Prosím o pomoc s odstraněním viru
Napsal: 04 úno 2014 01:21
Dobrý den,
do počítače se mi dostal nějaký virus, kterého se nemůžu zbavit. Avast mi najednou začal několikrát denně hlásit, že „štít souborového systému zablokoval útok“. Podle toho jsem zjistila, že se mi v různých složkách v počítači samy vytvářejí různé exe soubory, které si spouští různé procesy. Když proces ukončím a soubor smažu, za chvíli se vytvoří a spustí znovu. Soubory, které se vytvářejí, na které jsem zatím přišla, se jmenují jhProtominer.exe, apts.exe, string.exe, 2.exe a 5.exe, a vytvářejí se na několika různých místech v počítači (i ve složce Program Files/Avast ).
Avast při žádném testu nic neobjeví. Zkoušela jsem podle různých návodů na internetu i jiné programy, např. Combofix nebo The Cleaner, ale vůbec to nepomohlo. Byla bych vděčná za jakoukoliv radu
Vkládám sem log z RSIT podle návodu tady na fóru.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Klif at 2014-02-04 01:14:59
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 414 GB (43%) free of 954 GB
Total RAM: 2047 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:15:02, on 4.2.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\AppServ\Apache2.2\bin\httpd.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVAST\AvastUI.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\QIP Infium\infium.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
C:\AppServ\Apache2.2\bin\httpd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Klif\Plocha\stazene\RSIT.exe
C:\Program Files\trend micro\Klif.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Web Accessibility Toolbar - {11352A67-0178-46B1-8855-D50B2F81C054} - C:\PROGRA~1\ACCESS~1\ACCESS~1.DLL
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST\aswWebRepIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [AutoKMS] C:\WINDOWS\AutoKMS.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [openoffic] \Windows\Explorer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP Infium\infium.exe" /autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [icq] C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe -CU
O4 - HKCU\..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [openoffic] \Windows\Explorer.exe
O4 - HKCU\..\Run: [tcactive] C:\Program Files\The Cleaner\tcap.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1614895754-287218729-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe (HKCU)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\AppServ\Apache2.2\bin\httpd.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: The Cleaner Helper Service (moohelp) - MooSoft Development LLC - C:\Program Files\The Cleaner\mhelper.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: mysql - Unknown owner - C:\AppServ\MySQL\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
--
End of file - 9017 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-KLIFIK-Klif.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Klif\Data aplikací\Mozilla\Firefox\Profiles\c3quzlch.default
"wrc@avast.com"=C:\Program Files\AVAST\WebRep\FF
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Documents and Settings\Klif\Data aplikací\Mozilla\Firefox\Profiles\c3quzlch.default\extensions\
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-18 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST\aswWebRepIE.dll [2014-01-05 1138536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC7E636D-39AA-49b6-B511-65413DA137A1}]
IE Developer Toolbar BHO - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll [2007-03-01 623992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-18 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{11352A67-0178-46B1-8855-D50B2F81C054} - Web Accessibility Toolbar - C:\PROGRA~1\ACCESS~1\ACCESS~1.DLL [2007-07-20 427520]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST\aswWebRepIE.dll [2014-01-05 1138536]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2014-01-03 20145368]
"AvastUI.exe"=C:\Program Files\AVAST\AvastUI.exe [2014-01-05 3764024]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-04-07 13891176]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-02-24 1753192]
