Škodlivý software v pc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Avatar uživatele
Thor
Návštěvník
Návštěvník
Příspěvky: 137
Registrován: 13 Říj 2008 14:52

Škodlivý software v pc

#1 Příspěvek od Thor »

Dobrý den,
chtěl bych Vás poprosit o pomoc s vyčištěním počítače od škodlivého obsahu. Včera se mi začal podivně chovat počítač. Najednou se začal sekat a slyšel jsem jak HDD pracuje na plné obrátky a já jsem měl přitom zaplý jen film a nebyl ani v HD. Tak mi to přišlo divný a za chvíli mi to nedalo a raději jsem si spustil MWAV, abych se ujistil, že to není virem. A tohle byl výsledek! Přikládám log z RSITU a MWAVu.

Moc Vás prosím, jestli byste mi neporadili jak se toho zbavit. Předem děkuji :worship:

MWAV


Object "Zlob Trojan-Downloader" found in File System! Action Taken: No Action Taken.
Object "Zlob Trojan-Downloader" found in File System! Action Taken: No Action Taken.
Object "Fix Tool Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "Cutwail Trojan" found in File System! Action Taken: No Action Taken.
Object "DeadEye Spyware/Adware" found in File System! Action Taken: No Action Taken.
File D:\games\Angry.Birds.v1.5.1u1.cracked.READ.NFO-THETA\NFOviewer.exe infected by "Generic Downloader.x.TE (ES)" Virus! Action Taken: No Action Taken.
File D:\games\Call_Of_Duty_4_Crackfix_And_Keygen-Razor1911\crack\rzr-cod4.exe infected by "not-a-virus.Keygen.CoD4.TE (ES)" Virus! Action Taken: No Action Taken.
File D:\games\Call_Of_Duty_4_Crackfix_And_Keygen-Razor1911\rzr-cod4.exe infected by "not-a-virus.Keygen.CoD4.TE (ES)" Virus! Action Taken: No Action Taken.
File D:\hry\Kane & Lynch 2- Dog Days\steam_api.dll infected by "HackTool:Win32/Keygen.TE (ES)" Virus! Action Taken: No Action Taken.
File D:\instalacky\Battlefield.Bad.Company.2-RELOADED\rld-bbc2\rld-bbc2\Crack\rld-bbc2.exe infected by "Troj/Keygen-DM.TE (ES)" Virus! Action Taken: No Action Taken.
File D:\Nová složka\programy\Acronis Disk Director 10.0.2161 CZ\keygen.exe infected by "not-a-virus.Keygen.Acronis.TE (ES)" Virus! Action Taken: No Action Taken.
File D:\Nová složka\programy\PowerDVD 8\PowerDVD 8\cyberlink.powerdvd.8.0.1531.0-nope.exe infected by "Trojan.Packed.21948 (DB)" Virus! Action Taken: No Action Taken.
File D:\programy\WinRAR 3.7\patch.exe infected by "Generic17.IZF (ES)" Virus! Action Taken: No Action Taken.

RSIT
Logfile of random's system information tool 1.09 (written by random/random)
Run by Hej Rup at 2012-03-04 15:54:55
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 52 GB (52%) free of 101 GB
Total RAM: 3569 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:55:02, on 4.3.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\ASUS\GamerOSD\ATKFastUserSwitching.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Bluetooth Suite\BtvStack.exe
C:\Program Files\Bluetooth Suite\AthBtTray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\GamePark2\gpcl.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Hej Rup\Desktop\RSIT.exe
C:\Program Files\trend micro\Hej Rup.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = start.qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Hej Rup\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\IPS\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Hej Rup\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [AtherosBtStack] "C:\Program Files\Bluetooth Suite\BtvStack.exe"
O4 - HKLM\..\Run: [AthBtTray] "C:\Program Files\Bluetooth Suite\AthBtTray.exe"
O4 - HKLM\..\Run: [BCU] "C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: GamePark klient 2.lnk = C:\Program Files\GamePark2\gpcl.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O23 - Service: ASDR - Unknown owner - C:\Windows\System32\ASDR.exe
O23 - Service: ATK Fast User Switch Service (ATKFUSService) - ASUSTeK COMPUTER INC. - C:\Windows\system32\ATKFUSService.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® PROSet Monitoring Service - Intel Corporation - C:\Windows\system32\IProsetMonitor.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 9845 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Hej Rup\AppData\Roaming\Mozilla\Firefox\Profiles\td7cwbzm.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://google.cz"
prefs.js - "extensions.enabledItems" - "DTToolbar@toolbarnet.com:1.1.4.0024, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:3.2.5.2, {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.18"
prefs.js - "keyword.URL" - "http://www.wicso.com/search/?ie=UTF-8&o ... kPzIaxF&q="

