Stránka 1 z 1

Superantispyware

Napsal: 22 led 2012 12:48
od ringov
Superantispyware mi nasiel toto SUPERAntiSpyware Scan Log a prikladam log z Rsite
http://www.superantispyware.com

Generated 01/22/2012 at 12:18 PM

Application Version : 5.0.1132

Core Rules Database Version : 8153
Trace Rules Database Version: 5965

Scan type : Quick Scan
Total Scan Time : 00:06:45

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned : 366
Memory threats detected : 0
Registry items scanned : 16373
Registry threats detected : 1
File items scanned : 6464
File threats detected : 0

Disabled.SecurityCenterOption
HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#FIREWALLDISABLENOTIFY
//////////////Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2012-01-22 12:47:37
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (22%) free of 8 GB
Total RAM: 511 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:48:12, on 22.1.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
D:\ANTIVIRY\Ashampoo FireWall FREE 1.20\Ashampoo FireWall\FireWall.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
D:\ANTIVIRY\Superantispyware\SASCORE.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
C:\Program Files\Trend Micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Ashampoo FireWall] "D:\ANTIVIRY\Ashampoo FireWall FREE 1.20\Ashampoo FireWall\FireWall.exe" -TRAY
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\ANTIVIRY\Superantispyware\SUPERAntiSpyware.exe
O20 - Winlogon Notify: !SASWinLogon - D:\ANTIVIRY\Superantispyware\SASWINLO.DLL
O20 - Winlogon Notify: Antiwpa - antiwpa.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - D:\ANTIVIRY\Superantispyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Unknown owner - D:\ANTIVIRY\Avira\Avira\AntiVir Desktop\sched.exe (file missing)
O23 - Service: Avira Realtime Protection (AntiVirService) - Unknown owner - D:\ANTIVIRY\Avira\Avira\AntiVir Desktop\avguard.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

--
End of file - 3166 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\MpIdleTask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Ashampoo FireWall"=D:\ANTIVIRY\Ashampoo FireWall FREE 1.20\Ashampoo FireWall\FireWall.exe [2007-04-05 3251800]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SUPERAntiSpyware"=D:\ANTIVIRY\Superantispyware\SUPERAntiSpyware.exe [2011-10-12 4615552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20.exe [2007-02-26 437160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UIWatcher]
D:\UTILITY\Ashampoo\AshampooUninstaler\Ashampoo UnInstaller 4\UIWatcher.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sdCoreService"=2
"sdAuxService"=2
"sp_rssrv"=2
"cmdAgent"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
D:\ANTIVIRY\Superantispyware\SASWINLO.DLL [2011-05-04 551296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa]
C:\WINDOWS\system32\antiwpa.dll [2008-07-09 60416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=D:\ANTIVIRY\Superantispyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoInstrumentation"=1
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"HonorAutoRunSetting"=1
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=C:\WINDOWS\system32\ir32_32.dll
"vidc.iv32"=C:\WINDOWS\system32\ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=serwvdrv.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.iv50"=ir50_32.dll
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"VIDC.IV41"=IR41_32.AX
"wave2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave4"=serwvdrv.dll
"wave5"=serwvdrv.dll
"midi"=wdmaud.drv
"wave6"=serwvdrv.dll

======List of files/folders created in the last 1 month======

2012-01-22 12:08:54 ----D---- C:\Documents and Settings\Administrator\Data aplikací\SUPERAntiSpyware.com
2012-01-22 12:01:34 ----D---- C:\Program Files\Defraggler
2012-01-22 11:05:29 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-01-21 17:33:12 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2012-01-21 17:25:46 ----D---- C:\Program Files\Microsoft Security Client
2012-01-21 16:41:27 ----A---- C:\WINDOWS\system32\WgaTray.exe
2012-01-21 16:41:27 ----A---- C:\WINDOWS\system32\WgaLogon.dll
2012-01-21 16:41:25 ----A---- C:\WINDOWS\system32\OGACheckControl.dll
2012-01-21 16:34:43 ----A---- C:\WINDOWS\system32\antiwpa.dll
2012-01-18 17:14:50 ----A---- C:\WINDOWS\system32\drivers\revoflt.sys
2012-01-18 16:35:20 ----D---- C:\WINDOWS\fonts\AdvUninstal
2012-01-18 16:35:08 ----D---- C:\Program Files\Common Files\Innovative Solutions
2012-01-18 16:07:48 ----A---- C:\WINDOWS\system32\mfc45.dll
2012-01-18 16:07:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\iolo
2012-01-18 16:07:40 ----D---- C:\Documents and Settings\Administrator\Data aplikací\iolo
2012-01-15 14:47:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ashampoo
2012-01-15 11:57:41 ----D---- C:\_OTM
2012-01-11 19:06:18 ----D---- C:\ProgramData
2012-01-11 17:22:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\CheckPoint
2012-01-10 17:34:03 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
2012-01-10 17:33:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-01-10 15:56:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2012-01-08 09:55:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2012-01-07 08:10:32 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-01-05 08:45:34 ----D---- C:\rsit
2012-01-05 08:12:57 ----A---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2012-01-05 08:12:56 ----A---- C:\WINDOWS\system32\mdmxsdk.dll

======List of files/folders modified in the last 1 month======

2012-01-22 12:48:02 ----D---- C:\WINDOWS\temp
2012-01-22 12:47:48 ----D---- C:\Program Files\Trend Micro
2012-01-22 12:47:07 ----SHD---- C:\System Volume Information
2012-01-22 12:01:34 ----RD---- C:\Program Files
2012-01-22 12:00:15 ----D---- C:\WINDOWS\Prefetch
2012-01-22 11:11:34 ----SD---- C:\WINDOWS\Tasks
2012-01-22 11:06:51 ----D---- C:\WINDOWS\system32\CatRoot2
2012-01-22 11:06:02 ----D---- C:\WINDOWS
2012-01-22 11:05:29 ----D---- C:\WINDOWS\system32
2012-01-22 11:05:27 ----D---- C:\Config.Msi
2012-01-21 17:45:08 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-01-21 17:41:06 ----HD---- C:\WINDOWS\inf
2012-01-21 17:29:32 ----D---- C:\WINDOWS\system32\drivers
2012-01-21 17:27:22 ----SHD---- C:\WINDOWS\Installer
2012-01-21 17:26:57 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-01-21 17:11:48 ----D---- C:\WINDOWS\assembly
2012-01-21 17:05:00 ----HD---- C:\WINDOWS\$hf_mig$
2012-01-21 16:59:23 ----D---- C:\WINDOWS\system32\CatRoot
2012-01-21 16:54:48 ----D---- C:\WINDOWS\SoftwareDistribution
2012-01-18 16:35:20 ----RSD---- C:\WINDOWS\Fonts
2012-01-18 16:35:08 ----D---- C:\Program Files\Common Files
2012-01-18 16:07:40 ----D---- C:\WINDOWS\system32\config
2012-01-11 17:35:01 ----D---- C:\WINDOWS\system32\drivers\etc
2012-01-08 13:29:27 ----D---- C:\WINDOWS\WinSxS
2012-01-08 11:03:06 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2012-01-07 12:55:15 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-07 10:41:14 ----D---- C:\WINDOWS\system32\NtmsData
2012-01-07 10:30:33 ----D---- C:\WINDOWS\Registration
2012-01-07 09:38:50 ----D---- C:\WINDOWS\system32\Restore
2012-01-05 08:18:14 ----A---- C:\WINDOWS\system32\VGAunistlog.ini
2012-01-05 08:13:05 ----D---- C:\WINDOWS\system32\ReinstallBackups

