Stránka 1 z 1

Prosím o kontrolu

Napsal: 16 led 2010 21:35
od .:D.e.x.t.e.r:.
Tady je log z RSITu .. PC se nějak zpomaluje, ale během 1-2 dnů proběhne čistka HDD a registrů ... ale chtěl jsem se nejdřív ujistit jestli jsem bez virů, rootů a malwerů nebo jiné havěti..



Logfile of random's system information tool 1.06 (written by random/random)
Run by Lukas at 2010-01-16 21:34:22
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 509 MB (3%) free of 15 GB
Total RAM: 511 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:34:50, on 16.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\IDMAN\IDMan.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
D:\Wolf's\miranda32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Lukas\Dokumenty\Downloads\Programs\RSIT.exe
C:\Program Files\trend micro\Lukas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\IDMAN\IDMIECC.dll
O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] D:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [IDMan] D:\IDMAN\IDMan.exe /onboot
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Registration Heroes of Might & Magic 5.LNK = D:\Heroes of Might and Magic V\registration\RegistrationReminder.exe
O4 - Startup: Registration Lock On
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Stáhnout s IDM - D:\IDMAN\IEExt.htm
O8 - Extra context menu item: Stáhnout s IDM obsah FLV videa - D:\IDMAN\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM všechny odkazy - D:\IDMAN\IEGetAll.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.icq.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/ ... TSUEng.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/ ... /CTPID.cab
O17 - HKLM\System\CS11\Services\Tcpip\Parameters: NameServer = 85.255.115.34,85.255.112.63
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 11457 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - D:\IDMAN\IDMIECC.dll [2009-05-07 169392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-08-26 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-07 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-07 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-07 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
free-downloads.net Toolbar - C:\Program Files\free-downloads.net\tbfre0.dll [2009-03-19 1883672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{ecdee021-0d17-467f-a1ff-c7a115230949} - free-downloads.net Toolbar - C:\Program Files\free-downloads.net\tbfre0.dll [2009-03-19 1883672]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"=C:\WINDOWS\SiSUSBrg.exe [2002-07-12 106496]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"WINDVDPatch"=C:\WINDOWS\system32\CTHELPER.EXE [2002-07-02 24576]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-07 136600]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-08-26 185896]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2005-01-19 221184]
"LogitechVideoRepair"=D:\Program Files\Logitech\Video\ISStart.exe [2005-01-19 458752]
"LogitechVideoTray"=D:\Program Files\Logitech\Video\LogiTray.exe [2005-01-19 217088]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2008-11-13 981904]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-16 86016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]
"SetDefaultMIDI"=C:\WINDOWS\MIDIDef.exe [2002-01-14 61440]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2009-11-07 323392]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe [2008-04-16 1079808]
"IDMan"=D:\IDMAN\IDMan.exe [2009-05-19 2811312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InvisibleBrowsing]
C:\Program Files\Invisible Browsing\InvisibleBrowsing.exe [2007-02-02 917504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2008-05-30 21718312]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Documents and Settings\Lukas\Nabídka Start\Programy\Po spuštění
Registration Heroes of Might & Magic 5.LNK - D:\Heroes of Might and Magic V\registration\RegistrationReminder.exe
Registration Lock On
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\Invisible Browsing\InvisibleBrowsing.exe"="C:\Program Files\Invisible Browsing\InvisibleBrowsing.exe:*:Enabled:Invisible Browsing"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Java\jre1.6.0_07\bin\java.exe"="C:\Program Files\Java\jre1.6.0_07\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Program Files\ICQ6.5\ICQ.exe"="D:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"D:\Super Online Tuner 1.1\Super Online Tuner 1.1.exe"="D:\Super Online Tuner 1.1\Super Online Tuner 1.1.exe:*:Enabled:Super Online Tuner 1.1"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{029961b7-3b1e-11d8-b2a6-806d6172696f}]
shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{029961b8-3b1e-11d8-b2a6-806d6172696f}]
shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e38e323-d3f9-11dd-adb6-000d879d9097}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
shell\Open(0)\command - K:\Recycled\ctfmon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6aefcd9e-3b1a-11d8-ac8a-000d879d9097}]
shell\AutoRun\command - H:\StartPortableApps.exe


======List of files/folders created in the last 1 months======

2010-01-13 14:07:10 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-13 14:06:12 ----A---- C:\WINDOWS\imsins.BAK
2010-01-13 14:05:41 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-01-03 14:58:12 ----D---- C:\Program Files\LogMeIn Hamachi
2009-12-27 11:19:20 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2009-12-27 11:19:18 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2009-12-27 11:19:16 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2009-12-27 11:19:14 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2009-12-27 11:19:13 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2009-12-27 11:19:12 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2009-12-27 11:19:11 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2009-12-27 11:19:10 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2009-12-27 11:19:10 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2009-12-27 11:19:09 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2009-12-27 11:19:07 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2009-12-27 11:19:07 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2009-12-27 11:19:07 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2009-12-27 11:19:02 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll

======List of files/folders modified in the last 1 months======

2010-01-16 21:34:50 ----D---- C:\Program Files\trend micro
2010-01-16 21:34:45 ----D---- C:\WINDOWS\Prefetch
2010-01-16 21:30:06 ----D---- C:\Program Files\Mozilla Firefox
2010-01-16 14:29:23 ----D---- C:\WINDOWS\temp
2010-01-16 14:28:40 ----D---- C:\WINDOWS\system32
2010-01-14 20:06:22 ----HD---- C:\WINDOWS\inf
2010-01-14 20:06:16 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-14 18:49:11 ----D---- C:\Documents and Settings\Lukas\Data aplikací\DMCache
2010-01-13 14:34:06 ----D---- C:\WINDOWS\Internet Logs
2010-01-13 14:32:19 ----D---- C:\Program Files\DNA
2010-01-13 14:32:19 ----D---- C:\Documents and Settings\Lukas\Data aplikací\DNA
2010-01-13 14:31:54 ----D---- C:\WINDOWS
2010-01-13 14:31:08 ----D---- C:\WINDOWS\AppPatch
2010-01-13 14:30:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-13 14:14:25 ----SHD---- C:\WINDOWS\Installer
2010-01-13 14:14:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-01-13 14:07:34 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-13 14:06:54 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-13 14:03:47 ----D---- C:\WINDOWS\Debug
2010-01-10 14:43:47 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-10 12:33:52 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-07 20:19:48 ----D---- C:\Documents and Settings\Lukas\Data aplikací\Skype
2010-01-07 18:50:35 ----D---- C:\Documents and Settings\Lukas\Data aplikací\skypePM
2010-01-06 14:52:43 ----D---- C:\Program Files\Hamachi
2010-01-06 14:21:44 ----D---- C:\Program Files\Microsoft Works
2010-01-06 14:21:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-01-06 14:12:31 ----A---- C:\WINDOWS\win.ini
2010-01-06 14:12:30 ----D---- C:\Program Files\Common Files\System
2010-01-05 01:17:46 ----A---- C:\WINDOWS\system32\MRT.exe
2010-01-03 14:58:41 ----D---- C:\WINDOWS\system32\drivers
2010-01-03 14:58:12 ----RD---- C:\Program Files
2010-01-03 14:58:02 ----D---- C:\Documents and Settings\Lukas\Data aplikací\Hamachi
2010-01-03 14:57:23 ----D---- C:\Temp
2009-12-27 11:27:28 ----D---- C:\WINDOWS\system32\DirectX
2009-12-23 21:44:01 ----D---- C:\WINDOWS\system32\Macromed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-09-03 54368]
R1 SSHDRV85;SSHDRV85; \??\C:\WINDOWS\system32\drivers\SSHDRV85.sys []
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2008-11-13 353680]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-10-26 278984]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-09-11 18048]
R2 PfModNT;PfModNT; \??\C:\WINDOWS\system32\drivers\PfModNT.sys []
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2005-08-29 853258]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2006-06-09 1373120]
R3 ctljystk;Game port pro zařízení Creative SB Live!; C:\WINDOWS\system32\DRIVERS\ctljystk.sys [2001-08-17 3712]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2009-06-18 34064]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2002-07-10 32256]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2003-09-19 45056]
S3 ag4kumk8;ag4kumk8; C:\WINDOWS\system32\drivers\ag4kumk8.sys []
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2005-08-29 428269]
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2005-08-29 30363]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2005-08-29 148360]
S3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2005-08-29 30221]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2005-08-29 64344]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2002-07-19 127948]
S3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2002-07-19 837548]
S3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2002-07-19 11068]
S3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2002-07-19 213860]
S3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2002-07-19 156604]
S3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2002-07-24 998004]
S3 hSONYPVh;hSONYPVh; \??\C:\DOCUME~1\Lukas\LOCALS~1\Temp\hSONYPVh.sys []
S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys [2005-01-19 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-07 17536]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-05-07 20864]
S3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2002-07-19 195432]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 PID_0928;Labtec WebCam(PID_0928); C:\WINDOWS\system32\DRIVERS\LV561AV.SYS [2005-01-19 211712]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 sony_ssm.sys;sony_ssm.sys; \??\C:\DOCUME~1\Lukas\LOCALS~1\Temp\sony_ssm.sys []
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 tap0801;TAP-Win32 Adapter V8; C:\WINDOWS\system32\DRIVERS\tap0801.sys [2007-02-15 26624]
S3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2008-06-06 8064]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2005-08-29 266295]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-07 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-03-03 75064]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2009-01-30 217088]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-08-07 575488]
S2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2008-11-13 2405776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-04 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe -d -f C:\Program Files\WinPcap\rpcapd.ini []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prosím o kontrolu

Napsal: 17 led 2010 00:14
od Marek-26
Odinstalujte ICQ a Yahoo! toolbar

stahnete a ulozte nejlepe na plochu ComboFix

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano:

Obrázek

dale muze dojit k varovani ohledne rezidentniho stitu vaseho antiviru a upozorneni na nenainstalovanou konzoli pro zotaveni; tu zatim neinstalujte.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, deaktivujte jeho rezidentni stit, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim Combofixu s rezidentem antispyware

po restartu aplikace vytvori log, ulozeny na C:/Combofix.txt (pri opakovanem pouziti jsou logy oznaceny Combofix2.txt atd.), jeho obsah vlozte sem

Re: Prosím o kontrolu

Napsal: 18 led 2010 20:05
od .:D.e.x.t.e.r:.
ComboFix 10-01-18.01 - Administrator 18.01.2010 19:06:35.10.1 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.339 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\QIP
c:\program files\QIP\LI\current.cfg
c:\program files\QIP\LI\English\_cntry.lng
c:\program files\QIP\LI\English\_intrsts.lng
c:\program files\QIP\LI\English\_langs.lng
c:\program files\QIP\LI\English\_marital.lng
c:\program files\QIP\LI\English\_occup.lng
c:\program files\QIP\LI\English\_orgs.lng
c:\program files\QIP\LI\English\_past.lng
c:\program files\QIP\LI\English\_rndchat.lng
c:\program files\QIP\LI\English\desc.txt
c:\program files\QIP\LI\English\chars_r.ini
c:\program files\QIP\LI\English\chars_t.ini
c:\program files\QIP\LI\English\lang.ini
c:\program files\QIP\LI\langs.cfg
c:\program files\QIP\LI\Russian\_cntry.lng
c:\program files\QIP\LI\Russian\_intrsts.lng
c:\program files\QIP\LI\Russian\_langs.lng
c:\program files\QIP\LI\Russian\_marital.lng
c:\program files\QIP\LI\Russian\_occup.lng
c:\program files\QIP\LI\Russian\_orgs.lng
c:\program files\QIP\LI\Russian\_past.lng
c:\program files\QIP\LI\Russian\_rndchat.lng
c:\program files\QIP\LI\Russian\desc.txt
c:\program files\QIP\LI\Russian\chars_r.ini
c:\program files\QIP\LI\Russian\chars_t.ini
c:\program files\QIP\LI\Russian\lang.ini
c:\program files\QIP\Plugins\docking.dll
c:\program files\QIP\qip.exe
c:\program files\QIP\QIP.license
c:\program files\QIP\Skins\current.cfg
c:\program files\QIP\Skins\ICQ5\addopt.bmp
c:\program files\QIP\Skins\ICQ5\allicons.bmp
c:\program files\QIP\Skins\ICQ5\clbg.bmp
c:\program files\QIP\Skins\ICQ5\clevent.bmp
c:\program files\QIP\Skins\ICQ5\clstatus.bmp
c:\program files\QIP\Skins\ICQ5\Colors.ini
c:\program files\QIP\Skins\ICQ5\desc.txt
c:\program files\QIP\Skins\ICQ5\downbutton1.bmp
c:\program files\QIP\Skins\ICQ5\fadehlp.bmp
c:\program files\QIP\Skins\ICQ5\fadehlpt.bmp
c:\program files\QIP\Skins\ICQ5\fademsg.bmp
c:\program files\QIP\Skins\ICQ5\fademsgt.bmp
c:\program files\QIP\Skins\ICQ5\fadesrv.bmp
c:\program files\QIP\Skins\ICQ5\fadesrvt.bmp
c:\program files\QIP\Skins\ICQ5\msgbg.bmp
c:\program files\QIP\Skins\ICQ5\msgbge.bmp
c:\program files\QIP\Skins\ICQ5\noimage.jpg
c:\program files\QIP\Skins\ICQ5\qipbtn.bmp
c:\program files\QIP\Skins\ICQ5\signs.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\_define.ini
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aa.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ab.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ac.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ad.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ae.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\af.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ag.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ah.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ai.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aj.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ak.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\al.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\am.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\an.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ao.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ap.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aq.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ar.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\as.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\at.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\au.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\av.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aw.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ax.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ay.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\az.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ba.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bb.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bc.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bd.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\be.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bf.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bg.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bh.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bi.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bj.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bk.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bl.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bm.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bn.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bo.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bp.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bq.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\br.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bs.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bt.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bu.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bv.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bw.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\Copyright(eng).txt
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\Copyright.txt
c:\program files\QIP\Skins\ICQ5\Smilies\Static\_define.ini
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aa.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ab.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ac.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ad.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ae.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\af.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ag.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ah.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ai.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aj.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ak.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\al.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\am.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\an.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ao.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ap.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aq.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ar.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\as.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\at.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\au.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\av.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aw.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ax.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ay.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ba.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\bb.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\bc.bmp
c:\program files\QIP\Skins\ICQ5\splash.bmp
c:\program files\QIP\Skins\ICQ5\st_custom.bmp
c:\program files\QIP\Skins\ICQ5\statuses.bmp
c:\program files\QIP\Skins\ICQ5\title.bmp
c:\program files\QIP\Skins\ICQ5\tray.bmp
c:\program files\QIP\Skins\ICQ5\tray2k.bmp
c:\program files\QIP\Skins\ICQ5\upbutton1.bmp
c:\program files\QIP\Skins\ICQ5\upbutton2.bmp
c:\program files\QIP\Skins\ICQ5\upbutton3.bmp
c:\program files\QIP\Skins\ICQ5\userinfo.bmp
c:\program files\QIP\Skins\ICQ5\vis.bmp
c:\program files\QIP\Skins\skins.cfg
c:\program files\QIP\Sounds\sndAuth.wav
c:\program files\QIP\Sounds\sndGlobal.wav
c:\program files\QIP\Sounds\sndMsg.wav
c:\program files\QIP\Sounds\sndMsgSent.wav
c:\program files\QIP\Sounds\sndPlugin.wav
c:\program files\QIP\Sounds\sndRemSelf.wav
c:\program files\QIP\Sounds\sndSrvMsg.wav
c:\program files\QIP\Sounds\sndStartup.wav
c:\program files\QIP\Sounds\sndSystem.wav
c:\program files\QIP\unins000.dat
c:\program files\QIP\unins000.exe
c:\program files\QIP\unins001.dat
c:\program files\QIP\unins001.exe
c:\program files\QIP\Users\445423528\_birth.txt
c:\program files\QIP\Users\445423528\_botq.txt
c:\program files\QIP\Users\445423528\_events.txt
c:\program files\QIP\Users\445423528\_eye.txt
c:\program files\QIP\Users\445423528\_groups.txt
c:\program files\QIP\Users\445423528\_m_away.txt
c:\program files\QIP\Users\445423528\_m_depr.txt
c:\program files\QIP\Users\445423528\_m_dnd.txt
c:\program files\QIP\Users\445423528\_m_evil.txt
c:\program files\QIP\Users\445423528\_m_ffc.txt
c:\program files\QIP\Users\445423528\_m_home.txt
c:\program files\QIP\Users\445423528\_m_lunch.txt
c:\program files\QIP\Users\445423528\_m_na.txt
c:\program files\QIP\Users\445423528\_m_occup.txt
c:\program files\QIP\Users\445423528\_m_work.txt
c:\program files\QIP\Users\445423528\_premsg.txt
c:\program files\QIP\Users\445423528\_st_away.txt
c:\program files\QIP\Users\445423528\_st_cust.txt
c:\program files\QIP\Users\445423528\445423528.cl
c:\program files\QIP\Users\445423528\445423528.clg
c:\program files\QIP\Users\445423528\445423528.cli
c:\program files\QIP\Users\445423528\445423528.clv
c:\program files\QIP\Users\445423528\445423528.lcl
c:\program files\QIP\Users\445423528\445423528.nil
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.cl
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.clg
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.cli
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.clv
c:\program files\QIP\Users\445423528\Config.ini
c:\program files\QIP\Users\445423528\Devils\422206483.jpg
c:\program files\QIP\Users\445423528\History\379858650.txt
c:\program files\QIP\Users\445423528\History\477229318.txt
c:\program files\QIP\Users\477229318\_birth.txt
c:\program files\QIP\Users\477229318\_botq.txt
c:\program files\QIP\Users\477229318\_events.txt
c:\program files\QIP\Users\477229318\_eye.txt
c:\program files\QIP\Users\477229318\_groups.txt
c:\program files\QIP\Users\477229318\_m_away.txt
c:\program files\QIP\Users\477229318\_m_depr.txt
c:\program files\QIP\Users\477229318\_m_dnd.txt
c:\program files\QIP\Users\477229318\_m_evil.txt
c:\program files\QIP\Users\477229318\_m_ffc.txt
c:\program files\QIP\Users\477229318\_m_home.txt
c:\program files\QIP\Users\477229318\_m_lunch.txt
c:\program files\QIP\Users\477229318\_m_na.txt
c:\program files\QIP\Users\477229318\_m_occup.txt
c:\program files\QIP\Users\477229318\_m_work.txt
c:\program files\QIP\Users\477229318\_premsg.txt
c:\program files\QIP\Users\477229318\_st_away.txt
c:\program files\QIP\Users\477229318\_st_cust.txt
c:\program files\QIP\Users\477229318\477229318.cl
c:\program files\QIP\Users\477229318\477229318.clg
c:\program files\QIP\Users\477229318\477229318.cli
c:\program files\QIP\Users\477229318\477229318.clv
c:\program files\QIP\Users\477229318\477229318.lcl
c:\program files\QIP\Users\477229318\477229318.nil
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.clv
c:\program files\QIP\Users\477229318\Config.ini
c:\program files\QIP\Users\477229318\Devils\191044808.jpg
c:\program files\QIP\Users\477229318\Devils\200626544.jpg
c:\program files\QIP\Users\477229318\Devils\201283496.jpg
c:\program files\QIP\Users\477229318\Devils\206945618.jpg
c:\program files\QIP\Users\477229318\Devils\218719122.jpg
c:\program files\QIP\Users\477229318\Devils\223699741.jpg
c:\program files\QIP\Users\477229318\Devils\225214711.jpg
c:\program files\QIP\Users\477229318\Devils\233941835.gif
c:\program files\QIP\Users\477229318\Devils\234453543.jpg
c:\program files\QIP\Users\477229318\Devils\240378346.gif
c:\program files\QIP\Users\477229318\Devils\251440913.jpg
c:\program files\QIP\Users\477229318\Devils\251450001.jpg
c:\program files\QIP\Users\477229318\Devils\261434868.jpg
c:\program files\QIP\Users\477229318\Devils\272702638.jpg
c:\program files\QIP\Users\477229318\Devils\278317529.jpg
c:\program files\QIP\Users\477229318\Devils\284295831.jpg
c:\program files\QIP\Users\477229318\Devils\292033155.jpg
c:\program files\QIP\Users\477229318\Devils\295836778.jpg
c:\program files\QIP\Users\477229318\Devils\296001957.jpg
c:\program files\QIP\Users\477229318\Devils\298820105.jpg
c:\program files\QIP\Users\477229318\Devils\307932779.jpg
c:\program files\QIP\Users\477229318\Devils\311251175.jpg
c:\program files\QIP\Users\477229318\Devils\317636468.jpg
c:\program files\QIP\Users\477229318\Devils\333919659.jpg
c:\program files\QIP\Users\477229318\Devils\339143260.jpg
c:\program files\QIP\Users\477229318\Devils\345331945.jpg
c:\program files\QIP\Users\477229318\Devils\348992625.jpg
c:\program files\QIP\Users\477229318\Devils\352975555.jpg
c:\program files\QIP\Users\477229318\Devils\353111070.jpg
c:\program files\QIP\Users\477229318\Devils\354589618.jpg
c:\program files\QIP\Users\477229318\Devils\355886725.jpg
c:\program files\QIP\Users\477229318\Devils\356005445.jpg
c:\program files\QIP\Users\477229318\Devils\356769703.jpg
c:\program files\QIP\Users\477229318\Devils\357011796.jpg
c:\program files\QIP\Users\477229318\Devils\359588186.jpg
c:\program files\QIP\Users\477229318\Devils\361568939.jpg
c:\program files\QIP\Users\477229318\Devils\362216105.jpg
c:\program files\QIP\Users\477229318\Devils\362357855.jpg
c:\program files\QIP\Users\477229318\Devils\363192529.jpg
c:\program files\QIP\Users\477229318\Devils\364337216.jpg
c:\program files\QIP\Users\477229318\Devils\377737683.jpg
c:\program files\QIP\Users\477229318\Devils\380125930.jpg
c:\program files\QIP\Users\477229318\Devils\381561034.jpg
c:\program files\QIP\Users\477229318\Devils\383320712.jpg
c:\program files\QIP\Users\477229318\Devils\384965908.jpg
c:\program files\QIP\Users\477229318\Devils\384971199.jpg
c:\program files\QIP\Users\477229318\Devils\386155825.jpg
c:\program files\QIP\Users\477229318\Devils\387144850.jpg
c:\program files\QIP\Users\477229318\Devils\390964144.jpg
c:\program files\QIP\Users\477229318\Devils\393718998.jpg
c:\program files\QIP\Users\477229318\Devils\394798538.jpg
c:\program files\QIP\Users\477229318\Devils\398228574.jpg
