Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosim o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
suppfly
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 úno 2009 23:49

prosim o kontrolu logu

#1 Příspěvek od suppfly »

Logfile of random's system information tool 1.06 (written by random/random)
Run by PC at 2010-02-15 19:37:16
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 30 GB (40%) free of 76 GB
Total RAM: 1535 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:37:45, on 15.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Carbonite\CarbonitePreinstaller.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\uTorrent\utorrent.exe
E:\TorrHotove\USB.Safely.Remove.v4.2.4.845.Cracked-CzW\Crack\USBSafelyRemove.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\T-Online\T-Online_Software_5\Basis-Software\Basis2\kernel.exe
C:\Program Files\T-Online\T-Online_Software_5\Basis-Software\Basis2\sc_watch.exe
C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\PROFIL~1.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\PC\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\PC\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\PC\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\PC\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\PC\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\RSIT.exe
C:\Documents and Settings\PC\Dokumenty\Stažené soubory\PC.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://de.ask.com?o=15161&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ToADiMon.exe] C:\Program Files\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [USB Safely Remove] E:\TorrHotove\USB.Safely.Remove.v4.2.4.845.Cracked-CzW\Crack\USBSafelyRemove.exe /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3182031077
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{43542496-524D-4D81-AA0A-3F89C38ABDCA}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{44DE8464-CB70-41A0-A8D4-15D68C43CCFB}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{829A94A0-D45B-40A9-BF53-3AE7674D1F90}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8311B901-5DB8-450E-9FBA-76C1D8DEA7A7}: NameServer = 217.0.43.177 217.0.43.161
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 9578 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\RaimaRadio_Radio 1_2592009_20_51_55.job
C:\WINDOWS\tasks\RaimaRadio_Radio 1_28112009_0_11_49.job
C:\WINDOWS\tasks\RaimaRadio_Radio 1_28112009_0_13_04.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-02 45056]
"ToADiMon.exe"=C:\Program Files\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe [2004-04-15 233539]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-02-15 981384]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2009-07-27 180224]
"nmctxth"=C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe [2009-07-07 647216]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-07-09 36352]
"CloneCDTray"=C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [2009-01-29 57344]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"CarboniteSetupLite"=C:\Program Files\Carbonite\CarbonitePreinstaller.exe [2009-08-04 318096]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2009-10-09 25623336]
"uTorrent"=C:\Program Files\uTorrent\utorrent.exe [2010-02-04 319280]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2008-09-02 205256]
"USB Safely Remove"=E:\TorrHotove\USB.Safely.Remove.v4.2.4.845.Cracked-CzW\Crack\USBSafelyRemove.exe [2009-11-24 1330688]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-02-15 19:31:33 ----A---- C:\Program Files\RSIT.exe
2010-02-15 18:25:57 ----A---- C:\ComboFix.txt
2010-02-15 17:46:27 ----A---- C:\WINDOWS\MBR.exe
2010-02-15 17:41:47 ----D---- C:\ComboFix
2010-02-15 17:22:38 ----A---- C:\WINDOWS\system32\CF18321.exe
2010-02-10 22:04:19 ----SHD---- C:\WINDOWS\ftpcache
2010-02-10 22:04:13 ----D---- C:\Program Files\Carbonite
2010-02-10 21:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\muvee Technologies
2010-02-10 21:57:43 ----D---- C:\Documents and Settings\PC\Data aplikací\Leadertech
2010-02-10 18:29:44 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 18:29:19 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 18:21:04 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 18:20:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 18:20:00 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 18:19:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 18:18:48 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 18:17:39 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 18:15:56 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-04 23:11:19 ----D---- C:\Program Files\Ask.com
2010-02-04 23:08:09 ----A---- C:\Program Files\utorrent.exe
2010-01-24 20:24:15 ----D---- C:\Program Files\7-Zip
2010-01-24 20:23:44 ----D---- C:\Program Files\7zip
2010-01-23 22:18:45 ----N---- C:\Documents and Settings\PC\Data aplikací\coreavc.ini

