Dobrý den,
prosím o kontrolu logu z combofixu, který našel a snad i vymazal nějaký rootkit. Předem moc děkuji
ComboFix 12-01-26.03 - Jakub 26.01.2012 23:03:50.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.510.260 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jakub\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\host32.exe
c:\windows\system32\ntos.exe
c:\windows\system32\sdra64.exe
c:\windows\system32\twext.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-26 do 2012-01-26 )))))))))))))))))))))))))))))))
.
.
2012-01-09 16:46 . 2012-01-09 16:46 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-09 16:46 . 2012-01-09 16:46 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-09 16:46 . 2012-01-09 16:46 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-09 16:46 . 2012-01-09 16:46 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-07 16:46 . 2012-01-16 18:15 270240 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-01-02 19:45 . 2011-06-21 10:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2012-01-02 19:45 . 2012-01-02 19:45 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Spyware Terminator
2012-01-02 19:45 . 2012-01-26 17:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spyware Terminator
2012-01-02 19:42 . 2012-01-11 17:41 -------- d-----w- c:\program files\Spyware Terminator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-16 18:15 . 2011-09-25 17:13 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-01-16 17:54 . 2011-12-11 18:19 139080 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-01-16 17:53 . 2011-12-11 18:18 270240 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-12-11 18:17 . 2011-09-25 17:00 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-12-11 15:24 . 2011-09-25 17:01 138056 ----a-w- c:\documents and settings\Jakub\Data aplikací\PnkBstrK.sys
2011-11-28 18:01 . 2011-03-24 22:08 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-03-24 22:08 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-03-24 22:09 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-03-24 22:09 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-03-24 22:09 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-03-24 22:09 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-03-24 22:09 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2011-03-24 22:09 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2011-03-24 22:09 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2011-03-24 22:09 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2001-10-25 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2001-10-25 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2001-10-25 12:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2011-03-24 21:28 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2001-10-25 12:00 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-03 15:29 . 2001-10-25 12:00 386560 ----a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:29 . 2001-10-25 12:00 1294848 ----a-w- c:\windows\system32\quartz.dll
2011-11-01 20:36 . 2011-03-24 21:28 81920 ------w- c:\windows\system32\ieencode.dll
2011-11-01 20:36 . 2001-10-25 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
2011-11-01 20:36 . 2001-10-25 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:34 . 2011-03-24 21:28 370176 ------w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2001-10-25 12:00 1288192 ----a-w- c:\windows\system32\ole32.dll
2012-01-09 16:46 . 2011-10-06 16:00 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-01_19.33.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-10-25 12:00 . 2011-11-01 20:36 37888 c:\windows\system32\url.dll
- 2001-10-25 12:00 . 2011-09-05 13:56 37888 c:\windows\system32\url.dll
+ 2011-03-25 07:45 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
- 2011-03-25 07:45 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
- 2001-10-25 12:00 . 2011-11-03 21:29 67646 c:\windows\system32\perfc009.dat
+ 2001-10-25 12:00 . 2012-01-05 19:25 67646 c:\windows\system32\perfc009.dat
- 2001-10-25 12:00 . 2011-11-03 21:29 78250 c:\windows\system32\perfc005.dat
+ 2001-10-25 12:00 . 2012-01-05 19:25 78250 c:\windows\system32\perfc005.dat
+ 2001-10-25 12:00 . 2011-10-14 14:47 23040 c:\windows\system32\mciseq.dll
- 2001-10-25 12:00 . 2008-04-14 03:21 23040 c:\windows\system32\mciseq.dll
+ 2011-06-21 18:18 . 2011-11-01 20:36 37888 c:\windows\system32\dllcache\url.dll
- 2011-06-21 18:18 . 2011-09-05 13:56 37888 c:\windows\system32\dllcache\url.dll
+ 2011-11-20 06:12 . 2011-11-20 06:12 60416 c:\windows\system32\dllcache\packager.exe
+ 2011-10-14 14:47 . 2011-10-14 14:47 23040 c:\windows\system32\dllcache\mciseq.dll
- 2010-04-16 15:38 . 2011-09-05 13:56 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2010-04-16 15:38 . 2011-11-01 20:36 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2009-12-14 07:10 . 2011-10-28 05:32 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2009-12-14 07:10 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2001-10-25 12:00 . 2011-04-26 11:07 33280 c:\windows\system32\csrsrv.dll
+ 2001-10-25 12:00 . 2011-10-28 05:32 33280 c:\windows\system32\csrsrv.dll
+ 2011-12-25 02:49 . 2011-12-25 02:49 31504 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2012-01-06 16:35 . 2012-01-06 16:35 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\750de53f30e516eb2c62de9bab7954e9\System.Web.DynamicData.Design.ni.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2011-10-14 10:59 . 2011-10-14 10:59 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-12-14 15:31 . 2011-07-08 13:49 46080 c:\windows\$NtUninstallKB2633952$\tzchange.exe
+ 2011-12-14 15:31 . 2011-11-08 14:58 16896 c:\windows\$NtUninstallKB2633952$\spuninst\tzchange.dll
+ 2011-12-14 15:29 . 2011-04-26 11:07 33280 c:\windows\$NtUninstallKB2620712$\csrsrv.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 37888 c:\windows\$NtUninstallKB2618444$\url.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 81920 c:\windows\$NtUninstallKB2618444$\ieencode.dll
+ 2011-12-14 17:01 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2639417\update\spcustom.dll
+ 2011-12-14 17:01 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2639417\spmsg.dll
+ 2011-12-14 15:28 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2633171\update\spcustom.dll
+ 2011-12-13 22:07 . 2011-10-26 10:51 16896 c:\windows\$hf_mig$\KB2633171\update\mpsyschk.dll
+ 2011-12-14 15:28 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2633171\spmsg.dll
+ 2011-12-14 17:00 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2624667\update\spcustom.dll
+ 2011-12-14 17:00 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2624667\spmsg.dll
+ 2011-12-14 15:29 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2620712\update\spcustom.dll
+ 2011-12-14 15:29 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2620712\spmsg.dll
+ 2011-10-28 05:31 . 2011-10-28 05:31 33280 c:\windows\$hf_mig$\KB2620712\SP3QFE\csrsrv.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2619339\update\spcustom.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2619339\spmsg.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2618451\update\spcustom.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2618451\spmsg.dll
+ 2011-12-14 15:30 . 2010-07-05 13:13 26488 c:\windows\$hf_mig$\KB2618444\update\spcustom.dll
+ 2011-12-14 15:30 . 2010-07-05 13:13 18296 c:\windows\$hf_mig$\KB2618444\spmsg.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 37888 c:\windows\$hf_mig$\KB2618444\SP3QFE\url.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 81920 c:\windows\$hf_mig$\KB2618444\SP3QFE\ieencode.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2011-10-14 11:00 . 2011-10-14 11:00 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2001-10-25 12:00 . 2008-04-14 03:22 174592 c:\windows\system32\winmm.dll
+ 2001-10-25 12:00 . 2011-10-14 14:47 174592 c:\windows\system32\winmm.dll
- 2001-10-25 12:00 . 2011-09-05 13:56 627712 c:\windows\system32\urlmon.dll
+ 2001-10-25 12:00 . 2011-11-01 20:36 627712 c:\windows\system32\urlmon.dll
+ 2001-10-25 12:00 . 2011-11-16 14:21 152064 c:\windows\system32\schannel.dll
- 2001-10-25 12:00 . 2011-11-03 21:29 432690 c:\windows\system32\perfh009.dat
+ 2001-10-25 12:00 . 2012-01-05 19:25 432690 c:\windows\system32\perfh009.dat
+ 2001-10-25 12:00 . 2012-01-05 19:25 429262 c:\windows\system32\perfh005.dat
- 2001-10-25 12:00 . 2011-11-03 21:29 429262 c:\windows\system32\perfh005.dat
+ 2001-10-25 12:00 . 2011-11-01 20:36 532480 c:\windows\system32\mstime.dll
- 2001-10-25 12:00 . 2011-09-05 13:56 532480 c:\windows\system32\mstime.dll
+ 2001-10-25 12:00 . 2011-11-01 20:36 449536 c:\windows\system32\mshtmled.dll
- 2001-10-25 12:00 . 2011-09-05 13:56 449536 c:\windows\system32\mshtmled.dll
+ 2001-10-25 12:00 . 2011-11-01 20:36 251904 c:\windows\system32\iepeers.dll
- 2001-10-25 12:00 . 2011-09-05 13:56 251904 c:\windows\system32\iepeers.dll
- 2011-03-24 21:17 . 2011-10-14 11:07 115768 c:\windows\system32\FNTCACHE.DAT
+ 2011-03-24 21:17 . 2011-12-14 18:17 115768 c:\windows\system32\FNTCACHE.DAT
- 2011-03-24 21:29 . 2011-02-09 13:53 186880 c:\windows\system32\encdec.dll
+ 2011-03-24 21:29 . 2011-10-18 11:13 186880 c:\windows\system32\encdec.dll
+ 2010-06-18 17:47 . 2011-11-25 21:57 293376 c:\windows\system32\dllcache\winsrv.dll
- 2010-06-18 17:47 . 2011-06-20 17:44 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2011-10-14 14:47 . 2011-10-14 14:47 174592 c:\windows\system32\dllcache\winmm.dll
+ 2010-04-16 16:08 . 2011-11-01 20:36 668160 c:\windows\system32\dllcache\wininet.dll
- 2010-04-16 16:08 . 2011-09-05 13:56 668160 c:\windows\system32\dllcache\wininet.dll
- 2008-12-16 12:32 . 2009-08-25 09:19 354816 c:\windows\system32\dllcache\winhttp.dll
+ 2008-12-16 12:32 . 2011-11-16 14:21 354816 c:\windows\system32\dllcache\winhttp.dll
- 2010-04-16 16:08 . 2011-09-05 13:56 627712 c:\windows\system32\dllcache\urlmon.dll
+ 2010-04-16 16:08 . 2011-11-01 20:36 627712 c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-05 06:57 . 2011-11-16 14:21 152064 c:\windows\system32\dllcache\schannel.dll
+ 2011-11-03 15:29 . 2011-11-03 15:29 386560 c:\windows\system32\dllcache\qdvd.dll
- 2010-12-20 22:14 . 2011-09-05 13:56 532480 c:\windows\system32\dllcache\mstime.dll
+ 2010-12-20 22:14 . 2011-11-01 20:36 532480 c:\windows\system32\dllcache\mstime.dll
+ 2010-12-20 22:14 . 2011-11-01 20:36 449536 c:\windows\system32\dllcache\mshtmled.dll
- 2010-12-20 22:14 . 2011-09-05 13:56 449536 c:\windows\system32\dllcache\mshtmled.dll
+ 2010-04-16 16:08 . 2011-11-01 20:36 251904 c:\windows\system32\dllcache\iepeers.dll
- 2010-04-16 16:08 . 2011-09-05 13:56 251904 c:\windows\system32\dllcache\iepeers.dll
- 2011-02-09 13:53 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-02-09 13:53 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-12-25 02:49 . 2011-12-25 02:49 436496 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2011-12-25 04:40 . 2011-12-25 04:40 819200 c:\windows\Installer\4a192b8.msp
+ 2012-01-05 19:22 . 2012-01-05 19:22 507904 c:\windows\assembly\tmp\U17CHNSX\AspNetMMCExt.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\0bda7bdfaf440d5dd4bc6a1dea7ffa39\System.Web.Routing.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6e29f9faa74a48b83a13a3413b826295\System.Web.Extensions.Design.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\be8965fe859bc53dff61579bf626858b\System.Web.Entity.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\8441b3eb247e0344fede848337ee911c\System.Web.Entity.Design.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\09c6a41f187ba483486cdb92dad714a1\System.Web.DynamicData.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\5efb726d424b9712632eff749411fa89\System.Web.Abstractions.ni.dll
+ 2012-01-06 16:34 . 2012-01-06 16:34 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\f374e8e7849a72d1470b4a6a0771a137\System.Data.Entity.Design.ni.dll
+ 2012-01-06 16:33 . 2012-01-06 16:33 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\439732479756e0f6df88d29e50a402bf\ServiceModelReg.ni.exe
+ 2012-01-06 16:31 . 2012-01-06 16:31 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\bfcea15c95909860c4f4ac19bd7a2d6c\AspNetMMCExt.ni.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
- 2011-10-14 10:59 . 2011-10-14 10:59 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-12-14 17:01 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2639417$\spuninst\updspapi.dll
+ 2011-12-14 17:01 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2639417$\spuninst\spuninst.exe
+ 2011-12-14 15:31 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2633952$\spuninst\updspapi.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2633952$\spuninst\spuninst.exe
+ 2011-12-14 15:28 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2633171$\spuninst\updspapi.dll
+ 2011-12-14 15:28 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2633171$\spuninst\spuninst.exe
+ 2011-12-14 17:00 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2624667$\spuninst\updspapi.dll
+ 2011-12-14 17:00 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2624667$\spuninst\spuninst.exe
+ 2011-12-14 15:29 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2620712$\spuninst\updspapi.dll
+ 2011-12-14 15:29 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2620712$\spuninst\spuninst.exe
+ 2011-12-14 15:31 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2619339$\spuninst\updspapi.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2619339$\spuninst\spuninst.exe
+ 2011-12-14 15:31 . 2011-02-09 13:53 186880 c:\windows\$NtUninstallKB2619339$\encdec.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2618451$\spuninst\updspapi.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2618451$\spuninst\spuninst.exe
+ 2011-12-14 15:30 . 2011-09-05 13:56 668160 c:\windows\$NtUninstallKB2618444$\wininet.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 627712 c:\windows\$NtUninstallKB2618444$\urlmon.dll
+ 2011-12-14 15:30 . 2010-07-05 13:13 391032 c:\windows\$NtUninstallKB2618444$\spuninst\updspapi.dll
+ 2011-12-14 15:30 . 2010-07-05 13:13 233848 c:\windows\$NtUninstallKB2618444$\spuninst\spuninst.exe
+ 2011-12-14 15:30 . 2011-09-05 13:56 532480 c:\windows\$NtUninstallKB2618444$\mstime.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 449536 c:\windows\$NtUninstallKB2618444$\mshtmled.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 251904 c:\windows\$NtUninstallKB2618444$\iepeers.dll
+ 2011-12-14 17:01 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2639417\update\updspapi.dll
+ 2011-12-14 17:01 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2639417\update\update.exe
+ 2011-12-14 17:01 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2639417\spuninst.exe
+ 2011-12-14 15:28 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2633171\update\updspapi.dll
+ 2011-12-14 15:28 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2633171\update\update.exe
+ 2011-12-14 15:28 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2633171\spuninst.exe
+ 2011-12-14 17:00 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2624667\update\updspapi.dll
+ 2011-12-14 17:00 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2624667\update\update.exe
+ 2011-12-14 17:00 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2624667\spuninst.exe
+ 2011-12-14 15:29 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2620712\update\updspapi.dll
+ 2011-12-14 15:29 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2620712\update\update.exe
+ 2011-12-14 15:29 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2620712\spuninst.exe
+ 2011-12-14 15:31 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2619339\update\updspapi.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2619339\update\update.exe
+ 2011-12-14 15:31 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2619339\spuninst.exe
+ 2011-10-18 11:12 . 2011-10-18 11:12 186880 c:\windows\$hf_mig$\KB2619339\SP3QFE\encdec.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2618451\update\updspapi.dll
+ 2011-12-14 15:31 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2618451\update\update.exe
+ 2011-12-14 15:31 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2618451\spuninst.exe
+ 2011-12-14 15:30 . 2010-07-05 13:13 391032 c:\windows\$hf_mig$\KB2618444\update\updspapi.dll
+ 2011-12-14 15:30 . 2010-07-05 13:13 759160 c:\windows\$hf_mig$\KB2618444\update\update.exe
+ 2011-12-14 15:30 . 2010-07-05 13:13 233848 c:\windows\$hf_mig$\KB2618444\spuninst.exe
+ 2011-11-01 20:34 . 2011-11-01 20:34 669696 c:\windows\$hf_mig$\KB2618444\SP3QFE\wininet.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 628224 c:\windows\$hf_mig$\KB2618444\SP3QFE\urlmon.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 532480 c:\windows\$hf_mig$\KB2618444\SP3QFE\mstime.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 449536 c:\windows\$hf_mig$\KB2618444\SP3QFE\mshtmled.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 251904 c:\windows\$hf_mig$\KB2618444\SP3QFE\iepeers.dll
- 2001-10-25 12:00 . 2011-09-05 13:56 1510912 c:\windows\system32\shdocvw.dll
+ 2001-10-25 12:00 . 2011-11-01 20:36 1510912 c:\windows\system32\shdocvw.dll
- 2001-10-25 12:00 . 2010-12-09 15:14 2194944 c:\windows\system32\ntoskrnl.exe
+ 2001-10-25 12:00 . 2011-10-26 10:50 2194944 c:\windows\system32\ntoskrnl.exe
+ 2001-10-24 11:46 . 2011-10-26 10:50 2071552 c:\windows\system32\ntkrnlpa.exe
- 2001-10-24 11:46 . 2010-12-09 15:14 2071552 c:\windows\system32\ntkrnlpa.exe
+ 2001-10-25 12:00 . 2011-11-03 15:50 3108352 c:\windows\system32\mshtml.dll
+ 2010-05-02 08:09 . 2011-11-23 14:40 1859584 c:\windows\system32\dllcache\win32k.sys
+ 2010-04-16 16:08 . 2011-11-01 20:36 1510912 c:\windows\system32\dllcache\shdocvw.dll
- 2010-04-16 16:08 . 2011-09-05 13:56 1510912 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-11-27 17:14 . 2011-11-03 15:29 1294848 c:\windows\system32\dllcache\quartz.dll
+ 2010-07-16 12:00 . 2011-11-01 16:07 1288192 c:\windows\system32\dllcache\ole32.dll
+ 2011-03-25 09:40 . 2011-10-26 10:50 2194944 c:\windows\system32\dllcache\ntoskrnl.exe
- 2011-03-25 09:40 . 2010-12-09 15:14 2194944 c:\windows\system32\dllcache\ntoskrnl.exe
- 2011-03-25 09:40 . 2010-12-09 15:14 2029056 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2011-03-25 09:40 . 2011-10-26 10:49 2029056 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-10 18:09 . 2011-10-26 10:50 2071552 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-02-10 18:09 . 2010-12-09 15:14 2071552 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2011-03-25 09:40 . 2011-10-26 10:49 2150912 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2011-03-25 09:40 . 2010-12-09 15:14 2150912 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2010-04-16 16:08 . 2011-11-03 15:50 3108352 c:\windows\system32\dllcache\mshtml.dll
+ 2010-04-16 16:08 . 2011-11-01 20:36 1025024 c:\windows\system32\dllcache\browseui.dll
- 2010-04-16 16:08 . 2011-09-05 13:56 1025024 c:\windows\system32\dllcache\browseui.dll
+ 2001-10-25 12:00 . 2011-11-01 20:36 1025024 c:\windows\system32\browseui.dll
- 2001-10-25 12:00 . 2011-09-05 13:56 1025024 c:\windows\system32\browseui.dll
+ 2011-12-25 02:50 . 2011-12-25 02:50 5246976 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2011-12-26 08:59 . 2011-12-26 08:59 4368896 c:\windows\Installer\4a192b0.msp
- 2011-03-25 09:40 . 2010-12-09 15:14 2194944 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2011-03-25 09:40 . 2011-10-26 10:50 2194944 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2011-03-25 09:40 . 2010-12-09 15:14 2029056 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2011-03-25 09:40 . 2011-10-26 10:49 2029056 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-02-10 18:09 . 2010-12-09 15:14 2071552 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-02-10 18:09 . 2011-10-26 10:50 2071552 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2011-03-25 09:40 . 2011-10-26 10:49 2150912 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2011-03-25 09:40 . 2010-12-09 15:14 2150912 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2012-01-06 16:36 . 2012-01-06 16:36 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\05c29118462056cf810df0b6aa660d05\System.WorkflowServices.ni.dll
+ 2012-01-06 16:36 . 2012-01-06 16:36 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\26b3258c559dc0ab6bdce481ffd458b3\System.Workflow.Runtime.ni.dll
+ 2012-01-06 16:36 . 2012-01-06 16:36 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\1642d1b72cd84caf24cbe7c5e8fd8368\System.Workflow.ComponentModel.ni.dll
+ 2012-01-06 16:36 . 2012-01-06 16:36 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\32ce12c3c2049f2df94c44c94b052e16\System.Workflow.Activities.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\f63ae1310e004777e880f28377bcddd2\System.Web.Services.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\c99b02434e71ca9898bebbc08d63e885\System.Web.Mobile.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\c8f78b9e94857fdf6c2a378dd1629ee0\System.Web.Extensions.ni.dll
+ 2012-01-06 16:35 . 2012-01-06 16:35 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\ae749b024162e9ac79110c633b5ce6be\System.ServiceModel.Web.ni.dll
+ 2012-01-06 16:31 . 2012-01-06 16:31 1070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\23eb4618c9d171be9fb551a13a475a32\System.IdentityModel.ni.dll
+ 2012-01-06 16:34 . 2012-01-06 16:34 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\f35064c125799df650c1a959d8fa450b\System.Data.Services.ni.dll
+ 2012-01-06 16:33 . 2012-01-06 16:33 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\a86c12788293105a0d9fda1bc90c90bc\Microsoft.VisualBasic.ni.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-01-05 19:23 . 2012-01-05 19:23 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2011-10-14 10:59 . 2011-10-14 10:59 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-01-05 19:28 . 2012-01-05 19:28 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- 2011-10-01 20:03 . 2011-10-01 20:03 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- 2011-10-14 10:59 . 2011-10-14 10:59 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-01-05 19:22 . 2012-01-05 19:22 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-01-05 19:21 . 2012-01-05 19:21 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2012-01-05 19:24 . 2012-01-05 19:24 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2011-10-14 11:00 . 2011-10-14 11:00 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2011-12-14 17:01 . 2011-09-06 14:10 1858944 c:\windows\$NtUninstallKB2639417$\win32k.sys
+ 2011-12-14 15:26 . 2010-12-09 15:14 2194944 c:\windows\$NtUninstallKB2633171$\ntoskrnl.exe
+ 2011-12-14 15:28 . 2010-12-09 15:14 2029056 c:\windows\$NtUninstallKB2633171$\ntkrpamp.exe
+ 2011-12-14 15:27 . 2010-12-09 15:14 2071552 c:\windows\$NtUninstallKB2633171$\ntkrnlpa.exe
+ 2011-12-14 15:28 . 2010-12-09 15:14 2150912 c:\windows\$NtUninstallKB2633171$\ntkrnlmp.exe
+ 2011-12-14 17:00 . 2010-07-16 12:00 1287680 c:\windows\$NtUninstallKB2624667$\ole32.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 1510912 c:\windows\$NtUninstallKB2618444$\shdocvw.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 3107328 c:\windows\$NtUninstallKB2618444$\mshtml.dll
+ 2011-12-14 15:30 . 2011-09-05 13:56 1025024 c:\windows\$NtUninstallKB2618444$\browseui.dll
+ 2011-11-23 14:39 . 2011-11-23 14:39 1868544 c:\windows\$hf_mig$\KB2639417\SP3QFE\win32k.sys
+ 2011-10-26 10:49 . 2011-10-26 10:49 2194944 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe
+ 2011-10-26 10:49 . 2011-10-26 10:49 2029056 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrpamp.exe
+ 2011-10-26 10:49 . 2011-10-26 10:49 2071552 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe
+ 2011-10-26 10:49 . 2011-10-26 10:49 2150912 c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlmp.exe
+ 2011-11-01 16:05 . 2011-11-01 16:05 1288704 c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 1510912 c:\windows\$hf_mig$\KB2618444\SP3QFE\shdocvw.dll
+ 2011-11-03 15:49 . 2011-11-03 15:49 3108864 c:\windows\$hf_mig$\KB2618444\SP3QFE\mshtml.dll
+ 2011-11-01 20:34 . 2011-11-01 20:34 1025024 c:\windows\$hf_mig$\KB2618444\SP3QFE\browseui.dll
+ 2011-03-25 13:13 . 2012-01-12 19:21 52128560 c:\windows\system32\MRT.exe
+ 2012-01-06 16:35 . 2012-01-06 16:35 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll
+ 2012-01-06 16:32 . 2012-01-06 16:32 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\2dac4fc006596760cd4988d0bfd52ff0\System.ServiceModel.ni.dll
+ 2012-01-05 19:30 . 2012-01-05 19:30 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\9e15d80ffb037e9171fa4bd2e0233497\System.Design.ni.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-24 2880512]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"SpywareTerminatorShield"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2011-12-23 2779824]
"SpywareTerminatorUpdater"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-12-23 3621040]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 10:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^AVerQuick.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk
backup=c:\windows\pss\AVerQuick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acerWireless]
2004-06-09 10:15 417792 ----a-w- c:\program files\acer\Wireless\Utility\wlanutil.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACU]
2005-01-31 07:05 253952 ----a-w- c:\program files\Atheros\ACU.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-04-28 20:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp]
2004-10-15 10:31 356352 ----a-w- c:\program files\Intel\Wireless\Bin\EOUWiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPM-DM]
2005-03-28 17:04 188416 ----a-w- c:\acer\ePM\EPM-DM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-10-22 18:44 137536 ----atw- c:\documents and settings\Jakub\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
2007-07-11 14:09 20480 ----a-w- c:\windows\FixCamera.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2011-09-14 16:01 243360 ----a-w- c:\windows\system32\Macromed\Flash\FlashUtil10w_Plugin.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-08-01 08:28 124480 ----a-w- c:\program files\ICQ7.5\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2004-10-15 10:27 385024 ----a-w- c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2005-09-05 10:43 319488 ----a-w- c:\program files\Launch Manager\QtZgAcer.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:22 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-09-01 12:39 966712 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3]
2009-02-26 15:08 593920 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\fppdis3a.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
2006-01-06 11:57 344064 ----a-w- c:\windows\vsnp2std.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2011-12-23 02:42 3621040 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
2006-01-06 15:39 110592 ----a-w- c:\windows\tsnp2std.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)
"ServiceLayer"=3 (0x3)
"S24EventMonitor"=2 (0x2)
"RegSrvc"=2 (0x2)
"PnkBstrA"=2 (0x2)
"OwnershipProtocol"=2 (0x2)
"idsvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"EvtEng"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"ACS"=2 (0x2)
"ERSvc"=2 (0x2)
"WebClient"=2 (0x2)
"SysmonLog"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"SCardSvr"=3 (0x3)
"PolicyAgent"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"BITS"=3 (0x3)
"lanmanserver"=2 (0x2)
"seclogon"=2 (0x2)
"cisvc"=3 (0x3)
"upnphost"=3 (0x3)
"WmiApSrv"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\Jakub\\Local Settings\\Data aplikací\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\EA Games\\Battlefield Heroes\\BFHeroes.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [24.3.2011 23:09 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [24.3.2011 23:09 314456]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2.1.2012 20:45 32768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [24.3.2011 23:09 20568]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\Spyware Terminator\st_rsser.exe [2.1.2012 20:44 482992]
S3 AVerHybrid;AVerMedia Hybrid Tuner (NTSC/PAL/SECAM/DVB-T/FM);c:\windows\system32\drivers\averhbtv.sys [24.3.2011 23:28 302848]
S4 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24.4.2011 11:03 136176]
S4 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [24.4.2011 11:03 136176]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-24 10:03]
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-24 10:03]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
IE: Crawler Search - tbr:iemenu
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\35j97ap1.default\
FF - prefs.js: browser.startup.homepage - www.centrum.cz
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-26 23:14
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1076)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Celkový čas: 2012-01-26 23:19:00
ComboFix-quarantined-files.txt 2012-01-26 22:18
ComboFix2.txt 2011-12-01 19:37
.
Před spuštěním: Volných bajtů: 23 090 679 808
Po spuštění: Volných bajtů: 23 102 955 520
.
- - End Of File - - 3721611A46795FD1D42DEB9CB73C3F56

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Zdravím!
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.KillAll::
Folder::
c:\documents and settings\Jakub\Local Settings\Data aplikací\Facebook\Update
c:\program files\Google\Update
Driver::
gupdate
gupdatem
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu logu
Posílám log z Combofixu:
ComboFix 12-01-26.03 - Jakub 27.01.2012 21:33:24.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.510.249 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jakub\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Jakub\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.79\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.79\goopdate.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.79\psmachine.dll
c:\program files\Google\Update\1.3.21.79\psuser.dll
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.79\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{74AF07D8-FB8F-4D51-8AC7-927721D56EBB}\0.0.0.0\GoogleEarth-Win-Bundle-6.1.0.5001.exe
c:\program files\Google\Update\Download\{9BDB8132-624C-4E4B-9490-7D905987967E}\GoogleUpdateSetup.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\host32.exe
c:\windows\svchost.dll
c:\windows\system32\accies98.dll
c:\windows\system32\arprmdg0.dll
c:\windows\system32\avload32.dll
c:\windows\system32\avpe32.dll
c:\windows\system32\avpx32.dll
c:\windows\system32\axxt32.dll
c:\windows\system32\bmtdhh.dll
c:\windows\system32\browsemu.dll
c:\windows\system32\bt848rom.dll
c:\windows\system32\clbdll.dll
c:\windows\system32\directpt.dll
c:\windows\system32\directut.dll
c:\windows\system32\dll.dll
c:\windows\system32\docent0.dll
c:\windows\system32\docent2.dll
c:\windows\system32\dvd4free.dll
c:\windows\system32\dxtpdx.dll
c:\windows\system32\extxerox.dll
c:\windows\system32\hpprintx.dll
c:\windows\system32\iesdl4l.dll
c:\windows\system32\KernelDrv.exe
c:\windows\system32\kernelwind32.exe
c:\windows\system32\ksapgh.dll
c:\windows\system32\lanmui.dll
c:\windows\system32\mmx4xt.dll
c:\windows\system32\msindeo.dll
c:\windows\system32\msliksurcredo.dll
c:\windows\system32\msliksurdns.dll
c:\windows\system32\Mspdnx.dll
c:\windows\system32\msvcrl.dll
c:\windows\system32\ntos.exe
c:\windows\system32\obbn13t.dll
c:\windows\system32\pasksa.dll
c:\windows\system32\pptp16.dll
c:\windows\system32\pptp32.dll
c:\windows\system32\qo.dll
c:\windows\system32\satdll.dll
c:\windows\system32\scsiusr4.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\se500mdm.dll
c:\windows\system32\tcpwrk.dll
c:\windows\system32\twext.exe
c:\windows\system32\xptptt.dll
c:\windows\system32\yvpp01.dll
c:\windows\system32\yvsvga.dll
c:\windows\system32\zopenssl.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-27 do 2012-01-27 )))))))))))))))))))))))))))))))
.
.
2012-01-27 20:21 . 2012-01-27 20:21 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\FLEXnet
2012-01-27 20:15 . 2009-06-29 17:00 112640 ----a-r- c:\windows\system32\drivers\ewusbnet.sys
2012-01-27 20:14 . 2009-04-09 12:38 102400 ----a-r- c:\windows\system32\drivers\ewusbmdm.sys
2012-01-27 20:14 . 2008-04-13 18:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2012-01-27 20:14 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-01-27 20:13 . 2012-01-27 20:13 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Vodafone
2012-01-27 20:13 . 2012-01-27 20:13 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Vodafone
2012-01-27 20:13 . 2012-01-27 20:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Vodafone
2012-01-27 20:12 . 2012-01-27 20:12 -------- d-----w- c:\program files\Vodafone
2012-01-27 20:12 . 2012-01-27 20:12 -------- d-----w- c:\documents and settings\All Users\Data aplikací\FLEXnet
2012-01-27 20:12 . 2012-01-27 20:12 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\{6118B561-4CCF-4F70-B358-73ACA4B8FB39}
2012-01-27 19:59 . 2012-01-27 19:59 -------- d--h--w- c:\windows\PIF
2012-01-26 22:40 . 2012-01-26 22:40 -------- d-----w- c:\program files\trend micro
2012-01-26 22:40 . 2012-01-26 22:40 -------- d-----w- C:\rsit
2012-01-09 16:46 . 2012-01-09 16:46 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-09 16:46 . 2012-01-09 16:46 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-09 16:46 . 2012-01-09 16:46 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-09 16:46 . 2012-01-09 16:46 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-07 16:46 . 2012-01-16 18:15 270240 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-01-02 19:45 . 2011-06-21 10:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2012-01-02 19:45 . 2012-01-02 19:45 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Spyware Terminator
2012-01-02 19:45 . 2012-01-27 19:54 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spyware Terminator
2012-01-02 19:42 . 2012-01-11 17:41 -------- d-----w- c:\program files\Spyware Terminator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-16 18:15 . 2011-09-25 17:13 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-01-16 17:54 . 2011-12-11 18:19 139080 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-01-16 17:53 . 2011-12-11 18:18 270240 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-12-11 18:17 . 2011-09-25 17:00 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-12-11 15:24 . 2011-09-25 17:01 138056 ----a-w- c:\documents and settings\Jakub\Data aplikací\PnkBstrK.sys
2011-11-28 18:01 . 2011-03-24 22:08 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-03-24 22:08 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-03-24 22:09 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-03-24 22:09 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-03-24 22:09 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-03-24 22:09 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-03-24 22:09 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2011-03-24 22:09 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2011-03-24 22:09 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2011-03-24 22:09 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2001-10-25 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2001-10-25 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2001-10-25 12:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2011-03-24 21:28 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2001-10-25 12:00 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-03 15:29 . 2001-10-25 12:00 386560 ----a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:29 . 2001-10-25 12:00 1294848 ----a-w- c:\windows\system32\quartz.dll
2011-11-01 20:36 . 2011-03-24 21:28 81920 ------w- c:\windows\system32\ieencode.dll
2011-11-01 20:36 . 2001-10-25 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
2011-11-01 20:36 . 2001-10-25 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:34 . 2011-03-24 21:28 370176 ------w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2001-10-25 12:00 1288192 ----a-w- c:\windows\system32\ole32.dll
2012-01-09 16:46 . 2011-10-06 16:00 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-01-26_22.14.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-12-01 23:08 . 2006-12-01 23:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 23:26 . 2006-12-01 23:26 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-01 23:25 . 2006-12-01 23:25 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2012-01-27 20:13 . 2009-04-09 12:38 24448 c:\windows\system32\DRVSTORE\ewdcsc_DA2777CB9188B1F25A999918A47509FC693296FD\ewdcsc.sys
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\VodafoneConnectionMa_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\SMS_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\NewShortcut9_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\NewShortcut8_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\ARPPRODUCTICON.exe
+ 2006-12-01 21:54 . 2006-12-01 21:54 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-01 21:54 . 2006-12-01 21:54 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 21:54 . 2006-12-01 21:54 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2012-01-27 20:13 . 2009-04-09 12:38 621056 c:\windows\system32\DRVSTORE\mod7700_8C17870443A1EF4AA2DF3F4C259AD7DC9CE429DF\mod7700.sys
+ 2012-01-27 20:13 . 2009-04-09 12:38 102400 c:\windows\system32\DRVSTORE\ewser2k_BC96AE4EE9BF303EB19EDF9739A7EEB2DC612150\ewusbmdm.sys
+ 2012-01-27 20:13 . 2009-06-29 17:00 112640 c:\windows\system32\DRVSTORE\ewnet_23B357679E08714ADCBF3A5454C2DD9FE47FCEB1\ewusbnet.sys
+ 2012-01-27 20:13 . 2009-04-09 12:38 102400 c:\windows\system32\DRVSTORE\ewmdm2k_9D926F5881D46CBE167A3483FECC88FAFEB6AEDC\ewusbmdm.sys
+ 2012-01-27 20:13 . 2009-06-29 17:00 102656 c:\windows\system32\DRVSTORE\ewfake_1FBF9D50C5288ED070EF7C836A0A8FBE8BDC2E59\ewusbfake.sys
+ 2006-12-01 23:25 . 2006-12-01 23:25 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-01 23:25 . 2006-12-01 23:25 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2012-01-27 20:13 . 2012-01-27 20:13 2326016 c:\windows\Installer\a7080.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-24 2880512]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"SpywareTerminatorShield"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2011-12-23 2779824]
"SpywareTerminatorUpdater"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-12-23 3621040]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 188416]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2009-07-03 2328576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 10:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^AVerQuick.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk
backup=c:\windows\pss\AVerQuick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acerWireless]
2004-06-09 10:15 417792 ----a-w- c:\program files\acer\Wireless\Utility\wlanutil.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACU]
2005-01-31 07:05 253952 ----a-w- c:\program files\Atheros\ACU.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-04-28 20:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp]
2004-10-15 10:31 356352 ----a-w- c:\program files\Intel\Wireless\Bin\EOUWiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
2007-07-11 14:09 20480 ----a-w- c:\windows\FixCamera.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2011-09-14 16:01 243360 ----a-w- c:\windows\system32\Macromed\Flash\FlashUtil10w_Plugin.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-08-01 08:28 124480 ----a-w- c:\program files\ICQ7.5\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2004-10-15 10:27 385024 ----a-w- c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2005-09-05 10:43 319488 ----a-w- c:\program files\Launch Manager\QtZgAcer.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:22 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-09-01 12:39 966712 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3]
2009-02-26 15:08 593920 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\fppdis3a.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
2006-01-06 11:57 344064 ----a-w- c:\windows\vsnp2std.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2011-12-23 02:42 3621040 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
2006-01-06 15:39 110592 ----a-w- c:\windows\tsnp2std.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)
"ServiceLayer"=3 (0x3)
"S24EventMonitor"=2 (0x2)
"RegSrvc"=2 (0x2)
"PnkBstrA"=2 (0x2)
"OwnershipProtocol"=2 (0x2)
"idsvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"EvtEng"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"ACS"=2 (0x2)
"ERSvc"=2 (0x2)
"WebClient"=2 (0x2)
"SysmonLog"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"SCardSvr"=3 (0x3)
"PolicyAgent"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"BITS"=3 (0x3)
"lanmanserver"=2 (0x2)
"seclogon"=2 (0x2)
"cisvc"=3 (0x3)
"upnphost"=3 (0x3)
"WmiApSrv"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\Jakub\\Local Settings\\Data aplikací\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\EA Games\\Battlefield Heroes\\BFHeroes.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [24.3.2011 23:09 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [24.3.2011 23:09 314456]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2.1.2012 20:45 32768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [24.3.2011 23:09 20568]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\Spyware Terminator\st_rsser.exe [2.1.2012 20:44 482992]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [3.7.2009 11:40 9216]
R3 AVerHybrid;AVerMedia Hybrid Tuner (NTSC/PAL/SECAM/DVB-T/FM);c:\windows\system32\drivers\averhbtv.sys [24.3.2011 23:28 302848]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [27.1.2012 21:15 112640]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
IE: Crawler Search - tbr:iemenu
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\35j97ap1.default\
FF - prefs.js: browser.startup.homepage - www.centrum.cz
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-27 21:48
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1080)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
- - - - - - - > 'explorer.exe'(2344)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Intel\Wireless\Bin\ZcfgSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2012-01-27 21:53:20 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-27 20:53
ComboFix2.txt 2012-01-26 22:19
ComboFix3.txt 2011-12-01 19:37
.
Před spuštěním: Volných bajtů: 23 105 196 032
Po spuštění: Volných bajtů: 23 086 342 144
.
- - End Of File - - 54665416BF779B5F7274BAB2DFD661DD
ComboFix 12-01-26.03 - Jakub 27.01.2012 21:33:24.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.510.249 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jakub\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Jakub\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.79\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.79\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.79\goopdate.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.79\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.79\psmachine.dll
c:\program files\Google\Update\1.3.21.79\psuser.dll
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.79\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{74AF07D8-FB8F-4D51-8AC7-927721D56EBB}\0.0.0.0\GoogleEarth-Win-Bundle-6.1.0.5001.exe
c:\program files\Google\Update\Download\{9BDB8132-624C-4E4B-9490-7D905987967E}\GoogleUpdateSetup.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\windows\host32.exe
c:\windows\svchost.dll
c:\windows\system32\accies98.dll
c:\windows\system32\arprmdg0.dll
c:\windows\system32\avload32.dll
c:\windows\system32\avpe32.dll
c:\windows\system32\avpx32.dll
c:\windows\system32\axxt32.dll
c:\windows\system32\bmtdhh.dll
c:\windows\system32\browsemu.dll
c:\windows\system32\bt848rom.dll
c:\windows\system32\clbdll.dll
c:\windows\system32\directpt.dll
c:\windows\system32\directut.dll
c:\windows\system32\dll.dll
c:\windows\system32\docent0.dll
c:\windows\system32\docent2.dll
c:\windows\system32\dvd4free.dll
c:\windows\system32\dxtpdx.dll
c:\windows\system32\extxerox.dll
c:\windows\system32\hpprintx.dll
c:\windows\system32\iesdl4l.dll
c:\windows\system32\KernelDrv.exe
c:\windows\system32\kernelwind32.exe
c:\windows\system32\ksapgh.dll
c:\windows\system32\lanmui.dll
c:\windows\system32\mmx4xt.dll
c:\windows\system32\msindeo.dll
c:\windows\system32\msliksurcredo.dll
c:\windows\system32\msliksurdns.dll
c:\windows\system32\Mspdnx.dll
c:\windows\system32\msvcrl.dll
c:\windows\system32\ntos.exe
c:\windows\system32\obbn13t.dll
c:\windows\system32\pasksa.dll
c:\windows\system32\pptp16.dll
c:\windows\system32\pptp32.dll
c:\windows\system32\qo.dll
c:\windows\system32\satdll.dll
c:\windows\system32\scsiusr4.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\se500mdm.dll
c:\windows\system32\tcpwrk.dll
c:\windows\system32\twext.exe
c:\windows\system32\xptptt.dll
c:\windows\system32\yvpp01.dll
c:\windows\system32\yvsvga.dll
c:\windows\system32\zopenssl.dll
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-27 do 2012-01-27 )))))))))))))))))))))))))))))))
.
.
2012-01-27 20:21 . 2012-01-27 20:21 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\FLEXnet
2012-01-27 20:15 . 2009-06-29 17:00 112640 ----a-r- c:\windows\system32\drivers\ewusbnet.sys
2012-01-27 20:14 . 2009-04-09 12:38 102400 ----a-r- c:\windows\system32\drivers\ewusbmdm.sys
2012-01-27 20:14 . 2008-04-13 18:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2012-01-27 20:14 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-01-27 20:13 . 2012-01-27 20:13 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Vodafone
2012-01-27 20:13 . 2012-01-27 20:13 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Vodafone
2012-01-27 20:13 . 2012-01-27 20:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Vodafone
2012-01-27 20:12 . 2012-01-27 20:12 -------- d-----w- c:\program files\Vodafone
2012-01-27 20:12 . 2012-01-27 20:12 -------- d-----w- c:\documents and settings\All Users\Data aplikací\FLEXnet
2012-01-27 20:12 . 2012-01-27 20:12 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\{6118B561-4CCF-4F70-B358-73ACA4B8FB39}
2012-01-27 19:59 . 2012-01-27 19:59 -------- d--h--w- c:\windows\PIF
2012-01-26 22:40 . 2012-01-26 22:40 -------- d-----w- c:\program files\trend micro
2012-01-26 22:40 . 2012-01-26 22:40 -------- d-----w- C:\rsit
2012-01-09 16:46 . 2012-01-09 16:46 43992 ----a-w- c:\program files\Mozilla Firefox\mozutils.dll
2012-01-09 16:46 . 2012-01-09 16:46 548864 ----a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-09 16:46 . 2012-01-09 16:46 479232 ----a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-09 16:46 . 2012-01-09 16:46 626688 ----a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-07 16:46 . 2012-01-16 18:15 270240 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-01-02 19:45 . 2011-06-21 10:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2012-01-02 19:45 . 2012-01-02 19:45 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Spyware Terminator
2012-01-02 19:45 . 2012-01-27 19:54 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spyware Terminator
2012-01-02 19:42 . 2012-01-11 17:41 -------- d-----w- c:\program files\Spyware Terminator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-16 18:15 . 2011-09-25 17:13 270240 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-01-16 17:54 . 2011-12-11 18:19 139080 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-01-16 17:53 . 2011-12-11 18:18 270240 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-12-11 18:17 . 2011-09-25 17:00 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-12-11 15:24 . 2011-09-25 17:01 138056 ----a-w- c:\documents and settings\Jakub\Data aplikací\PnkBstrK.sys
2011-11-28 18:01 . 2011-03-24 22:08 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-03-24 22:08 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-03-24 22:09 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-03-24 22:09 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-03-24 22:09 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-03-24 22:09 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-03-24 22:09 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2011-03-24 22:09 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2011-03-24 22:09 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2011-03-24 22:09 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2001-10-25 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2001-10-25 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2001-10-25 12:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2011-03-24 21:28 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2001-10-25 12:00 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-03 15:29 . 2001-10-25 12:00 386560 ----a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:29 . 2001-10-25 12:00 1294848 ----a-w- c:\windows\system32\quartz.dll
2011-11-01 20:36 . 2011-03-24 21:28 81920 ------w- c:\windows\system32\ieencode.dll
2011-11-01 20:36 . 2001-10-25 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
2011-11-01 20:36 . 2001-10-25 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:34 . 2011-03-24 21:28 370176 ------w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2001-10-25 12:00 1288192 ----a-w- c:\windows\system32\ole32.dll
2012-01-09 16:46 . 2011-10-06 16:00 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-01-26_22.14.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-12-01 23:08 . 2006-12-01 23:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 23:08 . 2006-12-01 23:08 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 23:26 . 2006-12-01 23:26 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-01 23:25 . 2006-12-01 23:25 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2012-01-27 20:13 . 2009-04-09 12:38 24448 c:\windows\system32\DRVSTORE\ewdcsc_DA2777CB9188B1F25A999918A47509FC693296FD\ewdcsc.sys
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\VodafoneConnectionMa_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\SMS_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\NewShortcut9_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\NewShortcut8_B9D0823E49B04B5B9B0C5415624F0666.exe
+ 2012-01-27 20:13 . 2012-01-27 20:13 73728 c:\windows\Installer\{79A64F98-1796-4FA2-B5FF-C90F83D8BACD}\ARPPRODUCTICON.exe
+ 2006-12-01 21:54 . 2006-12-01 21:54 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-01 21:54 . 2006-12-01 21:54 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 21:54 . 2006-12-01 21:54 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2012-01-27 20:13 . 2009-04-09 12:38 621056 c:\windows\system32\DRVSTORE\mod7700_8C17870443A1EF4AA2DF3F4C259AD7DC9CE429DF\mod7700.sys
+ 2012-01-27 20:13 . 2009-04-09 12:38 102400 c:\windows\system32\DRVSTORE\ewser2k_BC96AE4EE9BF303EB19EDF9739A7EEB2DC612150\ewusbmdm.sys
+ 2012-01-27 20:13 . 2009-06-29 17:00 112640 c:\windows\system32\DRVSTORE\ewnet_23B357679E08714ADCBF3A5454C2DD9FE47FCEB1\ewusbnet.sys
+ 2012-01-27 20:13 . 2009-04-09 12:38 102400 c:\windows\system32\DRVSTORE\ewmdm2k_9D926F5881D46CBE167A3483FECC88FAFEB6AEDC\ewusbmdm.sys
+ 2012-01-27 20:13 . 2009-06-29 17:00 102656 c:\windows\system32\DRVSTORE\ewfake_1FBF9D50C5288ED070EF7C836A0A8FBE8BDC2E59\ewusbfake.sys
+ 2006-12-01 23:25 . 2006-12-01 23:25 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-01 23:25 . 2006-12-01 23:25 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2012-01-27 20:13 . 2012-01-27 20:13 2326016 c:\windows\Installer\a7080.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-24 2880512]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"SpywareTerminatorShield"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2011-12-23 2779824]
"SpywareTerminatorUpdater"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-12-23 3621040]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 188416]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2009-07-03 2328576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 10:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^AVerQuick.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk
backup=c:\windows\pss\AVerQuick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acerWireless]
2004-06-09 10:15 417792 ----a-w- c:\program files\acer\Wireless\Utility\wlanutil.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACU]
2005-01-31 07:05 253952 ----a-w- c:\program files\Atheros\ACU.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-04-28 20:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp]
2004-10-15 10:31 356352 ----a-w- c:\program files\Intel\Wireless\Bin\EOUWiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
2007-07-11 14:09 20480 ----a-w- c:\windows\FixCamera.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2011-09-14 16:01 243360 ----a-w- c:\windows\system32\Macromed\Flash\FlashUtil10w_Plugin.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-08-01 08:28 124480 ----a-w- c:\program files\ICQ7.5\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2004-10-15 10:27 385024 ----a-w- c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2005-09-05 10:43 319488 ----a-w- c:\program files\Launch Manager\QtZgAcer.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:22 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-09-01 12:39 966712 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3]
2009-02-26 15:08 593920 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\fppdis3a.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
2006-01-06 11:57 344064 ----a-w- c:\windows\vsnp2std.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2011-12-23 02:42 3621040 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
2006-01-06 15:39 110592 ----a-w- c:\windows\tsnp2std.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)
"ServiceLayer"=3 (0x3)
"S24EventMonitor"=2 (0x2)
"RegSrvc"=2 (0x2)
"PnkBstrA"=2 (0x2)
"OwnershipProtocol"=2 (0x2)
"idsvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"EvtEng"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"ACS"=2 (0x2)
"ERSvc"=2 (0x2)
"WebClient"=2 (0x2)
"SysmonLog"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"SCardSvr"=3 (0x3)
"PolicyAgent"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"BITS"=3 (0x3)
"lanmanserver"=2 (0x2)
"seclogon"=2 (0x2)
"cisvc"=3 (0x3)
"upnphost"=3 (0x3)
"WmiApSrv"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\Jakub\\Local Settings\\Data aplikací\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\EA Games\\Battlefield Heroes\\BFHeroes.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [24.3.2011 23:09 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [24.3.2011 23:09 314456]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2.1.2012 20:45 32768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [24.3.2011 23:09 20568]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\Spyware Terminator\st_rsser.exe [2.1.2012 20:44 482992]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [3.7.2009 11:40 9216]
R3 AVerHybrid;AVerMedia Hybrid Tuner (NTSC/PAL/SECAM/DVB-T/FM);c:\windows\system32\drivers\averhbtv.sys [24.3.2011 23:28 302848]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [27.1.2012 21:15 112640]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
IE: Crawler Search - tbr:iemenu
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\35j97ap1.default\
FF - prefs.js: browser.startup.homepage - www.centrum.cz
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-27 21:48
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1080)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
- - - - - - - > 'explorer.exe'(2344)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Intel\Wireless\Bin\ZcfgSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2012-01-27 21:53:20 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-27 20:53
ComboFix2.txt 2012-01-26 22:19
ComboFix3.txt 2011-12-01 19:37
.
Před spuštěním: Volných bajtů: 23 105 196 032
Po spuštění: Volných bajtů: 23 086 342 144
.
- - End Of File - - 54665416BF779B5F7274BAB2DFD661DD
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Bylo toho tam ještě dost, ale CF vše smazal. Chová se nyní PC normálně?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu logu
Dobrý večer,
taky jsem koukal kolik se toho tam ještě objevilo, ale PC se zatím chová v pohodě, tak uvidíme, kdyžtak dám vědět. Každopádně mnohokrát děkuji
taky jsem koukal kolik se toho tam ještě objevilo, ale PC se zatím chová v pohodě, tak uvidíme, kdyžtak dám vědět. Každopádně mnohokrát děkuji

- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Prosím o kontrolu logu
Ještě se mi počítač a hlavně firefox zdá pomalejší než dřív, zkuste prosím ještě kouknout na log z RSIT, jestli tam něco není, předem díky...
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jakub at 2012-01-29 20:08:23
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (60%) free of 36 GB
Total RAM: 510 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:09:09, on 29.1.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\acer\epm\epm-dm.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Program Files\IObit\Game Booster 3\gbtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jakub\Plocha\RSIT.exe
C:\Program Files\trend micro\Jakub.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SpywareTerminatorShield] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files\Spyware Terminator\st_rsser.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
--
End of file - 4504 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\35j97ap1.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=C:\PROGRA~1\Crawler\Toolbar\firefox\
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\35j97ap1.default\extensions\
2020Player_IKEA@2020Technologies.com
battlefieldheroespatcher@ea.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
&Crawler Toolbar Helper - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2011-04-01 1232520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2011-04-01 1232520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ePowerManagement"=C:\Acer\ePM\ePM.exe [2005-03-24 2880512]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]
"SpywareTerminatorShield"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-12-23 2779824]
"SpywareTerminatorUpdater"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-12-23 3621040]
"EPM-DM"=c:\acer\epm\epm-dm.exe [2005-03-28 188416]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acerWireless]
C:\Program Files\acer\Wireless\Utility\WlanUtil.exe [2004-06-09 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACU]
C:\Program Files\Atheros\ACU.exe [2005-01-31 253952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04-28 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp]
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe [2004-10-15 356352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
C:\WINDOWS\FixCamera.exe [2007-07-11 20480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\FlashUtil10w_Plugin.exe [2011-09-14 243360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.5\ICQ.exe [2011-08-01 124480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2004-10-15 385024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
C:\Program Files\Launch Manager\QtZgAcer.EXE [2005-09-05 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2011-09-01 966712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2009-02-26 593920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
C:\WINDOWS\vsnp2std.exe [2006-01-06 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-12-23 3621040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
C:\WINDOWS\tsnp2std.exe [2006-01-06 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2005-09-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^AVerQuick.lnk]
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERQU~2.EXE [2007-04-17 614400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2
"ServiceLayer"=3
"S24EventMonitor"=2
"RegSrvc"=2
"PnkBstrA"=2
"OwnershipProtocol"=2
"idsvc"=3
"gupdatem"=3
"gupdate"=2
"EvtEng"=2
"Ati HotKey Poller"=2
"ACS"=2
"ERSvc"=2
"WebClient"=2
"SysmonLog"=3
"RemoteRegistry"=2
"RDSessMgr"=3
"SCardSvr"=3
"PolicyAgent"=2
"WmdmPmSN"=3
"SSDPSRV"=3
"srservice"=2
"BITS"=3
"lanmanserver"=2
"seclogon"=2
"cisvc"=3
"upnphost"=3
"WmiApSrv"=3
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-04-28 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [2004-10-15 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Disabled:Nokia Ovi Suite"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Documents and Settings\Jakub\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe"="C:\Documents and Settings\Jakub\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin"
"C:\Program Files\EA Games\Battlefield Heroes\BFHeroes.exe"="C:\Program Files\EA Games\Battlefield Heroes\BFHeroes.exe:*:Enabled:BFHeroes.exe"
"C:\Program Files\Spyware Terminator\SpywareTerminator.exe"="C:\Program Files\Spyware Terminator\SpywareTerminator.exe:*:Enabled:Spyware Terminator 2012"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Spyware Terminator 2012"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\System32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"wave2"=wdmaud.drv
"wave3"=wdmaud.drv
"wave4"=wdmaud.drv
"wave5"=wdmaud.drv
"wave6"=wdmaud.drv
"wave7"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-01-28 17:27:23 ----SHD---- C:\RECYCLER
2012-01-27 21:55:37 ----RA---- C:\WINDOWS\system32\drivers\ewusbfake.sys
2012-01-27 21:53:22 ----A---- C:\ComboFix.txt
2012-01-27 21:21:13 ----D---- C:\Documents and Settings\Jakub\Data aplikací\FLEXnet
2012-01-27 21:15:07 ----RA---- C:\WINDOWS\system32\drivers\ewusbnet.sys
2012-01-27 21:14:59 ----RA---- C:\WINDOWS\system32\drivers\ewusbmdm.sys
2012-01-27 21:14:41 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2012-01-27 21:13:56 ----D---- C:\Documents and Settings\Jakub\Data aplikací\Vodafone
2012-01-27 21:13:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Vodafone
2012-01-27 21:12:40 ----D---- C:\Program Files\Vodafone
2012-01-27 21:12:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\FLEXnet
2012-01-27 20:59:07 ----HD---- C:\WINDOWS\PIF
2012-01-26 23:40:43 ----D---- C:\Program Files\trend micro
2012-01-26 23:40:41 ----D---- C:\rsit
2012-01-12 20:35:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-01-12 20:35:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2012-01-12 20:34:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-01-12 20:20:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-01-12 20:20:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-01-12 20:20:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-01-07 17:46:40 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2012-01-02 20:45:06 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2012-01-02 20:45:02 ----D---- C:\Documents and Settings\Jakub\Data aplikací\Spyware Terminator
2012-01-02 20:45:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2012-01-02 20:42:31 ----D---- C:\Program Files\Spyware Terminator
======List of files/folders modified in the last 1 month======
2012-01-29 20:03:51 ----D---- C:\WINDOWS
2012-01-29 19:56:22 ----D---- C:\WINDOWS\system32\CatRoot2
2012-01-29 19:56:17 ----D---- C:\WINDOWS\Prefetch
2012-01-29 18:01:22 ----D---- C:\WINDOWS\Temp
2012-01-29 11:21:54 ----D---- C:\WINDOWS\system32
2012-01-28 19:18:13 ----D---- C:\Documents and Settings\Jakub\Data aplikací\ICQ
2012-01-27 21:55:37 ----D---- C:\WINDOWS\system32\drivers
2012-01-27 21:53:29 ----D---- C:\Qoobox
2012-01-27 21:52:22 ----SD---- C:\WINDOWS\Tasks
2012-01-27 21:48:32 ----N---- C:\WINDOWS\system.ini
2012-01-27 21:47:39 ----D---- C:\WINDOWS\system32\drivers\etc
2012-01-27 21:45:32 ----D---- C:\WINDOWS\system32\config
2012-01-27 21:45:20 ----D---- C:\WINDOWS\ERDNT
2012-01-27 21:39:15 ----D---- C:\WINDOWS\AppPatch
2012-01-27 21:38:53 ----D---- C:\Program Files\Common Files
2012-01-27 21:21:11 ----RD---- C:\Program Files
2012-01-27 21:14:58 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-01-27 21:14:34 ----HD---- C:\WINDOWS\inf
2012-01-27 21:13:54 ----SHD---- C:\WINDOWS\Installer
2012-01-27 21:13:40 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-01-27 21:12:47 ----D---- C:\WINDOWS\WinSxS
2012-01-26 23:30:41 ----D---- C:\temp
2012-01-15 11:58:39 ----D---- C:\WINDOWS\Debug
2012-01-12 20:21:36 ----A---- C:\WINDOWS\system32\MRT.exe
2012-01-12 20:20:30 ----HD---- C:\WINDOWS\$hf_mig$
2012-01-09 17:46:55 ----D---- C:\Program Files\Mozilla Firefox
2012-01-06 17:36:22 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-06 17:36:19 ----RSD---- C:\WINDOWS\assembly
2012-01-05 20:25:46 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2011-03-24 17801]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R2 EpmPsd;Acer EPM Power Scheme Driver; \??\C:\WINDOWS\system32\drivers\epm-psd.sys []
R2 EpmShd;Acer EPM System Hardware Driver; \??\C:\WINDOWS\system32\drivers\epm-shd.sys []
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2004-10-15 11354]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-04-28 1132544]
R3 AVerHybrid;AVerMedia Hybrid Tuner (NTSC/PAL/SECAM/DVB-T/FM); C:\WINDOWS\system32\drivers\averhbtv.sys [2007-04-30 302848]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2003-09-26 44032]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camcaud.sys [2004-06-25 34048]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camchal.sys [2004-06-25 276480]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2005-09-05 16896]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-01-25 1038208]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2005-01-25 207616]
R3 IWCA;Intel Wireless Connection Agent Miniport for Win XP; C:\WINDOWS\system32\DRIVERS\iwca.sys [2004-08-12 234496]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w29n51;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2004-10-29 3222784]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-01-25 703616]
S3 akshasp;Aladdin HASP Key; C:\WINDOWS\system32\DRIVERS\akshasp.sys [2006-11-22 327168]
S3 aksusb;Aladdin USB Key; C:\WINDOWS\system32\DRIVERS\aksusb.sys [2006-11-22 100096]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ewusbnet.sys [2009-06-29 112640]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-04-09 102400]
S3 hwusbfake;Huawei DataCard USB Fake; C:\WINDOWS\system32\DRIVERS\ewusbfake.sys [2009-06-29 102656]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2011-05-18 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2011-05-18 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2006-05-13 10305664]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2011-05-18 8192]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2011-05-18 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-12-11 75136]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files\Spyware Terminator\st_rsser.exe [2011-12-23 482992]
R2 VMCService;Vodafone Mobile Connect Service; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2009-07-03 9216]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S4 ACS;Atheros Configuration Service; C:\WINDOWS\system32\acs.exe [2004-12-27 36864]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-04-28 364544]
S4 EvtEng;EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2004-10-15 86016]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 OwnershipProtocol;OwnershipProtocol; C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe [2004-10-15 98304]
S4 RegSrvc;RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2004-10-15 139264]
S4 S24EventMonitor;Spectrum24 Event Monitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2004-10-15 360521]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jakub at 2012-01-29 20:08:23
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (60%) free of 36 GB
Total RAM: 510 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:09:09, on 29.1.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\acer\epm\epm-dm.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Program Files\IObit\Game Booster 3\gbtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jakub\Plocha\RSIT.exe
C:\Program Files\trend micro\Jakub.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SpywareTerminatorShield] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files\Spyware Terminator\st_rsser.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
--
End of file - 4504 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\35j97ap1.default
prefs.js - "browser.startup.homepage" - "www.centrum.cz"
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=C:\PROGRA~1\Crawler\Toolbar\firefox\
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\35j97ap1.default\extensions\
2020Player_IKEA@2020Technologies.com
battlefieldheroespatcher@ea.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
&Crawler Toolbar Helper - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2011-04-01 1232520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2011-04-01 1232520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ePowerManagement"=C:\Acer\ePM\ePM.exe [2005-03-24 2880512]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]
"SpywareTerminatorShield"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-12-23 2779824]
"SpywareTerminatorUpdater"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-12-23 3621040]
"EPM-DM"=c:\acer\epm\epm-dm.exe [2005-03-28 188416]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acerWireless]
C:\Program Files\acer\Wireless\Utility\WlanUtil.exe [2004-06-09 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACU]
C:\Program Files\Atheros\ACU.exe [2005-01-31 253952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04-28 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp]
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe [2004-10-15 356352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
C:\WINDOWS\FixCamera.exe [2007-07-11 20480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\FlashUtil10w_Plugin.exe [2011-09-14 243360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.5\ICQ.exe [2011-08-01 124480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2004-10-15 385024]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
C:\Program Files\Launch Manager\QtZgAcer.EXE [2005-09-05 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2011-09-01 966712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfFactory Dispatcher v3]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2009-02-26 593920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
C:\WINDOWS\vsnp2std.exe [2006-01-06 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-12-23 3621040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
C:\WINDOWS\tsnp2std.exe [2006-01-06 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2005-09-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^AVerQuick.lnk]
C:\PROGRA~1\COMMON~1\AVERME~1\AVERQU~1\AVERQU~2.EXE [2007-04-17 614400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2
"ServiceLayer"=3
"S24EventMonitor"=2
"RegSrvc"=2
"PnkBstrA"=2
"OwnershipProtocol"=2
"idsvc"=3
"gupdatem"=3
"gupdate"=2
"EvtEng"=2
"Ati HotKey Poller"=2
"ACS"=2
"ERSvc"=2
"WebClient"=2
"SysmonLog"=3
"RemoteRegistry"=2
"RDSessMgr"=3
"SCardSvr"=3
"PolicyAgent"=2
"WmdmPmSN"=3
"SSDPSRV"=3
"srservice"=2
"BITS"=3
"lanmanserver"=2
"seclogon"=2
"cisvc"=3
"upnphost"=3
"WmiApSrv"=3
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-04-28 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [2004-10-15 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe"="C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe:*:Disabled:Nokia Ovi Suite"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Documents and Settings\Jakub\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe"="C:\Documents and Settings\Jakub\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin"
"C:\Program Files\EA Games\Battlefield Heroes\BFHeroes.exe"="C:\Program Files\EA Games\Battlefield Heroes\BFHeroes.exe:*:Enabled:BFHeroes.exe"
"C:\Program Files\Spyware Terminator\SpywareTerminator.exe"="C:\Program Files\Spyware Terminator\SpywareTerminator.exe:*:Enabled:Spyware Terminator 2012"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Spyware Terminator 2012"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\System32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"wave2"=wdmaud.drv
"wave3"=wdmaud.drv
"wave4"=wdmaud.drv
"wave5"=wdmaud.drv
"wave6"=wdmaud.drv
"wave7"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-01-28 17:27:23 ----SHD---- C:\RECYCLER
2012-01-27 21:55:37 ----RA---- C:\WINDOWS\system32\drivers\ewusbfake.sys
2012-01-27 21:53:22 ----A---- C:\ComboFix.txt
2012-01-27 21:21:13 ----D---- C:\Documents and Settings\Jakub\Data aplikací\FLEXnet
2012-01-27 21:15:07 ----RA---- C:\WINDOWS\system32\drivers\ewusbnet.sys
2012-01-27 21:14:59 ----RA---- C:\WINDOWS\system32\drivers\ewusbmdm.sys
2012-01-27 21:14:41 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2012-01-27 21:13:56 ----D---- C:\Documents and Settings\Jakub\Data aplikací\Vodafone
2012-01-27 21:13:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Vodafone
2012-01-27 21:12:40 ----D---- C:\Program Files\Vodafone
2012-01-27 21:12:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\FLEXnet
2012-01-27 20:59:07 ----HD---- C:\WINDOWS\PIF
2012-01-26 23:40:43 ----D---- C:\Program Files\trend micro
2012-01-26 23:40:41 ----D---- C:\rsit
2012-01-12 20:35:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-01-12 20:35:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2012-01-12 20:34:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-01-12 20:20:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-01-12 20:20:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-01-12 20:20:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-01-07 17:46:40 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2012-01-02 20:45:06 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2012-01-02 20:45:02 ----D---- C:\Documents and Settings\Jakub\Data aplikací\Spyware Terminator
2012-01-02 20:45:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2012-01-02 20:42:31 ----D---- C:\Program Files\Spyware Terminator
======List of files/folders modified in the last 1 month======
2012-01-29 20:03:51 ----D---- C:\WINDOWS
2012-01-29 19:56:22 ----D---- C:\WINDOWS\system32\CatRoot2
2012-01-29 19:56:17 ----D---- C:\WINDOWS\Prefetch
2012-01-29 18:01:22 ----D---- C:\WINDOWS\Temp
2012-01-29 11:21:54 ----D---- C:\WINDOWS\system32
2012-01-28 19:18:13 ----D---- C:\Documents and Settings\Jakub\Data aplikací\ICQ
2012-01-27 21:55:37 ----D---- C:\WINDOWS\system32\drivers
2012-01-27 21:53:29 ----D---- C:\Qoobox
2012-01-27 21:52:22 ----SD---- C:\WINDOWS\Tasks
2012-01-27 21:48:32 ----N---- C:\WINDOWS\system.ini
2012-01-27 21:47:39 ----D---- C:\WINDOWS\system32\drivers\etc
2012-01-27 21:45:32 ----D---- C:\WINDOWS\system32\config
2012-01-27 21:45:20 ----D---- C:\WINDOWS\ERDNT
2012-01-27 21:39:15 ----D---- C:\WINDOWS\AppPatch
2012-01-27 21:38:53 ----D---- C:\Program Files\Common Files
2012-01-27 21:21:11 ----RD---- C:\Program Files
2012-01-27 21:14:58 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-01-27 21:14:34 ----HD---- C:\WINDOWS\inf
2012-01-27 21:13:54 ----SHD---- C:\WINDOWS\Installer
2012-01-27 21:13:40 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-01-27 21:12:47 ----D---- C:\WINDOWS\WinSxS
2012-01-26 23:30:41 ----D---- C:\temp
2012-01-15 11:58:39 ----D---- C:\WINDOWS\Debug
2012-01-12 20:21:36 ----A---- C:\WINDOWS\system32\MRT.exe
2012-01-12 20:20:30 ----HD---- C:\WINDOWS\$hf_mig$
2012-01-09 17:46:55 ----D---- C:\Program Files\Mozilla Firefox
2012-01-06 17:36:22 ----D---- C:\WINDOWS\Microsoft.NET
2012-01-06 17:36:19 ----RSD---- C:\WINDOWS\assembly
2012-01-05 20:25:46 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2011-03-24 17801]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R2 EpmPsd;Acer EPM Power Scheme Driver; \??\C:\WINDOWS\system32\drivers\epm-psd.sys []
R2 EpmShd;Acer EPM System Hardware Driver; \??\C:\WINDOWS\system32\drivers\epm-shd.sys []
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2004-10-15 11354]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-04-28 1132544]
R3 AVerHybrid;AVerMedia Hybrid Tuner (NTSC/PAL/SECAM/DVB-T/FM); C:\WINDOWS\system32\drivers\averhbtv.sys [2007-04-30 302848]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2003-09-26 44032]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camcaud.sys [2004-06-25 34048]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camchal.sys [2004-06-25 276480]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2005-09-05 16896]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-01-25 1038208]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2005-01-25 207616]
R3 IWCA;Intel Wireless Connection Agent Miniport for Win XP; C:\WINDOWS\system32\DRIVERS\iwca.sys [2004-08-12 234496]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w29n51;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2004-10-29 3222784]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-01-25 703616]
S3 akshasp;Aladdin HASP Key; C:\WINDOWS\system32\DRIVERS\akshasp.sys [2006-11-22 327168]
S3 aksusb;Aladdin USB Key; C:\WINDOWS\system32\DRIVERS\aksusb.sys [2006-11-22 100096]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\WINDOWS\system32\DRIVERS\ewusbnet.sys [2009-06-29 112640]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2009-04-09 102400]
S3 hwusbfake;Huawei DataCard USB Fake; C:\WINDOWS\system32\DRIVERS\ewusbfake.sys [2009-06-29 102656]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2011-05-18 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2011-05-18 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2006-05-13 10305664]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2011-05-18 8192]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2011-05-18 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-12-11 75136]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files\Spyware Terminator\st_rsser.exe [2011-12-23 482992]
R2 VMCService;Vodafone Mobile Connect Service; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2009-07-03 9216]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S4 ACS;Atheros Configuration Service; C:\WINDOWS\system32\acs.exe [2004-12-27 36864]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-04-28 364544]
S4 EvtEng;EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2004-10-15 86016]
S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 OwnershipProtocol;OwnershipProtocol; C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe [2004-10-15 98304]
S4 RegSrvc;RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2004-10-15 139264]
S4 S24EventMonitor;Spectrum24 Event Monitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2004-10-15 360521]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119515
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Zkuste:
1. Reinstalovat FF pomocí MozBackup: http://www.stahuj.centrum.cz/utility_a_ ... mozbackup/ .
2. PC vyčistěte od balastu CCleanerem: http://forum.viry.cz/viewtopic.php?f=46&t=7478 .
1. Reinstalovat FF pomocí MozBackup: http://www.stahuj.centrum.cz/utility_a_ ... mozbackup/ .
2. PC vyčistěte od balastu CCleanerem: http://forum.viry.cz/viewtopic.php?f=46&t=7478 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.