Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o preventivku

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
ΛGΣNГ
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 383
Registrován: 14 zář 2009 16:45
Bydliště: Rokytnice nad Jizerou (ČR)

Prosím o preventivku

#1 Příspěvek od ΛGΣNГ »

Ahoj, jsem na PC kamose ktery rozesila rusky psany SPAM :) . Nevím jestli má legální OS tak by se mi to taky hodilo vedet.
Zde je log z RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Lynx at 2010-01-20 14:32:35
Microsoft Windows XP Home Edition Service Pack 1
System drive C: has 8 GB (10%) free of 76 GB
Total RAM: 256 MB (28% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:33:08, on 20.1.2010
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Lynx\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Lynx.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://free.bluetone.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no file)
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTor1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [NvCplScan] nvsc32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Securety] wurguar.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [snapple] snapple.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [NvCplScan] nvsc32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [NvCplScan] nvsc32.exe (User 'Default user')
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: ICQ Lite - {E59EB121-F339-4851-A3BA-FE49C35617C2} - ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {E59EB121-F339-4851-A3BA-FE49C35617C2} - ICQ.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://free.bluetone.cz/
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3206556125
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A46B132-AB20-46B2-A288-547A8EDD7FD6}: NameServer = 212.158.128.2,212.158.128.3
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe

--
End of file - 8997 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-11-18 333192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7c5c0f58-e061-457d-9033-77307f5ed00c}]
TorrentMan Toolbar - C:\Program Files\TorrentMan\tbTor1.dll [2009-09-24 2215960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}]
BAHelper Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2008-10-08 1172792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{FAA356E4-D317-42a6-AB41-A3021C6E7D52}
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\TRANSL~1\WEBIE.DLL [2005-12-03 315392]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINDOWS\System32\msdxm.ocx [2003-04-16 844828]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Foxit Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-11-18 333192]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2008-10-08 1172792]
{7c5c0f58-e061-457d-9033-77307f5ed00c} - TorrentMan Toolbar - C:\Program Files\TorrentMan\tbTor1.dll [2009-09-24 2215960]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2004-02-04 2899968]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2004-02-04 46080]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2006-11-24 487424]
"DAEMON Tools-1033"=C:\Program Files\D-Tools\daemon.exe [2004-08-22 81920]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-04-26 111928]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2007-02-21 366400]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\System32\ctfmon.exe [2003-04-16 13312]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-06-02 1957888]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2008-02-22 217544]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe /s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\System32\ctfmon.exe [2003-04-16 13312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd.exe [2003-08-04 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Update]
lsac.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplScan]
nvsc32.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snapple]
snapple.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2003-09-16 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^okay^Nabídka Start^Programy^Po spuštění^PowerReg Scheduler.exe]
C:\Documents and Settings\okay\Nabídka Start\Programy\Po spuštění\PowerReg Scheduler.exe []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2010-01-20 14:32:37 ----D---- C:\Program Files\trend micro
2010-01-20 14:32:35 ----D---- C:\rsit
2010-01-20 14:17:21 ----D---- C:\Program Files\CCleaner
2010-01-20 14:10:07 ----A---- C:\WINDOWS\game.ini
2010-01-12 16:23:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-01-12 16:22:28 ----D---- C:\Program Files\Picasa2
2010-01-11 15:03:33 ----D---- C:\Program Files\Jump Mario 2
2010-01-08 19:55:01 ----D---- C:\Program Files\THQ
2010-01-08 14:24:52 ----A---- C:\WINDOWS\UnGins.exe
2010-01-08 14:24:50 ----D---- C:\Program Files\Blondes Xonix
2010-01-07 15:13:38 ----D---- C:\Program Files\ElastoManiaRegistered
2010-01-06 17:17:58 ----D---- C:\Program Files\GameTop.com
2010-01-06 17:16:21 ----D---- C:\Program Files\XMoto
2010-01-03 14:14:24 ----D---- C:\PC TRANSLATOR DEMO
2010-01-03 14:14:19 ----D---- C:\Documents and Settings\Lynx\Data aplikací\LangSoft
2010-01-03 14:14:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\LangSoft
2010-01-01 11:23:37 ----D---- C:\Program Files\GamersFirst
2009-12-31 12:28:30 ----D---- C:\Program Files\EA GAMES
2009-12-31 12:21:50 ----D---- C:\NFSMWDemo
2009-12-30 14:49:51 ----A---- C:\WINDOWS\System32\mpg4dmod.dll
2009-12-29 14:56:08 ----D---- C:\Program Files\Codemasters
2009-12-29 13:02:45 ----D---- C:\Program Files\Mad Skills Motocross Demo
2009-12-27 13:08:12 ----D---- C:\Program Files\MyPlayCity.com