"{BBDA0591-3099-440a-AA10-41764D9DB4DB}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\
"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_5_2


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdnu.dll
npdnu.xpt
npdnupdater2.dll
npdnupdater2.xpt
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Hej Rup\AppData\Roaming\Mozilla\Firefox\Profiles\td7cwbzm.default\extensions\
{0b38152b-1b20-484d-a11f-5e04a9b0661f}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

C:\Users\Hej Rup\AppData\Roaming\Mozilla\Firefox\Profiles\td7cwbzm.default\searchplugins\
aol-web-search.xml
conduit.xml
daemon-search.xml
google-search.xml
qipsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll [2011-12-09 436152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\IPS\IPSBHO.DLL [2011-03-31 210872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files\Bluetooth Suite\IEPlugIn.dll [2010-10-27 60576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\Hej Rup\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-02-10 119808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\18.7.0.13\coIEPlg.dll [2011-12-09 436152]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-11-02 9808488]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]
"AtherosBtStack"=C:\Program Files\Bluetooth Suite\BtvStack.exe [2010-10-27 486560]
"AthBtTray"=C:\Program Files\Bluetooth Suite\AthBtTray.exe [2010-10-27 302240]
"BCU"=C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe [2009-10-26 375000]
"ASUSGamerOSD"=C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [2009-07-30 380928]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-04-10 37888]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2011-07-05 421888]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2011-08-10 1313640]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-01-03 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-02 843712]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2011-12-21 6676808]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
GamePark klient 2.lnk - C:\Program Files\GamePark2\gpcl.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"ConsentPromptBehaviorAdmin"=0
"EnableLUA"=0
"PromptOnSecureDesktop"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.XVID"=xvidvfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-03-04 15:54:55 ----D---- C:\rsit
2012-03-04 15:54:55 ----D---- C:\Program Files\trend micro
2012-03-04 06:50:55 ----D---- C:\Windows\pss
2012-03-04 04:52:00 ----D---- C:\ProgramData\Comodo
2012-03-04 04:51:58 ----D---- C:\Program Files\COMODO
2012-03-04 03:49:22 ----AD---- C:\Windows\VDLL.DLL
2012-03-04 03:49:22 ----AD---- C:\Windows\system32\runouce.exe
2012-03-04 03:49:22 ----AD---- C:\Windows\rundll16.exe
2012-03-04 03:49:22 ----AD---- C:\Windows\RUNDL132.EXE
2012-03-04 03:49:22 ----AD---- C:\Windows\logo1_.exe
2012-03-04 03:49:22 ----AD---- C:\Windows\logo_1.exe
2012-03-04 03:47:20 ----A---- C:\Windows\system32\msvcr80.dll
2012-03-04 03:47:19 ----A---- C:\Windows\system32\msvcp80.dll
2012-03-04 03:47:18 ----A---- C:\Windows\system32\msvcp90.dll
2012-03-04 03:47:17 ----A---- C:\Windows\system32\msvcr90.dll
2012-03-04 03:47:16 ----A---- C:\Windows\system32\eEmpty.exe
2012-03-04 03:47:12 ----D---- C:\Program Files\Common Files\MicroWorld
2012-03-04 03:47:09 ----D---- C:\ProgramData\MicroWorld
2012-03-04 03:35:55 ----A---- C:\Windows\system32\easyupdatusapiu.dll
2012-03-04 03:34:15 ----D---- C:\Users\Hej Rup\AppData\Roaming\Tific
2012-03-04 03:14:43 ----D---- C:\Program Files\CCleaner
2012-03-03 17:36:42 ----A---- C:\Windows\system32\MRT.exe
2012-03-03 17:33:39 ----D---- C:\Windows\system32\SPReview
2012-03-03 17:33:04 ----D---- C:\Windows\system32\EventProviders
2012-03-03 17:00:41 ----A---- C:\Windows\d3dx.dat
2012-02-29 08:13:53 ----D---- C:\Program Files\Microsoft IntelliType Pro
2012-02-22 07:22:21 ----D---- C:\Users\Hej Rup\AppData\Roaming\WinRAR
2012-02-22 07:22:19 ----D---- C:\Program Files\WinRAR
2012-02-20 09:17:35 ----A---- C:\Windows\War3Unin.dat
2012-02-20 09:17:34 ----A---- C:\Windows\War3Unin.pif
2012-02-20 09:17:34 ----A---- C:\Windows\War3Unin.exe
2012-02-20 09:07:36 ----D---- C:\ProgramData\Ubisoft
2012-02-20 09:06:34 ----D---- C:\ProgramData\Solidshield
2012-02-20 09:03:08 ----D---- C:\Users\Hej Rup\AppData\Roaming\PunkBuster
2012-02-20 09:02:36 ----D---- C:\Program Files\Ubisoft
2012-02-20 09:02:22 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-02-20 09:02:22 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-02-20 09:02:22 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-02-20 09:02:22 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-02-20 09:02:22 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-02-20 09:02:22 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-02-20 09:02:21 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-02-20 09:02:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-02-20 09:02:19 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-02-20 09:02:19 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-02-20 09:02:19 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-02-20 09:02:19 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-02-20 09:02:19 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-02-20 09:02:18 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-02-20 09:02:18 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-02-20 09:02:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-02-20 09:02:18 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-02-20 09:02:18 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-02-20 09:02:17 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-02-20 09:02:17 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-02-20 09:02:17 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-02-20 09:02:17 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-02-20 09:02:17 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-02-20 09:02:16 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-02-20 09:02:16 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-02-20 09:02:16 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-02-20 09:02:16 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-02-20 09:02:15 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-02-20 09:02:15 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-02-20 09:02:14 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-02-20 09:02:14 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-02-20 09:02:14 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-02-20 09:02:13 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-02-20 09:02:13 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-02-20 09:02:12 ----A---- C:\Windows\system32\xinput1_3.dll
