LOCALS~1\Temp\abt94528\avetanaBT.dll
c:\documents and settings\admin\Local Settings\Temp\abt16599\BTCheckWC.dll
c:\documents and settings\admin\Local Settings\Temp\abt33570\BTCheckMS.dll
c:\documents and settings\admin\Local Settings\Temp\abt94528\avetanaBT.dll
c:\windows\iun6002.exe
c:\windows\msmqinst.log
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\ST6UNST.000
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-16 do 2011-12-16 )))))))))))))))))))))))))))))))
.
.
2011-12-16 19:27 . 2011-12-16 19:27 -------- d-----w- C:\rsit
2011-12-16 19:27 . 2011-12-16 19:27 -------- d-----w- c:\program files\trend micro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2008-09-20 09:28 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-17 13:49 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-10-25 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-10-25 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\prxtbSof0.dll" [2011-01-17 175912]
"{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}"= "c:\program files\Free_Lunch_Design\prxtbFre0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2011-01-17 14:54 175912 ----a-w- c:\program files\Softonic-Eng7\prxtbSof0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
2011-01-17 14:54 175912 ----a-w- c:\program files\Free_Lunch_Design\prxtbFre0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\prxtbSof0.dll" [2011-01-17 175912]
"{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}"= "c:\program files\Free_Lunch_Design\prxtbFre0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\prxtbSof0.dll" [2011-01-17 175912]
"{57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC}"= "c:\program files\Free_Lunch_Design\prxtbFre0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-14 39408]
"MP4 Player"="c:\program files\MP4 Player\mp4Player.exe" [2007-09-19 639488]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-06-03 177456]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-05-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-05-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-05-22 137752]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-08-12 2215064]
"TNod UP"="c:\program files\ESET\ESET Smart Security\T nod\TNODUP.exe" [2010-04-01 1811968]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
eInstruction Device Manager.lnk - c:\program files\eInstruction\Device Manager\Launch.exe [2010-4-8 306416]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0ajxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0fnxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0mwxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0oyxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0tbxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1ckxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2aixx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3mwxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3ryxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3whxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4jsxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4krxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4nxxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4owxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4oyxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4uexx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5blxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6ktxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6raxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6yjxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7jtxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7owxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7pxxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7tcxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8dnxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8xhxx.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eInstruction\\Device Manager\\Launch.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29. 7. 2010 12:31 115008]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [12. 8. 2010 13:16 810144]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [13. 11. 2009 12:31 92008]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [20. 9. 2008 11:26 193840]
S0 ati0ajxx;ati0ajxx;c:\windows\system32\Drivers\ati0ajxx.sys --> c:\windows\system32\Drivers\ati0ajxx.sys [?]