======List of files/folders modified in the last 1 months======

2010-01-20 14:32:37 ----D---- C:\Program Files
2010-01-20 14:27:22 ----D---- C:\Program Files\Mozilla Firefox
2010-01-20 14:25:20 ----D---- C:\Documents and Settings\Lynx\Data aplikací\Skype
2010-01-20 14:24:34 ----D---- C:\WINDOWS\Temp
2010-01-20 14:23:16 ----D---- C:\Documents and Settings\Lynx\Data aplikací\skypePM
2010-01-20 14:19:26 ----SHD---- C:\WINDOWS\Installer
2010-01-20 14:19:26 ----SHD---- C:\Config.Msi
2010-01-20 14:19:24 ----D---- C:\Program Files\Google
2010-01-20 14:18:08 ----D---- C:\WINDOWS\Minidump
2010-01-20 14:18:08 ----D---- C:\WINDOWS\Debug
2010-01-20 14:18:08 ----D---- C:\WINDOWS
2010-01-20 14:00:04 ----D---- C:\WINDOWS\Prefetch
2010-01-20 08:32:06 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-01-19 17:08:05 ----SHD---- C:\RECYCLER
2010-01-19 17:06:15 ----D---- C:\Documents and Settings
2010-01-19 16:14:49 ----D---- C:\WINDOWS\System32\CatRoot2
2010-01-18 17:00:35 ----D---- C:\Program Files\ICQ6Toolbar
2010-01-18 16:53:11 ----D---- C:\Documents and Settings\Lynx\Data aplikací\ICQ
2010-01-18 16:51:18 ----D---- C:\Program Files\Common Files
2010-01-18 16:51:09 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-18 16:50:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-01-17 17:31:13 ----A---- C:\WINDOWS\win.ini
2010-01-16 19:32:48 ----A---- C:\WINDOWS\WTRAN32.INI
2010-01-12 16:37:30 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-12 16:21:06 ----D---- C:\Program Files\Common Files\eSellerate
2010-01-11 11:43:15 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-11 11:43:15 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-11 11:43:14 ----D---- C:\WINDOWS\system32
2010-01-11 11:43:12 ----D---- C:\WINDOWS\LastGood
2010-01-11 07:58:46 ----D---- C:\Program Files\AskBarDis
2010-01-08 19:46:05 ----D---- C:\Program Files\Activision
2010-01-08 19:37:20 ----RSD---- C:\WINDOWS\assembly
2010-01-08 19:37:05 ----HD---- C:\WINDOWS\inf
2010-01-08 19:36:12 ----D---- C:\WINDOWS\System32\DirectX
2010-01-08 14:27:29 ----D---- C:\Games
2010-01-08 14:27:03 ----A---- C:\WINDOWS\wincmd.ini
2010-01-03 16:06:43 ----D---- C:\Program Files\Ubisoft
2010-01-03 13:35:34 ----D---- C:\Program Files\ICQ6.5
2010-01-01 13:14:57 ----D---- C:\WINDOWS\System32\drivers
2010-01-01 09:01:52 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-01 09:01:50 ----D---- C:\Program Files\IKEA HomePlanner
2009-12-30 14:51:46 ----D---- C:\WINDOWS\System32\CatRoot
2009-12-30 14:49:51 ----RSHDC---- C:\WINDOWS\System32\dllcache
2009-12-30 14:49:47 ----D---- C:\Program Files\Windows Media Player
2009-12-28 10:19:00 ----D---- C:\Program Files\Microsoft Games
2009-12-23 13:00:13 ----A---- C:\WINDOWS\System32\CmdLineExt.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\System32\drivers\AFS2K.sys [2004-12-25 43488]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-01-26 52224]
R2 atksgt;atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [2008-08-26 165376]
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 lirsgt;lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [2008-08-26 18048]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-02-04 1878432]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\System32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 578368]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2003-04-16 19328]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2003-04-16 51968]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2003-04-16 19328]
R4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\System32\DRIVERS\sr.sys [2003-04-16 69120]
S3 agf5xsdf;agf5xsdf; C:\WINDOWS\System32\drivers\agf5xsdf.sys []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-14 404736]
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-08-21 462940]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\System32\drivers\EagleNT.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\System32\DRIVERS\hamachi.sys [2008-11-07 25280]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2004-01-05 51056]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2004-01-05 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2004-01-05 21488]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 se46bus;Sony Ericsson Device 070 driver (WDM); C:\WINDOWS\System32\DRIVERS\se46bus.sys [2006-11-30 61536]
S3 se46mdfl;Sony Ericsson Device 070 USB WMC Modem Filter; C:\WINDOWS\System32\DRIVERS\se46mdfl.sys [2006-11-30 9360]
S3 se46mdm;Sony Ericsson Device 070 USB WMC Modem Driver; C:\WINDOWS\System32\DRIVERS\se46mdm.sys [2006-11-30 97088]
S3 se46mgmt;Sony Ericsson Device 070 USB WMC Device Management Drivers (WDM); C:\WINDOWS\System32\DRIVERS\se46mgmt.sys [2006-11-30 88624]
S3 se46nd5;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\System32\DRIVERS\se46nd5.sys [2006-11-30 18704]
S3 se46obex;Sony Ericsson Device 070 USB WMC OBEX Interface; C:\WINDOWS\System32\DRIVERS\se46obex.sys [2006-11-30 86432]
S3 se46unic;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\System32\DRIVERS\se46unic.sys [2006-11-30 90800]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2002-08-29 28160]
S3 usbprint;Třída USB Printer; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2002-08-29 24960]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2002-08-29 14208]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 21760]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 Z550bus;Sony Ericsson Z550 driver (WDM); C:\WINDOWS\System32\DRIVERS\Z550bus.sys [2006-03-13 60800]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2004-02-04 77824]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\System32\PnkBstrA.exe [2008-10-27 66872]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912]
S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:\WINDOWS\system32\sfrem01.exe [2006-05-10 353912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 GoogleDesktopManager;GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-01-12 1838592]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-12 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2004-01-05 65795]
S3 TUWinStylerThemeSvc;TuneUp WinStyler Theme Service; C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe [2005-08-10 118272]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#2 Příspěvek od Caroprd111 »

Zdravím :)

:arrow: Doinstalujte SP3 http://www.viry.cz/forum/viewtopic.php?f=46&t=86100

:arrow: V logu nevidím antivir a firewall, doinstalujte :!: http://www.viry.cz/forum/viewtopic.php?f=29&t=6152 + http://www.viry.cz/forum/viewtopic.php?f=41&t=6523

:arrow: Doporučuji odinstalovat (pokud nepoužíváte) toolbary (lišty) v Přidat nebo odebrat programy.

Až provedete tyto úkony, vložte sem nový log z RSIT a budeme pokračovat :)
Obrázek

ΛGΣNГ
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 383
Registrován: 14 zář 2009 16:45
Bydliště: Rokytnice nad Jizerou (ČR)

Re: Prosím o preventivku

#3 Příspěvek od ΛGΣNГ »

Systém je legální ? Jinak na ostatních se už pracuje ale u FW nevidim moznost ze by to kamos pochopil :D :!:
Ten SP 3 se asi bude stahovat dlouho ale snazim se. Jinak diky ze nam pomuzes (mne uz nebavi dostavat od nej SPAM :) ).

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#4 Příspěvek od Caroprd111 »

:arrow: Jestli je systém legální vám nemohu říct, většinou to v logu není poznat.

:arrow: Ještě odinstalujte jeden z emulátorů virtuálních mechanik, máte tam Alcohol a DAEMON Tools. Kombinace obou se nedoporučuje.

Firewall určitě pochopí :)
Obrázek

ΛGΣNГ
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 383
Registrován: 14 zář 2009 16:45
Bydliště: Rokytnice nad Jizerou (ČR)

Re: Prosím o preventivku

#5 Příspěvek od ΛGΣNГ »

Tak alkohol jsem odinstaloval, ani nevedel ze ho tam ma :D . Vzkazuje ze FW urcite nepochopi ( prakticky nevi co to je :roll: ) a kdybych mu to vysvetlil tak to do tydne zapomene. To by musel byt nejaky sakra jednoduch FW.

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#6 Příspěvek od Caroprd111 »

Firewall nic složitého není :)

V této sekci http://www.viry.cz/forum/viewforum.php?f=41 jsou pěkné návody na nastavení.
Obrázek

ΛGΣNГ
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 383
Registrován: 14 zář 2009 16:45
Bydliště: Rokytnice nad Jizerou (ČR)

Re: Prosím o preventivku

#7 Příspěvek od ΛGΣNГ »

Ten SP 3 bych preskocil, zapnul jsem mu totiz automaticke aktualizace a ma to teprv 7% :D . Av by tam uz mnel byt a FW vyberu az na to bude cas. Hned udelam log z RSIT (pokud muzu).

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#8 Příspěvek od Caroprd111 »

Ano můžete, hlavně, že stahujete aktualizace :)
Obrázek

ΛGΣNГ
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 383
Registrován: 14 zář 2009 16:45
Bydliště: Rokytnice nad Jizerou (ČR)

Re: Prosím o preventivku

#9 Příspěvek od ΛGΣNГ »

Tak se snazim co jde, testuji ted PC antivirem. Tady je log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Lynx at 2010-01-20 17:07:48
Microsoft Windows XP Home Edition Service Pack 1
System drive C: has 11 GB (15%) free of 76 GB
Total RAM: 256 MB (29% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:09:27, on 20.1.2010
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Avira\AntiVir Desktop\avscan.exe
C:\WINDOWS\SoftwareDistribution\Download\aa3a5f4ef5110dbd852184d98c07b61a\update\update.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Lynx\Plocha\RSIT.exe
C:\Program Files\trend micro\Lynx.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://free.bluetone.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no file)
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [NvCplScan] nvsc32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Securety] wurguar.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [snapple] snapple.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [NvCplScan] nvsc32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [NvCplScan] nvsc32.exe (User 'Default user')
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\TRANSL~1\WEBIE.DLL
O9 - Extra button: ICQ Lite - {E59EB121-F339-4851-A3BA-FE49C35617C2} - ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {E59EB121-F339-4851-A3BA-FE49C35617C2} - ICQ.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://free.bluetone.cz/
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3206556125
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A46B132-AB20-46B2-A288-547A8EDD7FD6}: NameServer = 212.158.128.2,212.158.128.3
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe

--
End of file - 8391 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7c5c0f58-e061-457d-9033-77307f5ed00c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}]
BAHelper Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{FAA356E4-D317-42a6-AB41-A3021C6E7D52}
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\TRANSL~1\WEBIE.DLL [2005-12-03 315392]
{8E718888-423F-11D2-876E-00A0C9082467} - &Rádio - C:\WINDOWS\System32\msdxm.ocx [2003-04-16 844828]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2004-02-04 2899968]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2004-02-04 46080]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2006-11-24 487424]
"DAEMON Tools-1033"=C:\Program Files\D-Tools\daemon.exe [2004-08-22 81920]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2007-02-21 366400]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\System32\ctfmon.exe [2003-04-16 13312]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-06-02 1957888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe /s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\System32\ctfmon.exe [2003-04-16 13312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd.exe [2003-08-04 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Update]
lsac.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplScan]
nvsc32.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snapple]
snapple.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2003-09-16 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^okay^Nabídka Start^Programy^Po spuštění^PowerReg Scheduler.exe]
C:\Documents and Settings\okay\Nabídka Start\Programy\Po spuštění\PowerReg Scheduler.exe []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2010-01-20 15:50:22 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\~0
2010-01-20 15:34:17 ----A---- C:\WINDOWS\System32\wucltui.dll.mui
2010-01-20 15:34:16 ----A---- C:\WINDOWS\System32\wuaueng.dll.mui
2010-01-20 15:34:15 ----A---- C:\WINDOWS\System32\wuapi.dll.mui
2010-01-20 14:45:17 ----D---- C:\Program Files\Avira
2010-01-20 14:45:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-01-20 14:32:37 ----D---- C:\Program Files\trend micro
2010-01-20 14:32:35 ----D---- C:\rsit
2010-01-20 14:17:21 ----D---- C:\Program Files\CCleaner
2010-01-20 14:10:07 ----A---- C:\WINDOWS\game.ini
2010-01-12 16:23:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-01-12 16:22:28 ----D---- C:\Program Files\Picasa2
2010-01-08 19:55:01 ----D---- C:\Program Files\THQ
2010-01-08 14:24:52 ----A---- C:\WINDOWS\UnGins.exe
2010-01-08 14:24:50 ----D---- C:\Program Files\Blondes Xonix
2010-01-07 15:13:38 ----D---- C:\Program Files\ElastoManiaRegistered
2010-01-03 14:14:24 ----D---- C:\PC TRANSLATOR DEMO
2010-01-03 14:14:19 ----D---- C:\Documents and Settings\Lynx\Data aplikací\LangSoft
2010-01-03 14:14:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\LangSoft
2010-01-01 11:23:37 ----D---- C:\Program Files\GamersFirst
2009-12-31 12:28:30 ----D---- C:\Program Files\EA GAMES
2009-12-31 12:21:50 ----D---- C:\NFSMWDemo
2009-12-30 14:49:51 ----A---- C:\WINDOWS\System32\mpg4dmod.dll
2009-12-29 14:56:08 ----D---- C:\Program Files\Codemasters
2009-12-29 13:02:45 ----D---- C:\Program Files\Mad Skills Motocross Demo
2009-12-27 13:08:12 ----D---- C:\Program Files\MyPlayCity.com

======List of files/folders modified in the last 1 months======

2010-01-20 16:54:20 ----D---- C:\WINDOWS\Temp
2010-01-20 16:52:33 ----D---- C:\WINDOWS
2010-01-20 16:52:06 ----D---- C:\WINDOWS\System32\CatRoot2
2010-01-20 16:43:23 ----D---- C:\Program Files\Mozilla Firefox
2010-01-20 16:42:18 ----HD---- C:\WINDOWS\inf
2010-01-20 16:41:16 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-20 16:26:52 ----A---- C:\WINDOWS\wincmd.ini
2010-01-20 16:26:46 ----SHD---- C:\WINDOWS\Installer
2010-01-20 16:26:46 ----SHD---- C:\Config.Msi
2010-01-20 16:26:45 ----D---- C:\Program Files
2010-01-20 16:25:16 ----D---- C:\WINDOWS\System32\drivers
2010-01-20 16:25:12 ----DC---- C:\WINDOWS\System32\DRVSTORE
2010-01-20 16:12:06 ----D---- C:\WINDOWS\Debug
2010-01-20 16:09:43 ----D---- C:\WINDOWS\system32
2010-01-20 16:08:59 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-20 16:04:06 ----D---- C:\Program Files\SeeMePlayMe
2010-01-20 16:00:22 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-20 15:56:16 ----D---- C:\Program Files\Winamp
2010-01-20 15:40:56 ----D---- C:\WINDOWS\LastGood
2010-01-20 15:35:10 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-20 15:35:06 ----D---- C:\WINDOWS\Help
2010-01-20 15:34:16 ----RSHDC---- C:\WINDOWS\System32\dllcache
2010-01-20 15:29:24 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-20 14:47:55 ----D---- C:\Program Files\Google
2010-01-20 14:44:35 ----D---- C:\WINDOWS\WinSxS
2010-01-20 14:25:20 ----D---- C:\Documents and Settings\Lynx\Data aplikací\Skype
2010-01-20 14:23:16 ----D---- C:\Documents and Settings\Lynx\Data aplikací\skypePM
2010-01-20 14:18:08 ----D---- C:\WINDOWS\Minidump
2010-01-20 14:00:04 ----D---- C:\WINDOWS\Prefetch
2010-01-19 17:08:05 ----SHD---- C:\RECYCLER
2010-01-19 17:06:15 ----D---- C:\Documents and Settings
2010-01-18 17:00:35 ----D---- C:\Program Files\ICQ6Toolbar
2010-01-18 16:53:11 ----D---- C:\Documents and Settings\Lynx\Data aplikací\ICQ
2010-01-18 16:51:18 ----D---- C:\Program Files\Common Files
2010-01-18 16:50:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2010-01-17 17:31:13 ----A---- C:\WINDOWS\win.ini
2010-01-16 19:32:48 ----A---- C:\WINDOWS\WTRAN32.INI
2010-01-12 16:37:30 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-12 16:21:06 ----D---- C:\Program Files\Common Files\eSellerate
2010-01-08 19:46:05 ----D---- C:\Program Files\Activision
2010-01-08 19:37:23 ----D---- C:\WINDOWS\System32\DirectX
2010-01-08 19:37:20 ----RSD---- C:\WINDOWS\assembly
2010-01-08 14:27:29 ----D---- C:\Games
2010-01-03 16:06:43 ----D---- C:\Program Files\Ubisoft
2010-01-03 13:35:34 ----D---- C:\Program Files\ICQ6.5
2010-01-01 09:01:52 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-01 09:01:50 ----D---- C:\Program Files\IKEA HomePlanner
2009-12-30 14:51:46 ----D---- C:\WINDOWS\System32\CatRoot
2009-12-30 14:49:47 ----D---- C:\Program Files\Windows Media Player
2009-12-28 10:19:00 ----D---- C:\Program Files\Microsoft Games
2009-12-23 13:00:13 ----A---- C:\WINDOWS\System32\CmdLineExt.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\System32\drivers\AFS2K.sys [2004-12-25 43488]
R1 avgntdd;avgntdd; C:\WINDOWS\SYSTEM32\DRIVERS\avgntdd.sys [2009-02-13 45416]
R1 avipbb;avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-01-26 52224]
R1 ssmdrv;ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 atksgt;atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [2008-08-26 165376]
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 lirsgt;lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [2008-08-26 18048]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-02-04 1878432]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\System32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 578368]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2003-04-16 19328]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2003-04-16 51968]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2003-04-16 19328]
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-14 404736]
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-08-21 462940]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\System32\drivers\EagleNT.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\System32\DRIVERS\hamachi.sys [2008-11-07 25280]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2004-01-05 51056]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2004-01-05 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2004-01-05 21488]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 se46bus;Sony Ericsson Device 070 driver (WDM); C:\WINDOWS\System32\DRIVERS\se46bus.sys [2006-11-30 61536]
S3 se46mdfl;Sony Ericsson Device 070 USB WMC Modem Filter; C:\WINDOWS\System32\DRIVERS\se46mdfl.sys [2006-11-30 9360]
S3 se46mdm;Sony Ericsson Device 070 USB WMC Modem Driver; C:\WINDOWS\System32\DRIVERS\se46mdm.sys [2006-11-30 97088]
S3 se46mgmt;Sony Ericsson Device 070 USB WMC Device Management Drivers (WDM); C:\WINDOWS\System32\DRIVERS\se46mgmt.sys [2006-11-30 88624]
S3 se46nd5;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\System32\DRIVERS\se46nd5.sys [2006-11-30 18704]
S3 se46obex;Sony Ericsson Device 070 USB WMC OBEX Interface; C:\WINDOWS\System32\DRIVERS\se46obex.sys [2006-11-30 86432]
S3 se46unic;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\System32\DRIVERS\se46unic.sys [2006-11-30 90800]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2002-08-29 28160]
S3 usbprint;Třída USB Printer; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2002-08-29 24960]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2002-08-29 14208]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 21760]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 Z550bus;Sony Ericsson Z550 driver (WDM); C:\WINDOWS\System32\DRIVERS\Z550bus.sys [2006-03-13 60800]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\System32\DRIVERS\sr.sys [2003-04-16 69120]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2004-02-04 77824]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\System32\PnkBstrA.exe [2008-10-27 66872]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912]
S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:\WINDOWS\system32\sfrem01.exe [2006-05-10 353912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 GoogleDesktopManager;GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-01-12 1838592]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-12 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2004-01-05 65795]
S3 TUWinStylerThemeSvc;TuneUp WinStyler Theme Service; C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe [2005-08-10 118272]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#10 Příspěvek od Caroprd111 »

OK, podívám se na to :)
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#11 Příspěvek od Caroprd111 »

Ještě poprosím o log z ComboFix:

:arrow: Odinstalujte Daemon tools

:arrow: Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe

:arrow: Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary

:arrow: Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrází stránka s licenčnímy podmínkami, pokračujte stisknutím tlačítka "Ano"

:arrow: Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:

:arrow: Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.

:arrow: Během skenování může být počítač restartován.
Obrázek

ΛGΣNГ
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 383
Registrován: 14 zář 2009 16:45
Bydliště: Rokytnice nad Jizerou (ČR)

Re: Prosím o preventivku

#12 Příspěvek od ΛGΣNГ »

Dnes už budu muset koncit, s kanosem se domluvim a bude delat vse co bude potreba. Zitra budu pokracovat. Zatim diky!

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#13 Příspěvek od Caroprd111 »

OK, jen doplním, že Daemon tools si po dokončení léčení můžete znovu nainstalovat.

Není zač :)
Obrázek

ΛGΣNГ
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 383
Registrován: 14 zář 2009 16:45
Bydliště: Rokytnice nad Jizerou (ČR)

Re: Prosím o preventivku

#14 Příspěvek od ΛGΣNГ »

Tak tady je log z Combofix:

ComboFix 10-01-19.08 - Lynx 20.01.2010 18:46:32.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.1.1250.420.1029.18.256.56 [GMT 1:00]
Spuštěný z: c:\documents and settings\Lynx\Plocha\ComboFix.exe
.
/wow section - STAGE 4
play.lnk není názvem vnitřního ani vnějšího příkazu
ECHOhdahc.drv není názvem vnitřního ani vnějšího příkazu
play.lnk není názvem vnitřního ani vnějšího příkazu
Malware není názvem vnitřního ani vnějšího příkazu
play.lnk není názvem vnitřního ani vnějšího příkazu
Malware není názvem vnitřního ani vnějšího příkazu
play.lnk není názvem vnitřního ani vnějšího příkazu
play.lnk není názvem vnitřního ani vnějšího příkazu


((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\data
c:\data\Bitmaps.dat
c:\data\error.txt
c:\documents and settings\Lynx\Dokumenty\01.reg
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\program files\ICQ6.5\ICQLRun.exe
c:\recycler\S-1-5-21-2587936551-162025716-2501954535-1006
c:\windows\jestertb.dll
c:\windows\system\oeminfo.ini
c:\windows\system32\ieuinit.inf
c:\windows\system32\SIntf16.dll

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NVCPLSCAN


((((((((((((((((((((((((( Soubory vytvořené od 2009-12-20 do 2010-01-20 )))))))))))))))))))))))))))))))
.

2010-01-20 16:49 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-20 16:42 . 2010-01-20 16:42 -------- d-----w- c:\program files\Lavasoft
2010-01-20 13:45 . 2009-03-30 08:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-20 13:45 . 2009-02-13 10:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-20 13:45 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-20 13:45 . 2010-01-20 13:45 -------- d-----w- c:\program files\Avira
2010-01-20 13:32 . 2010-01-20 16:08 -------- d-----w- c:\program files\trend micro
2010-01-20 13:32 . 2010-01-20 13:33 -------- d-----w- C:\rsit
2010-01-20 13:17 . 2010-01-20 13:17 -------- d-----w- c:\program files\CCleaner
2010-01-12 15:22 . 2010-01-12 15:23 -------- d-----w- c:\program files\Picasa2
2010-01-08 18:55 . 2010-01-11 18:07 -------- d-----w- c:\program files\THQ
2010-01-08 13:24 . 2000-07-08 14:06 87040 ----a-w- c:\windows\UnGins.exe
2010-01-08 13:24 . 2010-01-08 13:24 -------- d-----w- c:\program files\Blondes Xonix
2010-01-07 14:13 . 2010-01-07 14:21 -------- d-----w- c:\program files\ElastoManiaRegistered
2010-01-03 13:14 . 2010-01-03 13:14 -------- d-----w- C:\PC TRANSLATOR DEMO
2010-01-01 10:23 . 2010-01-01 10:23 -------- d-----w- c:\program files\GamersFirst
2009-12-31 11:28 . 2010-01-20 15:03 -------- d-----w- c:\program files\EA GAMES
2009-12-31 11:21 . 2009-12-31 11:26 -------- d-----w- C:\NFSMWDemo
2009-12-30 13:49 . 2002-12-11 16:34 241664 -c--a-w- c:\windows\system32\dllcache\mpg4dmod.dll
2009-12-30 13:49 . 2002-12-11 16:34 241664 ----a-w- c:\windows\system32\mpg4dmod.dll
2009-12-30 13:49 . 2002-12-11 17:09 217600 -c--a-w- c:\windows\system32\dllcache\npdrmv2.dll
2009-12-30 13:49 . 2002-12-11 16:34 9728 -c--a-w- c:\windows\system32\dllcache\npwmsdrm.dll
2009-12-29 13:56 . 2010-01-20 14:55 -------- d-----w- c:\program files\Codemasters
2009-12-29 12:02 . 2009-12-29 12:03 -------- d-----w- c:\program files\Mad Skills Motocross Demo
2009-12-27 12:08 . 2009-12-27 12:08 -------- d-----w- c:\program files\MyPlayCity.com

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-20 17:58 . 2003-04-16 12:00 398472 ----a-w- c:\windows\system32\perfh005.dat
2010-01-20 17:58 . 2003-04-16 12:00 73236 ----a-w- c:\windows\system32\perfc005.dat
2010-01-20 17:52 . 2009-08-20 07:29 -------- d-----w- c:\program files\ICQ6.5
2010-01-20 15:09 . 2008-07-18 13:30 -------- d-----w- c:\program files\Conduit
2010-01-20 15:04 . 2008-01-31 14:42 -------- d-----w- c:\program files\SeeMePlayMe
2010-01-20 15:00 . 2003-12-26 13:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-20 14:56 . 2008-11-25 16:53 -------- d-----w- c:\program files\Winamp
2010-01-20 13:47 . 2009-11-26 15:30 -------- d-----w- c:\program files\Google
2010-01-18 16:00 . 2009-08-20 07:33 -------- d-----w- c:\program files\ICQ6Toolbar
2010-01-12 15:21 . 2009-11-26 15:26 -------- d-----w- c:\program files\Common Files\eSellerate
2010-01-08 18:46 . 2005-12-14 14:39 -------- d-----w- c:\program files\Activision
2010-01-03 15:06 . 2008-11-17 11:31 -------- d-----w- c:\program files\Ubisoft
2010-01-01 08:01 . 2005-12-02 13:28 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-01 08:01 . 2009-08-25 16:30 -------- d-----w- c:\program files\IKEA HomePlanner
2009-12-28 09:19 . 2008-12-19 16:33 -------- d-----w- c:\program files\Microsoft Games
2009-12-23 12:00 . 2005-06-16 16:43 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-11-26 15:29 . 2009-11-26 15:29 -------- d-----w- c:\program files\Western Digital
2008-05-22 15:23 . 2008-05-22 15:23 162 ---ha-w- c:\program files\~$talog_IKEA_2008.pdf
2002-11-19 06:35 . 2009-05-05 17:34 27454954 ----a-w- c:\program files\dj frisky - jungle mix.mp3
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 1957888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-02-04 2899968]
"nwiz"="nwiz.exe" [2004-02-04 782336]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-02-04 46080]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-21 366400]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2003-04-16 13312]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^okay^Nabídka Start^Programy^Po spuštění^PowerReg Scheduler.exe]
path=c:\documents and settings\okay\Nabídka Start\Programy\Po spuštění\PowerReg Scheduler.exe
backup=c:\windows\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2003-04-16 12:00 13312 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-08-04 16:28 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe"
"nwiz"=nwiz.exe /install
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"Microsoft MediaScope"=winmes.exe
"snapple"=snapple.exe

R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [20.1.2010 14:45 22360]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.7.2008 14:24 716272]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [20.1.2010 14:45 45416]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [20.1.2010 14:45 108289]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14.5.2007 10:26 508288]
S0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [20.1.2010 17:49 64288]
S3 se46bus;Sony Ericsson Device 070 driver (WDM);c:\windows\system32\drivers\se46bus.sys [5.2.2008 16:03 61536]
S3 se46mdfl;Sony Ericsson Device 070 USB WMC Modem Filter;c:\windows\system32\drivers\se46mdfl.sys [7.2.2008 16:28 9360]
S3 se46mdm;Sony Ericsson Device 070 USB WMC Modem Driver;c:\windows\system32\drivers\se46mdm.sys [7.2.2008 16:28 97088]
S3 se46mgmt;Sony Ericsson Device 070 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\se46mgmt.sys [12.2.2008 16:09 88624]
S3 se46nd5;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (NDIS);c:\windows\system32\drivers\se46nd5.sys [12.2.2008 16:09 18704]
S3 se46obex;Sony Ericsson Device 070 USB WMC OBEX Interface;c:\windows\system32\drivers\se46obex.sys [11.2.2008 17:44 86432]
S3 se46unic;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (WDM);c:\windows\system32\drivers\se46unic.sys [12.2.2008 16:09 90800]
S3 Z550bus;Sony Ericsson Z550 driver (WDM);c:\windows\system32\drivers\Z550bus.sys [29.11.2009 10:41 60800]
.
Obsah adresáře 'Naplánované úlohy'

2010-01-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2006\SystemOptimizer.exe [2005-09-21 16:54]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\TRANSL~1\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\TRANSL~1\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\TRANSL~1\WEBIE.DLL
Trusted Zone: contentmatch.net\ny
TCP: {8A46B132-AB20-46B2-A288-547A8EDD7FD6} = 212.158.128.2,212.158.128.3
FF - ProfilePath - c:\documents and settings\Lynx\Data aplikací\Mozilla\Firefox\Profiles\0gvoc6o9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/skinit/icq/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

URLSearchHooks-{C94E154B-1459-4A47-966B-4B843BEFC7DB} - c:\program files\AskSearch\bin\DefaultSearch.dll
BHO-{7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
BHO-{A3FDD654-A057-4971-9844-4ED8E67DBBB8} - (no file)
Toolbar-{FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKU-Default-Run-Microsoft Update - lsac.exe
HKU-Default-Run-Windows SSL File - winssv.exe
HKU-Default-Run-NvCplScan - nvsc32.exe
HKU-Default-Run-Microsoft Windows Securety - wurguar.exe
HKU-Default-Run-snapple - snapple.exe
HKU-Default-RunOnce-NvCplScan - nvsc32.exe
SafeBoot-Lavasoft Ad-Aware Service
MSConfigStartUp-CloneCDTray - c:\program files\SlySoft\CloneCD\CloneCDTray.exe
MSConfigStartUp-Microsoft Update - lsac.exe
MSConfigStartUp-NvCplScan - nvsc32.exe
MSConfigStartUp-snapple - snapple.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-20 18:57
Windows 5.1.2600 Service Pack 1 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-2587936551-162025716-2501954535-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:1a,03,7e,cb,2c,ca,27,ef,a2,b8,8c,98,82,eb,4e,5b,ac,02,a3,97,8a,25,d9,
70,20,ce,97,cb,be,d6,d2,15,18,56,53,f4,3f,8e,e0,25,20,88,2b,ea,d7,1a,83,88,\
"??"=hex:1e,ce,e6,54,5b,02,ca,6c,07,5d,d7,24,7e,5d,ea,fa
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(660)
c:\windows\System32\ODBC32.dll

- - - - - - - > 'lsass.exe'(716)
c:\windows\System32\dssenh.dll

- - - - - - - > 'explorer.exe'(2316)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\System32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\System32\nvsvc32.exe
c:\windows\System32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\System32\wdfmgr.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Celkový čas: 2010-01-20 19:06:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-20 18:06

Před spuštěním: Volných bajtů: 11 273 396 224
Po spuštění: Volných bajtů: 11 184 099 328

winxpsp1_cs_hom_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect

- - End Of File - - 41E022001E2EDAF78677598A1D6A02E6

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o preventivku

#15 Příspěvek od Caroprd111 »

Zdravím :)

Poprosím ještě o log z RSIT http://www.viry.cz/forum/viewtopic.php?f=13&t=82743
Obrázek

Odpovědět