c:\program files\QIP\Users\477229318\Devils\399543393.jpg
c:\program files\QIP\Users\477229318\Devils\405160313.jpg
c:\program files\QIP\Users\477229318\Devils\406113816.jpg
c:\program files\QIP\Users\477229318\Devils\412020963.jpg
c:\program files\QIP\Users\477229318\Devils\414265376.jpg
c:\program files\QIP\Users\477229318\Devils\417916768.jpg
c:\program files\QIP\Users\477229318\Devils\419504310.jpg
c:\program files\QIP\Users\477229318\Devils\420668884.jpg
c:\program files\QIP\Users\477229318\Devils\424330781.jpg
c:\program files\QIP\Users\477229318\Devils\424433258.jpg
c:\program files\QIP\Users\477229318\Devils\426061177.jpg
c:\program files\QIP\Users\477229318\Devils\429399111.jpg
c:\program files\QIP\Users\477229318\Devils\429999017.jpg
c:\program files\QIP\Users\477229318\Devils\430259115.jpg
c:\program files\QIP\Users\477229318\Devils\432531808.jpg
c:\program files\QIP\Users\477229318\Devils\433264122.jpg
c:\program files\QIP\Users\477229318\Devils\434082602.jpg
c:\program files\QIP\Users\477229318\Devils\435184843.jpg
c:\program files\QIP\Users\477229318\Devils\437067773.jpg
c:\program files\QIP\Users\477229318\Devils\438776900.jpg
c:\program files\QIP\Users\477229318\Devils\439033233.jpg
c:\program files\QIP\Users\477229318\Devils\439820076.jpg
c:\program files\QIP\Users\477229318\Devils\442644223.jpg
c:\program files\QIP\Users\477229318\Devils\443358181.jpg
c:\program files\QIP\Users\477229318\Devils\445423528.jpg
c:\program files\QIP\Users\477229318\Devils\446124114.jpg
c:\program files\QIP\Users\477229318\Devils\447374678.jpg
c:\program files\QIP\Users\477229318\Devils\447791934.jpg
c:\program files\QIP\Users\477229318\Devils\450964174.jpg
c:\program files\QIP\Users\477229318\Devils\452151098.jpg
c:\program files\QIP\Users\477229318\Devils\452294342.jpg
c:\program files\QIP\Users\477229318\Devils\454320588.jpg
c:\program files\QIP\Users\477229318\Devils\454414656.jpg
c:\program files\QIP\Users\477229318\Devils\460114642.jpg
c:\program files\QIP\Users\477229318\Devils\462217766.jpg
c:\program files\QIP\Users\477229318\Devils\463892562.jpg
c:\program files\QIP\Users\477229318\Devils\470070522.jpg
c:\program files\QIP\Users\477229318\Devils\474556211.jpg
c:\program files\QIP\Users\477229318\Devils\477229318.jpg
c:\program files\QIP\Users\477229318\Devils\477232147.jpg
c:\program files\QIP\Users\477229318\Devils\482533244.jpg
c:\program files\QIP\Users\477229318\Devils\482846250.jpg
c:\program files\QIP\Users\477229318\Devils\484627599.jpg
c:\program files\QIP\Users\477229318\Devils\492433895.jpg
c:\program files\QIP\Users\477229318\Devils\493524407.jpg
c:\program files\QIP\Users\477229318\Devils\493944587.jpg
c:\program files\QIP\Users\477229318\Devils\495115361.jpg
c:\program files\QIP\Users\477229318\Devils\497073463.jpg
c:\program files\QIP\Users\477229318\Devils\499983990.jpg
c:\program files\QIP\Users\477229318\Devils\597154603.jpg
c:\program files\QIP\Users\477229318\History\_srvlog.txt
c:\program files\QIP\Users\477229318\History\169939003.txt
c:\program files\QIP\Users\477229318\History\191044808.txt
c:\program files\QIP\Users\477229318\History\201150704.txt
c:\program files\QIP\Users\477229318\History\219135403.txt
c:\program files\QIP\Users\477229318\History\233941835.txt
c:\program files\QIP\Users\477229318\History\245997749.txt
c:\program files\QIP\Users\477229318\History\250994034.txt
c:\program files\QIP\Users\477229318\History\272702638.txt
c:\program files\QIP\Users\477229318\History\284295831.txt
c:\program files\QIP\Users\477229318\History\292033155.txt
c:\program files\QIP\Users\477229318\History\298820105.txt
c:\program files\QIP\Users\477229318\History\307932779.txt
c:\program files\QIP\Users\477229318\History\317886817.txt
c:\program files\QIP\Users\477229318\History\345331945.txt
c:\program files\QIP\Users\477229318\History\345862661.txt
c:\program files\QIP\Users\477229318\History\350119005.txt
c:\program files\QIP\Users\477229318\History\356005445.txt
c:\program files\QIP\Users\477229318\History\356769703.txt
c:\program files\QIP\Users\477229318\History\357011796.txt
c:\program files\QIP\Users\477229318\History\362216105.txt
c:\program files\QIP\Users\477229318\History\364337216.txt
c:\program files\QIP\Users\477229318\History\368619818.txt
c:\program files\QIP\Users\477229318\History\380125930.txt
c:\program files\QIP\Users\477229318\History\381082161.txt
c:\program files\QIP\Users\477229318\History\381561034.txt
c:\program files\QIP\Users\477229318\History\381927209.txt
c:\program files\QIP\Users\477229318\History\383320712.txt
c:\program files\QIP\Users\477229318\History\384971199.txt
c:\program files\QIP\Users\477229318\History\386155825.txt
c:\program files\QIP\Users\477229318\History\387144850.txt
c:\program files\QIP\Users\477229318\History\399451063.txt
c:\program files\QIP\Users\477229318\History\409977084.txt
c:\program files\QIP\Users\477229318\History\412898306.txt
c:\program files\QIP\Users\477229318\History\416372408.txt
c:\program files\QIP\Users\477229318\History\419504310.txt
c:\program files\QIP\Users\477229318\History\419618359.txt
c:\program files\QIP\Users\477229318\History\420668884.txt
c:\program files\QIP\Users\477229318\History\424330781.txt
c:\program files\QIP\Users\477229318\History\424433258.txt
c:\program files\QIP\Users\477229318\History\425261776.txt
c:\program files\QIP\Users\477229318\History\426061177.txt
c:\program files\QIP\Users\477229318\History\429399111.txt
c:\program files\QIP\Users\477229318\History\429999017.txt
c:\program files\QIP\Users\477229318\History\430406566.txt
c:\program files\QIP\Users\477229318\History\430409661.txt
c:\program files\QIP\Users\477229318\History\431716705.txt
c:\program files\QIP\Users\477229318\History\432875197.txt
c:\program files\QIP\Users\477229318\History\438776900.txt
c:\program files\QIP\Users\477229318\History\439033233.txt
c:\program files\QIP\Users\477229318\History\441066144.txt
c:\program files\QIP\Users\477229318\History\442644223.txt
c:\program files\QIP\Users\477229318\History\445423528.txt
c:\program files\QIP\Users\477229318\History\447791934.txt
c:\program files\QIP\Users\477229318\History\448548061.txt
c:\program files\QIP\Users\477229318\History\452151098.txt
c:\program files\QIP\Users\477229318\History\454320588.txt
c:\program files\QIP\Users\477229318\History\454414656.txt
c:\program files\QIP\Users\477229318\History\460114642.txt
c:\program files\QIP\Users\477229318\History\460531353.txt
c:\program files\QIP\Users\477229318\History\465971194.txt
c:\program files\QIP\Users\477229318\History\470070522.txt
c:\program files\QIP\Users\477229318\History\474556211.txt
c:\program files\QIP\Users\477229318\History\477232147.txt
c:\program files\QIP\Users\477229318\History\482846250.txt
c:\program files\QIP\Users\477229318\History\483269838.txt
c:\program files\QIP\Users\477229318\History\493524407.txt
c:\program files\QIP\Users\477229318\History\495115361.txt
c:\program files\QIP\Users\477229318\History\495295084.txt
c:\program files\QIP\Users\477229318\History\497073463.txt
c:\program files\QIP\Users\477229318\RcvdFiles\284295831_Ristin\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\284295831_Ristin\wwi2epc2.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-_\253af0f.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-_\Bez Teba.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-_\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\Bez Teba.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\DSCF6212.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\DSCF6290.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\dzTC_4uPjd.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\dzTC_55XP6.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\H16 - Milujem.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\Tomas Bezdeda-krasne krasna.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_We.rush.Ka\DSCF4074.JPG
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_We.rush.Ka\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\380125930_Paťas\Snímek pro Lukáše4.JPG
c:\program files\QIP\Users\477229318\RcvdFiles\380125930_Paťas\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\1.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\2.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\3.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\4.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\Thumbs.db
c:\program files\QIP\Users\482846250\_botq.txt
c:\program files\QIP\Users\482846250\_events.txt
c:\program files\QIP\Users\482846250\_eye.txt
c:\program files\QIP\Users\482846250\_groups.txt
c:\program files\QIP\Users\482846250\_m_away.txt
c:\program files\QIP\Users\482846250\_m_depr.txt
c:\program files\QIP\Users\482846250\_m_dnd.txt
c:\program files\QIP\Users\482846250\_m_evil.txt
c:\program files\QIP\Users\482846250\_m_ffc.txt
c:\program files\QIP\Users\482846250\_m_home.txt
c:\program files\QIP\Users\482846250\_m_lunch.txt
c:\program files\QIP\Users\482846250\_m_na.txt
c:\program files\QIP\Users\482846250\_m_occup.txt
c:\program files\QIP\Users\482846250\_m_work.txt
c:\program files\QIP\Users\482846250\_premsg.txt
c:\program files\QIP\Users\482846250\_st_away.txt
c:\program files\QIP\Users\482846250\_st_cust.txt
c:\program files\QIP\Users\482846250\482846250.cl
c:\program files\QIP\Users\482846250\482846250.clg
c:\program files\QIP\Users\482846250\482846250.cli
c:\program files\QIP\Users\482846250\482846250.clv
c:\program files\QIP\Users\482846250\482846250.lcl
c:\program files\QIP\Users\482846250\482846250.nil
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.cl
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.clg
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.cli
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.clv
c:\program files\QIP\Users\482846250\Config.ini
c:\program files\QIP\Users\482846250\Devils\422206483.jpg
c:\program files\QIP\Users\482846250\Devils\443982206.jpg
c:\program files\QIP\Users\482846250\Devils\482846250.jpg
c:\program files\QIP\Users\482846250\History\477229318.txt
c:\program files\QIP\Users\495115361\_botq.txt
c:\program files\QIP\Users\495115361\_events.txt
c:\program files\QIP\Users\495115361\_eye.txt
c:\program files\QIP\Users\495115361\_groups.txt
c:\program files\QIP\Users\495115361\_m_away.txt
c:\program files\QIP\Users\495115361\_m_depr.txt
c:\program files\QIP\Users\495115361\_m_dnd.txt
c:\program files\QIP\Users\495115361\_m_evil.txt
c:\program files\QIP\Users\495115361\_m_ffc.txt
c:\program files\QIP\Users\495115361\_m_home.txt
c:\program files\QIP\Users\495115361\_m_lunch.txt
c:\program files\QIP\Users\495115361\_m_na.txt
c:\program files\QIP\Users\495115361\_m_occup.txt
c:\program files\QIP\Users\495115361\_m_work.txt
c:\program files\QIP\Users\495115361\_premsg.txt
c:\program files\QIP\Users\495115361\_st_away.txt
c:\program files\QIP\Users\495115361\_st_cust.txt
c:\program files\QIP\Users\495115361\495115361.cl
c:\program files\QIP\Users\495115361\495115361.clg
c:\program files\QIP\Users\495115361\495115361.cli
c:\program files\QIP\Users\495115361\495115361.clv
c:\program files\QIP\Users\495115361\495115361.lcl
c:\program files\QIP\Users\495115361\495115361.nil
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.cl
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.clg
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.cli
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.clv
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.cl
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.clg
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.cli
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.clv
c:\program files\QIP\Users\495115361\Config.ini
c:\program files\QIP\Users\495115361\Devils\276820054.jpg
c:\program files\QIP\Users\495115361\Devils\356769703.jpg
c:\program files\QIP\Users\495115361\Devils\400958290.jpg
c:\program files\QIP\Users\495115361\Devils\408939515.jpg
c:\program files\QIP\Users\495115361\Devils\445423528.jpg
c:\program files\QIP\Users\495115361\Devils\477229318.jpg
c:\program files\QIP\Users\495115361\Devils\493524407.jpg
c:\program files\QIP\Users\495115361\Devils\560274160.jpg
c:\program files\QIP\Users\495115361\History\379542198.txt
c:\program files\QIP\Users\495115361\History\394295566.txt
c:\program files\QIP\Users\495115361\History\477229318.txt
c:\program files\QIP\Users\Accounts.cfg
c:\program files\QIP\Users\Config.ini
c:\program files\QIP\Users\Default.cfg
c:\windows\system32\Data
c:\windows\system32\Data\CT0060W.DAT
c:\windows\system32\Data\CTP0060W.DAT
c:\windows\system32\Data\CTP0061W.DAT
c:\windows\system32\Data\CTP0100W.DAT
c:\windows\system32\Data\CTP0101W.DAT
c:\windows\system32\Data\CTP0102W.DAT
c:\windows\system32\Data\CTP0103W.DAT
c:\windows\system32\Data\CTP0105W.DAT
c:\windows\system32\Data\CTP0221W.DAT
c:\windows\system32\Data\CTP0222W.DAT
c:\windows\system32\Data\CTP1140W.DAT
c:\windows\system32\Data\CTP4620W.DAT
c:\windows\system32\Data\CTP4670W.DAT
c:\windows\system32\Data\CTP4760W.DAT
c:\windows\system32\Data\CTP4780W.DAT
c:\windows\system32\Data\CTP4790W.DAT
c:\windows\system32\Data\CTP4830W.DAT
c:\windows\system32\Data\CTP4831W.DAT
c:\windows\system32\Data\CTP4832W.DAT
c:\windows\system32\Data\CTP4840W.DAT
c:\windows\system32\Data\CTP4850W.DAT
c:\windows\system32\Data\CTP4870W.DAT
c:\windows\system32\Data\CTP4871W.DAT
c:\windows\system32\Data\CTP4872W.DAT
c:\windows\system32\Data\CTP4890W.DAT
c:\windows\system32\Data\CTP4891W.DAT
c:\windows\system32\Data\CTP4893W.DAT
c:\windows\system32\Data\CTPDXW.DAT
c:\windows\system32\Data\CTPM002W.DAT
c:\windows\system32\Data\CTSBAS2W.DAT
c:\windows\system32\Data\CTSBASW.DAT
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SIntf16.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Soubory vytvořené od 2009-12-18 do 2010-01-18 )))))))))))))))))))))))))))))))
.

