Dobry den, po navstiveni jedne webove stranky, byl muj system napaden a vznikla chyba s svchost.exe 99procent zazizeni PC. V nouzovem rezimu jsem udelal Rsit Log a nasledny Combofix. Jestli muzete poradit co dal?
Mimochodem, je to obycejna stranka ktera slibuje obsah simpsonovi online. Divim se na ni vyhledavace neupozornuji jako to obcas dela google.
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-04-03 17:25:09
Systém Microsoft Windows XP Professional Service Pack 2
System drive D: has 889 MB (13%) free of 7 GB
Total RAM: 255 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:25:10, on 3.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\taskmgr.exe
D:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\RSIT.exe
C:\Programy\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] "D:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
--
End of file - 2976 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-15 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-15 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=D:\WINDOWS\SOUNDMAN.EXE [2006-08-03 577536]
"nod32kui"=D:\Program Files\Eset\nod32kui.exe [2008-03-24 921600]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2005-02-24 5537792]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=D:\WINDOWS\system32\NvMcTray.dll [2005-02-24 86016]
"VirtualCloneDrive"=D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2006-04-29 94208]
"SunJavaUpdateSched"=D:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Mozilla Firefox\firefox.exe"="D:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"D:\Program Files\Vuze\Azureus.exe"="D:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\VideoLAN\VLC\vlc.exe"="D:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"D:\Program Files\QIP\qip.exe"="D:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-03 17:25:09 ----D---- D:\rsit
2010-04-03 17:22:27 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Macromedia
2010-04-03 17:22:27 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Adobe
2010-04-03 17:21:59 ----D---- D:\Documents and Settings\Administrator\Data aplikací\Mozilla
2010-04-03 02:11:46 ----A---- D:\WINDOWS\system32\fjhdyfhsn.bat
2010-03-21 17:25:22 ----SHD---- D:\RECYCLER
2010-03-07 16:45:43 ----D---- D:\WINDOWS\temp
2010-03-07 16:35:45 ----ASH---- D:\Documents and Settings\Administrator\Data aplikací\desktop.ini
2010-03-07 16:35:44 ----SD---- D:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-03-07 16:35:38 ----SHD---- D:\WINDOWS\CSC
2010-03-07 16:35:31 ----A---- D:\WINDOWS\ntbtlog.txt
======List of files/folders modified in the last 1 months======
2010-04-03 17:16:29 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-04-03 14:17:36 ----D---- D:\WINDOWS\Prefetch
2010-04-03 02:13:09 ----RSHDC---- D:\WINDOWS\system32\dllcache
2010-04-03 02:13:03 ----D---- D:\WINDOWS\system32\drivers
2010-04-03 02:12:28 ----D---- D:\WINDOWS\system32\CatRoot2
2010-04-03 02:11:46 ----D---- D:\WINDOWS\system32
2010-04-03 00:32:43 ----D---- D:\Program Files\Mozilla Firefox
2010-03-29 17:53:42 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-03-21 17:22:01 ----D---- D:\WINDOWS\Minidump
2010-03-21 17:21:12 ----SHD---- D:\System Volume Information
2010-03-21 17:21:12 ----D---- D:\WINDOWS\system32\Restore
2010-03-21 17:21:09 ----D---- D:\WINDOWS
2010-03-21 17:20:47 ----RD---- D:\Program Files
2010-03-21 13:53:35 ----A---- D:\WINDOWS\system.ini
2010-03-21 13:47:25 ----D---- D:\WINDOWS\AppPatch
2010-03-21 13:47:21 ----D---- D:\Program Files\Common Files
2010-03-07 16:35:43 ----D---- D:\Documents and Settings
2010-03-06 20:21:29 ----A---- D:\WINDOWS\winamp.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; D:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R3 ElbyDelay;ElbyDelay; D:\WINDOWS\System32\Drivers\ElbyDelay.sys [2005-04-12 4608]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; D:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 AmdK7;Ovladač procesoru AMD K7; D:\WINDOWS\system32\DRIVERS\amdk7.sys [2004-08-17 41216]
S1 DumaNT;NVIDIA Stereo Helper Service; D:\WINDOWS\system32\DRIVERS\dumant.sys [2002-03-09 393784]
S2 AMON;AMON; \??\D:\WINDOWS\system32\drivers\amon.sys []
S2 ElbyCDIO;ElbyCDIO Driver; D:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2006-04-22 8064]
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); D:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-10-13 4022528]
S3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-02-24 3454144]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; D:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S2 NOD32krn;NOD32 Kernel Service; D:\Program Files\Eset\nod32krn.exe [2008-03-24 507904]
S2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2005-02-24 127043]
S2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\wmpnetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
ComboFix 10-04-02.01 - Administrator 03.04.2010 17:29:16.5.1 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.255.62 [GMT 2:00]
Spuštěný z: d:\documents and settings\Administrator\Dokumenty\Stažené soubory\ComboFix.exe
AV: Eset NOD32 Antivirus 2.51 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\system32\fjhdyfhsn.bat
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-03 do 2010-04-03 )))))))))))))))))))))))))))))))
.
2010-04-03 15:25 . 2010-04-03 15:25 -------- d-----w- D:\rsit
2010-04-03 00:12 . 2010-04-03 15:33 804864 ----a-w- d:\windows\system32\drivers\gtpkq.sys
2010-03-07 02:02 . 2004-08-03 21:59 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys
2010-03-07 02:02 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\changer.sys
2010-03-07 02:02 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-29 15:53 . 2001-10-25 14:00 46016 ----a-w- d:\windows\system32\perfc005.dat
2010-03-29 15:53 . 2001-10-25 14:00 309716 ----a-w- d:\windows\system32\perfh005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 577536]
"nod32kui"="d:\program files\Eset\nod32kui.exe" [2008-03-24 921600]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"nwiz"="nwiz.exe" [2005-02-24 1495040]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2005-02-24 86016]
"VirtualCloneDrive"="d:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
d:\documents and settings\lama\Nabˇdka Start\Programy\Po spuçtŘnˇ\
syspck32.exe [2004-8-17 29696]
d:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - d:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Program Files\\Vuze\\Azureus.exe"=
"d:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\Program Files\\QIP\\qip.exe"=
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - gtpkq
.
.
------- Doplňkový sken -------
.