S0 ati0fnxx;ati0fnxx;c:\windows\system32\Drivers\ati0fnxx.sys --> c:\windows\system32\Drivers\ati0fnxx.sys [?]
S0 ati0mwxx;ati0mwxx;c:\windows\system32\Drivers\ati0mwxx.sys --> c:\windows\system32\Drivers\ati0mwxx.sys [?]
S0 ati0oyxx;ati0oyxx;c:\windows\system32\Drivers\ati0oyxx.sys --> c:\windows\system32\Drivers\ati0oyxx.sys [?]
S0 ati0tbxx;ati0tbxx;c:\windows\system32\Drivers\ati0tbxx.sys --> c:\windows\system32\Drivers\ati0tbxx.sys [?]
S0 ati1ckxx;ati1ckxx;c:\windows\system32\Drivers\ati1ckxx.sys --> c:\windows\system32\Drivers\ati1ckxx.sys [?]
S0 ati2aixx;ati2aixx;c:\windows\system32\Drivers\ati2aixx.sys --> c:\windows\system32\Drivers\ati2aixx.sys [?]
S0 ati3mwxx;ati3mwxx;c:\windows\system32\Drivers\ati3mwxx.sys --> c:\windows\system32\Drivers\ati3mwxx.sys [?]
S0 ati3ryxx;ati3ryxx;c:\windows\system32\Drivers\ati3ryxx.sys --> c:\windows\system32\Drivers\ati3ryxx.sys [?]
S0 ati3whxx;ati3whxx;c:\windows\system32\Drivers\ati3whxx.sys --> c:\windows\system32\Drivers\ati3whxx.sys [?]
S0 ati4jsxx;ati4jsxx;c:\windows\system32\Drivers\ati4jsxx.sys --> c:\windows\system32\Drivers\ati4jsxx.sys [?]
S0 ati4krxx;ati4krxx;c:\windows\system32\Drivers\ati4krxx.sys --> c:\windows\system32\Drivers\ati4krxx.sys [?]
S0 ati4nxxx;ati4nxxx;c:\windows\system32\Drivers\ati4nxxx.sys --> c:\windows\system32\Drivers\ati4nxxx.sys [?]
S0 ati4owxx;ati4owxx;c:\windows\system32\Drivers\ati4owxx.sys --> c:\windows\system32\Drivers\ati4owxx.sys [?]
S0 ati4oyxx;ati4oyxx;c:\windows\system32\Drivers\ati4oyxx.sys --> c:\windows\system32\Drivers\ati4oyxx.sys [?]
S0 ati4uexx;ati4uexx;c:\windows\system32\Drivers\ati4uexx.sys --> c:\windows\system32\Drivers\ati4uexx.sys [?]
S0 ati5blxx;ati5blxx;c:\windows\system32\Drivers\ati5blxx.sys --> c:\windows\system32\Drivers\ati5blxx.sys [?]
S0 ati6ktxx;ati6ktxx;c:\windows\system32\Drivers\ati6ktxx.sys --> c:\windows\system32\Drivers\ati6ktxx.sys [?]
S0 ati6raxx;ati6raxx;c:\windows\system32\Drivers\ati6raxx.sys --> c:\windows\system32\Drivers\ati6raxx.sys [?]
S0 ati6yjxx;ati6yjxx;c:\windows\system32\Drivers\ati6yjxx.sys --> c:\windows\system32\Drivers\ati6yjxx.sys [?]
S0 ati7jtxx;ati7jtxx;c:\windows\system32\Drivers\ati7jtxx.sys --> c:\windows\system32\Drivers\ati7jtxx.sys [?]
S0 ati7owxx;ati7owxx;c:\windows\system32\Drivers\ati7owxx.sys --> c:\windows\system32\Drivers\ati7owxx.sys [?]
S0 ati7pxxx;ati7pxxx;c:\windows\system32\Drivers\ati7pxxx.sys --> c:\windows\system32\Drivers\ati7pxxx.sys [?]
S0 ati7tcxx;ati7tcxx;c:\windows\system32\Drivers\ati7tcxx.sys --> c:\windows\system32\Drivers\ati7tcxx.sys [?]
S0 ati8dnxx;ati8dnxx;c:\windows\system32\Drivers\ati8dnxx.sys --> c:\windows\system32\Drivers\ati8dnxx.sys [?]
S0 ati8xhxx;ati8xhxx;c:\windows\system32\Drivers\ati8xhxx.sys --> c:\windows\system32\Drivers\ati8xhxx.sys [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29. 1. 2010 6:23 135664]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [29. 1. 2010 6:23 135664]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc8e3a33382d4e.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 05:23]
.
2011-12-16 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-08-29 21:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1708250
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 10.0.0.2
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\zek15swz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2405280&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Softonic-Eng7 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2405280&SearchSource=13
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: Free Lunch Design Toolbar: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - %profile%\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKU-Default-Run-[system] - c:\windows\system32\drivers\services.exe
Notify-bgbvzje - bgbvzje.dll
SafeBoot-ati0kuxx.sys
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-16 22:20
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(840)
c:\windows\system32\webcheck.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\program files\Common Files\Microsoft Shared\Web Components\10\1051\OWCI10.DLL
c:\windows\system32\btmmhook.dll
c:\windows\system32\msls31.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Celkový čas: 2011-12-16 22:25:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-16 21:25
.
Před spuštěním: Volných bajtů: 15 345 340 416
Po spuštění: Volných bajtů: 16 489 086 976
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - D9F8E3CC11C7749290DD518D0CE4D486