2012-02-20 09:02:12 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-02-20 09:02:12 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-02-20 09:02:11 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-02-20 09:02:11 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-02-20 09:02:10 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-02-20 09:02:09 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-02-20 09:02:09 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-02-20 09:02:09 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-02-20 09:02:09 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-02-20 09:02:09 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-02-20 09:02:09 ----A---- C:\Windows\system32\d3dx10.dll
2012-02-20 09:02:08 ----A---- C:\Windows\system32\xinput1_2.dll
2012-02-20 09:02:08 ----A---- C:\Windows\system32\xinput1_1.dll
2012-02-20 09:02:08 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-02-20 09:02:08 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-02-20 09:02:08 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-02-20 09:02:08 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-02-20 09:02:03 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-02-20 09:02:03 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-02-20 09:02:03 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-02-20 09:02:03 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-02-20 09:02:03 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-02-20 09:02:01 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-02-20 09:02:01 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-02-20 09:02:00 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-02-20 09:02:00 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\wininet.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\wextract.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\webcheck.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\vbscript.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\urlmon.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\url.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\pngfilt.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\occache.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\msrating.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\msls31.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\mshtmler.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\mshtmled.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\mshtml.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\mshta.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\msfeedssync.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\msfeedsbs.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\msfeeds.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\licmgr10.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\jsproxy.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\jscript9.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\jscript.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\inseng.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\imgutil.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\iexpress.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieUnatt.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieui.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\iesysprep.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\iesetup.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\iertutil.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\iernonce.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\iepeers.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieframe.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\iedkcs32.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieapfltr.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieapfltr.dat
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieakui.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieaksie.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ieakeng.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\IEAdvpack.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\ie4uinit.exe
2012-02-19 23:13:08 ----A---- C:\Windows\system32\icardie.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\dxtrans.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\dxtmsft.dll
2012-02-19 23:13:08 ----A---- C:\Windows\system32\admparse.dll
2012-02-19 23:01:48 ----A---- C:\Windows\system32\ntdll.dll
2012-02-19 23:01:47 ----A---- C:\Windows\system32\packager.dll
2012-02-19 23:01:44 ----A---- C:\Windows\system32\quartz.dll
2012-02-19 23:01:44 ----A---- C:\Windows\system32\qdvd.dll
2012-02-19 23:01:43 ----A---- C:\Windows\system32\webio.dll
2012-02-19 23:01:43 ----A---- C:\Windows\system32\sspisrv.dll
2012-02-19 23:01:43 ----A---- C:\Windows\system32\sspicli.dll
2012-02-19 23:01:43 ----A---- C:\Windows\system32\schannel.dll
2012-02-19 23:01:43 ----A---- C:\Windows\system32\secur32.dll
2012-02-19 23:01:43 ----A---- C:\Windows\system32\lsass.exe
2012-02-19 23:01:43 ----A---- C:\Windows\system32\lsasrv.dll
2012-02-19 23:01:43 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-02-19 23:01:43 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-02-19 23:01:43 ----A---- C:\Windows\system32\drivers\cng.sys
2012-02-19 23:01:42 ----A---- C:\Windows\system32\msvcrt.dll
2012-02-19 23:01:41 ----A---- C:\Windows\system32\shell32.dll
2012-02-19 23:01:40 ----A---- C:\Windows\system32\ntshrui.dll
2012-02-19 23:01:37 ----A---- C:\Windows\system32\win32k.sys