======List of files/folders modified in the last 1 months======

2010-02-15 19:37:18 ----D---- C:\WINDOWS\Temp
2010-02-15 19:37:15 ----D---- C:\Documents and Settings\PC\Data aplikací\uTorrent
2010-02-15 19:31:59 ----D---- C:\Documents and Settings\PC\Data aplikací\Skype
2010-02-15 19:31:33 ----RD---- C:\Program Files
2010-02-15 18:32:23 ----D---- C:\WINDOWS\Internet Logs
2010-02-15 18:27:44 ----A---- C:\WINDOWS\win.ini
2010-02-15 18:26:02 ----D---- C:\Qoobox
2010-02-15 18:26:01 ----D---- C:\WINDOWS\system32\drivers
2010-02-15 18:21:00 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-15 18:17:56 ----D---- C:\Documents and Settings\PC\Data aplikací\skypePM
2010-02-15 18:17:33 ----AD---- C:\WINDOWS
2010-02-15 18:15:42 ----A---- C:\WINDOWS\system.ini
2010-02-15 17:51:12 ----D---- C:\WINDOWS\system32
2010-02-15 17:51:12 ----D---- C:\WINDOWS\AppPatch
2010-02-15 17:51:09 ----D---- C:\Program Files\Common Files
2010-02-15 17:46:38 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-12 06:42:40 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-12 06:10:23 ----D---- C:\HD Movie
2010-02-11 06:40:42 ----D---- C:\Program Files\JDownloader
2010-02-10 22:03:51 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-10 22:00:40 ----SHD---- C:\WINDOWS\Installer
2010-02-10 22:00:36 ----D---- C:\WINDOWS\WinSxS
2010-02-10 22:00:36 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-10 21:43:13 ----HD---- C:\WINDOWS\inf
2010-02-10 18:29:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-10 18:29:26 ----A---- C:\WINDOWS\imsins.BAK
2010-02-10 18:29:23 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-04 23:11:30 ----SD---- C:\WINDOWS\Tasks
2010-02-04 23:10:55 ----D---- C:\Program Files\uTorrent
2010-02-04 22:54:07 ----D---- C:\WINDOWS\system32\config
2010-02-04 22:53:53 ----D---- C:\WINDOWS\system32\wbem
2010-02-04 22:53:52 ----D---- C:\WINDOWS\Registration
2010-02-01 20:39:15 ----D---- C:\Program Files\Garmin
2010-02-01 20:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
2010-02-01 06:50:52 ----D---- C:\Garmin
2010-01-30 16:18:22 ----D---- C:\WINDOWS\system32\LogFiles
2010-01-30 11:18:22 ----D---- C:\Program Files\Mozilla Firefox
2010-01-28 21:31:54 ----D---- C:\WINDOWS\system32\NtmsData
2010-01-27 19:24:35 ----D---- C:\WINDOWS\repair
2010-01-26 21:06:45 ----D---- C:\Documents and Settings\PC\Data aplikací\Winamp
2010-01-24 17:35:02 ----D---- C:\WINDOWS\Prefetch
2010-01-23 18:20:30 ----D---- C:\Program Files\Internet Explorer
2010-01-23 18:20:18 ----D---- C:\WINDOWS\ie8updates

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2009-07-27 58908]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-02-15 353672]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 pnarp;Pure Networks Device Discovery Driver; C:\WINDOWS\system32\DRIVERS\pnarp.sys [2009-07-07 25392]
R2 purendis;Pure Networks Wireless Driver; C:\WINDOWS\system32\DRIVERS\purendis.sys [2009-07-07 26672]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 catchme;catchme; \??\C:\DOCUME~1\PC\LOCALS~1\Temp\catchme.sys []
R3 EL90Xbc;3Com 3C90X-BC Family PCI EtherLink Adapter; C:\WINDOWS\system32\DRIVERS\el90Xbc5.SYS [2002-08-13 74338]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2002-12-05 13056]
R3 NVENET;NVIDIA nForce MCP Networking Adapter Driver; C:\WINDOWS\System32\DRIVERS\NVENET.sys [2002-09-23 80896]
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2002-12-05 241664]
R3 TDSLAdapter;T-DSL-Adapter (T-Online); C:\WINDOWS\system32\DRIVERS\TDSLAdap.sys [2001-02-12 47616]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 a9wyus37;a9wyus37; C:\WINDOWS\system32\drivers\a9wyus37.sys []
S3 BRIDGE;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 mbr;mbr; \??\C:\DOCUME~1\PC\LOCALS~1\Temp\mbr.sys []
S3 PCANDIS5;PCANDIS5; \??\C:\PROGRA~1\T-Online\T-DSLT~1\PCANDIS5.SYS []
S3 TDSLProtocol;T-DSL-Protocol (T-Online); C:\WINDOWS\system32\DRIVERS\TDSLProt.sys [2001-02-12 6688]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 nmservice;Pure Networks Platform Service; C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [2009-07-07 647216]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2007-02-15 707344]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-02-15 2402184]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-05-03 520192]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118310
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu logu

#2 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

suppfly
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 úno 2009 23:49

Re: prosim o kontrolu logu

#3 Příspěvek od suppfly »

ComboFix 10-02-12.01 - PC 15.02.2010 17:47:40.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1535.1078 [GMT 1:00]
Spuštěný z: c:\documents and settings\PC\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100215-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\etc\lmhosts . . . . nemohl být smazán

----- BITS: Možné infikované stránky -----

hxxp://armmf.adobe.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-15 do 2010-02-15 )))))))))))))))))))))))))))))))
.

2010-02-15 16:22 . 2010-02-15 16:20 390144 ----a-w- c:\windows\system32\CF18321.exe
2010-02-10 21:04 . 2010-02-10 21:04 -------- d-sh--w- c:\windows\ftpcache
2010-02-10 21:04 . 2010-02-10 21:04 -------- d-----w- c:\program files\Carbonite
2010-02-04 22:11 . 2010-02-04 22:11 -------- d-----w- c:\program files\Ask.com
2010-02-04 22:08 . 2010-02-04 22:09 319280 ----a-w- c:\program files\utorrent.exe
2010-02-04 21:53 . 2010-02-04 21:53 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-24 19:24 . 2010-01-24 19:24 -------- d-----w- c:\program files\7-Zip
2010-01-24 19:23 . 2010-01-24 19:23 -------- d-----w- c:\program files\7zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 13:32 . 2009-09-21 04:36 1374293 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-02-11 05:40 . 2009-12-05 19:09 -------- d-----w- c:\program files\JDownloader
2010-02-11 05:08 . 2010-02-11 05:09 1867264 ----a-w- c:\windows\Internet Logs\xDB13.tmp
2010-02-10 21:03 . 2009-09-17 09:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-05 14:47 . 2010-02-05 14:55 2697216 ----a-w- c:\windows\Internet Logs\xDB11.tmp
2010-02-05 14:47 . 2010-02-05 14:55 1848832 ----a-w- c:\windows\Internet Logs\xDB12.tmp
2010-02-04 22:10 . 2009-09-17 17:26 -------- d-----w- c:\program files\uTorrent
2010-02-01 19:39 . 2009-09-19 15:50 -------- d-----w- c:\program files\Garmin
2010-01-24 02:15 . 2010-01-24 02:14 3172864 ----a-w- c:\windows\Internet Logs\xDBF.tmp
2010-01-24 02:15 . 2010-01-24 02:14 1818624 ----a-w- c:\windows\Internet Logs\xDB10.tmp
2009-12-31 16:50 . 2001-10-25 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2002-09-20 17:05 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 19:47 . 2009-12-17 19:48 2626560 ----a-w- c:\windows\Internet Logs\xDBE.tmp
2009-12-17 07:42 . 2009-09-17 09:33 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2002-09-20 17:03 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-10 02:25 . 2001-10-25 12:00 82372 ----a-w- c:\windows\system32\perfc005.dat
2009-12-10 02:25 . 2001-10-25 12:00 437558 ----a-w- c:\windows\system32\perfh005.dat
2009-12-09 10:11 . 2002-09-20 17:12 2068224 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-09 10:11 . 2002-09-20 16:12 2191360 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-06 22:23 . 2009-12-06 22:24 1787392 ----a-w- c:\windows\Internet Logs\xDBD.tmp
2009-12-05 19:09 . 2009-12-05 19:05 28253422 ----a-w- c:\program files\JDownloaderSetup.exe
2009-12-05 14:40 . 2009-12-05 14:40 1785344 ----a-w- c:\windows\Internet Logs\xDBC.tmp
2009-12-05 14:40 . 2009-12-05 14:40 4135936 ----a-w- c:\windows\Internet Logs\xDBB.tmp
2009-12-04 18:22 . 2002-08-29 00:59 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-04 14:42 . 2001-10-25 12:00 2864 ----a-w- c:\windows\system32\winsock.dll