"AutoKMS"=C:\WINDOWS\AutoKMS.exe [2014-01-03 615936]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-01-04 500208]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"openoffic"=\Windows\Explorer.exe [2008-04-14 1034240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"Infium"=C:\Program Files\QIP Infium\infium.exe [2010-09-01 5896656]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-11-14 20584608]
"icq"=C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe [2014-01-04 33664344]
"Xvid"=C:\Program Files\Xvid\CheckUpdate.exe [2011-01-17 8192]
"Rainlendar2"=C:\Program Files\Rainlendar2\Rainlendar2.exe [2011-02-04 2346496]
"openoffic"=\Windows\Explorer.exe [2008-04-14 1034240]
"tcactive"=C:\Program Files\The Cleaner\tcap.exe [2013-11-24 6152272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"TaskbarNoNotification"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\AppServ\Apache2.2\bin\httpd.exe"="C:\AppServ\Apache2.2\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe"="C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe:*:Enabled:ICQ"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
======List of files/folders created in the last 1 month======
2014-02-04 01:13:31 ----D---- C:\rsit
2014-02-04 01:13:31 ----D---- C:\Program Files\trend micro
2014-02-04 01:06:27 ----A---- C:\ComboFix.txt
2014-02-02 23:08:42 ----D---- C:\Documents and Settings\Klif\Data aplikací\Runscanner.net
2014-02-02 22:46:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2014-02-02 22:46:04 ----D---- C:\Program Files\IObit Unlocker
2014-02-01 15:24:14 ----D---- C:\Documents and Settings\Klif\Data aplikací\thecleaner
2014-02-01 15:22:39 ----D---- C:\Program Files\The Cleaner
2014-01-31 21:56:15 ----RASHD---- C:\cmdcons
2014-01-31 21:41:03 ----A---- C:\WINDOWS\zip.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\SWXCACLS.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\SWSC.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\SWREG.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\sed.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\PEV.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\NIRCMD.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\MBR.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\grep.exe
2014-01-31 21:39:49 ----D---- C:\Qoobox
2014-01-31 21:39:21 ----D---- C:\WINDOWS\erdnt
2014-01-24 00:24:40 ----D---- C:\Documents and Settings\Klif\Data aplikací\NVIDIA
2014-01-24 00:21:51 ----D---- C:\Documents and Settings\Klif\Data aplikací\newnext.me
2014-01-24 00:20:16 ----D---- C:\Program Files\DVDVideoSoft
2014-01-24 00:20:16 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2014-01-24 00:20:16 ----D---- C:\Documents and Settings\Klif\Data aplikací\OpenCandy
2014-01-24 00:20:16 ----D---- C:\Documents and Settings\Klif\Data aplikací\DVDVideoSoft
2014-01-24 00:10:24 ----D---- C:\Documents and Settings\Klif\Data aplikací\FreeVideoConverter
2014-01-24 00:10:04 ----D---- C:\Program Files\Free Video Converter
2014-01-20 03:13:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Gemfor
2014-01-20 02:54:38 ----A---- C:\WINDOWS\system32\javaws.exe
2014-01-20 02:54:31 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-01-20 02:54:31 ----A---- C:\WINDOWS\system32\javaw.exe
2014-01-20 02:54:31 ----A---- C:\WINDOWS\system32\java.exe
2014-01-19 16:03:49 ----D---- C:\Documents and Settings\Klif\Data aplikací\.minecraft
2014-01-16 02:35:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-01-15 23:38:51 ----D---- C:\WINDOWS\Minidump
2014-01-15 19:59:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\{CC71B1CB-A2E4-4CF7-8EDB-A0E290BA1604}
2014-01-15 18:11:32 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem.txt
2014-01-15 18:09:24 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2014-01-15 18:09:19 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2014-01-15 18:09:14 ----A---- C:\WINDOWS\system32\wdfcoinstaller01007.dll
2014-01-15 18:09:14 ----A---- C:\WINDOWS\system32\drivers\WdfCoInstaller01007.dll
2014-01-15 18:09:09 ----D---- C:\Program Files\Huawei
2014-01-15 18:08:55 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2014-01-05 14:14:26 ----A---- C:\WINDOWS\XMLSchemaValidator.INI
2014-01-05 00:56:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2014-01-05 00:15:49 ----D---- C:\Program Files\Common Files\DirectX
2014-01-05 00:14:21 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2014-01-05 00:14:21 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2014-01-05 00:14:20 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2014-01-05 00:14:20 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2014-01-05 00:14:20 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2014-01-05 00:14:19 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2014-01-05 00:14:19 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2014-01-05 00:14:17 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2014-01-05 00:14:10 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2014-01-05 00:14:10 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2014-01-05 00:14:10 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2014-01-05 00:14:09 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2014-01-05 00:14:09 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2014-01-05 00:14:09 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2014-01-05 00:14:08 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2014-01-05 00:14:08 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2014-01-05 00:14:07 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2014-01-05 00:14:05 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2014-01-05 00:13:31 ----D---- C:\Program Files\Hospital Tycoon
2014-01-05 00:02:50 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
======List of files/folders modified in the last 1 month======
2014-02-04 01:14:43 ----D---- C:\Documents and Settings\Klif\Data aplikací\FileZilla
2014-02-04 01:13:31 ----RD---- C:\Program Files
2014-02-04 01:11:02 ----D---- C:\WINDOWS\Temp
2014-02-04 01:01:13 ----D---- C:\Documents and Settings\Klif\Data aplikací\Skype
2014-02-04 00:59:27 ----D---- C:\WINDOWS
2014-02-04 00:59:27 ----A---- C:\WINDOWS\system.ini
2014-02-04 00:51:17 ----D---- C:\WINDOWS\system32\drivers
2014-02-04 00:51:17 ----D---- C:\WINDOWS\system32
2014-02-04 00:51:17 ----D---- C:\WINDOWS\AppPatch
2014-02-04 00:51:13 ----D---- C:\Program Files\Common Files
2014-02-04 00:42:17 ----D---- C:\WINDOWS\system32\CatRoot2
2014-02-04 00:41:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-02-04 00:38:32 ----D---- C:\WINDOWS\Prefetch
2014-02-02 22:53:18 ----D---- C:\Program Files\Opera
2014-01-31 22:22:22 ----SD---- C:\WINDOWS\Tasks
2014-01-31 22:15:56 ----D---- C:\WINDOWS\system32\drivers\etc
2014-01-30 23:44:52 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-01-24 18:31:41 ----D---- C:\Documents and Settings\Klif\Data aplikací\Adobe
2014-01-24 00:11:23 ----A---- C:\WINDOWS\win.ini
2014-01-20 22:35:57 ----HD---- C:\WINDOWS\inf
2014-01-20 18:49:59 ----A---- C:\WINDOWS\php.ini
2014-01-20 18:46:59 ----SHD---- C:\WINDOWS\Installer
2014-01-20 02:54:31 ----D---- C:\Program Files\Java
2014-01-16 02:37:55 ----D---- C:\WINDOWS\system32\MRT
2014-01-16 02:35:39 ----A---- C:\WINDOWS\system32\MRT.exe
2014-01-16 02:35:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-01-15 18:09:27 ----A---- C:\WINDOWS\imsins.BAK
2014-01-09 19:31:43 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-01-09 00:05:20 ----D---- C:\Program Files\QIP Infium
2014-01-07 00:45:40 ----D---- C:\Program Files\Mozilla Thunderbird
2014-01-07 00:44:18 ----D---- C:\Program Files\Adobe
2014-01-07 00:44:15 ----D---- C:\Program Files\Common Files\Adobe AIR
2014-01-05 02:26:21 ----D---- C:\WINDOWS\Microsoft.NET
2014-01-05 02:26:18 ----RSD---- C:\WINDOWS\assembly
2014-01-05 02:12:10 ----D---- C:\Program Files\AVAST
2014-01-05 02:09:37 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-01-05 01:06:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-01-05 01:06:08 ----D---- C:\WINDOWS\WinSxS
2014-01-05 00:57:56 ----D---- C:\WINDOWS\system32\CatRoot
2014-01-05 00:43:38 ----D---- C:\WINDOWS\system32\XPSViewer
2014-01-05 00:14:22 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-01-03 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-01-05 180248]
R1 aswRdr;aswRdr; \??\C:\WINDOWS\system32\drivers\aswRdr.sys []
R1 aswSnx;aswSnx; \??\C:\WINDOWS\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; \??\C:\WINDOWS\system32\drivers\aswSP.sys []
R1 aswTdi;aswTdi; \??\C:\WINDOWS\system32\drivers\aswTdi.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2014-01-03 243128]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2014-01-03 5620440]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-04-08 12501600]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2010-11-29 35712]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2014-01-03 1691480]
S3 catchme;catchme; \??\C:\DOCUME~1\Klif\LOCALS~1\Temp\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys []
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\WINDOWS\system32\DRIVERS\ew_usbenumfilter.sys []
S3 huawei_cdcacm;huawei_cdcacm; C:\WINDOWS\system32\DRIVERS\ew_jucdcacm.sys []
S3 huawei_cdcecm;huawei_cdcecm; C:\WINDOWS\system32\DRIVERS\ew_jucdcecm.sys []
S3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\system32\DRIVERS\ew_jubusenum.sys []
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\WINDOWS\system32\DRIVERS\ew_juextctrl.sys []
S3 IObitUnlocker;IObitUnlocker; \??\C:\Program Files\IObit Unlocker\IObitUnlocker.sys []
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2014-01-03 1395800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apache2.2;Apache2.2; C:\AppServ\Apache2.2\bin\httpd.exe [2008-01-17 24635]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST\AvastSvc.exe [2014-01-05 50344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-12-18 182696]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-04-07 155752]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-03 116648]
S2 moohelp;The Cleaner Helper Service; C:\Program Files\The Cleaner\mhelper.exe [2013-11-24 816208]
S2 mysql;mysql; C:\AppServ\MySQL\bin\mysqld-nt --defaults-file=C:\AppServ\MySQL\my.ini mysql []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-30 257928]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-03 116648]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-05 119408]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Předem moc děkuji
Helena
do počítače se mi dostal nějaký virus, kterého se nemůžu zbavit. Avast mi najednou začal několikrát denně hlásit, že „štít souborového systému zablokoval útok“. Podle toho jsem zjistila, že se mi v různých složkách v počítači samy vytvářejí různé exe soubory, které si spouští různé procesy. Když proces ukončím a soubor smažu, za chvíli se vytvoří a spustí znovu. Soubory, které se vytvářejí, na které jsem zatím přišla, se jmenují jhProtominer.exe, apts.exe, string.exe, 2.exe a 5.exe, a vytvářejí se na několika různých místech v počítači (i ve složce Program Files/Avast ).
Avast při žádném testu nic neobjeví. Zkoušela jsem podle různých návodů na internetu i jiné programy, např. Combofix nebo The Cleaner, ale vůbec to nepomohlo. Byla bych vděčná za jakoukoliv radu
Vkládám sem log z RSIT podle návodu tady na fóru.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Klif at 2014-02-04 01:14:59
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 414 GB (43%) free of 954 GB
Total RAM: 2047 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:15:02, on 4.2.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\AppServ\Apache2.2\bin\httpd.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVAST\AvastUI.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\QIP Infium\infium.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
C:\AppServ\Apache2.2\bin\httpd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Klif\Plocha\stazene\RSIT.exe
C:\Program Files\trend micro\Klif.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Web Accessibility Toolbar - {11352A67-0178-46B1-8855-D50B2F81C054} - C:\PROGRA~1\ACCESS~1\ACCESS~1.DLL
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST\aswWebRepIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [AutoKMS] C:\WINDOWS\AutoKMS.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [openoffic] \Windows\Explorer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP Infium\infium.exe" /autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [icq] C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe -CU
O4 - HKCU\..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [openoffic] \Windows\Explorer.exe
O4 - HKCU\..\Run: [tcactive] C:\Program Files\The Cleaner\tcap.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1614895754-287218729-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe (HKCU)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\AppServ\Apache2.2\bin\httpd.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: The Cleaner Helper Service (moohelp) - MooSoft Development LLC - C:\Program Files\The Cleaner\mhelper.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: mysql - Unknown owner - C:\AppServ\MySQL\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
--
End of file - 9017 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-KLIFIK-Klif.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Klif\Data aplikací\Mozilla\Firefox\Profiles\c3quzlch.default
"wrc@avast.com"=C:\Program Files\AVAST\WebRep\FF
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Documents and Settings\Klif\Data aplikací\Mozilla\Firefox\Profiles\c3quzlch.default\extensions\
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-18 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST\aswWebRepIE.dll [2014-01-05 1138536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC7E636D-39AA-49b6-B511-65413DA137A1}]
IE Developer Toolbar BHO - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll [2007-03-01 623992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-18 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{11352A67-0178-46B1-8855-D50B2F81C054} - Web Accessibility Toolbar - C:\PROGRA~1\ACCESS~1\ACCESS~1.DLL [2007-07-20 427520]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST\aswWebRepIE.dll [2014-01-05 1138536]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2014-01-03 20145368]
"AvastUI.exe"=C:\Program Files\AVAST\AvastUI.exe [2014-01-05 3764024]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-04-07 13891176]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-02-24 1753192]
"AutoKMS"=C:\WINDOWS\AutoKMS.exe [2014-01-03 615936]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-01-04 500208]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"openoffic"=\Windows\Explorer.exe [2008-04-14 1034240]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"Infium"=C:\Program Files\QIP Infium\infium.exe [2010-09-01 5896656]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-11-14 20584608]
"icq"=C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe [2014-01-04 33664344]
"Xvid"=C:\Program Files\Xvid\CheckUpdate.exe [2011-01-17 8192]
"Rainlendar2"=C:\Program Files\Rainlendar2\Rainlendar2.exe [2011-02-04 2346496]
"openoffic"=\Windows\Explorer.exe [2008-04-14 1034240]
"tcactive"=C:\Program Files\The Cleaner\tcap.exe [2013-11-24 6152272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"TaskbarNoNotification"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\AppServ\Apache2.2\bin\httpd.exe"="C:\AppServ\Apache2.2\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe"="C:\Documents and Settings\Klif\Data aplikací\ICQM\icq.exe:*:Enabled:ICQ"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
======List of files/folders created in the last 1 month======
2014-02-04 01:13:31 ----D---- C:\rsit
2014-02-04 01:13:31 ----D---- C:\Program Files\trend micro
2014-02-04 01:06:27 ----A---- C:\ComboFix.txt
2014-02-02 23:08:42 ----D---- C:\Documents and Settings\Klif\Data aplikací\Runscanner.net
2014-02-02 22:46:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2014-02-02 22:46:04 ----D---- C:\Program Files\IObit Unlocker
2014-02-01 15:24:14 ----D---- C:\Documents and Settings\Klif\Data aplikací\thecleaner
2014-02-01 15:22:39 ----D---- C:\Program Files\The Cleaner
2014-01-31 21:56:15 ----RASHD---- C:\cmdcons
2014-01-31 21:41:03 ----A---- C:\WINDOWS\zip.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\SWXCACLS.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\SWSC.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\SWREG.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\sed.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\PEV.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\NIRCMD.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\MBR.exe
2014-01-31 21:41:03 ----A---- C:\WINDOWS\grep.exe
2014-01-31 21:39:49 ----D---- C:\Qoobox
2014-01-31 21:39:21 ----D---- C:\WINDOWS\erdnt
2014-01-24 00:24:40 ----D---- C:\Documents and Settings\Klif\Data aplikací\NVIDIA
2014-01-24 00:21:51 ----D---- C:\Documents and Settings\Klif\Data aplikací\newnext.me
2014-01-24 00:20:16 ----D---- C:\Program Files\DVDVideoSoft
2014-01-24 00:20:16 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2014-01-24 00:20:16 ----D---- C:\Documents and Settings\Klif\Data aplikací\OpenCandy
2014-01-24 00:20:16 ----D---- C:\Documents and Settings\Klif\Data aplikací\DVDVideoSoft
2014-01-24 00:10:24 ----D---- C:\Documents and Settings\Klif\Data aplikací\FreeVideoConverter
2014-01-24 00:10:04 ----D---- C:\Program Files\Free Video Converter
2014-01-20 03:13:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Gemfor
2014-01-20 02:54:38 ----A---- C:\WINDOWS\system32\javaws.exe
2014-01-20 02:54:31 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-01-20 02:54:31 ----A---- C:\WINDOWS\system32\javaw.exe
2014-01-20 02:54:31 ----A---- C:\WINDOWS\system32\java.exe
2014-01-19 16:03:49 ----D---- C:\Documents and Settings\Klif\Data aplikací\.minecraft
2014-01-16 02:35:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-01-15 23:38:51 ----D---- C:\WINDOWS\Minidump
2014-01-15 19:59:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\{CC71B1CB-A2E4-4CF7-8EDB-A0E290BA1604}
2014-01-15 18:11:32 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem.txt
2014-01-15 18:09:24 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2014-01-15 18:09:19 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2014-01-15 18:09:14 ----A---- C:\WINDOWS\system32\wdfcoinstaller01007.dll
2014-01-15 18:09:14 ----A---- C:\WINDOWS\system32\drivers\WdfCoInstaller01007.dll
2014-01-15 18:09:09 ----D---- C:\Program Files\Huawei
2014-01-15 18:08:55 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2014-01-05 14:14:26 ----A---- C:\WINDOWS\XMLSchemaValidator.INI
2014-01-05 00:56:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2014-01-05 00:15:49 ----D---- C:\Program Files\Common Files\DirectX
2014-01-05 00:14:21 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2014-01-05 00:14:21 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2014-01-05 00:14:20 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2014-01-05 00:14:20 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2014-01-05 00:14:20 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2014-01-05 00:14:19 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2014-01-05 00:14:19 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2014-01-05 00:14:18 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2014-01-05 00:14:17 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2014-01-05 00:14:10 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2014-01-05 00:14:10 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2014-01-05 00:14:10 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2014-01-05 00:14:09 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2014-01-05 00:14:09 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2014-01-05 00:14:09 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2014-01-05 00:14:08 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2014-01-05 00:14:08 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2014-01-05 00:14:07 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2014-01-05 00:14:05 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2014-01-05 00:13:31 ----D---- C:\Program Files\Hospital Tycoon
2014-01-05 00:02:50 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
======List of files/folders modified in the last 1 month======
2014-02-04 01:14:43 ----D---- C:\Documents and Settings\Klif\Data aplikací\FileZilla
2014-02-04 01:13:31 ----RD---- C:\Program Files
2014-02-04 01:11:02 ----D---- C:\WINDOWS\Temp
2014-02-04 01:01:13 ----D---- C:\Documents and Settings\Klif\Data aplikací\Skype
2014-02-04 00:59:27 ----D---- C:\WINDOWS
2014-02-04 00:59:27 ----A---- C:\WINDOWS\system.ini
2014-02-04 00:51:17 ----D---- C:\WINDOWS\system32\drivers
2014-02-04 00:51:17 ----D---- C:\WINDOWS\system32
2014-02-04 00:51:17 ----D---- C:\WINDOWS\AppPatch
2014-02-04 00:51:13 ----D---- C:\Program Files\Common Files
2014-02-04 00:42:17 ----D---- C:\WINDOWS\system32\CatRoot2
2014-02-04 00:41:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-02-04 00:38:32 ----D---- C:\WINDOWS\Prefetch
2014-02-02 22:53:18 ----D---- C:\Program Files\Opera
2014-01-31 22:22:22 ----SD---- C:\WINDOWS\Tasks
2014-01-31 22:15:56 ----D---- C:\WINDOWS\system32\drivers\etc
2014-01-30 23:44:52 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-01-24 18:31:41 ----D---- C:\Documents and Settings\Klif\Data aplikací\Adobe
2014-01-24 00:11:23 ----A---- C:\WINDOWS\win.ini
2014-01-20 22:35:57 ----HD---- C:\WINDOWS\inf
2014-01-20 18:49:59 ----A---- C:\WINDOWS\php.ini
2014-01-20 18:46:59 ----SHD---- C:\WINDOWS\Installer
2014-01-20 02:54:31 ----D---- C:\Program Files\Java
2014-01-16 02:37:55 ----D---- C:\WINDOWS\system32\MRT
2014-01-16 02:35:39 ----A---- C:\WINDOWS\system32\MRT.exe
2014-01-16 02:35:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-01-15 18:09:27 ----A---- C:\WINDOWS\imsins.BAK
2014-01-09 19:31:43 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-01-09 00:05:20 ----D---- C:\Program Files\QIP Infium
2014-01-07 00:45:40 ----D---- C:\Program Files\Mozilla Thunderbird
2014-01-07 00:44:18 ----D---- C:\Program Files\Adobe
2014-01-07 00:44:15 ----D---- C:\Program Files\Common Files\Adobe AIR
2014-01-05 02:26:21 ----D---- C:\WINDOWS\Microsoft.NET
2014-01-05 02:26:18 ----RSD---- C:\WINDOWS\assembly
2014-01-05 02:12:10 ----D---- C:\Program Files\AVAST
2014-01-05 02:09:37 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-01-05 01:06:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-01-05 01:06:08 ----D---- C:\WINDOWS\WinSxS
2014-01-05 00:57:56 ----D---- C:\WINDOWS\system32\CatRoot
2014-01-05 00:43:38 ----D---- C:\WINDOWS\system32\XPSViewer
2014-01-05 00:14:22 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-01-03 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-01-05 180248]
R1 aswRdr;aswRdr; \??\C:\WINDOWS\system32\drivers\aswRdr.sys []
R1 aswSnx;aswSnx; \??\C:\WINDOWS\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; \??\C:\WINDOWS\system32\drivers\aswSP.sys []
R1 aswTdi;aswTdi; \??\C:\WINDOWS\system32\drivers\aswTdi.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2014-01-03 243128]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2014-01-03 5620440]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-04-08 12501600]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2010-11-29 35712]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2014-01-03 1691480]
S3 catchme;catchme; \??\C:\DOCUME~1\Klif\LOCALS~1\Temp\catchme.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys []
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\WINDOWS\system32\DRIVERS\ew_usbenumfilter.sys []
S3 huawei_cdcacm;huawei_cdcacm; C:\WINDOWS\system32\DRIVERS\ew_jucdcacm.sys []
S3 huawei_cdcecm;huawei_cdcecm; C:\WINDOWS\system32\DRIVERS\ew_jucdcecm.sys []
S3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\system32\DRIVERS\ew_jubusenum.sys []
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\WINDOWS\system32\DRIVERS\ew_juextctrl.sys []
S3 IObitUnlocker;IObitUnlocker; \??\C:\Program Files\IObit Unlocker\IObitUnlocker.sys []
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2014-01-03 1395800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apache2.2;Apache2.2; C:\AppServ\Apache2.2\bin\httpd.exe [2008-01-17 24635]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST\AvastSvc.exe [2014-01-05 50344]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-12-18 182696]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-04-07 155752]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-03 116648]
S2 moohelp;The Cleaner Helper Service; C:\Program Files\The Cleaner\mhelper.exe [2013-11-24 816208]
S2 mysql;mysql; C:\AppServ\MySQL\bin\mysqld-nt --defaults-file=C:\AppServ\MySQL\my.ini mysql []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-30 257928]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-03 116648]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-05 119408]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Předem moc děkuji
Helena