LSP: d:\windows\system32\imon.dll
FF - ProfilePath - d:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\aautxks2.default\
FF - plugin: d:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- NASTAVENÍ FIREFOXU ----
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
d:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-HijackThis - d:\program files\trend micro\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-03 17:33
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gtpkq]
.
Celkový čas: 2010-04-03 17:35:10
ComboFix-quarantined-files.txt 2010-04-03 15:35
Před spuštěním: 898 646 016
Po spuštění: 873 013 248
- - End Of File - - 887E0494508142BF0D9273A6668F2150

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o vyreseni problemu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosim o vyreseni problemu
Za ten ComboFix se omlouvam, ale prave protoze mam tolik prizpevku vim, ze za Rsit logem zpravidla nasleduje ze mam spustit combofix a tak jsem chtel usetrit cas
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/04/03 18:16
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: D:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF79F5000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: D:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF9F5A000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: D:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF60B5000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: D:\hiberfil.sys
Status: Locked to the Windows API!
Path: D:\WINDOWS\system32\drivers\gtpkq.sys
Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x81b7aaa0 Size: 1376
Hidden Services
-------------------
Service Name: gtpkq
Image Path: D:\WINDOWS\system32\drivers\gtpkq.sys
==EOF==
OTL logfile created on: 3.4.2010 18:40:39 - Run 1
OTL by OldTimer - Version 3.2.1.0 Folder = D:\Documents and Settings\lama\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
255,00 Mb Total Physical Memory | 55,00 Mb Available Physical Memory | 21,00% Memory free
618,00 Mb Paging File | 374,00 Mb Available in Paging File | 61,00% Paging File free
Paging file location(s): D:\pagefile.sys 384 768 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 25,62 Gb Total Space | 2,61 Gb Free Space | 10,17% Space Free | Partition Type: NTFS
Drive D: | 6,79 Gb Total Space | 0,57 Gb Free Space | 8,33% Space Free | Partition Type: NTFS
Drive E: | 702,24 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: WHO
Current User Name: lama
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.04.03 18:35:31 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
PRC - [2010.04.03 00:32:23 | 000,910,296 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008.03.24 18:40:14 | 000,921,600 | ---- | M] (Eset ) -- D:\Program Files\ESET\nod32kui.exe
PRC - [2008.03.24 18:40:13 | 000,507,904 | ---- | M] (Eset ) -- D:\Program Files\ESET\nod32krn.exe
PRC - [2006.08.03 06:12:36 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\soundman.exe
PRC - [2006.04.29 15:21:28 | 000,094,208 | ---- | M] (Elaborate Bytes AG) -- D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
PRC - [2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010.04.03 18:35:31 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
MOD - [2004.08.17 15:48:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2008.03.24 18:40:13 | 000,507,904 | ---- | M] (Eset ) [Auto | Running] -- D:\Program Files\Eset\nod32krn.exe -- (NOD32krn)
========== Driver Services (SafeList) ==========
DRV - [2008.03.24 18:40:21 | 000,502,368 | ---- | M] (Eset ) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\amon.sys -- (AMON)
DRV - [2006.10.13 18:31:00 | 004,022,528 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006.04.22 21:59:21 | 000,024,320 | ---- | M] (Elaborate Bytes AG) [Kernel | Boot | Running] -- D:\WINDOWS\system32\DRIVERS\VClone.sys -- (VClone)
DRV - [2006.04.22 03:44:39 | 000,008,064 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2005.04.12 10:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2005.02.24 08:32:00 | 003,454,144 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004.08.04 00:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- D:\WINDOWS\system32\drivers\changer.sys -- (Changer)
DRV - [2004.08.03 23:59:34 | 000,034,688 | ---- | M] (Toshiba Corp.) [Kernel | System | Stopped] -- D:\WINDOWS\system32\drivers\lbrtfdc.sys -- (lbrtfdc)
DRV - [2002.03.09 12:53:00 | 000,393,784 | ---- | M] (NVIDIA Corporation) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\dumant.sys -- (DumaNT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-299502267-1645522239-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.centrum.cz"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010.04.03 17:22:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010.04.03 00:32:32 | 000,000,000 | ---D | M]
[2009.01.15 20:55:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla\Extensions
[2010.04.02 22:57:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla\Firefox\Profiles\miqofcyt.default\extensions
[2009.12.22 04:46:29 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla\Firefox\Profiles\miqofcyt.default\extensions\dave2x@download
[2010.04.02 22:57:02 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions
[2010.03.21 19:22:33 | 000,000,638 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.03.21 19:22:33 | 000,001,687 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.03.21 19:22:33 | 000,001,367 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.03.21 19:22:33 | 000,000,654 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.03.21 19:22:33 | 000,001,179 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.03.21 13:53:04 | 000,000,027 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [nod32kui] D:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SoundMan] D:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [VirtualCloneDrive] D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - Startup: D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: D:\Documents and Settings\lama\Nabídka Start\Programy\Po spuštění\syspck32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - D:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - D:\WINDOWS\System32\imon.dll (Eset )
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.10.10.1 10.10.10.2
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: D:\Documents and Settings\lama\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\lama\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.01.26 18:29:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - D:\WINDOWS\system32\ias [2008.03.24 18:28:34 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)
========== Files/Folders - Created Within 7 Days ==========
[2010.04.03 18:34:17 | 000,561,664 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
[2010.04.03 18:13:43 | 000,472,064 | ---- | C] ( ) -- D:\RootRepeal.exe