2010-01-18 18:02 . 2010-01-18 18:02 390144 ----a-w- c:\windows\system32\CF8.exe
2010-01-18 17:55 . 2010-01-18 17:55 390144 ----a-w- c:\windows\system32\CF31391.exe
2010-01-13 12:40 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-03 13:58 . 2010-01-03 13:58 -------- d-----w- c:\program files\LogMeIn Hamachi

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-18 18:21 . 2001-10-25 14:00 79242 ----a-w- c:\windows\system32\perfc005.dat
2010-01-18 18:21 . 2001-10-25 14:00 432278 ----a-w- c:\windows\system32\perfh005.dat
2010-01-18 18:18 . 2008-10-22 15:06 -------- d-----w- c:\program files\DNA
2010-01-17 20:03 . 2008-08-13 18:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-16 20:45 . 2009-01-27 10:57 -------- d-----w- c:\program files\NewName
2010-01-16 20:34 . 2009-08-05 12:51 -------- d-----w- c:\program files\trend micro
2010-01-10 16:42 . 2010-01-10 16:43 2781696 ----a-w- c:\windows\Internet Logs\xDB4.tmp
2010-01-06 13:52 . 2008-11-25 17:21 -------- d-----w- c:\program files\Hamachi
2010-01-06 13:21 . 2003-12-30 23:26 -------- d-----w- c:\program files\Microsoft Works
2009-11-24 17:04 . 2009-11-24 17:04 78848 ----a-w- c:\windows\system32\drivers\SSHDRV85.sys
2009-11-24 15:15 . 2008-10-15 19:07 -------- d-----w- c:\program files\Yahoo!
2009-11-24 15:12 . 2009-03-25 18:46 -------- d-----w- c:\program files\OpenOffice.org 3
2009-11-24 15:05 . 2009-08-05 12:49 -------- d-----w- c:\program files\Online TV Player 4
2009-11-23 18:25 . 2009-11-23 18:25 -------- d-----w- c:\program files\Common Files\PocketSoft
2009-11-21 16:03 . 2004-08-17 14:49 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 20:32 . 2008-08-31 15:17 138352 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-18 20:32 . 2008-08-31 15:17 191304 -c--a-w- c:\windows\system32\PnkBstrB.exe
2009-11-18 15:10 . 2008-08-18 17:24 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-10-29 07:43 . 2004-08-17 14:49 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-28 07:30 . 2009-10-28 07:29 21371722 -c--a-w- c:\windows\Internet Logs\vsmon_on_demand_thread_2009_10_26_13_52_35_full.dmp.zip
2009-10-21 05:40 . 2004-08-17 14:49 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:40 . 2004-08-17 14:49 25088 ----a-w- c:\windows\system32\httpapi.dll
2008-03-04 14:17 . 2008-10-28 13:36 65465 -c--a-w- c:\program files\Mount&Blade
2003-12-18 09:33 . 2009-02-21 08:42 20102 -c--a-w- c:\program files\Readme.txt
2003-09-03 05:46 . 2009-02-21 08:42 10960 -c--a-w- c:\program files\EULA.txt
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-03-19 1883672]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-03-19 16:56 1883672 ----a-w- c:\program files\free-downloads.net\tbfre0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-03-19 1883672]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-03-19 1883672]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"SetDefaultMIDI"="MIDIDef.exe" [2002-01-14 61440]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-07 323392]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 1079808]
"IDMan"="d:\idman\IDMan.exe" [2009-05-19 2811312]
"Google Update"="c:\documents and settings\Lukas\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-01-16 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 24576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-07 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-26 185896]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-01-19 221184]
"LogitechVideoRepair"="d:\program files\Logitech\Video\ISStart.exe" [2005-01-19 458752]
"LogitechVideoTray"="d:\program files\Logitech\Video\LogiTray.exe" [2005-01-19 217088]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-9 610365]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InvisibleBrowsing]
2007-02-02 10:13 917504 ----a-w- c:\program files\Invisible Browsing\InvisibleBrowsing.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-05-30 13:54 21718312 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Invisible Browsing\\InvisibleBrowsing.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"d:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.12.2003 0:05 717296]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [24.11.2009 18:04 78848]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29.10.2009 12:27 1074568]
S3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);c:\windows\system32\drivers\ctlsb16.sys [1.3.2009 15:08 96256]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [15.2.2007 18:48 26624]
S3 TVICHW32;TVICHW32;c:\windows\system32\drivers\TVICHW32.SYS [13.8.2008 20:34 23600]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{029961b7-3b1e-11d8-b2a6-806d6172696f}]
\Shell\AutoRun\command - E:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{029961b8-3b1e-11d8-b2a6-806d6172696f}]
\Shell\AutoRun\command - F:\noautorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e38e323-d3f9-11dd-adb6-000d879d9097}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - k:\recycled\ctfmon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6aefcd9e-3b1a-11d8-ac8a-000d879d9097}]
\Shell\AutoRun\command - H:\StartPortableApps.exe
.
Obsah adresáře 'Naplánované úlohy'

2009-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-01-18 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-01 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Download All by FlashGet - d:\program files\FlashGet\jc_all.htm
IE: Download using FlashGet - d:\program files\FlashGet\jc_link.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint - Náhled - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint - Přidat na seznam k tisku - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint - Tisk - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Easy-WebPrint - Vysokorychlostní tisk - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Stáhnout s IDM - d:\idman\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - d:\idman\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - d:\idman\IEGetAll.htm
Trusted Zone: icq.com\www
FF - ProfilePath - c:\documents and settings\Lukas\Data aplikací\Mozilla\Firefox\Profiles\auvp6y39.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\Lukas\Data aplikací\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-Chop - c:\program files\Common Files\InstallerA\Setup.exe \CHOP
AddRemove-QIP 2005_is1 - c:\program files\QIP\unins000.exe
AddRemove-Uplink - d:\uplink\Uninst.isu
AddRemove-{8C3727F2-8E37-49E4-820C-03B1677F53B6} - c:\program files\InstallShield Installation Information\{8C3727F2-8E37-49E4-820C-03B1677F53B6}\setup.exe
AddRemove-QIP 2005 - c:\program files\QIP\unins001.exe
AddRemove-ROTR Beta Patch 1.1 - d:\program files\EA Games\Command & Conquer Generals Zero Hour\Uinst_ROTR_Beta.exe
AddRemove-ROTR Public Beta - d:\program files\EA Games\Command & Conquer Generals Zero Hour\Uinst_ROTR_Beta.exe
AddRemove-ShockWave V0.95 - d:\ea games\Command & Conquer Generals Zero Hour\Uinst_shw.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-18 19:19
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys >>UNKNOWN [0x833B4270]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8555f28
\Driver\ACPI -> ACPI.sys @ 0xf83b0cb8
\Driver\atapi -> prosync1.sys @ 0xf8a196c1
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
user & kernel MBR OK

