Stránka 1 z 2

Zavirované starší PC, virus vypíná přístup na internet

Napsal: 09 lis 2012 21:59
od stenly25
Dobrý večer, prosím o pomoc s odvirováním, log níže:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Petr at 2012-11-09 21:54:42
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 33 GB (22%) free of 153 GB
Total RAM: 1022 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:54:50, on 9.11.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\windows\system32\nvsvc32.exe
C:\windows\system32\PnkBstrA.exe
C:\Program Files\SMART Board Software\SMARTBoardService.exe
C:\windows\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\windows\Explorer.EXE
C:\Program Files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe
C:\windows\RTHDCPL.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\windows\PixArt\PAC207\Monitor.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Petr\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Petr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://safesearchr.lavasoft.com/?source ... 506BCDE634
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll
F2 - REG:system.ini: UserInit=C:\windows\system32\userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: MyPlayCity Toolbar - {4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} - C:\Program Files\MyPlayCity\tbMyPl.dll
O2 - BHO: SMART Notebook Download Plugin - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files\SMART Board Software\NotebookPlugin.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll
O4 - HKLM\..\Run: [Startup Cleaner] C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe
O4 - HKLM\..\Run: [ScreenManager Pro for LCD] C:\Program Files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] C:\windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe"
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\windows\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: VideoBrowser Camera Monitor.lnk = E:\Pixela\CameraMonitor.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/stati ... 0.67.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0446CF07-24EC-44FA-8C33-09384CB705B8}: NameServer = 62.240.178.250,10.0.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0446CF07-24EC-44FA-8C33-09384CB705B8}: NameServer = 62.240.178.250,10.0.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\windows\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Desura Install Service - Desura Pty Ltd - C:\Program Files\Common Files\Desura\desura_service.exe
O23 - Service: Google Update Service (gupdate1c98d5c200745e8) (gupdate1c98d5c200745e8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: Network Utility (PxDMSService) - Unknown owner - C:\Program Files\PIXELA\Network Utility\PxDMSService.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Služba SMART Board (SMART Board Service) - SMART Technologies Inc. - C:\Program Files\SMART Board Software\SMARTBoardService.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 11804 bytes

======Scheduled tasks folder======

C:\windows\tasks\Ad-Aware Antivirus Scheduled Scan.job
C:\windows\tasks\Ad-Aware Update (Weekly).job
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\AppleSoftwareUpdate.job
C:\windows\tasks\avast! Emergency Update.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\NetworkUtility起動.job
C:\windows\tasks\RMSchedule.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "wrc@avast.com:20110101, battlefieldheroespatcher@ea.com:5.0.31.0, {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.2, {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, bkmrksync@nokia.com:1.0.0.723, {5C655500-E712-41e7-9349-CE462F844B19}:0.8.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.18"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.7&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"bkmrksync@nokia.com"=C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"wrc@avast.com"=C:\Program Files\Alwil Software\Avast5\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi]
"Description"=ZoneAlarm Toolbar Api
"Path"=C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@comrade.gamespy.com/comrade]
"Description"=
"Path"=C:\Program Files\GameSpy\Comrade\npcomrade.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483]
"Description"=6.0.12.1483
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files\Sony\Media Go\npmediago.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@unity3d.com/UnityPlayer]
"Description"=Unity Player 2.5.0f5
"Path"=C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll

C:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
AskSearch.js
binary.manifest
browsercomps.dll
msservice.js
nppl3260.xpt
nsIQTScriptablePlugin.xpt
nsJSRealPlayerPlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
adawaretb.xml
avg_igeared.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\
battlefieldheroespatcher@ea.com
jid1-yZwVFzbsyfMrqQ@jetpack
{20a82645-c095-46ed-80e3-08825760534b}
{87934c42-161d-45bc-8cef-ef18abe2a30c}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

C:\Documents and Settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\searchplugins\
ask.xml
icqplugin-1.xml
icqplugin-10.xml
icqplugin-11.xml
icqplugin-12.xml
icqplugin-13.xml
icqplugin-14.xml
icqplugin-15.xml
icqplugin-16.xml
icqplugin-17.xml
icqplugin-18.xml
icqplugin-19.xml
icqplugin-2.xml
icqplugin-20.xml
icqplugin-21.xml
icqplugin-22.xml
icqplugin-23.xml
icqplugin-24.xml
icqplugin-25.xml
icqplugin-26.xml
icqplugin-27.xml
icqplugin-28.xml
icqplugin-29.xml
icqplugin-3.xml
icqplugin-30.xml
icqplugin-31.xml
icqplugin-32.xml
icqplugin-33.xml
icqplugin-34.xml
icqplugin-35.xml
icqplugin-36.xml
icqplugin-37.xml
icqplugin-38.xml
icqplugin-39.xml
icqplugin-4.xml
icqplugin-40.xml
icqplugin-41.xml
icqplugin-42.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
MyPlayCity Toolbar - C:\Program Files\MyPlayCity\tbMyPl.dll [2008-03-04 1470488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67BCF957-85FC-4036-8DC4-D4D80E00A77B}]
CIEDownload Object - C:\Program Files\SMART Board Software\NotebookPlugin.dll [2006-06-27 602112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-06-09 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
Ad-Aware Security Add-on - C:\Program Files\adawaretb\adawareDx.dll [2012-09-20 87448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-08-21 1227224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-11-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-11-12 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-08-21 1227224]
{6c97a91e-4524-4019-86af-2aa2d567bf5c} - Ad-Aware Security Add-on - C:\Program Files\adawaretb\adawareDx.dll [2012-09-20 87448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Startup Cleaner"=C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe [2006-10-08 122880]
"ScreenManager Pro for LCD"=C:\Program Files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe [2004-10-20 8925184]
"RTHDCPL"=C:\windows\RTHDCPL.EXE [2005-06-08 14565376]
"RemoteControl"=C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-10-11 75304]
"gcasServ"=C:\Program Files\Microsoft AntiSpyware\gcasServ.exe [2005-11-15 473928]
"PAC207_Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Monitor"=C:\windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2012-08-21 4282728]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-08-27 59280]
"NvMediaCenter"=C:\windows\system32\NvMcTray.dll [2011-10-08 203072]
"NvCplDaemon"=C:\windows\system32\NvCpl.dll [2011-10-08 16744256]
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2011-10-08 1632360]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2012-09-09 421776]
"Ad-Aware Browsing Protection"=C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe [2012-08-08 540056]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"=C:\windows\system32\sti_ci.dll [2008-04-14 136704]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"= []
"ctfmon.exe"=C:\windows\system32\ctfmon.exe [2008-04-14 15360]
"OfficeSyncProcess"=C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [2012-01-20 719672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Nástroje SMART Board.lnk]
C:\PROGRA~1\SMARTB~1\SMARTB~2.EXE [2006-06-27 3371008]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
VideoBrowser Camera Monitor.lnk - E:\Pixela\CameraMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\windows\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{9EF34FF2-3396-4527-9D27-04C8C1C67806}"=C:\Program Files\Microsoft AntiSpyware\shellextension.dll [2005-11-15 101080]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Průvodce přenesením souborů a nastavení"
"C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\age2_x1.icd"="C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\age2_x1.icd:*:Enabled:Age of Empires II Expansion"
"C:\Program Files\Team17 Software Ltd\WormsForts\WF.exe"="C:\Program Files\Team17 Software Ltd\WormsForts\WF.exe:*:Disabled:WF"
"C:\Program Files\Port Royale\PortRoyale.exe"="C:\Program Files\Port Royale\PortRoyale.exe:*:Enabled:Port Royale"
"C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD"="C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II"
"C:\Program Files\OziExplorer\OziExp.exe"="C:\Program Files\OziExplorer\OziExp.exe:*:Enabled:OziExp"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe"="C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\Codemasters\Worms 4 Totalni narez\Worms 4 Mayhem.exe"="C:\Program Files\Codemasters\Worms 4 Totalni narez\Worms 4 Mayhem.exe:*:Enabled:Worms 4 Mayhem"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\GameSpy\Comrade\Comrade.exe"="C:\Program Files\GameSpy\Comrade\Comrade.exe:*:Enabled:Comrade"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon"
"C:\Program Files\Sony Ericsson\Update Service\Update Service.exe"="C:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service"
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace"
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe"="C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe:*:Enabled:Update Engine"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"E:\stronghold\Stronghold2.exe"="E:\stronghold\Stronghold2.exe:*:Enabled:Stronghold 2"
"E:\Hunter\launcher\launcher.exe"="E:\Hunter\launcher\launcher.exe:*:Enabled:theHunter Launcher"
"E:\steam\Steam.exe"="E:\steam\Steam.exe:*:Enabled:Steam"
"E:\Hry\World_of_Tanks_closed_Beta\WOTLauncher.exe"="E:\Hry\World_of_Tanks_closed_Beta\WOTLauncher.exe:*:Enabled:World of Tanks Launcher"
"E:\Hry\World_of_Tanks_closed_Beta\WorldOfTanks.exe"="E:\Hry\World_of_Tanks_closed_Beta\WorldOfTanks.exe:*:Enabled:World of Tanks"
"E:\steam\steamapps\common\company of heroes\RelicCOH.exe"="E:\steam\steamapps\common\company of heroes\RelicCOH.exe:*:Enabled:Company of Heroes: Tales of Valor"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Documents and Settings\Petr\Plocha\chmatakov15.exe"="C:\Documents and Settings\Petr\Plocha\chmatakov15.exe:*:Enabled:chmatakov15"
"E:\steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe"="E:\steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe:*:Enabled:Relic Patch Download Manager"
"E:\steam\steamapps\common\portal 2\portal2.exe"="E:\steam\steamapps\common\portal 2\portal2.exe:*:Enabled:Portal 2"
"C:\Program Files\PIXELA\Network Utility\PxDMSService.exe"="C:\Program Files\PIXELA\Network Utility\PxDMSService.exe:*:Enabled:Network Utility"
"E:\Hry\Ace of Spades\server.exe"="E:\Hry\Ace of Spades\server.exe:*:Enabled:server"
"E:\Honza\steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe"="E:\Honza\steam\steamapps\common\company of heroes\RelicDownloader\RelicDownloader.exe:*:Enabled:Relic Patch Download Manager"
"E:\Honza\steam\steamapps\common\company of heroes\RelicCOH.exe"="E:\Honza\steam\steamapps\common\company of heroes\RelicCOH.exe:*:Enabled:RelicCOH"
"E:\Honza\steam\steamapps\popo0123456789\team fortress 2\hl2.exe"="E:\Honza\steam\steamapps\popo0123456789\team fortress 2\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\adawaretb\dtUser.exe"="C:\Program Files\adawaretb\dtUser.exe:*:Enabled:Ad-Aware Security Add-on DTX Broker"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"VIDC.MPG4"=MPG4c32.dll
"VIDC.MP42"=MPG4c32.dll
"vidc.tscc"=tsccvid.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.DIVX"=DivX.dll
"VIDC.XVID"=xvid.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"vidc.MP43"=MPG4c32.dll

======List of files/folders created in the last 1 month======

2012-11-06 12:33:34 ----A---- C:\scu.dat
2012-10-29 21:45:26 ----D---- C:\Program Files\Mozilla Firefox
2012-10-11 21:16:40 ----HDC---- C:\windows\$NtUninstallKB2724197$
2012-10-11 21:08:17 ----HDC---- C:\windows\$NtUninstallKB2756822$
2012-10-11 21:06:48 ----HDC---- C:\windows\$NtUninstallKB2749655$
2012-10-11 21:06:30 ----HDC---- C:\windows\$NtUninstallKB2661254-v2$

======List of files/folders modified in the last 1 month======

2012-11-09 21:54:51 ----D---- C:\windows\Prefetch
2012-11-09 21:54:45 ----D---- C:\Program Files\trend micro
2012-11-09 21:49:55 ----D---- C:\windows\temp
2012-11-09 21:39:05 ----D---- C:\windows\system32\CatRoot2
2012-11-09 21:36:28 ----D---- C:\Program Files\Microsoft AntiSpyware
2012-11-09 21:36:26 ----D---- C:\windows\system32\Lang
2012-11-09 21:36:24 ----D---- C:\windows\system32
2012-11-09 21:03:00 ----A---- C:\windows\SchedLgU.Txt
2012-11-06 20:28:45 ----D---- C:\Documents and Settings\Petr\Data aplikací\Canon
2012-11-06 19:01:11 ----D---- C:\Program Files\Mozilla Thunderbird
2012-11-06 11:26:09 ----SD---- C:\windows\Downloaded Program Files
2012-11-06 11:24:03 ----D---- C:\Documents and Settings\Petr\Data aplikací\adawaretb
2012-11-05 19:02:29 ----A---- C:\windows\Filzip.ini
2012-10-31 18:10:42 ----A---- C:\windows\system32\wrap_oal.dll
2012-10-31 18:10:41 ----A---- C:\windows\system32\OpenAL32.dll
2012-10-31 17:22:02 ----D---- C:\Program Files\Handbrake
2012-10-31 16:58:38 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-10-30 18:52:36 ----RD---- C:\Program Files
2012-10-28 10:10:54 ----A---- C:\windows\system32\PerfStringBackup.INI
2012-10-25 15:18:52 ----D---- C:\Documents and Settings\Petr\Data aplikací\.minecraft
2012-10-23 19:24:55 ----D---- C:\Documents and Settings\Petr\Data aplikací\OpenOffice.org2
2012-10-12 08:42:19 ----D---- C:\WINDOWS
2012-10-11 21:16:52 ----HD---- C:\windows\inf
2012-10-11 21:16:47 ----RSHDC---- C:\windows\system32\dllcache
2012-10-11 21:16:16 ----SHD---- C:\windows\Installer
2012-10-11 21:16:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-10-11 21:08:29 ----A---- C:\windows\system32\MRT.exe
2012-10-11 21:08:22 ----A---- C:\windows\imsins.BAK
2012-10-11 20:38:13 ----A---- C:\windows\system32\FlashPlayerApp.exe
2012-10-11 17:40:41 ----HD---- C:\windows\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\windows\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 prohlp02;StarForce Protection Helper Driver v2; C:\windows\System32\drivers\prohlp02.sys [2004-08-09 114016]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\windows\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\windows\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\windows\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp01;StarForce Protection Helper Driver; C:\windows\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\windows\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\windows\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\windows\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\windows\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\windows\system32\drivers\Aavmker4.sys [2012-08-21 25256]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\windows\system32\drivers\atkkbnt.sys [2004-07-20 20096]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2012-08-21 35928]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 intelppm;Řadič procesoru Intel; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\windows\System32\drivers\prodrv06.sys [2004-08-09 53920]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMon2;avast! Standard Shield Support; C:\windows\system32\drivers\aswMon2.sys [2012-08-21 97608]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R3 Arp1394;Protokol 1394 ARP Client; C:\windows\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\windows\system32\DRIVERS\e1e5132.sys [2005-07-06 176128]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RtkHDAud.sys [2005-06-08 3160576]
R3 mouhid;Ovladač myši standardu HID; C:\windows\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\windows\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2011-10-08 12791488]
R3 PAC207;e-Messenger 112; C:\windows\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\windows\System32\Drivers\RootMdm.sys [2004-08-18 5888]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\windows\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 SBRE;SBRE; \??\C:\windows\system32\drivers\SBREdrv.sys []
S3 61883;61883 Unit Device; C:\windows\system32\DRIVERS\61883.sys [2008-04-13 48128]
S3 Avc;AVC Device; C:\windows\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 AVCSTRM;AVC Streaming Filter Driver; C:\windows\system32\DRIVERS\avcstrm.sys [2008-04-13 13696]
S3 AVerE506;AVerE506 service; C:\windows\system32\DRIVERS\AVerE506.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder iPod Edition\SysInfo.sys []
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\windows\system32\FsUsbExDisk.SYS []
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2012-07-25 12400]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2012-07-25 25200]
S3 GMSIPCI;GMSIPCI; C:\windows\system32\drivers\GMSIPCI.sys []
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2007-04-04 17480]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\mbamswissarmy.sys []
S3 MPE;Filtr MPE BDA; C:\windows\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSDV;Microsoft DV Camera and VCR; C:\windows\system32\DRIVERS\msdv.sys [2008-04-13 51200]
S3 MSTAPE;Microsoft AV/C Tape Subunit Device; C:\windows\system32\DRIVERS\mstape.sys [2008-04-13 49024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent; C:\windows\system32\drivers\ccdcmb.sys [2009-10-06 17664]
S3 nmwcdc;Nokia USB Generic; C:\windows\system32\drivers\ccdcmbo.sys [2009-10-06 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 seehcri;Sony Ericsson seehcri Device Driver; C:\windows\system32\DRIVERS\seehcri.sys [2010-10-19 27632]
S3 SLIP;BDA Slip De-Framer; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2009-10-06 7936]
S3 USBAAPL;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbprint;Třída USB Printer; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-10-06 7936]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 w600bus;Sony Ericsson W600 driver (WDM); C:\windows\system32\DRIVERS\w600bus.sys [2005-08-15 60928]
S3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter; C:\windows\system32\DRIVERS\w600mdfl.sys [2005-08-15 8336]
S3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers; C:\windows\system32\DRIVERS\w600mdm.sys [2005-08-15 96672]
S3 w600mgmt;Sony Ericsson W600 USB WMC Device Management Drivers; C:\windows\system32\DRIVERS\w600mgmt.sys [2005-08-15 88080]
S3 w600obex;Sony Ericsson W600 USB WMC OBEX Interface Drivers; C:\windows\system32\DRIVERS\w600obex.sys [2005-08-15 85952]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\windows\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 Pcouffin;Low level access layer for CD devices; C:\windows\System32\Drivers\Pcouffin.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2004-07-20 90112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-08-21 44808]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-12 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-12-18 73728]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-20 935208]
R2 NVSvc;NVIDIA Driver Helper Service; C:\windows\system32\nvsvc32.exe [2011-10-08 298304]
R2 PnkBstrA;PnkBstrA; C:\windows\system32\PnkBstrA.exe [2011-08-17 75136]
R2 SMART Board Service;Služba SMART Board; C:\Program Files\SMART Board Software\SMARTBoardService.exe [2006-06-27 970752]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-09-09 821648]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate1c98d5c200745e8;Google Update Service (gupdate1c98d5c200745e8); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-12 133104]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-11 250808]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Desura Install Service;Desura Install Service; C:\Program Files\Common Files\Desura\desura_service.exe [2012-07-23 131912]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-12 133104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-29 115168]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PxDMSService;Network Utility; C:\Program Files\PIXELA\Network Utility\PxDMSService.exe []
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-04-20 152064]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2012-09-07 529744]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 09 lis 2012 22:11
od Rudy
Zdravím!
Poprosím o log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 09 lis 2012 22:50
od stenly25
Tady je:

ComboFix 12-11-09.02 - Petr 09.11.2012 22:20:58.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1022.370 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Petr\WINDOWS
c:\windows\IsUn0405.exe
c:\windows\IsUn0407.exe
c:\windows\iun6002.exe
c:\windows\system32\TZLog.log
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-09 do 2012-11-09 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-31 17:10 . 2003-11-07 12:28 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-31 17:10 . 2003-11-07 12:28 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-11 19:38 . 2012-04-09 06:40 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 19:38 . 2011-05-16 06:14 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 15:18 . 2004-08-18 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:18 . 2004-08-18 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:18 . 2004-08-18 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-18 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2004-08-18 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:27 . 2004-08-18 12:00 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2004-08-17 15:45 2029568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-21 11:01 . 2009-09-17 19:41 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2009-09-17 19:41 106928 ----a-w- c:\windows\system32\GEARAspi.dll
2012-08-21 09:13 . 2011-03-03 20:13 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2010-09-13 19:58 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2010-09-13 19:58 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2010-09-13 19:58 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-21 09:13 . 2010-09-13 19:58 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-08-21 09:13 . 2010-09-13 19:58 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-08-21 09:13 . 2010-09-13 19:58 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:13 . 2010-09-13 19:58 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-08-21 09:12 . 2010-09-13 19:57 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2010-09-13 19:57 227648 ----a-w- c:\windows\system32\aswBoot.exe
2004-10-01 14:00 . 2006-02-26 17:11 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2012-10-29 20:45 . 2012-10-29 20:45 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files\adawaretb\adawareDx.dll" [2012-09-20 87448]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"= "c:\program files\MyPlayCity\tbMyPl.dll" [2008-03-04 1470488]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
2008-03-04 11:44 1470488 ----a-w- c:\program files\MyPlayCity\tbMyPl.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2012-09-20 20:06 87448 ----a-w- c:\program files\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files\adawaretb\adawareDx.dll" [2012-09-20 87448]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"= "c:\program files\MyPlayCity\tbMyPl.dll" [2008-03-04 1470488]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC}"= "c:\program files\MyPlayCity\tbMyPl.dll" [2008-03-04 1470488]
.
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-20 719672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-10-08 122880]
"ScreenManager Pro for LCD"="c:\program files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe" [2004-10-20 8925184]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-08 14565376]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 473928]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-10-08 203072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-09 421776]
"Ad-Aware Browsing Protection"="c:\documents and settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe" [2012-08-08 540056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [2008-04-14 136704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
VideoBrowser Camera Monitor.lnk - e:\pixela\CameraMonitor.exe [2012-5-13 425336]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Nástroje SMART Board.lnk]
backup=c:\windows\pss\Nástroje SMART Board.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Team17 Software Ltd\\WormsForts\\WF.exe"=
"c:\\Program Files\\OziExplorer\\OziExp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Codemasters\\Worms 4 Totalni narez\\Worms 4 Mayhem.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"e:\\stronghold\\Stronghold2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Honza\\steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe"=
"e:\\Honza\\steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"=
"e:\\Honza\\steam\\steamapps\\popo0123456789\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\adawaretb\\dtUser.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"50103:TCP"= 50103:TCP:NetworkUtility TCP 50103
"50104:TCP"= 50104:TCP:NetworkUtility TCP 50104
"50105:TCP"= 50105:TCP:NetworkUtility TCP 50105
"50106:TCP"= 50106:TCP:NetworkUtility TCP 50106
"50107:TCP"= 50107:TCP:NetworkUtility TCP 50107
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3.3.2011 21:13 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [13.9.2010 20:58 355632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [13.9.2010 20:58 21256]
R2 gupdate1c98d5c200745e8;Google Update Service (gupdate1c98d5c200745e8);c:\program files\Google\Update\GoogleUpdate.exe [12.2.2009 22:51 133104]
R3 PAC207;e-Messenger 112;c:\windows\system32\drivers\PFC027.SYS [9.2.2009 16:12 616064]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 12:28 160944]
S3 AVerE506;AVerE506 service;c:\windows\system32\DRIVERS\AVerE506.sys --> c:\windows\system32\DRIVERS\AVerE506.sys [?]
S3 Desura Install Service;Desura Install Service;c:\program files\Common Files\Desura\desura_service.exe [23.7.2012 15:23 131912]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [7.2.2010 19:04 36608]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [19.10.2010 16:17 12400]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [31.8.2010 16:24 38224]
S3 PxDMSService;Network Utility;"c:\program files\PIXELA\Network Utility\PxDMSService.exe" --> c:\program files\PIXELA\Network Utility\PxDMSService.exe [?]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [19.10.2010 16:17 27632]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [12.11.2010 22:37 152064]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [7.2.2010 19:04 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [7.2.2010 19:04 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [7.2.2010 19:04 121856]
S3 w600bus;Sony Ericsson W600 driver (WDM);c:\windows\system32\drivers\w600bus.sys [15.8.2005 14:04 60928]
S3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter;c:\windows\system32\drivers\w600mdfl.sys [15.8.2005 14:04 8336]
S3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers;c:\windows\system32\drivers\w600mdm.sys [15.8.2005 14:04 96672]
S3 w600mgmt;Sony Ericsson W600 USB WMC Device Management Drivers;c:\windows\system32\drivers\w600mgmt.sys [15.8.2005 14:04 88080]
S3 w600obex;Sony Ericsson W600 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\w600obex.sys [15.8.2005 14:04 85952]
S4 Pcouffin;Low level access layer for CD devices;c:\windows\system32\Drivers\Pcouffin.sys --> c:\windows\system32\Drivers\Pcouffin.sys [?]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 19:38]
.
2012-09-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:57]
.
2012-11-09 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-08-14 09:12]
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 21:51]
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 21:51]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=D6477B80F6B0A94C89F7A4506BCDE634
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel
IE: Od&eslat do aplikace OneNote
TCP: DhcpNameServer = 192.168.2.254
TCP: Interfaces\{0446CF07-24EC-44FA-8C33-09384CB705B8}: NameServer = 62.240.178.250,10.0.0.1
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\
FF - prefs.js: browser.search.selectedEngine - blekko
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q=
FF - ExtSQL: 2012-10-03 07:32; {87934c42-161d-45bc-8cef-ef18abe2a30c}; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
FF - ExtSQL: 2012-10-03 07:32; jid1-yZwVFzbsyfMrqQ@jetpack; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
FF - ExtSQL: !HIDDEN! 2009-09-02 00:30; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-PowerBar - (no file)
AddRemove-CM_DiskCleaner - c:\windows\iun6002.exe
AddRemove-Easy-WebPrint - c:\windows\IsUn0405.exe
AddRemove-Reward - c:\windows\IsUn0405.exe
AddRemove-Steam App 20540 - e:\steam\steam.exe
AddRemove-Steam App 400 - e:\steam\steam.exe
AddRemove-Steam App 4560 - e:\steam\steam.exe
AddRemove-Steam App 620 - e:\steam\steam.exe
AddRemove-Steam App 9340 - e:\steam\steam.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-09 22:41
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ????<???D??sh?????6~????h???Z?6~(???*?6~t?@?l?@?Prg???????????????????????????????????????????????????????9~0?6~????*?6~??6~????D??s??????????6~????l?@?????q?7~????t?@??xh?????????l?@?l?@?????zw7~????t?@?????l?@?8?@?l?@?3??s????????????????????8?@?_??s8?@?8?@
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2012-11-09 22:46:51
ComboFix-quarantined-files.txt 2012-11-09 21:46
.
Před spuštěním: Volných bajtů: 34 673 475 584
Po spuštění: Volných bajtů: 35 714 830 336
.
- - End Of File - - B0C474423FE8672A6CC70A58308AB4E1

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 09 lis 2012 23:06
od Rudy
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

Folder::
c:\program files\adawaretb
c:\program files\MyPlayCity

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Registry::
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
[-HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
[-HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"50103:TCP"=-
"50104:TCP"=-
"50105:TCP"=-
"50106:TCP"=-
"50107:TCP"=-

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 09 lis 2012 23:49
od stenly25
Nový log tady:

ComboFix 12-11-09.02 - Petr 09.11.2012 23:12:05.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1022.386 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Petr\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\adawaretb
c:\program files\adawaretb\adawareDx.dll
c:\program files\adawaretb\adawaretb.dll
c:\program files\adawaretb\adawaretb.xml
c:\program files\adawaretb\components\windowmediator.js
c:\program files\adawaretb\dtUser.exe
c:\program files\adawaretb\chrome\content\custom.js
c:\program files\adawaretb\chrome\content\lib\about.xml
c:\program files\adawaretb\chrome\content\lib\dtxpanel.xul
c:\program files\adawaretb\chrome\content\lib\dtxpaneltransparent.xul
c:\program files\adawaretb\chrome\content\lib\dtxpanelwin.xul
c:\program files\adawaretb\chrome\content\lib\dtxprefwin.xul
c:\program files\adawaretb\chrome\content\lib\dtxtransparentwin.xul
c:\program files\adawaretb\chrome\content\lib\dtxwin.xul
c:\program files\adawaretb\chrome\content\lib\emailnotifierproviders.xml
c:\program files\adawaretb\chrome\content\lib\external.js
c:\program files\adawaretb\chrome\content\lib\neterror.xhtml
c:\program files\adawaretb\chrome\content\lib\rsspreview.html
c:\program files\adawaretb\chrome\content\lib\rsswin.xml
c:\program files\adawaretb\chrome\content\lib\rsswin.xsl
c:\program files\adawaretb\chrome\content\modules\datastore.jsm
c:\program files\adawaretb\chrome\content\modules\nsDragAndDrop.js
c:\program files\adawaretb\chrome\content\newtab\images\bullet.gif
c:\program files\adawaretb\chrome\content\newtab\images\field_bg.gif
c:\program files\adawaretb\chrome\content\newtab\images\powered_by_yahoo.gif
c:\program files\adawaretb\chrome\content\newtab\newtab.html
c:\program files\adawaretb\chrome\content\preferences.xml
c:\program files\adawaretb\chrome\content\toolbar.htm
c:\program files\adawaretb\chrome\content\toolbar.xul
c:\program files\adawaretb\chrome\content\widgets\net.vmn.www.BrowserDataCleaner\ClearBrowserDataDialog.xml
c:\program files\adawaretb\chrome\content\widgets\net.vmn.www.BrowserDataCleaner\tb_icon.png
c:\program files\adawaretb\chrome\content\widgets\net.vmn.www.BrowserDataCleaner\widget.js
c:\program files\adawaretb\chrome\content\widgets\net.vmn.www.BrowserDataCleaner\widget.xml
c:\program files\adawaretb\chrome\content\widgets\net.vmn.www.ToolbarCleaner\tb_icon.png
c:\program files\adawaretb\chrome\content\widgets\net.vmn.www.ToolbarCleaner\widget.js
c:\program files\adawaretb\chrome\content\widgets\net.vmn.www.ToolbarCleaner\widget.xml
c:\program files\adawaretb\chrome\data\search\engines.xml
c:\program files\adawaretb\chrome\data\search\search.xsl
c:\program files\adawaretb\chrome\locale\lib\de.js
c:\program files\adawaretb\chrome\locale\lib\en.js
c:\program files\adawaretb\chrome\locale\lib\es.js
c:\program files\adawaretb\chrome\locale\lib\fr.js
c:\program files\adawaretb\chrome\locale\lib\it.js
c:\program files\adawaretb\chrome\locale\toolbar\de.js
c:\program files\adawaretb\chrome\locale\toolbar\en.js
c:\program files\adawaretb\chrome\locale\toolbar\es.js
c:\program files\adawaretb\chrome\locale\toolbar\fr.js
c:\program files\adawaretb\chrome\locale\toolbar\it.js
c:\program files\adawaretb\chrome\skin\blekko16.png
c:\program files\adawaretb\chrome\skin\bluelite.gif
c:\program files\adawaretb\chrome\skin\bluesky.gif
c:\program files\adawaretb\chrome\skin\btn-safe-de.png
c:\program files\adawaretb\chrome\skin\btn-safe-en.png
c:\program files\adawaretb\chrome\skin\btn-safe-es.png
c:\program files\adawaretb\chrome\skin\btn-safe-fr.png
c:\program files\adawaretb\chrome\skin\btn-safe-it.png
c:\program files\adawaretb\chrome\skin\btn-safe.png
c:\program files\adawaretb\chrome\skin\btn-search-de-over.png
c:\program files\adawaretb\chrome\skin\btn-search-de.png
c:\program files\adawaretb\chrome\skin\btn-search-en-over.png
c:\program files\adawaretb\chrome\skin\btn-search-en.png
c:\program files\adawaretb\chrome\skin\btn-search-es-over.png
c:\program files\adawaretb\chrome\skin\btn-search-es.png
c:\program files\adawaretb\chrome\skin\btn-search-fr-over.png
c:\program files\adawaretb\chrome\skin\btn-search-fr.png
c:\program files\adawaretb\chrome\skin\btn-search-it-over.png
c:\program files\adawaretb\chrome\skin\btn-search-it.png
c:\program files\adawaretb\chrome\skin\btn-settings-over.png
c:\program files\adawaretb\chrome\skin\btn-settings.png
c:\program files\adawaretb\chrome\skin\btn-unsafe-de.png
c:\program files\adawaretb\chrome\skin\btn-unsafe-en.png
c:\program files\adawaretb\chrome\skin\btn-unsafe-es.png
c:\program files\adawaretb\chrome\skin\btn-unsafe-fr.png
c:\program files\adawaretb\chrome\skin\btn-unsafe-it.png
c:\program files\adawaretb\chrome\skin\btn-unsafe.png
c:\program files\adawaretb\chrome\skin\custom.css
c:\program files\adawaretb\chrome\skin\dictionary.png
c:\program files\adawaretb\chrome\skin\downloadcom.png
c:\program files\adawaretb\chrome\skin\facebook.png
c:\program files\adawaretb\chrome\skin\games.png
c:\program files\adawaretb\chrome\skin\grey.gif
c:\program files\adawaretb\chrome\skin\ico-cleaner.png
c:\program files\adawaretb\chrome\skin\ico-clear.png
c:\program files\adawaretb\chrome\skin\images.png
c:\program files\adawaretb\chrome\skin\lib\add.png
c:\program files\adawaretb\chrome\skin\lib\aol.png
c:\program files\adawaretb\chrome\skin\lib\arrow-dn.gif
c:\program files\adawaretb\chrome\skin\lib\arrow-right-disabled.gif
c:\program files\adawaretb\chrome\skin\lib\arrow-right.gif
c:\program files\adawaretb\chrome\skin\lib\arrow-up.gif
c:\program files\adawaretb\chrome\skin\lib\bg-btn-end.png
c:\program files\adawaretb\chrome\skin\lib\bg-btn-mdl.png
c:\program files\adawaretb\chrome\skin\lib\bg-btn-mdl_ff.png
c:\program files\adawaretb\chrome\skin\lib\bg-btn-start.png
c:\program files\adawaretb\chrome\skin\lib\bg-btnover-end.png
c:\program files\adawaretb\chrome\skin\lib\bg-btnover-mdl.png
c:\program files\adawaretb\chrome\skin\lib\bg-btnover-mdl_ff.png
c:\program files\adawaretb\chrome\skin\lib\bg-btnover-start.png
c:\program files\adawaretb\chrome\skin\lib\blank.gif
c:\program files\adawaretb\chrome\skin\lib\btnback-down-vista.png
c:\program files\adawaretb\chrome\skin\lib\btnback-vista.png
c:\program files\adawaretb\chrome\skin\lib\btnleft-down-vista.png
c:\program files\adawaretb\chrome\skin\lib\btnleft-vista.png
c:\program files\adawaretb\chrome\skin\lib\btnright-down-vista.png
c:\program files\adawaretb\chrome\skin\lib\btnright-vista.png
c:\program files\adawaretb\chrome\skin\lib\button-splitter-down-vista.png
c:\program files\adawaretb\chrome\skin\lib\button-splitter-vista.png
c:\program files\adawaretb\chrome\skin\lib\collapse.png
c:\program files\adawaretb\chrome\skin\lib\comcast.png
c:\program files\adawaretb\chrome\skin\lib\dtx.css
c:\program files\adawaretb\chrome\skin\lib\edit-back-hot.png
c:\program files\adawaretb\chrome\skin\lib\edit-back.png
c:\program files\adawaretb\chrome\skin\lib\expand.png
c:\program files\adawaretb\chrome\skin\lib\found.png
c:\program files\adawaretb\chrome\skin\lib\gmail.png
c:\program files\adawaretb\chrome\skin\lib\highlight.png
c:\program files\adawaretb\chrome\skin\lib\highlight_blue.png
c:\program files\adawaretb\chrome\skin\lib\highlight_cyan.png
c:\program files\adawaretb\chrome\skin\lib\highlight_lime.png
c:\program files\adawaretb\chrome\skin\lib\highlight_magenta.png
c:\program files\adawaretb\chrome\skin\lib\highlight_yellow.png
c:\program files\adawaretb\chrome\skin\lib\hotmail.png
c:\program files\adawaretb\chrome\skin\lib\checkmark.png
c:\program files\adawaretb\chrome\skin\lib\chevron.png
c:\program files\adawaretb\chrome\skin\lib\imap.png
c:\program files\adawaretb\chrome\skin\lib\lastsearch-thumb-back.gif
c:\program files\adawaretb\chrome\skin\lib\loadingMid.gif
c:\program files\adawaretb\chrome\skin\lib\lock.png
c:\program files\adawaretb\chrome\skin\lib\mailcom.png
c:\program files\adawaretb\chrome\skin\lib\menu_bg-basic.png
c:\program files\adawaretb\chrome\skin\lib\menu_separator_bar.png
c:\program files\adawaretb\chrome\skin\lib\menuitem-splitter.png
c:\program files\adawaretb\chrome\skin\lib\menuitemback-down-vista.png
c:\program files\adawaretb\chrome\skin\lib\menuitemback-vista.png
c:\program files\adawaretb\chrome\skin\lib\menuitemleft-down-vista.png
c:\program files\adawaretb\chrome\skin\lib\menuitemleft-vista.png
c:\program files\adawaretb\chrome\skin\lib\menuitemright-down-vista.png
c:\program files\adawaretb\chrome\skin\lib\menuitemright-vista.png
c:\program files\adawaretb\chrome\skin\lib\modify.png
c:\program files\adawaretb\chrome\skin\lib\move.gif
c:\program files\adawaretb\chrome\skin\lib\movetarget.png
c:\program files\adawaretb\chrome\skin\lib\panels\css\ie-only.css
c:\program files\adawaretb\chrome\skin\lib\panels\css\ie7-only.css
c:\program files\adawaretb\chrome\skin\lib\panels\css\popupAbout.css
c:\program files\adawaretb\chrome\skin\lib\panels\css\popupWidgets.css
c:\program files\adawaretb\chrome\skin\lib\panels\default\css\dialog.css
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\bg.gif
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\btn-close-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\btn-close.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\btn-wide-close-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\btn-wide-close.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\default.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\footer-short-left.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\footer-short-middle.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\footer-short-right.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\titlebar-left.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\titlebar-middle.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\titlebar-right.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\transparent.gif
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\win-btm-left.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\win-btm-mdl.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\win-btm-right-resize.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\images\win-btm-right.png
c:\program files\adawaretb\chrome\skin\lib\panels\default\main.html
c:\program files\adawaretb\chrome\skin\lib\panels\default\scripts\defscript.js
c:\program files\adawaretb\chrome\skin\lib\panels\images\ajax-loader.gif
c:\program files\adawaretb\chrome\skin\lib\panels\images\apps-bg-gradient-grid.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\apps-hover.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\appsfeatured-bg-gradient-grid.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\arrow-down-white.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\arrow-left.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\arrow-right.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\arrow-sml-drop.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\arrow-sml.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\arrowr-bluew5.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\bg-aboutbox.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\bg-btnover.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\bg-pnl520x390.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\bg-scrollbar-thumb-y.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\bg-scrollbar-track-y.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\bg-scrollbar-trackend-y.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-add-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-add.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-addtoolbar-left-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-addtoolbar-left.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-addtoolbar-right.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-close-grey-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-close-grey.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-close-greyover.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-close-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-close.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-dark-left22-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-dark-left22.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-dark-middle22-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-dark-middle22.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-dark-right22-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-dark-right22.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-drag.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-install.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-launch-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-launch.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-mdl-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-mdl.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-next-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-next.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-previous-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-previous.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-right-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\btn-search-pnlbtm.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\categories-bg-gradient-grid.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\featured-bg-btm-gradient.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\footer-short-left.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\footer-short-middle.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\footer-short-right.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\gamethumb-on.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-box-next.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-calendar.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-download.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-info-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-info.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-pref-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-pref.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-tags.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\ico-user-monitor.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\icon-Add.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\icon-Info.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\left-menu-hover.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\menul-bgon.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\menul-bgover.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\panel-botm-noscroll.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scroll-bg-206.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scroll-bg.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scroll-topwin.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollb-disable.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollb-down.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollb-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollb.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollt-disable.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollt-down.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollt-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\scrollt.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\searchbox-pnlbtm.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\searchbox.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\shadow-leftmenu.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\star.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\star_blank.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\star_x_grey.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\star_x_orange.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\throbber.gif
c:\program files\adawaretb\chrome\skin\lib\panels\images\titlebar-left.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\titlebar-middle.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\titlebar-right.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\topbar-inside-gradient.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\TRUSTe_about.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\view-detailed-on.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\view-detailed-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\view-thumb-on.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\view-thumb-over.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\widgets-square-16px.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\widgets-square-24px.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-bottom-middleglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-left-bottomglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-left-middleglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-left-topglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-right-bottomglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-right-middleglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-right-topglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\images\win-top-middleglow.png
c:\program files\adawaretb\chrome\skin\lib\panels\js\default.js
c:\program files\adawaretb\chrome\skin\lib\panels\js\jquery-ui.js
c:\program files\adawaretb\chrome\skin\lib\panels\js\jquery.js
c:\program files\adawaretb\chrome\skin\lib\panels\js\jquery.tinyscrollbar.js
c:\program files\adawaretb\chrome\skin\lib\panels\js\jquery.tinyscrollbar.min.js
c:\program files\adawaretb\chrome\skin\lib\panels\js\jquery.url.js
c:\program files\adawaretb\chrome\skin\lib\panels\js\kendo.all.min.js
c:\program files\adawaretb\chrome\skin\lib\panels\popupWidgets.html
c:\program files\adawaretb\chrome\skin\lib\pop.png
c:\program files\adawaretb\chrome\skin\lib\radio.png
c:\program files\adawaretb\chrome\skin\lib\reload.png
c:\program files\adawaretb\chrome\skin\lib\remove.png
c:\program files\adawaretb\chrome\skin\lib\rename.gif
c:\program files\adawaretb\chrome\skin\lib\resize-box.gif
c:\program files\adawaretb\chrome\skin\lib\rss.png
c:\program files\adawaretb\chrome\skin\lib\rsschannelback.png
c:\program files\adawaretb\chrome\skin\lib\RSSLogo.png
c:\program files\adawaretb\chrome\skin\lib\rsstabdivider.gif
c:\program files\adawaretb\chrome\skin\lib\scroll-left.png
c:\program files\adawaretb\chrome\skin\lib\scroll-right.png
c:\program files\adawaretb\chrome\skin\lib\search-go.png
c:\program files\adawaretb\chrome\skin\lib\search.png
c:\program files\adawaretb\chrome\skin\lib\text-ellipsis.xml
c:\program files\adawaretb\chrome\skin\lib\throbber.gif
c:\program files\adawaretb\chrome\skin\lib\toolbarsplitter.gif
c:\program files\adawaretb\chrome\skin\lib\transparent_1px.gif
c:\program files\adawaretb\chrome\skin\lib\uwa\border_02.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_03.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_04.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_06.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_07.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_08.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_09.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_10.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_11.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_12.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_13.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_14.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_15.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_16.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_18.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_19.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_20.png
c:\program files\adawaretb\chrome\skin\lib\uwa\border_21.png
c:\program files\adawaretb\chrome\skin\lib\uwa\btn-close-grey.png
c:\program files\adawaretb\chrome\skin\lib\uwa\btn-close-greyover.png
c:\program files\adawaretb\chrome\skin\lib\uwa\close-hot.png
c:\program files\adawaretb\chrome\skin\lib\uwa\close-normal.png
c:\program files\adawaretb\chrome\skin\lib\uwa\loadingMid.gif
c:\program files\adawaretb\chrome\skin\lib\uwa\paneltemplate.html
c:\program files\adawaretb\chrome\skin\lib\uwa\proxy.html
c:\program files\adawaretb\chrome\skin\lib\uwa\template.html
c:\program files\adawaretb\chrome\skin\lib\uwa\template.xml
c:\program files\adawaretb\chrome\skin\lib\uwa\templateFF.html
c:\program files\adawaretb\chrome\skin\lib\uwa\throbber.gif
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\icons\cond999.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\icons\icons.xml
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\icons\na-s.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\icons\na.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\icons\weather.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\add.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\box-check.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\popupWeather.css
c:\program files\adawaretb\chrome\skin\lib\weatherbutton\panels\popupWeather.html
c:\program files\adawaretb\chrome\skin\lib\yahoo.png
c:\program files\adawaretb\chrome\skin\lichen.gif
c:\program files\adawaretb\chrome\skin\logo-about.png
c:\program files\adawaretb\chrome\skin\logo-over.png
c:\program files\adawaretb\chrome\skin\logo.png
c:\program files\adawaretb\chrome\skin\modify-save.png
c:\program files\adawaretb\chrome\skin\modify.png
c:\program files\adawaretb\chrome\skin\music.png
c:\program files\adawaretb\chrome\skin\news.png
c:\program files\adawaretb\chrome\skin\options\options-main.png
c:\program files\adawaretb\chrome\skin\options\options-search.png
c:\program files\adawaretb\chrome\skin\options\options-weather.png
c:\program files\adawaretb\chrome\skin\options\options-widgets.png
c:\program files\adawaretb\chrome\skin\orange.gif
c:\program files\adawaretb\chrome\skin\search-background-de.png
c:\program files\adawaretb\chrome\skin\search-background-en.png
c:\program files\adawaretb\chrome\skin\search-background-es.png
c:\program files\adawaretb\chrome\skin\search-background-fr.png
c:\program files\adawaretb\chrome\skin\search-background-it.png
c:\program files\adawaretb\chrome\skin\search-background.png
c:\program files\adawaretb\chrome\skin\shopping.png
c:\program files\adawaretb\chrome\skin\skin-bluelite.png
c:\program files\adawaretb\chrome\skin\skin-bluesky.png
c:\program files\adawaretb\chrome\skin\skin-grey.png
c:\program files\adawaretb\chrome\skin\skin-lichen.png
c:\program files\adawaretb\chrome\skin\skin-orange.png
c:\program files\adawaretb\chrome\skin\skin-yellow.png
c:\program files\adawaretb\chrome\skin\technorati.png
c:\program files\adawaretb\chrome\skin\throbber.gif
c:\program files\adawaretb\chrome\skin\toolbarsplitter.png
c:\program files\adawaretb\chrome\skin\vertical_separator.png
c:\program files\adawaretb\chrome\skin\web.png
c:\program files\adawaretb\chrome\skin\wikipedia.png
c:\program files\adawaretb\chrome\skin\yellow.gif
c:\program files\adawaretb\chrome\skin\youtube.png
c:\program files\adawaretb\ieUtils.exe
c:\program files\adawaretb\install.ico
c:\program files\adawaretb\manifest.xml
c:\program files\adawaretb\search.ico
c:\program files\adawaretb\uninstall.exe
c:\program files\MyPlayCity
c:\program files\MyPlayCity\INSTALL.LOG
c:\program files\MyPlayCity\tbMyPl.dll
c:\program files\MyPlayCity\toolbar.cfg
c:\program files\MyPlayCity\UNWISE.EXE
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-09 do 2012-11-09 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-31 17:10 . 2003-11-07 12:28 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-31 17:10 . 2003-11-07 12:28 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-11 19:38 . 2012-04-09 06:40 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 19:38 . 2011-05-16 06:14 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 15:18 . 2004-08-18 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:18 . 2004-08-18 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:18 . 2004-08-18 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-18 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2004-08-18 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:27 . 2004-08-18 12:00 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2004-08-17 15:45 2029568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-21 11:01 . 2009-09-17 19:41 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2009-09-17 19:41 106928 ----a-w- c:\windows\system32\GEARAspi.dll
2012-08-21 09:13 . 2011-03-03 20:13 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2010-09-13 19:58 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2010-09-13 19:58 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2010-09-13 19:58 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-21 09:13 . 2010-09-13 19:58 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-08-21 09:13 . 2010-09-13 19:58 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-08-21 09:13 . 2010-09-13 19:58 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:13 . 2010-09-13 19:58 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-08-21 09:12 . 2010-09-13 19:57 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2010-09-13 19:57 227648 ----a-w- c:\windows\system32\aswBoot.exe
2004-10-01 14:00 . 2006-02-26 17:11 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2012-10-29 20:45 . 2012-10-29 20:45 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-20 719672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-10-08 122880]
"ScreenManager Pro for LCD"="c:\program files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe" [2004-10-20 8925184]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-08 14565376]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 473928]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-10-08 203072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-09 421776]
"Ad-Aware Browsing Protection"="c:\documents and settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe" [2012-08-08 540056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [2008-04-14 136704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Nástroje SMART Board.lnk]
backup=c:\windows\pss\Nástroje SMART Board.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Team17 Software Ltd\\WormsForts\\WF.exe"=
"c:\\Program Files\\OziExplorer\\OziExp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Codemasters\\Worms 4 Totalni narez\\Worms 4 Mayhem.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"e:\\stronghold\\Stronghold2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Honza\\steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe"=
"e:\\Honza\\steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"=
"e:\\Honza\\steam\\steamapps\\popo0123456789\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x]
R2 gupdate1c98d5c200745e8;Google Update Service (gupdate1c98d5c200745e8);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AVerE506;AVerE506 service;c:\windows\system32\DRIVERS\AVerE506.sys [x]
R3 Desura Install Service;Desura Install Service;c:\program files\Common Files\Desura\desura_service.exe [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 PxDMSService;Network Utility;c:\program files\PIXELA\Network Utility\PxDMSService.exe [x]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [x]
R3 w600bus;Sony Ericsson W600 driver (WDM);c:\windows\system32\DRIVERS\w600bus.sys [x]
R3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter;c:\windows\system32\DRIVERS\w600mdfl.sys [x]
R3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers;c:\windows\system32\DRIVERS\w600mdm.sys [x]
R3 w600mgmt;Sony Ericsson W600 USB WMC Device Management Drivers;c:\windows\system32\DRIVERS\w600mgmt.sys [x]
R3 w600obex;Sony Ericsson W600 USB WMC OBEX Interface Drivers;c:\windows\system32\DRIVERS\w600obex.sys [x]
R4 Pcouffin;Low level access layer for CD devices;c:\windows\system32\Drivers\Pcouffin.sys [x]
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\System32\drivers\sfdrv01a.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S3 PAC207;e-Messenger 112;c:\windows\system32\DRIVERS\PFC027.SYS [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 19:38]
.
2012-09-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:57]
.
2012-11-09 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-08-14 09:12]
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 21:51]
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 21:51]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_2&u=D6477B80F6B0A94C89F7A4506BCDE634
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel
IE: Od&eslat do aplikace OneNote
TCP: DhcpNameServer = 192.168.2.254
TCP: Interfaces\{0446CF07-24EC-44FA-8C33-09384CB705B8}: NameServer = 62.240.178.250,10.0.0.1
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\
FF - prefs.js: browser.search.selectedEngine - blekko
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q=
FF - ExtSQL: 2012-10-03 07:32; {87934c42-161d-45bc-8cef-ef18abe2a30c}; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
FF - ExtSQL: 2012-10-03 07:32; jid1-yZwVFzbsyfMrqQ@jetpack; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
FF - ExtSQL: !HIDDEN! 2009-09-02 00:30; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-Wdf01000.sys
AddRemove-adawaretb - c:\program files\adawaretb\uninstall.exe
AddRemove-MyPlayCity Toolbar - c:\progra~1\MYPLAY~1\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-09 23:36
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(4028)
c:\documents and settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~4\Office14\1029\GrooveIntlResource.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\RTHDCPL.EXE
c:\program files\Microsoft AntiSpyware\gcasDtServ.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\PnkBstrA.exe
c:\program files\SMART Board Software\SMARTBoardService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\iPod\bin\iPodService.exe
e:\pixela\CameraMonitor.exe
.
**************************************************************************
.
Celkový čas: 2012-11-09 23:43:09 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-09 22:43
ComboFix2.txt 2012-11-09 21:46
.
Před spuštěním: Volných bajtů: 35 684 687 872
Po spuštění: Volných bajtů: 35 676 295 168
.
- - End Of File - - C239AAF6FB5E4529948F14511EF6387C

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 10 lis 2012 11:16
od Rudy
Ještě jednou spusťte ComboFix tímto skriptem:
KillAll::

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Firefox::
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\
FF - prefs.js: browser.search.selectedEngine - blekko
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... r=1.1.7&q=
FF - ExtSQL: 2012-10-03 07:32; {87934c42-161d-45bc-8cef-ef18abe2a30c}; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
FF - ExtSQL: 2012-10-03 07:32; jid1-yZwVFzbsyfMrqQ@jetpack; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
FF - ExtSQL: !HIDDEN! 2009-09-02 00:30; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

Reboot::

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 10 lis 2012 17:51
od stenly25
Tady je log:

ComboFix 12-11-09.02 - Petr 10.11.2012 16:28:37.6.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1022.515 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Petr\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-10 do 2012-11-10 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-31 17:10 . 2003-11-07 12:28 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-31 17:10 . 2003-11-07 12:28 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-11 19:38 . 2012-04-09 06:40 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 19:38 . 2011-05-16 06:14 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 15:18 . 2004-08-18 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:18 . 2004-08-18 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:18 . 2004-08-18 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-18 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2004-08-18 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-23 06:27 . 2004-08-18 12:00 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-23 06:27 . 2004-08-17 15:45 2029568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-21 11:01 . 2009-09-17 19:41 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2009-09-17 19:41 106928 ----a-w- c:\windows\system32\GEARAspi.dll
2012-08-21 09:13 . 2011-03-03 20:13 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2010-09-13 19:58 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2010-09-13 19:58 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2010-09-13 19:58 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-21 09:13 . 2010-09-13 19:58 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-08-21 09:13 . 2010-09-13 19:58 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-08-21 09:13 . 2010-09-13 19:58 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:13 . 2010-09-13 19:58 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-08-21 09:12 . 2010-09-13 19:57 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2010-09-13 19:57 227648 ----a-w- c:\windows\system32\aswBoot.exe
2004-10-01 14:00 . 2006-02-26 17:11 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2012-10-29 20:45 . 2012-10-29 20:45 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-20 719672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-10-08 122880]
"ScreenManager Pro for LCD"="c:\program files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe" [2004-10-20 8925184]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-08 14565376]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 473928]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-10-08 203072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-09 421776]
"Ad-Aware Browsing Protection"="c:\documents and settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe" [2012-08-08 540056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [2008-04-14 136704]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
VideoBrowser Camera Monitor.lnk - e:\pixela\CameraMonitor.exe [2012-5-13 425336]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Nástroje SMART Board.lnk]
backup=c:\windows\pss\Nástroje SMART Board.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Team17 Software Ltd\\WormsForts\\WF.exe"=
"c:\\Program Files\\OziExplorer\\OziExp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Codemasters\\Worms 4 Totalni narez\\Worms 4 Mayhem.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"e:\\stronghold\\Stronghold2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Honza\\steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe"=
"e:\\Honza\\steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"=
"e:\\Honza\\steam\\steamapps\\popo0123456789\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3.3.2011 21:13 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [13.9.2010 20:58 355632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [13.9.2010 20:58 21256]
R3 PAC207;e-Messenger 112;c:\windows\system32\drivers\PFC027.SYS [9.2.2009 16:12 616064]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 gupdate1c98d5c200745e8;Google Update Service (gupdate1c98d5c200745e8);c:\program files\Google\Update\GoogleUpdate.exe [12.2.2009 22:51 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 12:28 160944]
S3 AVerE506;AVerE506 service;c:\windows\system32\DRIVERS\AVerE506.sys --> c:\windows\system32\DRIVERS\AVerE506.sys [?]
S3 Desura Install Service;Desura Install Service;c:\program files\Common Files\Desura\desura_service.exe [23.7.2012 15:23 131912]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [7.2.2010 19:04 36608]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [19.10.2010 16:17 12400]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [31.8.2010 16:24 38224]
S3 PxDMSService;Network Utility;"c:\program files\PIXELA\Network Utility\PxDMSService.exe" --> c:\program files\PIXELA\Network Utility\PxDMSService.exe [?]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [19.10.2010 16:17 27632]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [12.11.2010 22:37 152064]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [7.2.2010 19:04 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [7.2.2010 19:04 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [7.2.2010 19:04 121856]
S3 w600bus;Sony Ericsson W600 driver (WDM);c:\windows\system32\drivers\w600bus.sys [15.8.2005 14:04 60928]
S3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter;c:\windows\system32\drivers\w600mdfl.sys [15.8.2005 14:04 8336]
S3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers;c:\windows\system32\drivers\w600mdm.sys [15.8.2005 14:04 96672]
S3 w600mgmt;Sony Ericsson W600 USB WMC Device Management Drivers;c:\windows\system32\drivers\w600mgmt.sys [15.8.2005 14:04 88080]
S3 w600obex;Sony Ericsson W600 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\w600obex.sys [15.8.2005 14:04 85952]
S4 Pcouffin;Low level access layer for CD devices;c:\windows\system32\Drivers\Pcouffin.sys --> c:\windows\system32\Drivers\Pcouffin.sys [?]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 19:38]
.
2012-09-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:57]
.
2012-11-10 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-08-14 09:12]
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 21:51]
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-12 21:51]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel
IE: Od&eslat do aplikace OneNote
TCP: DhcpNameServer = 192.168.2.254
TCP: Interfaces\{0446CF07-24EC-44FA-8C33-09384CB705B8}: NameServer = 62.240.178.250,10.0.0.1
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2012-10-03 07:32; {87934c42-161d-45bc-8cef-ef18abe2a30c}; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
FF - ExtSQL: 2012-10-03 07:32; jid1-yZwVFzbsyfMrqQ@jetpack; c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\nnum2yml.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
FF - ExtSQL: !HIDDEN! 2009-09-02 00:30; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-10 17:03
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3124)
c:\documents and settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~4\Office14\1029\GrooveIntlResource.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\SMART Board Software\SMARTBoardService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\RTHDCPL.EXE
c:\program files\Microsoft AntiSpyware\gcasDtServ.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Celkový čas: 2012-11-10 17:08:29 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-10 16:08
ComboFix2.txt 2012-11-09 22:43
ComboFix3.txt 2012-11-09 21:46
.
Před spuštěním: Volných bajtů: 35 689 017 344
Po spuštění: Volných bajtů: 35 493 556 224
.
- - End Of File - - 0F6543ECB284CD893BC6204E77849305

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 10 lis 2012 18:50
od Rudy
Log je již OK. Nasatala nějaká změna?

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 10 lis 2012 21:48
od stenly25
Zatím vypadá ok.
Mí dva synové otestují zítra :-)
Dám vědět zítra večer nebo v pondělí.

Díky moc
Petr

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 10 lis 2012 22:44
od Rudy
Nemáte zač! :)

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 13 lis 2012 21:58
od stenly25
Stále PC není 100%, síťové připojení poměrně často zamrzne, musím shodit a znovu povolit. Ale je to o dost lepší než dříve, to spadlo třeba minutu po naběhnutí PC.
Dělám dva dny údržbu, co zvládnu, promazávám soubory, defragmentuji. Přes noc spustím hloubkový scan a dám vědět.
Petr

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 13 lis 2012 22:12
od Rudy
Zkuste ještě použít WinsockFix: http://www.softpedia.com/get/Tweak/Netw ... kFix.shtml . Utilita reinstaluje TCP/IP protokol. Máte-li parametry sítě zadány ručně, budete je muset po restartu PC znovu zadat.

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 14 lis 2012 21:49
od stenly25
Tak Avast ani Eset online scanner nic nenašli. Problém s webem dělaly pravděpodobně doplňky prohlížečů od Lavasoft Ad-aware, které se vzaly v PC bůhví jak.
Asi se nesnášejí s Avastem.
Odinstalováno a dnes celý den ok.

Ještě jednou děkuji moc, jste frajeři.
Téma můžete zamknout.
Petr

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 14 lis 2012 22:18
od Rudy
Je to možné. Pokud jste měl zapnutý rezident Ad_Aware. Nemáte zač! :)

Re: Zavirované starší PC, virus vypíná přístup na internet

Napsal: 16 lis 2012 21:11
od stenly25
Díky za odemknutí.
Tak místo oficiálního ad-aware tam mám safesearch.lavasoft.com virus, který mi blokuje prohlížeč. Právě jsem ukončil proces adawarebp.exe
Prosím o radu