
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Pro Motji: trojan Generic15.apnz
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Pro Motji: trojan Generic15.apnz
Ještě odinstalujte OTm takto
:arrow:Otevřete znovu Otm a klikněte na tlačítko CleanUp,potvrďte ok
a pročištěte to druhé pc CCleanerem.
:arrow:Otevřete znovu Otm a klikněte na tlačítko CleanUp,potvrďte ok
a pročištěte to druhé pc CCleanerem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pro Motji: trojan Generic15.apnz
Neprováděl jsem vůbec nic (bohužel
). Ale může to být pozůstatek virtumonde, nebo tak něco.
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-04-27 23:14:29
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (18%) free of 10 GB
Total RAM: 3070 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:26:19, on 13.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Rodina\Plocha\RSIT.exe
I:\Program Files\Trend Micro\HijackThis\Rodina.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - I:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - I:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O8 - Extra context menu item: &Download by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://I:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra 'Tools' menuitem: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - I:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Acronis Malware Shield Service (psh_svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
--
End of file - 7535 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Norton Security Scan for Rodina.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - I:\Program Files\Orbitdownloader\orbitcth.dll [2010-04-16 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - I:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E24AD748-155E-4254-B674-4EDF86E7E1DF}]
CAdBlocker Object - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll [2006-04-18 788312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - I:\Program Files\Orbitdownloader\GrabPro.dll [2010-04-16 666816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=I:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"COMODO Internet Security"=I:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-04-15 2029456]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"I:\Program Files\Skype\Phone\Skype.exe"="I:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"I:\Program Files\Orbitdownloader\orbitdm.exe"="I:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"I:\Program Files\Orbitdownloader\orbitnet.exe"="I:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-27 23:14:29 ----D---- C:\rsit
2010-04-27 21:16:12 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-04-27 21:13:58 ----D---- C:\Program Files\Norton Security Scan
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Symantec
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2010-04-27 21:13:57 ----D---- C:\Program Files\NortonInstaller
2010-04-27 21:13:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2010-04-21 21:05:14 ----D---- C:\VundoFix Backups
2010-04-21 20:40:11 ----A---- C:\WINDOWS\system32\h323log.txt
2010-04-21 00:07:32 ----HD---- C:\VritualRoot
2010-04-20 22:43:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\F-Secure
2010-04-19 20:09:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-04-19 20:08:41 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2010-04-18 00:58:12 ----D---- C:\WINDOWS\system32\XPSViewer
2010-04-18 00:58:10 ----D---- C:\Program Files\MSBuild
2010-04-18 00:58:09 ----D---- C:\WINDOWS\system32\en-US
2010-04-18 00:58:04 ----D---- C:\Program Files\Reference Assemblies
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-04-18 00:54:41 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-04-18 00:54:37 ----D---- C:\Program Files\MSXML 6.0
2010-04-15 20:34:39 ----A---- C:\WINDOWS\Ascd_tmp.ini
2010-04-15 19:04:10 ----RSD---- C:\WINDOWS\assembly
2010-04-15 19:03:48 ----D---- C:\WINDOWS\Microsoft.NET
2010-04-13 23:52:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
2010-04-13 23:50:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\COMODO
2010-04-13 23:44:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-13 23:44:11 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-13 23:42:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-13 23:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-13 23:41:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-13 23:41:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 23:40:58 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2010-04-13 23:37:46 ----D---- C:\WINDOWS\system32\NtmsData
2010-04-13 23:33:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-04-13 21:19:10 ----SHD---- C:\RECYCLER
2010-04-12 17:30:11 ----D---- C:\WINDOWS\temp
2010-04-11 12:02:19 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-04-11 11:50:56 ----A---- C:\Boot.bak
2010-04-11 11:50:51 ----RASHD---- C:\cmdcons
2010-04-11 00:18:05 ----SHD---- C:\WINDOWS\CSC
2010-04-09 23:42:52 ----A---- C:\WINDOWS\cavscan.INI
2010-04-09 23:10:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-04-08 23:58:07 ----A---- C:\WINDOWS\cfplogvw.INI
2010-04-08 22:56:57 ----A---- C:\WINDOWS\CIS_Setup_3.13.121240.574_XP_Vista_x32.INI
2010-04-08 01:31:59 ----A---- C:\WINDOWS\system32\RUNDLL32.EXE
2010-04-07 23:15:17 ----N---- C:\WINDOWS\system32\SVCHOST.EXE
2010-04-07 22:47:43 ----N---- C:\WINDOWS\explorer.exe
2010-04-07 02:44:20 ----N---- C:\WINDOWS\system32\services.exe
2010-04-06 20:50:01 ----RASH---- C:\boot.ini
2010-04-03 19:23:18 ----A---- C:\WINDOWS\system32\nvmccs.dll
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvmctray.dll
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvcpl.dll
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvcolor.exe
2010-04-03 19:22:54 ----A---- C:\WINDOWS\system32\nvwddi.dll
2010-03-29 18:15:34 ----A---- C:\WINDOWS\unvise32qt.exe
2010-03-29 18:14:37 ----D---- C:\WINDOWS\system32\QuickTime
2010-03-29 18:13:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\QuickTime
======List of files/folders modified in the last 1 months======
2010-04-27 23:41:11 ----D---- C:\Program Files\Common Files
2010-04-27 23:11:22 ----D---- C:\WINDOWS\Prefetch
2010-04-27 22:16:56 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-27 21:48:15 ----D---- C:\WINDOWS
2010-04-27 21:44:10 ----SHD---- C:\System Volume Information
2010-04-27 21:14:01 ----SD---- C:\WINDOWS\Tasks
2010-04-27 21:13:58 ----RD---- C:\Program Files
2010-04-27 21:13:58 ----D---- C:\WINDOWS\system32\drivers
2010-04-26 22:36:41 ----D---- C:\WINDOWS\Registration
2010-04-26 22:28:24 ----D---- C:\WINDOWS\system32
2010-04-25 15:33:45 ----A---- C:\WINDOWS\NeroDigital.ini
2010-04-24 09:31:12 ----HD---- C:\WINDOWS\inf
2010-04-20 20:11:20 ----SHD---- C:\WINDOWS\Installer
2010-04-20 20:11:19 ----D---- C:\WINDOWS\WinSxS
2010-04-19 20:11:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-19 20:09:57 ----D---- C:\WINDOWS\system32\CatRoot
2010-04-19 20:09:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-19 20:09:06 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-18 00:58:08 ----RSD---- C:\WINDOWS\Fonts
2010-04-18 00:57:56 ----D---- C:\WINDOWS\system32\spool
2010-04-18 00:56:06 ----D---- C:\WINDOWS\system32\mui
2010-04-18 00:56:06 ----D---- C:\Program Files\Internet Explorer
2010-04-18 00:10:02 ----D---- C:\downloads
2010-04-15 20:35:58 ----D---- C:\WINDOWS\system
2010-04-15 19:49:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-04-15 19:45:10 ----A---- C:\WINDOWS\system32\guard32.dll
2010-04-15 19:33:57 ----D---- C:\WINDOWS\Help
2010-04-15 19:33:17 ----D---- C:\Program Files\NVIDIA Corporation
2010-04-15 19:33:06 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-04-14 21:39:32 ----D---- C:\WINDOWS\Debug
2010-04-14 06:15:14 ----D---- C:\WINDOWS\system32\Restore
2010-04-13 23:41:53 ----D---- C:\WINDOWS\ie8updates
2010-04-13 23:37:46 ----D---- C:\WINDOWS\repair
2010-04-13 21:10:42 ----A---- C:\WINDOWS\system.ini
2010-04-13 21:08:26 ----D---- C:\WINDOWS\AppPatch
2010-04-13 21:04:34 ----D---- C:\WINDOWS\system32\config
2010-04-13 00:19:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-04-11 19:21:01 ----D---- C:\Program Files\Microsoft IntelliPoint
2010-04-08 22:33:12 ----D---- C:\WINDOWS\twain_32
2010-04-07 23:34:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-04-07 22:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-05 10:13:43 ----D---- C:\WINDOWS\Logs
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\OpenCL.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvudisp.exe
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcuda.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcodins.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcod.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvapi.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2010-04-02 16:54:38 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2006-10-18 12664]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
R1 avgio;avgio; \??\I:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2010-04-15 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-04-15 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-04-15 25240]
R1 NVTCP;NVIDIA TCP/IP Protocol Driver; C:\WINDOWS\System32\DRIVERS\NVTcp.sys [2006-09-11 110592]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 psh_drv;Process Activity Acronis Monitor; C:\WINDOWS\system32\DRIVERS\psh_drv.sys [2009-05-05 98880]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-04 10232128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-09-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-09-11 19968]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-12-26 47360]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2006-11-08 21760]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2005-09-27 16000]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2009-09-11 22792]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2009-09-11 35592]
R3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2009-09-11 31752]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2009-09-11 66056]
S1 asusgsb;ASUS Virtual Video Capture Device Driver; C:\WINDOWS\system32\drivers\asusgsb32.sys [2005-10-20 12416]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Rodina\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 TF1D091000SER;TF1D091000SER USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\TF1D091000SER.sys [2008-01-08 99968]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2009-09-11 14984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-02-27 717296]
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-17 73344]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; I:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-19 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; I:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-09-04 241664]
R2 cmdAgent;COMODO Internet Security Helper Service; I:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-04-15 1769216]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2006-09-11 172032]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-04-13 20543]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2006-09-11 135227]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-09-11 65599]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 psh_svc;Acronis Malware Shield Service; C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; I:\Program Files\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-04-27 23:14:29
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (18%) free of 10 GB
Total RAM: 3070 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:26:19, on 13.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Rodina\Plocha\RSIT.exe
I:\Program Files\Trend Micro\HijackThis\Rodina.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - I:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - I:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O8 - Extra context menu item: &Download by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://I:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra 'Tools' menuitem: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - I:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Acronis Malware Shield Service (psh_svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
--
End of file - 7535 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Norton Security Scan for Rodina.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - I:\Program Files\Orbitdownloader\orbitcth.dll [2010-04-16 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - I:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E24AD748-155E-4254-B674-4EDF86E7E1DF}]
CAdBlocker Object - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll [2006-04-18 788312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - I:\Program Files\Orbitdownloader\GrabPro.dll [2010-04-16 666816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=I:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"COMODO Internet Security"=I:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-04-15 2029456]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"I:\Program Files\Skype\Phone\Skype.exe"="I:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"I:\Program Files\Orbitdownloader\orbitdm.exe"="I:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"I:\Program Files\Orbitdownloader\orbitnet.exe"="I:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-04-27 23:14:29 ----D---- C:\rsit
2010-04-27 21:16:12 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-04-27 21:13:58 ----D---- C:\Program Files\Norton Security Scan
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Symantec
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2010-04-27 21:13:57 ----D---- C:\Program Files\NortonInstaller
2010-04-27 21:13:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2010-04-21 21:05:14 ----D---- C:\VundoFix Backups
2010-04-21 20:40:11 ----A---- C:\WINDOWS\system32\h323log.txt
2010-04-21 00:07:32 ----HD---- C:\VritualRoot
2010-04-20 22:43:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\F-Secure
2010-04-19 20:09:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-04-19 20:08:41 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2010-04-18 00:58:12 ----D---- C:\WINDOWS\system32\XPSViewer
2010-04-18 00:58:10 ----D---- C:\Program Files\MSBuild
2010-04-18 00:58:09 ----D---- C:\WINDOWS\system32\en-US
2010-04-18 00:58:04 ----D---- C:\Program Files\Reference Assemblies
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-04-18 00:54:41 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-04-18 00:54:37 ----D---- C:\Program Files\MSXML 6.0
2010-04-15 20:34:39 ----A---- C:\WINDOWS\Ascd_tmp.ini
2010-04-15 19:04:10 ----RSD---- C:\WINDOWS\assembly
2010-04-15 19:03:48 ----D---- C:\WINDOWS\Microsoft.NET
2010-04-13 23:52:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
2010-04-13 23:50:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\COMODO
2010-04-13 23:44:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-13 23:44:11 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-13 23:42:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-13 23:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-13 23:41:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-13 23:41:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 23:40:58 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2010-04-13 23:37:46 ----D---- C:\WINDOWS\system32\NtmsData
2010-04-13 23:33:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-04-13 21:19:10 ----SHD---- C:\RECYCLER
2010-04-12 17:30:11 ----D---- C:\WINDOWS\temp
2010-04-11 12:02:19 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-04-11 11:50:56 ----A---- C:\Boot.bak
2010-04-11 11:50:51 ----RASHD---- C:\cmdcons
2010-04-11 00:18:05 ----SHD---- C:\WINDOWS\CSC
2010-04-09 23:42:52 ----A---- C:\WINDOWS\cavscan.INI
2010-04-09 23:10:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-04-08 23:58:07 ----A---- C:\WINDOWS\cfplogvw.INI
2010-04-08 22:56:57 ----A---- C:\WINDOWS\CIS_Setup_3.13.121240.574_XP_Vista_x32.INI
2010-04-08 01:31:59 ----A---- C:\WINDOWS\system32\RUNDLL32.EXE
2010-04-07 23:15:17 ----N---- C:\WINDOWS\system32\SVCHOST.EXE
2010-04-07 22:47:43 ----N---- C:\WINDOWS\explorer.exe
2010-04-07 02:44:20 ----N---- C:\WINDOWS\system32\services.exe
2010-04-06 20:50:01 ----RASH---- C:\boot.ini
2010-04-03 19:23:18 ----A---- C:\WINDOWS\system32\nvmccs.dll
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvmctray.dll
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvcpl.dll
2010-04-03 19:23:16 ----A---- C:\WINDOWS\system32\nvcolor.exe
2010-04-03 19:22:54 ----A---- C:\WINDOWS\system32\nvwddi.dll
2010-03-29 18:15:34 ----A---- C:\WINDOWS\unvise32qt.exe
2010-03-29 18:14:37 ----D---- C:\WINDOWS\system32\QuickTime
2010-03-29 18:13:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\QuickTime
======List of files/folders modified in the last 1 months======
2010-04-27 23:41:11 ----D---- C:\Program Files\Common Files
2010-04-27 23:11:22 ----D---- C:\WINDOWS\Prefetch
2010-04-27 22:16:56 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-27 21:48:15 ----D---- C:\WINDOWS
2010-04-27 21:44:10 ----SHD---- C:\System Volume Information
2010-04-27 21:14:01 ----SD---- C:\WINDOWS\Tasks
2010-04-27 21:13:58 ----RD---- C:\Program Files
2010-04-27 21:13:58 ----D---- C:\WINDOWS\system32\drivers
2010-04-26 22:36:41 ----D---- C:\WINDOWS\Registration
2010-04-26 22:28:24 ----D---- C:\WINDOWS\system32
2010-04-25 15:33:45 ----A---- C:\WINDOWS\NeroDigital.ini
2010-04-24 09:31:12 ----HD---- C:\WINDOWS\inf
2010-04-20 20:11:20 ----SHD---- C:\WINDOWS\Installer
2010-04-20 20:11:19 ----D---- C:\WINDOWS\WinSxS
2010-04-19 20:11:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-19 20:09:57 ----D---- C:\WINDOWS\system32\CatRoot
2010-04-19 20:09:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-19 20:09:06 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-18 00:58:08 ----RSD---- C:\WINDOWS\Fonts
2010-04-18 00:57:56 ----D---- C:\WINDOWS\system32\spool
2010-04-18 00:56:06 ----D---- C:\WINDOWS\system32\mui
2010-04-18 00:56:06 ----D---- C:\Program Files\Internet Explorer
2010-04-18 00:10:02 ----D---- C:\downloads
2010-04-15 20:35:58 ----D---- C:\WINDOWS\system
2010-04-15 19:49:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-04-15 19:45:10 ----A---- C:\WINDOWS\system32\guard32.dll
2010-04-15 19:33:57 ----D---- C:\WINDOWS\Help
2010-04-15 19:33:17 ----D---- C:\Program Files\NVIDIA Corporation
2010-04-15 19:33:06 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-04-14 21:39:32 ----D---- C:\WINDOWS\Debug
2010-04-14 06:15:14 ----D---- C:\WINDOWS\system32\Restore
2010-04-13 23:41:53 ----D---- C:\WINDOWS\ie8updates
2010-04-13 23:37:46 ----D---- C:\WINDOWS\repair
2010-04-13 21:10:42 ----A---- C:\WINDOWS\system.ini
2010-04-13 21:08:26 ----D---- C:\WINDOWS\AppPatch
2010-04-13 21:04:34 ----D---- C:\WINDOWS\system32\config
2010-04-13 00:19:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-04-11 19:21:01 ----D---- C:\Program Files\Microsoft IntelliPoint
2010-04-08 22:33:12 ----D---- C:\WINDOWS\twain_32
2010-04-07 23:34:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-04-07 22:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-05 10:13:43 ----D---- C:\WINDOWS\Logs
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\OpenCL.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvudisp.exe
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcuda.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcodins.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvcod.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nvapi.dll
2010-04-04 00:55:31 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2010-04-02 16:54:38 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2006-10-18 12664]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
R1 avgio;avgio; \??\I:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2010-04-15 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-04-15 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-04-15 25240]
R1 NVTCP;NVIDIA TCP/IP Protocol Driver; C:\WINDOWS\System32\DRIVERS\NVTcp.sys [2006-09-11 110592]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 psh_drv;Process Activity Acronis Monitor; C:\WINDOWS\system32\DRIVERS\psh_drv.sys [2009-05-05 98880]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-04 10232128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-09-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-09-11 19968]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-12-26 47360]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2006-11-08 21760]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2005-09-27 16000]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2009-09-11 22792]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2009-09-11 35592]
R3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2009-09-11 31752]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2009-09-11 66056]
S1 asusgsb;ASUS Virtual Video Capture Device Driver; C:\WINDOWS\system32\drivers\asusgsb32.sys [2005-10-20 12416]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Rodina\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 TF1D091000SER;TF1D091000SER USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\TF1D091000SER.sys [2008-01-08 99968]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2009-09-11 14984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-02-27 717296]
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-17 73344]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; I:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-19 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; I:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-09-04 241664]
R2 cmdAgent;COMODO Internet Security Helper Service; I:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-04-15 1769216]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2006-09-11 172032]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-04-13 20543]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2006-09-11 135227]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-09-11 65599]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 psh_svc;Acronis Malware Shield Service; C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; I:\Program Files\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Re: Pro Motji: trojan Generic15.apnz

-souhlaste s instalací konzole pro zotavení
- ComboFix je třeba spustit pod účtem s právy administrátora
- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary
- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano
- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pro Motji: trojan Generic15.apnz
ComboFix šel spustit pouze v nouzovém režimu, jinak hlásil problémy se souborem hidec.exe.
ComboFix 10-04-26.05 - Rodina 27.04.2010 23:56:16.9.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.3070.2705 [GMT 2:00]
Spuštěný z: c:\documents and settings\Rodina\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-27 do 2010-04-27 )))))))))))))))))))))))))))))))
.
2010-04-27 21:36 . 2010-04-27 21:36 7199979 ----a-w- c:\program files\Common Files\InstallShield.zip
2010-04-27 21:14 . 2010-04-27 21:14 -------- d-----w- C:\rsit
2010-04-27 19:16 . 2010-04-27 19:57 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-04-27 19:13 . 2010-04-27 19:13 -------- d-----w- c:\windows\system32\drivers\NSS
2010-04-27 19:13 . 2010-04-27 19:13 -------- d-----w- c:\program files\Norton Security Scan
2010-04-27 19:13 . 2010-04-27 19:13 -------- d-----w- c:\program files\NortonInstaller
2010-04-21 19:05 . 2010-04-21 19:05 -------- d-----w- C:\VundoFix Backups
2010-04-20 22:07 . 2010-04-20 22:07 -------- d-----w- C:\VritualRoot
2010-04-17 22:58 . 2010-04-17 22:58 -------- d-----w- c:\windows\system32\XPSViewer
2010-04-17 22:58 . 2010-04-17 22:58 -------- d-----w- c:\program files\MSBuild
2010-04-17 22:58 . 2010-04-17 22:58 -------- d-----w- c:\program files\Reference Assemblies
2010-04-17 22:57 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-04-17 22:57 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-04-17 22:57 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-04-17 22:57 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-04-17 22:57 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-04-17 22:57 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-04-17 22:57 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-04-17 22:57 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-04-17 22:57 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-04-17 22:54 . 2010-04-17 22:54 -------- d-----w- c:\program files\MSXML 6.0
2010-04-13 21:37 . 2010-04-26 21:57 -------- d-----w- c:\windows\system32\NtmsData
2010-04-13 21:33 . 2010-03-01 07:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-04-13 21:33 . 2010-02-16 11:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-04-13 21:33 . 2009-05-11 09:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-04-13 21:33 . 2009-05-11 09:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-04-11 21:20 . 2009-08-21 13:04 182912 ------w- c:\windows\system32\dllcache\ndis.sys
2010-04-11 21:20 . 2009-08-21 13:04 182912 ------w- c:\windows\system32\drivers\ndis.sys
2010-04-10 22:11 . 2006-08-21 10:24 105344 ----a-r- c:\windows\system32\drivers\nvata_2.sys
2010-04-09 21:10 . 2010-04-09 21:10 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-04-08 21:07 . 2010-04-13 22:00 145952 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-04-07 23:31 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\RUNDLL32.EXE
2010-04-07 21:15 . 2004-08-17 13:49 14336 ------w- c:\windows\system32\SVCHOST.EXE
2010-04-07 21:00 . 2004-08-03 20:59 95360 ------w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-07 20:47 . 2007-06-13 13:23 1033728 ------w- c:\windows\explorer.exe
2010-04-07 20:04 . 2010-04-07 20:04 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2010-04-07 00:44 . 2009-02-09 10:11 111104 ------w- c:\windows\system32\services.exe
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-29 16:15 . 1999-11-10 09:05 86016 ----a-w- c:\windows\unvise32qt.exe
2010-03-29 16:14 . 2010-04-08 22:15 -------- d-----w- c:\windows\system32\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-19 18:11 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-04-19 18:11 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2010-04-15 17:45 . 2010-03-03 15:54 277240 ----a-w- c:\windows\system32\guard32.dll
2010-04-15 17:45 . 2010-03-03 15:54 86800 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-04-15 17:45 . 2010-03-03 15:54 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-04-15 17:45 . 2010-03-23 16:40 225344 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-04-15 17:45 . 2010-03-03 15:54 15464 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-04-15 17:33 . 2009-04-04 20:59 -------- d-----w- c:\program files\NVIDIA Corporation
2010-04-12 20:54 . 2001-10-25 14:00 5888 ----a-w- c:\windows\system32\drivers\dmload.sys
2010-04-11 17:21 . 2009-04-09 21:01 -------- d-----w- c:\program files\Microsoft IntelliPoint
2010-04-02 14:54 . 2009-04-04 20:57 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-03-22 16:27 . 2010-03-22 16:27 -------- d-----w- c:\program files\MSECache
2010-03-20 19:32 . 2010-03-13 15:29 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-11 21:42 . 2010-03-11 21:42 -------- d-----w- c:\program files\Common Files\Java
2010-03-11 21:42 . 2009-06-17 19:39 -------- d-----w- c:\program files\Java
2010-03-10 06:17 . 2004-08-17 13:49 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-27 14:33 . 2009-04-05 19:31 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-25 06:18 . 2004-08-17 13:49 916480 ------w- c:\windows\system32\wininet.dll
2010-02-24 12:31 . 2004-08-03 21:15 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 19:34 . 2004-08-17 15:45 2018816 ------w- c:\windows\system32\ntkrnlpa.exe
2010-02-16 19:34 . 2004-08-17 13:45 2139136 ------w- c:\windows\system32\ntoskrnl.exe
2010-02-12 04:47 . 2004-08-17 13:49 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:01 . 2004-08-03 21:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2010-03-02 08:28 282792 ----a-w- i:\program files\Avira\AntiVir Desktop\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Internet Security]
2010-04-15 17:44 2029456 ----a-w- i:\program files\Comodo\COMODO Internet Security\cfp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-17 13:49 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ASUS SmartDoctor"=c:\program files\ASUS\SmartDoctor\SmartDoctor.exe /start
"Shield"=i:\program files\Acronis\PrivacyExpert\Shield.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Ai Gear Help"="i:\program files\ASUS\AI Gear\GearHelp.exe"
"AsusStartupHelp"=c:\program files\ASUS\AASP\1.00.15\AsRunHelp.exe
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"GameFace Messenger"=c:\program files\GameFace Messenger\GameFace.exe
"Launch Ai Booster"="i:\program files\ASUS\AI Booster\OverClk.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"COMODO Internet Security"="i:\program files\Comodo\COMODO Internet Security\cfp.exe" -h
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"i:\\Program Files\\Skype\\Phone\\Skype.exe"=
"i:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"i:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [3.3.2010 17:54 15464]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [23.3.2010 18:40 225344]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [3.3.2010 17:54 25240]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;i:\program files\Avira\AntiVir Desktop\sched.exe [13.4.2010 23:33 135336]
S2 gupdate;Služba Google Update (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S2 psh_drv;Process Activity Acronis Monitor;c:\windows\system32\drivers\psh_drv.sys [5.5.2009 22:10 98880]
S2 psh_svc;Acronis Malware Shield Service;"c:\program files\Common Files\Acronis\Ochranný štít\psh_svc.exe" --> c:\program files\Common Files\Acronis\Ochranný štít\psh_svc.exe [?]
S3 TF1D091000SER;TF1D091000SER USB Device for Legacy Serial Communication;c:\windows\system32\drivers\TF1D091000SER.sys [14.10.2009 20:03 99968]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5.4.2009 21:31 717296]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - PSH_DRV
.
Obsah adresáře 'Naplánované úlohy'
2010-04-27 c:\windows\Tasks\Norton Security Scan for Rodina.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-04-27 01:05]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: &Download by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovat do aplikace Microsoft Office Excel - i:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
MSConfigStartUp-nwiz - nwiz.exe
AddRemove-CCleaner - n:\ccleaner\uninst.exe
AddRemove-InstallShield_{04726714-8286-43B8-AFD6-2DF92EC49995} - c:\progra~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{12E11FBB-7CA6-4A86-834D-5E6390D51009} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{43C67D92-F56E-4729-8673-9A2D5A6036F8} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{7A529246-912F-4C40-A82A-E608DB702FD7} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{92B07938-0550-4937-9447-E0ECC04AB99D} - c:\progra~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-27 23:59
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-839522115-1004336348-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:ef,a1,ef,fd,9e,d3,5d,dc,e3,ed,e8,0d,0b,99,a4,41,06,6b,21,3a,97,
ea,96,4e,75,99,a8,5b,44,c4,21,a8,27,ad,dd,a9,c8,e1,16,0b,7a,89,bb,b4,52,bf,\
"rkeysecu"=hex:c7,04,72,eb,a6,b0,ce,f1,84,86,41,ff,62,0f,7a,1a
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(424)
c:\windows\system32\guard32.dll
- - - - - - - > 'lsass.exe'(480)
c:\windows\system32\guard32.dll
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(1636)
c:\windows\system32\guard32.dll
.
Celkový čas: 2010-04-27 23:59:53
ComboFix-quarantined-files.txt 2010-04-27 21:59
Před spuštěním: 1 879 093 248
Po spuštění: 1 843 597 312
- - End Of File - - 69C0DF0419F393DCB5C100532B3553C7
ComboFix 10-04-26.05 - Rodina 27.04.2010 23:56:16.9.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.3070.2705 [GMT 2:00]
Spuštěný z: c:\documents and settings\Rodina\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-27 do 2010-04-27 )))))))))))))))))))))))))))))))
.
2010-04-27 21:36 . 2010-04-27 21:36 7199979 ----a-w- c:\program files\Common Files\InstallShield.zip
2010-04-27 21:14 . 2010-04-27 21:14 -------- d-----w- C:\rsit
2010-04-27 19:16 . 2010-04-27 19:57 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-04-27 19:13 . 2010-04-27 19:13 -------- d-----w- c:\windows\system32\drivers\NSS
2010-04-27 19:13 . 2010-04-27 19:13 -------- d-----w- c:\program files\Norton Security Scan
2010-04-27 19:13 . 2010-04-27 19:13 -------- d-----w- c:\program files\NortonInstaller
2010-04-21 19:05 . 2010-04-21 19:05 -------- d-----w- C:\VundoFix Backups
2010-04-20 22:07 . 2010-04-20 22:07 -------- d-----w- C:\VritualRoot
2010-04-17 22:58 . 2010-04-17 22:58 -------- d-----w- c:\windows\system32\XPSViewer
2010-04-17 22:58 . 2010-04-17 22:58 -------- d-----w- c:\program files\MSBuild
2010-04-17 22:58 . 2010-04-17 22:58 -------- d-----w- c:\program files\Reference Assemblies
2010-04-17 22:57 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-04-17 22:57 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-04-17 22:57 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-04-17 22:57 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-04-17 22:57 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-04-17 22:57 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-04-17 22:57 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-04-17 22:57 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-04-17 22:57 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-04-17 22:54 . 2010-04-17 22:54 -------- d-----w- c:\program files\MSXML 6.0
2010-04-13 21:37 . 2010-04-26 21:57 -------- d-----w- c:\windows\system32\NtmsData
2010-04-13 21:33 . 2010-03-01 07:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-04-13 21:33 . 2010-02-16 11:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-04-13 21:33 . 2009-05-11 09:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-04-13 21:33 . 2009-05-11 09:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-04-11 21:20 . 2009-08-21 13:04 182912 ------w- c:\windows\system32\dllcache\ndis.sys
2010-04-11 21:20 . 2009-08-21 13:04 182912 ------w- c:\windows\system32\drivers\ndis.sys
2010-04-10 22:11 . 2006-08-21 10:24 105344 ----a-r- c:\windows\system32\drivers\nvata_2.sys
2010-04-09 21:10 . 2010-04-09 21:10 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-04-08 21:07 . 2010-04-13 22:00 145952 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-04-07 23:31 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\RUNDLL32.EXE
2010-04-07 21:15 . 2004-08-17 13:49 14336 ------w- c:\windows\system32\SVCHOST.EXE
2010-04-07 21:00 . 2004-08-03 20:59 95360 ------w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-07 20:47 . 2007-06-13 13:23 1033728 ------w- c:\windows\explorer.exe
2010-04-07 20:04 . 2010-04-07 20:04 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2010-04-07 00:44 . 2009-02-09 10:11 111104 ------w- c:\windows\system32\services.exe
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-29 16:15 . 1999-11-10 09:05 86016 ----a-w- c:\windows\unvise32qt.exe
2010-03-29 16:14 . 2010-04-08 22:15 -------- d-----w- c:\windows\system32\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-19 18:11 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-04-19 18:11 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2010-04-15 17:45 . 2010-03-03 15:54 277240 ----a-w- c:\windows\system32\guard32.dll
2010-04-15 17:45 . 2010-03-03 15:54 86800 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-04-15 17:45 . 2010-03-03 15:54 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-04-15 17:45 . 2010-03-23 16:40 225344 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-04-15 17:45 . 2010-03-03 15:54 15464 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-04-15 17:33 . 2009-04-04 20:59 -------- d-----w- c:\program files\NVIDIA Corporation
2010-04-12 20:54 . 2001-10-25 14:00 5888 ----a-w- c:\windows\system32\drivers\dmload.sys
2010-04-11 17:21 . 2009-04-09 21:01 -------- d-----w- c:\program files\Microsoft IntelliPoint
2010-04-02 14:54 . 2009-04-04 20:57 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-03-22 16:27 . 2010-03-22 16:27 -------- d-----w- c:\program files\MSECache
2010-03-20 19:32 . 2010-03-13 15:29 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-11 21:42 . 2010-03-11 21:42 -------- d-----w- c:\program files\Common Files\Java
2010-03-11 21:42 . 2009-06-17 19:39 -------- d-----w- c:\program files\Java
2010-03-10 06:17 . 2004-08-17 13:49 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-27 14:33 . 2009-04-05 19:31 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-25 06:18 . 2004-08-17 13:49 916480 ------w- c:\windows\system32\wininet.dll
2010-02-24 12:31 . 2004-08-03 21:15 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 19:34 . 2004-08-17 15:45 2018816 ------w- c:\windows\system32\ntkrnlpa.exe
2010-02-16 19:34 . 2004-08-17 13:45 2139136 ------w- c:\windows\system32\ntoskrnl.exe
2010-02-12 04:47 . 2004-08-17 13:49 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:01 . 2004-08-03 21:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2010-03-02 08:28 282792 ----a-w- i:\program files\Avira\AntiVir Desktop\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Internet Security]
2010-04-15 17:44 2029456 ----a-w- i:\program files\Comodo\COMODO Internet Security\cfp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-17 13:49 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ASUS SmartDoctor"=c:\program files\ASUS\SmartDoctor\SmartDoctor.exe /start
"Shield"=i:\program files\Acronis\PrivacyExpert\Shield.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Ai Gear Help"="i:\program files\ASUS\AI Gear\GearHelp.exe"
"AsusStartupHelp"=c:\program files\ASUS\AASP\1.00.15\AsRunHelp.exe
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"GameFace Messenger"=c:\program files\GameFace Messenger\GameFace.exe
"Launch Ai Booster"="i:\program files\ASUS\AI Booster\OverClk.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"COMODO Internet Security"="i:\program files\Comodo\COMODO Internet Security\cfp.exe" -h
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"i:\\Program Files\\Skype\\Phone\\Skype.exe"=
"i:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"i:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [3.3.2010 17:54 15464]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [23.3.2010 18:40 225344]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [3.3.2010 17:54 25240]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;i:\program files\Avira\AntiVir Desktop\sched.exe [13.4.2010 23:33 135336]
S2 gupdate;Služba Google Update (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S2 psh_drv;Process Activity Acronis Monitor;c:\windows\system32\drivers\psh_drv.sys [5.5.2009 22:10 98880]
S2 psh_svc;Acronis Malware Shield Service;"c:\program files\Common Files\Acronis\Ochranný štít\psh_svc.exe" --> c:\program files\Common Files\Acronis\Ochranný štít\psh_svc.exe [?]
S3 TF1D091000SER;TF1D091000SER USB Device for Legacy Serial Communication;c:\windows\system32\drivers\TF1D091000SER.sys [14.10.2009 20:03 99968]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5.4.2009 21:31 717296]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - PSH_DRV
.
Obsah adresáře 'Naplánované úlohy'
2010-04-27 c:\windows\Tasks\Norton Security Scan for Rodina.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-04-27 01:05]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: &Download by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - i:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xportovat do aplikace Microsoft Office Excel - i:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
MSConfigStartUp-nwiz - nwiz.exe
AddRemove-CCleaner - n:\ccleaner\uninst.exe
AddRemove-InstallShield_{04726714-8286-43B8-AFD6-2DF92EC49995} - c:\progra~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{12E11FBB-7CA6-4A86-834D-5E6390D51009} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{43C67D92-F56E-4729-8673-9A2D5A6036F8} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{7A529246-912F-4C40-A82A-E608DB702FD7} - c:\progra~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{92B07938-0550-4937-9447-E0ECC04AB99D} - c:\progra~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-27 23:59
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-839522115-1004336348-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:ef,a1,ef,fd,9e,d3,5d,dc,e3,ed,e8,0d,0b,99,a4,41,06,6b,21,3a,97,
ea,96,4e,75,99,a8,5b,44,c4,21,a8,27,ad,dd,a9,c8,e1,16,0b,7a,89,bb,b4,52,bf,\
"rkeysecu"=hex:c7,04,72,eb,a6,b0,ce,f1,84,86,41,ff,62,0f,7a,1a
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(424)
c:\windows\system32\guard32.dll
- - - - - - - > 'lsass.exe'(480)
c:\windows\system32\guard32.dll
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(1636)
c:\windows\system32\guard32.dll
.
Celkový čas: 2010-04-27 23:59:53
ComboFix-quarantined-files.txt 2010-04-27 21:59
Před spuštěním: 1 879 093 248
Po spuštění: 1 843 597 312
- - End Of File - - 69C0DF0419F393DCB5C100532B3553C7
Re: Pro Motji: trojan Generic15.apnz



Můžete sem dát screen toho, co Comodo hlásí?

-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pro Motji: trojan Generic15.apnz
Antivir u Comoda vypnu. Zatím se nepoprali
Scan jsem dělal nejdříve Kasperskym, ten byl úplně čistý a Norton hlásil 3 soubory nebezpečné, z toho dva od Acronis jako že rezidentní štít, třetí byl jazyková knihovna od CCleaneru s číslem 29. Vše smazáno, ale acronis se objevil znova.
Další dva soubory byly tracking cookies s příponou .pl.
Obrazovku Comoda Vám pošlu, ale až přijdu domů. Zatím jsem v práci.
MBAM byl jedním z programů, které se mně zdály podezřelé v souvislosti s virtumondem a svítící ikonkou v kontextovém menu - odinstalováno.
Přeji hezké odpoledne.

Scan jsem dělal nejdříve Kasperskym, ten byl úplně čistý a Norton hlásil 3 soubory nebezpečné, z toho dva od Acronis jako že rezidentní štít, třetí byl jazyková knihovna od CCleaneru s číslem 29. Vše smazáno, ale acronis se objevil znova.
Další dva soubory byly tracking cookies s příponou .pl.
Obrazovku Comoda Vám pošlu, ale až přijdu domů. Zatím jsem v práci.
MBAM byl jedním z programů, které se mně zdály podezřelé v souvislosti s virtumondem a svítící ikonkou v kontextovém menu - odinstalováno.
Přeji hezké odpoledne.
Re: Pro Motji: trojan Generic15.apnz
Screen se mi nepodařilo vložit. Proto příloha. Právě tam bylo 14 komunikací.
- Přílohy
-
- scr.jpg
- (63.5 KiB) Staženo 66 x
Re: Pro Motji: trojan Generic15.apnz
Takže jsou tam 4 IP adresy
Český Telecom
SuperNetwork s.r.o. -znáte?
Google
Ignum s.r.o -znáte?
Český Telecom
SuperNetwork s.r.o. -znáte?
Ignum s.r.o -znáte?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pro Motji: trojan Generic15.apnz
MBAM bez zjištění:
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Verze databáze: 4047
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
28.4.2010 21:18:12
mbam-log-2010-04-28 (21-18-12).txt
Typ skenu: Úplný sken (C:\|D:\|I:\|)
Skenované objekty: 195210
Uplynulý čas: 46 minuta(y), 15 sekunda(y)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Norton 5x insight a 2x tracking cookies: rodina@hit.gemius.pl
Pokud jde o ty adresy, tak neznám a ani si nepamatuji, že bych tam kdy byl......................
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Verze databáze: 4047
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
28.4.2010 21:18:12
mbam-log-2010-04-28 (21-18-12).txt
Typ skenu: Úplný sken (C:\|D:\|I:\|)
Skenované objekty: 195210
Uplynulý čas: 46 minuta(y), 15 sekunda(y)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Norton 5x insight a 2x tracking cookies: rodina@hit.gemius.pl
Pokud jde o ty adresy, tak neznám a ani si nepamatuji, že bych tam kdy byl......................
Re: Pro Motji: trojan Generic15.apnz
Google se nejspíš chtělo aktualizovat, ty ostatní IP adresy v comodu zakažte.
Pc je stále pomalé?
Pc je stále pomalé?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pro Motji: trojan Generic15.apnz
Tak jsem zakazoval, až jsem se nedostal ani na viry.cz.........
Bohužel neumím přiřadit jednotlivé IP adresy serverům, takže je to pokus omyl a na dlouho. Internet se občas kousne, ale nejdéle trvá start počítače.
Takto vypadá spouštění PC:
Ano HKCU:Run ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
Ano HKLM:Run NvCplDaemon RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
Ano HKLM:Run NvMediaCenter RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
Ano HKLM:Run SoundMAXPnP C:\Program Files\Analog Devices\Core\smax4pnp.exe
Ano HKLM:Run avgnt "I:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
Ano HKLM:Run COMODO Internet Security "I:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
Ano HKLM:RunOnce Malwarebytes' Anti-Malware I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

Bohužel neumím přiřadit jednotlivé IP adresy serverům, takže je to pokus omyl a na dlouho. Internet se občas kousne, ale nejdéle trvá start počítače.
Takto vypadá spouštění PC:
Ano HKCU:Run ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
Ano HKLM:Run NvCplDaemon RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
Ano HKLM:Run NvMediaCenter RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
Ano HKLM:Run SoundMAXPnP C:\Program Files\Analog Devices\Core\smax4pnp.exe
Ano HKLM:Run avgnt "I:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
Ano HKLM:Run COMODO Internet Security "I:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
Ano HKLM:RunOnce Malwarebytes' Anti-Malware I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
Re: Pro Motji: trojan Generic15.apnz
Ano HKLM:RunOnce Malwarebytes' Anti-Malware I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
tohle můžete zastavit.
Jak to ted s pc vypadá?
Na to comodo se zeptám.
tohle můžete zastavit.
Jak to ted s pc vypadá?
Na to comodo se zeptám.

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pro Motji: trojan Generic15.apnz
MBAM se startuje od včerejška, ale zastavím ho.
Nainstaloval jsem znovu Spyware Search and Destroy, třeba dokáže zastavit nějakou nekalou komunikaci.
Při startu nejdéle trvá start připojení na síť. Když start srovnám s druhým PC, tak je to nebe a dudy (bohužel asi nezávisle na posledním zavirování).
Nainstaloval jsem znovu Spyware Search and Destroy, třeba dokáže zastavit nějakou nekalou komunikaci.
Při startu nejdéle trvá start připojení na síť. Když start srovnám s druhým PC, tak je to nebe a dudy (bohužel asi nezávisle na posledním zavirování).
Re: Pro Motji: trojan Generic15.apnz
A kromě náběhu startu internetu je vše ok?
Zkuste ještě přeinstalovat ovladače od sítovky.
Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
K tomu Comodu - Kolega PetrTI mi poradil, tak to zkusím trochu popsat
Pro každou adresu, kterou chcete blokovat, uděláte globální pravidlo:
Action - Block
Protocol - IP
Direction - Out
Source Address - Any
Destination Address - konkrétní IP adresa kterou chcete zablokovat
Source Port - Any
Destination Port - Any
Tyto pravidla přesunout úplně nahoru.
Na úplný konec dát pravidlo (zkráceně posáno) Block, IP, In, Any, Any, Any, Any. To bude blokovat ten nechtěný příchozí traffic.
Pokud něčemu nerozumíte, ptejte se
Zkuste ještě přeinstalovat ovladače od sítovky.

- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********


Pro každou adresu, kterou chcete blokovat, uděláte globální pravidlo:
Action - Block
Protocol - IP
Direction - Out
Source Address - Any
Destination Address - konkrétní IP adresa kterou chcete zablokovat
Source Port - Any
Destination Port - Any
Tyto pravidla přesunout úplně nahoru.
Na úplný konec dát pravidlo (zkráceně posáno) Block, IP, In, Any, Any, Any, Any. To bude blokovat ten nechtěný příchozí traffic.
Pokud něčemu nerozumíte, ptejte se

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pro Motji: trojan Generic15.apnz
Dobrý večer, kroky provádím postupně. Zatím jsem u logu z RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-05-04 21:41:57
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (19%) free of 10 GB
Total RAM: 3070 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:26:19, on 13.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Rodina\Plocha\RSIT.exe
I:\Program Files\Trend Micro\HijackThis\Rodina.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - I:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - I:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O8 - Extra context menu item: &Download by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://I:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra 'Tools' menuitem: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - I:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Acronis Malware Shield Service (psh_svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
--
End of file - 7535 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Norton Security Scan for Rodina.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - I:\Program Files\Orbitdownloader\orbitcth.dll [2010-04-16 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - I:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E24AD748-155E-4254-B674-4EDF86E7E1DF}]
CAdBlocker Object - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll [2006-04-18 788312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - I:\Program Files\Orbitdownloader\GrabPro.dll [2010-04-16 666816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"avgnt"=I:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"COMODO Internet Security"=I:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-04-15 2029456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"I:\Program Files\Orbitdownloader\orbitdm.exe"="I:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"I:\Program Files\Orbitdownloader\orbitnet.exe"="I:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"I:\Program Files\Skype\Phone\Skype.exe"="I:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-05-04 21:41:57 ----D---- C:\rsit
2010-05-04 21:27:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-04 21:25:05 ----SHD---- C:\RECYCLER
2010-05-04 21:24:07 ----D---- C:\WINDOWS\temp
2010-04-28 20:30:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-04-27 21:16:12 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-04-27 21:13:58 ----D---- C:\Program Files\Norton Security Scan
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Symantec
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2010-04-27 21:13:57 ----D---- C:\Program Files\NortonInstaller
2010-04-27 21:13:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2010-04-21 20:40:11 ----A---- C:\WINDOWS\system32\h323log.txt
2010-04-21 00:07:32 ----D---- C:\VritualRoot
2010-04-20 22:43:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\F-Secure
2010-04-19 20:09:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-04-19 20:08:41 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2010-04-18 00:58:12 ----D---- C:\WINDOWS\system32\XPSViewer
2010-04-18 00:58:10 ----D---- C:\Program Files\MSBuild
2010-04-18 00:58:09 ----D---- C:\WINDOWS\system32\en-US
2010-04-18 00:58:04 ----D---- C:\Program Files\Reference Assemblies
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-04-18 00:54:41 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-04-18 00:54:37 ----D---- C:\Program Files\MSXML 6.0
2010-04-15 20:34:39 ----A---- C:\WINDOWS\Ascd_tmp.ini
2010-04-15 19:04:10 ----RSD---- C:\WINDOWS\assembly
2010-04-15 19:03:48 ----D---- C:\WINDOWS\Microsoft.NET
2010-04-13 23:52:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
2010-04-13 23:50:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\COMODO
2010-04-13 23:44:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-13 23:44:11 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-13 23:42:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-13 23:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-13 23:41:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-13 23:41:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 23:40:58 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2010-04-13 23:37:46 ----D---- C:\WINDOWS\system32\NtmsData
2010-04-13 23:33:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-04-11 11:50:56 ----A---- C:\Boot.bak
2010-04-11 11:50:51 ----RASHD---- C:\cmdcons
2010-04-11 00:18:05 ----SHD---- C:\WINDOWS\CSC
2010-04-09 23:42:52 ----A---- C:\WINDOWS\cavscan.INI
2010-04-09 23:10:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-04-08 23:58:07 ----A---- C:\WINDOWS\cfplogvw.INI
2010-04-08 22:56:57 ----A---- C:\WINDOWS\CIS_Setup_3.13.121240.574_XP_Vista_x32.INI
2010-04-08 01:31:59 ----A---- C:\WINDOWS\system32\RUNDLL32.EXE
2010-04-07 23:15:17 ----N---- C:\WINDOWS\system32\SVCHOST.EXE
2010-04-07 22:47:43 ----N---- C:\WINDOWS\explorer.exe
2010-04-07 02:44:20 ----N---- C:\WINDOWS\system32\services.exe
2010-04-06 20:50:01 ----RASH---- C:\boot.ini
======List of files/folders modified in the last 1 months======
2010-05-04 21:41:19 ----D---- C:\WINDOWS\Prefetch
2010-05-04 21:36:07 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-04 21:32:07 ----D---- C:\WINDOWS
2010-05-04 21:25:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-05-04 21:22:55 ----A---- C:\WINDOWS\system.ini
2010-05-04 21:22:20 ----D---- C:\WINDOWS\system32\drivers
2010-05-04 21:22:02 ----D---- C:\WINDOWS\system32
2010-05-04 21:22:02 ----D---- C:\WINDOWS\AppPatch
2010-05-04 21:22:01 ----D---- C:\Program Files\Common Files
2010-05-04 21:15:23 ----SHD---- C:\System Volume Information
2010-05-04 21:15:23 ----D---- C:\WINDOWS\system32\Restore
2010-05-03 00:19:59 ----D---- C:\downloads
2010-05-03 00:05:05 ----A---- C:\WINDOWS\NeroDigital.ini
2010-04-27 21:14:01 ----SD---- C:\WINDOWS\Tasks
2010-04-27 21:13:58 ----RD---- C:\Program Files
2010-04-26 22:36:41 ----D---- C:\WINDOWS\Registration
2010-04-24 09:31:12 ----HD---- C:\WINDOWS\inf
2010-04-20 20:11:20 ----SHD---- C:\WINDOWS\Installer
2010-04-20 20:11:19 ----D---- C:\WINDOWS\WinSxS
2010-04-19 20:11:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-19 20:09:57 ----D---- C:\WINDOWS\system32\CatRoot
2010-04-19 20:09:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-19 20:09:06 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-18 00:58:08 ----RSD---- C:\WINDOWS\Fonts
2010-04-18 00:57:56 ----D---- C:\WINDOWS\system32\spool
2010-04-18 00:56:06 ----D---- C:\WINDOWS\system32\mui
2010-04-18 00:56:06 ----D---- C:\Program Files\Internet Explorer
2010-04-15 20:35:58 ----D---- C:\WINDOWS\system
2010-04-15 19:49:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-04-15 19:45:10 ----A---- C:\WINDOWS\system32\guard32.dll
2010-04-15 19:33:57 ----D---- C:\WINDOWS\Help
2010-04-15 19:33:17 ----D---- C:\Program Files\NVIDIA Corporation
2010-04-15 19:33:06 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-04-14 21:39:32 ----D---- C:\WINDOWS\Debug
2010-04-13 23:41:53 ----D---- C:\WINDOWS\ie8updates
2010-04-13 23:37:46 ----D---- C:\WINDOWS\repair
2010-04-13 21:04:34 ----D---- C:\WINDOWS\system32\config
2010-04-11 19:21:01 ----D---- C:\Program Files\Microsoft IntelliPoint
2010-04-09 00:15:16 ----D---- C:\WINDOWS\system32\QuickTime
2010-04-08 22:33:12 ----D---- C:\WINDOWS\twain_32
2010-04-07 23:34:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-04-07 22:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-05 10:13:43 ----D---- C:\WINDOWS\Logs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2006-10-18 12664]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
R1 avgio;avgio; \??\I:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2010-04-15 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-04-15 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-04-15 25240]
R1 NVTCP;NVIDIA TCP/IP Protocol Driver; C:\WINDOWS\System32\DRIVERS\NVTcp.sys [2006-09-11 110592]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 psh_drv;Process Activity Acronis Monitor; C:\WINDOWS\system32\DRIVERS\psh_drv.sys [2009-05-05 98880]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-04 10232128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-09-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-09-11 19968]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-12-26 47360]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2006-11-08 21760]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2005-09-27 16000]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2009-09-11 22792]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2009-09-11 35592]
R3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2009-09-11 31752]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2009-09-11 66056]
S1 asusgsb;ASUS Virtual Video Capture Device Driver; C:\WINDOWS\system32\drivers\asusgsb32.sys [2005-10-20 12416]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Rodina\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 TF1D091000SER;TF1D091000SER USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\TF1D091000SER.sys [2008-01-08 99968]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2009-09-11 14984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-02-27 717296]
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-17 73344]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; I:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-19 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; I:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-09-04 241664]
R2 cmdAgent;COMODO Internet Security Helper Service; I:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-04-15 1769216]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2006-09-11 172032]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-04-13 20543]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2006-09-11 135227]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-09-11 65599]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 psh_svc;Acronis Malware Shield Service; C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; I:\Program Files\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-05-04 21:41:57
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (19%) free of 10 GB
Total RAM: 3070 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:26:19, on 13.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Rodina\Plocha\RSIT.exe
I:\Program Files\Trend Micro\HijackThis\Rodina.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - I:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - I:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O8 - Extra context menu item: &Download by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://I:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://I:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra 'Tools' menuitem: Acronis Blokování pop-up oken - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - I:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Acronis Malware Shield Service (psh_svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe
--
End of file - 7535 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Norton Security Scan for Rodina.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - I:\Program Files\Orbitdownloader\orbitcth.dll [2010-04-16 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - I:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E24AD748-155E-4254-B674-4EDF86E7E1DF}]
CAdBlocker Object - I:\Program Files\Acronis\PrivacyExpert\Blokování.dll [2006-04-18 788312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - I:\Program Files\Orbitdownloader\GrabPro.dll [2010-04-16 666816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"avgnt"=I:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"COMODO Internet Security"=I:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-04-15 2029456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"I:\Program Files\Orbitdownloader\orbitdm.exe"="I:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"I:\Program Files\Orbitdownloader\orbitnet.exe"="I:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
"I:\Program Files\Skype\Phone\Skype.exe"="I:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-05-04 21:41:57 ----D---- C:\rsit
2010-05-04 21:27:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-04 21:25:05 ----SHD---- C:\RECYCLER
2010-05-04 21:24:07 ----D---- C:\WINDOWS\temp
2010-04-28 20:30:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-04-27 21:16:12 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-04-27 21:13:58 ----D---- C:\Program Files\Norton Security Scan
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Symantec
2010-04-27 21:13:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2010-04-27 21:13:57 ----D---- C:\Program Files\NortonInstaller
2010-04-27 21:13:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\NortonInstaller
2010-04-21 20:40:11 ----A---- C:\WINDOWS\system32\h323log.txt
2010-04-21 00:07:32 ----D---- C:\VritualRoot
2010-04-20 22:43:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\F-Secure
2010-04-19 20:09:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-04-19 20:08:41 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2010-04-18 00:58:12 ----D---- C:\WINDOWS\system32\XPSViewer
2010-04-18 00:58:10 ----D---- C:\Program Files\MSBuild
2010-04-18 00:58:09 ----D---- C:\WINDOWS\system32\en-US
2010-04-18 00:58:04 ----D---- C:\Program Files\Reference Assemblies
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-04-18 00:57:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-04-18 00:54:41 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-04-18 00:54:37 ----D---- C:\Program Files\MSXML 6.0
2010-04-15 20:34:39 ----A---- C:\WINDOWS\Ascd_tmp.ini
2010-04-15 19:04:10 ----RSD---- C:\WINDOWS\assembly
2010-04-15 19:03:48 ----D---- C:\WINDOWS\Microsoft.NET
2010-04-13 23:52:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
2010-04-13 23:50:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\COMODO
2010-04-13 23:44:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-13 23:44:11 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-13 23:42:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-13 23:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-13 23:41:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-13 23:41:47 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 23:40:58 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2010-04-13 23:37:46 ----D---- C:\WINDOWS\system32\NtmsData
2010-04-13 23:33:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-04-11 11:50:56 ----A---- C:\Boot.bak
2010-04-11 11:50:51 ----RASHD---- C:\cmdcons
2010-04-11 00:18:05 ----SHD---- C:\WINDOWS\CSC
2010-04-09 23:42:52 ----A---- C:\WINDOWS\cavscan.INI
2010-04-09 23:10:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-04-08 23:58:07 ----A---- C:\WINDOWS\cfplogvw.INI
2010-04-08 22:56:57 ----A---- C:\WINDOWS\CIS_Setup_3.13.121240.574_XP_Vista_x32.INI
2010-04-08 01:31:59 ----A---- C:\WINDOWS\system32\RUNDLL32.EXE
2010-04-07 23:15:17 ----N---- C:\WINDOWS\system32\SVCHOST.EXE
2010-04-07 22:47:43 ----N---- C:\WINDOWS\explorer.exe
2010-04-07 02:44:20 ----N---- C:\WINDOWS\system32\services.exe
2010-04-06 20:50:01 ----RASH---- C:\boot.ini
======List of files/folders modified in the last 1 months======
2010-05-04 21:41:19 ----D---- C:\WINDOWS\Prefetch
2010-05-04 21:36:07 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-04 21:32:07 ----D---- C:\WINDOWS
2010-05-04 21:25:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-05-04 21:22:55 ----A---- C:\WINDOWS\system.ini
2010-05-04 21:22:20 ----D---- C:\WINDOWS\system32\drivers
2010-05-04 21:22:02 ----D---- C:\WINDOWS\system32
2010-05-04 21:22:02 ----D---- C:\WINDOWS\AppPatch
2010-05-04 21:22:01 ----D---- C:\Program Files\Common Files
2010-05-04 21:15:23 ----SHD---- C:\System Volume Information
2010-05-04 21:15:23 ----D---- C:\WINDOWS\system32\Restore
2010-05-03 00:19:59 ----D---- C:\downloads
2010-05-03 00:05:05 ----A---- C:\WINDOWS\NeroDigital.ini
2010-04-27 21:14:01 ----SD---- C:\WINDOWS\Tasks
2010-04-27 21:13:58 ----RD---- C:\Program Files
2010-04-26 22:36:41 ----D---- C:\WINDOWS\Registration
2010-04-24 09:31:12 ----HD---- C:\WINDOWS\inf
2010-04-20 20:11:20 ----SHD---- C:\WINDOWS\Installer
2010-04-20 20:11:19 ----D---- C:\WINDOWS\WinSxS
2010-04-19 20:11:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-19 20:09:57 ----D---- C:\WINDOWS\system32\CatRoot
2010-04-19 20:09:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-19 20:09:06 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-18 00:58:08 ----RSD---- C:\WINDOWS\Fonts
2010-04-18 00:57:56 ----D---- C:\WINDOWS\system32\spool
2010-04-18 00:56:06 ----D---- C:\WINDOWS\system32\mui
2010-04-18 00:56:06 ----D---- C:\Program Files\Internet Explorer
2010-04-15 20:35:58 ----D---- C:\WINDOWS\system
2010-04-15 19:49:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-04-15 19:45:10 ----A---- C:\WINDOWS\system32\guard32.dll
2010-04-15 19:33:57 ----D---- C:\WINDOWS\Help
2010-04-15 19:33:17 ----D---- C:\Program Files\NVIDIA Corporation
2010-04-15 19:33:06 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-04-14 21:39:32 ----D---- C:\WINDOWS\Debug
2010-04-13 23:41:53 ----D---- C:\WINDOWS\ie8updates
2010-04-13 23:37:46 ----D---- C:\WINDOWS\repair
2010-04-13 21:04:34 ----D---- C:\WINDOWS\system32\config
2010-04-11 19:21:01 ----D---- C:\Program Files\Microsoft IntelliPoint
2010-04-09 00:15:16 ----D---- C:\WINDOWS\system32\QuickTime
2010-04-08 22:33:12 ----D---- C:\WINDOWS\twain_32
2010-04-07 23:34:14 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-04-07 22:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-05 10:13:43 ----D---- C:\WINDOWS\Logs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2006-10-18 12664]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
R1 avgio;avgio; \??\I:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2010-04-15 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-04-15 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-04-15 25240]
R1 NVTCP;NVIDIA TCP/IP Protocol Driver; C:\WINDOWS\System32\DRIVERS\NVTcp.sys [2006-09-11 110592]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 psh_drv;Process Activity Acronis Monitor; C:\WINDOWS\system32\DRIVERS\psh_drv.sys [2009-05-05 98880]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-04 10232128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-09-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-09-11 19968]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-12-26 47360]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2006-11-08 21760]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2005-09-27 16000]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2009-09-11 22792]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2009-09-11 35592]
R3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2009-09-11 31752]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2009-09-11 66056]
S1 asusgsb;ASUS Virtual Video Capture Device Driver; C:\WINDOWS\system32\drivers\asusgsb32.sys [2005-10-20 12416]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\Rodina\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 TF1D091000SER;TF1D091000SER USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\TF1D091000SER.sys [2008-01-08 99968]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2009-09-11 14984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-02-27 717296]
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-17 73344]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; I:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-19 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; I:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-09-04 241664]
R2 cmdAgent;COMODO Internet Security Helper Service; I:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-04-15 1769216]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2006-09-11 172032]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-04-13 20543]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2006-09-11 135227]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-09-11 65599]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 psh_svc;Acronis Malware Shield Service; C:\Program Files\Common Files\Acronis\Ochranný štít\psh_svc.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; I:\Program Files\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------