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyčistenie od bordelu

#6 Příspěvek od Rudy »

Ještě dočistíme. Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

Collect::
c:\windows\system32\Drivers\ati0ajxx.sys
c:\windows\system32\Drivers\ati0fnxx.sys
c:\windows\system32\Drivers\ati0mwxx.sys
c:\windows\system32\Drivers\ati0oyxx.sys
c:\windows\system32\Drivers\ati0tbxx.sys
c:\windows\system32\Drivers\ati1ckxx.sys
c:\windows\system32\Drivers\ati2aixx.sys
c:\windows\system32\Drivers\ati3mwxx.sys
c:\windows\system32\Drivers\ati3ryxx.sys
c:\windows\system32\Drivers\ati3whxx.sys
c:\windows\system32\Drivers\ati4jsxx.sys
c:\windows\system32\Drivers\ati4krxx.sys
c:\windows\system32\Drivers\ati4nxxx.sys
c:\windows\system32\Drivers\ati4owxx.sys
c:\windows\system32\Drivers\ati4oyxx.sys
c:\windows\system32\Drivers\ati4uexx.sys
c:\windows\system32\Drivers\ati5blxx.sys
c:\windows\system32\Drivers\ati6ktxx.sys
c:\windows\system32\Drivers\ati6raxx.sys
c:\windows\system32\Drivers\ati6yjxx.sys
c:\windows\system32\Drivers\ati7jtxx.sys
c:\windows\system32\Drivers\ati7owxx.sys
c:\windows\system32\Drivers\ati7pxxx.sys
c:\windows\system32\Drivers\ati7tcxx.sys
c:\windows\system32\Drivers\ati8dnxx.sys
c:\windows\system32\Drivers\ati8xhxx.sys

Folder::
c:\program files\ConduitEngine
c:\program files\Softonic-Eng7
c:\program files\Free_Lunch_Design
c:\program files\Google\Update

Driver::
ati0ajxx
ati0fnxx
ati0mwxx
ati0oyxx
ati0tbxx
ati1ckxx
ati2aixx
ati3mwxx
ati3ryxx
ati3whxx
ati4jsxx
ati4krxx
ati4nxxx
ati4owxx
ati4oyxx
ati4uexx
ati5blxx
ati6ktxx
ati6raxx
ati6yjxx
ati7jtxx
ati7owxx
ati7pxxx
ati7tcxx
ati8dnxx
ati8xhxx
gupdate
gupdatem

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0ajxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0fnxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0mwxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0oyxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0tbxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1ckxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2aixx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3mwxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3ryxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3whxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4jsxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4krxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4nxxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4owxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4oyxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4uexx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5blxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6ktxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6raxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6yjxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7jtxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7owxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7pxxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7tcxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8dnxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8xhxx.sys]

Firefox::
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\zek15swz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Softonic-Eng7 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT24052 ... hSource=13
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Toxisteel
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 13 pro 2011 18:14

Re: Vyčistenie od bordelu

#7 Příspěvek od Toxisteel »

Mi napísalo že script je zle vyhláskovaný ... a pritom som zadal dobre, CFSscript a uložiť jak .txt

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyčistenie od bordelu

#8 Příspěvek od Rudy »

Pokud toto CF napíše, pak není s názvem souboru něco v pořádku. Klikněte pravým myšítkem na soubor>přejmenovat a napište CFScript. Nic víc, nic míň a znovu zkuste.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Toxisteel
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 13 pro 2011 18:14

Re: Vyčistenie od bordelu

#9 Příspěvek od Toxisteel »

Čo treba este urobiť ???

tu je log... čo si mi napísal ten script...

