Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

stále zavirován

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
pike
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 02 dub 2012 14:35

stále zavirován

#1 Příspěvek od pike »

Pokusil jsem se odvirovat sám dle návodů uvedených ve vláknech, ale nb je stále zavirován.
Díky za pomoc.

Kód: Vybrat vše

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2012-04-02 15:29:41
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (28%) free of 10 GB
Total RAM: 1944 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:29:51, on 2.4.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Intel\WiFi\bin\S24EvMon.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
D:\Program Files\ThinkPad\Utilities\DOZESVC.EXE
D:\Program Files\Intel\WiFi\bin\EvtEng.exe
D:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
D:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
D:\Program Files\Apoint2K\ApMsgFwd.exe
C:\WINDOWS\system32\NWTRAY.EXE
D:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\WINDOWS\system32\igfxext.exe
D:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
D:\Program Files\Apoint2K\Apntex.exe
D:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
D:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\net.exe
C:\WINDOWS\system32\net1.exe
D:\Program Files\PSPad editor\PSPad.exe
D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
D:\Program Files\PhotoFiltre\PhotoFiltre.exe
D:\Program Files\XnView\xnview.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Program Files\Total Commander\TOTALCMD.EXE
D:\Program Files\CIGLER SOFTWARE\Money S3 START\MonS3.exe
D:\Program Files\Mozilla Thunderbird\thunderbird.exe
D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
D:\Program Files\Java\jre7\bin\java.exe
D:\install\_sw_Win\_antivir\_removal tools\RSIT.exe
D:\Program Files\trend micro\Administrator.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Ad-Aware Security Toolbar - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - D:\Program Files\adawaretb\adawareDx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Ad-Aware Security Toolbar - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - D:\Program Files\adawaretb\adawareDx.dll
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 D:\PROGRA~2\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [TPHOTKEY] D:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ACWLIcon] D:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "D:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKCU\..\Run: [ccleaner] "D:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11g_Plugin.exe -update plugin
O4 - HKUS\S-1-5-21-2000478354-1078081533-839522115-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'winpostgr')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - D:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - D:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{66CE5AD8-1E54-4D3B-8564-D3BB71A73B14}: NameServer = 192.168.10.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{A11FDA25-C941-4E1D-9727-93E7C24910DB}: NameServer = 10.0.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo  - D:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo  - D:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - D:\Program Files\ThinkPad\Utilities\DOZESVC.EXE
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - D:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - D:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Power Manager DBC Service - Unknown owner - D:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - D:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: WinStromService (Service1) - WinStrom s.r.o. - D:\Program Files\WinStrom\winstromservice.exe
O23 - Service: WinStrom-PostgreSQL - PostgreSQL Global Development Group - D:/Program Files/WinStrom/pgsql/bin/pg_ctl.exe

--
End of file - 9016 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\PMTask.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\37bl4p0u.default

prefs.js - "browser.startup.homepage" -  "http://www.google.cz/"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=D:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi]
"Description"=ZoneAlarm LTD Toolbar Api
"Path"=D:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=D:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=D:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=D:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.0]
"Description"=VLC Multimedia Plugin
"Path"=D:\Program Files\VideoLAN\VLC\npvlc.dll

D:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{B13721C7-F507-4982-B2E5-502A71474FED}

D:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

D:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\37bl4p0u.default\extensions\
foxmarks@kei.com
{87934c42-161d-45bc-8cef-ef18abe2a30c}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
Ad-Aware Security Toolbar - D:\Program Files\adawaretb\adawareDx.dll [2011-12-21 87440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-03-27 59272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{6c97a91e-4524-4019-86af-2aa2d567bf5c} - Ad-Aware Security Toolbar - D:\Program Files\adawaretb\adawareDx.dll [2011-12-21 87440]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"=rundll32 D:\PROGRA~2\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor []
"TPHOTKEY"=D:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2008-09-30 68976]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-06-17 150040]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-06-17 170520]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-06-17 141848]
"Apoint"=D:\Program Files\Apoint2K\Apoint.exe [2008-03-07 167936]
"avast"=D:\Program Files\AVAST Software\Avast\avastUI.exe [2012-03-07 4241512]
"ACWLIcon"=D:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe [2011-10-20 191552]
"COMODO Internet Security"=D:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-03-11 6749512]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"NWTRAY"=C:\WINDOWS\system32\NWTRAY.EXE [2002-03-12 28672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"=D:\Program Files\CCleaner\CCleaner.exe [2012-02-22 2761024]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\WINDOWS\system32\Macromed\Flash\FlashUtil11g_Plugin.exe [2012-03-16 250528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection]
C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe [2011-11-15 197288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWTRAY]
C:\WINDOWS\system32\NWTRAY.EXE [2002-03-12 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Bluetooth.lnk]
D:\PROGRA~2\ThinkPad\BLUETO~1\BTTray.exe [2008-08-18 604776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-06-11 212992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
D:\Program Files\Lenovo\HOTKEY\notifyf2.dll [2006-09-06 34344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
D:\Program Files\Lenovo\HOTKEY\tphklock.dll [2008-08-08 28672]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwv1_0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"CompatibleRUPSecurity"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"D:\Program Files\Mozilla Firefox\firefox.exe"="D:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.txt - open - D:\PROGRA~2\PSPADE~1\PSPad.exe "%1"

======List of files/folders created in the last 1 month======

2012-04-02 15:29:42 ----D---- D:\Program Files\trend micro
2012-04-02 15:29:41 ----D---- C:\rsit
2012-03-29 11:22:24 ----A---- C:\avenger.txt
2012-03-29 11:17:55 ----A---- C:\cleanup.exe
2012-03-28 23:54:59 ----D---- C:\Documents and Settings\Administrator\Data aplikací\.winstrom
2012-03-28 23:54:28 ----D---- C:\Program Files\Common Files\WinStrom
2012-03-28 23:53:26 ----D---- D:\Program Files\WinStrom
2012-03-28 21:00:14 ----D---- C:\Avenger
2012-03-28 12:11:11 ----D---- C:\WINDOWS\system32\PreInstall
2012-03-28 12:11:10 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-03-28 12:11:10 ----HD---- C:\WINDOWS\$hf_mig$
2012-03-27 14:08:59 ----D---- C:\WINDOWS\Sun
2012-03-27 14:06:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2012-03-27 14:06:47 ----D---- C:\Program Files\Common Files\Java
2012-03-27 14:06:26 ----A---- C:\WINDOWS\system32\npdeployJava1.dll
2012-03-27 14:06:26 ----A---- C:\WINDOWS\system32\javaws.exe
2012-03-27 14:06:26 ----A---- C:\WINDOWS\system32\javaw.exe
2012-03-27 14:06:26 ----A---- C:\WINDOWS\system32\java.exe
2012-03-27 14:06:26 ----A---- C:\WINDOWS\system32\deployJava1.dll
2012-03-27 14:01:29 ----D---- D:\Program Files\Java
2012-03-27 14:01:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Sun
2012-03-26 16:34:10 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2012-03-26 12:05:10 ----SHD---- C:\RECYCLER
2012-03-26 11:26:55 ----A---- C:\TDSSKiller.2.7.11.0_26.03.2012_11.26.55_log.txt
2012-03-26 11:17:00 ----A---- C:\gmer.exe
2012-03-26 11:01:38 ----D---- C:\WINDOWS\temp
2012-03-26 11:01:36 ----A---- C:\ComboFix.txt
2012-03-26 10:50:32 ----A---- C:\Boot.bak
2012-03-26 10:50:11 ----RASHD---- C:\cmdcons
2012-03-26 10:48:55 ----A---- C:\WINDOWS\zip.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\SWXCACLS.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\SWSC.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\SWREG.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\sed.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\PEV.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\NIRCMD.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\MBR.exe
2012-03-26 10:48:55 ----A---- C:\WINDOWS\grep.exe
2012-03-26 10:48:50 ----D---- C:\WINDOWS\ERDNT
2012-03-26 10:47:26 ----D---- C:\Qoobox
2012-03-26 10:30:27 ----D---- C:\TDSSKiller_Quarantine
2012-03-26 10:29:48 ----A---- C:\TDSSKiller.2.7.11.0_26.03.2012_10.29.48_log.txt
2012-03-26 10:28:04 ----A---- C:\WINDOWS\system32\drivers\eula.txt
2012-03-26 10:28:00 ----A---- C:\WINDOWS\system32\drivers\TDSSKiller.exe
2012-03-26 10:23:55 ----A---- C:\WINDOWS\system32\drivers\SBREDrv.sys
2012-03-25 21:21:48 ----D---- C:\Documents and Settings\Administrator\Data aplikací\dvdcss
2012-03-24 10:53:28 ----D---- D:\Program Files\Tor Browser
2012-03-23 12:39:49 ----A---- C:\WINDOWS\ODBC.INI
2012-03-23 12:39:45 ----A---- C:\WINDOWS\system32\mdimon.dll
2012-03-23 12:38:56 ----D---- C:\Program Files\Common Files\DESIGNER
2012-03-23 12:38:51 ----D---- D:\Program Files\Microsoft Works
2012-03-23 12:38:45 ----D---- D:\Program Files\Microsoft Visual Studio
2012-03-23 12:38:36 ----D---- C:\WINDOWS\SHELLNEW
2012-03-23 12:38:34 ----D---- D:\Program Files\Microsoft.NET
2012-03-23 12:38:34 ----D---- D:\Program Files\Microsoft Office
2012-03-23 12:29:58 ----RD---- C:\MSOCache
2012-03-22 09:47:01 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Foxit Software
2012-03-22 00:33:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo
2012-03-22 00:33:14 ----D---- D:\Program Files\COMODO
2012-03-22 00:21:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Agnitum
2012-03-21 19:13:49 ----D---- C:\WINDOWS\pss
2012-03-21 13:37:53 ----D---- D:\Program Files\Samsung Network Printer Utilities
2012-03-21 13:37:53 ----A---- C:\WINDOWS\system32\SecSNMP.dll
2012-03-21 13:37:53 ----A---- C:\WINDOWS\system32\secmon.dll
2012-03-21 13:37:27 ----A---- C:\WINDOWS\IsUninst.exe
2012-03-21 13:27:52 ----A---- C:\WINDOWS\system32\TrackID.DLL
2012-03-21 13:27:52 ----A---- C:\WINDOWS\system32\TIFmtA.dll
2012-03-21 13:27:52 ----A---- C:\WINDOWS\system32\TIBase64.dll
2012-03-21 13:27:52 ----A---- C:\WINDOWS\system32\RICJC32.dll
2012-03-21 13:27:52 ----A---- C:\WINDOWS\system32\RIC53EX.EXE
2012-03-21 13:27:52 ----A---- C:\WINDOWS\system32\RIC53EPI.DLL
2012-03-21 13:27:52 ----A---- C:\WINDOWS\system32\JCUI.exe
2012-03-21 13:26:40 ----A---- C:\WINDOWS\system32\clpa1LMK.DLL
2012-03-21 13:17:24 ----D---- C:\Documents and Settings\Administrator\Data aplikací\AcWizard
2012-03-21 13:13:50 ----D---- C:\WINDOWS\system32\ChalRespUninstall
2012-03-21 13:13:50 ----A---- C:\WINDOWS\system32\crlcm.dll
2012-03-21 13:13:43 ----D---- C:\WINDOWS\system32\NMAS
2012-03-21 13:13:43 ----A---- C:\WINDOWS\system32\nmasncp.dll
2012-03-21 13:13:43 ----A---- C:\WINDOWS\system32\nmasmsg.dll
2012-03-21 13:13:43 ----A---- C:\WINDOWS\system32\nmas.dll
2012-03-21 13:13:43 ----A---- C:\WINDOWS\system32\ncc.exe
2012-03-21 13:13:42 ----HD---- D:\Program Files\Zero G Registry
2012-03-21 13:13:42 ----D---- C:\WINDOWS\system32\jre
2012-03-21 13:13:31 ----N---- C:\WINDOWS\system32\ccsw32.dll
2012-03-21 13:13:31 ----D---- C:\WINDOWS\system32\novell
2012-03-21 13:11:30 ----D---- D:\Program Files\CUAgent
2012-03-21 13:11:30 ----D---- C:\WINDOWS\system32\NetWare
2012-03-21 13:11:29 ----D---- C:\WINDOWS\system32\nls
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\zlib.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\wmutil.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\wmreg.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\vlmsup.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\vlmsup.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\vipxvdd.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\vipx.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\sporder.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\slpinfo.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\setupw2k.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\rcuagent.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\pwdnotfy.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwv1_0.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwtray.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwsrvloc.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwspool.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwsndmsg.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwslog32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwsipx32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwshlxnt.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\NWSETUP.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwpfctrs.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwlscrpt.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwlghelp.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwgina.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nwapp32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\novnpnt.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nippzppd.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nippzlib.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nipped.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nippdzip.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\nippdrvi.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\ndszip.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\mapbase.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\loginw32.exe
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\loginsvc.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\locwin32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\lgncxw32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\lgncon32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\dscqry32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\drivers\nicm.sys
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\dpswin32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\dprpcw32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\dppwin32.dll
2012-03-21 13:04:57 ----A---- C:\WINDOWS\system32\dplwin32.dll
2012-03-21 13:04:56 ----A---- C:\WINDOWS\system32\dpawin32.dll
2012-03-21 13:04:56 ----A---- C:\WINDOWS\system32\cw3230mt.dll
2012-03-21 13:04:56 ----A---- C:\WINDOWS\system32\cusrvc.exe
2012-03-21 13:04:56 ----A---- C:\WINDOWS\system32\connsvc.dll
2012-03-21 13:04:56 ----A---- C:\WINDOWS\system32\cmdinfo.exe
2012-03-21 13:04:54 ----A---- C:\WINDOWS\system32\spflist.exe
2012-03-21 13:04:54 ----A---- C:\WINDOWS\system32\rdrstats.ini
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\spmnwcc.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\prtwin32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\nwsso.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\nwpsrv32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\nwipxspx.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\nsss.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\nssncp.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\nrdwin32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\netwin32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\ncpwin32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\loginw32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\lgnwnt32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\ldapssl.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\ldapsdk.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\gsskrb5.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\clxwin32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\clnwin32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\calwin32.dll
2012-03-21 13:04:53 ----A---- C:\WINDOWS\system32\audwin32.dll
2012-03-21 08:51:16 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2012-03-21 08:50:57 ----D---- D:\Program Files\Skype
2012-03-21 08:50:57 ----D---- C:\Program Files\Common Files\Skype
2012-03-21 08:50:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-03-20 19:33:53 ----A---- C:\WINDOWS\system32\heciudlg.exe
2012-03-20 19:33:53 ----A---- C:\WINDOWS\system32\drivers\HECI.sys
2012-03-20 17:57:17 ----A---- C:\WINDOWS\system32\drivers\btwusb.sys
2012-03-20 17:57:17 ----A---- C:\WINDOWS\system32\drivers\btwsecfl.sys
2012-03-20 17:57:17 ----A---- C:\WINDOWS\system32\drivers\btkrnl.sys
2012-03-20 17:57:17 ----A---- C:\WINDOWS\system32\btw_ci.dll
2012-03-19 13:47:41 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Thunderbird
2012-03-19 13:47:35 ----D---- D:\Program Files\Mozilla Thunderbird
2012-03-18 21:22:33 ----D---- C:\Program Files\Common Files\Lenovo
2012-03-18 21:22:30 ----A---- C:\WINDOWS\system32\drivers\IBMBLDID.sys
2012-03-18 21:22:30 ----A---- C:\WINDOWS\system32\drivers\ANC.sys
2012-03-18 20:58:23 ----D---- C:\WINDOWS\Minidump
2012-03-18 19:00:40 ----A---- C:\WINDOWS\system32\RTNUninst32.dll
2012-03-18 19:00:40 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2012-03-18 17:59:17 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Avaya
2012-03-18 17:54:49 ----A---- C:\WINDOWS\system32\drivers\Rtenicxp.sys
2012-03-17 13:49:51 ----D---- C:\Documents and Settings\Administrator\Data aplikací\PwrMgr
2012-03-16 10:08:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection
2012-03-16 10:08:30 ----A---- C:\WINDOWS\system32\rp_stats.dat
2012-03-16 10:08:30 ----A---- C:\WINDOWS\system32\rp_rules.dat
2012-03-16 10:08:23 ----D---- D:\Program Files\Toolbar Cleaner
2012-03-16 10:08:21 ----D---- D:\Program Files\adawaretb
2012-03-16 10:08:21 ----D---- C:\Documents and Settings\Administrator\Data aplikací\adawaretb
2012-03-16 10:08:06 ----A---- C:\WINDOWS\system32\drivers\Lbd.sys
2012-03-16 10:07:49 ----D---- D:\Program Files\Lavasoft
2012-03-16 10:07:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2012-03-16 04:47:04 ----D---- D:\Program Files\Google
2012-03-16 04:47:03 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2012-03-16 04:47:03 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-03-16 04:47:02 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2012-03-16 04:47:02 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2012-03-16 04:47:02 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2012-03-16 04:47:02 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2012-03-16 04:47:02 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2012-03-16 04:47:02 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2012-03-16 04:46:41 ----A---- C:\WINDOWS\avastSS.scr
2012-03-16 04:46:40 ----A---- C:\WINDOWS\system32\aswBoot.exe
2012-03-16 04:46:24 ----D---- D:\Program Files\AVAST Software
2012-03-16 04:46:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2012-03-16 00:30:15 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Macromedia
2012-03-16 00:30:15 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Adobe
2012-03-16 00:10:20 ----D---- D:\Program Files\CIGLER SOFTWARE
2012-03-15 22:37:57 ----D---- D:\Program Files\Symantec Ghost Explorer 11.0.2
2012-03-15 21:43:50 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Mozilla
2012-03-15 21:13:46 ----D---- D:\Program Files\Mozilla Firefox
2012-03-15 21:11:55 ----HDC---- C:\WINDOWS\$NtUninstallKB943232$
2012-03-15 20:52:49 ----D---- D:\Program Files\CCleaner
2012-03-15 10:49:06 ----D---- D:\Program Files\Microcom
2012-03-14 22:50:49 ----A---- C:\WINDOWS\system32\msxml4r.dll
2012-03-14 22:50:49 ----A---- C:\WINDOWS\system32\msxml4a.dll
2012-03-14 22:50:49 ----A---- C:\WINDOWS\system32\msxml4.dll
2012-03-14 22:50:49 ----A---- C:\WINDOWS\system32\msxml3a.dll
2012-03-14 20:14:02 ----A---- C:\WINDOWS\system32\tvt_gina_api.dll
2012-03-14 20:14:02 ----A---- C:\WINDOWS\system32\tvt_gina.dll
2012-03-14 20:14:02 ----A---- C:\WINDOWS\system32\msvcr71.dll
2012-03-14 20:14:02 ----A---- C:\WINDOWS\system32\msvcp71.dll
2012-03-14 20:14:02 ----A---- C:\WINDOWS\system32\MFC71u.dll
2012-03-14 20:14:02 ----A---- C:\WINDOWS\system32\MFC71.dll
2012-03-14 20:08:46 ----D---- C:\Documents and Settings\Administrator\Data aplikací\vlc
2012-03-14 20:07:45 ----D---- D:\Program Files\VideoLAN
2012-03-14 20:05:51 ----D---- C:\Documents and Settings\Administrator\Data aplikací\pdfforge
2012-03-14 20:05:49 ----A---- C:\WINDOWS\system32\pdfcmon.dll
2012-03-14 20:05:48 ----D---- D:\Program Files\PDFCreator
2012-03-14 20:05:48 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2012-03-14 17:22:01 ----D---- D:\Program Files\Ecd
2012-03-14 14:34:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\XnView
2012-03-14 14:28:12 ----D---- D:\Program Files\XnView
2012-03-14 14:26:53 ----D---- C:\Documents and Settings\Administrator\Data aplikací\PhotoFiltre
2012-03-14 14:26:51 ----D---- D:\Program Files\PhotoFiltre
2012-03-14 11:50:31 ----A---- C:\WINDOWS\system32\wpa.bak
2012-03-14 01:07:18 ----A---- C:\WINDOWS\system32\snymsico.dll
2012-03-14 01:07:18 ----A---- C:\WINDOWS\system32\drivers\rimsptsk.sys
2012-03-14 01:07:17 ----A---- C:\WINDOWS\system32\rixdicon.dll
2012-03-14 01:07:17 ----A---- C:\WINDOWS\system32\drivers\rixdptsk.sys
2012-03-14 01:07:13 ----A---- C:\WINDOWS\system32\drivers\rimmptsk.sys
2012-03-14 01:01:20 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2012-03-14 01:01:05 ----D---- D:\Program Files\Apoint2K
2012-03-14 01:01:02 ----A---- C:\WINDOWS\system32\WdfCoinstaller01007.dll
2012-03-14 01:01:02 ----A---- C:\WINDOWS\system32\Vxdif.dll
2012-03-14 01:01:02 ----A---- C:\WINDOWS\system32\drivers\Apfiltr.sys
2012-03-13 21:31:04 ----D---- D:\Program Files\Foxit Software
2012-03-13 21:29:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\PSpad
2012-03-13 21:29:08 ----D---- D:\Program Files\PSPad editor
2012-03-13 21:12:33 ----D---- D:\Program Files\Total Commander
2012-03-13 21:12:33 ----A---- C:\WINDOWS\UC.PIF
2012-03-13 21:12:33 ----A---- C:\WINDOWS\RAR.PIF
2012-03-13 21:12:33 ----A---- C:\WINDOWS\NOCLOSE.PIF
2012-03-13 21:12:33 ----A---- C:\WINDOWS\LHA.PIF
2012-03-13 21:12:33 ----A---- C:\WINDOWS\ARJ.PIF
2012-03-13 20:03:32 ----A---- C:\WINDOWS\system32\igfxtray.exe
2012-03-13 20:03:31 ----A---- C:\WINDOWS\system32\igxprd32.dll
2012-03-13 20:03:31 ----A---- C:\WINDOWS\system32\igfxpers.exe
2012-03-13 20:03:31 ----A---- C:\WINDOWS\system32\igfxexps.dll
2012-03-13 20:03:30 ----A---- C:\WINDOWS\system32\drivers\igxpmp32.sys
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\igfxzoom.exe
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\igfxext.exe
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\ig4dev32.dll
2012-03-13 20:03:29 ----A---- C:\WINDOWS\system32\hccutils.dll
2012-03-13 20:03:28 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2012-03-13 20:03:28 ----A---- C:\WINDOWS\system32\igfxdev.dll
2012-03-13 20:03:28 ----A---- C:\WINDOWS\system32\igfxCoIn_v4957.dll
2012-03-13 20:03:28 ----A---- C:\WINDOWS\system32\ig4icd32.dll
2012-03-13 20:03:28 ----A---- C:\WINDOWS\system32\hkcmd.exe
2012-03-13 20:03:27 ----A---- C:\WINDOWS\system32\igfxress.dll
2012-03-13 20:03:27 ----A---- C:\WINDOWS\system32\igfxpph.dll
2012-03-13 20:03:27 ----A---- C:\WINDOWS\system32\igfxdo.dll
2012-03-13 20:03:26 ----D---- C:\WINDOWS\system32\Lang
2012-03-13 20:03:26 ----A---- C:\WINDOWS\system32\igxpun.exe
2012-03-13 20:03:26 ----A---- C:\WINDOWS\system32\difxapi.dll
2012-03-13 19:50:02 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Intel
2012-03-13 19:49:48 ----A---- C:\WINDOWS\system32\NETw5r32.dll
2012-03-13 19:49:48 ----A---- C:\WINDOWS\system32\NETw5c32.dll
2012-03-13 19:49:48 ----A---- C:\WINDOWS\system32\drivers\NETw5x32.sys
2012-03-13 19:49:42 ----D---- C:\Program Files\Common Files\Intel
2012-03-13 19:49:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\Intel
2012-03-13 19:43:11 ----D---- D:\Program Files\Lenovo
2012-03-13 19:04:21 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2012-03-13 18:57:44 ----N---- C:\WINDOWS\system32\drivers\TPPWRIF.SYS
2012-03-13 18:57:44 ----N---- C:\WINDOWS\system32\drivers\DOZEHDD.SYS
2012-03-13 18:57:44 ----N---- C:\WINDOWS\PWMBTHLP.EXE
2012-03-13 18:48:27 ----D---- C:\WINDOWS\system32\XPSViewer
2012-03-13 18:48:22 ----D---- D:\Program Files\MSBuild
2012-03-13 18:48:21 ----D---- C:\WINDOWS\system32\en-US
2012-03-13 18:48:15 ----D---- D:\Program Files\Reference Assemblies
2012-03-13 18:47:53 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2012-03-13 18:47:53 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2012-03-13 18:47:53 ----N---- C:\WINDOWS\system32\prntvpt.dll
2012-03-13 18:47:23 ----RSD---- C:\WINDOWS\assembly
2012-03-13 18:47:07 ----D---- C:\WINDOWS\Microsoft.NET
2012-03-13 18:46:30 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2012-03-13 18:46:29 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2012-03-13 18:46:24 ----D---- D:\Program Files\MSXML 6.0
2012-03-13 18:37:48 ----N---- C:\WINDOWS\system32\spmsg.dll
2012-03-13 18:37:37 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2012-03-13 18:30:56 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2012-03-13 16:01:37 ----D---- D:\Program Files\ThinkPad
2012-03-13 15:41:03 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2012-03-13 15:41:02 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2012-03-13 15:41:02 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2012-03-13 15:40:59 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2012-03-13 15:40:58 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2012-03-13 15:40:57 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2012-03-13 15:40:57 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2012-03-13 15:40:56 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2012-03-13 15:40:56 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2012-03-13 15:40:55 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2012-03-13 15:40:54 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2012-03-13 15:40:45 ----D---- D:\Program Files\CONEXANT
2012-03-13 15:40:44 ----A---- C:\WINDOWS\system32\ksuser.dll
2012-03-13 15:40:44 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2012-03-13 15:37:17 ----HDC---- C:\WINDOWS\$NtUninstallKB835221WXP$
2012-03-13 15:37:12 ----N---- C:\WINDOWS\system32\RtlCPAPI.dll
2012-03-13 15:37:12 ----N---- C:\WINDOWS\system32\RTCOMDLL.dll
2012-03-13 15:37:12 ----N---- C:\WINDOWS\system32\ChCfg.exe
2012-03-13 15:37:12 ----N---- C:\WINDOWS\system32\drivers\RtkHDAud.Sys
2012-03-13 15:37:12 ----N---- C:\WINDOWS\SoundMan.exe
2012-03-13 15:37:12 ----N---- C:\WINDOWS\RTLCPL.exe
2012-03-13 15:37:12 ----N---- C:\WINDOWS\RTHDCPL.exe
2012-03-13 15:37:12 ----N---- C:\WINDOWS\alcwzrd.exe
2012-03-13 15:37:10 ----HD---- D:\Program Files\InstallShield Installation Information
2012-03-13 15:37:10 ----D---- D:\Program Files\Realtek
2012-03-13 15:37:02 ----D---- C:\Program Files\Common Files\InstallShield
2012-03-13 15:34:18 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-03-13 15:34:16 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-03-13 15:34:16 ----D---- D:\Program Files\Intel
2012-03-13 15:34:16 ----A---- C:\WINDOWS\system32\CSVer.dll
2012-03-13 15:33:52 ----D---- C:\Intel
2012-03-13 10:28:39 ----A---- C:\WINDOWS\system32\h323log.txt
2012-03-13 10:20:26 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2012-03-13 10:20:20 ----A---- C:\WINDOWS\system32\drivers\compbatt.sys
2012-03-13 10:20:19 ----A---- C:\WINDOWS\system32\drivers\CmBatt.sys
2012-03-13 10:20:19 ----A---- C:\WINDOWS\system32\drivers\battc.sys
2012-03-13 10:20:03 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2012-03-13 10:19:59 ----A---- C:\WINDOWS\system32\drivers\enum1394.sys
2012-03-13 10:19:53 ----A---- C:\WINDOWS\system32\usbui.dll
2012-03-13 10:19:52 ----A---- C:\WINDOWS\system32\drivers\wmiacpi.sys
2012-03-13 10:19:19 ----SHD---- C:\WINDOWS\Installer
2012-03-13 10:19:19 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-03-13 10:19:18 ----D---- C:\Program Files\Common Files\ODBC
2012-03-13 10:19:18 ----A---- C:\WINDOWS\ODBCINST.INI
2012-03-13 10:19:16 ----D---- C:\Program Files\Common Files\SpeechEngines
2012-03-13 10:19:15 ----RD---- C:\Program Files
2012-03-13 10:19:15 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-03-13 10:19:10 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2012-03-13 10:19:10 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2012-03-13 10:19:10 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdur.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdru.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2012-03-13 10:19:08 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2012-03-13 10:19:06 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2012-03-13 10:19:06 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2012-03-13 10:19:06 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2012-03-13 10:19:06 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2012-03-13 10:19:06 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2012-03-13 10:19:06 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2012-03-13 10:19:06 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2012-03-13 10:19:05 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2012-03-13 10:19:05 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2012-03-13 10:19:05 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2012-03-13 10:19:05 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2012-03-13 10:19:05 ----RA---- C:\WINDOWS\system32\kbdest.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdro.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2012-03-13 10:18:58 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2012-03-13 10:18:57 ----A---- C:\WINDOWS\system32\spxcoins.dll
2012-03-13 10:18:57 ----A---- C:\WINDOWS\system32\irclass.dll
2012-03-13 10:18:57 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2012-03-13 10:18:57 ----A---- C:\WINDOWS\system32\dgsetup.dll
2012-03-13 10:18:57 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2012-03-13 10:18:55 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2012-03-13 10:18:55 ----A---- C:\WINDOWS\TASKMAN.EXE
2012-03-13 10:18:55 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2012-03-13 10:18:54 ----A---- C:\WINDOWS\system32\batt.dll
2012-03-13 10:18:54 ----A---- C:\WINDOWS\NOTEPAD.EXE
2012-03-13 10:18:53 ----A---- C:\WINDOWS\system32\storprop.dll
2012-03-13 10:18:51 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2012-03-13 10:18:48 ----RA---- C:\WINDOWS\SET8.tmp
2012-03-13 10:18:46 ----RA---- C:\WINDOWS\SET4.tmp
2012-03-13 10:18:45 ----RA---- C:\WINDOWS\SET3.tmp
2012-03-13 10:18:41 ----D---- C:\WINDOWS\system32\CatRoot2
2012-03-13 10:18:41 ----D---- C:\WINDOWS\system32\CatRoot
2012-03-13 10:18:35 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-03-13 10:18:16 ----D---- C:\Documents and Settings
2012-03-13 10:18:15 ----SHD---- C:\System Volume Information
2012-03-13 10:18:15 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2012-03-13 10:16:43 ----RASH---- C:\boot.ini
2012-03-13 10:12:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-03-13 10:12:06 ----RSD---- C:\WINDOWS\Fonts
2012-03-13 10:12:06 ----RD---- C:\WINDOWS\Web
2012-03-13 10:12:06 ----HD---- C:\WINDOWS\inf
2012-03-13 10:12:06 ----D---- C:\WINDOWS\WinSxS
2012-03-13 10:12:06 ----D---- C:\WINDOWS\twain_32
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\wins
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\wbem
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\usmt
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\spool
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\ShellExt
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\Setup
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\ras
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\oobe
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\npp
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\mui
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\inetsrv
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\IME
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\icsxml
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\ias
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\export
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\drivers\etc
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\drivers\disdn
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\drivers
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\dhcp
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\config
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\3com_dmi
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\3076
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\2052
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1054
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1042
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1041
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1037
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1033
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1031
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1029
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1028
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32\1025
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system32
2012-03-13 10:12:06 ----D---- C:\WINDOWS\system
2012-03-13 10:12:06 ----D---- C:\WINDOWS\security
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Resources
2012-03-13 10:12:06 ----D---- C:\WINDOWS\repair
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Provisioning
2012-03-13 10:12:06 ----D---- C:\WINDOWS\pchealth
2012-03-13 10:12:06 ----D---- C:\WINDOWS\PeerNet
2012-03-13 10:12:06 ----D---- C:\WINDOWS\NLDRV
2012-03-13 10:12:06 ----D---- C:\WINDOWS\mui
2012-03-13 10:12:06 ----D---- C:\WINDOWS\msapps
2012-03-13 10:12:06 ----D---- C:\WINDOWS\msagent
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Media
2012-03-13 10:12:06 ----D---- C:\WINDOWS\java
2012-03-13 10:12:06 ----D---- C:\WINDOWS\ime
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Help
2012-03-13 10:12:06 ----D---- C:\WINDOWS\ehome
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Driver Cache
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Debug
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Cursors
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Connection Wizard
2012-03-13 10:12:06 ----D---- C:\WINDOWS\Config
2012-03-13 10:12:06 ----D---- C:\WINDOWS\AppPatch
2012-03-13 10:12:06 ----D---- C:\WINDOWS\addins
2012-03-13 10:12:06 ----D---- C:\WINDOWS
2012-03-13 10:12:06 ----ASH---- C:\pagefile.sys
2012-03-13 10:07:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Identities
2012-03-13 10:07:16 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2012-03-13 09:55:28 ----D---- C:\WINDOWS\SoftwareDistribution
2012-03-13 09:55:26 ----SD---- C:\WINDOWS\system32\Microsoft
2012-03-13 09:55:26 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-03-13 09:55:26 ----D---- C:\WINDOWS\Prefetch
2012-03-13 09:34:31 ----AS---- C:\WINDOWS\bootstat.dat
2012-03-13 09:32:47 ----D---- C:\WINDOWS\system32\xircom
2012-03-13 09:32:36 ----RASH---- C:\MSDOS.SYS
2012-03-13 09:32:36 ----RASH---- C:\IO.SYS
2012-03-13 09:32:36 ----A---- C:\WINDOWS\control.ini
2012-03-13 09:32:36 ----A---- C:\CONFIG.SYS
2012-03-13 09:32:36 ----A---- C:\AUTOEXEC.BAT
2012-03-13 09:32:29 ----A---- C:\WINDOWS\system32\mapi32.dll
2012-03-13 09:31:56 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-03-13 09:31:56 ----RD---- C:\WINDOWS\Offline Web Pages
2012-03-13 09:31:36 ----D---- C:\WINDOWS\system32\DirectX
2012-03-13 09:31:18 ----A---- C:\WINDOWS\system32\atrace.dll
2012-03-13 09:31:16 ----A---- C:\WINDOWS\system32\desktop.ini
2012-03-13 09:31:16 ----A---- C:\WINDOWS\desktop.ini
2012-03-13 09:31:09 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2012-03-13 09:31:08 ----A---- C:\WINDOWS\system32\acctres.dll
2012-03-13 09:31:07 ----D---- C:\Program Files\Common Files\Services
2012-03-13 09:31:05 ----SD---- C:\WINDOWS\Tasks
2012-03-13 09:31:05 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2012-03-13 09:31:04 ----D---- C:\Program Files\Common Files\MSSoap
2012-03-13 09:31:00 ----D---- C:\WINDOWS\system32\Macromed
2012-03-13 09:31:00 ----D---- C:\WINDOWS\srchasst
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wuweb.dll
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wups.dll
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wucltui.dll
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wuauserv.dll
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wuaueng.dll
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2012-03-13 09:30:57 ----A---- C:\WINDOWS\system32\wuauclt.exe
2012-03-13 09:30:56 ----A---- C:\WINDOWS\system32\wuapi.dll
2012-03-13 09:30:56 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2012-03-13 09:30:56 ----A---- C:\WINDOWS\system32\qmgr.dll
2012-03-13 09:30:56 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2012-03-13 09:30:56 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2012-03-13 09:30:49 ----A---- C:\WINDOWS\system32\safrslv.dll
2012-03-13 09:30:49 ----A---- C:\WINDOWS\system32\safrdm.dll
2012-03-13 09:30:49 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2012-03-13 09:30:49 ----A---- C:\WINDOWS\system32\racpldlg.dll
2012-03-13 09:30:46 ----A---- C:\WINDOWS\system32\fltMc.exe
2012-03-13 09:30:46 ----A---- C:\WINDOWS\system32\fltlib.dll
2012-03-13 09:30:46 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2012-03-13 09:30:45 ----D---- C:\WINDOWS\system32\Restore
2012-03-13 09:30:45 ----A---- C:\WINDOWS\system32\srsvc.dll
2012-03-13 09:30:45 ----A---- C:\WINDOWS\system32\srrstr.dll
2012-03-13 09:30:45 ----A---- C:\WINDOWS\system32\srclient.dll
2012-03-13 09:30:45 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2012-03-13 09:30:44 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2012-03-13 09:30:44 ----A---- C:\WINDOWS\system32\msconf.dll
2012-03-13 09:30:44 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2012-03-13 09:30:44 ----A---- C:\WINDOWS\system32\mnmdd.dll
2012-03-13 09:30:44 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2012-03-13 09:30:44 ----A---- C:\WINDOWS\system32\ils.dll
2012-03-13 09:30:41 ----A---- C:\WINDOWS\system32\msoert2.dll
2012-03-13 09:30:41 ----A---- C:\WINDOWS\system32\msoeacct.dll
2012-03-13 09:30:40 ----A---- C:\WINDOWS\system32\inetres.dll
2012-03-13 09:30:40 ----A---- C:\WINDOWS\system32\inetcomm.dll
2012-03-13 09:30:38 ----A---- C:\WINDOWS\system32\schedsvc.dll
2012-03-13 09:30:38 ----A---- C:\WINDOWS\system32\mstinit.exe
2012-03-13 09:30:38 ----A---- C:\WINDOWS\system32\mstask.dll
2012-03-13 09:30:38 ----A---- C:\WINDOWS\system32\isign32.dll
2012-03-13 09:30:38 ----A---- C:\WINDOWS\system32\icwphbk.dll
2012-03-13 09:30:38 ----A---- C:\WINDOWS\system32\icwdial.dll
2012-03-13 09:30:37 ----A---- C:\WINDOWS\system32\inetcfg.dll
2012-03-13 09:30:32 ----D---- C:\Program Files\Common Files\System
2012-03-13 09:30:15 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2012-03-13 09:30:14 ----A---- C:\WINDOWS\vbaddin.ini
2012-03-13 09:30:14 ----A---- C:\WINDOWS\vb.ini
2012-03-13 09:30:12 ----D---- C:\WINDOWS\Registration
2012-03-13 09:30:04 ----A---- C:\WINDOWS\system32\write.exe
2012-03-13 09:29:56 ----A---- C:\WINDOWS\system32\sndvol32.exe
2012-03-13 09:29:56 ----A---- C:\WINDOWS\system32\hticons.dll
2012-03-13 09:29:56 ----A---- C:\WINDOWS\system32\avwav.dll
2012-03-13 09:29:56 ----A---- C:\WINDOWS\system32\avtapi.dll
2012-03-13 09:29:56 ----A---- C:\WINDOWS\system32\avmeter.dll
2012-03-13 09:29:55 ----A---- C:\WINDOWS\system32\winchat.exe
2012-03-13 09:29:49 ----A---- C:\WINDOWS\system32\charmap.exe
2012-03-13 09:29:49 ----A---- C:\WINDOWS\system32\getuname.dll
2012-03-13 09:29:49 ----A---- C:\WINDOWS\system32\calc.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\tslabels.ini
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\tskill.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\tscon.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\shadow.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\rwinsta.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\reset.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\regini.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\qwinsta.exe
2012-03-13 09:29:47 ----A---- C:\WINDOWS\system32\qappsrv.exe
2012-03-13 09:29:46 ----A---- C:\WINDOWS\system32\msg.exe
2012-03-13 09:29:46 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2012-03-13 09:29:46 ----A---- C:\WINDOWS\system32\logoff.exe
2012-03-13 09:29:46 ----A---- C:\WINDOWS\system32\cdmodem.dll
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\stclient.dll
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\mtxex.dll
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\mtxdm.dll
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\comsnap.dll
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\comrepl.dll
2012-03-13 09:29:45 ----A---- C:\WINDOWS\system32\comaddin.dll
2012-03-13 09:29:40 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2012-03-13 09:29:39 ----A---- C:\WINDOWS\system32\sndrec32.exe
2012-03-13 09:29:39 ----A---- C:\WINDOWS\system32\mplay32.exe
2012-03-13 09:29:39 ----A---- C:\WINDOWS\system32\hypertrm.dll
2012-03-13 09:29:39 ----A---- C:\WINDOWS\system32\accwiz.exe
2012-03-13 09:29:38 ----A---- C:\WINDOWS\system32\mspaint.exe
2012-03-13 09:29:37 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2012-03-13 09:29:37 ----A---- C:\WINDOWS\system32\remotepg.dll
2012-03-13 09:29:37 ----A---- C:\WINDOWS\system32\mstscax.dll
2012-03-13 09:29:37 ----A---- C:\WINDOWS\system32\mstsc.exe
2012-03-13 09:29:37 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2012-03-13 09:29:37 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2012-03-13 09:29:37 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\termsrv.dll
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\sessmgr.exe
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\rdshost.exe
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\rdpclip.exe
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\rdchost.dll
2012-03-13 09:29:36 ----A---- C:\WINDOWS\system32\qprocess.exe
2012-03-13 09:29:35 ----D---- C:\WINDOWS\system32\MsDtc
2012-03-13 09:29:35 ----A---- C:\WINDOWS\system32\mtxoci.dll
2012-03-13 09:29:35 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2012-03-13 09:29:35 ----A---- C:\WINDOWS\system32\msdtctm.dll
2012-03-13 09:29:35 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2012-03-13 09:29:35 ----A---- C:\WINDOWS\system32\icaapi.dll
2012-03-13 09:29:35 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2012-03-13 09:29:34 ----A---- C:\WINDOWS\system32\xolehlp.dll
2012-03-13 09:29:34 ----A---- C:\WINDOWS\system32\msdtclog.dll
2012-03-13 09:29:34 ----A---- C:\WINDOWS\system32\msdtc.exe
2012-03-13 09:29:33 ----D---- C:\WINDOWS\system32\Com
2012-03-13 09:29:33 ----A---- C:\WINDOWS\system32\comsvcs.dll
2012-03-13 09:29:33 ----A---- C:\WINDOWS\system32\colbact.dll
2012-03-13 09:29:33 ----A---- C:\WINDOWS\system32\clbcatex.dll
2012-03-13 09:29:33 ----A---- C:\WINDOWS\system32\catsrvut.dll
2012-03-13 09:29:33 ----A---- C:\WINDOWS\system32\catsrvps.dll
2012-03-13 09:29:33 ----A---- C:\WINDOWS\system32\catsrv.dll
2012-03-13 09:29:32 ----A---- C:\WINDOWS\system32\comuid.dll
2012-03-13 09:29:32 ----A---- C:\WINDOWS\system32\clbcatq.dll
2012-03-13 09:29:27 ----A---- C:\WINDOWS\system32\servdeps.dll
2012-03-13 09:29:27 ----A---- C:\WINDOWS\system32\mmfutil.dll
2012-03-13 09:29:25 ----A---- C:\WINDOWS\system32\licwmi.dll
2012-03-13 09:29:25 ----A---- C:\WINDOWS\system32\cmprops.dll
2012-03-13 09:29:21 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2012-03-13 09:29:21 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2012-03-13 01:24:00 ----D---- D:\Program Files\xerox
2012-03-13 01:24:00 ----D---- D:\Program Files\windows nt
2012-03-13 01:24:00 ----D---- D:\Program Files\windows media player
2012-03-13 01:24:00 ----D---- D:\Program Files\outlook express
2012-03-13 01:24:00 ----D---- D:\Program Files\netmeeting
2012-03-13 01:24:00 ----D---- D:\Program Files\msn gaming zone
2012-03-13 01:24:00 ----D---- D:\Program Files\movie maker
2012-03-13 01:24:00 ----D---- D:\Program Files\internet explorer
2012-03-13 01:23:59 ----D---- D:\Program Files\microsoft frontpage
2012-03-11 22:13:48 ----A---- C:\WINDOWS\system32\drivers\inspect.sys
2012-03-11 22:13:46 ----A---- C:\WINDOWS\system32\drivers\cmdhlp.sys
2012-03-11 22:13:46 ----A---- C:\WINDOWS\system32\drivers\cmdGuard.sys
2012-03-11 22:13:44 ----A---- C:\WINDOWS\system32\drivers\cmderd.sys
2012-03-11 22:13:20 ----A---- C:\WINDOWS\system32\guard32.dll
2012-03-11 22:13:20 ----A---- C:\WINDOWS\system32\cmdcsr.dll

======List of files/folders modified in the last 1 month======

2012-03-26 10:57:15 ----A---- C:\WINDOWS\system.ini
2012-03-13 09:32:36 ----A---- C:\WINDOWS\win.ini
2012-03-13 09:32:21 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 DozeHDD;DozeHDD; C:\WINDOWS\System32\DRIVERS\DozeHDD.sys [2010-01-06 24304]
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\System32\Drivers\iaStor.sys [2008-11-07 319000]
R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2012-03-11 97760]
R0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys [2011-12-23 64512]
R0 NICM;Novell InterService Communication Driver; C:\WINDOWS\system32\drivers\nicm.sys [2004-08-19 38848]
R0 NWFILTER;Novell UNC Path Filter; C:\WINDOWS\system32\NetWare\nwfilter.sys [2005-05-26 15891]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-18 61056]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-03-07 24920]
R1 ANC;ANC; C:\WINDOWS\System32\drivers\ANC.SYS [2011-08-30 11520]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\AswRdr.sys [2012-03-07 35672]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-03-07 612184]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-03-07 337880]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-03-07 53848]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2012-03-11 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2012-03-11 31704]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 TPHKDRV;TPHKDRV; C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys [2008-05-12 17844]
R1 TPPWRIF;TPPWRIF; C:\WINDOWS\System32\drivers\Tppwrif.sys [2010-01-06 4442]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-03-07 20696]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-03-07 95704]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2008-04-09 12672]
R2 NetwareWorkstation;Novell Client for Windows; C:\WINDOWS\system32\NetWare\nwfs.sys [2005-08-19 497423]
R2 NWDHCP;Novell DHCP Inform Client; C:\WINDOWS\system32\NetWare\nwdhcp.sys [2004-08-16 17101]
R2 RESMGR;Novell NetWare Resource Manager; C:\WINDOWS\system32\NetWare\resmgr.sys [2004-06-01 27249]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2008-02-15 46592]
R2 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2008-04-18 11904]
R2 SRVLOC;Novell Service Location; C:\WINDOWS\system32\NetWare\srvloc.sys [2005-05-05 155697]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2008-03-07 154672]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-08-19 991656]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDAU32.sys [2008-06-12 764416]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-08-12 137728]
R3 HECI;Intel(R) Management Engine Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2008-03-26 40832]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2008-04-09 985472]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2008-04-09 210560]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-06-11 6021184]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2008-09-29 23848]
R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2008-06-26 3630080]
R3 NWDNS;Novell DNS Name Space Service Provider; C:\WINDOWS\system32\NetWare\nwdns.sys [2005-06-23 35568]
R3 NWHOST;Novell Host File Name Space Service Provider; C:\WINDOWS\system32\NetWare\NWHOST.sys [2004-02-17 11856]
R3 NWSLP;Novell SLP Name Space Service Provider; C:\WINDOWS\system32\NetWare\nwslp.sys [2005-01-03 20332]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2011-12-08 327400]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-18 67584]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2007-09-15 501800]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2008-04-09 731264]
S1 IBMTPCHK;IBMTPCHK; \??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys []
S2 NWSIPX32;Novell NetWare IPX/SPX Transport Interface; C:\WINDOWS\system32\NetWare\nwsipx32.sys [2004-07-12 41888]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-18 60800]
S3 ASFWHide;ASFWHide; \??\D:\temp\ASFWHide []
S3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2007-11-29 163328]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-08-19 47272]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver; C:\WINDOWS\system32\DRIVERS\CnxEtP.sys []
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver; C:\WINDOWS\system32\DRIVERS\CnxEtU.sys []
S3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver; C:\WINDOWS\system32\DRIVERS\CnxTgNP.sys []
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-18 61824]
S3 NWSAP;Novell SAP Name Space Provider; C:\WINDOWS\system32\NetWare\NWSAP.sys [2003-02-26 23232]
S3 NWSNS;Novell Simple Naming Services; C:\WINDOWS\system32\NetWare\NWSNS.sys [2003-02-13 5808]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcPrfMgrSvc;Ac Profile Manager Service; D:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe [2011-10-20 105536]
R2 AcSvc;Access Connections Main Service; D:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe [2011-10-20 244800]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-03-07 44768]
R2 btwdins;Bluetooth Service; D:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe [2008-08-18 346720]
R2 cmdAgent;COMODO Internet Security Helper Service; D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-03-11 1983232]
R2 DozeSvc;Lenovo Doze Mode Service; D:\Program Files\ThinkPad\Utilities\DOZESVC.EXE [2012-01-23 292200]
R2 EvtEng;Intel® PROSet/Wireless Event Log; D:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-07-10 819200]
R2 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
R2 IBMPMSVC;ThinkPad PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2008-09-29 38176]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre7\bin\jqs.exe [2012-03-27 161664]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 Power Manager DBC Service;Power Manager DBC Service; D:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE [2012-01-23 69632]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-07-10 466944]
R2 S24EventMonitor;Intel® PROSet/Wireless WiFi Service; D:\Program Files\Intel\WiFi\bin\S24EvMon.exe [2008-07-10 901120]
R2 WinStrom-PostgreSQL;WinStrom-PostgreSQL; D:/Program Files/WinStrom/pgsql/bin/pg_ctl.exe runservice -N WinStrom-PostgreSQL -D D:/Program Files/WinStrom/data -w  -o -h 127.0.0.1 -p 5435 []
S2 gupdate;Služba Google Update (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-16 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2012-03-26 2152152]
S2 Service1;WinStromService; D:\Program Files\WinStrom\winstromservice.exe [2009-05-25 559104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 cusrvc;Client Update Service for Novell; C:\WINDOWS\system32\cusrvc.exe [2005-01-18 36864]
S3 gupdatem;Služba Google Update (gupdatem); D:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-16 136176]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Naposledy upravil(a) pike dne 03 dub 2012 22:44, celkem upraveno 1 x.

pike
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 02 dub 2012 14:35

Re: stále zavirován

#2 Příspěvek od pike »

Ahoj,
Ahoj,

Díky za odpověď. Nákaza se vyskytovala ve složce:
C:\Documents and Settings\NetworkService...
šlo o soubory s generovanými názvy a příponami rastrových obrázků, nicméně po náhledu bylo vidět, že se jedná o binární (pravděpodobně spustitelné) soubory

AV (AvastFree Antivirus, poslední verze, aktualizován) vyhazoval vyskakovací okna, něco jsem projížděl avastem, ještě v kombinaci s AdAware (také něco občas našlo). Po Vámi uvedených postupech se situace zklidnila, ale jednou opět Avast vyhodil onen PopUp s nalezením nákazy. Firewall (Comodo) také ukazuje nějaké pokusy o průnik.

Vše jsem nyní zaktualizoval a provedl dle zadání výše znovu a přikládám veškeré logy z výše uvedených skenerů.

díky za Tvůj čas

pike
Přílohy
forum_naughty_logy.zip
(40.93 KiB) Staženo 23 x

pike
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 02 dub 2012 14:35

cesta k nákaze

#3 Příspěvek od pike »

pouze doplňuji,

Avast hlásí nákazu např. zde:

Kód: Vybrat vše

c:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4DMB0L2N\tmytqhmn[1].png
Naposledy upravil(a) pike dne 03 dub 2012 22:45, celkem upraveno 1 x.

pike
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 02 dub 2012 14:35

logy dle zadání

#4 Příspěvek od pike »

Ahoj,

Díky za odpověď. Veškeré logy dle zadání jsou v zipu, log z ComboFixu a log z MBRScan navíc přikládám zde:

Kód: Vybrat vše

ComboFix 12-04-03.02 - Administrator 03.04.2012  21:54:38.3.2 - x86
Systém Microsoft Windows XP Professional  5.1.2600.2.1250.420.1029.18.1944.1286 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
(((((((((((((((((((((((((   Soubory vytvořené od 2012-03-03 do 2012-04-03  )))))))))))))))))))))))))))))))
.
.
2012-04-02 13:29 . 2012-04-02 13:29	--------	d-----w-	d:\program files\trend micro
2012-04-02 13:29 . 2012-04-02 13:29	--------	d-----w-	C:\rsit
2012-03-28 21:53 . 2012-03-28 21:54	--------	d-----w-	d:\program files\WinStrom
2012-03-27 12:01 . 2012-03-27 12:06	--------	d-----w-	d:\program files\Java
2012-03-26 09:17 . 2011-07-16 20:21	302592	----a-w-	C:\gmer.exe
2012-03-26 08:30 . 2012-03-26 08:30	--------	d-----w-	C:\TDSSKiller_Quarantine
2012-03-24 08:53 . 2012-03-16 22:10	--------	d-----w-	d:\program files\Tor Browser
2012-03-23 10:38 . 2012-03-23 10:38	--------	d-----w-	d:\program files\Microsoft Works
2012-03-23 10:38 . 2012-03-23 10:38	--------	d-----w-	d:\program files\Microsoft.NET
2012-03-23 10:29 . 2012-03-23 10:29	--------	d-----r-	C:\MSOCache
2012-03-21 22:33 . 2012-03-21 22:33	--------	d-----w-	d:\program files\COMODO
2012-03-21 11:37 . 2012-03-21 11:37	--------	d-----w-	d:\program files\Samsung Network Printer Utilities
2012-03-21 11:13 . 2012-03-21 11:13	--------	d--h--w-	d:\program files\Zero G Registry
2012-03-21 11:11 . 2012-03-21 11:14	--------	d-----w-	d:\program files\CUAgent
2012-03-21 06:50 . 2012-03-21 06:51	--------	d-----w-	d:\program files\Skype
2012-03-19 11:47 . 2012-03-19 11:47	--------	d-----w-	d:\program files\Mozilla Thunderbird
2012-03-16 08:08 . 2012-03-16 08:08	--------	d-----w-	d:\program files\Toolbar Cleaner
2012-03-16 08:08 . 2012-03-16 08:08	--------	d-----w-	d:\program files\adawaretb
2012-03-16 08:07 . 2012-03-16 08:07	--------	d-----w-	d:\program files\Lavasoft
2012-03-16 02:47 . 2012-03-16 02:47	--------	d-----w-	d:\program files\Google
2012-03-16 02:46 . 2012-03-16 02:46	--------	d-----w-	d:\program files\AVAST Software
2012-03-15 22:10 . 2012-03-16 00:11	--------	d-----w-	d:\program files\CIGLER SOFTWARE
2012-03-15 20:37 . 2012-03-15 20:37	--------	d-----w-	d:\program files\Symantec Ghost Explorer 11.0.2
2012-03-15 18:52 . 2012-03-15 18:52	--------	d-----w-	d:\program files\CCleaner
2012-03-15 08:49 . 2012-03-15 08:49	--------	d-----w-	d:\program files\Microcom
2012-03-14 18:07 . 2012-03-14 18:07	--------	d-----w-	d:\program files\VideoLAN
2012-03-14 18:05 . 2012-03-14 18:05	--------	d-----w-	d:\program files\PDFCreator
2012-03-14 15:22 . 2012-03-14 15:22	--------	d-----w-	d:\program files\Ecd
2012-03-14 12:28 . 2011-03-31 11:16	--------	d-----w-	d:\program files\XnView
2012-03-14 12:26 . 2012-03-14 12:27	--------	d-----w-	d:\program files\PhotoFiltre
2012-03-13 23:01 . 2012-03-17 07:10	--------	d-----w-	d:\program files\Apoint2K
2012-03-13 19:31 . 2012-03-13 19:31	--------	d-----w-	d:\program files\Foxit Software
2012-03-13 19:29 . 2012-03-13 19:29	--------	d-----w-	d:\program files\PSPad editor
2012-03-13 19:12 . 2012-03-18 18:05	--------	d-----w-	d:\program files\Total Commander
2012-03-13 17:43 . 2012-03-13 17:43	--------	d-----w-	d:\program files\Lenovo
2012-03-13 16:48 . 2012-03-13 16:48	--------	d-----w-	d:\program files\MSBuild
2012-03-13 16:48 . 2012-03-13 16:48	--------	d-----w-	d:\program files\Reference Assemblies
2012-03-13 16:46 . 2012-03-13 16:46	--------	d-----w-	d:\program files\MSXML 6.0
2012-03-13 14:01 . 2012-03-20 15:57	--------	d-----w-	d:\program files\ThinkPad
2012-03-13 13:40 . 2012-03-13 13:41	--------	d-----w-	d:\program files\CONEXANT
2012-03-13 13:37 . 2012-03-21 11:13	--------	d--h--w-	d:\program files\InstallShield Installation Information
2012-03-13 13:37 . 2012-03-18 17:00	--------	d-----w-	d:\program files\Realtek
2012-03-13 13:34 . 2012-03-13 17:49	--------	d-----w-	d:\program files\Intel
2012-03-13 13:33 . 2012-03-13 13:33	--------	d-----w-	C:\Intel
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M výpis   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-13 04:38 . 2012-03-15 19:43	97208	----a-w-	d:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-11-07 . 07DE423FB70EBAC5136677E3956FDBC3 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((   SnapShot@2012-03-26_08.57.14   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-06 17:24 . 2009-08-06 17:24	44768              c:\windows\system32\wups2.dll
+ 2012-03-13 07:30 . 2009-08-06 17:24	35552              c:\windows\system32\wups.dll
+ 2012-03-13 07:30 . 2009-08-06 17:24	53472              c:\windows\system32\wuauclt.exe
+ 2012-03-26 14:34 . 2009-08-06 17:24	35552              c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
- 2004-08-18 11:00 . 2012-03-26 08:50	67646              c:\windows\system32\perfc009.dat
+ 2004-08-18 11:00 . 2012-03-26 09:41	67646              c:\windows\system32\perfc009.dat
- 2004-08-18 11:00 . 2012-03-26 08:50	78228              c:\windows\system32\perfc005.dat
+ 2004-08-18 11:00 . 2012-03-26 09:41	78228              c:\windows\system32\perfc005.dat
+ 2012-03-13 07:30 . 2009-08-06 17:24	35552              c:\windows\system32\dllcache\wups.dll
+ 2012-03-13 07:30 . 2009-08-06 17:24	53472              c:\windows\system32\dllcache\wuauclt.exe
+ 2004-08-18 11:00 . 2009-08-06 17:24	96480              c:\windows\system32\dllcache\cdm.dll
+ 2004-08-18 11:00 . 2009-08-06 17:24	96480              c:\windows\system32\cdm.dll
+ 2012-03-13 07:30 . 2009-08-06 17:24	209632              c:\windows\system32\wuweb.dll
+ 2012-03-13 07:30 . 2009-08-06 17:24	327896              c:\windows\system32\wucltui.dll
+ 2012-03-13 07:30 . 2009-08-06 17:23	575704              c:\windows\system32\wuapi.dll
- 2004-08-18 11:00 . 2012-03-26 08:50	432690              c:\windows\system32\perfh009.dat
+ 2004-08-18 11:00 . 2012-03-26 09:41	432690              c:\windows\system32\perfh009.dat
- 2004-08-18 11:00 . 2012-03-26 08:50	429256              c:\windows\system32\perfh005.dat
+ 2004-08-18 11:00 . 2012-03-26 09:41	429256              c:\windows\system32\perfh005.dat
+ 2012-03-27 12:06 . 2012-03-27 12:06	637848              c:\windows\system32\npdeployJava1.dll
+ 2011-03-31 11:53 . 2011-03-31 11:53	250528              c:\windows\system32\Macromed\Flash\FlashUtil11g_ActiveX.exe
+ 2011-03-31 11:53 . 2011-03-31 11:53	335520              c:\windows\system32\Macromed\Flash\FlashUtil11g_ActiveX.dll
+ 2012-03-27 12:06 . 2012-03-27 12:06	224136              c:\windows\system32\javaws.exe
+ 2012-03-27 12:06 . 2012-03-27 12:06	173960              c:\windows\system32\javaw.exe
+ 2012-03-27 12:06 . 2012-03-27 12:06	173960              c:\windows\system32\java.exe
+ 2012-03-13 08:18 . 2012-03-29 09:22	171488              c:\windows\system32\FNTCACHE.DAT
+ 2012-03-13 07:30 . 2009-08-06 17:24	209632              c:\windows\system32\dllcache\wuweb.dll
+ 2012-03-13 07:30 . 2009-08-06 17:24	327896              c:\windows\system32\dllcache\wucltui.dll
+ 2012-03-13 07:30 . 2009-08-06 17:23	575704              c:\windows\system32\dllcache\wuapi.dll
+ 2012-03-27 12:06 . 2012-03-27 12:06	567696              c:\windows\system32\deployJava1.dll
+ 2012-03-27 12:06 . 2012-03-27 12:06	176128              c:\windows\Installer\5ab2c7a.msi
+ 2012-03-27 12:06 . 2012-03-27 12:06	938496              c:\windows\Installer\5ab2c74.msi
+ 2012-03-27 12:01 . 2012-03-27 12:01	519680              c:\windows\Installer\5ab2c70.msi
+ 2012-03-13 07:30 . 2009-08-06 17:23	1929952              c:\windows\system32\wuaueng.dll
+ 2012-03-26 08:28 . 2012-04-02 08:34	2068528              c:\windows\system32\drivers\TDSSKiller.exe
+ 2012-03-13 07:30 . 2009-08-06 17:23	1929952              c:\windows\system32\dllcache\wuaueng.dll
.
((((((((((((((((((((((((((((((((((   Spouštěcí body v registru   )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2011-12-21 15:44	87440	----a-w-	d:\program files\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "d:\program files\adawaretb\adawareDx.dll" [2011-12-21 87440]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15	123536	----a-w-	d:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="d:\program files\CCleaner\CCleaner.exe" [2012-02-22 2761024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"="d:\progra~2\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2012-01-23 818240]
"TPHOTKEY"="d:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-09-30 68976]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-17 141848]
"Apoint"="d:\program files\Apoint2K\Apoint.exe" [2008-03-07 167936]
"avast"="d:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"ACWLIcon"="d:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2011-10-20 191552]
"COMODO Internet Security"="d:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 28672]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"adaware"="reg.exe delete HKCU\Software\AppDataLow\Software\adaware" [X]
"adaware_XP"="reg.exe delete HKCU\Software\adaware" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 15:37	34344	----a-w-	d:\program files\Lenovo\HOTKEY\notifyf2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-08-08 18:14	28672	----a-w-	d:\program files\Lenovo\HOTKEY\tphklock.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages	REG_MULTI_SZ   	msv1_0 nwv1_0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Bluetooth.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Aware Browsing Protection]
2011-11-14 23:15	197288	----a-w-	c:\documents and settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWTRAY]
2002-03-12 09:37	28672	----a-w-	c:\windows\system32\nwtray.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"d:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 DozeHDD;DozeHDD;c:\windows\system32\drivers\DOZEHDD.SYS [13.3.2012 18:57 24304]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16.3.2012 10:08 64512]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [16.3.2012 4:47 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [16.3.2012 4:47 337880]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [11.3.2012 22:13 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [11.3.2012 22:13 31704]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [16.3.2012 4:47 20696]
R2 DozeSvc;Lenovo Doze Mode Service;d:\program files\ThinkPad\Utilities\DOZESVC.EXE [17.3.2012 0:11 292200]
R2 Power Manager DBC Service;Power Manager DBC Service;d:\program files\ThinkPad\Utilities\PWMDBSVC.exe [17.3.2012 0:11 69632]
S2 gupdate;Služba Google Update (gupdate);d:\program files\Google\Update\GoogleUpdate.exe [16.3.2012 4:47 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;d:\program files\Lavasoft\Ad-Aware\AAWService.exe [23.12.2011 8:12 2152152]
S2 WinStrom-PostgreSQL;WinStrom-PostgreSQL;D:/Program Files/WinStrom/pgsql/bin/pg_ctl.exe runservice -N "WinStrom-PostgreSQL" -D "D:/Program Files/WinStrom/data" -w  -o "-h 127.0.0.1 -p 5435" --> D:/Program Files/WinStrom/pgsql/bin/pg_ctl.exe runservice -N WinStrom-PostgreSQL [?]
S3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;c:\windows\system32\DRIVERS\CnxEtP.sys --> c:\windows\system32\DRIVERS\CnxEtP.sys [?]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\DRIVERS\CnxEtU.sys --> c:\windows\system32\DRIVERS\CnxEtU.sys [?]
S3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;c:\windows\system32\DRIVERS\CnxTgNP.sys --> c:\windows\system32\DRIVERS\CnxTgNP.sys [?]
S3 gupdatem;Služba Google Update (gupdatem);d:\program files\Google\Update\GoogleUpdate.exe [16.3.2012 4:47 136176]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - Lavasoft Kernexplorer
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-31 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- d:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-12-23 08:23]
.
2011-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2012-03-16 02:47]
.
2012-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2012-03-16 02:47]
.
2011-03-31 c:\windows\Tasks\PMTask.job
- d:\progra~2\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2012-03-16 00:39]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Office Excel - d:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - d:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - d:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
TCP: Interfaces\{66CE5AD8-1E54-4D3B-8564-D3BB71A73B14}: NameServer = 192.168.10.254
TCP: Interfaces\{A11FDA25-C941-4E1D-9727-93E7C24910DB}: NameServer = 10.0.0.1
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\37bl4p0u.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
.
.
------- Asociace souborů -------
.
txtfile="d:\program files\PSPad editor\PSPad.exe" "%1"
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-03 21:59
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...  
.
skenování skrytých položek 'Po spuštění' ... 
.
skenování skrytých souborů ...  
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinStrom-PostgreSQL]
"ImagePath"="D:/Program Files/WinStrom/pgsql/bin/pg_ctl.exe runservice -N \"WinStrom-PostgreSQL\" -D \"D:/Program Files/WinStrom/data\" -w  -o \"-h 127.0.0.1 -p 5435\""
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\d:\temp\ASFWHide"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinStrom-PostgreSQL]
"ImagePath"="D:/Program Files/WinStrom/pgsql/bin/pg_ctl.exe runservice -N \"WinStrom-PostgreSQL\" -D \"D:/Program Files/WinStrom/data\" -w  -o \"-h 127.0.0.1 -p 5435\""
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\guard32.dll
d:\program files\Lenovo\HOTKEY\tphklock.dll
.
- - - - - - - > 'lsass.exe'(944)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
c:\windows\system32\NLS\ENGLISH\NWSHLXNR.DLL
c:\windows\system32\NLS\ENGLISH\NOVNPNTR.DLL
.
- - - - - - - > 'Explorer.exe'(5376)
c:\windows\system32\guard32.dll
c:\windows\system32\MSCTF.dll
.
- - - - - - - > 'csrss.exe'(860)
c:\windows\system32\cmdcsr.dll
.
Celkový čas: 2012-04-03  22:01:02
ComboFix-quarantined-files.txt  2012-04-03 20:00
ComboFix2.txt  2012-03-26 09:01
.
Před spuštěním: 2 813 718 528
Po spuštění: 2 803 847 168
.
- - End Of File - - 1352AA7B1EE3C3075CA972F7CCD6A25C
alespoň tak jsem pochopil, že to chceš vložit

díky

pike
Naposledy upravil(a) pike dne 03 dub 2012 22:06, celkem upraveno 1 x.

pike
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 02 dub 2012 14:35

a ještě zip

#5 Příspěvek od pike »

ještě ten zip v příloze...
Přílohy
forum_naughty_logy_02.zip
(111.46 KiB) Staženo 24 x

pike
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 02 dub 2012 14:35

Re: stále zavirován

#6 Příspěvek od pike »

Ahoj,

Po Velikonocích zpět. Příspěvek jsem četl již před, ale narychlo a pak byl pryč. Dám to dohromady během zítřka. K Tvým otázkám:

ano, na nb byla původně Vista, stejně jako Ty :). ji i já nemám rád, tak šla pryč...
chápu, že logy z CF stejně jako TDSSKiller se noží díky mým předchozím pokusům 'bez dozoru' ale snažil jsem se projít fóra než se na něco zeptám a páchal jsem na vlastní pěst, což v tomto případě bylo nezodpovědné :(.
MBRScan uvádí OS: Windows XP Home, ale jsou to WinXP Profi (což asi není podstatné)

PS:
na jaké fakultě jsi viděl Novell Netware?

Odpovědět