Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#1 Příspěvek od Ideatore »

Dobrý den, koukal jsem, že se mi do počítače dostaly nějaký brebery, v logu jich pár je :D Poprosil bych o zkontrolování a pomoc, děkuji.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Lukáš at 2010-01-27 14:04:00
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 9 GB (6%) free of 156 GB
Total RAM: 1023 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:04:09, on 27.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\system32\oodtray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Lukáš.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Svátky a výročí] C:\Program Files\OKsoftware\Svátky a výročí\Vyroci.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -"Mozilla/5.0 (Windows; U; Windows NT 5.1; cs; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20" -"http://www.candystand.com/play.do?id=18 ... house%2Bad"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: wwwpos32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 6606050109
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 8146 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\NeroLiveEpgUpdate-STROJ_Martin.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-24 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS Probe"=C:\Program Files\ASUS\Probe\AsusProb.exe [2002-12-06 617984]
"nForce Tray Options"=sstray.exe /r []
"CHotkey"=C:\WINDOWS\mHotkey.exe [2002-07-05 491008]
"OODefragTray"=C:\WINDOWS\system32\oodtray.exe [2007-05-11 2512392]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2004-06-29 88363]
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2008-10-07 86016]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"Svátky a výročí"=C:\Program Files\OKsoftware\Svátky a výročí\Vyroci.exe [2004-12-12 960512]
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-07-03 81920]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"=C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE [2008-12-05 460216]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk.disabled - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění
wwwpos32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
:\WINDOWS\system32\srrstr.dll

cli
scecli
scecli
scecli
scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Totalcmd\TOTALCMD.EXE"="C:\Program Files\Totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Java\jre1.6.0_07\launch4j-tmp\JDownloader.exe"="C:\Program Files\Java\jre1.6.0_07\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\WINDOWS\system32\java.exe"="C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\StrongDC\StrongDC.exe"="C:\Program Files\StrongDC\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\Sony\Vegas 6.0\VegSrv60.exe"="C:\Program Files\Sony\Vegas 6.0\VegSrv60.exe:*:Enabled:Sony Vegas Network Render Service Control"
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe"="C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe"="C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe"="C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi"
"C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe"="C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Documents and Settings\Martin\Plocha\Counter Strike\cstrike.exe"="C:\Documents and Settings\Martin\Plocha\Counter Strike\cstrike.exe:*:Enabled:Counter-Strike Launcher"
"F:\hry\Atari\Test Drive Unlimited\TestDriveUnlimited.exe"="F:\hry\Atari\Test Drive Unlimited\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\hry\Valve\hl.exe"="C:\hry\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\Program Files\VLC\vlc.exe"="C:\Program Files\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"F:\hry\2K Sports\NBA 2K10\nba2k10.exe"="F:\hry\2K Sports\NBA 2K10\nba2k10.exe:*:Disabled:2K Sports NBA 2K10"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
shell\AutoRun\command - J:\wd_windows_tools\WDSetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0f53175-4dce-11dd-a3c3-9965402625e2}]
shell\AutoRun\command - J:\wd_windows_tools\WDSetup.exe


======List of files/folders created in the last 1 months======

2010-01-23 01:28:04 ----DC---- C:\Program Files\Common Files\Skype
2010-01-19 20:57:03 ----DC---- C:\Documents and Settings\All Users\Data aplikací\HP Product Assistant
2010-01-05 15:51:13 ----AC---- C:\WINDOWS\system32\dxdllreg.exe

======List of files/folders modified in the last 1 months======

2010-01-27 14:02:59 ----DC---- C:\WINDOWS\Prefetch
2010-01-27 14:01:47 ----DC---- C:\WINDOWS\Temp
2010-01-27 14:01:15 ----DC---- C:\WINDOWS\system32\CatRoot2
2010-01-27 05:38:29 ----AC---- C:\WINDOWS\ntbtlog.txt
2010-01-27 05:18:15 ----DC---- C:\Program Files\Mozilla Firefox
2010-01-27 05:18:01 ----AC---- C:\WINDOWS\wincmd.ini
2010-01-27 04:51:14 ----AC---- C:\WINDOWS\NeroDigital.ini
2010-01-27 04:51:13 ----DC---- C:\WINDOWS
2010-01-27 01:29:06 ----DC---- C:\WINDOWS\system32\drivers
2010-01-27 01:28:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-27 01:21:48 ----DC---- C:\WINDOWS\system32
2010-01-26 19:48:05 ----SHDC---- C:\WINDOWS\Installer
2010-01-26 19:48:05 ----HDC---- C:\Config.Msi
2010-01-26 19:05:41 ----DC---- C:\Program Files\Mozilla Thunderbird
2010-01-26 18:47:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-26 17:08:04 ----DC---- C:\Program Files\AVerTV DVB-T
2010-01-26 17:08:04 ----AC---- C:\WINDOWS\AVerDVBT.ini
2010-01-26 16:58:13 ----AC---- C:\demux_log.txt
2010-01-25 18:23:37 ----AC---- C:\WINDOWS\ODBC.INI
2010-01-25 18:22:57 ----DC---- C:\Program Files\Common Files\Microsoft Shared
2010-01-25 18:22:56 ----RSDC---- C:\WINDOWS\Fonts
2010-01-25 18:22:55 ----HDC---- C:\WINDOWS\ShellNew
2010-01-25 18:19:24 ----RDC---- C:\Program Files
2010-01-25 18:19:24 ----DC---- C:\WINDOWS\system
2010-01-25 01:20:25 ----DC---- C:\Documents and Settings\Lukáš\Data aplikací\gtk-2.0
2010-01-23 01:29:15 ----DC---- C:\Documents and Settings\Lukáš\Data aplikací\Skype
2010-01-23 01:28:04 ----RDC---- C:\Program Files\Skype
2010-01-23 01:28:04 ----DC---- C:\Program Files\Common Files
2010-01-23 01:27:59 ----DC---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-01-23 01:26:52 ----DC---- C:\Documents and Settings\Lukáš\Data aplikací\skypePM
2010-01-22 23:23:24 ----RDC---- C:\hry
2010-01-19 20:57:05 ----DC---- C:\WINDOWS\WinSxS
2010-01-17 20:22:46 ----AC---- C:\WINDOWS\win.ini
2010-01-16 15:46:25 ----AC---- C:\WINDOWS\wcx_ftp.ini
2010-01-15 23:53:09 ----HDC---- C:\WINDOWS\inf
2010-01-13 07:30:26 ----DC---- C:\Documents and Settings
2010-01-10 18:54:15 ----DC---- C:\Program Files\Totalcmd
2010-01-07 14:55:20 ----DC---- C:\Documents and Settings\Lukáš\Data aplikací\Canon
2010-01-05 15:50:46 ----DC---- C:\WINDOWS\system32\DirectX
2010-01-05 15:45:36 ----HDC---- C:\Program Files\InstallShield Installation Information
2010-01-03 16:17:15 ----DC---- C:\WINDOWS\Minidump
2010-01-03 14:52:11 ----RSDC---- C:\WINDOWS\assembly
2010-01-03 14:20:46 ----DC---- C:\WINDOWS\system32\oodag
2010-01-03 12:51:42 ----DC---- C:\WINDOWS\Internet Logs

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 aslm75;aslm75; \??\C:\WINDOWS\system32\drivers\aslm75.sys []
R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1999-09-10 25244]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-06-15 28520]
R2 ATTSCAP;AVerMedia, WDM MPEG-2 TS Capture (DVBT); C:\WINDOWS\system32\drivers\attscap.sys [2003-06-24 18048]
R2 ATVCAP;AVerMedia, DVB-T WDM Video Capture; C:\WINDOWS\system32\drivers\atvcap.sys [2003-06-24 56320]
R2 ATXBAR;AVerMedia, DVB-T WDM Crossbar; C:\WINDOWS\system32\drivers\ATXBAR.sys [2003-06-24 8576]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-01-18 56816]
R2 dvdmmg;dvdmmg; \??\C:\WINDOWS\system32\drivers\dvdmmg.sys []
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-06-29 1268204]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-08-17 701440]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-06-29 25280]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-10-27 49664]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-10-27 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-27 21568]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-06-02 171008]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2002-09-23 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2003-08-13 36864]
R3 NVENET;NVIDIA nForce MCP Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2003-06-06 70656]
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2003-08-13 311552]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2002-06-21 10144]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2002-06-21 39776]
S1 632f6b96;632f6b96; C:\WINDOWS\System32\drivers\632f6b96.sys []
S1 glaide32;glaide32; \??\C:\WINDOWS\system32\drivers\glaide32.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 61883;61883 Unit Device; C:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-14 48128]
S3 a1eqj0b9;a1eqj0b9; C:\WINDOWS\system32\drivers\a1eqj0b9.sys []
S3 ASAPIW2K;ASAPIW2K; \??\C:\WINDOWS\system32\Drivers\asapiW2k.sys []
S3 Avc;AVC Device; C:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-14 38912]
S3 BTCAMDRV;Mobiola Web Camera driver; C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2006-11-01 219264]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\LUK~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2008-04-14 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-10-06 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-10-06 22016]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-10-06 7936]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 win32x;win32x; \??\C:\WINDOWS\system32\drivers\win32x.sys []
S3 WmFilter;Logitech WingMan HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2002-06-21 20128]
S3 WmHidLo;Logitech WingMan USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2002-06-21 13920]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2002-06-21 5728]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2004-08-19 189568]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-08 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-06-15 108289]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-07-03 131072]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2007-05-11 1050120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2005-03-14 69632]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-04-01 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-04-01 107832]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2008-10-07 163908]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-10-17 72704]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-14 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 HP Port Resolver;HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [2005-05-20 81920]
S3 HP Status Server;HP Status Server; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE [2004-10-16 73728]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-21 355584]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

pitimir
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 479
Registrován: 18 čer 2008 17:54
Bydliště: Šutrovec
Kontaktovat uživatele:

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#2 Příspěvek od pitimir »

Nazdar.

1) Stiahni GMER, rozbal ho na plochu a spust. Program automaticky zacne scan (po jeho skonceni vloz log c. 1) - pokial pri scanovani nieco najde (=vyskoci nejake upozornenie), klik na "NO" a nastavis program podla obrazku:
Obrázek
Klik na "Scan". Po scane klik na "Save" a log c. 2 vloz sem.

Ak nic nenajde (=nevyskoci nic), zaskrtaj vpravo vsetko a spusti scan. Po jeho ukonceni klik na "Copy" a vloz log c. 2.


2) Stiahni OTL. Uloz na plochu a spust dvojklikom subor "OTL.exe". Otvori sa okno programu, v nom zaskrtni "Scan All Users", "Lop" aj "Purity Check" a "File Scan" zmen na 7 dni miesto 30. Do policka pod nazvom "Custom Scans/Fixes" skopiruj:

Kód: Vybrat vše

netsvcs
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\eventlog.dll /s /md5
%SYSTEMDRIVE%\scecli.dll /s /md5
%SYSTEMDRIVE%\netlogon.dll /s /md5
%SYSTEMDRIVE%\cngaudit.dll /s /md5
%SYSTEMDRIVE%\sceclt.dll /s /md5
%SYSTEMDRIVE%\ntelogon.dll /s /md5
%SYSTEMDRIVE%\logevent.dll /s /md5
%SYSTEMDRIVE%\iaStor.sys /s /md5
%SYSTEMDRIVE%\nvstor.sys /s /md5
%SYSTEMDRIVE%\atapi.sys /s /md5
%SYSTEMDRIVE%\IdeChnDr.sys /s /md5
%SYSTEMDRIVE%\viasraid.sys /s /md5
%SYSTEMDRIVE%\AGP440.sys /s /md5
%SYSTEMDRIVE%\vaxscsi.sys /s /md5
%SYSTEMDRIVE%\nvatabus.sys /s /md5
%SYSTEMDRIVE%\viamraid.sys /s /md5
%SYSTEMDRIVE%\nvata.sys /s /md5
%SYSTEMROOT%\*. /mp /s
CREATERESTOREPOINT
%SYSTEMROOT%\system32\*.dll /lockedfiles
%SYSTEMROOT%\Tasks\*.job /lockedfiles
Potom klikni na "Run Scan". Zacne scan pocitaca, po jeho ukonceni sa otvoria dva reporty - obsah oboch potrebujem vidiet.
Ja som skromný, mám len dve veci do podpisu...

1) Chcete pomôcť fóru? Podporte ho_!!

2) Prosím všetkých, ktorí majú problém: :!:
- založte si vlastný topic a do 1. prispevku vložte log z RSIT a presný stručný popis problému.
- bez odporúčania nespúšťajte ŽIADEN iný program nájdený na fóre/internete.
- needitujte a nemažte príspevky.
- dodržujte inštrukcie a nerobte nič naviac (z vlastnej iniciatívy).

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#3 Příspěvek od Ideatore »

Omlouvám se za zdržení, ale když jsem GMER spustil, vyskočil mi výpis vyzický RAM :?: tak jsem ho zkusil pustit v nouzáku a tam už to jede. Takže první log z GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-01-27 14:57:37
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1.000\LOCALS~1\Temp\axtdypog.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)

---- EOF - GMER 1.0.15 ----


Na druhym logu se pracuje.

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#4 Příspěvek od Ideatore »

Druhej log z GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-27 18:19:03
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1.000\LOCALS~1\Temp\axtdypog.sys


---- Kernel code sections - GMER 1.0.15 ----

.sfreloc˙˙˙˙sfsync03unknown last section [0xF763C000, 0xA20, 0x40000040] C:\WINDOWS\system32\drivers\sfsync03.sys unknown last section [0xF763C000, 0xA20, 0x40000040]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\{1F4D3C0D-EE6D-470F-A3C7-96C352329C4F}\Parameters\Tcpip@LeaseObtainedTime 1264612229
Reg HKLM\SYSTEM\CurrentControlSet\Services\{1F4D3C0D-EE6D-470F-A3C7-96C352329C4F}\Parameters\Tcpip@T1 1264612356
Reg HKLM\SYSTEM\CurrentControlSet\Services\{1F4D3C0D-EE6D-470F-A3C7-96C352329C4F}\Parameters\Tcpip@T2 1264612452
Reg HKLM\SYSTEM\CurrentControlSet\Services\{1F4D3C0D-EE6D-470F-A3C7-96C352329C4F}\Parameters\Tcpip@LeaseTerminatesTime 1264612484
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG10.00.00.01WORKSTATION C988BE2ABDBD27317048B3283C3A9E62607428B37D7E2C62CD3C11D2B97737E64956A653A9A7B77F292FC99EF8C1E8940A736F665217F6B6DEDDAA1BEED0D4400CE3B9B4438010C59722AC4C31F8BD566A269504CF7E740C1AFE4B3D434158ECC72839A62226311B16344A0EEB6B1BD39B5C500E8E0F3CC2FA4B90827F0D8F237D49CCD55FEB44A8C22B6F163419A0CCFC98B75BA99484D0C2A27B07EEEF6C2BEBA5FD45971912307E7ED16996749315B1114697C0CF2C3FF5177139E2180666184C3C46ED688B84F1DD076329E7D895A0AFDEC07676B32A5B713C5C302593C4CC8258048788428B84FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79339DB7CE019D40AA5CC038D530D6EB34529DB7CE019D40AA5CB75486B957DDD9EE3C79A99873AF0CA3759F40C119422D011D4F8D62410AC35D0321288A64554FEC6E187F86BE69FAAE5402B3DE732FA06CD7E643DA78E81648A58C7B97CE7ECEDC928EC92F135BCCE812F7CCEE5A53E0907C7DC11CDBA0B82A1F3A3B4D6E6DC41E2506A75156EF6254CA55AF9FDF1363B1E0305567CD2ED529222EF69E93572ED7570C902DE4B6AE374B52D5240D75AF56117F9CFE23B22B2B1851927C7F951DF20D15CA0A8BE2B81C15888D33DD27E34ACACE092AA47309DD9A72C7E2E8A6B
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x97 0x20 0x4E 0x9A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x37 0xA4 0xAA 0xC3 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem@ DirectPlay8 Modem Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem\CLSID@ {6D4A3650-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem\CurVer
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem\CurVer@ DirectPlay8SPModem.Modem.1
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem.1@ DirectPlay8 Modem Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Modem.1\CLSID@ {6D4A3650-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial@ DirectPlay8 Serial Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial\CLSID@ {743B5D60-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial\CurVer
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial\CurVer@ DirectPlay8SPModem.Serial.1
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial.1@ DirectPlay8 Serial Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPModem.Serial.1\CLSID@ {743B5D60-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX@ DirectPlay8 WSock IPX Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX\CLSID@ {53934290-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX\CurVer
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX\CurVer@ DirectPlay8SPWSock.IPX.1
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX.1@ DirectPlay8 WSock IPX Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.IPX.1\CLSID@ {53934290-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP@ DirectPlay8 WSock TCPIP Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP\CLSID@ {EBFE7BA0-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP\CurVer
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP\CurVer@ DirectPlay8SPWSock.TCPIP.1
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP.1@ DirectPlay8 WSock TCPIP Provider Object
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP.1\CLSID
Reg HKLM\SOFTWARE\Classes\DirectPlay8SPWSock.TCPIP.1\CLSID@ {EBFE7BA0-628D-11D2-AE0F-006097B01411}
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC@ DMCComponent
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC\CLSID
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC\CLSID@ {B286F068-5B17-4AE8-989B-8F9A199C47BA}
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC\CurVer
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC\CurVer@ DMCComponent.IDMC.1
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC.1@ DMCComponent
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC.1\CLSID
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC.1\CLSID@ {B286F068-5B17-4AE8-989B-8F9A199C47BA}
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1@ DMCComponent
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1\CLSID
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1\CLSID@ {98087D89-B93F-4BCF-A998-AE4D9F607C14}
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1\CurVer
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1\CurVer@ DMCComponent.IDMC1.1
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1.1@ DMCComponent
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1.1\CLSID
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC1.1\CLSID@ {98087D89-B93F-4BCF-A998-AE4D9F607C14}
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2@ DMCComponent
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2\CLSID
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2\CLSID@ {3A999A50-AB25-4A20-90A9-08F71FCE320F}
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2\CurVer
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2\CurVer@ DMCComponent.IDMC2.1
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2.1@ DMCComponent
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2.1\CLSID
Reg HKLM\SOFTWARE\Classes\DMCComponent.IDMC2.1\CLSID@ {3A999A50-AB25-4A20-90A9-08F71FCE320F}
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAecDMO@ DirectSoundCaptureAecDMO
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAecDMO\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAecDMO\CLSID@ {1C22C56D-9879-4F5B-A389-27996DDC2810}
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAecDMO\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAecDMO\CurVer@ Microsoft.DirectSoundCaptureAecDMO.1
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAgcDMO@ DirectSoundCaptureAgcDMO
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAgcDMO\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAgcDMO\CLSID@ {950E55B9-877C-4C67-BE08-E47B5611130A}
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAgcDMO\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureAgcDMO\CurVer@ Microsoft.DirectSoundCaptureAgcDMO.1
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureNoiseSuppressDMO@ DirectSoundCaptureNoiseSuppressDMO
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureNoiseSuppressDMO\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureNoiseSuppressDMO\CLSID@ {5AB0882E-7274-4516-877D-4EEE99BA4FD0}
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureNoiseSuppressDMO\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.DirectSoundCaptureNoiseSuppressDMO\CurVer@ Microsoft.DirectSoundCaptureNoiseSuppressDMO.1

pitimir
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 479
Registrován: 18 čer 2008 17:54
Bydliště: Šutrovec
Kontaktovat uživatele:

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#5 Příspěvek od pitimir »

Dobre, este OTL logy :)
Ja som skromný, mám len dve veci do podpisu...