ComboFix 11-12-19.01 - admin . 12. 2011 19:10:24.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2039.1403 [GMT 1:00]
Spuštěný z: f:\data\Preberanie\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\admin\Plocha\CFScript.txt
AV: ESET Smart Security 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ConduitEngine
c:\program files\ConduitEngine\appContextMenu.xml
c:\program files\ConduitEngine\ConduitEngin0.dll
c:\program files\ConduitEngine\ConduitEngine.dll
c:\program files\ConduitEngine\ConduitEngineHelper.exe
c:\program files\ConduitEngine\ConduitEngineUninstall.exe
c:\program files\ConduitEngine\engineContextMenu.xml
c:\program files\ConduitEngine\EngineSettings.json
c:\program files\ConduitEngine\prxConduitEngine.dll
c:\program files\ConduitEngine\toolbar.cfg
c:\program files\Free_Lunch_Design
c:\program files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe
c:\program files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper1.exe
c:\program files\Free_Lunch_Design\INSTALL.LOG
c:\program files\Free_Lunch_Design\ldrtbFre0.dll
c:\program files\Free_Lunch_Design\prxtbFre0.dll
c:\program files\Free_Lunch_Design\tbFre0.dll
c:\program files\Free_Lunch_Design\tbFre1.dll
c:\program files\Free_Lunch_Design\tbFree.dll
c:\program files\Free_Lunch_Design\toolbar.cfg
c:\program files\Free_Lunch_Design\uninstall.exe
c:\program files\Free_Lunch_Design\UNWISE.EXE
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.79\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.79\goopdate.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.79\psmachine.dll
c:\program files\Google\Update\1.3.21.79\psuser.dll
c:\program files\Google\Update\Download\{168F71C0-0C8A-44C9-8A82-E42E461D34D7}\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.79\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\16.0.912.63\chrome_updater.exe
c:\program files\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\7.2.2308.2056\GoogleToolbarInstaller_updater_signed.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Softonic-Eng7
c:\program files\Softonic-Eng7\INSTALL.LOG
c:\program files\Softonic-Eng7\ldrtbSof0.dll
c:\program files\Softonic-Eng7\prxtbSof0.dll
c:\program files\Softonic-Eng7\Softonic-Eng7ToolbarHelper.exe
c:\program files\Softonic-Eng7\Softonic-Eng7ToolbarHelper1.exe
c:\program files\Softonic-Eng7\tbSof0.dll
c:\program files\Softonic-Eng7\tbSof1.dll
c:\program files\Softonic-Eng7\tbSoft.dll
c:\program files\Softonic-Eng7\toolbar.cfg
c:\program files\Softonic-Eng7\uninstall.exe
c:\program files\Softonic-Eng7\UNWISE.EXE
c:\windows\msmqinst.log
c:\windows\system32\SET11E.tmp
c:\windows\system32\SET122.tmp
c:\windows\system32\SET123.tmp
c:\windows\system32\SET12A.tmp
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ATI5BLXX
-------\Legacy_GUPDATE
-------\Service_ati0ajxx
-------\Service_ati0fnxx
-------\Service_ati0mwxx
-------\Service_ati0oyxx
-------\Service_ati0tbxx
-------\Service_ati1ckxx
-------\Service_ati2aixx
-------\Service_ati3mwxx
-------\Service_ati3ryxx
-------\Service_ati3whxx
-------\Service_ati4jsxx
-------\Service_ati4krxx
-------\Service_ati4nxxx
-------\Service_ati4owxx
-------\Service_ati4oyxx
-------\Service_ati4uexx
-------\Service_ati5blxx
-------\Service_ati6ktxx
-------\Service_ati6raxx
-------\Service_ati6yjxx
-------\Service_ati7jtxx
-------\Service_ati7owxx
-------\Service_ati7pxxx
-------\Service_ati7tcxx
-------\Service_ati8dnxx
-------\Service_ati8xhxx
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-19 do 2011-12-19 )))))))))))))))))))))))))))))))
.
.
2011-12-16 19:27 . 2011-12-16 19:27 -------- d-----w- C:\rsit
2011-12-16 19:27 . 2011-12-16 19:27 -------- d-----w- c:\program files\trend micro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 14:40 . 2004-08-17 13:44 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:13 . 2004-08-17 13:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 19:13 . 2004-08-17 13:49 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:13 . 2004-08-17 13:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 11:23 . 2004-08-17 13:44 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-17 13:49 1288192 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:32 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-26 10:49 . 2004-08-17 15:45 2029056 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-26 10:49 . 2004-08-17 13:45 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-18 11:13 . 2004-08-17 13:49 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2008-09-20 09:28 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-17 13:49 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 17:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-10-25 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-10-25 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-16_21.21.05 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-08-28 15:16 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