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-2000478354-1965331169-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b4,49,e6,19,7b,e9,4d,63,25,76,bb,4e,2c,cd,f8,0a,49,8d,51,58,d6,
1b,b3,0a,66,4e,81,0d,f5,f5,4b,c2,11,18,05,71,f6,40,28,b4,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7b9ed357-6dbc-44dd-acd3-8ee3fd2f5b93}]
@Denied: (Full) (Everyone)
"Model"=dword:0000016c
"Therad"=dword:0000001c
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(3952)
c:\progra~1\WINDOW~2\wmpband.dll
d:\wolf's\Plugins\advancedautoaway.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RUNDLL32.EXE
c:\documents and settings\Lukas\Local Settings\Data aplikací\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\UAService7.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\windows\system32\wscntfy.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
d:\wolf's\miranda32.exe
c:\windows\system32\RUNDLL32.EXE
.
**************************************************************************
.
Celkový čas: 2010-01-18 19:26:48 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-18 18:26
ComboFix2.txt 2009-08-07 08:03
ComboFix3.txt 2009-01-25 17:42
ComboFix4.txt 2009-01-21 14:38
ComboFix5.txt 2009-08-20 18:32

Před spuštěním: 3 194 937 344
Po spuštění: 2 571 239 424

Current=14 Default=14 Failed=13 LastKnownGood=15 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15
- - End Of File - - 1089E89AF3FE6655E29856680659EF4D

Re: Prosím o kontrolu

Napsal: 19 led 2010 19:58
od Marek-26
Omlouvám se za delší odmlku a smazaný QIP :wink:

Co je disk K: ??

Stáhněte si novou verzi ComboFixu a uložte jí na plochu.
Otevrete si Poznamkovy blok a do nej zkopirujte skript z nasledujiciho okna:

Kód: Vybrat vše

DeQuarantine::
c:\program files\QIP
c:\program files\QIP\LI\current.cfg
c:\program files\QIP\LI\English\_cntry.lng
c:\program files\QIP\LI\English\_intrsts.lng
c:\program files\QIP\LI\English\_langs.lng
c:\program files\QIP\LI\English\_marital.lng
c:\program files\QIP\LI\English\_occup.lng
c:\program files\QIP\LI\English\_orgs.lng
c:\program files\QIP\LI\English\_past.lng
c:\program files\QIP\LI\English\_rndchat.lng
c:\program files\QIP\LI\English\desc.txt
c:\program files\QIP\LI\English\chars_r.ini
c:\program files\QIP\LI\English\chars_t.ini
c:\program files\QIP\LI\English\lang.ini
c:\program files\QIP\LI\langs.cfg
c:\program files\QIP\LI\Russian\_cntry.lng
c:\program files\QIP\LI\Russian\_intrsts.lng
c:\program files\QIP\LI\Russian\_langs.lng
c:\program files\QIP\LI\Russian\_marital.lng
c:\program files\QIP\LI\Russian\_occup.lng
c:\program files\QIP\LI\Russian\_orgs.lng
c:\program files\QIP\LI\Russian\_past.lng
c:\program files\QIP\LI\Russian\_rndchat.lng
c:\program files\QIP\LI\Russian\desc.txt
c:\program files\QIP\LI\Russian\chars_r.ini
c:\program files\QIP\LI\Russian\chars_t.ini
c:\program files\QIP\LI\Russian\lang.ini
c:\program files\QIP\Plugins\docking.dll
c:\program files\QIP\qip.exe
c:\program files\QIP\QIP.license
c:\program files\QIP\Skins\current.cfg
c:\program files\QIP\Skins\ICQ5\addopt.bmp
c:\program files\QIP\Skins\ICQ5\allicons.bmp
c:\program files\QIP\Skins\ICQ5\clbg.bmp
c:\program files\QIP\Skins\ICQ5\clevent.bmp
c:\program files\QIP\Skins\ICQ5\clstatus.bmp
c:\program files\QIP\Skins\ICQ5\Colors.ini
c:\program files\QIP\Skins\ICQ5\desc.txt
c:\program files\QIP\Skins\ICQ5\downbutton1.bmp
c:\program files\QIP\Skins\ICQ5\fadehlp.bmp
c:\program files\QIP\Skins\ICQ5\fadehlpt.bmp
c:\program files\QIP\Skins\ICQ5\fademsg.bmp
c:\program files\QIP\Skins\ICQ5\fademsgt.bmp
c:\program files\QIP\Skins\ICQ5\fadesrv.bmp
c:\program files\QIP\Skins\ICQ5\fadesrvt.bmp
c:\program files\QIP\Skins\ICQ5\msgbg.bmp
c:\program files\QIP\Skins\ICQ5\msgbge.bmp
c:\program files\QIP\Skins\ICQ5\noimage.jpg
c:\program files\QIP\Skins\ICQ5\qipbtn.bmp
c:\program files\QIP\Skins\ICQ5\signs.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\_define.ini
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aa.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ab.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ac.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ad.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ae.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\af.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ag.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ah.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ai.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aj.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ak.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\al.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\am.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\an.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ao.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ap.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aq.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ar.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\as.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\at.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\au.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\av.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\aw.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ax.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ay.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\az.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\ba.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bb.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bc.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bd.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\be.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bf.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bg.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bh.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bi.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bj.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bk.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bl.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bm.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bn.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bo.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bp.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bq.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\br.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bs.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bt.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bu.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bv.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\bw.gif
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\Copyright(eng).txt
c:\program files\QIP\Skins\ICQ5\Smilies\Animated\Copyright.txt
c:\program files\QIP\Skins\ICQ5\Smilies\Static\_define.ini
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aa.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ab.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ac.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ad.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ae.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\af.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ag.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ah.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ai.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aj.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ak.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\al.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\am.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\an.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ao.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ap.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aq.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ar.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\as.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\at.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\au.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\av.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\aw.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ax.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ay.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\ba.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\bb.bmp
c:\program files\QIP\Skins\ICQ5\Smilies\Static\bc.bmp
c:\program files\QIP\Skins\ICQ5\splash.bmp
c:\program files\QIP\Skins\ICQ5\st_custom.bmp
c:\program files\QIP\Skins\ICQ5\statuses.bmp
c:\program files\QIP\Skins\ICQ5\title.bmp
c:\program files\QIP\Skins\ICQ5\tray.bmp
c:\program files\QIP\Skins\ICQ5\tray2k.bmp
c:\program files\QIP\Skins\ICQ5\upbutton1.bmp
c:\program files\QIP\Skins\ICQ5\upbutton2.bmp
c:\program files\QIP\Skins\ICQ5\upbutton3.bmp
c:\program files\QIP\Skins\ICQ5\userinfo.bmp
c:\program files\QIP\Skins\ICQ5\vis.bmp
c:\program files\QIP\Skins\skins.cfg
c:\program files\QIP\Sounds\sndAuth.wav
c:\program files\QIP\Sounds\sndGlobal.wav
c:\program files\QIP\Sounds\sndMsg.wav
c:\program files\QIP\Sounds\sndMsgSent.wav
c:\program files\QIP\Sounds\sndPlugin.wav
c:\program files\QIP\Sounds\sndRemSelf.wav
c:\program files\QIP\Sounds\sndSrvMsg.wav
c:\program files\QIP\Sounds\sndStartup.wav
c:\program files\QIP\Sounds\sndSystem.wav
c:\program files\QIP\unins000.dat
c:\program files\QIP\unins000.exe
c:\program files\QIP\unins001.dat
c:\program files\QIP\unins001.exe
c:\program files\QIP\Users\445423528\_birth.txt
c:\program files\QIP\Users\445423528\_botq.txt
c:\program files\QIP\Users\445423528\_events.txt
c:\program files\QIP\Users\445423528\_eye.txt
c:\program files\QIP\Users\445423528\_groups.txt
c:\program files\QIP\Users\445423528\_m_away.txt
c:\program files\QIP\Users\445423528\_m_depr.txt
c:\program files\QIP\Users\445423528\_m_dnd.txt
c:\program files\QIP\Users\445423528\_m_evil.txt
c:\program files\QIP\Users\445423528\_m_ffc.txt
c:\program files\QIP\Users\445423528\_m_home.txt
c:\program files\QIP\Users\445423528\_m_lunch.txt
c:\program files\QIP\Users\445423528\_m_na.txt
c:\program files\QIP\Users\445423528\_m_occup.txt
c:\program files\QIP\Users\445423528\_m_work.txt
c:\program files\QIP\Users\445423528\_premsg.txt
c:\program files\QIP\Users\445423528\_st_away.txt
c:\program files\QIP\Users\445423528\_st_cust.txt
c:\program files\QIP\Users\445423528\445423528.cl
c:\program files\QIP\Users\445423528\445423528.clg
c:\program files\QIP\Users\445423528\445423528.cli
c:\program files\QIP\Users\445423528\445423528.clv
c:\program files\QIP\Users\445423528\445423528.lcl
c:\program files\QIP\Users\445423528\445423528.nil
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.cl
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.clg
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.cli
c:\program files\QIP\Users\445423528\BackupCL\445423528_2009_03.clv
c:\program files\QIP\Users\445423528\Config.ini
c:\program files\QIP\Users\445423528\Devils\422206483.jpg
c:\program files\QIP\Users\445423528\History\379858650.txt
c:\program files\QIP\Users\445423528\History\477229318.txt
c:\program files\QIP\Users\477229318\_birth.txt
c:\program files\QIP\Users\477229318\_botq.txt
c:\program files\QIP\Users\477229318\_events.txt
c:\program files\QIP\Users\477229318\_eye.txt
c:\program files\QIP\Users\477229318\_groups.txt
c:\program files\QIP\Users\477229318\_m_away.txt
c:\program files\QIP\Users\477229318\_m_depr.txt
c:\program files\QIP\Users\477229318\_m_dnd.txt
c:\program files\QIP\Users\477229318\_m_evil.txt
c:\program files\QIP\Users\477229318\_m_ffc.txt
c:\program files\QIP\Users\477229318\_m_home.txt
c:\program files\QIP\Users\477229318\_m_lunch.txt
c:\program files\QIP\Users\477229318\_m_na.txt
c:\program files\QIP\Users\477229318\_m_occup.txt
c:\program files\QIP\Users\477229318\_m_work.txt
c:\program files\QIP\Users\477229318\_premsg.txt
c:\program files\QIP\Users\477229318\_st_away.txt
c:\program files\QIP\Users\477229318\_st_cust.txt
c:\program files\QIP\Users\477229318\477229318.cl
c:\program files\QIP\Users\477229318\477229318.clg
c:\program files\QIP\Users\477229318\477229318.cli
c:\program files\QIP\Users\477229318\477229318.clv
c:\program files\QIP\Users\477229318\477229318.lcl
c:\program files\QIP\Users\477229318\477229318.nil
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2008_12.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_01.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_02.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_03.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_04.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_05.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_06.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_07.clv
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.cl
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.clg
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.cli
c:\program files\QIP\Users\477229318\BackupCL\477229318_2009_08.clv
c:\program files\QIP\Users\477229318\Config.ini
c:\program files\QIP\Users\477229318\Devils\191044808.jpg
c:\program files\QIP\Users\477229318\Devils\200626544.jpg
c:\program files\QIP\Users\477229318\Devils\201283496.jpg
c:\program files\QIP\Users\477229318\Devils\206945618.jpg
c:\program files\QIP\Users\477229318\Devils\218719122.jpg
c:\program files\QIP\Users\477229318\Devils\223699741.jpg
c:\program files\QIP\Users\477229318\Devils\225214711.jpg
c:\program files\QIP\Users\477229318\Devils\233941835.gif
c:\program files\QIP\Users\477229318\Devils\234453543.jpg
c:\program files\QIP\Users\477229318\Devils\240378346.gif
c:\program files\QIP\Users\477229318\Devils\251440913.jpg
c:\program files\QIP\Users\477229318\Devils\251450001.jpg
c:\program files\QIP\Users\477229318\Devils\261434868.jpg
c:\program files\QIP\Users\477229318\Devils\272702638.jpg
c:\program files\QIP\Users\477229318\Devils\278317529.jpg
c:\program files\QIP\Users\477229318\Devils\284295831.jpg
c:\program files\QIP\Users\477229318\Devils\292033155.jpg
c:\program files\QIP\Users\477229318\Devils\295836778.jpg
c:\program files\QIP\Users\477229318\Devils\296001957.jpg
c:\program files\QIP\Users\477229318\Devils\298820105.jpg
c:\program files\QIP\Users\477229318\Devils\307932779.jpg
c:\program files\QIP\Users\477229318\Devils\311251175.jpg
c:\program files\QIP\Users\477229318\Devils\317636468.jpg
c:\program files\QIP\Users\477229318\Devils\333919659.jpg
c:\program files\QIP\Users\477229318\Devils\339143260.jpg
c:\program files\QIP\Users\477229318\Devils\345331945.jpg
c:\program files\QIP\Users\477229318\Devils\348992625.jpg
c:\program files\QIP\Users\477229318\Devils\352975555.jpg
c:\program files\QIP\Users\477229318\Devils\353111070.jpg
c:\program files\QIP\Users\477229318\Devils\354589618.jpg
c:\program files\QIP\Users\477229318\Devils\355886725.jpg
c:\program files\QIP\Users\477229318\Devils\356005445.jpg
c:\program files\QIP\Users\477229318\Devils\356769703.jpg
c:\program files\QIP\Users\477229318\Devils\357011796.jpg
c:\program files\QIP\Users\477229318\Devils\359588186.jpg
c:\program files\QIP\Users\477229318\Devils\361568939.jpg
c:\program files\QIP\Users\477229318\Devils\362216105.jpg
c:\program files\QIP\Users\477229318\Devils\362357855.jpg
c:\program files\QIP\Users\477229318\Devils\363192529.jpg
c:\program files\QIP\Users\477229318\Devils\364337216.jpg
c:\program files\QIP\Users\477229318\Devils\377737683.jpg
c:\program files\QIP\Users\477229318\Devils\380125930.jpg
c:\program files\QIP\Users\477229318\Devils\381561034.jpg
c:\program files\QIP\Users\477229318\Devils\383320712.jpg
c:\program files\QIP\Users\477229318\Devils\384965908.jpg
c:\program files\QIP\Users\477229318\Devils\384971199.jpg
c:\program files\QIP\Users\477229318\Devils\386155825.jpg
c:\program files\QIP\Users\477229318\Devils\387144850.jpg
c:\program files\QIP\Users\477229318\Devils\390964144.jpg
c:\program files\QIP\Users\477229318\Devils\393718998.jpg
c:\program files\QIP\Users\477229318\Devils\394798538.jpg
c:\program files\QIP\Users\477229318\Devils\398228574.jpg
c:\program files\QIP\Users\477229318\Devils\399543393.jpg
c:\program files\QIP\Users\477229318\Devils\405160313.jpg
c:\program files\QIP\Users\477229318\Devils\406113816.jpg
c:\program files\QIP\Users\477229318\Devils\412020963.jpg
c:\program files\QIP\Users\477229318\Devils\414265376.jpg
c:\program files\QIP\Users\477229318\Devils\417916768.jpg
c:\program files\QIP\Users\477229318\Devils\419504310.jpg
c:\program files\QIP\Users\477229318\Devils\420668884.jpg
c:\program files\QIP\Users\477229318\Devils\424330781.jpg
c:\program files\QIP\Users\477229318\Devils\424433258.jpg
c:\program files\QIP\Users\477229318\Devils\426061177.jpg
c:\program files\QIP\Users\477229318\Devils\429399111.jpg
c:\program files\QIP\Users\477229318\Devils\429999017.jpg
c:\program files\QIP\Users\477229318\Devils\430259115.jpg
c:\program files\QIP\Users\477229318\Devils\432531808.jpg
c:\program files\QIP\Users\477229318\Devils\433264122.jpg
c:\program files\QIP\Users\477229318\Devils\434082602.jpg
c:\program files\QIP\Users\477229318\Devils\435184843.jpg
c:\program files\QIP\Users\477229318\Devils\437067773.jpg
c:\program files\QIP\Users\477229318\Devils\438776900.jpg
c:\program files\QIP\Users\477229318\Devils\439033233.jpg
c:\program files\QIP\Users\477229318\Devils\439820076.jpg
c:\program files\QIP\Users\477229318\Devils\442644223.jpg
c:\program files\QIP\Users\477229318\Devils\443358181.jpg
c:\program files\QIP\Users\477229318\Devils\445423528.jpg
c:\program files\QIP\Users\477229318\Devils\446124114.jpg
c:\program files\QIP\Users\477229318\Devils\447374678.jpg
c:\program files\QIP\Users\477229318\Devils\447791934.jpg
c:\program files\QIP\Users\477229318\Devils\450964174.jpg
c:\program files\QIP\Users\477229318\Devils\452151098.jpg
c:\program files\QIP\Users\477229318\Devils\452294342.jpg
c:\program files\QIP\Users\477229318\Devils\454320588.jpg
c:\program files\QIP\Users\477229318\Devils\454414656.jpg
c:\program files\QIP\Users\477229318\Devils\460114642.jpg
c:\program files\QIP\Users\477229318\Devils\462217766.jpg
c:\program files\QIP\Users\477229318\Devils\463892562.jpg
c:\program files\QIP\Users\477229318\Devils\470070522.jpg
c:\program files\QIP\Users\477229318\Devils\474556211.jpg
c:\program files\QIP\Users\477229318\Devils\477229318.jpg
c:\program files\QIP\Users\477229318\Devils\477232147.jpg
c:\program files\QIP\Users\477229318\Devils\482533244.jpg
c:\program files\QIP\Users\477229318\Devils\482846250.jpg
c:\program files\QIP\Users\477229318\Devils\484627599.jpg
c:\program files\QIP\Users\477229318\Devils\492433895.jpg
c:\program files\QIP\Users\477229318\Devils\493524407.jpg
c:\program files\QIP\Users\477229318\Devils\493944587.jpg
c:\program files\QIP\Users\477229318\Devils\495115361.jpg
c:\program files\QIP\Users\477229318\Devils\497073463.jpg
c:\program files\QIP\Users\477229318\Devils\499983990.jpg
c:\program files\QIP\Users\477229318\Devils\597154603.jpg
c:\program files\QIP\Users\477229318\History\_srvlog.txt
c:\program files\QIP\Users\477229318\History\169939003.txt
c:\program files\QIP\Users\477229318\History\191044808.txt
c:\program files\QIP\Users\477229318\History\201150704.txt
c:\program files\QIP\Users\477229318\History\219135403.txt
c:\program files\QIP\Users\477229318\History\233941835.txt
c:\program files\QIP\Users\477229318\History\245997749.txt
c:\program files\QIP\Users\477229318\History\250994034.txt
c:\program files\QIP\Users\477229318\History\272702638.txt
c:\program files\QIP\Users\477229318\History\284295831.txt
c:\program files\QIP\Users\477229318\History\292033155.txt
c:\program files\QIP\Users\477229318\History\298820105.txt
c:\program files\QIP\Users\477229318\History\307932779.txt
c:\program files\QIP\Users\477229318\History\317886817.txt
c:\program files\QIP\Users\477229318\History\345331945.txt
c:\program files\QIP\Users\477229318\History\345862661.txt
c:\program files\QIP\Users\477229318\History\350119005.txt
c:\program files\QIP\Users\477229318\History\356005445.txt
c:\program files\QIP\Users\477229318\History\356769703.txt
c:\program files\QIP\Users\477229318\History\357011796.txt
c:\program files\QIP\Users\477229318\History\362216105.txt
c:\program files\QIP\Users\477229318\History\364337216.txt
c:\program files\QIP\Users\477229318\History\368619818.txt
c:\program files\QIP\Users\477229318\History\380125930.txt
c:\program files\QIP\Users\477229318\History\381082161.txt
c:\program files\QIP\Users\477229318\History\381561034.txt
c:\program files\QIP\Users\477229318\History\381927209.txt
c:\program files\QIP\Users\477229318\History\383320712.txt
c:\program files\QIP\Users\477229318\History\384971199.txt
c:\program files\QIP\Users\477229318\History\386155825.txt
c:\program files\QIP\Users\477229318\History\387144850.txt
c:\program files\QIP\Users\477229318\History\399451063.txt
c:\program files\QIP\Users\477229318\History\409977084.txt
c:\program files\QIP\Users\477229318\History\412898306.txt
c:\program files\QIP\Users\477229318\History\416372408.txt
c:\program files\QIP\Users\477229318\History\419504310.txt
c:\program files\QIP\Users\477229318\History\419618359.txt
c:\program files\QIP\Users\477229318\History\420668884.txt
c:\program files\QIP\Users\477229318\History\424330781.txt
c:\program files\QIP\Users\477229318\History\424433258.txt
c:\program files\QIP\Users\477229318\History\425261776.txt
c:\program files\QIP\Users\477229318\History\426061177.txt
c:\program files\QIP\Users\477229318\History\429399111.txt
c:\program files\QIP\Users\477229318\History\429999017.txt
c:\program files\QIP\Users\477229318\History\430406566.txt
c:\program files\QIP\Users\477229318\History\430409661.txt
c:\program files\QIP\Users\477229318\History\431716705.txt
c:\program files\QIP\Users\477229318\History\432875197.txt
c:\program files\QIP\Users\477229318\History\438776900.txt
c:\program files\QIP\Users\477229318\History\439033233.txt
c:\program files\QIP\Users\477229318\History\441066144.txt
c:\program files\QIP\Users\477229318\History\442644223.txt
c:\program files\QIP\Users\477229318\History\445423528.txt
c:\program files\QIP\Users\477229318\History\447791934.txt
c:\program files\QIP\Users\477229318\History\448548061.txt
c:\program files\QIP\Users\477229318\History\452151098.txt
c:\program files\QIP\Users\477229318\History\454320588.txt
c:\program files\QIP\Users\477229318\History\454414656.txt
c:\program files\QIP\Users\477229318\History\460114642.txt
c:\program files\QIP\Users\477229318\History\460531353.txt
c:\program files\QIP\Users\477229318\History\465971194.txt
c:\program files\QIP\Users\477229318\History\470070522.txt
c:\program files\QIP\Users\477229318\History\474556211.txt
c:\program files\QIP\Users\477229318\History\477232147.txt
c:\program files\QIP\Users\477229318\History\482846250.txt
c:\program files\QIP\Users\477229318\History\483269838.txt
c:\program files\QIP\Users\477229318\History\493524407.txt
c:\program files\QIP\Users\477229318\History\495115361.txt
c:\program files\QIP\Users\477229318\History\495295084.txt
c:\program files\QIP\Users\477229318\History\497073463.txt
c:\program files\QIP\Users\477229318\RcvdFiles\284295831_Ristin\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\284295831_Ristin\wwi2epc2.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-_\253af0f.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-_\Bez Teba.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-_\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\Bez Teba.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\DSCF6212.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\DSCF6290.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\dzTC_4uPjd.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\dzTC_55XP6.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\H16 - Milujem.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_Velušenka _-{}\Tomas Bezdeda-krasne krasna.mp3
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_We.rush.Ka\DSCF4074.JPG
c:\program files\QIP\Users\477229318\RcvdFiles\356769703_We.rush.Ka\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\380125930_Paťas\Snímek pro Lukáše4.JPG
c:\program files\QIP\Users\477229318\RcvdFiles\380125930_Paťas\Thumbs.db
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\1.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\2.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\3.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\4.jpg
c:\program files\QIP\Users\477229318\RcvdFiles\454320588_Filoush\Thumbs.db
c:\program files\QIP\Users\482846250\_botq.txt
c:\program files\QIP\Users\482846250\_events.txt
c:\program files\QIP\Users\482846250\_eye.txt
c:\program files\QIP\Users\482846250\_groups.txt
c:\program files\QIP\Users\482846250\_m_away.txt
c:\program files\QIP\Users\482846250\_m_depr.txt
c:\program files\QIP\Users\482846250\_m_dnd.txt
c:\program files\QIP\Users\482846250\_m_evil.txt
c:\program files\QIP\Users\482846250\_m_ffc.txt
c:\program files\QIP\Users\482846250\_m_home.txt
c:\program files\QIP\Users\482846250\_m_lunch.txt
c:\program files\QIP\Users\482846250\_m_na.txt
c:\program files\QIP\Users\482846250\_m_occup.txt
c:\program files\QIP\Users\482846250\_m_work.txt
c:\program files\QIP\Users\482846250\_premsg.txt
c:\program files\QIP\Users\482846250\_st_away.txt
c:\program files\QIP\Users\482846250\_st_cust.txt
c:\program files\QIP\Users\482846250\482846250.cl
c:\program files\QIP\Users\482846250\482846250.clg
c:\program files\QIP\Users\482846250\482846250.cli
c:\program files\QIP\Users\482846250\482846250.clv
c:\program files\QIP\Users\482846250\482846250.lcl
c:\program files\QIP\Users\482846250\482846250.nil
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.cl
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.clg
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.cli
c:\program files\QIP\Users\482846250\BackupCL\482846250_2009_03.clv
c:\program files\QIP\Users\482846250\Config.ini
c:\program files\QIP\Users\482846250\Devils\422206483.jpg
c:\program files\QIP\Users\482846250\Devils\443982206.jpg
c:\program files\QIP\Users\482846250\Devils\482846250.jpg
c:\program files\QIP\Users\482846250\History\477229318.txt
c:\program files\QIP\Users\495115361\_botq.txt
c:\program files\QIP\Users\495115361\_events.txt
c:\program files\QIP\Users\495115361\_eye.txt
c:\program files\QIP\Users\495115361\_groups.txt
c:\program files\QIP\Users\495115361\_m_away.txt
c:\program files\QIP\Users\495115361\_m_depr.txt
c:\program files\QIP\Users\495115361\_m_dnd.txt
c:\program files\QIP\Users\495115361\_m_evil.txt
c:\program files\QIP\Users\495115361\_m_ffc.txt
c:\program files\QIP\Users\495115361\_m_home.txt
c:\program files\QIP\Users\495115361\_m_lunch.txt
c:\program files\QIP\Users\495115361\_m_na.txt
c:\program files\QIP\Users\495115361\_m_occup.txt
c:\program files\QIP\Users\495115361\_m_work.txt
c:\program files\QIP\Users\495115361\_premsg.txt
c:\program files\QIP\Users\495115361\_st_away.txt
c:\program files\QIP\Users\495115361\_st_cust.txt
c:\program files\QIP\Users\495115361\495115361.cl
c:\program files\QIP\Users\495115361\495115361.clg
c:\program files\QIP\Users\495115361\495115361.cli
c:\program files\QIP\Users\495115361\495115361.clv
c:\program files\QIP\Users\495115361\495115361.lcl
c:\program files\QIP\Users\495115361\495115361.nil
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.cl
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.clg
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.cli
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_08.clv
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.cl
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.clg
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.cli
c:\program files\QIP\Users\495115361\BackupCL\495115361_2009_10.clv
c:\program files\QIP\Users\495115361\Config.ini
c:\program files\QIP\Users\495115361\Devils\276820054.jpg
c:\program files\QIP\Users\495115361\Devils\356769703.jpg
c:\program files\QIP\Users\495115361\Devils\400958290.jpg
c:\program files\QIP\Users\495115361\Devils\408939515.jpg
c:\program files\QIP\Users\495115361\Devils\445423528.jpg
c:\program files\QIP\Users\495115361\Devils\477229318.jpg
c:\program files\QIP\Users\495115361\Devils\493524407.jpg
c:\program files\QIP\Users\495115361\Devils\560274160.jpg
c:\program files\QIP\Users\495115361\History\379542198.txt
c:\program files\QIP\Users\495115361\History\394295566.txt
c:\program files\QIP\Users\495115361\History\477229318.txt
c:\program files\QIP\Users\Accounts.cfg
c:\program files\QIP\Users\Config.ini
c:\program files\QIP\Users\Default.cfg