======List of files/folders modified in the last 1 month======

2012-03-04 15:54:55 ----D---- C:\Program Files
2012-03-04 15:54:34 ----D---- C:\Windows\system32\drivers
2012-03-04 15:53:50 ----D---- C:\ProgramData\NVIDIA
2012-03-04 07:17:28 ----D---- C:\Windows\system32\config
2012-03-04 07:17:27 ----D---- C:\Windows\Temp
2012-03-04 07:11:26 ----D---- C:\Windows\inf
2012-03-04 06:53:18 ----D---- C:\Windows\System32
2012-03-04 06:53:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-03-04 06:50:55 ----D---- C:\Windows
2012-03-04 06:49:17 ----D---- C:\Users\Hej Rup\AppData\Roaming\Skype
2012-03-04 05:07:52 ----D---- C:\Users\Hej Rup\AppData\Roaming\vlc
2012-03-04 04:56:04 ----SHD---- C:\Windows\Installer
2012-03-04 04:56:02 ----HD---- C:\ProgramData
2012-03-04 04:54:48 ----D---- C:\Program Files\DAEMON Tools Toolbar
2012-03-04 04:52:39 ----D---- C:\Windows\system32\DriverStore
2012-03-04 04:52:39 ----D---- C:\Windows\system32\catroot
2012-03-04 03:47:44 ----A---- C:\Windows\win.ini
2012-03-04 03:47:12 ----D---- C:\Program Files\Common Files
2012-03-04 03:45:16 ----SHD---- C:\System Volume Information
2012-03-04 03:44:51 ----D---- C:\Windows\Prefetch
2012-03-04 03:39:31 ----D---- C:\Windows\winsxs
2012-03-04 03:36:29 ----D---- C:\Windows\system32\NDF
2012-03-04 03:36:05 ----RD---- C:\Users
2012-03-04 03:36:03 ----D---- C:\Program Files\NVIDIA Corporation
2012-03-04 03:32:39 ----D---- C:\Windows\Logs
2012-03-04 03:31:24 ----D---- C:\Users\Hej Rup\AppData\Roaming\Winamp
2012-03-04 03:31:24 ----D---- C:\Users\Hej Rup\AppData\Roaming\DAEMON Tools Lite
2012-03-04 03:30:49 ----D---- C:\Windows\Panther
2012-03-04 03:30:49 ----D---- C:\Windows\Minidump
2012-03-04 03:30:49 ----D---- C:\Windows\debug
2012-03-04 03:30:38 ----RSD---- C:\Windows\assembly
2012-03-04 03:30:38 ----D---- C:\Windows\Microsoft.NET
2012-03-04 03:24:24 ----D---- C:\Program Files\Windows Mail
2012-03-04 03:24:23 ----D---- C:\Program Files\Windows Sidebar
2012-03-04 03:24:23 ----D---- C:\Program Files\Windows Portable Devices
2012-03-04 03:24:23 ----D---- C:\Program Files\Windows Photo Viewer
2012-03-04 03:24:23 ----D---- C:\Program Files\Windows Media Player
2012-03-04 03:24:23 ----D---- C:\Program Files\Windows Journal
2012-03-04 03:24:23 ----D---- C:\Program Files\Internet Explorer
2012-03-04 03:24:23 ----D---- C:\Program Files\DVD Maker
2012-03-04 03:24:23 ----D---- C:\Program Files\Common Files\System
2012-03-04 03:24:22 ----D---- C:\Windows\servicing
2012-03-04 03:24:22 ----D---- C:\Windows\ehome
2012-03-04 03:24:22 ----D---- C:\Program Files\Windows Defender
2012-03-04 03:24:20 ----D---- C:\Windows\system32\sysprep
2012-03-04 03:24:20 ----D---- C:\Windows\system32\Setup
2012-03-04 03:24:20 ----D---- C:\Windows\system32\oobe
2012-03-04 03:24:20 ----D---- C:\Windows\system32\migration
2012-03-04 03:24:20 ----D---- C:\Windows\system32\en-US
2012-03-04 03:24:20 ----D---- C:\Windows\system32\da-DK
2012-03-04 03:24:20 ----D---- C:\Windows\system32\AdvancedInstallers
2012-03-04 03:24:20 ----D---- C:\Windows\PolicyDefinitions
2012-03-04 03:24:19 ----D---- C:\Windows\system32\cs-CZ
2012-03-04 03:24:19 ----D---- C:\Windows\system32\cs
2012-03-04 03:24:15 ----D---- C:\Windows\system32\wbem
2012-03-04 03:24:15 ----D---- C:\Windows\system32\sppui
2012-03-04 03:24:15 ----D---- C:\Windows\system32\manifeststore
2012-03-04 03:24:15 ----D---- C:\Windows\system32\es-ES
2012-03-04 03:24:15 ----D---- C:\Windows\system32\drivers\cs-CZ
2012-03-04 03:24:14 ----D---- C:\Windows\system32\migwiz
2012-03-04 03:24:14 ----D---- C:\Windows\system32\Dism
2012-03-04 03:24:00 ----RSD---- C:\Windows\Fonts
2012-03-04 03:23:59 ----D---- C:\Windows\AppPatch
2012-03-04 03:23:52 ----D---- C:\Windows\system32\Boot
2012-03-04 01:26:11 ----D---- C:\Program Files\Mozilla Firefox
2012-03-03 17:43:19 ----D---- C:\Windows\system32\catroot2
2012-03-03 17:36:12 ----A---- C:\Windows\system32\msclmd.dll
2012-03-03 17:32:19 ----D---- C:\ProgramData\Adobe
2012-03-03 17:32:19 ----D---- C:\Program Files\Common Files\Adobe
2012-03-03 17:32:19 ----D---- C:\Program Files\Adobe
2012-03-03 17:16:05 ----D---- C:\Windows\system32\Tasks
2012-02-29 08:15:13 ----SD---- C:\Users\Hej Rup\AppData\Roaming\Microsoft
2012-02-29 08:15:13 ----SD---- C:\ProgramData\Microsoft
2012-02-22 12:42:10 ----HD---- C:\Program Files\InstallShield Installation Information
2012-02-22 12:41:49 ----D---- C:\Program Files\Common Files\InstallShield
2012-02-21 08:11:01 ----D---- C:\Windows\rescache
2012-02-20 20:48:14 ----D---- C:\Windows\system32\drivers\NIS
2012-02-20 09:03:11 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-02-20 09:03:09 ----A---- C:\Windows\system32\PnkBstrA.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-08-10 104024]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 266544]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NIS\1207000.00D\SYMDS.SYS [2011-01-27 340088]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NIS\1207000.00D\SYMEFA.SYS [2011-03-15 744568]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110909.001\BHDrvx86.sys [2011-09-09 816760]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2012-01-17 491816]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-12-19 39640]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-28 218688]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2011-07-29 374392]
R1 EIO;EIO Driver; C:\Windows\system32\DRIVERS\EIO.sys [2011-07-28 14336]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20110917.031\IDSvix86.sys [2011-08-22 368248]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-12-19 82400]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1207000.00D\SRTSPX.SYS [2011-03-31 50168]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NIS\1207000.00D\Ironx86.SYS [2011-01-27 136312]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NIS\1207000.00D\SYMNETS.SYS [2011-04-21 299640]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2010-12-08 95720]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2010-12-08 292840]
R3 asusgsb;ASUS Virtual Video Capture Device Driver; C:\Windows\system32\drivers\asusgsb.sys [2009-02-17 15232]