1) Chcete pomôcť fóru? Podporte ho_!!

2) Prosím všetkých, ktorí majú problém: :!:
- založte si vlastný topic a do 1. prispevku vložte log z RSIT a presný stručný popis problému.
- bez odporúčania nespúšťajte ŽIADEN iný program nájdený na fóre/internete.
- needitujte a nemažte príspevky.
- dodržujte inštrukcie a nerobte nič naviac (z vlastnej iniciatívy).

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#6 Příspěvek od Ideatore »

byla to fuška :D ale tady jsou:

OTL.txt:

OTL logfile created on: 27.1.2010 18:37:36 - Run 1
OTL by OldTimer - Version 3.1.27.0 Folder = C:\Documents and Settings\Lukáš\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 023,00 Mb Total Physical Memory | 647,00 Mb Available Physical Memory | 63,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152,66 Gb Total Space | 9,17 Gb Free Space | 6,01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 37,27 Gb Total Space | 9,30 Gb Free Space | 24,97% Space Free | Partition Type: NTFS
Drive F: | 279,47 Gb Total Space | 15,33 Gb Free Space | 5,48% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STROJ
Current User Name: Lukáš
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.01.27 14:32:12 | 00,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
PRC - [2009.10.11 04:17:36 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009.10.11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009.08.08 14:44:10 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.06.15 12:10:14 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009.04.01 17:54:42 | 00,107,832 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe
PRC - [2009.04.01 17:54:33 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2009.03.31 09:39:36 | 00,233,472 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2009.03.02 12:08:47 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2008.12.08 15:50:04 | 00,054,576 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\hpwuschd2.exe
PRC - [2008.04.14 08:52:46 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\savedump.exe
PRC - [2008.04.14 08:52:24 | 01,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008.04.14 04:22:55 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2007.07.03 11:32:16 | 00,131,072 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2007.05.11 01:09:48 | 01,050,120 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\system32\oodag.exe
PRC - [2007.05.11 01:08:54 | 02,512,392 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\system32\oodtray.exe
PRC - [2005.03.14 12:05:02 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004.06.29 08:06:38 | 00,088,363 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
PRC - [2003.08.13 05:25:56 | 00,073,728 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\sstray.exe
PRC - [2002.12.06 15:07:48 | 00,617,984 | ---- | M] () -- C:\Program Files\ASUS\Probe\AsusProb.exe
PRC - [2002.07.05 15:37:18 | 00,491,008 | ---- | M] (Chicony) -- C:\WINDOWS\mHotkey.exe


========== Modules (SafeList) ==========

MOD - [2010.01.27 14:32:12 | 00,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
MOD - [2001.07.02 19:36:30 | 00,024,576 | ---- | M] () -- C:\WINDOWS\HKNTDLL.dll


========== Win32 Services (SafeList) ==========

SRV - [2009.10.27 09:26:36 | 00,657,408 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.10.11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009.08.08 14:44:10 | 00,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.06.15 12:10:14 | 00,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009.04.01 17:54:42 | 00,107,832 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB)
SRV - [2009.04.01 17:54:33 | 00,066,872 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA)
SRV - [2009.03.31 09:39:36 | 00,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2009.03.14 19:51:27 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008.10.17 15:27:29 | 00,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2008.10.07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2008.07.29 18:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.07.21 00:28:02 | 00,355,584 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.05.29 08:28:54 | 00,028,416 | ---- | M] (TuneUp Software GmbH) [Auto | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2007.07.03 11:32:16 | 00,131,072 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
SRV - [2007.05.11 01:09:48 | 01,050,120 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)
SRV - [2005.05.20 10:37:12 | 00,081,920 | ---- | M] (Hewlett-Packard Company) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE -- (HP Port Resolver)
SRV - [2005.03.14 12:05:02 | 00,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2004.10.22 02:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004.10.16 05:31:06 | 00,073,728 | ---- | M] (Hewlett-Packard Company) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE -- (HP Status Server)
SRV - [2003.07.28 19:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2002.12.17 16:26:22 | 07,520,337 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 16:23:30 | 00,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)


========== Driver Services (SafeList) ==========

DRV - [2010.01.18 13:43:55 | 00,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.10.29 02:56:58 | 00,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.10.06 11:52:34 | 00,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.10.06 11:52:34 | 00,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009.10.06 11:52:34 | 00,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.09.24 01:30:11 | 00,000,000 | ---- | M] () [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\632f6b96.sys -- (632f6b96)
DRV - [2009.06.29 09:35:16 | 00,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.06.15 12:10:15 | 00,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.03.31 09:39:36 | 00,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009.03.30 09:33:07 | 00,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009.03.20 10:01:26 | 00,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009.03.20 10:01:26 | 00,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2009.03.20 10:01:26 | 00,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2009.02.13 11:35:05 | 00,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008.10.07 13:33:00 | 06,133,856 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2008.09.17 15:14:00 | 00,027,672 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\entech.sys -- (ENTECH)
DRV - [2008.08.26 09:26:12 | 00,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.14 04:22:50 | 00,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\win32x.exe -- (win32x)
DRV - [2008.04.14 00:16:22 | 00,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2008.04.14 00:16:22 | 00,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2008.04.14 00:16:10 | 00,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV)
DRV - [2008.04.14 00:15:30 | 00,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008.04.14 00:11:00 | 00,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\changer.sys -- (Changer)
DRV - [2008.04.13 22:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2007.09.06 11:15:22 | 00,005,504 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\dvdmmg.sys -- (dvdmmg)
DRV - [2007.07.03 11:33:04 | 00,006,912 | ---- | M] (NVidia Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\nvoclock.sys -- (NVR0Dev)
DRV - [2007.02.01 17:50:12 | 00,017,328 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SiWinAcc.sys -- (SiWinAcc)
DRV - [2007.02.01 17:50:12 | 00,017,328 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys -- (SiFilter)
DRV - [2007.02.01 17:50:10 | 00,110,128 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\si3112r.sys -- (si3112r)
DRV - [2006.11.01 19:45:14 | 00,219,264 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcamdrv.sys -- (BTCAMDRV)
DRV - [2006.05.16 21:23:54 | 00,046,080 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2005.12.06 16:11:18 | 00,035,328 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync03.sys -- (sfsync03) StarForce Protection Synchronization Driver (version 3.x)
DRV - [2005.10.27 10:52:19 | 00,021,568 | R--- | M] (HP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12)
DRV - [2005.10.27 10:52:19 | 00,016,496 | R--- | M] (HP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12)
DRV - [2005.10.27 10:52:18 | 00,049,664 | R--- | M] (HP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HPZid412.sys -- (HPZid412)
DRV - [2005.08.10 13:44:04 | 00,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.06.02 18:28:38 | 00,171,008 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2005.05.16 14:20:39 | 00,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005.02.09 11:59:00 | 00,014,165 | ---- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI)
DRV - [2004.08.19 00:21:00 | 00,189,568 | R--- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2004.08.17 15:43:40 | 00,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004.06.29 08:07:18 | 01,268,204 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2003.08.13 02:45:00 | 00,311,552 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvapu.sys -- (nvnforce) Service for NVIDIA(R) nForce(TM)
DRV - [2003.08.13 02:45:00 | 00,036,864 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvax.sys -- (nvax) Service for NVIDIA(R) nForce(TM)
DRV - [2003.06.24 18:22:32 | 00,056,320 | R--- | M] (AVerMedia Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atvcap.sys -- (ATVCAP)
DRV - [2003.06.24 18:19:08 | 00,018,048 | R--- | M] (AVerMedia Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\attscap.sys -- (ATTSCAP) AVerMedia, WDM MPEG-2 TS Capture (DVBT)
DRV - [2003.06.24 12:23:24 | 00,008,576 | R--- | M] (AVerMedia Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atxbar.sys -- (ATXBAR)
DRV - [2003.06.06 23:53:16 | 00,070,656 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENET.sys -- (NVENET)
DRV - [2003.03.19 08:51:00 | 00,018,688 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2002.09.23 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2002.06.21 02:45:44 | 00,013,920 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2002.06.21 02:45:42 | 00,020,128 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2002.06.21 02:45:40 | 00,010,144 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2002.06.21 02:45:36 | 00,005,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2002.06.21 02:45:34 | 00,039,776 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2001.08.17 23:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [1999.09.10 12:06:00 | 00,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (ASPI32)
DRV - [1997.04.22 09:16:00 | 00,006,272 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ASLM75.SYS -- (aslm75)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1292428093-926492609-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
IE - HKU\S-1-5-21-1292428093-926492609-725345543-1005\..\URLSearchHook: {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-1292428093-926492609-725345543-1005\S-1-5-21-1292428093-926492609-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1292428093-926492609-725345543-1005\S-1-5-21-1292428093-926492609-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "www.centrum.cz"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.0.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20091209.4
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.723
FF - prefs.js..extensions.enabledItems: {29c4afe1-db19-4298-8785-fcc94d1d6c1d}:0.6.2009110501
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.7
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.66
FF - prefs.js..network.proxy.type: 4


FF - HKLM\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.12.10 15:50:15 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.01.07 18:25:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.01.07 18:25:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009.08.24 10:39:12 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.01.25 18:22:58 | 00,000,000 | ---D | M]

[2009.04.05 03:00:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Extensions
[2010.01.26 23:49:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions
[2009.11.26 14:13:06 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2009.11.26 14:13:05 | 00,000,000 | ---D | M] (Stylish) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2009.08.24 21:55:57 | 00,000,000 | ---D | M] (Noia 2.0 (eXtreme)) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2010.01.17 09:21:32 | 00,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010.01.08 04:22:36 | 00,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009.09.19 23:43:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions\elemhidehelper@adblockplus.org
[2010.01.17 09:21:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\5070c3g6.default\extensions\staged-xpis
[2010.01.27 14:56:21 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.12.18 12:49:05 | 00,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2009.12.18 12:49:05 | 00,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2009.12.18 12:49:05 | 00,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2009.12.18 12:49:06 | 00,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2009.12.18 12:49:06 | 00,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2010.01.27 05:43:26 | 00,374,222 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 http://www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 http://www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 http://www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 http://www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 http://www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 http://www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 http://www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 http://www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 http://www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 http://www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 http://www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 12897 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (QIPBHO Class) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\mHotkey.exe (Chicony)
O4 - HKLM..\Run: [nForce Tray Options] C:\WINDOWS\System32\sstray.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe (O&O Software GmbH)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1292428093-926492609-725345543-1005..\Run: [] File not found
O4 - HKU\S-1-5-21-1292428093-926492609-725345543-1005..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKU\S-1-5-21-1292428093-926492609-725345543-1005..\Run: [Svátky a výročí] C:\Program Files\OKsoftware\Svátky a výročí\Vyroci.exe (Igor Gottwald - OKsoftware)
O4 - HKU\S-1-5-21-1292428093-926492609-725345543-1005..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -Mozilla\5.0 ( File not found
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění\wwwpos32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1292428093-926492609-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (ICQ Ltd.)
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (ICQ Ltd.)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1292428093-926492609-725345543-1005\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 6606050109 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.10.17 15:55:07 | 00,000,095 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{e0f53175-4dce-11dd-a3c3-9965402625e2}\Shell\AutoRun\command - "" = J:\wd_windows_tools\WDSetup.exe -- File not found
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\wd_windows_tools\WDSetup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009.10.25 08:37:31 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55172488459452416)

========== Files/Folders - Created Within 7 Days ==========

[2010.01.27 14:32:05 | 00,548,864 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2010.01.27 01:26:27 | 00,008,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2010.01.27 01:25:32 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\changer.sys
[2010.01.27 01:25:32 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\changer.sys
[2010.01.26 16:50:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Plocha\Dream Evil
[2010.01.26 15:59:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Plocha\HUBO25AA_by_KaHHa6uC
[2010.01.23 01:28:04 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009.04.18 12:08:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\NVIDIA Corporation
[2009.03.25 16:54:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Help
[2008.12.30 14:45:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\HP
[2008.10.24 15:52:39 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2008.07.24 19:55:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AdobeUM
[2008.07.24 19:54:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Adobe
[2008.07.24 19:54:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Adobe
[2008.07.24 19:54:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Real
[2008.07.09 17:05:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2008.07.09 16:50:38 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2008.07.09 16:50:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[70 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[22 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1422 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2010.01.27 18:32:50 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.01.27 18:32:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.01.27 18:32:40 | 01,846,486 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2010.01.27 18:31:21 | 16,777,216 | ---- | M] () -- C:\Documents and Settings\Lukáš\ntuser.dat
[2010.01.27 18:31:21 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Lukáš\ntuser.ini
[2010.01.27 18:22:58 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.01.27 17:32:39 | 00,000,202 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.01.27 14:53:32 | 10,733,11744 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010.01.27 14:32:12 | 00,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2010.01.27 14:31:05 | 00,284,915 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\gmer.zip
[2010.01.27 14:13:07 | 03,838,105 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2010.01.27 05:43:26 | 00,374,222 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.01.27 05:32:25 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
[2010.01.27 05:18:01 | 00,002,175 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.01.27 01:21:21 | 00,000,004 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\avdrn.dat
[2010.01.27 00:00:00 | 00,000,372 | ---- | M] () -- C:\WINDOWS\tasks\NeroLiveEpgUpdate-STROJ_Martin.job
[2010.01.26 17:08:04 | 00,001,401 | ---- | M] () -- C:\WINDOWS\AVerDVBT.ini
[2010.01.26 17:01:18 | 00,022,136 | ---- | M] () -- C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.01.26 17:01:04 | 00,002,191 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\SPMT.lnk
[2010.01.26 13:51:57 | 00,232,960 | ---- | M] () -- C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.01.26 08:48:08 | 01,429,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.01.25 18:23:37 | 00,000,390 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2010.01.25 01:20:25 | 00,003,604 | ---- | M] () -- C:\Documents and Settings\Lukáš\.recently-used.xbel
[2010.01.23 01:28:41 | 00,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[22 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1422 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.01.27 14:33:21 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\Lukáš\Plocha\gmer.exe
[2010.01.27 14:30:28 | 00,284,915 | ---- | C] () -- C:\Documents and Settings\Lukáš\Plocha\gmer.zip
[2010.01.27 14:12:54 | 03,838,105 | ---- | C] () -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2010.01.27 01:21:29 | 00,000,012 | ---- | C] () -- C:\Documents and Settings\NetworkService\Data aplikací\anvkgp.dat
[2010.01.27 01:21:21 | 00,000,004 | ---- | C] () -- C:\Documents and Settings\Lukáš\Data aplikací\avdrn.dat
[2010.01.25 01:20:25 | 00,003,604 | ---- | C] () -- C:\Documents and Settings\Lukáš\.recently-used.xbel
[2010.01.23 01:28:05 | 00,002,283 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2009.12.09 03:27:00 | 00,001,350 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2009.10.29 02:56:58 | 00,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009.10.26 23:28:02 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2009.10.26 23:28:02 | 00,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2009.10.26 23:27:49 | 00,002,528 | ---- | C] () -- C:\Documents and Settings\Lukáš\Data aplikací\$_hpcst$.hpc
[2009.10.25 22:13:58 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009.09.21 22:31:46 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\632f6b96.sys
[2009.07.28 17:51:33 | 00,266,717 | ---- | C] () -- C:\Program Files\setuplog.txt
[2009.05.02 21:53:51 | 00,056,320 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2009.04.01 17:54:53 | 00,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009.04.01 13:55:31 | 00,000,036 | ---- | C] () -- C:\Documents and Settings\Lukáš\Data aplikací\wiaserva.log
[2009.01.29 00:10:06 | 00,000,125 | ---- | C] () -- C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\fusioncache.dat
[2009.01.28 04:26:49 | 00,580,114 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2009.01.28 04:26:48 | 00,856,064 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.01.28 04:26:48 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.01.28 04:26:47 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009.01.28 04:26:46 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.01.28 04:26:46 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009.01.25 19:34:45 | 00,001,401 | ---- | C] () -- C:\WINDOWS\AVerDVBT.ini
[2009.01.05 20:19:47 | 00,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2008.12.30 14:22:24 | 00,003,256 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2008.10.17 17:28:11 | 00,000,077 | ---- | C] () -- C:\WINDOWS\VMorpher.INI
[2008.10.17 17:28:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\VDVD.INI
[2008.10.17 17:28:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Cover.INI
[2008.10.17 17:28:11 | 00,000,000 | ---- | C] () -- C:\WINDOWS\avvcnvrt.INI
[2008.10.17 17:28:01 | 00,000,029 | ---- | C] () -- C:\WINDOWS\AVFTP.INI
[2008.10.17 17:20:19 | 00,000,031 | ---- | C] () -- C:\WINDOWS\System32\Days5.ini
[2008.10.17 15:55:07 | 00,001,182 | ---- | C] () -- C:\WINDOWS\VFO.INI
[2008.10.07 13:33:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008.09.28 00:31:52 | 00,000,192 | ---- | C] () -- C:\WINDOWS\dvdtomp3converter.ini
[2008.09.11 18:55:30 | 00,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.09.02 15:47:07 | 00,000,518 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.08.21 16:13:24 | 00,000,008 | ---- | C] () -- C:\Documents and Settings\Lukáš\Data aplikací\NMM-MetaData.db
[2008.07.28 13:39:35 | 00,000,245 | ---- | C] () -- C:\WINDOWS\level.ini
[2008.07.10 01:13:10 | 00,232,960 | ---- | C] () -- C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.07.10 00:48:59 | 00,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.07.10 00:42:04 | 00,000,532 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008.07.09 23:50:58 | 00,000,000 | ---- | C] () -- C:\WINDOWS\oodcnt.INI
[2008.07.09 20:02:10 | 00,002,175 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.07.09 19:53:36 | 00,157,696 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.07.09 19:53:31 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2008.07.09 19:05:45 | 00,013,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\MTiCtwl.sys
[2008.07.09 18:58:22 | 00,024,576 | ---- | C] () -- C:\WINDOWS\HKNTDLL.dll
[2008.07.09 18:58:22 | 00,000,491 | ---- | C] () -- C:\WINDOWS\Instit.ini
[2008.07.09 17:14:40 | 00,018,253 | ---- | C] () -- C:\WINDOWS\System32\ssnvfx.ini
[2008.07.09 17:09:27 | 00,006,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASLM75.SYS
[2008.07.09 17:07:44 | 00,003,520 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008.07.09 17:07:39 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007.10.25 17:26:10 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007.09.06 11:15:22 | 00,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\dvdmmg.sys
[2007.03.12 11:01:30 | 00,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2006.11.11 22:52:52 | 00,454,656 | ---- | C] () -- C:\WINDOWS\System32\mmSQL.dll
[2004.12.20 17:24:03 | 01,663,068 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2002.09.23 13:00:00 | 00,249,270 | ---- | C] () -- C:\WINDOWS\System32\_003679_.tmp.dll
[2002.09.23 13:00:00 | 00,022,040 | ---- | C] () -- C:\WINDOWS\System32\_003647_.tmp.dll
[2001.07.06 16:30:00 | 00,003,165 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI

========== LOP Check ==========

[2009.10.25 22:26:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.STROJ.000\Data aplikací\TuneUp Software
[2009.04.01 17:54:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\id Software
[2009.12.10 15:43:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2008.11.10 00:50:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2008.10.17 16:10:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2008.10.17 15:52:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle Studio
[2008.09.20 16:54:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2008.07.10 00:42:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanAppDataDir
[2008.07.10 00:42:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanWizard
[2009.11.22 15:43:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.07.21 00:27:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2009.01.28 04:42:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\bsplayer
[2010.01.07 14:55:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Canon
[2008.07.23 20:43:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools
[2010.01.25 01:20:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\gtk-2.0
[2008.07.09 20:09:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ICQLite
[2008.07.12 00:49:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ID3 renamer
[2009.06.09 23:21:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Jpeg Resampler
[2009.10.27 00:08:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Jumping Bytes
[2008.12.07 02:51:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Leadertech
[2008.07.09 19:15:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\MailFrontier
[2009.12.26 06:44:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mobile Master
[2009.02.15 22:18:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nokia
[2008.07.23 02:39:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PC Suite
[2009.11.22 04:41:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Registry Mechanic
[2009.10.26 23:27:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Samsung
[2008.07.10 00:42:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ScanSoft
[2008.09.23 22:54:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\SPORE
[2008.08.25 00:42:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Summer Athletics 2008
[2009.06.29 17:48:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\temp
[2008.08.06 13:49:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Thunderbird
[2008.07.21 00:28:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\TuneUp Software
[2009.06.30 13:44:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\uTorrent
[2009.12.19 14:25:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\VitySoft
[2008.07.26 18:06:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\BSplayer
[2009.12.20 20:28:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Canon
[2008.09.20 18:23:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\DAEMON Tools
[2009.11.08 11:37:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\gtk-2.0
[2008.07.18 21:45:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\ICQLite
[2009.04.01 17:58:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\id Software
[2008.10.12 20:42:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Jpeg Resampler
[2008.07.09 19:23:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\MailFrontier
[2009.07.17 23:07:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Nokia
[2008.09.07 15:11:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\PC Suite
[2008.09.20 17:01:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Publish Providers
[2008.10.27 19:42:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\QIP
[2008.09.20 19:05:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Sony
[2008.11.16 11:22:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\SPORE
[2008.09.22 15:53:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Summer Athletics 2008
[2008.07.28 12:11:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Thunderbird
[2008.09.05 18:58:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\TuneUp Software
[2009.11.25 03:29:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\uTorrent
[2009.01.22 19:20:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Martin\Data aplikací\Video DVD Maker FREE
[2009.10.26 00:01:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\BSplayer
[2008.09.29 20:38:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\Canon
[2009.10.29 02:55:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\DAEMON Tools
[2008.07.09 19:12:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\ICQLite
[2008.07.09 23:01:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\MailFrontier
[2009.12.22 22:20:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\Mobile Master
[2009.05.30 10:46:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\PC Suite
[2009.12.22 22:21:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\Samsung
[2009.10.26 13:39:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Data aplikací\TuneUp Software

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2004.08.17 15:49:08 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[72 C:\WINDOWS\$NtServicePackUninstall$\*.tmp files -> C:\WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[2008.04.14 08:51:42 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 08:51:42 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[1422 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2004.08.17 15:49:18 | 00,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[72 C:\WINDOWS\$NtServicePackUninstall$\*.tmp files -> C:\WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[2008.04.14 08:51:56 | 00,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 08:51:56 | 00,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[1422 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2004.08.17 15:49:14 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[72 C:\WINDOWS\$NtServicePackUninstall$\*.tmp files -> C:\WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[2008.04.14 08:51:52 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 08:51:52 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[1422 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >

< %SYSTEMDRIVE%\sceclt.dll /s /md5 >

< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >

< %SYSTEMDRIVE%\logevent.dll /s /md5 >

< %SYSTEMDRIVE%\iaStor.sys /s /md5 >

< %SYSTEMDRIVE%\nvstor.sys /s /md5 >

< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2004.08.03 22:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[72 C:\WINDOWS\$NtServicePackUninstall$\*.tmp files -> C:\WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[2008.04.14 00:10:32 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]

< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >

< %SYSTEMDRIVE%\viasraid.sys /s /md5 >

< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2004.08.03 23:07:42 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[72 C:\WINDOWS\$NtServicePackUninstall$\*.tmp files -> C:\WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[2008.04.14 00:06:40 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]

< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >

< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >

< %SYSTEMDRIVE%\viamraid.sys /s /md5 >

< %SYSTEMDRIVE%\nvata.sys /s /md5 >

< %SYSTEMROOT%\*. /mp /s >

< %SYSTEMROOT%\system32\*.dll /lockedfiles >
[1422 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMROOT%\Tasks\*.job /lockedfiles >

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0CE7F3C9
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Lukáš\Plocha\Forrest_Gump_-_sample.mkv:SummaryInformation
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
< End of report >

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#7 Příspěvek od Ideatore »

Extras.txt:

OTL Extras logfile created on: 27.1.2010 18:37:36 - Run 1
OTL by OldTimer - Version 3.1.27.0 Folder = C:\Documents and Settings\Lukáš\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 023,00 Mb Total Physical Memory | 647,00 Mb Available Physical Memory | 63,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152,66 Gb Total Space | 9,17 Gb Free Space | 6,01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 37,27 Gb Total Space | 9,30 Gb Free Space | 24,97% Space Free | Partition Type: NTFS
Drive F: | 279,47 Gb Total Space | 15,33 Gb Free Space | 5,48% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STROJ
Current User Name: Lukáš
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [JpegResamplerDir] -- "J:\!!!!!Záloha\Program Files\JPEG Resampler\JpegResampler.exe" "%1" File not found
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"13144:TCP" = 13144:TCP:*:Enabled:++1
"13144:UDP" = 13144:UDP:*:Enabled:++2
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ICQLite\ICQLite.exe" = C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite -- (ICQ Ltd.)
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent -- ()
"C:\Program Files\Totalcmd\TOTALCMD.EXE" = C:\Program Files\Totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows -- (C. Ghisler & Co.)
"C:\Program Files\QIP\qip.exe" = C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager -- (The Author of QIP)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\Java\jre1.6.0_07\launch4j-tmp\JDownloader.exe" = C:\Program Files\Java\jre1.6.0_07\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\WINDOWS\system32\java.exe" = C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\StrongDC\StrongDC.exe" = C:\Program Files\StrongDC\StrongDC.exe:*:Enabled:StrongDC++ -- (Big Muscle, KohlSoft® Corporation ;-))
"C:\Program Files\Sony\Vegas 6.0\VegSrv60.exe" = C:\Program Files\Sony\Vegas 6.0\VegSrv60.exe:*:Enabled:Sony Vegas Network Render Service Control -- (Sony Pictures Digital Inc.)
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager -- File not found
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio -- File not found
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile -- File not found
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi -- File not found
"C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe" = C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\Documents and Settings\Martin\Plocha\Counter Strike\cstrike.exe" = C:\Documents and Settings\Martin\Plocha\Counter Strike\cstrike.exe:*:Enabled:Counter-Strike Launcher -- File not found
"F:\hry\Atari\Test Drive Unlimited\TestDriveUnlimited.exe" = F:\hry\Atari\Test Drive Unlimited\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited -- (Eden Games)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- File not found
"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()
"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver -- (www.sopcast.com)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application -- (www.sopcast.com)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"C:\hry\Valve\hl.exe" = C:\hry\Valve\hl.exe:*:Enabled:Half-Life Launcher -- File not found
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server -- (PeeringPortal)
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server -- (PeeringPortal)
"C:\Program Files\VLC\vlc.exe" = C:\Program Files\VLC\vlc.exe:*:Enabled:VLC media player -- ()
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe" = C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"F:\hry\2K Sports\NBA 2K10\nba2k10.exe" = F:\hry\2K Sports\NBA 2K10\nba2k10.exe:*:Disabled:2K Sports NBA 2K10 -- File not found
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager -- (Skype Technologies)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0F40754C-F1FD-43df-B73E-9DA38399CDD6}" = hpf_ProductContext
"{12519F61-F8C9-4363-8113-81424B68BBA6}" = MobileMaster
"{14A67CE0-4F30-4607-885B-43EE27BAC746}" = Readme
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{577AD794-8B34-40B4-9E7A-BE4CFFE396E6}" = Microsoft Visual Basic 2005 Express Edition - ENU
"{6869591A-7DD8-46D2-837F-57CBF7358955}" = Nokia Connectivity Cable Driver
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6E0352EE-6F0D-4FBC-B1B8-4FF032C78BE0}" = PC Connectivity Solution
"{7ADE9F27-A175-447F-A4B4-B05FA82735E1}" = HP Deskjet 6900 series (csy)
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{87F59A07-55EE-415E-A966-31F3D8B6B7AD}" = LP6940_Help
"{8A03FE64-0C8B-4E8F-B488-F36BA40A8640}" = Shogun - Total War - Gold Edition
"{8DC6CA16-9B4E-4C10-95EE-2BD91EB0290C}" = LP6940Trb
"{90150405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Access 2003
"{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}" = Nokia PC Suite
"{9C209B30-F71F-4c53-8D26-453208EC8E91}" = dj6940
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB1F3886-AE9F-46fb-8325-6B0718989285}" = dj_taplugin
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F69FD33C-8815-46BF-9134-A643DE68F3C0}" = WinFast(R) Display Driver
"05B59228C7E1C21DFBE89260F879BD95880548D8" = Balíček ovladače systému Windows - Nokia Modem (10/05/2009 4.2)
"504244733D18C8F63FF584AEB290E3904E791693" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Balíček ovladače systému Windows - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Balíček ovladače systému Windows - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"8CDCFB95BB84DD9C0F88F22266A0CA86035E55BA" = Balíček ovladače systému Windows - Nokia Modem (06/01/2009 7.01.0.4)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"Czech Racer_is1" = Czech Racer 1.0
"Euro Truck Simulator" = Euro Truck Simulator 1.1
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft Visual Basic 2005 Express Edition - ENU" = Microsoft Visual Basic 2005 Express Edition - ENU
"Mozilla Firefox (3.0.17)" = Mozilla Firefox (3.0.17)
"Nokia PC Suite" = Nokia PC Suite
"PSPad editor_is1" = PSPad editor
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"SystemRequirementsLab" = System Requirements Lab
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"XPlite" = XPlite PROFESSIONAL

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1292428093-926492609-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9.12.2009 11:16:30 | Computer Name = STROJ | Source = LoadPerf | ID = 3012
Description = Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces
Performance rozšíření zprostředkovatele čítačů. Hodnotu BaseIndex z registru výkonu
obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota
DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error - 9.12.2009 11:20:13 | Computer Name = STROJ | Source = Application Error | ID = 1000
Description = Chybující aplikace winamp.exe, verze 5.2.3.672, chybující modul ,
verze 0.0.0.0, adresa chyby 0x00000000.

Error - 9.12.2009 16:37:36 | Computer Name = STROJ | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace tak.vshost.exe, verze 8.0.50727.42, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 20.12.2009 2:12:02 | Computer Name = STROJ | Source = CardSpace 3.0.0.0 | ID = 327937
Description = Při přístupu do kolekce karet došlo k chybě. Bylo zjištěno, že buď
s adresářem skladu nebo se skladovými soubory ACLs bylo manipulováno. ACLs byly
obnoveny na jejich výchozí nastavení. Additional Information: v System.Environment.GetStackTrace(Exception
e, Boolean needFileInfo) v System.Environment.get_StackTrace() v Microsoft.InfoCards.Diagnostics.InfoCardTrace.BuildMessage(InfoCardBaseException
ie) v Microsoft.InfoCards.Diagnostics.InfoCardTrace.TraceAndLogException(Exception
e) v Microsoft.InfoCards.FileDataSource.LogIfAclsTampered(FileSystemInfo fileSysInfo)

v Microsoft.InfoCards.FileDataSource.OpenOrCreateHelper(FileInfo theFile, FileStream&
fileStream) v Microsoft.InfoCards.FileDataSource.CreateDirAndFiles() v Microsoft.InfoCards.FileDataSource.OnLoad()

v Microsoft.InfoCards.StoreConnection.Load() v Microsoft.InfoCards.StoreConnection.GetConnection(WindowsIdentity
identity, Boolean allowCreate) v Microsoft.InfoCards.StoreConnection.CreateConnection()

v Microsoft.InfoCards.ClientUIRequest.OnInitializeAsUser() v Microsoft.InfoCards.Request.Initialize()

v Microsoft.InfoCards.RequestFactory.CreateClientRequestInstance(UIAgentMonitorHandle
monitorHandle, String reqName, IntPtr rpcHandle, Stream inStream, Stream outStream)

v Microsoft.InfoCards.RequestFactory.ProcessNewRequest(Int32 parentRequestHandle,
IntPtr rpcHandle, IntPtr inArgs, IntPtr& outArgs)

Error - 3.1.2010 7:43:36 | Computer Name = STROJ | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace mplayerc.exe, verze 6.4.9.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 9.1.2010 15:28:56 | Computer Name = STROJ | Source = Application Error | ID = 1000
Description = Chybující aplikace pspad.exe, verze 4.5.4.2356, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0xfffffd8d.

Error - 9.1.2010 15:29:02 | Computer Name = STROJ | Source = Application Error | ID = 1000
Description = Chybující aplikace pspad.exe, verze 4.5.4.2356, chybující modul kernel32.dll,
verze 5.1.2600.5781, adresa chyby 0x00012afb.

Error - 16.1.2010 16:13:13 | Computer Name = STROJ | Source = Application Error | ID = 1000
Description = Chybující aplikace pspad.exe, verze 4.5.4.2356, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0x00000000.

Error - 24.1.2010 8:49:36 | Computer Name = STROJ | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace loterie.vshost.exe, verze 8.0.50727.42, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 24.1.2010 9:10:11 | Computer Name = STROJ | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace loterie.vshost.exe, verze 8.0.50727.42, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

[ System Events ]
Error - 27.1.2010 13:30:19 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:30:21 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:30:36 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:30:38 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:30:41 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:30:43 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:30:46 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:30:49 | Computer Name = STROJ | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk1\D má chybný blok.

Error - 27.1.2010 13:33:04 | Computer Name = STROJ | Source = Print | ID = 23
Description = Tiskárnu pdfFactory,0 se nepodařilo inicializovat, protože potřebný
ovladač pdfFactory 3 nebyl nalezen.

Error - 27.1.2010 13:33:19 | Computer Name = STROJ | Source = Service Control Manager | ID = 7000
Description = Služba TuneUp Theme Extension neuspěla při spuštění v důsledku následující
chyby: %%1083


< End of report >

pitimir
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 479
Registrován: 18 čer 2008 17:54
Bydliště: Šutrovec
Kontaktovat uživatele:

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#8 Příspěvek od pitimir »

No vidis :)
Inak dufam, ze s ten CF nemienis pustat na vlastne triko...

Skopiruj v OTL do policka pod nazvom "Custom Scans/Fixes":

Kód: Vybrat vše

:otl
DRV - [2009.09.24 01:30:11 | 00,000,000 | ---- | M] () [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\632f6b96.sys -- (632f6b96)
IE - HKU\S-1-5-21-1292428093-926492609-725345543-1005\..\URLSearchHook: {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O2 - BHO: (QIPBHO Class) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-21-1292428093-926492609-725345543-1005..\Run: [] File not found
O4 - HKU\S-1-5-21-1292428093-926492609-725345543-1005..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -Mozilla\5.0 ( File not found
O4 - Startup: C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění\wwwpos32.exe ()
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 6606050109 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O33 - MountPoints2\{e0f53175-4dce-11dd-a3c3-9965402625e2}\Shell\AutoRun\command - "" = J:\wd_windows_tools\WDSetup.exe -- File not found
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\wd_windows_tools\WDSetup.exe -- File not found
[2010.01.27 01:21:29 | 00,000,012 | ---- | C] () -- C:\Documents and Settings\NetworkService\Data aplikací\anvkgp.dat
[2010.01.27 01:21:21 | 00,000,004 | ---- | C] () -- C:\Documents and Settings\Lukáš\Data aplikací\avdrn.dat
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0CE7F3C9
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Lukáš\Plocha\Forrest_Gump_-_sample.mkv:SummaryInformation
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1

:commands
[resethosts]
[emptytemp]
[reboot]
Klikni na "Run Fix". Program zacne pracovat, mozny je restart PC. Po nom by sa ti mal objavit log, ten by som rad videl.
Ja som skromný, mám len dve veci do podpisu...

1) Chcete pomôcť fóru? Podporte ho_!!

2) Prosím všetkých, ktorí majú problém: :!:
- založte si vlastný topic a do 1. prispevku vložte log z RSIT a presný stručný popis problému.
- bez odporúčania nespúšťajte ŽIADEN iný program nájdený na fóre/internete.
- needitujte a nemažte príspevky.
- dodržujte inštrukcie a nerobte nič naviac (z vlastnej iniciatívy).

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#9 Příspěvek od Ideatore »

Kdepak, toho tam mam, kdyb byl potřeba. Posílám onen log:

All processes killed
========== OTL ==========
Service 632f6b96 stopped successfully!
Service 632f6b96 deleted successfully!
C:\WINDOWS\system32\drivers\632f6b96.sys moved successfully.
Registry value HKEY_USERS\S-1-5-21-1292428093-926492609-725345543-1005\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ not found.
File C:\Documents and Settings\Martin\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1292428093-926492609-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1292428093-926492609-725345543-1005\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Shockwave Updater deleted successfully.
File move failed. C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění\wwwpos32.exe scheduled to be moved on reboot.
Starting removal of ActiveX control {17492023-C23A-453E-A040-C7C580BBF700}
C:\WINDOWS\Downloaded Program Files\LegitCheckControl.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{17492023-C23A-453E-A040-C7C580BBF700}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17492023-C23A-453E-A040-C7C580BBF700}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{17492023-C23A-453E-A040-C7C580BBF700}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17492023-C23A-453E-A040-C7C580BBF700}\ not found.
Starting removal of ActiveX control {6414512B-B978-451D-A0D8-FCFDF33E833C}
C:\WINDOWS\Downloaded Program Files\wuweb.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6414512B-B978-451D-A0D8-FCFDF33E833C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6414512B-B978-451D-A0D8-FCFDF33E833C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6414512B-B978-451D-A0D8-FCFDF33E833C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6414512B-B978-451D-A0D8-FCFDF33E833C}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {D27CDB6E-AE6D-11CF-96B8-444553540000}
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\swflash.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found.
Starting removal of ActiveX control DirectAnimation Java Classes
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0f53175-4dce-11dd-a3c3-9965402625e2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0f53175-4dce-11dd-a3c3-9965402625e2}\ not found.
File J:\wd_windows_tools\WDSetup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J\ deleted successfully.
File J:\wd_windows_tools\WDSetup.exe not found.
C:\Documents and Settings\NetworkService\Data aplikací\anvkgp.dat moved successfully.
C:\Documents and Settings\Lukáš\Data aplikací\avdrn.dat moved successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:0CE7F3C9 deleted successfully.
ADS C:\Documents and Settings\Lukáš\Plocha\Forrest_Gump_-_sample.mkv:SummaryInformation deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1 deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator.STROJ
->Temp folder emptied: 10305 bytes
->Temporary Internet Files folder emptied: 320538 bytes
->FireFox cache emptied: 53524 bytes

User: Administrator.STROJ.000
->Temp folder emptied: 4615 bytes
->Temporary Internet Files folder emptied: 543068 bytes
->FireFox cache emptied: 3284592 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 100475 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 49554 bytes

User: Lukáš
->Temp folder emptied: 132888137 bytes
->Temporary Internet Files folder emptied: 13820235 bytes
->Java cache emptied: 70829388 bytes
->FireFox cache emptied: 136276807 bytes

User: Martin
->Temp folder emptied: 507500338 bytes
->Temporary Internet Files folder emptied: 320172498 bytes
->Java cache emptied: 47123475 bytes
->FireFox cache emptied: 154436821 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: User
->Temp folder emptied: 25839557 bytes
->Temporary Internet Files folder emptied: 1897950 bytes
->Java cache emptied: 43560515 bytes
->FireFox cache emptied: 71334766 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 10610867 bytes
%systemroot%\System32 .tmp files removed: 446811912 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 3193536 bytes
Windows Temp folder emptied: 1944969 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 15934276 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1 916,00 mb


OTL by OldTimer - Version 3.1.27.0 log created on 01272010_212610

Files\Folders moved on Reboot...
C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění\wwwpos32.exe moved successfully.

Registry entries deleted on Reboot...

pitimir
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 479
Registrován: 18 čer 2008 17:54
Bydliště: Šutrovec
Kontaktovat uživatele:

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#10 Příspěvek od pitimir »

Super. Zlepsilo sa spravanie PC? Malo by to byt lepsie aspon co sa tyka vytazenia...

Pojdes >>sem<< a das si spravit scan. Tu je navod (by sundavis):
Obrázek
Ja som skromný, mám len dve veci do podpisu...

1) Chcete pomôcť fóru? Podporte ho_!!

2) Prosím všetkých, ktorí majú problém: :!:
- založte si vlastný topic a do 1. prispevku vložte log z RSIT a presný stručný popis problému.
- bez odporúčania nespúšťajte ŽIADEN iný program nájdený na fóre/internete.
- needitujte a nemažte príspevky.
- dodržujte inštrukcie a nerobte nič naviac (z vlastnej iniciatívy).

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#11 Příspěvek od Ideatore »

Jo jo, už je to fajn, už nežere a i jinak se chová slušně. Ale ten scan našel tohle:

File name / Threat / Threats count
C:\Documents and Settings\Martin\Data aplikací\Thunderbird\Profiles\hxwsppyl.default\Mail\Local Folders\Inbox Infected: Worm.Win32.Feebs.gen 2
C:\Documents and Settings\Martin\Data aplikací\Thunderbird\Profiles\hxwsppyl.default\Mail\Local Folders\Inbox Infected: Trojan-Spy.Win32.Goldun.bce 1
C:\Documents and Settings\Martin\Plocha\e-shop\zálohy\images\index.html Infected: Trojan-Clicker.HTML.IFrame.ajv 1

Co s tim? přece bratrovi jen tak nesmažu poštu...

pitimir
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 479
Registrován: 18 čer 2008 17:54
Bydliště: Šutrovec
Kontaktovat uživatele:

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#12 Příspěvek od pitimir »

Ved to nie je hocijaka, ale infikovana posta :)
Ale ak chces, mozme sa v tom este povrtat a pohladat dalsich pripadnych nezelanych hosti.
Ja som skromný, mám len dve veci do podpisu...

1) Chcete pomôcť fóru? Podporte ho_!!

2) Prosím všetkých, ktorí majú problém: :!:
- založte si vlastný topic a do 1. prispevku vložte log z RSIT a presný stručný popis problému.
- bez odporúčania nespúšťajte ŽIADEN iný program nájdený na fóre/internete.
- needitujte a nemažte príspevky.
- dodržujte inštrukcie a nerobte nič naviac (z vlastnej iniciatívy).

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#13 Příspěvek od Ideatore »

No jo, ale Avira nic nehlásí, akorát ten Kaspersky a ten mi takhle zas nenahlásí, kterej mejl to je konkrétně a do tý pošty se nedostanu. A aby toho nebylo málo, bratr tu není. Jinak to zatím všechno běhá normálně.

pitimir
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 479
Registrován: 18 čer 2008 17:54
Bydliště: Šutrovec
Kontaktovat uživatele:

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#14 Příspěvek od pitimir »

Stiahni ComboFix, najlepsie na plochu. Vypni vsetky otvorene aplikacie, ako aj rezidenty antiviru, antispywaru a firewall. Spust program cez ucet s administratorskymi pravami a postupuj podla instrukcii. Cely sken bude trvat cca 10 minut. Pocas neho moze byt PC restartovane. Log, ktory ComboFix vytvori, najdes na adrese "C:\ComboFix.txt".
Ten vloz sem.

Pozor: Kym ComboFix nevytvori log, na nic neklikat, nic nestlacat !!
Ja som skromný, mám len dve veci do podpisu...

1) Chcete pomôcť fóru? Podporte ho_!!

2) Prosím všetkých, ktorí majú problém: :!:
- založte si vlastný topic a do 1. prispevku vložte log z RSIT a presný stručný popis problému.
- bez odporúčania nespúšťajte ŽIADEN iný program nájdený na fóre/internete.
- needitujte a nemažte príspevky.
- dodržujte inštrukcie a nerobte nič naviac (z vlastnej iniciatívy).

Ideatore
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 říj 2006 16:52

Re: svchost.exe žere cpu, antivir nahlásil RKIT/Kryptic.763904

#15 Příspěvek od Ideatore »

Tak jsem si dal CF, všechno jelo jak mělo, ale pak mi vyskočila modrá vobrazovka a už to jelo:D následoval restart a pak už jen chyba při načítání operačního systému. konzola pro zotavení z install cd win nepomůže, páč to s tim diskem odmítá komunikovat, stejně tak live ubuntu. Já si ale vyhraju:D:D

edit: naštěstí si s tim duo fixmbr, fixboot poradilo a já sem můžu dát log z CF:

ComboFix 10-01-26.05 - Administrator . 01. 2010 9:28.3.1 - x86 MINIMAL
Spuštěný z: c:\documents and settings\Administrator.STROJ.000\Plocha\ComboFix.exe

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Předchozí spuštění -------
.
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\_003433_.tmp.dll
c:\windows\system32\_003435_.tmp.dll
c:\windows\system32\_003441_.tmp.dll
c:\windows\system32\_003443_.tmp.dll
c:\windows\system32\_003449_.tmp.dll
c:\windows\system32\_003451_.tmp.dll
c:\windows\system32\_003457_.tmp.dll
c:\windows\system32\_003459_.tmp.dll
c:\windows\system32\_003465_.tmp.dll
c:\windows\system32\_003467_.tmp.dll
c:\windows\system32\_003473_.tmp.dll
c:\windows\system32\_003475_.tmp.dll
c:\windows\system32\_003637_.tmp.dll
c:\windows\system32\_003639_.tmp.dll
c:\windows\system32\_003647_.tmp.dll
c:\windows\system32\_003648_.tmp.dll
c:\windows\system32\_003649_.tmp.dll
c:\windows\system32\_003651_.tmp.dll
c:\windows\system32\_003652_.tmp.dll
c:\windows\system32\_003655_.tmp.dll
c:\windows\system32\_003656_.tmp.dll
c:\windows\system32\_003665_.tmp.dll
c:\windows\system32\_003666_.tmp.dll
c:\windows\system32\_003671_.tmp.dll
c:\windows\system32\_003673_.tmp.dll
c:\windows\system32\_003676_.tmp.dll
c:\windows\system32\_003679_.tmp.dll
c:\windows\system32\_003681_.tmp.dll
c:\windows\system32\_003682_.tmp.dll
c:\windows\system32\_003686_.tmp.dll
c:\windows\system32\_003687_.tmp.dll
c:\windows\system32\_003688_.tmp.dll
c:\windows\system32\_003689_.tmp.dll
c:\windows\system32\_003694_.tmp.dll
c:\windows\system32\sstray.exe
c:\windows\system32\twain_32.dll

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_win32x
-------\Service_glaide32
-------\Service_win32x


((((((((((((((((((((((((( Soubory vytvořené od 2009-12-28 do 2010-01-31 )))))))))))))))))))))))))))))))
.

2010-01-27 20:26 . 2010-01-27 20:26 -------- dc----w- C:\_OTL
2010-01-27 00:26 . 2008-04-13 23:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-01-27 00:25 . 2008-04-13 23:11 8192 -c--a-w- c:\windows\system32\drivers\changer.sys
2010-01-27 00:25 . 2008-04-13 23:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-01-23 00:28 . 2010-01-23 00:28 -------- dc----w- c:\program files\Common Files\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 12:58 . 2008-07-21 09:58 -------- dc----w- c:\program files\AVerTV DVB-T
2010-01-30 12:16 . 2008-07-28 11:11 -------- dc----w- c:\program files\Mozilla Thunderbird
2010-01-23 00:28 . 2008-08-06 20:34 -------- dc----r- c:\program files\Skype
2010-01-18 12:43 . 2009-05-01 10:49 56816 -c--a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-10 17:54 . 2008-07-10 02:28 -------- dc----w- c:\program files\Totalcmd
2010-01-05 14:45 . 2008-07-09 16:50 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-12-26 06:55 . 2009-06-03 00:34 -------- dc----w- c:\program files\PokerStars
2009-12-22 21:20 . 2009-10-26 23:08 -------- dc----w- c:\program files\Mobile Master
2009-12-20 19:36 . 2008-12-30 13:30 -------- dc----w- c:\program files\HP
2009-12-20 19:32 . 2009-12-20 19:21 105710 -c--a-w- c:\windows\HPFins09.dat
2009-12-14 17:44 . 2009-06-02 19:35 -------- dc----w- c:\program files\Penezni denik
2009-12-11 01:21 . 2009-12-11 01:17 -------- dc----w- c:\program files\Mobiola Web Camera 2 for S60 2nd Edition
2009-12-10 21:50 . 2009-12-10 21:50 0 -c-ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-12-10 21:50 . 2009-12-10 21:50 0 -c-ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-12-10 14:50 . 2009-12-10 14:50 -------- dc----w- c:\program files\Common Files\PCSuite
2009-12-10 14:50 . 2009-12-10 14:50 -------- dc----w- c:\program files\Common Files\Nokia
2009-12-10 14:48 . 2008-07-10 01:58 -------- dc----w- c:\program files\DIFX
2009-12-10 14:48 . 2009-02-15 19:36 -------- dc----w- c:\program files\PC Connectivity Solution
2009-12-10 14:45 . 2008-07-10 01:57 -------- dc----w- c:\program files\Nokia
2009-12-09 19:57 . 2009-12-09 19:56 -------- dc----w- c:\program files\Microsoft Visual Studio 8
2009-12-09 15:16 . 2002-09-23 12:00 855012 ----a-w- c:\windows\system32\perfh005.dat
2009-12-09 15:16 . 2002-09-23 12:00 227990 ----a-w- c:\windows\system32\perfc005.dat
2009-07-28 16:51 . 2009-07-28 16:51 266717 -c--a-w- c:\program files\setuplog.txt
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-10-30 13801]
"TSClientAXDisabler"="c:\windows\Installer\TSClientMsiTrans\tscdsbl.bat" [2008-01-18 2247]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Probe"="c:\program files\ASUS\Probe\AsusProb.exe" [2002-12-06 617984]
"nForce Tray Options"="sstray.exe" [BU]
"CHotkey"="mHotkey.exe" [2002-07-05 491008]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2007-05-11 2512392]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2005-01-26 1490944]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2008-10-07 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"QuickDVBT"=c:\program files\AVerTV DVB-T\QuickDVB-T.exe
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
"OPSE reminder"="c:\program files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "c:\program files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"NPSStartup"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQLite\\ICQLite.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\StrongDC\\StrongDC.exe"=
"c:\\Program Files\\Sony\\Vegas 6.0\\VegSrv60.exe"=
"f:\\hry\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"c:\\Program Files\\VLC\\vlc.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Martin\\Plocha\\Miranda\\Miranda\\miranda32.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13144:TCP"= 13144:TCP:++1
"13144:UDP"= 13144:UDP:++2

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-10-29 691696]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-06-15 108289]
R2 ATTSCAP;AVerMedia, WDM MPEG-2 TS Capture (DVBT);c:\windows\system32\drivers\attscap.sys [2003-06-24 18048]
R2 ATVCAP;AVerMedia, DVB-T WDM Video Capture;c:\windows\system32\drivers\atvcap.sys [2003-06-24 56320]
R2 ATXBAR;AVerMedia, DVB-T WDM Crossbar;c:\windows\system32\drivers\ATXBAR.sys [2003-06-24 8576]
R2 dvdmmg;dvdmmg;c:\windows\system32\drivers\dvdmmg.sys [2007-09-06 5504]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\system32\DRIVERS\BTCamDrv.sys [2006-11-01 219264]
R3 cpuz130;cpuz130;c:\docume~1\LUK~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\System32\drivers\sfsync03.sys [2005-12-06 35328]
S0 si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\si3112r.sys [2007-02-01 110128]
S0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [2007-02-01 17328]


--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - ATXBAR
.
.
------- Doplňkový sken -------
.
FF - ProfilePath - c:\documents and settings\Administrator.STROJ.000\Data aplikací\Mozilla\Firefox\Profiles\hgqxe8hb.default\
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-31 09:35
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="C988BE2ABDBD27317048B3283C3A9E62607428B37D7E2C62CD3C11D2B97737E64956A653A9A7B77F292FC99EF8C1E8940A736F665217F6B6DEDDAA1BEED0D4400CE3B9B4438010C59722AC4C31F8BD566A269504CF7E740C1AFE4B3D434158ECC72839A62226311B16344A0EEB6B1BD39B5C500E8E0F3CC2FA4B90827F0D8F237D49CCD55FEB44A8C22B6F163419A0CCFC98B75BA99484D0C2A27B07EEEF6C2BEBA5FD45971912307E7ED16996749315B1114697C0CF2C3FF5177139E2180666184C3C46ED688B84F1DD076329E7D895A0AFDEC07676B32A5B713C5C302593C4CC8258048788428B84FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79339DB7CE019D40AA5CC038D530D6EB34529DB7CE019D40AA5CB75486B957DDD9EE3C79A99873AF0CA3759F40C119422D011D4F8D62410AC35D0321288A64554FEC6E187F86BE69FAAE5402B3DE732FA06CD7E643DA78E81648A58C7B97CE7ECEDC928EC92F135BCCE812F7CCEE5A53E0907C7DC11CDBA0B82A1F3A3B4D6E6DC41E2506A75156EF6254CA55AF9FDF1363B1E0305567CD2ED529222EF69E93572ED7570C902DE4B6AE374B52D5240D75AF56117F9CFE23B22B2B1851927C7F951DF20D15CA0A8BE2B81C15888D33DD27E34ACACE092AA47309DD9A72C7E2E8A6B99BDEF574310F4A9CD0DC787907C1F72E9B0168E3B79058D431F9C21F4CF72C3CC21AE9FD6F27E787680C860EDD1C5B559E5876C5F2966E89D8B8D67BB94DEBF39FBD0FAB167CDBBF37C177957C47E92F69AD0B1EB3DCE7B1CD90A80FB0F851432880E797FC31E61A584E792E278D5F28598F1930CE7A18704C6B95E03A8167209C485AAD7BD4F282AA371949A8AF1BC20ABDFA92207EF8FAD2E95ECD6161E1147C34312EF07087F7CE37CC2C5160229061B1EB2F88E92619A65EA906B706163F0D131B2F3DFE560FAC3A6A71F1491B3C06940BC56BAFE22AD0D0808C5152FED1D7692B98C7EFB1ED6DE2AC87E206538062C5DE68AFBA121E1B7C4FB8C71B39932AF055A679A48ED07F8534AE7EA5B82E26574FFEC1673D7A98D1E738B62B085E9495F56C3F750A05932D047C22ADE0A8450F28C3908710D89AF2010940C0501FEC774BCB0C2D62EF229604DCB19583E9F4E89A45115F5D66BBB832FE088D1B5B4BEBF67F550B7A8864B37E0B1348FAFC31113AE5B9A799E3D62EF943363718260EFA019293C1D858D7A9239BB1A7C982B9EC7FDC068D5DA78B92B94F77D8982B556051E746F7A881BFD10671FB0691AE12124735F5B266993FD9B5F5FE7E92A8070F38B2EC49B835A1B91F47E22D9B4A004AD1CD8D2C93381AAB98587D2D9F70CC29687D0FC47DB9C7A3C7AC60D753318F944458D403EA9407E1EF6F2FD77DE9"
.
Celkový čas: 2010-01-31 09:38:21
ComboFix-quarantined-files.txt 2010-01-31 08:38

Před spuštěním: 6 959 386 624
Po spuštění: 6 905 929 728

- - End Of File - - F422F614E2D6A8F522347F436D0639BE

Odpovědět