2009-11-28 15:37 . 2010-02-14 13:21 183324 ----a-w- c:\windows\PCHealth\HelpCtr\Config\Cache\Professional_32_1029.dat
2009-11-27 17:14 . 2002-09-20 17:04 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14 . 2001-10-24 12:24 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2001-10-25 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2002-09-20 17:04 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2002-09-20 17:03 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:09 . 2001-10-24 12:24 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-24 23:54 . 2009-09-18 05:06 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-09-18 05:06 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-09-18 05:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-09-18 05:06 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-09-18 05:06 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-09-18 05:06 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-09-18 05:06 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-09-18 05:06 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-09-18 05:06 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-24 06:04 . 2009-11-24 06:13 1763840 ----a-w- c:\windows\Internet Logs\xDBA.tmp
2009-11-21 16:03 . 2002-09-20 17:03 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-11 10:17 . 2009-11-11 10:17 30456 ----a-w- c:\program files\MPEG4Modifier.zip
2009-11-11 10:17 . 2009-11-11 10:17 54958 ----a-w- c:\program files\MPEG4Modifier-Source.zip
2009-11-09 19:07 . 2009-11-09 19:07 411509 ----a-w- c:\program files\GSpot270a.zip
2009-11-05 23:24 . 2009-11-05 23:23 4115100 ----a-w- c:\program files\mkvtoolnix-unicode-2.4.1-build20081207-44-setup.exe
2009-11-05 16:36 . 2009-11-05 16:36 1087682 ----a-w- c:\program files\subtitleworkshop251.zip
2009-10-18 17:52 . 2009-10-18 17:33 18527244 ----a-w- c:\program files\vlc-1.0.2-win32.exe
2009-10-18 17:37 . 2009-10-18 17:32 6054824 ----a-w- c:\program files\GOMPLAYERENSETUP.EXE
2009-09-17 15:52 . 2009-09-17 15:52 7881016 ----a-w- c:\program files\Firefox Setup 3.5.2.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 13:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]
"uTorrent"="c:\program files\uTorrent\utorrent.exe" [2010-02-04 319280]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-09-02 205256]
"USB Safely Remove"="e:\torrhotove\USB.Safely.Remove.v4.2.4.845.Cracked-CzW\Crack\USBSafelyRemove.exe" [2009-11-24 1330688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"ToADiMon.exe"="c:\program files\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe" [2004-04-15 233539]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-07-09 36352]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [16.9.2009 13:12 116264]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.9.2009 5:31 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [18.9.2009 6:06 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18.9.2009 6:06 20560]
R3 TDSLAdapter;T-DSL-Adapter (T-Online);c:\windows\system32\drivers\TDSLAdap.sys [17.9.2009 16:37 47616]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [24.9.2009 22:02 23152]
S3 TDSLProtocol;T-DSL-Protocol (T-Online);c:\windows\system32\drivers\TDSLProt.sys [17.9.2009 16:37 6688]
.
Obsah adresáře 'Naplánované úlohy'

2010-02-12 c:\windows\Tasks\RaimaRadio_Radio 1_2592009_20_51_55.job
- c:\program files\RarmaRadio\RarmaRadio.exe [2009-09-25 09:43]

2010-02-14 c:\windows\Tasks\RaimaRadio_Radio 1_28112009_0_11_49.job
- c:\program files\RarmaRadio\RarmaRadio.exe [2009-09-25 09:43]

2010-02-12 c:\windows\Tasks\RaimaRadio_Radio 1_28112009_0_13_04.job
- c:\program files\RarmaRadio\RarmaRadio.exe [2009-09-25 09:43]

2010-02-15 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-09-02 13:56]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://de.ask.com?o=15161&l=dis
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {43542496-524D-4D81-AA0A-3F89C38ABDCA} = 192.168.0.1
TCP: {44DE8464-CB70-41A0-A8D4-15D68C43CCFB} = 192.168.0.1
TCP: {829A94A0-D45B-40A9-BF53-3AE7674D1F90} = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\PC\Data aplikací\Mozilla\Firefox\Profiles\yro8e1lq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - hxxp://tracker.czech-server.com/torrents.php
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
HKLM-Run-RegistryMechanic - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-15 18:15
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x898A91F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf765bf28
\Driver\ACPI -> ACPI.sys @ 0xf7496cb8
\Driver\atapi -> atapi.sys @ 0xf7978b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="05AD349E37A908CBA23BC9CBD6FC0EE8137D854B0595402DE3AB30005FE4F6F6455CFAE43DF2DCF57751AB0DC8298977FB4E97A959345B33A5F86E28A7ED33ACEAD8DB59CD6078AA14D5EE3014D16C33ADD3580797E2CAA655D579FD36BFC5D85135BDE4CF5BC549F7FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB34528EDD5E5BE2F6E6679DB7CE019D40AA5CD47E7A75E0CF636D8545B34319054A2FB92AB03F73A981FCE7A28262774110F20F98A76EA10E9FE2EECB75B11D4E2A344BF8949595D4BC2044DA86FC91ED50B8BD72C779651122C551A771472EE8B2E55C32FA216222BA0D8F59805DEF96C74C197DA1636A3FDB66D87866E4C9F69C3BA943BB78B88F1B82B678816DF1B7234EDFA3210A33B01EEA3352B7FEB4CE847F720BD4C33DD0640DA8873FAB3E0370B4D23DD36105B4A0CD133DEE1E74FC6AD1796166C0D64E0093DB47932ABD5B20C6389A6D70EA4B7F5BAE36B7DDD5BD3423870FB540B3223BCA476D7C8E9CD98B22597EC553322ABAB7C12C61EDE684A7BC67CF2D29439EC5C0E8A49B944CCA6BB7041FD537EEBA34568A846093FAF87337E9545672B9C3B7D2C18A378883AFDE4C8AA93D61749BB3824B16CBA62AF3A682E0C264AB8DCB09B75531394EB83C67F6413BBFA8DE1D66594B2CDF14CE04B661A534AC74FDA097F4AB9F305AABD96C2603E6C2F70C45D9CC54087CDB076D7A6A1435260288632567D2CE4CB95C24371BAC35534F1D4D0122B5DDA691B7A430870A46EF1FF1E4D5BE5BAD64880F6BF769209F1EC1F9A33574C25504DD08557778EBDD49A844B0337E591C73F94EB4BEFAC2957675CBE9B0AFD00A627D615ED351A2E2180EC8FDABFD667215D3E6B8830BFEFAD4A680F313173B8C31C0F4D02F7597B5635612BF11EA9EFA0E71E9E3A02CC226D2A4C9CCDF3F60E0848B357455233DA3DA1BF11796C2A1F0C0BFAC56D341FD612FD21F31FC93227E13D5D8C2766705744D8803DCD75A9409BA4147654084286CCD28BA93B850E9523A2D5AEB27A4665F31DF209CD0592168A78C9819EA8239FAB4AF1998C0099F3B79307A51DF92DE131EF6E815E3BAF329D94C40ADC01B30338E88FD1A28A1320FF414BB0A7CBBECAF51B7423A56D03C59C7BEA4940D840EB02BE66E2566541593732165603FFE9449AC9D55B3503C307A8AB56E718446D801FC12B5FBD7AEBF86E1B282D1C90F5CE9B3BB0CDCE0F6078260968A9C3DBD992A1C6461143C142B174FBA621226F1528F8FB698C678CB7E5C2B5EA924319B5E20414D4316B4B8D56AF03C9687418304A98DC66DB1ECDA57E5F018C2C5BEE3B9CF4C5171E0CBA645961DCF79CC69F1859D1FBA4497F71755715B688CF9287140974186C70569"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(808)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3068)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\Office10\msohev.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\oodag.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Skype\Phone\Skype.exe
c:\windows\system32\wscntfy.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\dwwin.exe
c:\windows\system32\dwwin.exe
c:\program files\T-Online\T-Online_Software_5\Basis-Software\Basis2\kernel.exe
c:\program files\T-Online\T-Online_Software_5\Basis-Software\Basis2\sc_watch.exe
c:\progra~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\PROFIL~1.EXE
.
**************************************************************************
.
Celkový čas: 2010-02-15 18:25:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-15 17:25
ComboFix2.txt 2009-09-19 17:58
ComboFix3.txt 2009-09-19 15:27

Před spuštěním: Volných bajtů: 31 985 197 056
Po spuštění: Volných bajtů: 31 895 863 296

- - End Of File - - C67705400982F652C4FA3E4F9ADEB9FB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118310
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu logu

#4 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files\Ask.com

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

suppfly
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 úno 2009 23:49

Re: prosim o kontrolu logu

#5 Příspěvek od suppfly »

ComboFix 10-02-12.01 - PC 16.02.2010 0:54.4.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1535.1064 [GMT 1:00]
Spuštěný z: c:\documents and settings\PC\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\PC\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100215-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\windows\system32\drivers\etc\lmhosts . . . . nemohl být smazán

----- BITS: Možné infikované stránky -----

hxxp://armmf.adobe.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-16 do 2010-02-16 )))))))))))))))))))))))))))))))
.

2010-02-15 18:31 . 2010-02-15 18:32 781909 ----a-w- c:\program files\RSIT.exe
2010-02-15 16:22 . 2010-02-15 16:20 390144 ----a-w- c:\windows\system32\CF18321.exe
2010-02-10 21:04 . 2010-02-10 21:04 -------- d-sh--w- c:\windows\ftpcache
2010-02-10 21:04 . 2010-02-10 21:04 -------- d-----w- c:\program files\Carbonite
2010-02-04 22:08 . 2010-02-04 22:09 319280 ----a-w- c:\program files\utorrent.exe
2010-02-04 21:53 . 2010-02-04 21:53 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-24 19:24 . 2010-01-24 19:24 -------- d-----w- c:\program files\7-Zip
2010-01-24 19:23 . 2010-01-24 19:23 -------- d-----w- c:\program files\7zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-15 23:51 . 2009-09-21 04:36 1690531 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-02-15 20:38 . 2009-12-05 19:09 -------- d-----w- c:\program files\JDownloader
2010-02-11 05:08 . 2010-02-11 05:09 1867264 ----a-w- c:\windows\Internet Logs\xDB13.tmp
2010-02-10 21:03 . 2009-09-17 09:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-05 14:47 . 2010-02-05 14:55 2697216 ----a-w- c:\windows\Internet Logs\xDB11.tmp
2010-02-05 14:47 . 2010-02-05 14:55 1848832 ----a-w- c:\windows\Internet Logs\xDB12.tmp
2010-02-04 22:10 . 2009-09-17 17:26 -------- d-----w- c:\program files\uTorrent
2010-02-01 19:39 . 2009-09-19 15:50 -------- d-----w- c:\program files\Garmin
2010-01-24 02:15 . 2010-01-24 02:14 3172864 ----a-w- c:\windows\Internet Logs\xDBF.tmp
2010-01-24 02:15 . 2010-01-24 02:14 1818624 ----a-w- c:\windows\Internet Logs\xDB10.tmp
2009-12-31 16:50 . 2001-10-25 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2002-09-20 17:05 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 19:47 . 2009-12-17 19:48 2626560 ----a-w- c:\windows\Internet Logs\xDBE.tmp
2009-12-17 07:42 . 2009-09-17 09:33 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2002-09-20 17:03 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-10 02:25 . 2001-10-25 12:00 82372 ----a-w- c:\windows\system32\perfc005.dat
2009-12-10 02:25 . 2001-10-25 12:00 437558 ----a-w- c:\windows\system32\perfh005.dat
2009-12-09 10:11 . 2002-09-20 17:12 2068224 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-09 10:11 . 2002-09-20 16:12 2191360 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-06 22:23 . 2009-12-06 22:24 1787392 ----a-w- c:\windows\Internet Logs\xDBD.tmp
2009-12-05 19:09 . 2009-12-05 19:05 28253422 ----a-w- c:\program files\JDownloaderSetup.exe
2009-12-05 14:40 . 2009-12-05 14:40 1785344 ----a-w- c:\windows\Internet Logs\xDBC.tmp
2009-12-05 14:40 . 2009-12-05 14:40 4135936 ----a-w- c:\windows\Internet Logs\xDBB.tmp
2009-12-04 18:22 . 2002-08-29 00:59 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-04 14:42 . 2001-10-25 12:00 2864 ----a-w- c:\windows\system32\winsock.dll
2009-11-28 15:37 . 2010-02-14 13:21 183324 ----a-w- c:\windows\PCHealth\HelpCtr\Config\Cache\Professional_32_1029.dat
2009-11-27 17:14 . 2002-09-20 17:04 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14 . 2001-10-24 12:24 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2001-10-25 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2002-09-20 17:04 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2002-09-20 17:03 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:09 . 2001-10-24 12:24 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-24 23:54 . 2009-09-18 05:06 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-09-18 05:06 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-09-18 05:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-09-18 05:06 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-09-18 05:06 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-09-18 05:06 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-09-18 05:06 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-09-18 05:06 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-09-18 05:06 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-24 06:04 . 2009-11-24 06:13 1763840 ----a-w- c:\windows\Internet Logs\xDBA.tmp
2009-11-21 16:03 . 2002-09-20 17:03 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-11 10:17 . 2009-11-11 10:17 30456 ----a-w- c:\program files\MPEG4Modifier.zip
2009-11-11 10:17 . 2009-11-11 10:17 54958 ----a-w- c:\program files\MPEG4Modifier-Source.zip
2009-11-09 19:07 . 2009-11-09 19:07 411509 ----a-w- c:\program files\GSpot270a.zip
2009-11-05 23:24 . 2009-11-05 23:23 4115100 ----a-w- c:\program files\mkvtoolnix-unicode-2.4.1-build20081207-44-setup.exe
2009-11-05 16:36 . 2009-11-05 16:36 1087682 ----a-w- c:\program files\subtitleworkshop251.zip
2009-10-18 17:52 . 2009-10-18 17:33 18527244 ----a-w- c:\program files\vlc-1.0.2-win32.exe
2009-10-18 17:37 . 2009-10-18 17:32 6054824 ----a-w- c:\program files\GOMPLAYERENSETUP.EXE
2009-09-17 15:52 . 2009-09-17 15:52 7881016 ----a-w- c:\program files\Firefox Setup 3.5.2.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]
"uTorrent"="c:\program files\uTorrent\utorrent.exe" [2010-02-04 319280]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-09-02 205256]
"USB Safely Remove"="e:\torrhotove\USB.Safely.Remove.v4.2.4.845.Cracked-CzW\Crack\USBSafelyRemove.exe" [2009-11-24 1330688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"ToADiMon.exe"="c:\program files\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe" [2004-04-15 233539]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-07-09 36352]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [16.9.2009 13:12 116264]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.9.2009 5:31 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [18.9.2009 6:06 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18.9.2009 6:06 20560]
R3 TDSLAdapter;T-DSL-Adapter (T-Online);c:\windows\system32\drivers\TDSLAdap.sys [17.9.2009 16:37 47616]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [24.9.2009 22:02 23152]
S3 TDSLProtocol;T-DSL-Protocol (T-Online);c:\windows\system32\drivers\TDSLProt.sys [17.9.2009 16:37 6688]
.
Obsah adresáře 'Naplánované úlohy'