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2008-04-13 40960]
R0 SiSide;SiSide; C:\WINDOWS\system32\DRIVERS\siside.sys [2000-01-01 4096]
R0 sisidex;sisidex; C:\WINDOWS\system32\drivers\sisidex.sys [2000-01-01 49024]
R0 sisperf;Add Performance Filter Driver; C:\WINDOWS\system32\drivers\sisperf.sys [2000-01-01 9472]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKsl9ad868c3;MpKsl9ad868c3; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{BCB3C6A0-A6CB-4216-B188-D08DFA83BFE1}\MpKsl9ad868c3.sys []
R1 SASDIFSV;SASDIFSV; \??\D:\ANTIVIRY\Superantispyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\D:\ANTIVIRY\Superantispyware\SASKUTIL.SYS []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 ASFWHide;ASFWHide; \??\C:\WINDOWS\TEMP\ASFWHide []
R3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
R3 swmsflt;swmsflt; C:\WINDOWS\System32\drivers\swmsflt.sys [2008-09-16 26888]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S0 dwshd;dwshd; C:\WINDOWS\system32\drivers\dwshd.sys []
S1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys []
S1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys []
S1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys []
S2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys []
S2 cmfd;cmfd; \??\D:\FIREWALLY\ComodoFirewall\cmfd.sys []
S3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.sys []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\drivers\AmdLLD.sys []
S3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 PRODIGY;PRODIGY; C:\WINDOWS\System32\Drivers\PRODIGY.SYS [2006-08-29 32377]
S3 Revoflt;Revoflt; C:\WINDOWS\system32\DRIVERS\revoflt.sys [2009-12-30 27064]
S3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
S3 S3SAVAGE4;S3SAVAGE4; C:\WINDOWS\system32\DRIVERS\s3savg4m.sys [2000-08-10 84704]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SWUMX20;Sierra Wireless USB MUX Driver (UMTS20); C:\WINDOWS\system32\DRIVERS\swumx20.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; D:\ANTIVIRY\Superantispyware\SASCORE.EXE [2011-08-12 116608]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 AntiVirService;Avira Realtime Protection; D:\ANTIVIRY\Avira\Avira\AntiVir Desktop\avguard.exe []
S2 AntiVirSchedulerService;Avira Scheduler; D:\ANTIVIRY\Avira\Avira\AntiVir Desktop\sched.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-12-11 252064]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Superantispyware

Napsal: 22 led 2012 13:01
od Rudy
Zdravím!
Vidím tam zbytky po cracku Win. Jak je to s legalitou vašeho OS?

Re: Superantispyware

Napsal: 22 led 2012 13:22
od ringov
To som len skusal lebo mi nechcelo aktualizovet framework ,ale este avast v tom aktivatoru nasiel virus tak som dal prec,to len preto lebo ten win mame dost dlho a cd win uz asi nemame.Tak prepecte .Ked mozte pomozte ked nie tak nie ,aj tak diky. :?:

Re: Superantispyware

Napsal: 22 led 2012 13:47
od Rudy
SaS hlásí, že je vypnut fw. Jak je to doopravdy?

Re: Superantispyware

Napsal: 22 led 2012 13:55
od ringov
Mam Ashampoo firewall a je stale zapnuty.

Re: Superantispyware

Napsal: 22 led 2012 14:00
od Rudy
Udělejte tedy kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: Superantispyware

Napsal: 22 led 2012 15:19
od ringov
musael som prerusit lebo islo to dost dlho,musim ist za chvilu prec,ale naslo daco//////////////Malwarebytes Anti-Malware 1.60.0.1800
http://www.malwarebytes.org

Verzia databázy: v2012.01.22.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: TEREZIA [administrátor]

22.1.2012 14:08:40
mbam-log-2012-01-22 (15-16-55).txt

Typ kontroly: Úplná kontrola
Možnosti kontroly zapnuté: Pamäť | Po spustení | Registre | Systémové súbory | Heuristika/Extra | Heuristika/Shuriken | PUP | PUM
Možnosti kontroly vypnuté: P2P
Objektov kontrolovaných: 61859
Uplynutý čas: 1 hod, 7 min, 37 sek [zrušené]

Detegované služby pamäte: 0
(Škodlivé položky neboli zistené)

Detegované moduly pamäte: 1
C:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Žiadna úloha nevykonaná.

Detegované registračné kľúče: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa (PUP.Wpakill) -> Žiadna úloha nevykonaná.

Detegované registračné hodnoty: 0
(Škodlivé položky neboli zistené)

Detegované položky registračných dát: 0
(Škodlivé položky neboli zistené)

Detegované priečinky: 0
(Škodlivé položky neboli zistené)

Detegované súbory: 1
C:\WINDOWS\system32\antiwpa.dll (PUP.Wpakill) -> Žiadna úloha nevykonaná.

(koniec) Mozem to vymazat?

Re: Superantispyware

Napsal: 22 led 2012 17:23
od Rudy
Nalezené položky smažte.

Re: Superantispyware

Napsal: 24 led 2012 15:37
od ringov
Dakujem,co to bol za virus?

Re: Superantispyware

Napsal: 24 led 2012 17:52
od Rudy
To jsou právě ty zbytky po cracku Win.