[2010.04.03 17:35:13 | 000,000,000 | ---D | C] -- D:\WINDOWS\temp
[2010.04.03 17:28:32 | 000,212,480 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWXCACLS.exe
[2010.04.03 17:28:32 | 000,161,792 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWREG.exe
[2010.04.03 17:28:32 | 000,136,704 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWSC.exe
[2010.04.03 17:28:32 | 000,031,232 | ---- | C] (NirSoft) -- D:\WINDOWS\NIRCMD.exe
[2010.04.03 17:28:26 | 000,000,000 | ---D | C] -- D:\WINDOWS\ERDNT
[2010.04.03 17:27:51 | 000,000,000 | ---D | C] -- D:\Qoobox
[2010.04.03 17:25:09 | 000,000,000 | ---D | C] -- D:\rsit
[2010.04.03 00:10:57 | 000,000,000 | ---D | C] -- D:\Documents and Settings\lama\Dokumenty\Stažené soubory
[2009.06.13 23:26:08 | 000,000,000 | --SD | M] -- D:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2008.12.25 22:33:34 | 000,000,000 | ---D | M] -- D:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2008.03.24 18:35:33 | 000,000,000 | --SD | M] -- D:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2008.03.24 18:35:32 | 000,000,000 | ---D | M] -- D:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2010.04.03 18:47:09 | 000,804,864 | ---- | M] () -- D:\WINDOWS\System32\drivers\gtpkq.sys
[2010.04.03 18:35:31 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
[2010.04.03 18:14:43 | 000,000,000 | ---- | M] () -- D:\settings.dat
[2010.04.03 18:12:50 | 000,464,491 | ---- | M] () -- D:\RootRepeal.zip
[2010.04.03 17:56:43 | 000,021,828 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml
[2010.04.03 17:56:37 | 000,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2010.04.03 17:56:32 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010.04.03 17:56:31 | 267,964,416 | -HS- | M] () -- D:\hiberfil.sys
[2010.04.03 17:33:29 | 000,000,227 | ---- | M] () -- D:\WINDOWS\system.ini
[2010.04.03 17:16:09 | 003,407,872 | -H-- | M] () -- D:\Documents and Settings\lama\NTUSER.DAT
[2010.04.03 17:16:09 | 000,000,178 | -HS- | M] () -- D:\Documents and Settings\lama\ntuser.ini
[2010.04.03 17:15:44 | 005,322,748 | -H-- | M] () -- D:\Documents and Settings\lama\Local Settings\Data aplikací\IconCache.db
[2010.04.03 02:11:14 | 000,000,008 | ---- | M] () -- D:\Documents and Settings\lama\Data aplikací\avdrn.dat
[2010.04.03 00:11:10 | 006,278,021 | ---- | M] () -- D:\Documents and Settings\lama\Plocha\GitaraUstna.wmv
[2010.04.02 22:46:14 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2010.03.29 17:53:44 | 000,311,604 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2010.03.29 17:53:44 | 000,039,992 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2010.03.29 17:53:43 | 000,309,716 | ---- | M] () -- D:\WINDOWS\System32\perfh005.dat
[2010.03.29 17:53:43 | 000,046,016 | ---- | M] () -- D:\WINDOWS\System32\perfc005.dat
[2010.03.29 17:53:42 | 000,714,818 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.04.03 18:14:43 | 000,000,000 | ---- | C] () -- D:\settings.dat
[2010.04.03 18:11:27 | 000,464,491 | ---- | C] () -- D:\RootRepeal.zip
[2010.04.03 17:56:31 | 267,964,416 | -HS- | C] () -- D:\hiberfil.sys
[2010.04.03 17:28:32 | 000,261,632 | ---- | C] () -- D:\WINDOWS\PEV.exe
[2010.04.03 17:28:32 | 000,098,816 | ---- | C] () -- D:\WINDOWS\sed.exe
[2010.04.03 17:28:32 | 000,080,412 | ---- | C] () -- D:\WINDOWS\grep.exe
[2010.04.03 17:28:32 | 000,077,312 | ---- | C] () -- D:\WINDOWS\MBR.exe
[2010.04.03 17:28:32 | 000,068,096 | ---- | C] () -- D:\WINDOWS\zip.exe
[2010.04.03 02:12:39 | 000,804,864 | ---- | C] () -- D:\WINDOWS\System32\drivers\gtpkq.sys
[2010.04.03 02:11:33 | 000,000,008 | ---- | C] () -- D:\Documents and Settings\NetworkService\Data aplikací\jasltw.dat
[2010.04.03 00:11:02 | 006,278,021 | ---- | C] () -- D:\Documents and Settings\lama\Plocha\GitaraUstna.wmv
[2010.03.07 04:01:55 | 000,000,016 | ---- | C] () -- D:\Documents and Settings\NetworkService\Data aplikací\rbuwzv.dat
[2010.03.07 04:01:43 | 000,000,008 | ---- | C] () -- D:\Documents and Settings\lama\Data aplikací\avdrn.dat
[2009.12.05 23:44:37 | 000,000,600 | ---- | C] () -- D:\Documents and Settings\lama\Data aplikací\winscp.rnd
[2009.12.05 22:29:14 | 000,000,600 | ---- | C] () -- D:\Documents and Settings\lama\PUTTY.RND
[2009.02.01 20:22:16 | 000,000,390 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2009.01.14 18:45:58 | 000,000,754 | ---- | C] () -- D:\WINDOWS\WORDPAD.INI
[2008.05.20 17:41:30 | 000,025,600 | ---- | C] () -- D:\Documents and Settings\lama\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.24 18:44:23 | 000,000,095 | ---- | C] () -- D:\WINDOWS\winamp.ini
[2008.03.24 18:44:22 | 000,088,064 | ---- | C] () -- D:\WINDOWS\System32\AudioExCtl.dll
[2008.03.24 18:39:20 | 000,143,360 | ---- | C] () -- D:\WINDOWS\System32\RtlCPAPI.dll
[2008.03.24 18:36:47 | 000,000,178 | -HS- | C] () -- D:\Documents and Settings\lama\ntuser.ini
[2008.03.24 18:36:45 | 000,001,024 | -H-- | C] () -- D:\Documents and Settings\lama\NTUSER.DAT.LOG
[2008.03.24 18:36:44 | 003,407,872 | -H-- | C] () -- D:\Documents and Settings\lama\NTUSER.DAT
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- D:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | ---- | C] () -- D:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,761,856 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- D:\WINDOWS\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | ---- | C] () -- D:\WINDOWS\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | ---- | C] () -- D:\WINDOWS\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\ogg.dll
[2005.02.24 08:32:00 | 000,540,672 | ---- | C] () -- D:\WINDOWS\System32\nvhwvid.dll
[2005.02.05 17:29:17 | 000,286,208 | ---- | C] () -- D:\WINDOWS\System32\CNCS232.DLL
[2004.08.17 15:49:10 | 000,081,920 | ---- | C] () -- D:\WINDOWS\System32\ieencode.dll
[2004.07.17 11:36:38 | 000,027,440 | ---- | C] () -- D:\WINDOWS\System32\drivers\secdrv.sys
[2002.03.09 12:53:00 | 000,368,640 | ---- | C] () -- D:\WINDOWS\System32\nvimage.dll
[2002.03.09 12:53:00 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\stereoi.dll
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- D:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2009.01.29 15:59:15 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\Azureus
[2009.06.11 03:41:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Azureus
[2009.01.29 01:20:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\BitSpirit
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
[2009.08.13 11:14:18 | 000,472,064 | ---- | M] ( ) -- D:\RootRepeal.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008.04.06 16:27:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Adobe
[2008.05.14 14:51:29 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\AdobeUM
[2009.06.11 03:41:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Azureus
[2009.01.29 01:20:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\BitSpirit
[2008.03.24 18:36:55 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Identities
[2008.12.27 03:30:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\InstallShield
[2008.03.24 18:46:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Macromedia
[2009.03.02 21:12:51 | 000,000,000 | --SD | M] -- D:\Documents and Settings\lama\Data aplikací\Microsoft
[2009.01.15 20:55:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla
[2009.01.26 23:02:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Sun
[2009.06.13 22:59:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\vlc
< %APPDATA%\*.exe /s >
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- D:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- D:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\ERDNT\cache\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\ERDNT\cache\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.03 22:59:10 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- D:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2004.08.04 00:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- D:\WINDOWS\system32\drivers\changer.sys
< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\ERDNT\cache\lsass.exe
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\ERDNT\cache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\ERDNT\cache\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\ERDNT\cache\scecli.dll
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- D:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- D:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\ERDNT\cache\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\ERDNT\cache\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\system32\dllcache\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\ERDNT\cache\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\ERDNT\cache\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\ERDNT\cache\ws2_32.dll
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.04.03 19:05:12 | 000,804,864 | ---- | M] () Unable to obtain MD5 -- D:\WINDOWS\system32\drivers\gtpkq.sys
< %systemroot%\System32\config\*.sav >
[2008.03.24 19:09:52 | 000,094,208 | ---- | M] () -- D:\WINDOWS\system32\config\default.sav
[2008.03.24 19:09:52 | 000,663,552 | ---- | M] () -- D:\WINDOWS\system32\config\software.sav
[2008.03.24 19:09:51 | 000,454,656 | ---- | M] () -- D:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< End of report >

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/04/03 18:16
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: D:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF79F5000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: D:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF9F5A000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: D:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF60B5000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: D:\hiberfil.sys
Status: Locked to the Windows API!
Path: D:\WINDOWS\system32\drivers\gtpkq.sys
Status: Locked to the Windows API!
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x81b7aaa0 Size: 1376
Hidden Services
-------------------
Service Name: gtpkq
Image Path: D:\WINDOWS\system32\drivers\gtpkq.sys
==EOF==
OTL logfile created on: 3.4.2010 18:40:39 - Run 1
OTL by OldTimer - Version 3.2.1.0 Folder = D:\Documents and Settings\lama\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
255,00 Mb Total Physical Memory | 55,00 Mb Available Physical Memory | 21,00% Memory free
618,00 Mb Paging File | 374,00 Mb Available in Paging File | 61,00% Paging File free
Paging file location(s): D:\pagefile.sys 384 768 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 25,62 Gb Total Space | 2,61 Gb Free Space | 10,17% Space Free | Partition Type: NTFS
Drive D: | 6,79 Gb Total Space | 0,57 Gb Free Space | 8,33% Space Free | Partition Type: NTFS
Drive E: | 702,24 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: WHO
Current User Name: lama
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.04.03 18:35:31 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
PRC - [2010.04.03 00:32:23 | 000,910,296 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008.03.24 18:40:14 | 000,921,600 | ---- | M] (Eset ) -- D:\Program Files\ESET\nod32kui.exe
PRC - [2008.03.24 18:40:13 | 000,507,904 | ---- | M] (Eset ) -- D:\Program Files\ESET\nod32krn.exe
PRC - [2006.08.03 06:12:36 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\soundman.exe
PRC - [2006.04.29 15:21:28 | 000,094,208 | ---- | M] (Elaborate Bytes AG) -- D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
PRC - [2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010.04.03 18:35:31 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
MOD - [2004.08.17 15:48:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2008.03.24 18:40:13 | 000,507,904 | ---- | M] (Eset ) [Auto | Running] -- D:\Program Files\Eset\nod32krn.exe -- (NOD32krn)
========== Driver Services (SafeList) ==========
DRV - [2008.03.24 18:40:21 | 000,502,368 | ---- | M] (Eset ) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\amon.sys -- (AMON)
DRV - [2006.10.13 18:31:00 | 004,022,528 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006.04.22 21:59:21 | 000,024,320 | ---- | M] (Elaborate Bytes AG) [Kernel | Boot | Running] -- D:\WINDOWS\system32\DRIVERS\VClone.sys -- (VClone)
DRV - [2006.04.22 03:44:39 | 000,008,064 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2005.04.12 10:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2005.02.24 08:32:00 | 003,454,144 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004.08.04 00:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- D:\WINDOWS\system32\drivers\changer.sys -- (Changer)
DRV - [2004.08.03 23:59:34 | 000,034,688 | ---- | M] (Toshiba Corp.) [Kernel | System | Stopped] -- D:\WINDOWS\system32\drivers\lbrtfdc.sys -- (lbrtfdc)
DRV - [2002.03.09 12:53:00 | 000,393,784 | ---- | M] (NVIDIA Corporation) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\dumant.sys -- (DumaNT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-299502267-1645522239-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.centrum.cz"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010.04.03 17:22:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010.04.03 00:32:32 | 000,000,000 | ---D | M]
[2009.01.15 20:55:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla\Extensions
[2010.04.02 22:57:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla\Firefox\Profiles\miqofcyt.default\extensions
[2009.12.22 04:46:29 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla\Firefox\Profiles\miqofcyt.default\extensions\dave2x@download
[2010.04.02 22:57:02 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions
[2010.03.21 19:22:33 | 000,000,638 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.03.21 19:22:33 | 000,001,687 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.03.21 19:22:33 | 000,001,367 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.03.21 19:22:33 | 000,000,654 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.03.21 19:22:33 | 000,001,179 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.03.21 13:53:04 | 000,000,027 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [nod32kui] D:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SoundMan] D:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [VirtualCloneDrive] D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - Startup: D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: D:\Documents and Settings\lama\Nabídka Start\Programy\Po spuštění\syspck32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-299502267-1645522239-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - D:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - D:\WINDOWS\System32\imon.dll (Eset )
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.10.10.1 10.10.10.2
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: D:\Documents and Settings\lama\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\lama\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.01.26 18:29:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - D:\WINDOWS\system32\ias [2008.03.24 18:28:34 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55745656140070912)
========== Files/Folders - Created Within 7 Days ==========
[2010.04.03 18:34:17 | 000,561,664 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
[2010.04.03 18:13:43 | 000,472,064 | ---- | C] ( ) -- D:\RootRepeal.exe
[2010.04.03 17:35:13 | 000,000,000 | ---D | C] -- D:\WINDOWS\temp
[2010.04.03 17:28:32 | 000,212,480 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWXCACLS.exe
[2010.04.03 17:28:32 | 000,161,792 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWREG.exe
[2010.04.03 17:28:32 | 000,136,704 | ---- | C] (SteelWerX) -- D:\WINDOWS\SWSC.exe
[2010.04.03 17:28:32 | 000,031,232 | ---- | C] (NirSoft) -- D:\WINDOWS\NIRCMD.exe
[2010.04.03 17:28:26 | 000,000,000 | ---D | C] -- D:\WINDOWS\ERDNT
[2010.04.03 17:27:51 | 000,000,000 | ---D | C] -- D:\Qoobox
[2010.04.03 17:25:09 | 000,000,000 | ---D | C] -- D:\rsit
[2010.04.03 00:10:57 | 000,000,000 | ---D | C] -- D:\Documents and Settings\lama\Dokumenty\Stažené soubory
[2009.06.13 23:26:08 | 000,000,000 | --SD | M] -- D:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2008.12.25 22:33:34 | 000,000,000 | ---D | M] -- D:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2008.03.24 18:35:33 | 000,000,000 | --SD | M] -- D:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2008.03.24 18:35:32 | 000,000,000 | ---D | M] -- D:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2010.04.03 18:47:09 | 000,804,864 | ---- | M] () -- D:\WINDOWS\System32\drivers\gtpkq.sys
[2010.04.03 18:35:31 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\lama\Plocha\OTL.exe
[2010.04.03 18:14:43 | 000,000,000 | ---- | M] () -- D:\settings.dat
[2010.04.03 18:12:50 | 000,464,491 | ---- | M] () -- D:\RootRepeal.zip
[2010.04.03 17:56:43 | 000,021,828 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml
[2010.04.03 17:56:37 | 000,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2010.04.03 17:56:32 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010.04.03 17:56:31 | 267,964,416 | -HS- | M] () -- D:\hiberfil.sys
[2010.04.03 17:33:29 | 000,000,227 | ---- | M] () -- D:\WINDOWS\system.ini
[2010.04.03 17:16:09 | 003,407,872 | -H-- | M] () -- D:\Documents and Settings\lama\NTUSER.DAT
[2010.04.03 17:16:09 | 000,000,178 | -HS- | M] () -- D:\Documents and Settings\lama\ntuser.ini
[2010.04.03 17:15:44 | 005,322,748 | -H-- | M] () -- D:\Documents and Settings\lama\Local Settings\Data aplikací\IconCache.db
[2010.04.03 02:11:14 | 000,000,008 | ---- | M] () -- D:\Documents and Settings\lama\Data aplikací\avdrn.dat
[2010.04.03 00:11:10 | 006,278,021 | ---- | M] () -- D:\Documents and Settings\lama\Plocha\GitaraUstna.wmv
[2010.04.02 22:46:14 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2010.03.29 17:53:44 | 000,311,604 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2010.03.29 17:53:44 | 000,039,992 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2010.03.29 17:53:43 | 000,309,716 | ---- | M] () -- D:\WINDOWS\System32\perfh005.dat
[2010.03.29 17:53:43 | 000,046,016 | ---- | M] () -- D:\WINDOWS\System32\perfc005.dat
[2010.03.29 17:53:42 | 000,714,818 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.04.03 18:14:43 | 000,000,000 | ---- | C] () -- D:\settings.dat
[2010.04.03 18:11:27 | 000,464,491 | ---- | C] () -- D:\RootRepeal.zip
[2010.04.03 17:56:31 | 267,964,416 | -HS- | C] () -- D:\hiberfil.sys
[2010.04.03 17:28:32 | 000,261,632 | ---- | C] () -- D:\WINDOWS\PEV.exe
[2010.04.03 17:28:32 | 000,098,816 | ---- | C] () -- D:\WINDOWS\sed.exe
[2010.04.03 17:28:32 | 000,080,412 | ---- | C] () -- D:\WINDOWS\grep.exe
[2010.04.03 17:28:32 | 000,077,312 | ---- | C] () -- D:\WINDOWS\MBR.exe
[2010.04.03 17:28:32 | 000,068,096 | ---- | C] () -- D:\WINDOWS\zip.exe
[2010.04.03 02:12:39 | 000,804,864 | ---- | C] () -- D:\WINDOWS\System32\drivers\gtpkq.sys
[2010.04.03 02:11:33 | 000,000,008 | ---- | C] () -- D:\Documents and Settings\NetworkService\Data aplikací\jasltw.dat
[2010.04.03 00:11:02 | 006,278,021 | ---- | C] () -- D:\Documents and Settings\lama\Plocha\GitaraUstna.wmv
[2010.03.07 04:01:55 | 000,000,016 | ---- | C] () -- D:\Documents and Settings\NetworkService\Data aplikací\rbuwzv.dat
[2010.03.07 04:01:43 | 000,000,008 | ---- | C] () -- D:\Documents and Settings\lama\Data aplikací\avdrn.dat
[2009.12.05 23:44:37 | 000,000,600 | ---- | C] () -- D:\Documents and Settings\lama\Data aplikací\winscp.rnd
[2009.12.05 22:29:14 | 000,000,600 | ---- | C] () -- D:\Documents and Settings\lama\PUTTY.RND
[2009.02.01 20:22:16 | 000,000,390 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2009.01.14 18:45:58 | 000,000,754 | ---- | C] () -- D:\WINDOWS\WORDPAD.INI
[2008.05.20 17:41:30 | 000,025,600 | ---- | C] () -- D:\Documents and Settings\lama\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.24 18:44:23 | 000,000,095 | ---- | C] () -- D:\WINDOWS\winamp.ini
[2008.03.24 18:44:22 | 000,088,064 | ---- | C] () -- D:\WINDOWS\System32\AudioExCtl.dll
[2008.03.24 18:39:20 | 000,143,360 | ---- | C] () -- D:\WINDOWS\System32\RtlCPAPI.dll
[2008.03.24 18:36:47 | 000,000,178 | -HS- | C] () -- D:\Documents and Settings\lama\ntuser.ini
[2008.03.24 18:36:45 | 000,001,024 | -H-- | C] () -- D:\Documents and Settings\lama\NTUSER.DAT.LOG
[2008.03.24 18:36:44 | 003,407,872 | -H-- | C] () -- D:\Documents and Settings\lama\NTUSER.DAT
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- D:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | ---- | C] () -- D:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,761,856 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- D:\WINDOWS\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | ---- | C] () -- D:\WINDOWS\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | ---- | C] () -- D:\WINDOWS\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | ---- | C] () -- D:\WINDOWS\System32\ogg.dll
[2005.02.24 08:32:00 | 000,540,672 | ---- | C] () -- D:\WINDOWS\System32\nvhwvid.dll
[2005.02.05 17:29:17 | 000,286,208 | ---- | C] () -- D:\WINDOWS\System32\CNCS232.DLL
[2004.08.17 15:49:10 | 000,081,920 | ---- | C] () -- D:\WINDOWS\System32\ieencode.dll
[2004.07.17 11:36:38 | 000,027,440 | ---- | C] () -- D:\WINDOWS\System32\drivers\secdrv.sys
[2002.03.09 12:53:00 | 000,368,640 | ---- | C] () -- D:\WINDOWS\System32\nvimage.dll
[2002.03.09 12:53:00 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\stereoi.dll
[1997.06.14 03:56:08 | 000,056,832 | ---- | C] () -- D:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2009.01.29 15:59:15 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\Azureus
[2009.06.11 03:41:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Azureus
[2009.01.29 01:20:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\BitSpirit
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
[2009.08.13 11:14:18 | 000,472,064 | ---- | M] ( ) -- D:\RootRepeal.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008.04.06 16:27:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Adobe
[2008.05.14 14:51:29 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\AdobeUM
[2009.06.11 03:41:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Azureus
[2009.01.29 01:20:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\BitSpirit
[2008.03.24 18:36:55 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Identities
[2008.12.27 03:30:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\InstallShield
[2008.03.24 18:46:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Macromedia
[2009.03.02 21:12:51 | 000,000,000 | --SD | M] -- D:\Documents and Settings\lama\Data aplikací\Microsoft
[2009.01.15 20:55:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Mozilla
[2009.01.26 23:02:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\Sun
[2009.06.13 22:59:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\lama\Data aplikací\vlc
< %APPDATA%\*.exe /s >
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- D:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- D:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- D:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\ERDNT\cache\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- D:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\ERDNT\cache\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- D:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.03 22:59:10 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- D:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2004.08.04 00:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- D:\WINDOWS\system32\drivers\changer.sys
< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\ERDNT\cache\lsass.exe
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- D:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\ERDNT\cache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- D:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\ERDNT\cache\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- D:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\ERDNT\cache\scecli.dll
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- D:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- D:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- D:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\ERDNT\cache\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- D:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\ERDNT\cache\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\system32\dllcache\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- D:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\ERDNT\cache\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- D:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\ERDNT\cache\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- D:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\ERDNT\cache\ws2_32.dll
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- D:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.04.03 19:05:12 | 000,804,864 | ---- | M] () Unable to obtain MD5 -- D:\WINDOWS\system32\drivers\gtpkq.sys
< %systemroot%\System32\config\*.sav >
[2008.03.24 19:09:52 | 000,094,208 | ---- | M] () -- D:\WINDOWS\system32\config\default.sav
[2008.03.24 19:09:52 | 000,663,552 | ---- | M] () -- D:\WINDOWS\system32\config\software.sav
[2008.03.24 19:09:51 | 000,454,656 | ---- | M] () -- D:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< End of report >
- Přílohy
-
- Extras.zip
- (4.36 KiB) Staženo 80 x
Naposledy upravil(a) Doil dne 03 dub 2010 18:11, celkem upraveno 1 x.
Re: Prosim o vyreseni problemu
Provedl jsem ten OTL scan, az potom jsem si precetl tvuj dalsi prispevek.
Rad bych ti pomohl neco vyzkouset, jenze jede mi tady svchost na 99procent a vsechno ostatni je pomale jak snek, tak nevim jestli to dobry napad neco testovat.
Co se tyce popsani muzu ti rict co je trochu zavadejici u OTL:
mozna OS 64b jsem tam ani nevidel. (sice je mi to jedno mam 32b)
ale zaskocil me tenhle radek:
- oznac na whitelist u polzky "specificke registry"
jestli to znamena,ze v te polozce "specificke registry" (kde je moznost vybrat Zadne, Vse, Pouzit whitelist) vybrat whitelist, tak jsem chvili premyslel protoze u vsech uz je implicitne nastaveno POuzit whitelist.
Rad bych ti pomohl neco vyzkouset, jenze jede mi tady svchost na 99procent a vsechno ostatni je pomale jak snek, tak nevim jestli to dobry napad neco testovat.
Co se tyce popsani muzu ti rict co je trochu zavadejici u OTL:
mozna OS 64b jsem tam ani nevidel. (sice je mi to jedno mam 32b)
ale zaskocil me tenhle radek:
- oznac na whitelist u polzky "specificke registry"
jestli to znamena,ze v te polozce "specificke registry" (kde je moznost vybrat Zadne, Vse, Pouzit whitelist) vybrat whitelist, tak jsem chvili premyslel protoze u vsech uz je implicitne nastaveno POuzit whitelist.
Naposledy upravil(a) Doil dne 03 dub 2010 18:30, celkem upraveno 1 x.
Re: Prosim o vyreseni problemu
K tomu navodu OTL, ja tam kolonku s 64b nemam, asi proto ze pouzivam 32b.
Provedl jsem avenger a nyni vsechno vypada OK, zatizeni zmizelo. Jestli uz je vse OK velmi Vam dekuji.
A co se tyce toho testovani, dneska uz nemam cas, ale zitra se na to podivam a dam Vam vedet.
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at D:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Driver "gtpkq" deleted successfully.
File "D:\WINDOWS\system32\drivers\gtpkq.sys" deleted successfully.
File "D:\Documents and Settings\lama\Nabídka Start\Programy\Po spuštění\syspck32.exe" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Provedl jsem avenger a nyni vsechno vypada OK, zatizeni zmizelo. Jestli uz je vse OK velmi Vam dekuji.
A co se tyce toho testovani, dneska uz nemam cas, ale zitra se na to podivam a dam Vam vedet.
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at D:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Driver "gtpkq" deleted successfully.
File "D:\WINDOWS\system32\drivers\gtpkq.sys" deleted successfully.
File "D:\Documents and Settings\lama\Nabídka Start\Programy\Po spuštění\syspck32.exe" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Re: Prosim o vyreseni problemu
Zdravim, omlouvam za zpozdeni, dostal jsem se poradne k PC az ted.
Vyzkousel jsem ten navod a vse probehlo bez problemu a navod se dal dobre pochopit. Mozna jen kdyz jsem mel otevrene okno OTH a chtel jsem znovu nastartovat exprorer, predtim nez jsem to napsal musel jsem najed do slozky windows, ale to je jasne, ze.
Logfile of random's system information tool 1.06 (written by random/random)
Run by lama at 2010-04-05 23:02:23
Systém Microsoft Windows XP Professional Service Pack 2
System drive D: has 290 MB (4%) free of 7 GB
Total RAM: 255 MB (15% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:02:43, on 5.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\Eset\nod32kui.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\DivX\DivX Update\DivXUpdate.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Eset\nod32krn.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\RSIT.exe
C:\Programy\lama.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] "D:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "D:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
--
End of file - 3626 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-15 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-15 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=D:\WINDOWS\SOUNDMAN.EXE [2006-08-03 577536]
"nod32kui"=D:\Program Files\Eset\nod32kui.exe [2008-03-24 921600]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2005-02-24 5537792]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=D:\WINDOWS\system32\NvMcTray.dll [2005-02-24 86016]
"VirtualCloneDrive"=D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2006-04-29 94208]
"SunJavaUpdateSched"=D:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"DivXUpdate"=D:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-03-05 1135912]
D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Mozilla Firefox\firefox.exe"="D:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"D:\Program Files\Vuze\Azureus.exe"="D:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\VideoLAN\VLC\vlc.exe"="D:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"D:\Program Files\QIP\qip.exe"="D:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"D:\Program Files\ESET\nod32kui.exe"="D:\Program Files\ESET\nod32kui.exe:*:Enabled:NOD32 Control Center"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-04 21:53:52 ----D---- D:\Program Files\Common Files\DivX Shared
2010-04-04 21:48:36 ----D---- D:\Program Files\DivX
2010-04-04 21:47:49 ----D---- D:\Documents and Settings\All Users\Data aplikací\DivX
2010-04-03 19:46:43 ----D---- D:\Avenger
2010-04-03 19:46:43 ----A---- D:\avenger.txt
2010-04-03 19:43:21 ----A---- D:\cleanup.exe
2010-04-03 19:43:21 ----A---- D:\cleanup.bat
2010-04-03 19:43:20 ----A---- D:\zip.exe
2010-04-03 19:10:22 ----SHD---- D:\RECYCLER
2010-04-03 18:27:09 ----A---- D:\RootRepeal report 04-03-10 (18-27-09).txt
2010-04-03 18:13:43 ----A---- D:\RootRepeal.exe
2010-04-03 17:35:13 ----D---- D:\WINDOWS\temp
2010-04-03 17:35:11 ----A---- D:\ComboFix.txt
2010-04-03 17:28:32 ----A---- D:\WINDOWS\zip.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\SWXCACLS.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\SWSC.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\SWREG.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\sed.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\PEV.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\NIRCMD.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\MBR.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\grep.exe
2010-04-03 17:28:26 ----D---- D:\WINDOWS\ERDNT
2010-04-03 17:27:51 ----D---- D:\Qoobox
2010-04-03 17:25:09 ----D---- D:\rsit
2010-03-07 16:35:38 ----SHD---- D:\WINDOWS\CSC
2010-03-07 16:35:31 ----A---- D:\WINDOWS\ntbtlog.txt
======List of files/folders modified in the last 1 months======
2010-04-05 23:02:31 ----D---- D:\WINDOWS\Prefetch
2010-04-05 23:01:26 ----A---- D:\WINDOWS\winamp.ini
2010-04-05 22:12:39 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-04-05 00:43:27 ----RD---- D:\Program Files
2010-04-05 00:43:26 ----SD---- D:\WINDOWS\Downloaded Program Files
2010-04-04 21:54:35 ----D---- D:\WINDOWS\system32
2010-04-04 21:54:32 ----SHD---- D:\WINDOWS\Installer
2010-04-04 21:54:29 ----D---- D:\WINDOWS\WinSxS
2010-04-04 21:53:52 ----D---- D:\Program Files\Common Files
2010-04-04 20:03:09 ----D---- D:\WINDOWS\system32\CatRoot2
2010-04-03 19:46:43 ----D---- D:\WINDOWS\system32\drivers
2010-04-03 17:35:13 ----D---- D:\WINDOWS
2010-04-03 17:33:29 ----A---- D:\WINDOWS\system.ini
2010-04-03 17:32:03 ----D---- D:\WINDOWS\AppPatch
2010-04-03 02:13:09 ----RSHDC---- D:\WINDOWS\system32\dllcache
2010-04-03 00:32:43 ----D---- D:\Program Files\Mozilla Firefox
2010-03-29 17:53:42 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-03-21 17:22:01 ----D---- D:\WINDOWS\Minidump
2010-03-21 17:21:12 ----SHD---- D:\System Volume Information
2010-03-21 17:21:12 ----D---- D:\WINDOWS\system32\Restore
2010-03-07 16:35:43 ----D---- D:\Documents and Settings
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; D:\WINDOWS\system32\DRIVERS\amdk7.sys [2004-08-17 41216]
R1 DumaNT;NVIDIA Stereo Helper Service; D:\WINDOWS\system32\DRIVERS\dumant.sys [2002-03-09 393784]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; D:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 AMON;AMON; \??\D:\WINDOWS\system32\drivers\amon.sys []
R2 ElbyCDIO;ElbyCDIO Driver; D:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2006-04-22 8064]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); D:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-10-13 4022528]
R3 ElbyDelay;ElbyDelay; D:\WINDOWS\System32\Drivers\ElbyDelay.sys [2005-04-12 4608]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; D:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-02-24 3454144]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 catchme;catchme; \??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; D:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 NOD32krn;NOD32 Kernel Service; D:\Program Files\Eset\nod32krn.exe [2008-03-24 507904]
R2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2005-02-24 127043]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\wmpnetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
Vyzkousel jsem ten navod a vse probehlo bez problemu a navod se dal dobre pochopit. Mozna jen kdyz jsem mel otevrene okno OTH a chtel jsem znovu nastartovat exprorer, predtim nez jsem to napsal musel jsem najed do slozky windows, ale to je jasne, ze.
Logfile of random's system information tool 1.06 (written by random/random)
Run by lama at 2010-04-05 23:02:23
Systém Microsoft Windows XP Professional Service Pack 2
System drive D: has 290 MB (4%) free of 7 GB
Total RAM: 255 MB (15% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:02:43, on 5.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\Eset\nod32kui.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\DivX\DivX Update\DivXUpdate.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Eset\nod32krn.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\RSIT.exe
C:\Programy\lama.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] "D:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "D:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - D:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
--
End of file - 3626 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-15 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-15 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=D:\WINDOWS\SOUNDMAN.EXE [2006-08-03 577536]
"nod32kui"=D:\Program Files\Eset\nod32kui.exe [2008-03-24 921600]
"NvCplDaemon"=D:\WINDOWS\system32\NvCpl.dll [2005-02-24 5537792]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=D:\WINDOWS\system32\NvMcTray.dll [2005-02-24 86016]
"VirtualCloneDrive"=D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2006-04-29 94208]
"SunJavaUpdateSched"=D:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"DivXUpdate"=D:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-03-05 1135912]
D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Mozilla Firefox\firefox.exe"="D:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"D:\Program Files\Vuze\Azureus.exe"="D:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\VideoLAN\VLC\vlc.exe"="D:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"D:\Program Files\QIP\qip.exe"="D:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"D:\Program Files\ESET\nod32kui.exe"="D:\Program Files\ESET\nod32kui.exe:*:Enabled:NOD32 Control Center"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-04 21:53:52 ----D---- D:\Program Files\Common Files\DivX Shared
2010-04-04 21:48:36 ----D---- D:\Program Files\DivX
2010-04-04 21:47:49 ----D---- D:\Documents and Settings\All Users\Data aplikací\DivX
2010-04-03 19:46:43 ----D---- D:\Avenger
2010-04-03 19:46:43 ----A---- D:\avenger.txt
2010-04-03 19:43:21 ----A---- D:\cleanup.exe
2010-04-03 19:43:21 ----A---- D:\cleanup.bat
2010-04-03 19:43:20 ----A---- D:\zip.exe
2010-04-03 19:10:22 ----SHD---- D:\RECYCLER
2010-04-03 18:27:09 ----A---- D:\RootRepeal report 04-03-10 (18-27-09).txt
2010-04-03 18:13:43 ----A---- D:\RootRepeal.exe
2010-04-03 17:35:13 ----D---- D:\WINDOWS\temp
2010-04-03 17:35:11 ----A---- D:\ComboFix.txt
2010-04-03 17:28:32 ----A---- D:\WINDOWS\zip.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\SWXCACLS.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\SWSC.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\SWREG.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\sed.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\PEV.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\NIRCMD.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\MBR.exe
2010-04-03 17:28:32 ----A---- D:\WINDOWS\grep.exe
2010-04-03 17:28:26 ----D---- D:\WINDOWS\ERDNT
2010-04-03 17:27:51 ----D---- D:\Qoobox
2010-04-03 17:25:09 ----D---- D:\rsit
2010-03-07 16:35:38 ----SHD---- D:\WINDOWS\CSC
2010-03-07 16:35:31 ----A---- D:\WINDOWS\ntbtlog.txt
======List of files/folders modified in the last 1 months======
2010-04-05 23:02:31 ----D---- D:\WINDOWS\Prefetch
2010-04-05 23:01:26 ----A---- D:\WINDOWS\winamp.ini
2010-04-05 22:12:39 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-04-05 00:43:27 ----RD---- D:\Program Files
2010-04-05 00:43:26 ----SD---- D:\WINDOWS\Downloaded Program Files
2010-04-04 21:54:35 ----D---- D:\WINDOWS\system32
2010-04-04 21:54:32 ----SHD---- D:\WINDOWS\Installer
2010-04-04 21:54:29 ----D---- D:\WINDOWS\WinSxS
2010-04-04 21:53:52 ----D---- D:\Program Files\Common Files
2010-04-04 20:03:09 ----D---- D:\WINDOWS\system32\CatRoot2
2010-04-03 19:46:43 ----D---- D:\WINDOWS\system32\drivers
2010-04-03 17:35:13 ----D---- D:\WINDOWS
2010-04-03 17:33:29 ----A---- D:\WINDOWS\system.ini
2010-04-03 17:32:03 ----D---- D:\WINDOWS\AppPatch
2010-04-03 02:13:09 ----RSHDC---- D:\WINDOWS\system32\dllcache
2010-04-03 00:32:43 ----D---- D:\Program Files\Mozilla Firefox
2010-03-29 17:53:42 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-03-21 17:22:01 ----D---- D:\WINDOWS\Minidump
2010-03-21 17:21:12 ----SHD---- D:\System Volume Information
2010-03-21 17:21:12 ----D---- D:\WINDOWS\system32\Restore
2010-03-07 16:35:43 ----D---- D:\Documents and Settings
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;Ovladač procesoru AMD K7; D:\WINDOWS\system32\DRIVERS\amdk7.sys [2004-08-17 41216]
R1 DumaNT;NVIDIA Stereo Helper Service; D:\WINDOWS\system32\DRIVERS\dumant.sys [2002-03-09 393784]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; D:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 AMON;AMON; \??\D:\WINDOWS\system32\drivers\amon.sys []
R2 ElbyCDIO;ElbyCDIO Driver; D:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2006-04-22 8064]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); D:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-10-13 4022528]
R3 ElbyDelay;ElbyDelay; D:\WINDOWS\System32\Drivers\ElbyDelay.sys [2005-04-12 4608]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; D:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-02-24 3454144]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 catchme;catchme; \??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; D:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 NOD32krn;NOD32 Kernel Service; D:\Program Files\Eset\nod32krn.exe [2008-03-24 507904]
R2 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2005-02-24 127043]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\wmpnetwk.exe [2007-01-05 913920]
-----------------EOF-----------------