Stránka 1 z 2

flashdisk a přepsání složek na zástupce pro E:\843921.exe

Napsal: 09 dub 2013 19:07
od SeaHorse
Ahoj,
tak jsem si ve skypu klikl na odkaz na fotky od známého a šup, už mám problém.... Jak to tu už dva dny čtu, je skoro s podivem, že se mi to stalo"až" teď. Kromně toho, že jsem v pc objevil pár virů, které jsem snad úspěšně zneškodnil, tak ten největší problém přetrvává. Přepsalo mi to složky na flashce a změnilo je to na zástupce, který má spouštět vir ....E:\843921.exe. Bohužel se nemohu dostat k datům, která na FD zřejmě stále jsou, ale tváří se to , že ne. Přepsalo to jen složky, soubory, které byly samostatně, tak ty fungují i nadále ok. Pokud jsem ve složce "poslední otevřené dokumenty" klikl na soubor, kterej je prokazatelně na té flashce, tak se otevřel a když jsem ho chtěl po úpravě uložit, tak mi ukázal vše co v jeho místě na té flashce je. Ovšem do toho zástupce se prostě dostat nedá. Teda já to neumím. Věděl by někdo z vás co s tím ???

Díky za odpověď

zkoušel jsem udělat ten USB fix, tady je, všechny složky s tím .lnk na E: jsou dnes pouze ikonama se skrytým obsahem ...

############################## | UsbFix V 7.120 | [Research]

User: Administrator (Administrator) # HP14000226212
Updated 30/03/2013 by El Desaparecido
Started at 16:17:46 | 08/04/2013

Website: http://sosvirus.org/
Upload Malware: http://upload.sosvirus.org/
Contact: contact@sosvirus.org

PC: Hewlett-Packard (HP Compaq dc7600 Convertible Minitower) (X86-based PC)
CPU: Intel(R) Pentium(R) 4 CPU 3.00GHz (2990)
RAM -> [Total : 2551 | Free : 1804]
BIOS: Default System BIOS
BOOT: Normal boot

OS: Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 149 Gb (104 Mb free - 70%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Removable drive # 14 Gb (7 Mb free - 48%) [KINGSTON] # FAT32
G:\ -> CD-ROM

################## | Active Processes |

C:\WINDOWS\System32\smss.exe (656)
C:\WINDOWS\system32\winlogon.exe (728)
C:\WINDOWS\system32\services.exe (772)
C:\WINDOWS\system32\lsass.exe (784)
C:\WINDOWS\system32\svchost.exe (968)
C:\WINDOWS\System32\svchost.exe (1132)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1488)
C:\WINDOWS\Explorer.EXE (1676)
C:\WINDOWS\system32\spoolsv.exe (1748)
C:\Program Files\Java\jre7\bin\jqs.exe (852)
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (1232)
C:\WINDOWS\system32\igfxtray.exe (2028)
C:\WINDOWS\system32\hkcmd.exe (476)
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe (988)
C:\WINDOWS\system32\igfxpers.exe (1380)
C:\WINDOWS\system32\svchost.exe (1332)
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (2228)
C:\WINDOWS\RTHDCPL.EXE (2312)
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE (2340)
C:\Program Files\AVAST Software\Avast\avastUI.exe (2400)
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2444)
C:\program files\real\realplayer\update\realsched.exe (2628)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (2656)
C:\WINDOWS\system32\ctfmon.exe (2708)
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (3032)
C:\Program Files\Skype\Phone\Skype.exe (3068)
C:\Program Files\System Explorer\SystemExplorer.exe (3464)
C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (3500)
C:\Program Files\Common Files\Sonic Shared\CineTray.exe (3512)
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (3528)
C:\Documents and Settings\Administrator\S-100-4902-8593-5693\winmgr.exe (3544)
C:\Program Files\TeamViewer\Version8\TeamViewer.exe (3640)
C:\WINDOWS\system32\wbem\wmiapsrv.exe (3928)
C:\Program Files\System Explorer\service\SystemExplorerService.exe (2392)
C:\Program Files\TeamViewer\Version8\tv_w32.exe (3052)
C:\WINDOWS\system32\msiexec.exe (3116)
C:\WINDOWS\system32\wscntfy.exe (3440)
C:\Program Files\Google\Chrome\Application\chrome.exe (3180)
C:\Program Files\Google\Chrome\Application\chrome.exe (2816)
C:\Program Files\Google\Chrome\Application\chrome.exe (1032)
C:\Program Files\Google\Chrome\Application\chrome.exe (2576)
C:\UsbFix\Go.exe (3300)
C:\Program Files\Google\Chrome\Application\chrome.exe (3704)

################## | El Desaparecido Section |

HKLM\SOFTWARE | Run : [IgfxTray] - C:\WINDOWS\system32\igfxtray.exe
HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe
HKLM\SOFTWARE | Run : [Persistence] - C:\WINDOWS\system32\igfxpers.exe
HKLM\SOFTWARE | Run : [Zástupce stránky vlastností sběrnice High Definition Audio] - HDAShCut.exe
HKLM\SOFTWARE | Run : [RTHDCPL] - RTHDCPL.EXE
HKLM\SOFTWARE | Run : [PTHOSTTR] - C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
HKLM\SOFTWARE | Run : [SetRefresh] - C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
HKLM\SOFTWARE | Run : [LayoutM] - KLayMgr.exe
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [TkBellExe] - "C:\program files\real\realplayer\update\realsched.exe" -osboot
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE
HKU\S-1-5-20\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [DAEMON Tools Lite] - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [Microsoft Windows Manager] - C:\Documents and Settings\Administrator\S-100-4902-8593-5693\winmgr.exe
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [SystemExplorerAutoStart] - "C:\Program Files\System Explorer\SystemExplorer.exe" /TRAY
HKU\S-1-5-18\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE

################## | Files # Infected Folders |

Found ! E:\LOST.DIR.lnk
Found ! E:\.android_secure.lnk
Found ! E:\CD01.lnk
Found ! E:\GE.lnk
Found ! E:\Plynostav.lnk
Found ! E:\SCANER.lnk
Found ! E:\avast.lnk
Found ! E:\Barvy.lnk
Found ! E:\bydlení.lnk
Found ! E:\cizi.lnk
Found ! E:\daně2006.lnk
Found ! E:\daně2007.lnk
Found ! E:\daně2008.lnk
Found ! E:\daně2009.lnk
Found ! E:\daně2010.lnk
Found ! E:\dovolená.lnk
Found ! E:\DVD.lnk
Found ! E:\Emise.lnk
Found ! E:\FAQuickMenu.lnk
Found ! E:\freehry.lnk
Found ! E:\garáž.lnk
Found ! E:\Golf.lnk
Found ! E:\iso.lnk
Found ! E:\kancelář.lnk
Found ! E:\knihy.lnk
Found ! E:\kontrola.lnk
Found ! E:\Moje !.lnk
Found ! E:\mt lep.lnk
Found ! E:\nemovitost.lnk
Found ! E:\Normy.lnk
Found ! E:\ofice.lnk
Found ! E:\PC.lnk
Found ! E:\plechy Vestas.lnk
Found ! E:\pokuta.lnk
Found ! E:\Polachová.lnk
Found ! E:\pracovní smlouvy.lnk
Found ! E:\pruhy.lnk
Found ! E:\rodokmen.lnk
Found ! E:\rumunština.lnk
Found ! E:\sex.lnk
Found ! E:\seznam.lnk
Found ! E:\Stehlík.lnk
Found ! E:\Truecrypt.lnk
Found ! E:\Vila Údolní.lnk
Found ! E:\Vypalování.lnk
Found ! E:\Vzory smluv.lnk
Found ! E:\zdárská.lnk
Found ! E:\SFBot_v2.0.1_win.lnk
Found ! E:\trans.lnk
Found ! E:\sfbot.lnk
Found ! E:\Foto.lnk
Found ! E:\Jura převod bytu.lnk
Found ! E:\SFBot_v2.1.0.lnk
Found ! E:\Nabídky.lnk
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1852271729.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2522797015.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\3319591313.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\4838392245.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7594820101.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8682132642.exe
Found ! C:\Documents and Settings\Administrator\S-100-4902-8593-5693
Found ! E:\syncguid.dat
Found ! E:\autorun.inf
Found ! C:\Documents and Settings\Administrator\Dokumenty\Downloads\IMG0540250-JPG (1).scr
Found ! C:\Documents and Settings\Administrator\Dokumenty\Downloads\IMG0540250-JPG.scr
Found ! C:\Documents and Settings\Administrator\S-100-4902-8593-5693\winmgr.exe

################## | Registry |

Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Microsoft Windows Manager

################## | Mountpoints2 |



################## | Vaccin |

(!) This computer is not vaccinated!

################## | E.O.F | http://sosvirus.org |

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 09 dub 2013 19:23
od SeaHorse
tak ještě čerstvý fix po odvirovávání, ale složky jsou stále ikonkami :/

############################## | UsbFix V 7.120 | [Research]

User: Administrator (Administrator) # HP14000226212
Updated 30/03/2013 by El Desaparecido
Started at 20:12:26 | 09/04/2013

Website: http://sosvirus.org/
Upload Malware: http://upload.sosvirus.org/
Contact: contact@sosvirus.org

PC: Hewlett-Packard (HP Compaq dc7600 Convertible Minitower) (X86-based PC)
CPU: Intel(R) Pentium(R) 4 CPU 3.00GHz (2990)
RAM -> [Total : 2551 | Free : 1656]
BIOS: Default System BIOS
BOOT: Normal boot

OS: Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 149 Gb (104 Mb free - 70%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Removable drive # 14 Gb (7 Mb free - 48%) [KINGSTON] # FAT32
G:\ -> CD-ROM

################## | Active Processes |

C:\WINDOWS\System32\smss.exe (644)
C:\WINDOWS\system32\winlogon.exe (788)
C:\WINDOWS\system32\services.exe (832)
C:\WINDOWS\system32\lsass.exe (844)
C:\WINDOWS\system32\svchost.exe (1032)
C:\WINDOWS\System32\svchost.exe (1196)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1416)
C:\WINDOWS\Explorer.EXE (1708)
C:\WINDOWS\system32\spoolsv.exe (1752)
C:\WINDOWS\system32\igfxtray.exe (1224)
C:\WINDOWS\system32\hkcmd.exe (1256)
C:\WINDOWS\system32\igfxpers.exe (1288)
C:\Program Files\Java\jre7\bin\jqs.exe (1440)
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (1876)
C:\WINDOWS\system32\svchost.exe (1448)
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (1052)
C:\WINDOWS\RTHDCPL.EXE (1788)
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE (1676)
C:\Program Files\AVAST Software\Avast\avastUI.exe (2240)
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2320)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (2480)
C:\program files\real\realplayer\update\realsched.exe (2536)
C:\WINDOWS\system32\ctfmon.exe (2544)
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2840)
C:\Program Files\TeamViewer\Version8\TeamViewer.exe (3444)
C:\WINDOWS\system32\wbem\wmiapsrv.exe (3640)
C:\Program Files\TeamViewer\Version8\tv_w32.exe (2212)
C:\Program Files\System Explorer\SystemExplorer.exe (3956)
C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (3532)
C:\Program Files\Common Files\Sonic Shared\CineTray.exe (560)
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (3668)
C:\Program Files\System Explorer\service\SystemExplorerService.exe (2664)
C:\Program Files\Mozilla Firefox\firefox.exe (1600)
C:\Program Files\Mozilla Firefox\plugin-container.exe (3568)
C:\Program Files\Skype\Phone\Skype.exe (3904)
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe (3672)
C:\WINDOWS\system32\mmc.exe (2296)
C:\WINDOWS\system32\dmremote.exe (2400)
C:\WINDOWS\System32\dmadmin.exe (2412)
C:\WINDOWS\system32\NOTEPAD.EXE (3832)
C:\UsbFix\Go.exe (2908)

################## | El Desaparecido Section |

HKLM\SOFTWARE | Run : [IgfxTray] - C:\WINDOWS\system32\igfxtray.exe
HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe
HKLM\SOFTWARE | Run : [Persistence] - C:\WINDOWS\system32\igfxpers.exe
HKLM\SOFTWARE | Run : [Zástupce stránky vlastností sběrnice High Definition Audio] - HDAShCut.exe
HKLM\SOFTWARE | Run : [RTHDCPL] - RTHDCPL.EXE
HKLM\SOFTWARE | Run : [PTHOSTTR] - C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
HKLM\SOFTWARE | Run : [SetRefresh] - C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
HKLM\SOFTWARE | Run : [LayoutM] - KLayMgr.exe
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [TkBellExe] - "C:\program files\real\realplayer\update\realsched.exe" -osboot
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE
HKU\S-1-5-20\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [DAEMON Tools Lite] - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [SystemExplorerAutoStart] - "C:\Program Files\System Explorer\SystemExplorer.exe" /TRAY
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-18\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE

################## | Files # Infected Folders |

Found ! E:\LOST.DIR.lnk
Found ! E:\.android_secure.lnk
Found ! E:\CD01.lnk
Found ! E:\GE.lnk
Found ! E:\Plynostav.lnk
Found ! E:\SCANER.lnk
Found ! E:\avast.lnk
Found ! E:\bydlení.lnk
Found ! E:\cizi.lnk
Found ! E:\daně2006.lnk
Found ! E:\daně2007.lnk
Found ! E:\daně2008.lnk
Found ! E:\daně2009.lnk
Found ! E:\daně2010.lnk
Found ! E:\dovolená.lnk
Found ! E:\DVD.lnk
Found ! E:\Emise.lnk
Found ! E:\FAQuickMenu.lnk
Found ! E:\freehry.lnk
Found ! E:\garáž.lnk
Found ! E:\Golf.lnk
Found ! E:\iso.lnk
Found ! E:\kancelář.lnk
Found ! E:\knihy.lnk
Found ! E:\kontrola.lnk
Found ! E:\Moje !.lnk
Found ! E:\mt lep.lnk
Found ! E:\nemovitost.lnk
Found ! E:\Normy.lnk
Found ! E:\ofice.lnk
Found ! E:\PC.lnk
Found ! E:\plechy Vestas.lnk
Found ! E:\pokuta.lnk
Found ! E:\Polachová.lnk
Found ! E:\pracovní smlouvy.lnk
Found ! E:\pruhy.lnk
Found ! E:\rodokmen.lnk
Found ! E:\rumunština.lnk
Found ! E:\sex.lnk
Found ! E:\seznam.lnk
Found ! E:\Stehlík.lnk
Found ! E:\Truecrypt.lnk
Found ! E:\Vila Údolní.lnk
Found ! E:\Vypalování.lnk
Found ! E:\Vzory smluv.lnk
Found ! E:\SFBot_v2.0.1_win.lnk
Found ! E:\trans.lnk
Found ! E:\sfbot.lnk
Found ! E:\Foto.lnk
Found ! E:\Jura převod bytu.lnk
Found ! E:\SFBot_v2.1.0.lnk
Found ! E:\Nabídky.lnk
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1852271729.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\4465344342.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\4838392245.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7594820101.exe
Found ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8682132642.exe
Found ! C:\Documents and Settings\Administrator\S-100-4902-8593-5693
Found ! E:\syncguid.dat
Found ! E:\autorun.inf

################## | Registry |

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 09 dub 2013 19:33
od cernohous13
Zdravím,

Spusť znovu USB Fix a klikni na Deletion
Po dokončení sem vlož log, pokud se sám neotevře, najdeš jej zde C:\UsbFix.txt

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 09 dub 2013 19:39
od SeaHorse
tak ještě ten log

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2013-04-09 20:25:35
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 106 GB (70%) free of 153 GB
Total RAM: 2551 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:25:46, on 9.4.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\program files\real\realplayer\update\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
C:\Program Files\System Explorer\SystemExplorer.exe
C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
C:\Program Files\Common Files\Sonic Shared\CineTray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\System Explorer\service\SystemExplorerService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\dmremote.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.avast.com/cs-cz/eula
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Zástupce stránky vlastností sběrnice High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [LayoutM] KLayMgr.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SystemExplorerAutoStart] "C:\Program Files\System Explorer\SystemExplorer.exe" /TRAY
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: System Explorer Service (SystemExplorerHelpService) - Mister Group - C:\Program Files\System Explorer\service\SystemExplorerService.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe

--
End of file - 11070 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-60421067-2947026938-3549707754-500.job
C:\WINDOWS\tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-60421067-2947026938-3549707754-500.job
C:\WINDOWS\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-60421067-2947026938-3549707754-500.job
C:\WINDOWS\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-60421067-2947026938-3549707754-500.job
C:\WINDOWS\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-60421067-2947026938-3549707754-500.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-60421067-2947026938-3549707754-500.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-60421067-2947026938-3549707754-500.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default

prefs.js - "browser.startup.homepage" - "http://www.google.com/firefox"
prefs.js - "keyword.URL" - "http://www.google.com/search?ie=UTF-8&oe=utf-8&q="

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{DAC3F861-B30D-40dd-9166-F4E75327FAC7}"=C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@mcafee.com/McAfeeMssPlugin]
"Description"=McAfee Mss Plugin
"Path"=C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files\real\realplayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1]
"Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1]
"Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1]
"Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files\real\realplayer\Netscape6\nprpplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]
"Description"=RealDownloader Plugin
"Path"=C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default\searchplugins\
askcom.xml
askcomsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll [2013-02-05 94112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-03-06 540328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-05 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-07 1224568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-15 192144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-01-31 4528760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll [2013-01-15 1000984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-05 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-07 1224568]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-15 192144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2005-04-05 94208]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-04-05 77824]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2005-04-05 114688]
"Zástupce stránky vlastností sběrnice High Definition Audio"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-03-08 13924864]
"PTHOSTTR"=C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE [2005-10-04 86016]
"SetRefresh"=C:\Program Files\Compaq\SetRefresh\SetRefresh.exe [2003-11-20 525824]
"LayoutM"=C:\WINDOWS\KLayMgr.exe [2004-08-16 45056]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-03-07 4767304]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"TkBellExe"=C:\program files\real\realplayer\update\realsched.exe [2013-04-09 295512]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2012-01-29 39408]
"SystemExplorerAutoStart"=C:\Program Files\System Explorer\SystemExplorer.exe [2012-12-02 2846168]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-02-28 18643048]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
Sonic CinePlayer Quick Launch.lnk - C:\Program Files\Common Files\Sonic Shared\CineTray.exe

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-04-05 131072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\EasySetupAssistant\wr741n\EasySetupAssistant.exe"="D:\EasySetupAssistant\wr741n\EasySetupAssistant.exe:*:Enabled:TP-LINK Easy Setup Assistant"
"C:\Program Files\TeamViewer\Version8\TeamViewer.exe"="C:\Program Files\TeamViewer\Version8\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\Documents and Settings\Administrator\S-100-4902-8593-5693\winmgr.exe"="C:\Documents and Settings\Administrator\S-100-4902-8593-5693\winmgr.exe:*:Enabled:Microsoft Windows Manager"
"C:\Documents and Settings\Administrator\S-500-9430-5849-2045\winmgr.exe"="C:\Documents and Settings\Administrator\S-500-9430-5849-2045\winmgr.exe:*:Enabled:Microsoft Windows Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======List of files/folders created in the last 1 month======

2013-04-09 20:25:35 ----D---- C:\rsit
2013-04-09 20:25:35 ----D---- C:\Program Files\trend micro
2013-04-09 20:12:26 ----A---- C:\UsbFix [Scan 2] HP14000226212.txt
2013-04-09 14:07:28 ----D---- C:\Program Files\Common Files\Skype
2013-04-09 14:07:26 ----RD---- C:\Program Files\Skype
2013-04-09 09:07:34 ----D---- C:\Documents and Settings\Administrator\Data aplikací\RealNetworks
2013-04-09 09:06:53 ----D---- C:\Program Files\RealNetworks
2013-04-09 09:06:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\RealNetworks
2013-04-09 09:05:52 ----D---- C:\Program Files\Common Files\xing shared
2013-04-09 08:45:23 ----D---- C:\WINDOWS\system32\appmgmt
2013-04-08 16:17:46 ----A---- C:\UsbFix [Scan 1] HP14000226212.txt
2013-04-08 16:16:27 ----D---- C:\UsbFix
2013-04-04 17:50:31 ----RASH---- C:\MSDOS.SYS
2013-04-04 17:50:31 ----RASH---- C:\IO.SYS
2013-04-04 17:07:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\SystemExplorer
2013-04-04 17:07:05 ----D---- C:\Program Files\System Explorer
2013-04-04 16:21:34 ----AH---- C:\Documents and Settings\Administrator\Data aplikací\winsvcns.sys
2013-04-03 09:33:03 ----D---- C:\Program Files\Mozilla Firefox
2013-03-28 12:37:27 ----D---- C:\WINDOWS\Minidump
2013-03-19 16:27:38 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2013-03-19 16:27:38 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2013-03-19 16:27:38 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2013-03-13 19:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2013-03-11 10:26:00 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$

======List of files/folders modified in the last 1 month======

2013-04-09 20:25:41 ----D---- C:\WINDOWS\Prefetch
2013-04-09 20:25:35 ----RD---- C:\Program Files
2013-04-09 20:17:21 ----D---- C:\WINDOWS\Temp
2013-04-09 20:07:39 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2013-04-09 14:08:12 ----SHD---- C:\WINDOWS\Installer
2013-04-09 14:07:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2013-04-09 14:07:28 ----D---- C:\Program Files\Common Files
2013-04-09 12:39:53 ----SD---- C:\WINDOWS\Tasks
2013-04-09 10:32:26 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-04-09 09:05:58 ----D---- C:\Program Files\Real
2013-04-09 09:05:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2013-04-09 09:05:36 ----D---- C:\WINDOWS\system32
2013-04-09 09:05:36 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2013-04-09 09:05:08 ----A---- C:\WINDOWS\system32\pndx5032.dll
2013-04-09 09:05:08 ----A---- C:\WINDOWS\system32\pndx5016.dll
2013-04-09 09:05:03 ----A---- C:\WINDOWS\system32\pncrt.dll
2013-04-09 09:04:57 ----D---- C:\WINDOWS\WinSxS
2013-04-09 09:04:03 ----A---- C:\WINDOWS\system32\msvcr71.dll
2013-04-09 09:04:03 ----A---- C:\WINDOWS\system32\msvcp71.dll
2013-04-08 07:06:56 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-28 12:37:27 ----D---- C:\WINDOWS
2013-03-27 07:46:40 ----D---- C:\Program Files\Google
2013-03-26 20:27:27 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2013-03-19 16:27:38 ----D---- C:\WINDOWS\system32\drivers
2013-03-13 19:10:08 ----HD---- C:\WINDOWS\inf
2013-03-13 19:10:04 ----RSHD---- C:\WINDOWS\system32\dllcache
2013-03-13 19:09:35 ----HD---- C:\WINDOWS\$hf_mig$
2013-03-13 19:09:34 ----D---- C:\WINDOWS\system32\CatRoot2
2013-03-13 13:36:15 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-03-13 04:02:25 ----A---- C:\WINDOWS\system32\MRT.exe
2013-03-13 04:02:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-03-13 04:01:23 ----A---- C:\WINDOWS\imsins.BAK
2013-03-13 04:01:12 ----D---- C:\Program Files\Internet Explorer
2013-03-13 04:00:56 ----D---- C:\WINDOWS\ie8updates
2013-03-11 11:38:29 ----D---- C:\WINDOWS\Microsoft.NET
2013-03-11 11:37:53 ----RSD---- C:\WINDOWS\assembly
2013-03-11 10:42:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-03-11 10:32:32 ----D---- C:\WINDOWS\system32\XPSViewer
2013-03-11 10:27:23 ----D---- C:\WINDOWS\system32\CatRoot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2013-03-07 49248]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-04-25 20640]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2012-10-31 20624]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2013-03-07 49760]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2013-03-07 765736]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2013-03-07 368176]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2013-03-07 62376]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-12-29 239168]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2013-03-07 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2005-04-08 132352]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-04-05 830684]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-03-05 2538624]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S1 P3;Ovladač procesoru Intel PentiumIII; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-14 46592]
S3 AR9271;Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athuw.sys [2009-08-14 1668352]
S3 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2013-03-07 164736]
S3 Blfp;Broadcom Advanced Server Program Driver; C:\WINDOWS\system32\DRIVERS\baspxp32.sys [2005-03-04 65664]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-10-24 117760]
S3 HdAudAddService;Ovladač funkcí Microsoft UAA pro služby sběrnice High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 i81x;i81x; C:\WINDOWS\system32\DRIVERS\i81xnt5.sys [2004-08-04 161020]
S3 iAimFP0;iAimFP0; C:\WINDOWS\system32\DRIVERS\wADV01nt.sys [2004-08-04 12415]
S3 iAimFP1;iAimFP1; C:\WINDOWS\system32\DRIVERS\wADV02NT.sys [2004-08-04 12127]
S3 iAimFP2;iAimFP2; C:\WINDOWS\system32\DRIVERS\wADV05NT.sys [2004-08-04 11775]
S3 iAimFP3;iAimFP3; C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys [2004-08-04 12063]
S3 iAimFP4;iAimFP4; C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys [2004-08-04 19455]
S3 iAimFP5;iAimFP5; C:\WINDOWS\system32\DRIVERS\wADV07nt.sys [2004-08-04 11807]
S3 iAimFP6;iAimFP6; C:\WINDOWS\system32\DRIVERS\wADV08nt.sys [2004-08-04 11295]
S3 iAimFP7;iAimFP7; C:\WINDOWS\system32\DRIVERS\wADV09nt.sys [2004-08-04 11871]
S3 iAimTV0;iAimTV0; C:\WINDOWS\system32\DRIVERS\wATV01nt.sys [2004-08-04 29311]
S3 iAimTV1;iAimTV1; C:\WINDOWS\system32\DRIVERS\wATV02NT.sys [2004-08-04 19551]
S3 iAimTV3;iAimTV3; C:\WINDOWS\system32\DRIVERS\wATV04nt.sys [2004-08-04 33599]
S3 iAimTV4;iAimTV4; C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys [2004-08-04 23615]
S3 iAimTV5;iAimTV5; C:\WINDOWS\system32\DRIVERS\wATV10nt.sys [2004-08-04 25471]
S3 iAimTV6;iAimTV6; C:\WINDOWS\system32\DRIVERS\wATV06nt.sys [2004-08-04 22271]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 adpu320;adpu320; C:\WINDOWS\system32\DRIVERS\adpu320.sys [2002-05-09 105472]
S4 Symmpi;Symmpi; C:\WINDOWS\system32\DRIVERS\symmpi.sys [2002-04-04 28416]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-03-07 45248]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-03-05 170912]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-03-06 39056]
R2 Skype C2C Service;Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-01-31 3289208]
R2 TeamViewer8;TeamViewer 8; C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe [2013-03-06 3560288]
R3 SystemExplorerHelpService;System Explorer Service; C:\Program Files\System Explorer\service\SystemExplorerService.exe [2012-11-25 567256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-29 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-02-28 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-13 253656]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-29 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-20 194032]
S3 hpqwmi;HP WMI Interface; C:\Program Files\HPQ\Shared\hpqwmi.exe [2005-10-04 94208]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-04-03 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 09 dub 2013 19:49
od SeaHorse
Tak tady je ten log po tom delete....Zdá se, že je Flashka zdravá, jsi génius ;-)

############################## | UsbFix V 7.120 | [Deletion]

User: Administrator (Administrator) # HP14000226212
Updated 30/03/2013 by El Desaparecido
Started at 20:42:04 | 09/04/2013

Website: http://sosvirus.org/
Upload Malware: http://upload.sosvirus.org/
Contact: contact@sosvirus.org

PC: Hewlett-Packard (HP Compaq dc7600 Convertible Minitower) (X86-based PC)
CPU: Intel(R) Pentium(R) 4 CPU 3.00GHz (2990)
RAM -> [Total : 2551 | Free : 1698]
BIOS: Default System BIOS
BOOT: Normal boot

OS: Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 149 Gb (104 Mb free - 70%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Removable drive # 14 Gb (7 Mb free - 48%) [KINGSTON] # FAT32
G:\ -> CD-ROM

################## | El Desaparecido Section |

HKLM\SOFTWARE | Run : [IgfxTray] - C:\WINDOWS\system32\igfxtray.exe
HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe
HKLM\SOFTWARE | Run : [Persistence] - C:\WINDOWS\system32\igfxpers.exe
HKLM\SOFTWARE | Run : [Zástupce stránky vlastností sběrnice High Definition Audio] - HDAShCut.exe
HKLM\SOFTWARE | Run : [RTHDCPL] - RTHDCPL.EXE
HKLM\SOFTWARE | Run : [PTHOSTTR] - C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
HKLM\SOFTWARE | Run : [SetRefresh] - C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
HKLM\SOFTWARE | Run : [LayoutM] - KLayMgr.exe
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [TkBellExe] - "C:\program files\real\realplayer\update\realsched.exe" -osboot
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE
HKU\S-1-5-20\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [DAEMON Tools Lite] - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [SystemExplorerAutoStart] - "C:\Program Files\System Explorer\SystemExplorer.exe" /TRAY
HKU\S-1-5-21-60421067-2947026938-3549707754-500\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-18\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\CTFMON.EXE

################## | Stopped processes |

Stopped! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1416)
Stopped! C:\WINDOWS\Explorer.EXE (1708)
Stopped! C:\WINDOWS\system32\spoolsv.exe (1752)
Stopped! C:\WINDOWS\system32\igfxtray.exe (1224)
Stopped! C:\WINDOWS\system32\hkcmd.exe (1256)
Stopped! C:\WINDOWS\system32\igfxpers.exe (1288)
Stopped! C:\Program Files\Java\jre7\bin\jqs.exe (1440)
Stopped! C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (1876)
Stopped! C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe (1052)
Stopped! C:\WINDOWS\RTHDCPL.EXE (1788)
Stopped! C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE (1676)
Stopped! C:\Program Files\AVAST Software\Avast\avastUI.exe (2240)
Stopped! C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2320)
Stopped! C:\Program Files\Common Files\Java\Java Update\jusched.exe (2480)
Stopped! C:\program files\real\realplayer\update\realsched.exe (2536)
Stopped! C:\WINDOWS\system32\ctfmon.exe (2544)
Stopped! C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2840)
Stopped! C:\Program Files\TeamViewer\Version8\TeamViewer.exe (3444)
Stopped! C:\WINDOWS\system32\wbem\wmiapsrv.exe (3640)
Stopped! C:\Program Files\TeamViewer\Version8\tv_w32.exe (2212)
Stopped! C:\Program Files\System Explorer\SystemExplorer.exe (3956)
Stopped! C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (3532)
Stopped! C:\Program Files\Common Files\Sonic Shared\CineTray.exe (560)
Stopped! C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (3668)
Stopped! C:\Program Files\System Explorer\service\SystemExplorerService.exe (2664)
Stopped! C:\Program Files\Mozilla Firefox\firefox.exe (1600)
Stopped! C:\Program Files\Mozilla Firefox\plugin-container.exe (3568)
Stopped! C:\Program Files\Skype\Phone\Skype.exe (3904)
Stopped! C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe (3672)
Stopped! C:\WINDOWS\system32\mmc.exe (2296)
Stopped! C:\WINDOWS\system32\dmremote.exe (2400)
Stopped! C:\WINDOWS\System32\dmadmin.exe (2412)

################## | Files # Infected Folders |

Deleted ! E:\LOST.DIR.lnk
Deleted ! E:\.android_secure.lnk
Deleted ! E:\CD01.lnk
Deleted ! E:\GE.lnk
Deleted ! E:\Plynostav.lnk
Deleted ! E:\SCANER.lnk
Deleted ! E:\avast.lnk
Deleted ! E:\bydlení.lnk
Deleted ! E:\cizi.lnk
Deleted ! E:\daně2006.lnk
Deleted ! E:\daně2007.lnk
Deleted ! E:\daně2008.lnk
Deleted ! E:\daně2009.lnk
Deleted ! E:\daně2010.lnk
Deleted ! E:\dovolená.lnk
Deleted ! E:\DVD.lnk
Deleted ! E:\Emise.lnk
Deleted ! E:\FAQuickMenu.lnk
Deleted ! E:\freehry.lnk
Deleted ! E:\garáž.lnk
Deleted ! E:\Golf.lnk
Deleted ! E:\iso.lnk
Deleted ! E:\kancelář.lnk
Deleted ! E:\knihy.lnk
Deleted ! E:\kontrola.lnk
Deleted ! E:\Moje !.lnk
Deleted ! E:\mt lep.lnk
Deleted ! E:\nemovitost.lnk
Deleted ! E:\Normy.lnk
Deleted ! E:\ofice.lnk
Deleted ! E:\PC.lnk
Deleted ! E:\plechy Vestas.lnk
Deleted ! E:\pokuta.lnk
Deleted ! E:\Polachová.lnk
Deleted ! E:\pracovní smlouvy.lnk
Deleted ! E:\pruhy.lnk
Deleted ! E:\rodokmen.lnk
Deleted ! E:\rumunština.lnk
Deleted ! E:\sex.lnk
Deleted ! E:\seznam.lnk
Deleted ! E:\Stehlík.lnk
Deleted ! E:\Truecrypt.lnk
Deleted ! E:\Vila Údolní.lnk
Deleted ! E:\Vypalování.lnk
Deleted ! E:\Vzory smluv.lnk
Deleted ! E:\SFBot_v2.0.1_win.lnk
Deleted ! E:\trans.lnk
Deleted ! E:\sfbot.lnk
Deleted ! E:\Foto.lnk
Deleted ! E:\Jura převod bytu.lnk
Deleted ! E:\SFBot_v2.1.0.lnk
Deleted ! E:\Nabídky.lnk
Deleted ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1852271729.exe
Deleted ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\4465344342.exe
Deleted ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\4838392245.exe
Deleted ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7594820101.exe
Deleted ! C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8682132642.exe
Deleted ! C:\Documents and Settings\Administrator\S-100-4902-8593-5693
Deleted ! E:\syncguid.dat
Deleted ! E:\autorun.inf

(!) Temporary files deleted.

################## | Registry |


################## | Mountpoints2 |


################## | Listing |

[06/03/2013 - 12:11:38 | D ] C:\07d12e339930ef7818e88df3a586f4a9
[04/03/2013 - 15:36:50 | D ] C:\Autodesk
[26/12/2011 - 20:49:13 | N | 211] C:\boot.ini
[18/08/2004 - 04:00:00 | N | 4952] C:\Bootfont.bin
[27/06/2012 - 11:11:21 | D ] C:\Casino
[26/12/2011 - 20:38:17 | D ] C:\Compaq
[26/12/2011 - 20:38:35 | D ] C:\Cpqapps
[27/12/2011 - 05:24:57 | D ] C:\Documents and Settings
[09/04/2013 - 10:33:13 | ASH | 2675359744] C:\hiberfil.sys
[27/12/2011 - 05:26:35 | D ] C:\i386
[26/12/2011 - 20:50:23 | D ] C:\Intel
[04/04/2013 - 17:50:31 | N | 0] C:\IO.SYS
[04/04/2013 - 17:50:31 | N | 0] C:\MSDOS.SYS
[29/12/2011 - 10:16:45 | RHD ] C:\MSOCache
[18/08/2004 - 04:00:00 | N | 47564] C:\NTDETECT.COM
[29/01/2012 - 16:25:39 | N | 250576] C:\ntldr
[12/12/2012 - 15:57:26 | N | 458317334] C:\ovzdusi.zip
[09/04/2013 - 12:38:37 | ASH | 792723456] C:\pagefile.sys
[09/04/2013 - 20:25:35 | D ] C:\Program Files
[29/12/2011 - 10:28:01 | SHD ] C:\RECYCLER
[09/04/2013 - 20:25:52 | D ] C:\rsit
[26/12/2011 - 20:49:29 | SHD ] C:\System Volume Information
[26/12/2011 - 20:49:19 | D ] C:\SYSTEM.SAV
[12/09/2012 - 13:13:06 | D ] C:\totalcmd
[09/04/2013 - 20:43:54 | D ] C:\UsbFix
[09/04/2013 - 20:44:21 | A | 8410] C:\UsbFix [Clean 1] HP14000226212.txt
[08/04/2013 - 16:21:33 | N | 8005] C:\UsbFix [Scan 1] HP14000226212.txt
[09/04/2013 - 20:16:20 | N | 7190] C:\UsbFix [Scan 2] HP14000226212.txt
[28/03/2013 - 12:37:27 | D ] C:\WINDOWS
[18/12/2011 - 21:05:00 | D ] E:\LOST.DIR
[18/12/2011 - 21:05:00 | D ] E:\.android_secure
[23/05/2011 - 18:37:42 | D ] E:\CD01
[25/05/2011 - 12:41:28 | N | 34932712] E:\eset-nod-32-antivirus-4-nekonecna-license.rar
[18/09/2009 - 16:06:44 | N | 35515904] E:\eavbe_nt32_rus.msi
[23/09/2009 - 18:25:48 | N | 136] E:\Keys.txt
[25/05/2011 - 16:51:48 | N | 35328] E:\super-vydelek-na-pc-ktery-opavdu-funguje-2010-2011-cz-novinky-avi-mp3-pc-cz.doc
[01/06/2011 - 19:03:06 | D ] E:\GE
[01/06/2011 - 23:05:10 | N | 806797] E:\T_240_120-2_Sancolor_odtrh Stepcuponu.pdf
[02/06/2011 - 17:46:20 | D ] E:\Plynostav
[03/06/2011 - 09:35:16 | D ] E:\SCANER
[03/06/2011 - 13:26:00 | N | 548268] E:\bruderPotter ruka.jpg
[03/06/2011 - 19:33:18 | N | 126976] E:\Repower - Checklist-Audit-Corrosion Protection_ steel parts (en) Vers B (CJ).xls
[03/06/2011 - 21:08:36 | D ] E:\avast
[03/06/2011 - 21:09:22 | D ] E:\Barvy
[03/06/2011 - 21:09:22 | D ] E:\bydlení
[03/06/2011 - 21:09:24 | D ] E:\cizi
[03/06/2011 - 21:09:24 | D ] E:\daně2006
[03/06/2011 - 21:09:32 | D ] E:\daně2007
[03/06/2011 - 21:09:34 | D ] E:\daně2008
[03/06/2011 - 21:09:40 | D ] E:\daně2009
[03/06/2011 - 21:09:46 | D ] E:\daně2010
[03/06/2011 - 21:09:46 | D ] E:\dovolená
[03/06/2011 - 21:11:22 | D ] E:\DVD
[03/06/2011 - 21:11:50 | D ] E:\Emise
[03/06/2011 - 21:22:28 | D ] E:\FAQuickMenu
[03/06/2011 - 21:22:40 | D ] E:\FOUND.000
[03/06/2011 - 21:22:40 | D ] E:\freehry
[03/06/2011 - 21:24:18 | D ] E:\garáž
[03/06/2011 - 21:24:18 | D ] E:\Golf
[03/06/2011 - 21:24:20 | D ] E:\iso
[03/06/2011 - 21:24:20 | D ] E:\kancelář
[18/12/2011 - 21:20:56 | D ] E:\knihy
[03/06/2011 - 21:24:56 | D ] E:\kontrola
[03/06/2011 - 21:25:32 | D ] E:\Moje !
[03/06/2011 - 21:44:36 | D ] E:\mt lep
[03/06/2011 - 21:48:52 | D ] E:\nemovitost
[03/06/2011 - 21:48:52 | D ] E:\Normy
[03/06/2011 - 21:48:52 | D ] E:\ofice
[03/06/2011 - 21:50:08 | D ] E:\PC
[03/06/2011 - 21:50:14 | D ] E:\plechy Vestas
[03/06/2011 - 21:50:32 | D ] E:\pokuta
[03/06/2011 - 21:50:40 | D ] E:\Polachová
[03/06/2011 - 21:50:40 | D ] E:\pracovní smlouvy
[03/06/2011 - 21:50:58 | D ] E:\pruhy
[03/06/2011 - 21:50:58 | D ] E:\rodokmen
[03/06/2011 - 21:51:12 | D ] E:\rumunština
[03/06/2011 - 21:51:12 | D ] E:\sex
[03/06/2011 - 21:51:12 | D ] E:\seznam
[03/06/2011 - 21:51:36 | D ] E:\Stehlík
[03/06/2011 - 21:51:38 | D ] E:\Truecrypt
[03/06/2011 - 21:51:40 | D ] E:\Vila Údolní
[03/06/2011 - 21:51:44 | D ] E:\Vypalování
[03/06/2011 - 21:52:56 | D ] E:\Vzory smluv
[03/06/2011 - 21:53:00 | D ] E:\zdárská
[18/11/2010 - 12:55:56 | N | 96768] E:\20101105_Kalkulation_Plan_2011_Stundensätze V5_Varde.xls
[07/01/2006 - 23:03:16 | N | 8966144] E:\81.98_forceware_winxp2k_international_whql.exe
[25/01/2007 - 18:31:26 | N | 28672] E:\Bilance spotřeb 2006.xls
[20/09/2008 - 00:53:50 | N | 13041690] E:\bioshock.czech.language.rip-c3rny-2-.rar
[08/07/2010 - 06:30:30 | N | 2776] E:\BOOTEX.LOG
[19/03/2010 - 13:35:00 | N | 87] E:\C_03_10
[28/05/2009 - 10:38:34 | N | 40646] E:\deník bozp.jpg
[24/06/2009 - 17:31:54 | N | 76800] E:\dodací list Léman.doc
[13/01/2010 - 09:27:50 | N | 1264264] E:\Exacom, otevřené plechovky.docx
[12/01/2011 - 14:51:56 | N | 196142] E:\Faktura_vydana_MARTIN_KURAS.PDF
[19/12/2009 - 18:11:22 | N | 31794284] E:\FreeStudio4.2.4.71.exe
[26/07/2005 - 03:59:12 | N | 3180269] E:\getright50beta4.exe
[04/02/2008 - 21:27:06 | N | 22528] E:\Kontrola Vestas.doc
[24/03/2005 - 11:32:28 | N | 186368] E:\Kopie - priznani_FO_B_2005_1.xls
[14/01/2010 - 17:49:46 | N | 790967] E:\koroze.pdf
[29/10/2009 - 11:34:50 | N | 509076] E:\krasa_lastur.jpg
[20/08/2008 - 10:19:44 | N | 118272] E:\Logo Chrudim Sancolor.doc
[23/11/2006 - 09:43:32 | N | 66048] E:\logo.doc
[12/07/2007 - 19:23:46 | N | 19456] E:\Madarsko bilance.xls
[13/02/2007 - 18:28:32 | N | 42050] E:\maska Nabidka Sancolor_rev.pdf
[10/01/2005 - 21:37:54 | N | 1367014] E:\MIDIs.zip
[25/10/2009 - 20:04:06 | N | 10258] E:\nastříkané m2 a orientační spotřeba 2009.xlsx
[08/02/2007 - 21:51:20 | N | 6809] E:\nítěnky.jpg
[18/11/2007 - 12:49:58 | N | 75776] E:\objednávka broků comprex.doc
[18/11/2007 - 12:49:40 | N | 75776] E:\objednávka broků.doc
[01/10/2010 - 08:51:30 | N | 79360] E:\objednávka dopravníkových pásů.doc
[19/01/2006 - 17:02:02 | N | 21504] E:\objednávka EKPS s.doc
[13/08/2010 - 11:08:48 | N | 75264] E:\objednávka opravy stříkacího zařízení.doc
[22/12/2005 - 00:00:18 | N | 75776] E:\objednávka pryskyřice.doc
[07/05/2009 - 09:50:28 | N | 79360] E:\objednávka tryskacích hadic052009.doc
[18/12/2008 - 12:43:30 | N | 78848] E:\objednávka tryskacích hadic122008.doc
[31/07/2009 - 10:32:12 | N | 77824] E:\potvrzení pro PÚ.doc
[07/08/2007 - 11:48:56 | N | 23040] E:\Pracovnici SRN.doc
[29/06/2005 - 05:28:42 | N | 19968] E:\Pracovníci fy KH Stav byli řádně poučeni a proškoleni o podmínkách provozu.doc
[08/11/2009 - 18:38:08 | N | 33212] E:\prasečí chřipka.docx
[22/01/2009 - 16:00:14 | N | 28160] E:\Prihlaska na kurz Sachs.doc
[07/08/2007 - 12:23:02 | N | 26624] E:\Prihlaska na kurz.doc
[06/03/2010 - 22:09:42 | N | 10654] E:\Prohlášení o úvěru Na jezírku.docx
[14/10/2010 - 11:13:32 | N | 77824] E:\předání kanceláří.doc
[17/10/2007 - 18:29:54 | N | 77824] E:\seznam nářadí vydaného do tryskače.doc
[01/05/2011 - 23:09:58 | N | 8291518] E:\SFBot_v2.0.1_win.zip
[12/05/2010 - 06:53:20 | N | 24576] E:\smenka.doc
[07/11/2007 - 00:40:42 | N | 13824] E:\spotřeby vestas 105 m Vlčková.xls
[06/08/2007 - 10:43:30 | N | 10240] E:\tabulka pro výpočet mzdy.xls
[22/02/2006 - 18:42:54 | N | 4942336] E:\UFD3in1.exe
[10/08/2005 - 10:30:42 | N | 49152] E:\Vseobecne podminky.doc
[08/12/2005 - 22:21:54 | N | 246044] E:\Výroba CR 064.jpg
[08/12/2005 - 22:21:52 | N | 254207] E:\Výroba CR 065.jpg
[23/12/2005 - 09:09:52 | N | 868073] E:\Výroba CR 066.jpg
[23/12/2005 - 09:09:54 | N | 881090] E:\Výroba CR 067.jpg
[07/08/2008 - 13:11:48 | N | 322523176] E:\WindowsXP-KB936929-SP3-x86-CSY.exe
[07/07/2010 - 12:27:06 | N | 141095] E:\účet za notebook.JPG
[14/01/2011 - 17:31:40 | N | 513475] E:\účet.jpg
[14/01/2011 - 17:55:36 | N | 149430] E:\účet1.jpg
[06/11/2009 - 21:36:04 | N | 698196] E:\winmail-reader-setup.exe
[14/03/2008 - 11:40:10 | N | 16757793] E:\World_Wind_1.4.0_Full.exe
[04/03/2008 - 22:15:18 | N | 8205838] E:\ytgrabber.exe
[21/01/2009 - 12:01:18 | N | 27099] E:\zaznam-o-dopravni-nehode.pdf
[11/06/2011 - 23:58:54 | D ] E:\SFBot_v2.0.1_win
[25/07/2011 - 16:41:26 | N | 43520] E:\Kopie - KZP WKT GE Energy 25 07 11(1).xls
[04/08/2011 - 15:38:10 | N | 8393419] E:\SFBot_v2.1.0.zip
[21/03/2011 - 22:19:18 | D ] E:\trans
[09/08/2011 - 23:49:42 | D ] E:\sfbot
[21/11/2011 - 20:00:48 | D ] E:\Foto
[25/01/2012 - 08:32:06 | D ] E:\Jura převod bytu
[09/12/2011 - 23:51:10 | N | 9165] E:\SeaHorse v důchodu.jpg
[10/12/2011 - 00:01:02 | N | 9237] E:\Seahorsekind.jpg
[09/12/2011 - 11:08:04 | N | 146972] E:\Doklad_2111754903.pdf
[29/01/2012 - 11:48:46 | D ] E:\SFBot_v2.1.0
[29/03/2012 - 20:26:44 | N | 10782] E:\Global asistance ford.docx
[12/04/2012 - 23:27:08 | N | 733155328] E:\Smrtonosna-jízda-Drive-Angry-Thriller-_-Akční,-USA,-2011--Nicolas-Cage.avi
[11/04/2012 - 17:16:30 | N | 782502108] E:\MÁLEM-HRDINOVÉ-super-komedie-FILM-OD-FILIPA-100%.avi
[11/04/2012 - 19:28:30 | N | 1681432576] E:\jeden-den-romanticka-komedie-2011-480p-cz-dten-ok.avi
[11/04/2012 - 15:13:34 | N | 735995904] E:\NESVATÝ-NOVINKY-super-komedie-FILM-OD-FILIPA-100%.avi
[03/06/2011 - 21:44:42 | D ] E:\Nabídky
[04/04/2013 - 18:51:12 | D ] E:\vir
[08/04/2013 - 07:36:48 | N | 24592] E:\03.28.xlsx

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | E.O.F | http://sosvirus.org |

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 10 dub 2013 04:22
od cernohous13
:arrow: USBFix -> Uninstall

:arrow: Klikni na https://www.virustotal.com
po kliknutí na "Choose File" jen zkopíruj do řádku "Název souboru":

C:\Program Files\System Explorer\SystemExplorer.exe

"Scan It" (pokud byl již testován, nech testovat znovu - Reanalyse)
Trpělivě vyčkej dokončení scanu dokud se neobjeví konečný výsledek např.0/41
Do fóra zkopíruj výsledný log. nebo odkaz z adresního řádku na stránku.
Pokud nebude nález stačí jen oznámit

:arrow: Stáhni AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Ulož nejlépe na plochu -> ukonči všechny programy -> spusť AdwCleaner -> klikni na Prohledat
Proběhne skenování a pak se objeví log, případně bude uložen na systémovém disku jako AdwCleaner[R?].txt, ten mi sem dej

:arrow: Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button (nelekej se přesměrování vyčkej)
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Kontrolor" -> Úplná kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 10 dub 2013 17:30
od SeaHorse
ha, tak jsem jásal, že je hotovo, ale asi o tom vím prdlajs jak to tady čtu. Snad to má maličkost zvládne jak píšeš. Ozvu se, zatím díky..

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 10 dub 2013 18:13
od SeaHorse
první výsledek 0/46

druhý

# AdwCleaner v2.200 - Log vytvooen 10/04/2013 v 19:11:44
# Aktualizováno 02/04/2013 Xplode
# Operaení systém : Microsoft Windows XP Service Pack 3 (32 bits)
# Uživatel : Administrator - HP14000226212
# Spuštin systém : Normální
# Spuštino z : C:\Documents and Settings\Administrator\Dokumenty\Downloads\adwcleaner.exe
# Volba [Prohledat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Nalezeno : C:\Documents and Settings\All Users\Data aplikací\Ask
Soubor Nalezeno : C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default\searchplugins\Askcom.xml
Soubor Nalezeno : C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default\searchplugins\askcomsearch.xml

***** [Registry] *****

Hodnota Nalezeno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry jsou eisté.

-\\ Mozilla Firefox v20.0 (cs)

Soubor : C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default\prefs.js

[OK] Soubor je eistý.

-\\ Google Chrome v26.0.1410.43

Soubor : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [1787 octets] - [10/04/2013 19:11:44]

########## EOF - C:\AdwCleaner[R1].txt - [1847 octets] ##########

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 10 dub 2013 19:45
od SeaHorse
Tak jsem to projel i tím MBAM a pár kousků to ještě našlo :

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.04.10.10

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: HP14000226212 [administrátor]

Ochrana: Povolena

10.4.2013 19:36:53
MBAM-log-2013-04-10 (20-44-14).txt

Typ: Kompletní kontrola (C:\|E:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 277081
Uplynulý čas: 1 hodin, 6 minut, 33 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 7
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NZ5Z1MC8\skp[1].exe (Trojan.VBKrypt) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\TCOC6VNR\IMG0540240-JPG[1].scr (Trojan.VBKrypt) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YNFFLEVX\spm[1].exe (Trojan.VBKrypt) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{37BE5458-E215-467E-83D7-4AF1AEC70570}\RP240\A0037611.exe (Trojan.VBKrypt) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{37BE5458-E215-467E-83D7-4AF1AEC70570}\RP240\A0037610.exe (Trojan.VBKrypt) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{37BE5458-E215-467E-83D7-4AF1AEC70570}\RP240\A0038201.exe (Trojan.VBKrypt) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Administrator\Data aplikací\winsvcns.sys (Malware.Trace) -> Nebyla provedena žádná instrukce.

(konec)

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 10 dub 2013 21:47
od cernohous13
:arrow: Spusť znovu AdwCleaner
Klikni na Vymazat
bude provedena oprava, restartuje se a vypadne log (C:\AdwCleaner [S?].txt) , jeho obsah vložíš sem

:arrow: Nález MBAM zkontroluj zda je vše označeno a nech odstranit

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 11 dub 2013 12:58
od SeaHorse
tak tady to je :

# AdwCleaner v2.200 - Log vytvooen 11/04/2013 v 13:49:30
# Aktualizováno 02/04/2013 Xplode
# Operaení systém : Microsoft Windows XP Service Pack 3 (32 bits)
# Uživatel : Administrator - HP14000226212
# Spuštin systém : Normální
# Spuštino z : C:\Documents and Settings\Administrator\Dokumenty\Downloads\adwcleaner.exe
# Volba [Vymazat]


***** [Služby] *****


***** [Soubory / Složky] *****

Složka Vymazáno : C:\Documents and Settings\All Users\Data aplikací\Ask
Soubor Vymazáno : C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default\searchplugins\Askcom.xml
Soubor Vymazáno : C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default\searchplugins\askcomsearch.xml

***** [Registry] *****

Hodnota Vymazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry jsou eisté.

-\\ Mozilla Firefox v20.0 (cs)

Soubor : C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\5k3nxtjn.default\prefs.js

[OK] Soubor je eistý.

-\\ Google Chrome v26.0.1410.64

Soubor : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Preferences

[OK] Soubor je eistý.

*************************

AdwCleaner[R1].txt - [1916 octets] - [10/04/2013 19:11:44]
AdwCleaner[R2].txt - [1976 octets] - [11/04/2013 13:48:55]
AdwCleaner[S1].txt - [1905 octets] - [11/04/2013 13:49:30]

########## EOF - C:\AdwCleaner[S1].txt - [1965 octets] ##########

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 11 dub 2013 13:51
od cernohous13
:???: Jak proběhlo mazání?
cernohous13 píše: :arrow: Nález MBAM zkontroluj zda je vše označeno a nech odstranit
:arrow: dej mi aktuální RSIT

jsou ještě nějaké problémy?

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 11 dub 2013 15:32
od SeaHorse
tak to jeeště našlo 2 kousky, který jsem odstranil

2013/04/11 02:34:57 +0200 HP14000226212 Administrator MESSAGE Executing scheduled update: Daily
2013/04/11 02:35:26 +0200 HP14000226212 Administrator MESSAGE Scheduled update executed successfully: database updated from version v2013.04.10.10 to version v2013.04.11.01
2013/04/11 02:35:26 +0200 HP14000226212 Administrator MESSAGE Starting database refresh
2013/04/11 02:35:26 +0200 HP14000226212 Administrator MESSAGE Stopping IP protection
2013/04/11 02:35:27 +0200 HP14000226212 Administrator MESSAGE IP Protection stopped successfully
2013/04/11 02:35:35 +0200 HP14000226212 Administrator MESSAGE Database refreshed successfully
2013/04/11 02:35:36 +0200 HP14000226212 Administrator MESSAGE Starting IP protection
2013/04/11 02:42:11 +0200 HP14000226212 Administrator MESSAGE IP Protection started successfully
2013/04/11 03:40:51 +0200 HP14000226212 MESSAGE Starting protection
2013/04/11 03:40:52 +0200 HP14000226212 MESSAGE Protection started successfully
2013/04/11 03:40:52 +0200 HP14000226212 MESSAGE Starting IP protection
2013/04/11 03:46:33 +0200 HP14000226212 Administrator MESSAGE IP Protection started successfully
2013/04/11 13:52:42 +0200 HP14000226212 MESSAGE Starting protection
2013/04/11 13:52:42 +0200 HP14000226212 MESSAGE Protection started successfully
2013/04/11 13:52:42 +0200 HP14000226212 MESSAGE Starting IP protection
2013/04/11 13:58:44 +0200 HP14000226212 Administrator MESSAGE IP Protection started successfully
2013/04/11 14:04:19 +0200 HP14000226212 Administrator DETECTION C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NZ5Z1MC8\skp[1].exe Trojan.VBKrypt QUARANTINE
2013/04/11 14:08:23 +0200 HP14000226212 Administrator DETECTION C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YNFFLEVX\spm[1].exe Trojan.VBKrypt QUARANTINE
2013/04/11 14:09:32 +0200 HP14000226212 Administrator DETECTION C:\System Volume Information\_restore{37BE5458-E215-467E-83D7-4AF1AEC70570}\RP240\A0037610.exe Trojan.VBKrypt QUARANTINE
2013/04/11 14:12:38 +0200 HP14000226212 Administrator MESSAGE Starting database refresh
2013/04/11 14:12:38 +0200 HP14000226212 Administrator MESSAGE Stopping IP protection
2013/04/11 14:12:39 +0200 HP14000226212 Administrator MESSAGE IP Protection stopped successfully
2013/04/11 14:12:50 +0200 HP14000226212 Administrator MESSAGE Database refreshed successfully
2013/04/11 14:12:50 +0200 HP14000226212 Administrator MESSAGE Starting IP protection
2013/04/11 14:20:02 +0200 HP14000226212 Administrator MESSAGE IP Protection started successfully
2013/04/11 15:36:22 +0200 HP14000226212 MESSAGE Starting protection
2013/04/11 15:36:23 +0200 HP14000226212 MESSAGE Protection started successfully
2013/04/11 15:36:23 +0200 HP14000226212 MESSAGE Starting IP protection
2013/04/11 15:42:28 +0200 HP14000226212 Administrator MESSAGE IP Protection started successfully

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 11 dub 2013 15:41
od cernohous13
:???: Ten log je z čeho?

Chtěl jsem RSIT :?:
a zprávu o MBAM

Re: flashdisk a přepsání složek na zástupce pro E:\843921.ex

Napsal: 11 dub 2013 15:50
od SeaHorse
je ze složky protokolů z MBAM - poslední protokol.

Už zas nevím jak na to RSIT :(