File::
k:\recycled\ctfmon.exe

Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{029961b7-3b1e-11d8-b2a6-806d6172696f}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{029961b8-3b1e-11d8-b2a6-806d6172696f}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e38e323-d3f9-11dd-adb6-000d879d9097}]
ulozte vami vytvoreny textovy soubor jako CFScript.txt na plochu

po ulozeni uchopte vami vytvoreny skript levym tlacitkem mysi a presunte jej nad ikonu Combofixu, nad niz skript upustte:

Obrázek

po aplikaci by na vas mel vybafnout dalsi log, vlozte jej sem :)

Upozorneni: je mozne, ze po aplikaci skriptu a restartu nenabehnou Windows, v takovem pripade znovu restartujte, po restartu mackejte F8 a zvolte Posledni znamou fukncni konfiguraci :)



Až budete mít tak stáhněte GMER , rozbalte a spustte

probehne sken, po jehoz ukonceni na vas bafnou vysledky

pote kliknete na Save a ulozite tak log, jehoz obsah sem vlozte

pote dle tohoto navodu absolvujte druhy sken a opet obsah logu sem :)

Re: Prosím o kontrolu

Napsal: 23 led 2010 09:21
od .:D.e.x.t.e.r:.
K je pro Flash disky a myslím, že i pro mobil...
ComboFix 10-01-18.01 - Lukas 23.01.2010 8:48.11.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.249 [GMT 1:00]
Spuštěný z: c:\documents and settings\Lukas\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Lukas\Plocha\CFScript.txt.txt
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
"k:\recycled\ctfmon.exe"
.

((((((((((((((((((((((((( Soubory vytvořené od 2009-12-23 do 2010-01-23 )))))))))))))))))))))))))))))))
.

2010-01-18 18:02 . 2010-01-18 18:02 390144 ----a-w- c:\windows\system32\CF8.exe
2010-01-18 17:55 . 2010-01-18 17:55 390144 ----a-w- c:\windows\system32\CF31391.exe
2010-01-13 12:40 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-03 13:58 . 2010-01-03 13:58 -------- d-----w- c:\program files\LogMeIn Hamachi

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-23 07:59 . 2008-10-22 15:06 -------- d-----w- c:\program files\DNA
2010-01-23 07:38 . 2010-01-23 07:38 121319 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2010_01_18_21_05_25_small.dmp.zip
2010-01-22 20:55 . 2008-08-13 18:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-21 15:01 . 2008-11-05 20:11 1193 -c--a-w- c:\windows\eReg.dat
2010-01-18 20:05 . 2010-01-23 07:38 296448 ----a-w- c:\windows\Internet Logs\xDB5.tmp
2010-01-18 18:21 . 2001-10-25 14:00 79242 ----a-w- c:\windows\system32\perfc005.dat
2010-01-18 18:21 . 2001-10-25 14:00 432278 ----a-w- c:\windows\system32\perfh005.dat
2010-01-16 20:45 . 2009-01-27 10:57 -------- d-----w- c:\program files\NewName
2010-01-16 20:34 . 2009-08-05 12:51 -------- d-----w- c:\program files\trend micro
2010-01-10 16:42 . 2010-01-10 16:43 2781696 ----a-w- c:\windows\Internet Logs\xDB4.tmp
2010-01-06 13:52 . 2008-11-25 17:21 -------- d-----w- c:\program files\Hamachi
2010-01-06 13:21 . 2003-12-30 23:26 -------- d-----w- c:\program files\Microsoft Works
2009-11-24 17:04 . 2009-11-24 17:04 78848 ----a-w- c:\windows\system32\drivers\SSHDRV85.sys
2009-11-24 15:15 . 2008-10-15 19:07 -------- d-----w- c:\program files\Yahoo!
2009-11-24 15:12 . 2009-03-25 18:46 -------- d-----w- c:\program files\OpenOffice.org 3
2009-11-24 15:05 . 2009-08-05 12:49 -------- d-----w- c:\program files\Online TV Player 4
2009-11-21 16:03 . 2004-08-17 14:49 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 20:32 . 2008-08-31 15:17 138352 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-18 20:32 . 2008-08-31 15:17 191304 -c--a-w- c:\windows\system32\PnkBstrB.exe
2009-11-18 15:10 . 2008-08-18 17:24 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-10-29 07:43 . 2004-08-17 14:49 916480 ------w- c:\windows\system32\wininet.dll
2009-10-28 07:30 . 2009-10-28 07:29 21371722 -c--a-w- c:\windows\Internet Logs\vsmon_on_demand_thread_2009_10_26_13_52_35_full.dmp.zip
2008-03-04 14:17 . 2008-10-28 13:36 65465 -c--a-w- c:\program files\Mount&Blade
2003-12-18 09:33 . 2009-02-21 08:42 20102 -c--a-w- c:\program files\Readme.txt
2003-09-03 05:46 . 2009-02-21 08:42 10960 -c--a-w- c:\program files\EULA.txt
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-03-19 1883672]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-03-19 16:56 1883672 ----a-w- c:\program files\free-downloads.net\tbfre0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-03-19 1883672]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-03-19 1883672]

[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"SetDefaultMIDI"="MIDIDef.exe" [2002-01-14 61440]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-07 323392]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 1079808]
"IDMan"="d:\idman\IDMan.exe" [2009-05-19 2811312]
"Google Update"="c:\documents and settings\Lukas\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-01-16 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 24576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-07 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-26 185896]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-01-19 221184]
"LogitechVideoRepair"="d:\program files\Logitech\Video\ISStart.exe" [2005-01-19 458752]
"LogitechVideoTray"="d:\program files\Logitech\Video\LogiTray.exe" [2005-01-19 217088]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-9 610365]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InvisibleBrowsing]
2007-02-02 10:13 917504 ----a-w- c:\program files\Invisible Browsing\InvisibleBrowsing.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-05-30 13:54 21718312 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Invisible Browsing\\InvisibleBrowsing.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"d:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [24.11.2009 18:04 78848]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29.10.2009 12:27 1074568]
S3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);c:\windows\system32\drivers\ctlsb16.sys [1.3.2009 15:08 96256]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [15.2.2007 18:48 26624]
S3 TVICHW32;TVICHW32;c:\windows\system32\drivers\TVICHW32.SYS [13.8.2008 20:34 23600]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.12.2003 0:05 717296]
.
Obsah adresáře 'Naplánované úlohy'

2009-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-01-23 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-01 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Download All by FlashGet - d:\program files\FlashGet\jc_all.htm
IE: Download using FlashGet - d:\program files\FlashGet\jc_link.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint - Náhled - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint - Přidat na seznam k tisku - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint - Tisk - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Easy-WebPrint - Vysokorychlostní tisk - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Stáhnout s IDM - d:\idman\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - d:\idman\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - d:\idman\IEGetAll.htm
LSP: c:\windows\system32\idmmbc.dll
Trusted Zone: icq.com\www
FF - ProfilePath - c:\documents and settings\Lukas\Data aplikací\Mozilla\Firefox\Profiles\auvp6y39.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\Lukas\Data aplikací\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-23 08:59
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys >>UNKNOWN [0x833D0500]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8527f28
\Driver\ACPI -> ACPI.sys @ 0xf849acb8
\Driver\atapi -> prosync1.sys @ 0xf89eb6c1
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
user & kernel MBR OK

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-2000478354-1965331169-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b4,49,e6,19,7b,e9,4d,63,25,76,bb,4e,2c,cd,f8,0a,49,8d,51,58,d6,
1b,b3,0a,66,4e,81,0d,f5,f5,4b,c2,11,18,05,71,f6,40,28,b4,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7b9ed357-6dbc-44dd-acd3-8ee3fd2f5b93}]
@Denied: (Full) (Everyone)
"Model"=dword:0000016c
"Therad"=dword:0000001c
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'lsass.exe'(844)
c:\windows\system32\idmmbc.dll

- - - - - - - > 'explorer.exe'(2920)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\UAService7.exe
c:\documents and settings\Lukas\Local Settings\Data aplikací\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Real\RealPlayer\RealPlay.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
d:\program files\Logitech\Video\FxSvr2.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
d:\idman\IEMonitor.exe
.
**************************************************************************
.
Celkový čas: 2010-01-23 09:09:04 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-23 08:08
ComboFix2.txt 2010-01-18 18:26
ComboFix3.txt 2009-08-07 08:03
ComboFix4.txt 2009-01-25 17:42
ComboFix5.txt 2010-01-23 07:39

Před spuštěním: 2 024 611 840
Po spuštění: 1 977 995 264

Current=14 Default=14 Failed=13 LastKnownGood=15 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15
- - End Of File - - 4EFDC40D42571BA26F46639A64A1D9E2

Re: Prosím o kontrolu

Napsal: 23 led 2010 11:55
od .:D.e.x.t.e.r:.
A tady je log z GMERu

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-23 11:48:41
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Lukas\LOCALS~1\Temp\uftdapow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwConnectPort [0xB88508D0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateFile [0xB884D6E0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateKey [0xB885A490]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreatePort [0xB8850E90]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xB8850F80]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xB884DC70]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteKey [0xB885AD10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0xB885AAC0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey [0xB885B230]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xB885B2B0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenFile [0xB884DAD0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRenameKey [0xB885B970]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xB885B3D0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xB88504F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xB885B7C0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xB884DEA0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetValueKey [0xB885A800]

---- Kernel code sections - GMER 1.0.15 ----

.xreloc C:\WINDOWS\system32\drivers\sfsync04.sys unknown last section [0xF8482000, 0xC5E, 0x40000040]
? Combo-Fix.sys Systém nemůže nalézt uvedený soubor. !
? srescan.sys Systém nemůže nalézt uvedený soubor. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xBA1BF360, 0x37388D, 0xE8000020]
.text C:\WINDOWS\system32\drivers\SSHDRV85.sys section is writeable [0xB8936000, 0x24A24, 0xE8000020]
.pklstb C:\WINDOWS\system32\drivers\SSHDRV85.sys entry point in ".pklstb" section [0xB8969000]
.relo2 C:\WINDOWS\system32\drivers\SSHDRV85.sys unknown last section [0xB897F000, 0x8E, 0x42000040]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB7C75300, 0x3AE88, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF87DB300, 0x1B7E, 0xE8000020]
? C:\ComboFix\catchme.sys Systém nemůže nalézt uvedenou cestu. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Systém nemůže nalézt uvedený soubor. !

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisOpenAdapter] [B8855220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisCloseAdapter] [B8855B50] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisDeregisterProtocol] [B8853780] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisRegisterProtocol] [B8855410] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [B8855410] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [B8855220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [B8855B50] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [B8853780] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [B8853780] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [B8855410] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [B8855220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [B8855B50] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [B8855410] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [B8853780] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [B8855B50] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [B8855220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [B8855B50] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [B8855220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [B8855410] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [B885D870] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [B8853780] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [B8855410] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [B8855220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [B8855B50] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [B8855410] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [B8853780] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [B8855B50] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [B8855220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [B884E320] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [B884E4D0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [B884E040] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [B884E3D0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

---- Devices - GMER 1.0.15 ----

Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\prodrv06 \Device\ProDrv06 E21A2008
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\prohlp02 \Device\ProHlp02 E1CBFB78
Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xED 0x3B 0xEE 0xA1 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xE7 0xA1 0xE0 0x3D ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x63 0xA0 0x37 0xEB ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x8E 0x45 0x6F 0xFB ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xF5 0x29 0xCE 0xBC ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x50 0xE4 0xC2 0x6F ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x06 0x7E 0xE1 0x4A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB5 0xBC 0x71 0x49 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x44 0xD9 0x5F 0xA0 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x64 0xB9 0x37 0xB4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x8D 0xD2 0xF2 0x83 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xD1 0x76 0xDF 0xDD ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x56 0x62 0xDA 0xE9 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB5 0xBC 0x71 0x49 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x44 0xD9 0x5F 0xA0 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x64 0xB9 0x37 0xB4 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x8D 0xD2 0xF2 0x83 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xD1 0x76 0xDF 0xDD ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x56 0x62 0xDA 0xE9 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB5 0xBC 0x71 0x49 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x44 0xD9 0x5F 0xA0 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x64 0xB9 0x37 0xB4 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x8D 0xD2 0xF2 0x83 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xD1 0x76 0xDF 0xDD ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x56 0x62 0xDA 0xE9 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD3 0x8C 0xEB 0xD1 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xF5 0x29 0xCE 0xBC ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x50 0xE4 0xC2 0x6F ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x06 0x7E 0xE1 0x4A ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA5 0x48 0x5F 0xB3 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x3B 0x47 0xA8 0xF6 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x02 0x07 0x91 0x0B ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x06 0x7E 0xE1 0x4A ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x78 0x5B 0x0D 0x19 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x21 0xB9 0x45 0xD4 ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x02 0x07 0x91 0x0B ...
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x06 0x7E 0xE1 0x4A ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x78 0x5B 0x0D 0x19 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x21 0xB9 0x45 0xD4 ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x02 0x07 0x91 0x0B ...
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x06 0x7E 0xE1 0x4A ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x78 0x5B 0x0D 0x19 ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xD9 0x60 0x29 0x3E ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x02 0x07 0x91 0x0B ...
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x06 0x7E 0xE1 0x4A ...
Reg HKLM\SYSTEM\ControlSet011\Services\msqpdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet011\Services\msqpdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet011\Services\msqpdxserv.sys@imagepath \systemroot\system32\drivers\msqpdxnomykmoy.sys
Reg HKLM\SYSTEM\ControlSet011\Services\msqpdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet011\Services\msqpdxserv.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\msqpdxserv.sys\modules@msqpdxserv \\?\globalroot\systemroot\system32\drivers\msqpdxnomykmoy.sys
Reg HKLM\SYSTEM\ControlSet011\Services\msqpdxserv.sys\modules@msqpdxl \\?\globalroot\systemroot\system32\msqpdxhwvmttkk.dll
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x85 0xE4 0xB7 0x1A ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x62 0xDC 0xB3 0x2C ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x0D 0xA3 0x75 0x7E ...
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xE0 0xE7 0x96 0x4F ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x66 0x2B 0xC9 0x3D ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x62 0xDC 0xB3 0x2C ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x0D 0xA3 0x75 0x7E ...
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xE0 0xE7 0x96 0x4F ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x74 0x31 0x6E 0x02 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xCF 0x3B 0x63 0x1D ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xD7 0x28 0x77 0x41 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x53 0xD1 0xD1 0x86 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x7D 0x22 0xF8 0xDA ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x62 0xDC 0xB3 0x2C ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x0D 0xA3 0x75 0x7E ...
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xE0 0xE7 0x96 0x4F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE4 0x22 0x02 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF5 0xF2 0x49 0x5B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF1 0xFA 0x3D 0xE3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xCA 0xFD 0x69 0x49 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x02 0x95 0xAC 0x18 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xDF 0x01 0xEB 0x4B ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xE4 0x22 0x02 0x0F ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xF5 0xF2 0x49 0x5B ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x99 0x8A 0x01 0x93 ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF1 0xFA 0x3D 0xE3 ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xCA 0xFD 0x69 0x49 ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x02 0x95 0xAC 0x18 ...
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xDF 0x01 0xEB 0x4B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}@scansk 0xB4 0x49 0xE6 0x19 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7b9ed357-6dbc-44dd-acd3-8ee3fd2f5b93}@Model 364
Reg HKLM\SOFTWARE\Classes\CLSID\{7b9ed357-6dbc-44dd-acd3-8ee3fd2f5b93}@Therad 28
Reg HKLM\SOFTWARE\Classes\CLSID\{7b9ed357-6dbc-44dd-acd3-8ee3fd2f5b93}@MData 0x73 0xD5 0xCF 0xB8 ...

---- EOF - GMER 1.0.15 ----

Re: Prosím o kontrolu

Napsal: 23 led 2010 14:17
od Marek-26
Tak žádné viry nevidím :) Provedeme tedy dočištění PC. Udělejte ještě jednou CFScript :wink:

Kód: Vybrat vše

KillAll::
FixCSet::
RegLock::
[HKEY_USERS\S-1-5-21-2000478354-1965331169-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7b9ed357-6dbc-44dd-acd3-8ee3fd2f5b93}]
Poté vložte log zase sem :)