R3 ATHDFU;Atheros Valkyrie USB BootROM; C:\Windows\System32\Drivers\AthDfu.sys [2010-10-27 47144]
R3 atkdisplf;ASUS Kernel Mode Enhanced Driver; C:\Windows\system32\drivers\ATKDispLowFilter.sys [2009-02-17 30976]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2010-10-27 26984]
R3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C; C:\Windows\system32\DRIVERS\e1c6232.sys [2010-09-21 238248]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-29 105592]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-02 3228712]
R3 MEI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2010-10-19 41088]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2010-06-21 105576]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2011-07-29 126584]
R4 IOMap;IOMap; \??\C:\Windows\system32\drivers\IOMap.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110917.007\NAVENG.SYS [2011-08-04 86136]
S3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20110917.007\NAVEX15.SYS [2011-08-04 1576312]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NIS\1207000.00D\SRTSP.SYS [2011-03-31 516216]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASDR;ASDR; C:\Windows\System32\ASDR.exe [2009-07-27 61440]
R2 ATKFUSService;ATK Fast User Switch Service; C:\Windows\system32\ATKFUSService.exe [2009-12-01 61952]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-10-26 223464]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2011-12-19 1960584]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2010-08-12 87712]
R2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\18.7.0.13\ccSvcHst.exe [2011-04-17 130008]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-05-21 615528]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-02-20 75136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-29 248936]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-15 136176]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-08-03 654848]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-15 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-07-28 1343400]

-----------------EOF-----------------

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Škodlivý software v pc

#2 Příspěvek od motji »

Hezké odpoledne :)
Systém a Norton máte legální?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Avatar uživatele
Thor
Návštěvník
Návštěvník
Příspěvky: 137
Registrován: 13 Říj 2008 14:52

Re: Škodlivý software v pc

#3 Příspěvek od Thor »

Já myslím, že ano. Ono je to počítač kamaráda a já jsem mu ho chtěl trochu vyčistit od tý havěti a zabezpečit. No a právě ochrana u Nortona vypršela. Proč se na to ptáte?

edit:

Norton je originální, byl u grafické karty při koupi. Počítač je starý teprve několik měsíců.

Windows je stažený a cracknutý. :oops:

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Škodlivý software v pc

#4 Příspěvek od motji »

Podle pravidel fora se zde nelegálními programy a systémem nezabýváme.
Takže má kamarád smůlu :closed:
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět