autorun.inf, vir hnedle na flešce i ostatních discích
Napsal: 16 dub 2012 14:32
Ahoj, včera jsem byl u sousedky že jí prý nějak blbne antivir.
1.přijdu tam: antivir (avast) zablokovaný, firewall (windowsovský) taky. odinstalace antiviru nefunguje a instalace jiného také ne. Nejdřív nešla ani jaká koliv stránka s těmito SW (avg,eset, atd - opraveno v MBAM)
2.vrazim tam flesku a šup hned se mi na ní objevil autorun.inf a soubor mnho.exe - smažu to ale hned je to tam znova akorád ten soubor *.exe se jmenuje jinak když názvy dávám do googlu tak to nic nenachází. usuzuji že název se generuje pokaždé jiný. v tom autorunu je vždy odkaz na ten soubor.
řikám si to nebude snad nic hrozného: má nainstalovaný spybot search and destroy - spustít se ale než se vůbec objeví okno hned ho "něco" sestřelí.
3.chci spustit combofix: ten jde sice spustit ale jak mile má dojít už k nějakému scanu tak se PC kousne.
4.chci to zkusit v nouzovém režimu, ale do něj to ani nenaběhe a PC se resne. zakázal jsem automatický restart při selhání a to končí nouzový režim BSOD že mám zkontrolovat disk CHKDSK. to jsem udělal ,ale výsledek holý žádný
5. zkusim MBAM - ten šel log jsem si ale nenahrál na flash nic méně v něm nic vážného nebylo (nejsem v tomhle směru taková lama)
6. další jsem zkusil RSIT přikládám log - ty tasks At1.job - At4.job jsou vpořádku to je nějaké zálohování.
Předem děkuji za rady
Logfile of random's system information tool 1.09 (written by random/random)
Run by Kalousová at 2012-04-16 12:05:42
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 37 GB (51%) free of 73 GB
Total RAM: 501 MB (27% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do-Not-Track - C:\Program Files\AVG\AVG2012\avgdtiex.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-01-24 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-10 192112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll [2012-04-10 1003576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-01-24 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-01-24 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files\Seznam.cz\listicka.dll [2010-10-07 1961240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-07 187672]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-10 192112]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2006-07-21 167936]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2006-07-21 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2006-07-21 159744]
"Cobian Backup 6"=C:\Program Files\Cobian Backup 6\CobBU.exe [2005-01-14 418816]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 117616]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 324328]
"ToolboxFX"=C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe [2010-10-25 1177144]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2010-06-09 131128]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1764864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 225280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
C:\WINDOWS\sttray.exe [2006-09-07 376832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3
"avast! Mail Scanner"=3
"avast! Antivirus"=2
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Documents and Settings\Kalousová\Nabídka Start\Programy\Po spuštění
login.bat
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-07-21 147456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:Enabled:InocIT"
"C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:Enabled:Realmon"
"C:\Documents and Settings\Kalousová\Local Settings\Temporary Internet Files\Content.IE5\IGUSP601\winbox[1].exe"="C:\Documents and Settings\Kalousová\Local Settings\Temporary Internet Files\Content.IE5\IGUSP601\winbox[1].exe:*:Enabled:winbox[1]"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"G:\RECYCLER\e621ca05.exe"="G:\RECYCLER\e621ca05.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wscntfy.exe"="C:\WINDOWS\system32\wscntfy.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\rogbo.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\rogbo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winutoly.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winutoly.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winydhfd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winydhfd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkpch.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkpch.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winxxpmty.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winxxpmty.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winienp.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winienp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\intl.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\intl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windmiadx.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windmiadx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winotxsj.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winotxsj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrxkki.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrxkki.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vrlsyn.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vrlsyn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\glyvxr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\glyvxr.exe:*:Enabled:ipsec"
"C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\iaeaa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\iaeaa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winskvuq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winskvuq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jiwee.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jiwee.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlwlrjq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlwlrjq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ncusj.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ncusj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjoka.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjoka.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrkot.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrkot.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\anix.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\anix.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ydxv.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ydxv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winifulpa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winifulpa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winsrswrl.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winsrswrl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrnfoux.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrnfoux.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\blfb.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\blfb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winghac.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winghac.exe:*:Enabled:ipsec"
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"="C:\Program Files\Common Files\Java\Java Update\jusched.exe:*:Enabled:ipsec"
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe:*:Enabled:ipsec"
"C:\Program Files\Cobian Backup 6\cobui.exe"="C:\Program Files\Cobian Backup 6\cobui.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winphogr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winphogr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\fpdqrs.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\fpdqrs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmwmfbs.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmwmfbs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqkejp.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqkejp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqocxu.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqocxu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfnuljm.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfnuljm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\faxfb.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\faxfb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\bkng.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\bkng.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hwpm.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hwpm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkscdou.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkscdou.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrbaul.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrbaul.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hlcebb.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hlcebb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hxdkxa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hxdkxa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkvwv.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkvwv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\drup.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\drup.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvfwtvd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvfwtvd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbochq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbochq.exe:*:Enabled:ipsec"
"C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe"="C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winywjxat.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winywjxat.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kpwit.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kpwit.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\ntvdm.exe"="C:\WINDOWS\system32\ntvdm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\oscqxf.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\oscqxf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\olor.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\olor.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winwouwf.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winwouwf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpqnvc.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpqnvc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\mnhyfg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\mnhyfg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfcwvxo.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfcwvxo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ahpn.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ahpn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\qwwgh.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\qwwgh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\pmdua.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\pmdua.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\gukpfl.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\gukpfl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winoetd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winoetd.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxtray.exe"="C:\WINDOWS\system32\igfxtray.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\whmej.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\whmej.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpkeym.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpkeym.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrmhwm.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrmhwm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpwoxa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpwoxa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmovhqr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmovhqr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winooks.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winooks.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbuccfd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbuccfd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winljnrr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winljnrr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vjujx.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vjujx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjfvw.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjfvw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\dvxsg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\dvxsg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbqxs.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbqxs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingltmt.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingltmt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\aojld.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\aojld.exe:*:Enabled:ipsec"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\hkcmd.exe"="C:\WINDOWS\system32\hkcmd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnktnh.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnktnh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqiwr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqiwr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqavok.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqavok.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windyyopv.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windyyopv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingtptq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingtptq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlomvvd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlomvvd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvyohsg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvyohsg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kjas.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kjas.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kwpgy.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kwpgy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnrnlr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnrnlr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jjgify.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jjgify.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlegg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlegg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\yunq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\yunq.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-04-16 12:05:43 ----D---- C:\Program Files\trend micro
2012-04-16 12:05:42 ----D---- C:\rsit
2012-04-12 16:06:52 ----HD---- C:\WINDOWS\$NtUninstallKB2653956$
2012-04-11 09:18:48 ----SHD---- C:\FOUND.003
2012-04-11 08:52:54 ----SHD---- C:\FOUND.002
2012-04-10 14:44:25 ----D---- C:\Documents and Settings\Kalousová\Data aplikací\AVG2012
2012-04-10 14:43:00 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2012-04-10 14:42:16 ----HD---- C:\$AVG
2012-04-10 14:42:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG2012
2012-04-10 14:41:51 ----D---- C:\Program Files\AVG
2012-04-10 14:38:26 ----D---- C:\Documents and Settings\Kalousová\Data aplikací\Google
2012-04-10 12:37:54 ----A---- C:\WINDOWS\zip.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\SWXCACLS.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\SWSC.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\SWREG.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\sed.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\PEV.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\NIRCMD.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\MBR.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\grep.exe
2012-04-10 12:37:49 ----SD---- C:\ComboFix
2012-04-10 11:17:15 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2012-04-10 11:17:15 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-04-10 11:17:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-04-10 11:10:00 ----D---- C:\!KillBox
2012-04-10 09:53:32 ----A---- C:\WINDOWS\ntbtlog.txt
2012-04-10 09:51:36 ----SHD---- C:\FOUND.001
2012-04-10 09:35:52 ----D---- C:\Qoobox
2012-04-10 09:34:27 ----ASH---- C:\pagefile.sys
2012-04-10 09:06:50 ----SHD---- C:\FOUND.000
2012-04-10 08:34:42 ----D---- C:\Program Files\CCleaner
2012-04-10 08:33:57 ----D---- C:\Program Files\Google
2012-04-10 08:33:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2012-04-06 11:39:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-04-06 08:58:33 ----A---- C:\Boot.bak
2012-04-06 08:58:31 ----RASHD---- C:\cmdcons
2012-04-06 08:50:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2012-04-06 08:50:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-03-19 14:49:18 ----D---- C:\WINDOWS\pss
2012-03-19 14:45:46 ----D---- C:\WINDOWS\ERDNT
2012-03-19 14:33:23 ----D---- C:\Program Files\ESET
2012-03-19 14:33:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2012-03-19 08:28:43 ----D---- C:\Kirhofová starý disk
======List of files/folders modified in the last 1 month======
2012-04-13 14:48:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-04-12 16:13:38 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-04-12 16:11:28 ----A---- C:\WINDOWS\system32\MRT.INI
2012-04-12 16:07:04 ----A---- C:\WINDOWS\system32\MRT.exe
2012-04-12 16:06:58 ----A---- C:\WINDOWS\imsins.BAK
2012-04-12 13:53:42 ----A---- C:\WINDOWS\NeroDigital.ini
2012-04-10 10:48:38 ----ASH---- C:\boot.ini
2012-04-10 10:31:04 ----A---- C:\WINDOWS\WINCMD.INI
2012-04-10 07:21:02 ----A---- C:\WINDOWS\OEWABLog.txt
2012-03-21 15:33:36 ----A---- C:\WINDOWS\win.ini
2012-03-21 15:33:36 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
R3 amsint32;amsint32; \??\C:\WINDOWS\system32\drivers\jqrlmn.sys []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HPFXBULKLEDM;HPFXBULKLEDM; C:\WINDOWS\system32\drivers\hppcbulkio.sys [2010-12-14 20504]
R3 HPFXFAX;HPFXFAX; C:\WINDOWS\system32\drivers\hppcfaxio.sys [2010-12-14 21528]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2006-07-21 1095968]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-09-07 1178088]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\avgidsehx.sys []
S3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys []
S3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys []
S3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\clever\LOCALS~1\Temp\catchme.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2006-01-12 163328]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 pxtdapob;pxtdapob; \??\C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\pxtdapob.sys []
S3 sfng32;Sonic Focus Plugin for Sigmatel HDA; C:\WINDOWS\system32\drivers\sfng32.sys [2005-12-02 41728]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-25 145920]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2012-01-24 153376]
R2 MSSQL$BANKKLIENT;MSSQL$BANKKLIENT; C:\bkwin\MSDE2K\MSSQL$BANKKLIENT\Binn\sqlservr.exe [2002-12-17 7520337]
R2 STacSV;SigmaTel Audio Service; C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe [2006-09-07 86016]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-10 214000]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\pev.3XE [2011-06-26 256000]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-10 214000]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-04-10 260592]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 148032]
S3 SQLAgent$BANKKLIENT;SQLAgent$BANKKLIENT; C:\bkwin\MSDE2K\MSSQL$BANKKLIENT\Binn\sqlagent.EXE [2002-12-17 393792]
S3 UMWdf;Sada ovladačů pro uživatelský režim systému Windows; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
S4 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe []
S4 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 798720]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
1.přijdu tam: antivir (avast) zablokovaný, firewall (windowsovský) taky. odinstalace antiviru nefunguje a instalace jiného také ne. Nejdřív nešla ani jaká koliv stránka s těmito SW (avg,eset, atd - opraveno v MBAM)
2.vrazim tam flesku a šup hned se mi na ní objevil autorun.inf a soubor mnho.exe - smažu to ale hned je to tam znova akorád ten soubor *.exe se jmenuje jinak když názvy dávám do googlu tak to nic nenachází. usuzuji že název se generuje pokaždé jiný. v tom autorunu je vždy odkaz na ten soubor.
řikám si to nebude snad nic hrozného: má nainstalovaný spybot search and destroy - spustít se ale než se vůbec objeví okno hned ho "něco" sestřelí.
3.chci spustit combofix: ten jde sice spustit ale jak mile má dojít už k nějakému scanu tak se PC kousne.
4.chci to zkusit v nouzovém režimu, ale do něj to ani nenaběhe a PC se resne. zakázal jsem automatický restart při selhání a to končí nouzový režim BSOD že mám zkontrolovat disk CHKDSK. to jsem udělal ,ale výsledek holý žádný
5. zkusim MBAM - ten šel log jsem si ale nenahrál na flash nic méně v něm nic vážného nebylo (nejsem v tomhle směru taková lama)
6. další jsem zkusil RSIT přikládám log - ty tasks At1.job - At4.job jsou vpořádku to je nějaké zálohování.
Předem děkuji za rady
Logfile of random's system information tool 1.09 (written by random/random)
Run by Kalousová at 2012-04-16 12:05:42
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 37 GB (51%) free of 73 GB
Total RAM: 501 MB (27% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do-Not-Track - C:\Program Files\AVG\AVG2012\avgdtiex.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-01-24 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-10 192112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll [2012-04-10 1003576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-01-24 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-01-24 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files\Seznam.cz\listicka.dll [2010-10-07 1961240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-07 187672]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-10 192112]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2006-07-21 167936]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2006-07-21 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2006-07-21 159744]
"Cobian Backup 6"=C:\Program Files\Cobian Backup 6\CobBU.exe [2005-01-14 418816]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 117616]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 324328]
"ToolboxFX"=C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe [2010-10-25 1177144]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2010-06-09 131128]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1764864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 225280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
C:\WINDOWS\sttray.exe [2006-09-07 376832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3
"avast! Mail Scanner"=3
"avast! Antivirus"=2
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Documents and Settings\Kalousová\Nabídka Start\Programy\Po spuštění
login.bat
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-07-21 147456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CA\eTrust Antivirus\InocIT.exe"="C:\Program Files\CA\eTrust Antivirus\InocIT.exe:*:Enabled:InocIT"
"C:\Program Files\CA\eTrust Antivirus\Realmon.exe"="C:\Program Files\CA\eTrust Antivirus\Realmon.exe:*:Enabled:Realmon"
"C:\Documents and Settings\Kalousová\Local Settings\Temporary Internet Files\Content.IE5\IGUSP601\winbox[1].exe"="C:\Documents and Settings\Kalousová\Local Settings\Temporary Internet Files\Content.IE5\IGUSP601\winbox[1].exe:*:Enabled:winbox[1]"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"G:\RECYCLER\e621ca05.exe"="G:\RECYCLER\e621ca05.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wscntfy.exe"="C:\WINDOWS\system32\wscntfy.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\rogbo.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\rogbo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winutoly.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winutoly.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winydhfd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winydhfd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkpch.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkpch.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winxxpmty.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winxxpmty.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winienp.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winienp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\intl.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\intl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windmiadx.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windmiadx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winotxsj.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winotxsj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrxkki.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrxkki.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vrlsyn.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vrlsyn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\glyvxr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\glyvxr.exe:*:Enabled:ipsec"
"C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\iaeaa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\iaeaa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winskvuq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winskvuq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jiwee.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jiwee.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlwlrjq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlwlrjq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ncusj.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ncusj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjoka.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjoka.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrkot.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrkot.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\anix.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\anix.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ydxv.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ydxv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winifulpa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winifulpa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winsrswrl.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winsrswrl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrnfoux.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrnfoux.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\blfb.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\blfb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winghac.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winghac.exe:*:Enabled:ipsec"
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"="C:\Program Files\Common Files\Java\Java Update\jusched.exe:*:Enabled:ipsec"
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe:*:Enabled:ipsec"
"C:\Program Files\Cobian Backup 6\cobui.exe"="C:\Program Files\Cobian Backup 6\cobui.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winphogr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winphogr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\fpdqrs.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\fpdqrs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmwmfbs.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmwmfbs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqkejp.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqkejp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqocxu.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqocxu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfnuljm.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfnuljm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\faxfb.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\faxfb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\bkng.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\bkng.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hwpm.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hwpm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkscdou.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkscdou.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrbaul.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrbaul.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hlcebb.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hlcebb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hxdkxa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\hxdkxa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkvwv.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winkvwv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\drup.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\drup.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvfwtvd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvfwtvd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbochq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbochq.exe:*:Enabled:ipsec"
"C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe"="C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winywjxat.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winywjxat.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kpwit.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kpwit.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\ntvdm.exe"="C:\WINDOWS\system32\ntvdm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\oscqxf.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\oscqxf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\olor.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\olor.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winwouwf.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winwouwf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpqnvc.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpqnvc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\mnhyfg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\mnhyfg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfcwvxo.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winfcwvxo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ahpn.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\ahpn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\qwwgh.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\qwwgh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\pmdua.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\pmdua.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\gukpfl.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\gukpfl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winoetd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winoetd.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxtray.exe"="C:\WINDOWS\system32\igfxtray.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\whmej.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\whmej.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpkeym.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpkeym.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrmhwm.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winrmhwm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpwoxa.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winpwoxa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmovhqr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winmovhqr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winooks.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winooks.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbuccfd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbuccfd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winljnrr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winljnrr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vjujx.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\vjujx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjfvw.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winjfvw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\dvxsg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\dvxsg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbqxs.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winbqxs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingltmt.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingltmt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\aojld.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\aojld.exe:*:Enabled:ipsec"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\hkcmd.exe"="C:\WINDOWS\system32\hkcmd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnktnh.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnktnh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqiwr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqiwr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqavok.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winqavok.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windyyopv.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\windyyopv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingtptq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\wingtptq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlomvvd.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlomvvd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvyohsg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winvyohsg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kjas.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kjas.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kwpgy.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\kwpgy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnrnlr.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winnrnlr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jjgify.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\jjgify.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlegg.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\winlegg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\yunq.exe"="C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\yunq.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-04-16 12:05:43 ----D---- C:\Program Files\trend micro
2012-04-16 12:05:42 ----D---- C:\rsit
2012-04-12 16:06:52 ----HD---- C:\WINDOWS\$NtUninstallKB2653956$
2012-04-11 09:18:48 ----SHD---- C:\FOUND.003
2012-04-11 08:52:54 ----SHD---- C:\FOUND.002
2012-04-10 14:44:25 ----D---- C:\Documents and Settings\Kalousová\Data aplikací\AVG2012
2012-04-10 14:43:00 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2012-04-10 14:42:16 ----HD---- C:\$AVG
2012-04-10 14:42:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG2012
2012-04-10 14:41:51 ----D---- C:\Program Files\AVG
2012-04-10 14:38:26 ----D---- C:\Documents and Settings\Kalousová\Data aplikací\Google
2012-04-10 12:37:54 ----A---- C:\WINDOWS\zip.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\SWXCACLS.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\SWSC.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\SWREG.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\sed.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\PEV.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\NIRCMD.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\MBR.exe
2012-04-10 12:37:54 ----A---- C:\WINDOWS\grep.exe
2012-04-10 12:37:49 ----SD---- C:\ComboFix
2012-04-10 11:17:15 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2012-04-10 11:17:15 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-04-10 11:17:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-04-10 11:10:00 ----D---- C:\!KillBox
2012-04-10 09:53:32 ----A---- C:\WINDOWS\ntbtlog.txt
2012-04-10 09:51:36 ----SHD---- C:\FOUND.001
2012-04-10 09:35:52 ----D---- C:\Qoobox
2012-04-10 09:34:27 ----ASH---- C:\pagefile.sys
2012-04-10 09:06:50 ----SHD---- C:\FOUND.000
2012-04-10 08:34:42 ----D---- C:\Program Files\CCleaner
2012-04-10 08:33:57 ----D---- C:\Program Files\Google
2012-04-10 08:33:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2012-04-06 11:39:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-04-06 08:58:33 ----A---- C:\Boot.bak
2012-04-06 08:58:31 ----RASHD---- C:\cmdcons
2012-04-06 08:50:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2012-04-06 08:50:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-03-19 14:49:18 ----D---- C:\WINDOWS\pss
2012-03-19 14:45:46 ----D---- C:\WINDOWS\ERDNT
2012-03-19 14:33:23 ----D---- C:\Program Files\ESET
2012-03-19 14:33:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2012-03-19 08:28:43 ----D---- C:\Kirhofová starý disk
======List of files/folders modified in the last 1 month======
2012-04-13 14:48:40 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-04-12 16:13:38 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-04-12 16:11:28 ----A---- C:\WINDOWS\system32\MRT.INI
2012-04-12 16:07:04 ----A---- C:\WINDOWS\system32\MRT.exe
2012-04-12 16:06:58 ----A---- C:\WINDOWS\imsins.BAK
2012-04-12 13:53:42 ----A---- C:\WINDOWS\NeroDigital.ini
2012-04-10 10:48:38 ----ASH---- C:\boot.ini
2012-04-10 10:31:04 ----A---- C:\WINDOWS\WINCMD.INI
2012-04-10 07:21:02 ----A---- C:\WINDOWS\OEWABLog.txt
2012-03-21 15:33:36 ----A---- C:\WINDOWS\win.ini
2012-03-21 15:33:36 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
R3 amsint32;amsint32; \??\C:\WINDOWS\system32\drivers\jqrlmn.sys []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HPFXBULKLEDM;HPFXBULKLEDM; C:\WINDOWS\system32\drivers\hppcbulkio.sys [2010-12-14 20504]
R3 HPFXFAX;HPFXFAX; C:\WINDOWS\system32\drivers\hppcfaxio.sys [2010-12-14 21528]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2006-07-21 1095968]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-09-07 1178088]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\avgidsehx.sys []
S3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys []
S3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys []
S3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\clever\LOCALS~1\Temp\catchme.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2006-01-12 163328]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 pxtdapob;pxtdapob; \??\C:\DOCUME~1\KALOUS~1\LOCALS~1\Temp\pxtdapob.sys []
S3 sfng32;Sonic Focus Plugin for Sigmatel HDA; C:\WINDOWS\system32\drivers\sfng32.sys [2005-12-02 41728]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-25 145920]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2012-01-24 153376]
R2 MSSQL$BANKKLIENT;MSSQL$BANKKLIENT; C:\bkwin\MSDE2K\MSSQL$BANKKLIENT\Binn\sqlservr.exe [2002-12-17 7520337]
R2 STacSV;SigmaTel Audio Service; C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe [2006-09-07 86016]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-10 214000]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\pev.3XE [2011-06-26 256000]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-10 214000]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-04-10 260592]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 148032]
S3 SQLAgent$BANKKLIENT;SQLAgent$BANKKLIENT; C:\bkwin\MSDE2K\MSSQL$BANKKLIENT\Binn\sqlagent.EXE [2002-12-17 393792]
S3 UMWdf;Sada ovladačů pro uživatelský režim systému Windows; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
S4 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe []
S4 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 798720]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------