+ 2009-08-28 15:16 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
- 2004-08-17 13:49 . 2011-08-22 23:41 66560 c:\windows\system32\mshtmled.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 66560 c:\windows\system32\mshtmled.dll
- 2009-03-08 02:31 . 2011-08-22 23:41 55296 c:\windows\system32\msfeedsbs.dll
+ 2009-03-08 02:31 . 2011-11-04 19:13 55296 c:\windows\system32\msfeedsbs.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 25600 c:\windows\system32\jsproxy.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 25600 c:\windows\system32\jsproxy.dll
+ 2010-07-06 12:01 . 2011-11-04 19:13 12800 c:\windows\system32\dllcache\xpshims.dll
- 2010-07-06 12:01 . 2011-08-22 23:41 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2010-07-06 12:01 . 2011-11-04 19:13 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2010-07-06 12:01 . 2011-08-22 23:41 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2009-12-14 07:10 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-12-14 07:10 . 2011-10-28 05:32 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 105984 c:\windows\system32\url.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 105984 c:\windows\system32\url.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 206848 c:\windows\system32\occache.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 206848 c:\windows\system32\occache.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 611840 c:\windows\system32\mstime.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 611840 c:\windows\system32\mstime.dll
- 2009-03-08 02:32 . 2011-08-22 23:41 602112 c:\windows\system32\msfeeds.dll
+ 2009-03-08 02:32 . 2011-11-04 19:13 602112 c:\windows\system32\msfeeds.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 184320 c:\windows\system32\iepeers.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 184320 c:\windows\system32\iepeers.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-17 13:49 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
+ 2004-08-17 13:49 . 2011-11-04 11:24 174080 c:\windows\system32\ie4uinit.exe
- 2008-09-20 11:19 . 2011-10-14 18:52 146016 c:\windows\system32\FNTCACHE.DAT
+ 2008-09-20 11:19 . 2011-12-17 12:24 146016 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-17 13:49 . 2011-11-04 19:13 916992 c:\windows\system32\dllcache\wininet.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 206848 c:\windows\system32\dllcache\occache.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 206848 c:\windows\system32\dllcache\occache.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 611840 c:\windows\system32\dllcache\mstime.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 611840 c:\windows\system32\dllcache\mstime.dll
+ 2010-07-06 12:01 . 2011-11-04 19:13 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2010-07-06 12:01 . 2011-08-22 23:41 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2010-07-06 12:01 . 2011-08-22 23:41 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2010-07-06 12:01 . 2011-11-04 19:13 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 184320 c:\windows\system32\dllcache\iepeers.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-07-06 12:01 . 2011-08-22 23:41 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-07-06 12:01 . 2011-11-04 19:13 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2004-08-17 13:49 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-17 13:49 . 2011-11-04 11:24 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2011-02-09 13:53 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-02-09 13:53 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2011-12-17 10:18 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2011-12-17 10:18 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2011-12-17 10:18 . 2011-08-22 23:41 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2011-12-17 10:18 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
- 2004-08-17 13:49 . 2011-08-22 23:41 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-17 13:49 . 2011-11-04 19:13 5978112 c:\windows\system32\mshtml.dll
- 2009-03-08 02:32 . 2011-08-22 23:41 2000384 c:\windows\system32\iertutil.dll
+ 2009-03-08 02:32 . 2011-11-04 19:13 2000384 c:\windows\system32\iertutil.dll
+ 2009-04-19 19:52 . 2011-11-23 14:40 1859584 c:\windows\system32\dllcache\win32k.sys
+ 2004-08-17 13:49 . 2011-11-04 19:13 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2004-08-17 13:49 . 2011-08-22 23:41 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2010-07-16 12:00 . 2011-11-01 16:07 1288192 c:\windows\system32\dllcache\ole32.dll
- 2009-08-28 17:31 . 2010-12-09 15:14 2194944 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-08-28 17:31 . 2011-10-26 10:50 2194944 c:\windows\system32\dllcache\ntoskrnl.exe
- 2009-08-28 17:31 . 2010-12-09 15:14 2029056 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-08-28 17:31 . 2011-10-26 10:49 2029056 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-10 17:09 . 2011-10-26 10:50 2071552 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-02-10 17:09 . 2010-12-09 15:14 2071552 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-08-28 17:31 . 2010-12-09 15:14 2150912 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-08-28 17:31 . 2011-10-26 10:49 2150912 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2004-08-17 13:49 . 2011-11-04 19:13 5978112 c:\windows\system32\dllcache\mshtml.dll
- 2010-07-06 12:01 . 2011-08-22 23:41 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2010-07-06 12:01 . 2011-11-04 19:13 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2011-12-17 10:18 . 2011-10-03 08:31 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2011-12-17 10:18 . 2011-08-22 23:41 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
+ 2009-08-28 17:31 . 2011-10-26 10:50 2194944 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-08-28 17:31 . 2010-12-09 15:14 2194944 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-08-28 17:31 . 2011-10-26 10:49 2029056 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-08-28 17:31 . 2010-12-09 15:14 2029056 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-10 17:09 . 2011-10-26 10:50 2071552 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-02-10 17:09 . 2010-12-09 15:14 2071552 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-08-28 17:31 . 2011-10-26 10:49 2150912 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2009-08-28 17:31 . 2010-12-09 15:14 2150912 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2010-07-06 11:48 . 2011-12-17 10:16 52988224 c:\windows\system32\MRT.exe
+ 2009-03-08 02:39 . 2011-11-05 13:13 11081728 c:\windows\system32\ieframe.dll
- 2009-03-08 02:39 . 2011-08-23 15:41 11081728 c:\windows\system32\ieframe.dll
+ 2010-07-06 12:01 . 2011-11-05 13:13 11081728 c:\windows\system32\dllcache\ieframe.dll
- 2010-07-06 12:01 . 2011-08-23 15:41 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-12-17 10:18 . 2011-08-23 15:41 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-14 39408]
"MP4 Player"="c:\program files\MP4 Player\mp4Player.exe" [2007-09-19 639488]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-06-03 177456]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-05-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-05-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-05-22 137752]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-08-12 2215064]
"TNod UP"="c:\program files\ESET\ESET Smart Security\T nod\TNODUP.exe" [2010-04-01 1811968]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
eInstruction Device Manager.lnk - c:\program files\eInstruction\Device Manager\Launch.exe [2010-4-8 306416]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eInstruction\\Device Manager\\Launch.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29. 7. 2010 12:31 115008]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [12. 8. 2010 13:16 810144]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [13. 11. 2009 12:31 92008]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [20. 9. 2008 11:26 193840]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-19 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-08-29 21:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1708250
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 10.0.0.2
FF - ProfilePath - c:\documents and settings\admin\Data aplikací\Mozilla\Firefox\Profiles\zek15swz.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: Free Lunch Design Toolbar: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - %profile%\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-conduitEngine - c:\program files\ConduitEngine\ConduitEngineUninstall.exe
AddRemove-Free_Lunch_Design Toolbar - c:\program files\Free_Lunch_Design\uninstall.exe
AddRemove-Softonic-Eng7 Toolbar - c:\program files\Softonic-Eng7\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-19 19:18
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(344)
c:\windows\system32\webcheck.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\program files\Common Files\Microsoft Shared\Web Components\10\1051\OWCI10.DLL
c:\windows\system32\btmmhook.dll
c:\windows\system32\msls31.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\agrsmsvc.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
.
**************************************************************************
.
Celkový čas: 2011-12-19 19:21:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-19 18:21
ComboFix2.txt 2011-12-16 21:25
.
Před spuštěním: Volných bajtů: 16 157 794 304
Po spuštění: Volných bajtů: 16 036 958 208
.
- - End Of File - - 84FBC35DA2B25C8410517DAF4D11D420

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119512
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vyčistenie od bordelu

#10 Příspěvek od Rudy »

Log již vypadá OK. Ještě odinstalujte ten crarcklý NOD a použijte některé free řešení: http://www.viry.cz/forum/viewforum.php?f=29 . Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět