
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu - zablokovaná lišta
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu logu - zablokovaná lišta
Po spuštění Windows se mi pokaždé zablokuje lišta - když na ni najedu myší, zobrazí se přesýpací hodiny (trvá to asi 5 min).
Logfile of random's system information tool 1.07 (written by random/random)
Run by Lukáš at 2010-05-13 21:49:58
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 5 GB (9%) free of 61 GB
Total RAM: 1023 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:50:05, on 13.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Antiviry\Avast5\AvastSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Antiviry\Avast5\avastUI.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Správa\OO Software\Defrag\oodag.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Prohlížeče\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
C:\Program Files\trend micro\Lukáš.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NetBeansBHO - {25CE9541-A839-46B4-81C6-1FAE46AD2EDE} - C:\Program Files\Editory\NetBeans 6.8\webcommon1\native\NetBeansExtension.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\Antiviry\Avast5\avastUI.exe /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\Download\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\Download\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\Komunikace\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\Komunikace\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://software.kuaiche.com
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apache2.2 - Apache Software Foundation - C:\dev\prog\apache\bin\httpd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Antiviry\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Antiviry\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Antiviry\Avast5\AvastSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: MySQL - Unknown owner - C:\dev\prog\mysql\bin\mysqld (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\CD a DVD\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Ethernet Packet Service (npacketservice) - Nokia - C:\WINDOWS\system32\npacketsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\Správa\OO Software\Defrag\oodag.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7391 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CE9541-A839-46B4-81C6-1FAE46AD2EDE}]
NetBeans Extension Class - C:\Program Files\Editory\NetBeans 6.8\webcommon1\native\NetBeansExtension.dll [2010-01-01 316928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-12 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-08-12 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\PROGRA~1\Antiviry\Avast5\avastUI.exe [2010-05-06 2815192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Komunikace\ICQ6.5\ICQ.exe"="C:\Program Files\Komunikace\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\dev\prog\apache\bin\httpd.exe"="C:\dev\prog\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\hry\TrackmaniaNationsForever\TmForever.exe"="C:\Program Files\hry\TrackmaniaNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Práce se soubory\Total Commander\TOTALCMD.EXE"="C:\Program Files\Práce se soubory\Total Commander\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Editory\NetBeans 6.8\bin\netbeans.exe"="C:\Program Files\Editory\NetBeans 6.8\bin\netbeans.exe:*:Enabled:netbeans"
"C:\Program Files\Prohlížeče\Opera\opera.exe"="C:\Program Files\Prohlížeče\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Přehrávače\VLC\vlc.exe"="C:\Program Files\Přehrávače\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Komunikace\Skype\Phone\Skype.exe"="C:\Program Files\Komunikace\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-05-13 21:49:58 ----D---- C:\rsit
2010-05-13 21:49:58 ----D---- C:\Program Files\trend micro
2010-05-13 17:44:11 ----A---- C:\ComboFix.txt
2010-05-13 17:22:47 ----A---- C:\Boot.bak
2010-05-13 17:22:42 ----RASHD---- C:\cmdcons
2010-05-13 15:14:30 ----A---- C:\WINDOWS\zip.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\SWSC.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\SWREG.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\sed.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\PEV.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\NIRCMD.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\MBR.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\grep.exe
2010-05-13 15:14:23 ----D---- C:\WINDOWS\ERDNT
2010-05-13 15:11:37 ----D---- C:\Qoobox
2010-05-12 21:47:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-11 20:30:36 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-05-11 20:30:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-05-09 17:52:56 ----A---- C:\WINDOWS\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2010-05-09 17:52:15 ----A---- C:\WINDOWS\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2010-05-09 17:50:12 ----D---- C:\WINDOWS\system32\RsFx
2010-05-09 17:47:44 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft Corporation
2010-05-09 17:32:59 ----D---- C:\Program Files\Microsoft Synchronization Services
2010-05-09 17:32:58 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-05-09 17:29:28 ----D---- C:\WINDOWS\symbols
2010-05-09 17:29:23 ----D---- C:\Program Files\Microsoft Help Viewer
2010-05-09 17:29:22 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2010-05-09 17:24:02 ----HDC---- C:\WINDOWS\$NtUninstallKB958655-v2$
2010-05-09 17:23:25 ----HDC---- C:\WINDOWS\$NtUninstallKB942288-v3$
2010-05-08 23:42:10 ----HD---- C:\Program Files\Zero G Registry
2010-05-08 20:34:35 ----D---- C:\Program Files\Perl
2010-04-27 22:14:27 ----A---- C:\WINDOWS\IE4 Error Log.txt
2010-04-27 21:14:24 ----D---- C:\Program Files\Antiviry
2010-04-27 20:58:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-04-24 23:52:16 ----A---- C:\WINDOWS\system32\npacketsvc.exe
2010-04-24 23:52:16 ----A---- C:\WINDOWS\system32\npacketmsg.dll
2010-04-24 23:52:16 ----A---- C:\WINDOWS\system32\npacket.dll
2010-04-24 23:49:07 ----A---- C:\WINDOWS\system32\npacketadmin.exe
2010-04-15 16:46:57 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 16:46:49 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 16:43:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 16:43:14 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 17:41:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 17:41:24 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
======List of files/folders modified in the last 1 months======
2010-05-13 21:49:58 ----RD---- C:\Program Files
2010-05-13 21:49:36 ----SHD---- C:\WINDOWS\Installer
2010-05-13 21:49:36 ----D---- C:\Config.Msi
2010-05-13 21:36:59 ----D---- C:\WINDOWS\system32\oodag
2010-05-13 21:36:41 ----D---- C:\WINDOWS\Temp
2010-05-13 21:34:38 ----D---- C:\Program Files\Common Files
2010-05-13 17:45:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-13 17:45:42 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-13 17:44:13 ----D---- C:\WINDOWS\system32\drivers
2010-05-13 17:43:04 ----SD---- C:\WINDOWS\Tasks
2010-05-13 17:35:03 ----D---- C:\WINDOWS
2010-05-13 17:35:03 ----A---- C:\WINDOWS\system.ini
2010-05-13 17:33:04 ----D---- C:\WINDOWS\system32\config
2010-05-13 17:31:30 ----D---- C:\WINDOWS\system32
2010-05-13 17:28:46 ----D---- C:\WINDOWS\network diagnostic
2010-05-13 17:27:15 ----D---- C:\WINDOWS\AppPatch
2010-05-13 17:22:47 ----RASH---- C:\boot.ini
2010-05-12 21:47:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-05-12 21:47:10 ----D---- C:\WINDOWS\inf
2010-05-12 21:47:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-12 21:47:08 ----D---- C:\Program Files\Outlook Express
2010-05-12 21:44:22 ----RSD---- C:\WINDOWS\assembly
2010-05-12 21:42:06 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-12 19:54:23 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-11 23:04:18 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-11 20:30:46 ----D---- C:\WINDOWS\WinSxS
2010-05-09 17:52:57 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-09 17:50:33 ----D---- C:\Program Files\Microsoft SQL Server
2010-05-09 17:48:19 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-09 17:48:07 ----D---- C:\WINDOWS\system32\1033
2010-05-09 17:47:53 ----D---- C:\Program Files\Microsoft.NET
2010-05-09 17:41:06 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-05-09 17:29:23 ----D---- C:\Program Files\MSBuild
2010-05-09 17:24:21 ----A---- C:\WINDOWS\imsins.BAK
2010-05-09 17:06:45 ----D---- C:\Program Files\Common Files\InstallShield
2010-05-09 17:01:18 ----D---- C:\Documents and Settings
2010-05-08 23:42:01 ----D---- C:\dev
2010-05-08 23:41:57 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-08 20:37:32 ----D---- C:\WINDOWS\Prefetch
2010-05-08 20:31:26 ----SD---- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft
2010-05-08 15:20:45 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\vlc
2010-05-05 16:00:03 ----D---- C:\WINDOWS\system32\Restore
2010-05-02 16:55:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\FLEXnet
2010-04-30 20:51:06 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-28 15:48:31 ----D---- C:\WINDOWS\SxsCaPendDel
2010-04-27 21:10:27 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-04-22 18:03:34 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\dvdcss
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-05-06 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-05-06 164048]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-05-06 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-05-06 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-05-06 100432]
R3 ALCXWDM;Service for Avance AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2002-07-23 659356]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-05-06 23376]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 npacketdriver;Ethernet Packet Driver; C:\WINDOWS\system32\drivers\npacket.sys [2004-02-13 20244]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2008-08-01 25216]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-14 26112]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 RsFx0103;RsFx0103 Driver; C:\WINDOWS\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Antiviry\Avast5\AvastSvc.exe [2010-05-06 40384]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-08-12 153376]
R2 O&O Defrag;O&O Defrag; C:\Program Files\Správa\OO Software\Defrag\oodag.exe [2009-09-12 1488128]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 SimpTcp;Jednoduché služby TCP/IP; C:\WINDOWS\System32\tcpsvcs.exe [2002-09-23 19456]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-05-03 520192]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe []
S3 Apache2.2;Apache2.2; C:\dev\prog\apache\bin\httpd.exe [2009-08-06 24645]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Antiviry\Avast5\AvastSvc.exe [2010-05-06 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Antiviry\Avast5\AvastSvc.exe [2010-05-06 40384]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-09-16 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
S3 MySQL;MySQL; C:\dev\prog\mysql\bin\mysqld --defaults-file=C:\dev\prog\mysql\my.ini MySQL []
S3 NBService;NBService; C:\Program Files\CD a DVD\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
S3 npacketservice;Ethernet Packet Service; C:\WINDOWS\system32\npacketsvc.exe [2004-10-26 61440]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 p2pgasvc;Ověřování v síti skupiny rovnocenných počítačů; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 p2pimsvc;Správce identit sítě rovnocenných počítačů; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 p2psvc;Síť rovnocenných počítačů; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 PNRPSvc;Protokol PNRP; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
-----------------EOF-----------------
Logfile of random's system information tool 1.07 (written by random/random)
Run by Lukáš at 2010-05-13 21:49:58
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 5 GB (9%) free of 61 GB
Total RAM: 1023 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:50:05, on 13.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Antiviry\Avast5\AvastSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Antiviry\Avast5\avastUI.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Správa\OO Software\Defrag\oodag.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Prohlížeče\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
C:\Program Files\trend micro\Lukáš.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NetBeansBHO - {25CE9541-A839-46B4-81C6-1FAE46AD2EDE} - C:\Program Files\Editory\NetBeans 6.8\webcommon1\native\NetBeansExtension.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\Antiviry\Avast5\avastUI.exe /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\Download\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\Download\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\Komunikace\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\Komunikace\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://software.kuaiche.com
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apache2.2 - Apache Software Foundation - C:\dev\prog\apache\bin\httpd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Antiviry\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Antiviry\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Antiviry\Avast5\AvastSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: MySQL - Unknown owner - C:\dev\prog\mysql\bin\mysqld (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\CD a DVD\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Ethernet Packet Service (npacketservice) - Nokia - C:\WINDOWS\system32\npacketsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\Správa\OO Software\Defrag\oodag.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7391 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CE9541-A839-46B4-81C6-1FAE46AD2EDE}]
NetBeans Extension Class - C:\Program Files\Editory\NetBeans 6.8\webcommon1\native\NetBeansExtension.dll [2010-01-01 316928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-12 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-08-12 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast5"=C:\PROGRA~1\Antiviry\Avast5\avastUI.exe [2010-05-06 2815192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Komunikace\ICQ6.5\ICQ.exe"="C:\Program Files\Komunikace\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\dev\prog\apache\bin\httpd.exe"="C:\dev\prog\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\hry\TrackmaniaNationsForever\TmForever.exe"="C:\Program Files\hry\TrackmaniaNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Práce se soubory\Total Commander\TOTALCMD.EXE"="C:\Program Files\Práce se soubory\Total Commander\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Editory\NetBeans 6.8\bin\netbeans.exe"="C:\Program Files\Editory\NetBeans 6.8\bin\netbeans.exe:*:Enabled:netbeans"
"C:\Program Files\Prohlížeče\Opera\opera.exe"="C:\Program Files\Prohlížeče\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Přehrávače\VLC\vlc.exe"="C:\Program Files\Přehrávače\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Komunikace\Skype\Phone\Skype.exe"="C:\Program Files\Komunikace\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-05-13 21:49:58 ----D---- C:\rsit
2010-05-13 21:49:58 ----D---- C:\Program Files\trend micro
2010-05-13 17:44:11 ----A---- C:\ComboFix.txt
2010-05-13 17:22:47 ----A---- C:\Boot.bak
2010-05-13 17:22:42 ----RASHD---- C:\cmdcons
2010-05-13 15:14:30 ----A---- C:\WINDOWS\zip.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\SWSC.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\SWREG.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\sed.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\PEV.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\NIRCMD.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\MBR.exe
2010-05-13 15:14:30 ----A---- C:\WINDOWS\grep.exe
2010-05-13 15:14:23 ----D---- C:\WINDOWS\ERDNT
2010-05-13 15:11:37 ----D---- C:\Qoobox
2010-05-12 21:47:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-11 20:30:36 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-05-11 20:30:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-05-09 17:52:56 ----A---- C:\WINDOWS\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2010-05-09 17:52:15 ----A---- C:\WINDOWS\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2010-05-09 17:50:12 ----D---- C:\WINDOWS\system32\RsFx
2010-05-09 17:47:44 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft Corporation
2010-05-09 17:32:59 ----D---- C:\Program Files\Microsoft Synchronization Services
2010-05-09 17:32:58 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-05-09 17:29:28 ----D---- C:\WINDOWS\symbols
2010-05-09 17:29:23 ----D---- C:\Program Files\Microsoft Help Viewer
2010-05-09 17:29:22 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2010-05-09 17:24:02 ----HDC---- C:\WINDOWS\$NtUninstallKB958655-v2$
2010-05-09 17:23:25 ----HDC---- C:\WINDOWS\$NtUninstallKB942288-v3$
2010-05-08 23:42:10 ----HD---- C:\Program Files\Zero G Registry
2010-05-08 20:34:35 ----D---- C:\Program Files\Perl
2010-04-27 22:14:27 ----A---- C:\WINDOWS\IE4 Error Log.txt
2010-04-27 21:14:24 ----D---- C:\Program Files\Antiviry
2010-04-27 20:58:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-04-24 23:52:16 ----A---- C:\WINDOWS\system32\npacketsvc.exe
2010-04-24 23:52:16 ----A---- C:\WINDOWS\system32\npacketmsg.dll
2010-04-24 23:52:16 ----A---- C:\WINDOWS\system32\npacket.dll
2010-04-24 23:49:07 ----A---- C:\WINDOWS\system32\npacketadmin.exe
2010-04-15 16:46:57 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 16:46:49 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 16:43:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 16:43:14 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 17:41:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 17:41:24 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
======List of files/folders modified in the last 1 months======
2010-05-13 21:49:58 ----RD---- C:\Program Files
2010-05-13 21:49:36 ----SHD---- C:\WINDOWS\Installer
2010-05-13 21:49:36 ----D---- C:\Config.Msi
2010-05-13 21:36:59 ----D---- C:\WINDOWS\system32\oodag
2010-05-13 21:36:41 ----D---- C:\WINDOWS\Temp
2010-05-13 21:34:38 ----D---- C:\Program Files\Common Files
2010-05-13 17:45:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-13 17:45:42 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-13 17:44:13 ----D---- C:\WINDOWS\system32\drivers
2010-05-13 17:43:04 ----SD---- C:\WINDOWS\Tasks
2010-05-13 17:35:03 ----D---- C:\WINDOWS
2010-05-13 17:35:03 ----A---- C:\WINDOWS\system.ini
2010-05-13 17:33:04 ----D---- C:\WINDOWS\system32\config
2010-05-13 17:31:30 ----D---- C:\WINDOWS\system32
2010-05-13 17:28:46 ----D---- C:\WINDOWS\network diagnostic
2010-05-13 17:27:15 ----D---- C:\WINDOWS\AppPatch
2010-05-13 17:22:47 ----RASH---- C:\boot.ini
2010-05-12 21:47:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-05-12 21:47:10 ----D---- C:\WINDOWS\inf
2010-05-12 21:47:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-12 21:47:08 ----D---- C:\Program Files\Outlook Express
2010-05-12 21:44:22 ----RSD---- C:\WINDOWS\assembly
2010-05-12 21:42:06 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-12 19:54:23 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-11 23:04:18 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-11 20:30:46 ----D---- C:\WINDOWS\WinSxS
2010-05-09 17:52:57 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-09 17:50:33 ----D---- C:\Program Files\Microsoft SQL Server
2010-05-09 17:48:19 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-09 17:48:07 ----D---- C:\WINDOWS\system32\1033
2010-05-09 17:47:53 ----D---- C:\Program Files\Microsoft.NET
2010-05-09 17:41:06 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-05-09 17:29:23 ----D---- C:\Program Files\MSBuild
2010-05-09 17:24:21 ----A---- C:\WINDOWS\imsins.BAK
2010-05-09 17:06:45 ----D---- C:\Program Files\Common Files\InstallShield
2010-05-09 17:01:18 ----D---- C:\Documents and Settings
2010-05-08 23:42:01 ----D---- C:\dev
2010-05-08 23:41:57 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-08 20:37:32 ----D---- C:\WINDOWS\Prefetch
2010-05-08 20:31:26 ----SD---- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft
2010-05-08 15:20:45 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\vlc
2010-05-05 16:00:03 ----D---- C:\WINDOWS\system32\Restore
2010-05-02 16:55:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\FLEXnet
2010-04-30 20:51:06 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-28 15:48:31 ----D---- C:\WINDOWS\SxsCaPendDel
2010-04-27 21:10:27 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-04-22 18:03:34 ----D---- C:\Documents and Settings\Lukáš\Data aplikací\dvdcss
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-05-06 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-05-06 164048]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-05-06 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-05-06 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-05-06 100432]
R3 ALCXWDM;Service for Avance AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2002-07-23 659356]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-05-06 23376]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 npacketdriver;Ethernet Packet Driver; C:\WINDOWS\system32\drivers\npacket.sys [2004-02-13 20244]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2008-08-01 25216]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-14 26112]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 RsFx0103;RsFx0103 Driver; C:\WINDOWS\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Antiviry\Avast5\AvastSvc.exe [2010-05-06 40384]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-08-12 153376]
R2 O&O Defrag;O&O Defrag; C:\Program Files\Správa\OO Software\Defrag\oodag.exe [2009-09-12 1488128]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 SimpTcp;Jednoduché služby TCP/IP; C:\WINDOWS\System32\tcpsvcs.exe [2002-09-23 19456]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-05-03 520192]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe []
S3 Apache2.2;Apache2.2; C:\dev\prog\apache\bin\httpd.exe [2009-08-06 24645]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Antiviry\Avast5\AvastSvc.exe [2010-05-06 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Antiviry\Avast5\AvastSvc.exe [2010-05-06 40384]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-09-16 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
S3 MySQL;MySQL; C:\dev\prog\mysql\bin\mysqld --defaults-file=C:\dev\prog\mysql\my.ini MySQL []
S3 NBService;NBService; C:\Program Files\CD a DVD\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
S3 npacketservice;Ethernet Packet Service; C:\WINDOWS\system32\npacketsvc.exe [2004-10-26 61440]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 p2pgasvc;Ověřování v síti skupiny rovnocenných počítačů; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 p2pimsvc;Správce identit sítě rovnocenných počítačů; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 p2psvc;Síť rovnocenných počítačů; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 PNRPSvc;Protokol PNRP; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
-----------------EOF-----------------
- 1danab
- Nováček
- Příspěvky: 1412
- Registrován: 21 říj 2007 13:04
- Bydliště: České Budějovice
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu - zablokovaná lišta
zdravím
vidím, že jste dnes aplikoval Combofix...poprosím Vás o vložení logu

vidím, že jste dnes aplikoval Combofix...poprosím Vás o vložení logu
Re: Prosím o kontrolu logu - zablokovaná lišta
ComboFix 10-05-12.06 - Lukáš 13.05.2010 17:25:04.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.565 [GMT 2:00]
Spuštěný z: c:\documents and settings\Lukáš\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\secustat.dat
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-13 do 2010-05-13 )))))))))))))))))))))))))))))))
.
2010-05-11 18:31 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-11 18:31 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-11 18:31 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-11 18:31 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-11 18:31 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-11 18:31 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-11 18:31 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-11 18:30 . 2010-05-06 20:59 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-11 18:30 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-09 15:52 . 2009-07-23 03:08 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2010-05-09 15:52 . 2009-07-23 03:08 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2010-05-09 15:50 . 2010-05-09 15:50 -------- d-----w- c:\windows\system32\RsFx
2010-05-09 15:32 . 2010-05-09 15:32 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-05-09 15:32 . 2010-05-09 15:32 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-05-09 15:29 . 2010-05-09 15:29 -------- d-----w- c:\windows\symbols
2010-05-09 15:29 . 2010-05-09 15:29 -------- d-----w- c:\program files\Microsoft Help Viewer
2010-05-09 15:29 . 2010-05-09 15:56 -------- d-----w- c:\program files\Microsoft Visual Studio 10.0
2010-05-08 21:42 . 2010-05-09 15:01 -------- d--h--w- c:\program files\Zero G Registry
2010-05-08 18:34 . 2010-05-08 19:45 -------- d-----w- c:\program files\Perl
2010-04-27 19:14 . 2010-05-11 18:30 -------- d-----w- c:\program files\Antiviry
2010-04-27 19:05 . 2010-04-27 19:05 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-04-24 21:52 . 2004-10-26 11:43 61440 ----a-w- c:\windows\system32\npacketsvc.exe
2010-04-24 21:52 . 2004-02-17 08:25 12288 ----a-w- c:\windows\system32\npacketmsg.dll
2010-04-24 21:52 . 2004-02-13 10:36 20244 ----a-w- c:\windows\system32\drivers\npacket.sys
2010-04-24 21:52 . 2004-02-13 10:36 73728 ----a-w- c:\windows\system32\npacket.dll
2010-04-24 21:49 . 2004-02-13 10:36 90112 ----a-w- c:\windows\system32\npacketadmin.exe
2010-04-24 21:49 . 2010-05-09 15:05 -------- d-----w- c:\program files\Common Files\Symbian
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-09 15:52 . 2002-09-23 10:00 556370 ----a-w- c:\windows\system32\perfh005.dat
2010-05-09 15:52 . 2002-09-23 10:00 122968 ----a-w- c:\windows\system32\perfc005.dat
2010-05-09 15:50 . 2010-02-08 19:01 -------- d-----w- c:\program files\Microsoft SQL Server
2010-05-09 15:47 . 2009-08-12 15:29 -------- d-----w- c:\program files\Microsoft.NET
2010-05-09 15:29 . 2009-08-12 12:37 -------- d-----w- c:\program files\MSBuild
2010-05-09 15:06 . 2009-08-12 11:46 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-08 21:41 . 2009-08-12 11:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-09 12:18 . 2009-08-14 16:16 -------- d-----w- c:\program files\Download
2010-03-29 20:54 . 2009-08-12 19:34 -------- d-----w- c:\program files\Editory
2010-03-28 13:28 . 2010-03-28 13:28 -------- d-----w- c:\program files\Návody
2010-03-20 19:46 . 2010-03-20 19:46 -------- d-----w- c:\program files\lcc
2010-03-18 14:47 . 2010-03-18 14:47 17760 ----a-w- c:\windows\system32\aspnet_counters.dll
2010-03-18 11:16 . 2010-03-18 11:16 771424 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2010-03-18 11:16 . 2010-03-18 11:16 70472 ----a-w- c:\windows\system32\dxva2.dll
2010-03-18 11:16 . 2010-03-18 11:16 486216 ----a-w- c:\windows\system32\evr.dll
2010-03-18 08:09 . 2010-03-18 08:09 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-18 08:09 . 2010-03-18 08:09 49488 ----a-w- c:\windows\system32\netfxperf.dll
2010-03-18 08:09 . 2010-03-18 08:09 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-03-18 08:09 . 2010-03-18 08:09 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-03-18 07:15 . 2010-03-18 07:15 80720 ----a-w- c:\windows\system32\mfcm100u.dll
2010-03-18 07:15 . 2010-03-18 07:15 80208 ----a-w- c:\windows\system32\mfcm100.dll
2010-03-18 07:15 . 2010-03-18 07:15 770384 ----a-w- c:\windows\system32\msvcr100.dll
2010-03-18 07:15 . 2010-03-18 07:15 743248 ----a-w- c:\windows\system32\msvcp100d.dll
2010-03-18 07:15 . 2010-03-18 07:15 4368720 ----a-w- c:\windows\system32\mfc100u.dll
2010-03-18 07:15 . 2010-03-18 07:15 4342088 ----a-w- c:\windows\system32\mfc100.dll
2010-03-18 07:15 . 2010-03-18 07:15 421200 ----a-w- c:\windows\system32\msvcp100.dll
2010-03-18 07:15 . 2010-03-18 07:15 1498960 ----a-w- c:\windows\system32\msvcr100d.dll
2010-03-18 07:15 . 2010-03-18 07:15 138056 ----a-w- c:\windows\system32\atl100.dll
2010-03-10 06:17 . 2002-09-23 10:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-05 11:07 . 2010-03-05 11:00 598 ----a-w- c:\windows\system32\secushr.dat
2010-02-25 06:18 . 2002-09-23 10:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-09-23 10:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:09 . 2002-09-23 10:00 2192128 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:09 . 2002-09-20 17:12 2068992 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-14 12:05 . 2010-02-14 12:05 234336 ----a-w- c:\windows\system32\SqlServerSpatial.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\Antiviry\Avast5\avastUI.exe" [2010-05-06 2815192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Komunikace\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\dev\\prog\\apache\\bin\\httpd.exe"=
"c:\\Program Files\\hry\\TrackmaniaNationsForever\\TmForever.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Práce se soubory\\Total Commander\\TOTALCMD.EXE"=
"c:\\Program Files\\Editory\\NetBeans 6.8\\bin\\netbeans.exe"=
"c:\\Program Files\\Prohlížeče\\Opera\\opera.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Přehrávače\\VLC\\vlc.exe"=
"c:\\Program Files\\Komunikace\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Skupiny sítě Peer-to-Peer
"3540:UDP"= 3540:UDP:Protokol PNRP (Peer Name Resolution Protocol)
"5353:TCP"= 5353:TCP:Adobe CSI CS4
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.5.2010 20:31 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.5.2010 20:31 19024]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 Apache2.2;Apache2.2;c:\dev\prog\apache\bin\httpd.exe [6.8.2009 15:50 24645]
S3 npacketdriver;Ethernet Packet Driver;c:\windows\system32\drivers\npacket.sys [24.4.2010 23:52 20244]
S3 npacketservice;Ethernet Packet Service;c:\windows\system32\npacketsvc.exe [24.4.2010 23:52 61440]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [23.7.2009 5:08 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [30.3.2009 3:09 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30.3.2009 3:23 366936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
Trusted Zone: kuaiche.com\software
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\lukas.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\lukas.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\lukas.default\extensions\info@lingea.com\components\LG_Mozilla2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-13 17:37
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\dev\prog\mysql\bin\mysqld\" --defaults-file=\"c:\dev\prog\mysql\my.ini\" MySQL"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="CE6B3168D878688691E833708D88E356FDB2D32BD08A893DB287F0221A5DE32842A28B483143DC373D91B42B9F89576C0FA15331753696FB2A5C2D67DECB761C870D4EDE881F766EECDCB79E55B28FF28EFEDB1DDD30DB967A6C74D34B67143E5429A15BF7615276E3A2D69864042D27EB1A9F7E7D4222D7DD9F2E58AF60C80A5398BD2EC946E01DD8DD40AB3662A7448B67E027FA9982908803D1288ECCF302A2A1728B016BE6B4F7AE39AE6993480F467FF830B0C46C139C49ED3C2126492AD3AD21ED50D2FD11DFD597BACEC3AC4E671C54F22C3A23B8B444FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DFEBC9E127BECC74CBA7FD869164D67942D98E55B86C17509DCA7E5B9181E57EA50E05BF04E14B0338CE63FE7697C1D859C20D208B3E2B9E38E349D2F2C8808E1469DC8B1FC7DB5EF1D443B6CC1C79D3A522F9469A595AA8C4CBFF011C5870653A704FA6BEF880DA09911CF76232FA3CA9DF7B602F1B74F95FABB272A218A216C0EE514D4A7D375296F231C43F3A37DF762F1753902AC9EB891E038ABCB061F7DA65E6C0578831F15239276F66A9A66A317D643DA955A05D09DAAD42AA9F039FCB147107B89C13191C83DE595938F1455C624C495BBACE1DD3F565E1D70C69C8385C0BD9757BA45EF8BC3A78B527DACB6919C53FCDB1009032BE8EBE12B8668CC0DB06820301FE926A98B2C2759694B182A457C892FF94409A8A74838393535BA413E39BEB8A321CEF4BC179832D5FD6CD86A0315435FCC5C159F71444C5A885137550A006900E0285546C3793ACD49C8F798DA5F7BBAD50CDE9E1B8EEC01613A9327EB558D7213134358BA42A1DEA469F5222E8D8B0C80CC0CB8A905743930438D262193C4BA1517CDE7BF516D1B78ADD81D5B24FD54E6F4344439F59196D9DA740C22F5029DB9DB172FC5E9F417A61735E3F211319B938184DC989748B0389829D499998FE2473055A976B1E7ED804E3715BA22566B87123C6248816E229733A03FE7FD8659F606D2992C3344BBCC1C9D932C8BF2D2B6EB2F7601AEAE8CB809E4509F0AD74F77746E057A5D6023C771BD02F4E4E1E40974C6022C028792D19A91500986469A6A339933230363C821607CCEF528CFB75A397E2E69BE4DDB8A8BD94C2021EB146622DA3120D8CCD7F89ED5A546B63F67FA6AE7EB0A0DA51480A6029293EB32987441CCD19DF9EAFDE8895AF82ED28510AEDA26ED94798BEA4458E239C6DADA0893B89C2AFBE5E3EAFA1EAB7FAAA34BD62D82F12AC4744E145C31E9965149F7C6B5518E91D0FCAF552F0082B3EDB59160A37E175C07D20FC640E51AC70072F03EBF77772763081C7877F528525E7727D8318DF584014CC5BF5ECF862D507904DA"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1604)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Antiviry\Avast5\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Správa\OO Software\Defrag\oodag.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\System32\tcpsvcs.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
.
**************************************************************************
.
Celkový čas: 2010-05-13 17:44:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-05-13 15:44
Před spuštěním: 4 184 199 168
Po spuštění: 5 423 386 624
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
- - End Of File - - F7C2ADF141B31E47015B7E660FF8B536
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.565 [GMT 2:00]
Spuštěný z: c:\documents and settings\Lukáš\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\secustat.dat
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-13 do 2010-05-13 )))))))))))))))))))))))))))))))
.
2010-05-11 18:31 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-11 18:31 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-11 18:31 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-11 18:31 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-11 18:31 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-11 18:31 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-11 18:31 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-11 18:30 . 2010-05-06 20:59 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-11 18:30 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-09 15:52 . 2009-07-23 03:08 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
2010-05-09 15:52 . 2009-07-23 03:08 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll
2010-05-09 15:50 . 2010-05-09 15:50 -------- d-----w- c:\windows\system32\RsFx
2010-05-09 15:32 . 2010-05-09 15:32 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-05-09 15:32 . 2010-05-09 15:32 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-05-09 15:29 . 2010-05-09 15:29 -------- d-----w- c:\windows\symbols
2010-05-09 15:29 . 2010-05-09 15:29 -------- d-----w- c:\program files\Microsoft Help Viewer
2010-05-09 15:29 . 2010-05-09 15:56 -------- d-----w- c:\program files\Microsoft Visual Studio 10.0
2010-05-08 21:42 . 2010-05-09 15:01 -------- d--h--w- c:\program files\Zero G Registry
2010-05-08 18:34 . 2010-05-08 19:45 -------- d-----w- c:\program files\Perl
2010-04-27 19:14 . 2010-05-11 18:30 -------- d-----w- c:\program files\Antiviry
2010-04-27 19:05 . 2010-04-27 19:05 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-04-24 21:52 . 2004-10-26 11:43 61440 ----a-w- c:\windows\system32\npacketsvc.exe
2010-04-24 21:52 . 2004-02-17 08:25 12288 ----a-w- c:\windows\system32\npacketmsg.dll
2010-04-24 21:52 . 2004-02-13 10:36 20244 ----a-w- c:\windows\system32\drivers\npacket.sys
2010-04-24 21:52 . 2004-02-13 10:36 73728 ----a-w- c:\windows\system32\npacket.dll
2010-04-24 21:49 . 2004-02-13 10:36 90112 ----a-w- c:\windows\system32\npacketadmin.exe
2010-04-24 21:49 . 2010-05-09 15:05 -------- d-----w- c:\program files\Common Files\Symbian
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-09 15:52 . 2002-09-23 10:00 556370 ----a-w- c:\windows\system32\perfh005.dat
2010-05-09 15:52 . 2002-09-23 10:00 122968 ----a-w- c:\windows\system32\perfc005.dat
2010-05-09 15:50 . 2010-02-08 19:01 -------- d-----w- c:\program files\Microsoft SQL Server
2010-05-09 15:47 . 2009-08-12 15:29 -------- d-----w- c:\program files\Microsoft.NET
2010-05-09 15:29 . 2009-08-12 12:37 -------- d-----w- c:\program files\MSBuild
2010-05-09 15:06 . 2009-08-12 11:46 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-08 21:41 . 2009-08-12 11:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-09 12:18 . 2009-08-14 16:16 -------- d-----w- c:\program files\Download
2010-03-29 20:54 . 2009-08-12 19:34 -------- d-----w- c:\program files\Editory
2010-03-28 13:28 . 2010-03-28 13:28 -------- d-----w- c:\program files\Návody
2010-03-20 19:46 . 2010-03-20 19:46 -------- d-----w- c:\program files\lcc
2010-03-18 14:47 . 2010-03-18 14:47 17760 ----a-w- c:\windows\system32\aspnet_counters.dll
2010-03-18 11:16 . 2010-03-18 11:16 771424 ----a-w- c:\windows\system32\msvcr100_clr0400.dll
2010-03-18 11:16 . 2010-03-18 11:16 70472 ----a-w- c:\windows\system32\dxva2.dll
2010-03-18 11:16 . 2010-03-18 11:16 486216 ----a-w- c:\windows\system32\evr.dll
2010-03-18 08:09 . 2010-03-18 08:09 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-18 08:09 . 2010-03-18 08:09 49488 ----a-w- c:\windows\system32\netfxperf.dll
2010-03-18 08:09 . 2010-03-18 08:09 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-03-18 08:09 . 2010-03-18 08:09 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-03-18 07:15 . 2010-03-18 07:15 80720 ----a-w- c:\windows\system32\mfcm100u.dll
2010-03-18 07:15 . 2010-03-18 07:15 80208 ----a-w- c:\windows\system32\mfcm100.dll
2010-03-18 07:15 . 2010-03-18 07:15 770384 ----a-w- c:\windows\system32\msvcr100.dll
2010-03-18 07:15 . 2010-03-18 07:15 743248 ----a-w- c:\windows\system32\msvcp100d.dll
2010-03-18 07:15 . 2010-03-18 07:15 4368720 ----a-w- c:\windows\system32\mfc100u.dll
2010-03-18 07:15 . 2010-03-18 07:15 4342088 ----a-w- c:\windows\system32\mfc100.dll
2010-03-18 07:15 . 2010-03-18 07:15 421200 ----a-w- c:\windows\system32\msvcp100.dll
2010-03-18 07:15 . 2010-03-18 07:15 1498960 ----a-w- c:\windows\system32\msvcr100d.dll
2010-03-18 07:15 . 2010-03-18 07:15 138056 ----a-w- c:\windows\system32\atl100.dll
2010-03-10 06:17 . 2002-09-23 10:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-05 11:07 . 2010-03-05 11:00 598 ----a-w- c:\windows\system32\secushr.dat
2010-02-25 06:18 . 2002-09-23 10:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-09-23 10:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:09 . 2002-09-23 10:00 2192128 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:09 . 2002-09-20 17:12 2068992 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-14 12:05 . 2010-02-14 12:05 234336 ----a-w- c:\windows\system32\SqlServerSpatial.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\Antiviry\Avast5\avastUI.exe" [2010-05-06 2815192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Komunikace\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\dev\\prog\\apache\\bin\\httpd.exe"=
"c:\\Program Files\\hry\\TrackmaniaNationsForever\\TmForever.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Práce se soubory\\Total Commander\\TOTALCMD.EXE"=
"c:\\Program Files\\Editory\\NetBeans 6.8\\bin\\netbeans.exe"=
"c:\\Program Files\\Prohlížeče\\Opera\\opera.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Přehrávače\\VLC\\vlc.exe"=
"c:\\Program Files\\Komunikace\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Skupiny sítě Peer-to-Peer
"3540:UDP"= 3540:UDP:Protokol PNRP (Peer Name Resolution Protocol)
"5353:TCP"= 5353:TCP:Adobe CSI CS4
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.5.2010 20:31 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.5.2010 20:31 19024]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 Apache2.2;Apache2.2;c:\dev\prog\apache\bin\httpd.exe [6.8.2009 15:50 24645]
S3 npacketdriver;Ethernet Packet Driver;c:\windows\system32\drivers\npacket.sys [24.4.2010 23:52 20244]
S3 npacketservice;Ethernet Packet Service;c:\windows\system32\npacketsvc.exe [24.4.2010 23:52 61440]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [23.7.2009 5:08 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [30.3.2009 3:09 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30.3.2009 3:23 366936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
Trusted Zone: kuaiche.com\software
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\lukas.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\lukas.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\lukas.default\extensions\info@lingea.com\components\LG_Mozilla2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Prohlˇ§eźe\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-13 17:37
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\dev\prog\mysql\bin\mysqld\" --defaults-file=\"c:\dev\prog\mysql\my.ini\" MySQL"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="CE6B3168D878688691E833708D88E356FDB2D32BD08A893DB287F0221A5DE32842A28B483143DC373D91B42B9F89576C0FA15331753696FB2A5C2D67DECB761C870D4EDE881F766EECDCB79E55B28FF28EFEDB1DDD30DB967A6C74D34B67143E5429A15BF7615276E3A2D69864042D27EB1A9F7E7D4222D7DD9F2E58AF60C80A5398BD2EC946E01DD8DD40AB3662A7448B67E027FA9982908803D1288ECCF302A2A1728B016BE6B4F7AE39AE6993480F467FF830B0C46C139C49ED3C2126492AD3AD21ED50D2FD11DFD597BACEC3AC4E671C54F22C3A23B8B444FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DFEBC9E127BECC74CBA7FD869164D67942D98E55B86C17509DCA7E5B9181E57EA50E05BF04E14B0338CE63FE7697C1D859C20D208B3E2B9E38E349D2F2C8808E1469DC8B1FC7DB5EF1D443B6CC1C79D3A522F9469A595AA8C4CBFF011C5870653A704FA6BEF880DA09911CF76232FA3CA9DF7B602F1B74F95FABB272A218A216C0EE514D4A7D375296F231C43F3A37DF762F1753902AC9EB891E038ABCB061F7DA65E6C0578831F15239276F66A9A66A317D643DA955A05D09DAAD42AA9F039FCB147107B89C13191C83DE595938F1455C624C495BBACE1DD3F565E1D70C69C8385C0BD9757BA45EF8BC3A78B527DACB6919C53FCDB1009032BE8EBE12B8668CC0DB06820301FE926A98B2C2759694B182A457C892FF94409A8A74838393535BA413E39BEB8A321CEF4BC179832D5FD6CD86A0315435FCC5C159F71444C5A885137550A006900E0285546C3793ACD49C8F798DA5F7BBAD50CDE9E1B8EEC01613A9327EB558D7213134358BA42A1DEA469F5222E8D8B0C80CC0CB8A905743930438D262193C4BA1517CDE7BF516D1B78ADD81D5B24FD54E6F4344439F59196D9DA740C22F5029DB9DB172FC5E9F417A61735E3F211319B938184DC989748B0389829D499998FE2473055A976B1E7ED804E3715BA22566B87123C6248816E229733A03FE7FD8659F606D2992C3344BBCC1C9D932C8BF2D2B6EB2F7601AEAE8CB809E4509F0AD74F77746E057A5D6023C771BD02F4E4E1E40974C6022C028792D19A91500986469A6A339933230363C821607CCEF528CFB75A397E2E69BE4DDB8A8BD94C2021EB146622DA3120D8CCD7F89ED5A546B63F67FA6AE7EB0A0DA51480A6029293EB32987441CCD19DF9EAFDE8895AF82ED28510AEDA26ED94798BEA4458E239C6DADA0893B89C2AFBE5E3EAFA1EAB7FAAA34BD62D82F12AC4744E145C31E9965149F7C6B5518E91D0FCAF552F0082B3EDB59160A37E175C07D20FC640E51AC70072F03EBF77772763081C7877F528525E7727D8318DF584014CC5BF5ECF862D507904DA"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1604)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Mobil\Nokia Pc Suite\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Antiviry\Avast5\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Správa\OO Software\Defrag\oodag.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\System32\tcpsvcs.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
.
**************************************************************************
.
Celkový čas: 2010-05-13 17:44:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-05-13 15:44
Před spuštěním: 4 184 199 168
Po spuštění: 5 423 386 624
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
- - End Of File - - F7C2ADF141B31E47015B7E660FF8B536
- 1danab
- Nováček
- Příspěvky: 1412
- Registrován: 21 říj 2007 13:04
- Bydliště: České Budějovice
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu - zablokovaná lišta
stáhněte GMER , rozbalte a spusťte
proběhne sken, po jehož ukončení se zobrazí výsledky
poté klikněte na Save a uložíte tak log, jeho obsah sem vložte
poté dle tohoto navodu absolvujte druhý sken a opět obsah logu sem
proběhne sken, po jehož ukončení se zobrazí výsledky
poté klikněte na Save a uložíte tak log, jeho obsah sem vložte
poté dle tohoto navodu absolvujte druhý sken a opět obsah logu sem

Re: Prosím o kontrolu logu - zablokovaná lišta
1. log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-14 14:49:18
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\LUK~1\LOCALS~1\Temp\ugrdapob.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF2EF0AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF2EF08EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF2EF0A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
2. log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-14 17:27:10
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\LUK~1\LOCALS~1\Temp\ugrdapob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF2EE3C7A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF2EE3B36]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF2EE40EA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF2EE4014]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF2EE370C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF2EE3C10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF2EE364C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF2EE36B0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF2EE3D30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF2EE41B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF2EE3CF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF2EE3E70]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF2EF0AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF2EF08EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF2EF0A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + 148 804DF7B4 4 Bytes JMP 27F2EE40
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Prohlížeče\Mozilla Firefox\firefox.exe[2216] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Prohlížeče\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[656] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[656] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL CE6B3168D878688691E833708D88E356FDB2D32BD08A893DB287F0221A5DE32842A28B483143DC373D91B42B9F89576C0FA15331753696FB2A5C2D67DECB761C870D4EDE881F766EECDCB79E55B28FF28EFEDB1DDD30DB967A6C74D34B67143E5429A15BF7615276E3A2D69864042D27EB1A9F7E7D4222D7DD9F2E58AF60C80A5398BD2EC946E01DD8DD40AB3662A7448B67E027FA9982908803D1288ECCF302A2A1728B016BE6B4F7AE39AE6993480F467FF830B0C46C139C49ED3C2126492AD3AD21ED50D2FD11DFD597BACEC3AC4E671C54F22C3A23B8B444FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DFEBC9E127BECC74CBA7FD869164D67942D98E55B86C17509DCA7E5B9181E57EA50E05BF04E14B0338CE63FE7697C1D859C20D208B3E2B9E38E349D2F2C8808E1469DC8B1FC7DB5EF1D443B6CC1C79D3A522F9469A595AA8C4CBFF011C5870653A704FA6BEF880DA09911CF76232FA3CA9DF7B602F1B74F95FABB272A218A216C0EE514D4A7D375296F231C43F3A37DF762F1753902AC9EB891E038ABCB061F7DA65E6C0578831F15239276F66A9A66A317D643DA955A05D09DAAD42AA9F039FCB147107B89C13191C83DE595938F1455C624C495BBACE1DD3F565E1D70C69C8385C0BD9757B
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesProcessed 19
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-05-14 14:49:18
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\LUK~1\LOCALS~1\Temp\ugrdapob.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF2EF0AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF2EF08EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF2EF0A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
2. log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-14 17:27:10
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\LUK~1\LOCALS~1\Temp\ugrdapob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF2EE3C7A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF2EE3B36]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF2EE40EA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF2EE4014]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF2EE370C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF2EE3C10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF2EE364C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF2EE36B0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF2EE3D30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF2EE41B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF2EE3CF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF2EE3E70]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF2EF0AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF2EF08EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF2EF0A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + 148 804DF7B4 4 Bytes JMP 27F2EE40
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Prohlížeče\Mozilla Firefox\firefox.exe[2216] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Prohlížeče\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[656] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[656] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL CE6B3168D878688691E833708D88E356FDB2D32BD08A893DB287F0221A5DE32842A28B483143DC373D91B42B9F89576C0FA15331753696FB2A5C2D67DECB761C870D4EDE881F766EECDCB79E55B28FF28EFEDB1DDD30DB967A6C74D34B67143E5429A15BF7615276E3A2D69864042D27EB1A9F7E7D4222D7DD9F2E58AF60C80A5398BD2EC946E01DD8DD40AB3662A7448B67E027FA9982908803D1288ECCF302A2A1728B016BE6B4F7AE39AE6993480F467FF830B0C46C139C49ED3C2126492AD3AD21ED50D2FD11DFD597BACEC3AC4E671C54F22C3A23B8B444FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DFEBC9E127BECC74CBA7FD869164D67942D98E55B86C17509DCA7E5B9181E57EA50E05BF04E14B0338CE63FE7697C1D859C20D208B3E2B9E38E349D2F2C8808E1469DC8B1FC7DB5EF1D443B6CC1C79D3A522F9469A595AA8C4CBFF011C5870653A704FA6BEF880DA09911CF76232FA3CA9DF7B602F1B74F95FABB272A218A216C0EE514D4A7D375296F231C43F3A37DF762F1753902AC9EB891E038ABCB061F7DA65E6C0578831F15239276F66A9A66A317D643DA955A05D09DAAD42AA9F039FCB147107B89C13191C83DE595938F1455C624C495BBACE1DD3F565E1D70C69C8385C0BD9757B
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesProcessed 19
---- EOF - GMER 1.0.15 ----
- 1danab
- Nováček
- Příspěvky: 1412
- Registrován: 21 říj 2007 13:04
- Bydliště: České Budějovice
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu - zablokovaná lišta
ještě pročistíme CCleanerem
návod zde http://www.viry.cz/forum/viewtopic.php?t=7478
dejte pak vědět jestli problémy s lištou přetrvávají
návod zde http://www.viry.cz/forum/viewtopic.php?t=7478
dejte pak vědět jestli problémy s lištou přetrvávají
Re: Prosím o kontrolu logu - zablokovaná lišta
Pročistil jsem to CCleanerem, ale lišta je stále při startu zablokovaná.
- 1danab
- Nováček
- Příspěvky: 1412
- Registrován: 21 říj 2007 13:04
- Bydliště: České Budějovice
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu - zablokovaná lišta
zkuste zastavit spouštění SQL a MySQL při startu a pak dejte vědět jestli je lišta po spuštění stále zablokovaná
Re: Prosím o kontrolu logu - zablokovaná lišta
Tak opravdu to tak nehorázně brzdilo MS SQL (MySQL se mi automaticky nespouštělo),
děkuji Vám za pomoc.
děkuji Vám za pomoc.
- 1danab
- Nováček
- Příspěvky: 1412
- Registrován: 21 říj 2007 13:04
- Bydliště: České Budějovice
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu - zablokovaná lišta
důležité je, že jste na to přišel
v tom případě je to vše ok

v tom případě je to vše ok
