Stránka 1 z 2

RECYCLER/e621ca05.exe

Napsal: 09 lis 2012 08:03
od TheMagicLight
Dobrý den. Povedlo se mi zasvinit si počítač virem RECYCLER/e621ca05.exe . Zatím mi sice nic nesmazal, ale mam to snad na všech Flash discích, kde si ten vir vytvoří skrytou složku RECYCLER a uvnitř soubory desktop.ini a e621ca05.exe + všechny složky uvnitř Flashky jsou jako zastupci, který se spouští v příkazové řádce (něco jako %windir%/ bla bla bla). Po připojení k internetu si vir sám začne něco stahovat, což je při FUP limitu 600MB měsíčně celkem dost blbý.
Jak to odstranit z PC a všech Flash disků?
Předem děkuji za pomoc.

Re: RECYCLER/e621ca05.exe

Napsal: 09 lis 2012 08:18
od stell
zdravim
Podla tohto mojho navodu sprav vsetko.
http://www.viruskasino.com/2011/08/erro ... disku.html
Logy z..
USBFIX
Malwarebytes
Vloz sem, a po vycisteni vloz sem aj log z RSIT.
http://forum.viry.cz/viewtopic.php?f=13&t=105895

Re: RECYCLER/e621ca05.exe

Napsal: 09 lis 2012 08:58
od TheMagicLight
Děkuji, hned jak se dostanu na svůj PC (neděle), udělám vše podle návodu.

Re: RECYCLER/e621ca05.exe

Napsal: 09 lis 2012 09:27
od stell
ok, stacis.

Re: RECYCLER/e621ca05.exe

Napsal: 11 lis 2012 20:20
od TheMagicLight
Dobrý den.
Dávam sem všechny 3 logy...

USBFix
############################## | UsbFix V 7.100 | [Deletion]

User: Gamer (Administrator) # GAMEPC
Updated 11/11/2012 by El Desaparecido
Started at 18:10:26 | 11/11/2012

Website: http://sosvirus.org
Contact: contact@eldesaparecido.com

PC: MSI (MS-6590) (X86-based PC
CPU: AMD Athlon(tm) XP 2600+ (2010)
RAM -> [Total : 1279 | Free : 932]
BIOS: Version 07.00T
BOOT: Normal boot

OS: Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 7.0.5730.13

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 112 Gb (31 Mb free - 28%) [] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
F:\ -> Removable drive # 976 Mb (933 Mb free - 96%) [FLASH DISK] # FAT
G:\ -> Removable drive # 4 Gb (1 Mb free - 33%) [BEZZUBKA] # FAT32
H:\ -> Removable drive # 7 Gb (155 Mb free - 2%) [KINGSTON] # FAT32
I:\ -> Removable drive # 4 Gb (497 Mb free - 13%) [MCDISC 4GB] # FAT32
J:\ -> Removable drive # 968 Mb (894 Mb free - 92%) [] # FAT

################## | Active Processes |

C:\WINDOWS\System32\smss.exe (400)
C:\WINDOWS\system32\csrss.exe (680)
C:\WINDOWS\system32\winlogon.exe (704)
C:\WINDOWS\system32\services.exe (748)
C:\WINDOWS\system32\lsass.exe (760)
C:\WINDOWS\system32\svchost.exe (912)
C:\WINDOWS\system32\svchost.exe (988)
C:\WINDOWS\System32\svchost.exe (1028)
C:\WINDOWS\system32\svchost.exe (1064)
C:\WINDOWS\system32\svchost.exe (1224)
C:\WINDOWS\system32\svchost.exe (1272)
C:\WINDOWS\system32\spoolsv.exe (1440)
C:\Program Files\Java\jre7\bin\jqs.exe (1628)
C:\WINDOWS\system32\nvsvc32.exe (1660)
C:\Program Files\Promise Technology, Inc\Promise Array Management\MsgAgt.exe (1700)
C:\Program Files\Promise Technology, Inc\Promise Array Management\MsgSvr.exe (1760)
C:\WINDOWS\System32\snmp.exe (1804)
C:\WINDOWS\system32\svchost.exe (1836)
C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe (1900)
C:\WINDOWS\System32\alg.exe (256)
C:\WINDOWS\Explorer.EXE (1376)
C:\WINDOWS\system32\wscntfy.exe (1780)
C:\UsbFix\Go.exe (3076)
C:\WINDOWS\system32\wbem\wmiprvse.exe (2904)

################## | Stopped processes |

Stopped! C:\WINDOWS\system32\spoolsv.exe (1440)
Stopped! C:\Program Files\Java\jre7\bin\jqs.exe (1628)
Stopped! C:\WINDOWS\system32\nvsvc32.exe (1660)
Stopped! C:\Program Files\Promise Technology, Inc\Promise Array Management\MsgAgt.exe (1700)
Stopped! C:\Program Files\Promise Technology, Inc\Promise Array Management\MsgSvr.exe (1760)
Stopped! C:\WINDOWS\System32\snmp.exe (1804)
Stopped! C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe (1900)
Stopped! C:\WINDOWS\System32\alg.exe (256)
Stopped! C:\WINDOWS\Explorer.EXE (1376)
Stopped! C:\WINDOWS\system32\wscntfy.exe (1780)

################## | Files # Infected Folders |

Deleted ! F:\RECYCLER.lnk
Deleted ! F:\EXTREME.lnk
Deleted ! G:\Prezentace.lnk
Deleted ! G:\Nová složka.lnk
Deleted ! H:\deepolis.lnk
Deleted ! H:\swf.lnk
Deleted ! H:\AGF.lnk
Deleted ! H:\FlatOut.lnk
Deleted ! H:\fotky holky.lnk
Deleted ! H:\Rocket in Danger.lnk
Deleted ! H:\mapy DP.lnk
Deleted ! H:\Mann-Filter Rallye.lnk
Deleted ! H:\Hippo Racer.lnk
Deleted ! H:\Brad and Roxy's Amazing Downhill.lnk
Deleted ! H:\Meteor Storm.lnk
Deleted ! H:\Nová složka (2).lnk
Deleted ! H:\qip cz.lnk
Deleted ! H:\AJ.lnk
Deleted ! H:\tanks-0.9.2.lnk
Deleted ! H:\tata.lnk
Deleted ! H:\__DT.lnk
Deleted ! H:\TopWare.lnk
Deleted ! H:\GCS.lnk
Deleted ! H:\2010-09-01 go_prima_2010.lnk
Deleted ! H:\RENDERS.lnk
Deleted ! H:\FOUND.000.lnk
Deleted ! H:\McLaren Racing.lnk
Deleted ! H:\Space Oddity.lnk
Deleted ! H:\Kristián.lnk
Deleted ! H:\Ninja Fruit.lnk
Deleted ! H:\VYTISKNOUT.lnk
Deleted ! H:\WinRAR.lnk
Deleted ! H:\GCS_TML_info.lnk
Deleted ! H:\prezentace.lnk
Deleted ! H:\fotak.lnk
Deleted ! H:\Deepolis - Vyúčtování.lnk
Deleted ! H:\2009-02-13-1641-36.lnk
Deleted ! H:\Custom Production Presets 7.0.lnk
Deleted ! H:\bin.lnk
Deleted ! H:\TISK.lnk
Deleted ! H:\adobe.lnk
Deleted ! H:\minecraft.lnk
Deleted ! H:\videa.lnk
Deleted ! H:\World of many buildings.lnk
Deleted ! H:\INVedit.lnk
Deleted ! H:\.Trash-1001.lnk
Deleted ! H:\New World of moje.lnk
Deleted ! H:\Bandicam.lnk
Deleted ! H:\Glacier World by RedStoneCHRIS.lnk
Deleted ! H:\Camtasia Studio 7.lnk
Deleted ! H:\Fonty_old.lnk
Deleted ! H:\Farm Frenzy 2 CZ+crack.lnk
Deleted ! H:\GTA La Heist.lnk
Deleted ! H:\becherragdoll.lnk
Deleted ! H:\data.lnk
Deleted ! I:\For Elii.lnk
Deleted ! I:\server.lnk
Deleted ! I:\atanua.lnk
Deleted ! I:\skin3.lnk
Deleted ! I:\Charred Dirt.lnk
Deleted ! I:\Nová složka.lnk
Deleted ! I:\UB's.lnk
Deleted ! I:\JCreator Pro 4.50.010.lnk
Deleted ! I:\Sony Vegas 11 PRO.lnk
Deleted ! I:\Minecraft Tekkit Pack.lnk
Deleted ! I:\TheMagicLight.lnk
Deleted ! I:\MCSkin3D.lnk
Deleted ! I:\Games.lnk
Deleted ! I:\!!!TISK!!!.lnk
Deleted ! C:\DOCUME~1\Gamer\LOCALS~1\Temp\AutoRun.exe
Deleted ! C:\Recycler\S-1-5-21-57989841-2111687655-725345543-1004
Not deleted ! D:\Autorun.inf
Not deleted ! D:\autorun.exe
Not deleted ! E:\autorun.inf
Deleted ! I:\run.bat

(!) Temporary files deleted.

################## | Registry |

Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig

################## | Mountpoints2 |

Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{071bf540-e891-11e1-9345-000c764286ca}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{1fedf0c0-d507-11e1-9d87-bb7c36f74672}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{22e5a8dc-b902-11e1-8386-95ff7308177d}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{daa23654-b93e-11e1-a570-8eea7be9b072}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{e36db11a-e520-11e1-bb07-000c764286ca}

################## | Listing |

[13/08/2012 - 10:44:44 | D ] C:\$WINDOWS.~BT
[06/09/2012 - 18:35:05 | N | 2056] C:\.swtch
[17/06/2012 - 20:24:36 | N | 0] C:\AUTOEXEC.BAT
[17/06/2012 - 20:57:44 | N | 211] C:\boot.ini
[25/10/2001 - 15:00:00 | N | 4952] C:\Bootfont.bin
[17/06/2012 - 20:24:36 | N | 0] C:\CONFIG.SYS
[03/11/2012 - 10:34:11 | D ] C:\D900IXDGE2
[13/08/2012 - 09:56:48 | D ] C:\de4aebd0f29ae4aba6b6442e752eab
[17/06/2012 - 20:28:52 | D ] C:\Documents and Settings
[07/11/2007 - 07:00:40 | N | 17734] C:\eula.1028.txt
[07/11/2007 - 07:00:40 | N | 17734] C:\eula.1031.txt
[07/11/2007 - 07:00:40 | N | 10134] C:\eula.1033.txt
[07/11/2007 - 07:00:40 | N | 17734] C:\eula.1036.txt
[07/11/2007 - 07:00:40 | N | 17734] C:\eula.1040.txt
[07/11/2007 - 07:00:40 | N | 118] C:\eula.1041.txt
[07/11/2007 - 07:00:40 | N | 17734] C:\eula.1042.txt
[07/11/2007 - 07:00:40 | N | 17734] C:\eula.2052.txt
[07/11/2007 - 07:00:40 | N | 17734] C:\eula.3082.txt
[07/11/2007 - 07:00:40 | N | 1110] C:\globdata.ini
[04/09/2012 - 17:57:50 | D ] C:\GTA San Andreas Music
[05/09/2012 - 12:36:42 | N | 40935] C:\haxxx.log
[11/11/2012 - 17:40:47 | ASH | 1341706240] C:\hiberfil.sys
[22/06/2012 - 15:53:02 | D ] C:\Inetpub
[07/11/2007 - 07:03:18 | N | 562688] C:\install.exe
[07/11/2007 - 07:00:40 | N | 843] C:\install.ini
[07/11/2007 - 07:03:18 | N | 76304] C:\install.res.1028.dll
[07/11/2007 - 07:03:18 | N | 96272] C:\install.res.1031.dll
[07/11/2007 - 07:03:18 | N | 91152] C:\install.res.1033.dll
[07/11/2007 - 07:03:18 | N | 97296] C:\install.res.1036.dll
[07/11/2007 - 07:03:18 | N | 95248] C:\install.res.1040.dll
[07/11/2007 - 07:03:18 | N | 81424] C:\install.res.1041.dll
[07/11/2007 - 07:03:18 | N | 79888] C:\install.res.1042.dll
[07/11/2007 - 07:03:18 | N | 75792] C:\install.res.2052.dll
[07/11/2007 - 07:03:18 | N | 96272] C:\install.res.3082.dll
[17/06/2012 - 20:24:36 | N | 0] C:\IO.SYS
[17/06/2012 - 20:24:36 | N | 0] C:\MSDOS.SYS
[13/04/2008 - 23:13:04 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 01:01:48 | N | 250576] C:\ntldr
[08/11/2012 - 19:35:49 | D ] C:\NVIDIA
[11/11/2012 - 17:40:46 | ASH | 1610612736] C:\pagefile.sys
[08/11/2012 - 18:00:59 | D ] C:\Program Files
[11/11/2012 - 18:12:16 | SHD ] C:\RECYCLER
[30/08/2012 - 20:36:36 | N | 5694] C:\Sdicon32.ico
[11/11/2012 - 17:48:18 | SHD ] C:\System Volume Information
[31/07/2012 - 17:50:55 | N | 2097] C:\tv3d_debug.txt
[11/11/2012 - 18:12:16 | D ] C:\UsbFix
[11/11/2012 - 18:14:56 | A | 5339] C:\UsbFix.txt
[07/11/2007 - 07:00:40 | N | 5686] C:\vcredist.bmp
[07/11/2007 - 07:09:22 | N | 1442522] C:\VC_RED.cab
[07/11/2007 - 07:12:28 | N | 232960] C:\VC_RED.MSI
[05/09/2012 - 12:36:42 | N | 3509] C:\view_log.txt
[11/11/2012 - 17:41:22 | D ] C:\WINDOWS
[22/06/2012 - 20:32:35 | D ] C:\WinRAR
[14/05/2009 - 21:08:48 | R | 51] D:\Autorun.inf
[15/05/2009 - 10:22:18 | RD ] D:\Bonus
[15/05/2009 - 10:22:24 | RD ] D:\DirectX
[14/05/2009 - 15:05:37 | R | 3277744] D:\Manual.pdf
[14/05/2009 - 15:44:37 | R | 7446386] D:\Skullcandy.exe
[14/05/2009 - 15:05:16 | R | 4022625] D:\Theme.mp3
[14/05/2009 - 15:44:42 | R | 7261723] D:\Video.wmv
[14/05/2009 - 21:19:54 | R | 1805166] D:\autorun.exe
[15/05/2009 - 10:20:55 | RD ] D:\background
[14/05/2009 - 15:05:34 | R | 193496] D:\banner.bmp
[12/08/2002 - 21:00:00 | R | 1792] D:\click.wav
[14/05/2009 - 17:14:57 | R | 1071945728] D:\setup-1.bin
[14/05/2009 - 17:28:14 | R | 1073741824] D:\setup-2.bin
[14/05/2009 - 17:36:02 | R | 1073741824] D:\setup-3.bin
[14/05/2009 - 17:36:15 | R | 30610025] D:\setup-4.bin
[14/05/2009 - 17:36:16 | R | 1796003] D:\setup.exe
[11/03/2005 - 20:45:52 | R | 36864] E:\CdAutoRun.exe
[06/10/2008 - 14:37:46 | RD ] E:\Dx9.0c Redist
[12/05/2005 - 14:19:06 | R | 6022] E:\ReadMeTrackManiaSunriseCZ.txt
[09/08/2004 - 14:04:26 | R | 3262] E:\TmSunrise.ico
[06/10/2008 - 14:58:58 | R | 664740123] E:\TmSunriseSetup-1.bin
[06/10/2008 - 14:56:41 | R | 532578] E:\TmSunriseSetup.exe
[11/03/2005 - 21:33:46 | R | 49] E:\autorun.inf
[30/05/2005 - 10:40:00 | R | 7087245] E:\navodTMS.pdf
[11/11/2012 - 17:56:00 | N | 61] F:\recycler.bat
[05/10/2012 - 14:54:22 | D ] F:\EXTREME
[02/10/2012 - 16:25:08 | N | 113032] G:\03_Pikachu.png
[02/10/2012 - 16:23:36 | N | 22385] G:\krtek.jpg
[03/10/2012 - 10:24:34 | N | 597000192] G:\Office-2003 (1).iso
[02/10/2012 - 16:29:32 | N | 31673] G:\obrazek_894.jpg
[16/06/2012 - 11:56:28 | N | 265122] G:\OEM.html
[04/07/2012 - 18:14:10 | N | 1619234934] G:\1svprijimani.wmv
[03/10/2012 - 12:01:22 | N | 123290033] G:\Apache_OpenOffice_incubating_3.4.1_Win_x86_install_cs.exe
[03/10/2012 - 12:48:20 | N | 323792] G:\MS-Office-2003-crack.rar
[03/10/2012 - 11:55:22 | N | 14303520] G:\the-sims-3-crack-patch.rar
[04/10/2012 - 08:06:34 | N | 368075612] G:\Enjoy the Silence Episode 2 - Mixed by Pepi.mp3
[04/10/2012 - 21:02:30 | D ] G:\Prezentace
[08/11/2012 - 18:35:30 | D ] G:\Nová složka
[11/11/2012 - 17:56:00 | N | 61] G:\recycler.bat
[09/09/2012 - 17:29:04 | N | 1861487] G:\need-for-speed-underground-2-2004-crack-only.rar
[02/10/2012 - 15:56:00 | N | 9534] G:\sracky_o_hcl.txt
[02/10/2012 - 16:15:10 | N | 5710] G:\kyselina-chlorovodikova.jpg
[02/10/2012 - 16:15:20 | N | 69367] G:\zaludek.jpg
[02/10/2012 - 16:15:26 | N | 4081] G:\GSH05_korozivni_small.gif
[02/10/2012 - 16:25:48 | N | 33198] G:\Pikachu-want-Soda-pikachu-18237632-320-240.jpg
[02/10/2012 - 16:15:32 | N | 6174] G:\9a0907c3cb_24529873_o2.jpg
[02/10/2012 - 16:20:46 | N | 62038] G:\krtek.gif.jpg
[11/11/2011 - 12:45:32 | N | 2211261] H:\minecraft.jar
[24/06/2011 - 09:02:58 | D ] H:\AJ
[27/12/2010 - 15:04:34 | D ] H:\tanks-0.9.2
[24/06/2011 - 12:41:34 | D ] H:\tata
[25/02/2010 - 03:37:40 | D ] H:\__DT
[27/12/2010 - 15:05:00 | D ] H:\TopWare
[17/06/2012 - 19:12:28 | D ] H:\GCS
[15/09/2010 - 10:13:12 | D ] H:\2010-09-01 go_prima_2010
[13/05/2011 - 19:30:38 | N | 74655] H:\xperia mismas.jpg
[06/09/2011 - 13:28:18 | D ] H:\RENDERS
[20/06/2012 - 14:31:36 | D ] H:\FOUND.000
[27/12/2010 - 15:05:10 | D ] H:\McLaren Racing
[27/12/2010 - 15:05:24 | D ] H:\Space Oddity
[27/12/2010 - 15:06:48 | D ] H:\Kristián
[02/11/2010 - 20:15:08 | N | 611328] H:\Materíál.doc
[07/06/2011 - 12:06:44 | D ] H:\Ninja Fruit
[17/01/2011 - 07:21:20 | D ] H:\VYTISKNOUT
[17/06/2012 - 19:10:34 | D ] H:\WinRAR
[17/06/2012 - 19:12:50 | D ] H:\GCS_TML_info
[20/06/2012 - 14:32:46 | N | 1920] H:\BOOTEX.LOG
[22/11/2009 - 20:26:44 | N | 936] H:\leeme.txt
[09/05/2011 - 08:01:32 | D ] H:\prezentace
[15/09/2010 - 18:43:58 | D ] H:\fotak
[24/07/2011 - 13:58:44 | D ] H:\Deepolis - Vyúčtování
[17/09/2010 - 13:30:16 | D ] H:\2009-02-13-1641-36
[17/06/2012 - 19:12:26 | D ] H:\Custom Production Presets 7.0
[11/09/2011 - 20:59:08 | N | 9028] H:\!!!!!PRO ČÉPU!!!!.txt
[19/06/2012 - 13:27:26 | N | 64999424] H:\Dungeon-Siege-II-Broken-World.iso
[20/06/2012 - 07:57:12 | N | 20552] H:\gdx-e2kg.zip
[22/06/2012 - 21:39:42 | D ] H:\bin
[02/05/2011 - 14:07:22 | D ] H:\TISK
[20/02/2011 - 15:50:56 | D ] H:\adobe
[31/01/2011 - 15:25:38 | D ] H:\minecraft
[17/02/2011 - 16:34:08 | D ] H:\videa
[27/08/2011 - 17:50:14 | N | 135034277] H:\Railroad-Tycoon-3-čestina.rar
[27/08/2011 - 17:34:00 | N | 10801110] H:\Remix ála začátečník000.mp3
[25/12/2011 - 15:04:22 | D ] H:\World of many buildings
[12/11/2011 - 12:24:32 | D ] H:\INVedit
[28/08/2011 - 18:26:56 | N | 63073291] H:\virtual_dj_6_with_skins_samples_and_sound_effects.rar
[12/06/2012 - 22:13:32 | N | 11000] H:\GCS.camproj
[12/06/2012 - 22:12:24 | N | 14115] H:\ju.camproj
[13/06/2011 - 16:21:56 | N | 54272] H:\kupni-smlouva-na-osobni-automobil.doc
[24/10/2011 - 16:08:44 | N | 954821944] H:\Zaříkávač koní.avi
[08/06/2012 - 13:45:38 | D ] H:\.Trash-1001
[14/05/2011 - 17:59:16 | D ] H:\New World of moje
[26/03/2011 - 10:54:14 | N | 118969] H:\mapa_obchody.gif
[13/05/2011 - 19:32:00 | N | 142000] H:\minecraft-hack-invedit (2).rar
[17/06/2012 - 19:16:18 | D ] H:\Bandicam
[11/11/2011 - 08:07:40 | N | 47965882] H:\MINECRAFT-Beta-1.8.1.rar
[12/11/2011 - 12:24:48 | D ] H:\Glacier World by RedStoneCHRIS
[13/11/2011 - 11:28:06 | N | 150594801] H:\Minecraft-1.7.3-too-many-items.rar
[17/06/2012 - 19:16:54 | D ] H:\Camtasia Studio 7
[17/06/2012 - 19:34:06 | D ] H:\Fonty_old
[18/06/2012 - 08:57:22 | N | 9160914] H:\Deamon-tools-4.35.5-Lite-cz.rar
[18/06/2012 - 08:59:14 | N | 3031185] H:\cestiny_2198_TorchlightCZ.rar
[18/06/2012 - 11:54:10 | N | 28841000] H:\KMPlayer_EN_3.2.0.0.exe
[18/06/2012 - 11:54:42 | N | 22255541] H:\K-Lite_Codec_Pack_880_Mega.exe
[20/06/2012 - 07:57:34 | N | 4026] H:\rld-e60k.rar
[20/06/2012 - 08:05:24 | N | 319] H:\UseShaderVersion1.3.zip
[19/06/2012 - 11:47:56 | N | 9763427] H:\Earth2160v1.3NoCDFixedexeRegionFixAll.rar
[19/06/2012 - 11:49:58 | N | 8002167] H:\Earth2160_Update13-137_ENG.exe
[19/06/2012 - 11:51:36 | N | 9782013] H:\Earth2160v1.3.7RegionFixEng.rar
[19/06/2012 - 12:24:32 | N | 1850149] H:\MineColony rc19.zip
[20/06/2012 - 08:58:58 | N | 51131] H:\TooManyItems2012_04_13_1.2.5.zip
[02/06/2012 - 22:35:52 | N | 6967325] H:\morphvox-pro-v4-33-crack.rar
[22/06/2012 - 07:57:52 | N | 21272011] H:\WinCH2_setup.exe
[22/06/2012 - 07:57:54 | N | 5743410] H:\Cheaty.exe
[22/06/2012 - 07:58:04 | N | 13050046] H:\Navody.exe
[22/06/2012 - 08:57:20 | N | 51131] H:\TooManyItems2012_04_13_1.2.5 (1).zip
[11/11/2012 - 17:56:00 | N | 61] H:\recycler.bat
[21/06/2012 - 08:02:20 | N | 13191767] H:\Smokey.libzip
[18/02/2010 - 14:46:22 | D ] H:\Farm Frenzy 2 CZ+crack
[29/06/2012 - 08:02:42 | N | 38959] H:\WinDV-1.2.3.zip
[12/06/2012 - 13:41:46 | N | 169946589] H:\Camtasia-Studio-7.0.0-+-Serials-&-Keygen---DivXNL-team.zip
[27/12/2010 - 14:33:46 | D ] H:\GTA La Heist
[27/12/2010 - 14:34:00 | D ] H:\becherragdoll
[27/12/2010 - 14:34:42 | D ] H:\data
[27/12/2010 - 14:34:44 | D ] H:\FlatOut
[27/12/2010 - 14:34:50 | D ] H:\fotky holky
[27/12/2010 - 14:36:48 | D ] H:\deepolis
[27/12/2010 - 14:36:58 | D ] H:\Rocket in Danger
[21/06/2012 - 07:59:46 | N | 7330321] H:\Screenplay.libzip
[27/12/2010 - 14:43:04 | D ] H:\swf
[21/06/2012 - 08:04:22 | N | 68336662] H:\WidescreenAssets.libzip
[27/12/2010 - 14:58:36 | D ] H:\mapy DP
[27/12/2010 - 14:58:46 | D ] H:\Mann-Filter Rallye
[27/12/2010 - 14:59:00 | D ] H:\Hippo Racer
[27/12/2010 - 14:59:08 | D ] H:\Brad and Roxy's Amazing Downhill
[27/12/2010 - 14:59:38 | D ] H:\Meteor Storm
[27/12/2010 - 15:00:08 | D ] H:\Nová složka (2)
[27/12/2010 - 15:02:36 | D ] H:\qip cz
[21/06/2012 - 08:00:24 | N | 1142393] H:\Dark_Hallway.libzip
[21/06/2012 - 08:04:34 | N | 62465526] H:\Colorscape.libzip
[21/06/2012 - 08:02:24 | N | 15726919] H:\Firefly.libzip
[21/06/2012 - 08:01:52 | N | 8136821] H:\Mystify.libzip
[27/12/2010 - 15:04:44 | D ] H:\AGF
[26/12/2009 - 14:34:22 | N | 765222400] H:\Happy Feet CZ.avi
[26/12/2010 - 13:55:06 | N | 16409960] H:\spybotsd162.exe
[14/11/2011 - 08:57:52 | N | 5536064] I:\MinecraftStructurePlanner.exe
[15/11/2011 - 14:29:12 | N | 20197256] I:\jre-7u1-windows-i586.exe
[29/06/2012 - 14:40:14 | D ] I:\For Elii
[06/11/2012 - 18:21:48 | N | 2056960000] I:\Battlefield 2.iso
[17/11/2011 - 17:33:28 | N | 40417144] I:\D900IXDGE2.exe
[29/03/2012 - 16:08:24 | N | 694784] I:\MinecraftSP.exe
[25/05/2012 - 13:16:14 | D ] I:\server
[18/11/2011 - 14:08:58 | D ] I:\Charred Dirt
[17/11/2011 - 18:07:06 | N | 6000103] I:\OneNAND Downloader v1.6 For PNX5230(tfs4 v1.6).rar
[21/11/2011 - 11:09:48 | N | 11405371] I:\Chemie.jpg
[13/12/2011 - 08:00:32 | N | 21981] I:\Grass.jpg
[02/01/2012 - 10:48:52 | N | 733913088] I:\Vall-i-CZ-dab.avi
[06/01/2012 - 13:40:18 | N | 3152159] I:\Transformice-parody-song-~-I-could-get-used-to-this.mp3
[04/04/2012 - 09:56:40 | N | 8005848] I:\[HD]-LMFAO---One-Day.mp3
[10/04/2012 - 11:55:30 | N | 11101992] I:\craftbukkit.jar
[08/12/2011 - 10:03:14 | N | 531292] I:\I_Miss_You.sis
[08/12/2011 - 10:04:56 | N | 216000] I:\Ice_Age_3.sis
[08/12/2011 - 10:05:48 | N | 423548] I:\I_Miss_You (1).sis
[10/12/2011 - 12:08:16 | D ] I:\atanua
[21/04/2012 - 10:17:40 | D ] I:\Nová složka
[11/11/2012 - 17:56:00 | N | 61] I:\recycler.bat
[03/03/2012 - 10:22:20 | N | 23040] I:\MC.doc
[12/12/2011 - 07:12:56 | N | 221] I:\darky.txt
[13/12/2011 - 09:53:34 | N | 23892191] I:\terraria.rar
[04/04/2012 - 09:55:54 | N | 10184275] I:\12-jason_derulo_-_breathing.mp3
[16/01/2012 - 18:08:44 | N | 215354] I:\[1.1]ReiMinimap_v3.0_01.zip
[16/01/2012 - 17:00:18 | N | 47993] I:\TooManyItems2012_01_12.zip
[16/01/2012 - 15:37:36 | N | 89249] I:\ModLoader.zip
[07/03/2012 - 11:52:20 | N | 379906] I:\CS_1.6_CZ.exe
[15/12/2011 - 20:33:00 | D ] I:\UB's
[20/03/2012 - 13:33:36 | N | 5818934] I:\JCreator-Pro-4.50.010.rar
[16/01/2009 - 11:03:36 | D ] I:\JCreator Pro 4.50.010
[16/12/2011 - 08:03:54 | N | 119167] I:\Horovice,,Cintlovka-Horovice,,nam.B.Nemcove.pdf
[10/05/2012 - 06:38:12 | N | 4224049] I:\minecraft.jar
[29/06/2012 - 15:50:12 | N | 4245596] I:\For Elii.rar
[07/06/2012 - 09:00:22 | D ] I:\Sony Vegas 11 PRO
[07/06/2012 - 13:09:04 | D ] I:\Minecraft Tekkit Pack
[11/06/2012 - 12:50:12 | N | 881] I:\how to change xp sp.txt
[11/06/2012 - 22:28:54 | D ] I:\TheMagicLight
[16/06/2012 - 10:06:30 | D ] I:\skin3
[16/06/2012 - 10:07:00 | D ] I:\MCSkin3D
[16/06/2012 - 10:07:56 | D ] I:\Games
[16/06/2012 - 10:43:56 | D ] I:\!!!TISK!!!
[16/06/2012 - 15:14:30 | N | 523778] I:\6590v14.exe
[03/10/2010 - 13:50:20 | N | 10088256] I:\DAEMONToolsPro4360309-0160.exe
[20/06/2012 - 14:30:22 | N | 1390] I:\BOOTEX.LOG
[27/06/2012 - 08:05:28 | N | 5616256] I:\Aura-Dione---friends-ft.-Rock-Mafia.mp3
[27/06/2012 - 10:16:24 | N | 306447626] I:\Nero-10.rar
[27/06/2012 - 12:01:16 | N | 6905480] I:\Sonic Ethers Unbelievable Shaders v08 1.2.4 and 1.2.5 (Windows).zip
[18/11/2011 - 17:59:34 | N | 7405] J:\default-capability.xml
[18/11/2011 - 17:59:34 | N | 141] J:\customized-capability.xml
[11/11/2012 - 16:50:48 | D ] J:\Private
[11/11/2012 - 16:50:54 | D ] J:\Games
[18/10/2011 - 18:04:32 | N | 1306887] J:\New Archive.zip.85a6160c.menc
[27/09/2006 - 12:01:34 | D ] J:\voices
[27/09/2006 - 12:01:36 | N | 301] J:\ttnavigator.bif
[11/11/2012 - 16:50:54 | D ] J:\Installs
[11/11/2012 - 16:50:54 | D ] J:\Others
[18/11/2009 - 16:52:00 | N | 4096] J:\tfs4_160.ess
[02/11/2011 - 16:27:24 | D ] J:\ActiveSync
[02/11/2011 - 16:27:26 | D ] J:\Images
[02/11/2011 - 16:27:26 | D ] J:\Videos
[02/11/2011 - 16:27:26 | D ] J:\Sounds
[02/11/2011 - 16:27:26 | D ] J:\Other files
[10/11/2011 - 16:14:38 | N | 135168] J:\Store(8fc91f86227a042f91187b4ae85273be4a45cb31).hds
[14/11/2011 - 06:18:04 | N | 16] J:\SThumbDB.tdb
[08/01/2007 - 02:41:16 | D ] J:\Music
[11/08/2009 - 19:51:50 | N | 12664] J:\ChangeLog
[11/08/2009 - 19:51:50 | N | 3374] J:\INSTALL
[11/08/2009 - 19:51:50 | N | 17992] J:\LICENSE
[11/08/2009 - 19:51:50 | N | 549] J:\UPGRADE
[11/08/2009 - 19:51:50 | N | 1581] J:\wing-linux-0.4pre3-gene.cab
[11/08/2009 - 19:51:50 | N | 1596] J:\wing-linux-0.4pre3-herald.cab
[11/08/2009 - 19:51:50 | N | 1581] J:\wing-linux-0.4pre3-prophet.cab
[11/08/2009 - 19:51:50 | N | 38559455] J:\wing-linux-0.4pre3-rootfs.cab
[11/08/2009 - 19:51:50 | N | 1596] J:\wing-linux-0.4pre3-wizard.cab
[16/05/2012 - 21:46:36 | N | 9476212] J:\Jennifer-Lopez-ft.-Pitbull---Dance-Again.mp3
[25/06/2012 - 20:03:38 | N | 5634545] J:\03-Deti-Stratenej-Generacie-(feat.-Ego).aac
[16/12/2011 - 18:28:46 | | 4310989] J:\Depeche-Mode---A-question-of-last~1.mp3
[29/12/2011 - 13:06:16 | | 1764446] J:\JENNIFER LOPEZ papi.mp3

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
J:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_GAMEPC.zip
http://sosvirus.org/viewtopic.php?f=208&t=250
Thank you for your contribution.

################## | E.O.F |

Re: RECYCLER/e621ca05.exe

Napsal: 11 lis 2012 20:21
od TheMagicLight
Anti-Malware
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.65.1.1000
www.malwarebytes.org

Verze databáze: v2012.09.29.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Gamer :: GAMEPC [administrátor]

Ochrana: Zakázána

11.11.2012 18:39:15
mbam-log-2012-11-11 (19-24-12).txt

Typ: Úplná kontrola (C:\|F:\|G:\|H:\|I:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 267007
Uplynulý čas: 29 minut, 57 sekund

Nalezené procesy v paměti: 1
C:\Documents and Settings\Gamer\Data aplikací\15.exe (Trojan.Agent) -> 2180 -> Žádná instrukce nebyla provedena.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 4
C:\Documents and Settings\Gamer\Plocha\My Files\mini hry\potrestanie.exe (Joke.Stressreducer) -> Žádná instrukce nebyla provedena.
C:\WINDOWS\Installer\{ADE7FEA4-151F-55B5-2562-1195054EDB75}\syshost.exe (Trojan.Ransom) -> Žádná instrukce nebyla provedena.
I:\Sony Vegas 11 PRO\Sony-Vegas-Pro-11-key.exe (RiskWare.Tool.HCK) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\Gamer\Data aplikací\15.exe (Trojan.Agent) -> Žádná instrukce nebyla provedena.

(konec)

Re: RECYCLER/e621ca05.exe

Napsal: 11 lis 2012 20:22
od TheMagicLight
RSIT
Logfile of random's system information tool 1.09 (written by random/random)
Run by Gamer at 2012-11-11 20:05:45
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 37 GB (33%) free of 114 GB
Total RAM: 1279 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:05:56, on 11.11.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Promise Technology, Inc\Promise Array Management\MsgAgt.exe
C:\Program Files\Promise Technology, Inc\Promise Array Management\MsgSvr.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\wudfhost.exe
C:\Program Files\vodafone\via the phone\PhoneConnectorVTP.exe
C:\Program Files\vodafone\via the phone\VtP.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Gamer\Plocha\RSIT.exe
C:\Program Files\trend micro\Gamer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{70F45271-45DA-4A3F-9CE7-6CD569F43499}: NameServer = 217.77.165.81 217.77.161.131
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Promise Array Message Agent (RAIDmAgt) - Unknown owner - C:\Program Files\Promise Technology, Inc.\Promise Array Management\MsgAgt.exe
O23 - Service: Promise Array Message Server (RAIDmSvr) - Unknown owner - C:\Program Files\Promise Technology, Inc.\Promise Array Management\MsgSvr.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Vodafone Connector Service (VodafoneConnectorService) - Vodafone Group - C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe

--
End of file - 5541 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Gamer\Data aplikací\Mozilla\Firefox\Profiles\tg1u0wz9.default

prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}"=C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-01-03 1514152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-06-18 57224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2012-01-03 1514152]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-10-30 1019336]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
C:\Program Files\Ask.com\Updater\Updater.exe [2012-01-03 1391272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
RunDll32 cmicnfg.cpl,CMICtrlWnd []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBM 5]
C:\Program Files\Motherboard Monitor 5\MBM5.EXE [2004-06-12 594944]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2010-02-05 385856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-05-04 252136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\syshost32]
C:\WINDOWS\Installer\{ADE7FEA4-151F-55B5-2562-1195054EDB75}\syshost.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-08-08 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Reality Pump\Earth 2160\Earth2160_NO_SSE.exe"="C:\Program Files\Reality Pump\Earth 2160\Earth2160_NO_SSE.exe:*:Enabled:Earth 2160"
"C:\Program Files\Reality Pump\Earth 2160\Earth2160_SSE.exe"="C:\Program Files\Reality Pump\Earth 2160\Earth2160_SSE.exe:*:Enabled:Earth 2160"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Java\jre7\bin\java.exe"="C:\Program Files\Java\jre7\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\FlightGear\bin\win32\fgfs.exe"="C:\Program Files\FlightGear\bin\win32\fgfs.exe:*:Enabled:fgfs"
"C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe"="C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe:*:Enabled:Opera Internet Browser - Plugin wrapper"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\FlatOut2\FlatOut2.exe"="C:\Program Files\FlatOut2\FlatOut2.exe:*:Enabled:FlatOut2"
"C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe"="C:\Program Files\EA GAMES\Need for Speed Underground 2\speed2.exe:*:Enabled:speed2"
"C:\WINDOWS\system32\javaw.exe"="C:\WINDOWS\system32\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\TopCD\Zachranari\Emergency 4\Em4.exe"="C:\Program Files\TopCD\Zachranari\Emergency 4\Em4.exe:*:Enabled:Em4"
"C:\Program Files\PANDORA.TV\PanService\PandoraService.exe"="C:\Program Files\PANDORA.TV\PanService\PandoraService.exe:*:Enabled:PandoraService"
"C:\Program Files\TrackMania Sunrise\TmSunrise.exe"="C:\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Enabled:TmSunrise"
"C:\Documents and Settings\Gamer\Plocha\My Files\SkypePortable\App\Skype\Phone\Skype.exe"="C:\Documents and Settings\Gamer\Plocha\My Files\SkypePortable\App\Skype\Phone\Skype.exe:*:Enabled:Skype "
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codecp.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"vidc.tscc"=tsccvid.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"MSVideo8"=VfWWDM32.dll

======List of files/folders created in the last 1 month======

2012-11-11 20:05:45 ----D---- C:\rsit
2012-11-11 20:05:45 ----D---- C:\Program Files\trend micro
2012-11-11 19:38:23 ----HD---- C:\WINDOWS\PIF
2012-11-11 19:28:01 ----D---- C:\Program Files\CCleaner
2012-11-11 18:27:59 ----D---- C:\Program Files\Vodafone
2012-11-11 18:24:06 ----D---- C:\Documents and Settings\Gamer\Data aplikací\Malwarebytes
2012-11-11 18:17:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-11-11 18:17:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-11-11 18:17:34 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-11-11 18:14:58 ----RASHD---- C:\Autorun.inf
2012-11-11 18:01:01 ----A---- C:\UsbFix.txt
2012-11-11 18:01:00 ----D---- C:\UsbFix
2012-11-08 21:00:56 ----D---- C:\WINDOWS\pss
2012-11-08 19:43:32 ----D---- C:\Program Files\Common Files\EasyInfo
2012-11-08 17:43:26 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2012-11-08 17:43:07 ----D---- C:\Program Files\DAEMON Tools Lite
2012-11-08 17:09:08 ----A---- C:\WINDOWS\system32\drivers\1884921e72e565c8.sys
2012-11-07 16:27:51 ----D---- C:\Documents and Settings\Gamer\Data aplikací\Skype
2012-11-07 16:27:49 ----D---- C:\Documents and Settings\Gamer\Data aplikací\SkypePM
2012-11-03 19:19:53 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2012-11-03 19:19:49 ----A---- C:\WINDOWS\system32\drivers\avc.sys
2012-11-03 19:19:44 ----A---- C:\WINDOWS\system32\drivers\61883.sys
2012-11-03 11:20:03 ----D---- C:\Documents and Settings\Gamer\Data aplikací\BANDISOFT
2012-11-03 11:14:54 ----D---- C:\Program Files\TrackMania Sunrise
2012-11-03 10:34:04 ----D---- C:\D900IXDGE2
2012-11-01 19:19:04 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2012-10-30 19:56:58 ----D---- C:\Program Files\TopCD
2012-10-30 19:56:17 ----D---- C:\Program Files\Mirage Interactive
2012-10-21 18:00:55 ----D---- C:\Program Files\Cenega Czech
2012-10-21 11:23:13 ----D---- C:\Documents and Settings\Gamer\Data aplikací\gtk-2.0
2012-10-21 10:43:19 ----D---- C:\Documents and Settings\Gamer\Data aplikací\.purple
2012-10-21 10:42:51 ----D---- C:\Program Files\Pidgin

======List of files/folders modified in the last 1 month======

2012-11-11 20:05:45 ----D---- C:\Program Files
2012-11-11 20:05:29 ----A---- C:\WINDOWS\ModemLog_SAMSUNG USB Mobile Modem #3.txt
2012-11-11 20:03:49 ----D---- C:\WINDOWS\system32\drivers
2012-11-11 20:01:55 ----D---- C:\WINDOWS
2012-11-11 20:00:20 ----D---- C:\Documents and Settings\Gamer\Data aplikací\Media Player Classic
2012-11-11 20:00:20 ----D---- C:\Documents and Settings\Gamer\Data aplikací\DAEMON Tools Lite
2012-11-11 20:00:19 ----D---- C:\WINDOWS\SoftwareDistribution
2012-11-11 20:00:19 ----D---- C:\WINDOWS\Minidump
2012-11-11 20:00:19 ----D---- C:\WINDOWS\Logs
2012-11-11 20:00:19 ----D---- C:\WINDOWS\Debug
2012-11-11 19:59:30 ----D---- C:\WINDOWS\Temp
2012-11-11 19:59:20 ----A---- C:\WINDOWS\MsgAgt.INI
2012-11-11 19:58:16 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-11-11 19:57:58 ----D---- C:\WINDOWS\system32
2012-11-11 19:26:47 ----SHD---- C:\System Volume Information
2012-11-11 19:26:47 ----D---- C:\WINDOWS\system32\Restore
2012-11-11 19:25:44 ----RSD---- C:\WINDOWS\Fonts
2012-11-11 19:24:26 ----D---- C:\WINDOWS\Prefetch
2012-11-11 18:28:01 ----SHD---- C:\WINDOWS\Installer
2012-11-11 18:12:16 ----SHD---- C:\RECYCLER
2012-11-11 17:39:39 ----A---- C:\WINDOWS\win.ini
2012-11-11 17:39:39 ----A---- C:\WINDOWS\system.ini
2012-11-11 17:36:11 ----HD---- C:\WINDOWS\inf
2012-11-11 17:36:11 ----D---- C:\WINDOWS\system32\CatRoot2
2012-11-08 19:44:19 ----D---- C:\WINDOWS\system32\DirectX
2012-11-08 19:38:30 ----HD---- C:\Program Files\InstallShield Installation Information
2012-11-08 19:38:30 ----D---- C:\Program Files\EA GAMES
2012-11-08 19:35:49 ----D---- C:\NVIDIA
2012-11-08 18:39:38 ----D---- C:\Program Files\The KMPlayer
2012-11-06 22:49:22 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-11-06 22:48:59 ----D---- C:\WINDOWS\Driver Cache
2012-11-05 16:17:20 ----D---- C:\Documents and Settings\Gamer\Data aplikací\.minecraft
2012-11-01 19:20:44 ----D---- C:\WINDOWS\system32\CatRoot
2012-11-01 19:19:07 ----D---- C:\WINDOWS\system32\Logfiles
2012-10-31 20:54:51 ----D---- C:\WINDOWS\system32\drivers\UMDF
2012-10-31 20:54:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-10-21 13:21:58 ----D---- C:\Program Files\PogoSticker

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\WINDOWS\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2011-03-18 25240]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 mbmiodrvr;mbmiodrvr; \??\C:\WINDOWS\system32\mbmiodrvr.sys []
R2 cpuz135;cpuz135; \??\C:\WINDOWS\system32\drivers\cpuz135_x32.sys []
R3 bcm4sbxp;MSI/Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2004-10-11 45056]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2005-12-15 1368000]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
R3 RT61;Hawking HWPG1 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2005-10-27 356096]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648]
R3 ss_bserd;SAMSUNG USB Mobile Logging Driver; C:\WINDOWS\system32\DRIVERS\ss_bserd.sys [2009-09-19 100224]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-08-08 38528]
R3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S3 61883;61883 Unit Device; C:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-14 48128]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 Avc;AVC Device; C:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-14 38912]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2012-11-11 242240]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2004-07-09 52096]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-11 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-01-21 18048]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-12-30 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-12-30 7936]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-12-30 7936]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-06-18 477240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-06-18 161664]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
R2 RAIDmAgt;Promise Array Message Agent; C:\Program Files\Promise Technology, Inc.\Promise Array Management\MsgAgt.exe [2003-06-20 679936]
R2 RAIDmSvr;Promise Array Message Server; C:\Program Files\Promise Technology, Inc.\Promise Array Management\MsgSvr.exe [2003-06-03 323584]
R2 SNMP;SNMP; C:\WINDOWS\System32\snmp.exe [2008-04-14 32768]
R2 VodafoneConnectorService;Vodafone Connector Service; C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe [2010-01-12 233472]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936]
S2 SMTPSVC;Simple Mail Transport Protocol (SMTP); C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LPDSVC;Tiskový server TCP/IP; C:\WINDOWS\system32\tcpsvcs.exe [2001-10-25 19456]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-06 114144]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-01-26 652800]
S3 SNMPTRAP;Zachytávání pro službu SNMP; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
PC se už nekouše, data nestahují, ale stále se na USB jednotkách složky mění v zastupce :(

Re: RECYCLER/e621ca05.exe

Napsal: 11 lis 2012 21:57
od TheMagicLight
Prosím pomozte, mam to na 4 fleškách, složka je jako zástupce s cestou %windir%\system32\cmd.exe /c "start %cd%RECYCLER\e621ca05.exe &&%windir%\explorer.exe %cd%FlatOut , udělal sem všechny postupy, vše OK jen ty flešky jsou pořád stejný! :(

Re: RECYCLER/e621ca05.exe

Napsal: 12 lis 2012 07:59
od stell
C:\Documents and Settings\Gamer\Plocha\My Files\mini hry\potrestanie.exe (Joke.Stressreducer) -> Žádná instrukce nebyla provedena.
C:\WINDOWS\Installer\{ADE7FEA4-151F-55B5-2562-1195054EDB75}\syshost.exe (Trojan.Ransom) -> Žádná instrukce nebyla provedena.
I:\Sony Vegas 11 PRO\Sony-Vegas-Pro-11-key.exe (RiskWare.Tool.HCK) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\Gamer\Data aplikací\15.exe (Trojan.Agent) -> Žádná instrukce nebyla provedena.
Vsetko?/ toto preco si nezmazal??
este daj log z combofix
http://www.bleepingcomputer.com/combofi ... t-combofix

Re: RECYCLER/e621ca05.exe

Napsal: 12 lis 2012 08:58
od TheMagicLight
Aha, špatný log, tj výpis před mazáním, CF udělám hned jak přijdu ze školy domu.

Re: RECYCLER/e621ca05.exe

Napsal: 12 lis 2012 09:13
od stell
ok,

Re: RECYCLER/e621ca05.exe

Napsal: 12 lis 2012 15:13
od TheMagicLight
Zde správný výpis z MBAM
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.65.1.1000
www.malwarebytes.org

Verze databáze: v2012.09.29.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Gamer :: GAMEPC [administrátor]

Ochrana: Zakázána

11.11.2012 18:39:15
mbam-log-2012-11-11 (18-39-15).txt

Typ: Úplná kontrola (C:\|F:\|G:\|H:\|I:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 267007
Uplynulý čas: 29 minut, 57 sekund

Nalezené procesy v paměti: 1
C:\Documents and Settings\Gamer\Data aplikací\15.exe (Trojan.Agent) -> 2180 -> Bude smazán při restartu.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 4
C:\Documents and Settings\Gamer\Plocha\My Files\mini hry\potrestanie.exe (Joke.Stressreducer) -> Umístnění do karantény a smazání se zdařilo.
C:\WINDOWS\Installer\{ADE7FEA4-151F-55B5-2562-1195054EDB75}\syshost.exe (Trojan.Ransom) -> Umístnění do karantény a smazání se zdařilo.
I:\Sony Vegas 11 PRO\Sony-Vegas-Pro-11-key.exe (RiskWare.Tool.HCK) -> Umístnění do karantény a smazání se zdařilo.
C:\Documents and Settings\Gamer\Data aplikací\15.exe (Trojan.Agent) -> Umístnění do karantény a smazání se zdařilo.

(konec)

Re: RECYCLER/e621ca05.exe

Napsal: 12 lis 2012 15:14
od TheMagicLight
ComboFix Log
ComboFix 12-11-12.02 - Gamer 12.11.2012 14:53:53.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.915 [GMT 1:00]
Spuštěný z: c:\documents and settings\Gamer\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\windows\system32\Cache
c:\windows\system32\drivers\1884921e72e565c8.sys
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_1884921e72e565c8
-------\Service_1884921e72e565c8
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-12 do 2012-11-12 )))))))))))))))))))))))))))))))
.
.
2012-11-12 13:32 . 2012-11-12 13:32 147968 ----a-w- c:\documents and settings\Gamer\Data aplikací\Fngwgb.exe
2012-11-11 20:59 . 2012-11-11 20:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Nero
2012-11-11 20:58 . 2012-11-11 20:58 -------- d-----w- c:\program files\Common Files\Nero
2012-11-11 20:58 . 2012-11-11 20:58 -------- d-----w- c:\program files\Nero
2012-11-11 20:39 . 2012-11-11 20:39 -------- d-----w- c:\program files\Microsoft.NET
2012-11-11 19:46 . 2012-11-11 19:46 -------- d-----w- c:\program files\DAEMON Tools Lite
2012-11-11 19:05 . 2012-11-11 19:05 -------- d-----w- C:\rsit
2012-11-11 19:05 . 2012-11-11 19:05 -------- d-----w- c:\program files\trend micro
2012-11-11 18:38 . 2012-11-11 18:38 -------- d--h--w- c:\windows\PIF
2012-11-11 18:28 . 2012-11-11 18:28 -------- d-----w- c:\program files\CCleaner
2012-11-11 17:27 . 2012-11-11 17:27 -------- d-----w- c:\program files\Vodafone
2012-11-11 17:24 . 2012-11-11 17:24 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\Malwarebytes
2012-11-11 17:17 . 2012-11-11 17:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-11-11 17:17 . 2012-11-11 17:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-11 17:17 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-11 17:01 . 2012-11-11 17:15 -------- d-----w- C:\UsbFix
2012-11-08 18:43 . 2012-11-08 18:43 -------- d-----w- c:\program files\Common Files\EasyInfo
2012-11-07 15:27 . 2012-11-07 15:27 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\Skype
2012-11-03 18:33 . 2012-11-03 18:33 -------- d-----w- c:\documents and settings\Gamer\Local Settings\Data aplikací\WMTools Downloaded Files
2012-11-03 18:19 . 2008-04-14 07:52 54272 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2012-11-03 18:19 . 2008-04-14 07:52 54272 ----a-w- c:\windows\system32\vfwwdm32.dll
2012-11-03 18:19 . 2008-04-13 23:16 38912 -c--a-w- c:\windows\system32\dllcache\avc.sys
2012-11-03 18:19 . 2008-04-13 23:16 38912 ----a-w- c:\windows\system32\drivers\avc.sys
2012-11-03 18:19 . 2008-04-13 23:16 48128 -c--a-w- c:\windows\system32\dllcache\61883.sys
2012-11-03 18:19 . 2008-04-13 23:16 48128 ----a-w- c:\windows\system32\drivers\61883.sys
2012-11-03 10:20 . 2012-11-03 10:20 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\BANDISOFT
2012-11-03 10:14 . 2012-11-04 12:15 -------- d-----w- c:\program files\TrackMania Sunrise
2012-11-03 09:34 . 2012-11-03 09:34 -------- d-----w- C:\D900IXDGE2
2012-10-30 18:56 . 2012-10-30 18:56 -------- d-----w- c:\program files\TopCD
2012-10-30 18:56 . 2012-10-30 18:56 -------- d-----w- c:\program files\Mirage Interactive
2012-10-21 17:00 . 2012-10-21 17:00 -------- d-----w- c:\program files\Cenega Czech
2012-10-21 10:23 . 2012-11-04 15:43 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\gtk-2.0
2012-10-21 09:43 . 2012-11-12 13:47 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\.purple
2012-10-21 09:42 . 2012-11-03 12:02 -------- d-----w- c:\program files\Pidgin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-11 17:15 . 2012-11-11 17:15 1714698 ----a-w- C:\UsbFix_Upload_Me_GAMEPC.zip
2012-10-09 13:43 . 2012-10-09 13:43 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 13:43 . 2012-10-09 13:43 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-06 01:26 . 2012-10-09 13:38 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-08-08 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 14:31 1514152 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fngwgb"="c:\documents and settings\Gamer\Data aplikací\Fngwgb.exe" [2012-11-12 147968]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 00:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
2012-01-03 14:31 1391272 ----a-w- c:\program files\Ask.com\Updater\Updater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 08:52 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBM 5]
2004-06-12 07:40 594944 ----a-w- c:\program files\Motherboard Monitor 5\MBM5.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-02-05 11:45 385856 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-02 20:46 13529088 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-05-02 20:46 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-05-02 20:46 1630208 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-05-04 11:59 252136 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_NO_SSE.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_SSE.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\java.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\FlatOut2\\FlatOut2.exe"=
"c:\\Program Files\\EA GAMES\\Need for Speed Underground 2\\speed2.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\TopCD\\Zachranari\\Emergency 4\\Em4.exe"=
"c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"c:\\Documents and Settings\\Gamer\\Plocha\\My Files\\SkypePortable\\App\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [18.6.2012 5:57 21992]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11.11.2012 18:17 676936]
R2 VodafoneConnectorService;Vodafone Connector Service;c:\program files\Vodafone\Via The Phone\VodafoneConnectorService.exe [12.1.2010 17:53 233472]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11.11.2012 18:17 22856]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\Gamer\LOCALS~1\Temp\CFcatchme.sys --> c:\docume~1\Gamer\LOCALS~1\Temp\CFcatchme.sys [?]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [13.8.2012 9:43 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [13.8.2012 9:43 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [13.8.2012 9:43 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [13.8.2012 9:43 100224]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.6.2012 6:34 477240]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - IPFILTERDRIVER
*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-12 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 14:31]
.
.
------- Doplňkový sken -------
.
FF - ProfilePath - c:\documents and settings\Gamer\Data aplikací\Mozilla\Firefox\Profiles\tg1u0wz9.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
MSConfigStartUp-Cmaudio - cmicnfg.cpl
MSConfigStartUp-syshost32 - c:\windows\Installer\{ADE7FEA4-151F-55B5-2562-1195054EDB75}\syshost.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-12 15:05
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Fngwgb = c:\documents and settings\Gamer\Data aplikac?\Fngwgb.exe
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fngwgb"="c:\\Documents and Settings\\Gamer\\Data aplikací\\Fngwgb.exe"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-57989841-2111687655-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-57989841-2111687655-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:da,2f,18,95,86,74,00,7a,df,ea,11,35,72,a0,de,f8,06,be,89,a8,0e,
4f,de,ca,28,e4,cd,1d,df,48,a6,7d,0f,31,69,b1,11,ec,5d,41,41,88,dc,67,ae,5f,\
"rkeysecu"=hex:b1,f1,05,fc,74,26,2e,6c,a5,4f,c5,b4,e1,a1,f6,e5
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{34A0FF07-F11A-4157-84A3-92F8AD688CBF}]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3000)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Promise Technology, Inc\Promise Array Management\MsgAgt.exe
c:\program files\Promise Technology, Inc\Promise Array Management\MsgSvr.exe
c:\windows\System32\snmp.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2012-11-12 15:07:59 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-12 14:07
.
Před spuštěním: Volných bajtů: 32 180 695 040
Po spuštění: Volných bajtů: 36 320 612 352
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - D51D3BC24BB12338C24B8D9DFE63CFAC

Re: RECYCLER/e621ca05.exe

Napsal: 12 lis 2012 18:36
od stell
Usbkluce treba mat stale pripojene.
Pri tejto akcii je nutné mať ComboFix na ploche.

Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.

Otvor Notepad (Poznámkový blok) a zkopíruj do neho celý tex:

Kód: Vybrat vše

KILLALL::
File::
c:\documents and settings\Gamer\Data aplikací\Fngwgb.exe
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fngwgb"=-
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Fngwgb" =-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fngwgb"=-
Folder::
c:\program files\Ask.com
RegLock:: 
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{34A0FF07-F11A-4157-84A3-92F8AD688CBF}]
ClearJavaCache::

Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :
Obrázek

Po skonceni skenu vlož log .

Zopakuj ,spust znovu vsade ten batak, recycler.bat, a potom ihned spust aj program USBFIX, logy vloz sem, zajtra sa na logy pozriem, dnes uz nemam cas,

Re: RECYCLER/e621ca05.exe

Napsal: 12 lis 2012 21:22
od TheMagicLight
Log ComboFix
ComboFix 12-11-12.02 - Gamer 12.11.2012 19:59:34.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.924 [GMT 1:00]
Spuštěný z: c:\documents and settings\Gamer\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Gamer\Plocha\CFScript.txt
.
FILE ::
"c:\documents and settings\Gamer\Data aplikací\Fngwgb.exe"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\assets\oobe\b.png
c:\program files\Ask.com\assets\oobe\bl.png
c:\program files\Ask.com\assets\oobe\br.png
c:\program files\Ask.com\assets\oobe\l.png
c:\program files\Ask.com\assets\oobe\pointer.png
c:\program files\Ask.com\assets\oobe\r.png
c:\program files\Ask.com\assets\oobe\t.png
c:\program files\Ask.com\assets\oobe\tl.png
c:\program files\Ask.com\assets\oobe\tr.png
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_26.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\precache.exe
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\Updater\config.xml
c:\program files\Ask.com\Updater\Updater.exe
c:\program files\Ask.com\UpdateTask.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-12 do 2012-11-12 )))))))))))))))))))))))))))))))
.
.
2012-11-12 18:56 . 2012-11-12 18:56 147968 ----a-w- c:\documents and settings\Gamer\Data aplikací\Fngwgb.exe
2012-11-11 20:39 . 2012-11-11 20:39 -------- d-----w- c:\program files\Microsoft.NET
2012-11-11 19:46 . 2012-11-11 19:46 -------- d-----w- c:\program files\DAEMON Tools Lite
2012-11-11 19:05 . 2012-11-11 19:05 -------- d-----w- C:\rsit
2012-11-11 19:05 . 2012-11-11 19:05 -------- d-----w- c:\program files\trend micro
2012-11-11 18:38 . 2012-11-11 18:38 -------- d--h--w- c:\windows\PIF
2012-11-11 18:28 . 2012-11-11 18:28 -------- d-----w- c:\program files\CCleaner
2012-11-11 17:27 . 2012-11-11 17:27 -------- d-----w- c:\program files\Vodafone
2012-11-11 17:24 . 2012-11-11 17:24 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\Malwarebytes
2012-11-11 17:17 . 2012-11-11 17:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-11-11 17:17 . 2012-11-11 17:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-11-11 17:17 . 2012-09-29 18:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-11 17:01 . 2012-11-11 17:15 -------- d-----w- C:\UsbFix
2012-11-08 18:43 . 2012-11-08 18:43 -------- d-----w- c:\program files\Common Files\EasyInfo
2012-11-07 15:27 . 2012-11-07 15:27 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\Skype
2012-11-03 18:33 . 2012-11-03 18:33 -------- d-----w- c:\documents and settings\Gamer\Local Settings\Data aplikací\WMTools Downloaded Files
2012-11-03 18:19 . 2008-04-14 07:52 54272 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2012-11-03 18:19 . 2008-04-14 07:52 54272 ----a-w- c:\windows\system32\vfwwdm32.dll
2012-11-03 18:19 . 2008-04-13 23:16 38912 -c--a-w- c:\windows\system32\dllcache\avc.sys
2012-11-03 18:19 . 2008-04-13 23:16 38912 ----a-w- c:\windows\system32\drivers\avc.sys
2012-11-03 18:19 . 2008-04-13 23:16 48128 -c--a-w- c:\windows\system32\dllcache\61883.sys
2012-11-03 18:19 . 2008-04-13 23:16 48128 ----a-w- c:\windows\system32\drivers\61883.sys
2012-11-03 10:20 . 2012-11-03 10:20 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\BANDISOFT
2012-11-03 10:14 . 2012-11-04 12:15 -------- d-----w- c:\program files\TrackMania Sunrise
2012-11-03 09:34 . 2012-11-03 09:34 -------- d-----w- C:\D900IXDGE2
2012-10-30 18:56 . 2012-10-30 18:56 -------- d-----w- c:\program files\TopCD
2012-10-30 18:56 . 2012-10-30 18:56 -------- d-----w- c:\program files\Mirage Interactive
2012-10-21 17:00 . 2012-10-21 17:00 -------- d-----w- c:\program files\Cenega Czech
2012-10-21 10:23 . 2012-11-04 15:43 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\gtk-2.0
2012-10-21 09:43 . 2012-11-12 15:17 -------- d-----w- c:\documents and settings\Gamer\Data aplikací\.purple
2012-10-21 09:42 . 2012-11-03 12:02 -------- d-----w- c:\program files\Pidgin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-11 17:15 . 2012-11-11 17:15 1714698 ----a-w- C:\UsbFix_Upload_Me_GAMEPC.zip
2012-10-09 13:43 . 2012-10-09 13:43 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 13:43 . 2012-10-09 13:43 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-06 01:26 . 2012-10-09 13:38 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-08-08 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 00:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 08:52 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBM 5]
2004-06-12 07:40 594944 ----a-w- c:\program files\Motherboard Monitor 5\MBM5.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-02-05 11:45 385856 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-02 20:46 13529088 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-05-02 20:46 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-05-02 20:46 1630208 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-05-04 11:59 252136 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_NO_SSE.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_SSE.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\java.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\FlatOut2\\FlatOut2.exe"=
"c:\\Program Files\\EA GAMES\\Need for Speed Underground 2\\speed2.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\TopCD\\Zachranari\\Emergency 4\\Em4.exe"=
"c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"c:\\Documents and Settings\\Gamer\\Plocha\\My Files\\SkypePortable\\App\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [18.6.2012 5:57 21992]
R2 VodafoneConnectorService;Vodafone Connector Service;c:\program files\Vodafone\Via The Phone\VodafoneConnectorService.exe [12.1.2010 17:53 233472]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11.11.2012 18:17 22856]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11.11.2012 18:17 676936]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\Gamer\LOCALS~1\Temp\CFcatchme.sys --> c:\docume~1\Gamer\LOCALS~1\Temp\CFcatchme.sys [?]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [13.8.2012 9:43 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [13.8.2012 9:43 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [13.8.2012 9:43 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [13.8.2012 9:43 100224]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.6.2012 6:34 477240]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
FF - ProfilePath - c:\documents and settings\Gamer\Data aplikací\Mozilla\Firefox\Profiles\tg1u0wz9.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-12 20:08
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-57989841-2111687655-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-57989841-2111687655-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:da,2f,18,95,86,74,00,7a,df,ea,11,35,72,a0,de,f8,06,be,89,a8,0e,
4f,de,ca,28,e4,cd,1d,df,48,a6,7d,0f,31,69,b1,11,ec,5d,41,41,88,dc,67,ae,5f,\
"rkeysecu"=hex:b1,f1,05,fc,74,26,2e,6c,a5,4f,c5,b4,e1,a1,f6,e5
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{34A0FF07-F11A-4157-84A3-92F8AD688CBF}]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2156)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Promise Technology, Inc\Promise Array Management\MsgAgt.exe
c:\program files\Promise Technology, Inc\Promise Array Management\MsgSvr.exe
c:\windows\System32\snmp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2012-11-12 20:10:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-12 19:10
ComboFix2.txt 2012-11-12 14:08
.
Před spuštěním: Volných bajtů: 34 577 817 600
Po spuštění: Volných bajtů: 36 335 419 392
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 40341C4A15B7335D43E7EC78E93D884E