2010-02-12 c:\windows\Tasks\RaimaRadio_Radio 1_2592009_20_51_55.job
- c:\program files\RarmaRadio\RarmaRadio.exe [2009-09-25 09:43]

2010-02-14 c:\windows\Tasks\RaimaRadio_Radio 1_28112009_0_11_49.job
- c:\program files\RarmaRadio\RarmaRadio.exe [2009-09-25 09:43]

2010-02-12 c:\windows\Tasks\RaimaRadio_Radio 1_28112009_0_13_04.job
- c:\program files\RarmaRadio\RarmaRadio.exe [2009-09-25 09:43]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://de.ask.com?o=15161&l=dis
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {43542496-524D-4D81-AA0A-3F89C38ABDCA} = 192.168.0.1
TCP: {44DE8464-CB70-41A0-A8D4-15D68C43CCFB} = 192.168.0.1
TCP: {829A94A0-D45B-40A9-BF53-3AE7674D1F90} = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\PC\Data aplikací\Mozilla\Firefox\Profiles\yro8e1lq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - hxxp://tracker.czech-server.com/torrents.php
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-16 01:05
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x898A91F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf765bf28
\Driver\ACPI -> ACPI.sys @ 0xf7496cb8
\Driver\atapi -> atapi.sys @ 0xf7978b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="05AD349E37A908CBA23BC9CBD6FC0EE8137D854B0595402DE3AB30005FE4F6F6455CFAE43DF2DCF57751AB0DC8298977FB4E97A959345B33A5F86E28A7ED33ACEAD8DB59CD6078AA14D5EE3014D16C33ADD3580797E2CAA655D579FD36BFC5D85135BDE4CF5BC549F7FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB34528EDD5E5BE2F6E6679DB7CE019D40AA5CD47E7A75E0CF636D8545B34319054A2FB92AB03F73A981FCE7A28262774110F20F98A76EA10E9FE2EECB75B11D4E2A344BF8949595D4BC2044DA86FC91ED50B8BD72C779651122C551A771472EE8B2E55C32FA216222BA0D8F59805DEF96C74C197DA1636A3FDB66D87866E4C9F69C3BA943BB78B88F1B82B678816DF1B7234EDFA3210A33B01EEA3352B7FEB4CE847F720BD4C33DD0640DA8873FAB3E0370B4D23DD36105B4A0CD133DEE1E74FC6AD1796166C0D64E0093DB47932ABD5B20C6389A6D70EA4B7F5BAE36B7DDD5BD3423870FB540B3223BCA476D7C8E9CD98B22597EC553322ABAB7C12C61EDE684A7BC67CF2D29439EC5C0E8A49B944CCA6BB7041FD537EEBA34568A846093FAF87337E9545672B9C3B7D2C18A378883AFDE4C8AA93D61749BB3824B16CBA62AF3A682E0C264AB8DCB09B75531394EB83C67F6413BBFA8DE1D66594B2CDF14CE04B661A534AC74FDA097F4AB9F305AABD96C2603E6C2F70C45D9CC54087CDB076D7A6A1435260288632567D2CE4CB95C24371BAC35534F1D4D0122B5DDA691B7A430870A46EF1FF1E4D5BE5BAD64880F6BF769209F1EC1F9A33574C25504DD08557778EBDD49A844B0337E591C73F94EB4BEFAC2957675CBE9B0AFD00A627D615ED351A2E2180EC8FDABFD667215D3E6B8830BFEFAD4A680F313173B8C31C0F4D02F7597B5635612BF11EA9EFA0E71E9E3A02CC226D2A4C9CCDF3F60E0848B357455233DA3DA1BF11796C2A1F0C0BFAC56D341FD612FD21F31FC93227E13D5D8C2766705744D8803DCD75A9409BA4147654084286CCD28BA93B850E9523A2D5AEB27A4665F31DF209CD0592168A78C9819EA8239FAB4AF1998C0099F3B79307A51DF92DE131EF6E815E3BAF329D94C40ADC01B30338E88FD1A28A1320FF414BB0A7CBBECAF51B7423A56D03C59C7BEA4940D840EB02BE66E2566541593732165603FFE9449AC9D55B3503C307A8AB56E718446D801FC12B5FBD7AEBF86E1B282D1C90F5CE9B3BB0CDCE0F6078260968A9C3DBD992A1C6461143C142B174FBA621226F1528F8FB698C678CB7E5C2B5EA924319B5E20414D4316B4B8D56AF03C9687418304A98DC66DB1ECDA57E5F018C2C5BEE3B9CF4C5171E0CBA645961DCF79CC69F1859D1FBA4497F71755715B688CF9287140974186C70569"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(808)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2352)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\oodag.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Skype\Phone\Skype.exe
c:\windows\system32\wscntfy.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\T-Online\T-Online_Software_5\Basis-Software\Basis2\kernel.exe
c:\program files\T-Online\T-Online_Software_5\Basis-Software\Basis2\sc_watch.exe
c:\progra~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\PROFIL~1.EXE
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Celkový čas: 2010-02-16 01:13:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-16 00:13
ComboFix2.txt 2010-02-15 17:25
ComboFix3.txt 2009-09-19 17:58
ComboFix4.txt 2009-09-19 15:27

Před spuštěním: Volných bajtů: 31 938 568 192
Po spuštění: Volných bajtů: 31 897 513 984

- - End Of File - - 9DB279E67B5EC19DFE498D96C52740EC
takze tohle je log po procisteni, dik za rady prosim o posozeni ci je pc ciste
diky

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118310
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu logu

#6 Příspěvek od Rudy »

Ještě poprosím o kontrolu MBR. Udělejte sken MBR: http://www2.gmer.net/mbr/mbr.exe a dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

suppfly
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 úno 2009 23:49

Re: prosim o kontrolu logu

#7 Příspěvek od suppfly »

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118310
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu logu

#8 Příspěvek od Rudy »

MBR a celý disk vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

suppfly
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 09 úno 2009 23:49

Re: prosim o kontrolu logu

#9 Příspěvek od suppfly »

diky jak budu v plzni mas u me pivo

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118310
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu logu

#10 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět