Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

preventivni log

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zpráva
Autor
jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

preventivni log

#1 Příspěvek od jacktenrek »

Zdravím se mě tu objevil nejaky šmejd stdrt.exe :???: dám log s rsit děkuji za Vaše rady :worship:



Logfile of random's system information tool 1.09 (written by random/random)
Run by natsof at 2012-07-24 18:02:42
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 69 GB (69%) free of 100 GB
Total RAM: 3328 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:02:52, on 24.7.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Comodo\COMODO Internet Security\cfp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files\UnHackMe\Unhackme.exe
C:\Program Files\UnHackMe\hackmon.exe
C:\Program Files\UnHackMe\reanimator.exe
C:\Program Files\UnHackMe\regruninfo.exe
C:\Users\natsof\AppData\Local\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\natsof.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: (no name) - {BC1A4275-EBD7-C096-4DF4-0F02699F086C} - (no file)
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
O4 - HKLM\..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 4185 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC1A4275-EBD7-C096-4DF4-0F02699F086C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetPacks Browser Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-06-04 1310040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetPacks Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-06-04 1310040]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO"=C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe [2011-11-23 208184]
"CPA"=C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe [2011-11-23 182584]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2011-12-19 6676808]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-07-03 17417392]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun-"=0
"NoDriveTypeAutoRun-"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=253

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun-"=0
"NoDriveTypeAutoRun-"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=253

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-07-24 18:02:44 ----D---- C:\Program Files\trend micro
2012-07-24 18:02:42 ----D---- C:\rsit
2012-07-24 17:59:25 ----A---- C:\Windows\system32\drivers\regguard.sys
2012-07-24 17:53:45 ----A---- C:\Windows\system32\drivers\UnHackMeDrv.sys
2012-07-24 17:53:37 ----D---- C:\Program Files\UnHackMe
2012-07-24 11:46:04 ----A---- C:\Windows\system32\PARTIZAN.TXT
2012-07-24 11:44:46 ----A---- C:\Windows\system32\Partizan.exe
2012-07-24 11:44:46 ----A---- C:\Windows\system32\drivers\Partizan.sys
2012-07-24 11:43:11 ----D---- C:\ProgramData\RegRun
2012-07-24 11:43:07 ----RSHD---- C:\desktop.ini
2012-07-24 11:43:07 ----RSHD---- C:\comment.htt
2012-07-24 11:43:07 ----RSHD---- C:\autorun.inf
2012-07-24 11:42:37 ----RASHOT---- C:\Windows\winstart.bat
2012-07-24 11:36:36 ----A---- C:\Windows\RunGuard.exe
2012-07-24 11:36:35 ----A---- C:\Windows\WinBait.exe
2012-07-24 11:35:16 ----D---- C:\Program Files\Greatis
2012-07-23 11:24:01 ----A---- C:\Windows\system32\XAudio2_7.dll
2012-07-23 11:24:01 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2012-07-23 11:24:01 ----A---- C:\Windows\system32\xactengine3_7.dll
2012-07-23 11:24:01 ----A---- C:\Windows\system32\d3dx11_43.dll
2012-07-23 11:24:01 ----A---- C:\Windows\system32\d3dcsx_43.dll
2012-07-23 11:24:01 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2012-07-23 11:24:00 ----A---- C:\Windows\system32\XAudio2_6.dll
2012-07-23 11:24:00 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2012-07-23 11:24:00 ----A---- C:\Windows\system32\D3DX9_43.dll
2012-07-23 11:24:00 ----A---- C:\Windows\system32\d3dx10_43.dll
2012-07-23 11:23:59 ----A---- C:\Windows\system32\XAudio2_5.dll
2012-07-23 11:23:59 ----A---- C:\Windows\system32\xactengine3_6.dll
2012-07-23 11:23:59 ----A---- C:\Windows\system32\xactengine3_5.dll
2012-07-23 11:23:59 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2012-07-23 11:23:58 ----A---- C:\Windows\system32\d3dcsx_42.dll
2012-07-23 11:23:58 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2012-07-23 11:23:57 ----A---- C:\Windows\system32\D3DX9_42.dll
2012-07-23 11:23:57 ----A---- C:\Windows\system32\d3dx11_42.dll
2012-07-23 11:23:57 ----A---- C:\Windows\system32\d3dx10_42.dll
2012-07-23 11:23:57 ----A---- C:\Windows\system32\d3dx10_41.dll
2012-07-23 11:23:57 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2012-07-23 11:23:56 ----A---- C:\Windows\system32\XAudio2_4.dll
2012-07-23 11:23:56 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2012-07-23 11:23:56 ----A---- C:\Windows\system32\xactengine3_4.dll
2012-07-23 11:23:56 ----A---- C:\Windows\system32\D3DX9_41.dll
2012-07-23 11:23:55 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2012-07-23 11:23:55 ----A---- C:\Windows\system32\D3DX9_40.dll
2012-07-23 11:23:55 ----A---- C:\Windows\system32\d3dx10_40.dll
2012-07-23 11:23:55 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2012-07-23 11:23:54 ----A---- C:\Windows\system32\XAudio2_3.dll
2012-07-23 11:23:54 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2012-07-23 11:23:54 ----A---- C:\Windows\system32\xactengine3_3.dll
2012-07-23 11:23:54 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2012-07-23 11:23:53 ----A---- C:\Windows\system32\XAudio2_2.dll
2012-07-23 11:23:53 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2012-07-23 11:23:53 ----A---- C:\Windows\system32\xactengine3_2.dll
2012-07-23 11:23:52 ----A---- C:\Windows\system32\D3DX9_39.dll
2012-07-23 11:23:52 ----A---- C:\Windows\system32\d3dx10_39.dll
2012-07-23 11:23:52 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2012-07-23 11:23:51 ----A---- C:\Windows\system32\XAudio2_1.dll
2012-07-23 11:23:51 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2012-07-23 11:23:51 ----A---- C:\Windows\system32\xactengine3_1.dll
2012-07-23 11:23:50 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2012-07-23 11:23:50 ----A---- C:\Windows\system32\d3dx10_38.dll
2012-07-23 11:23:50 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2012-07-23 11:23:49 ----A---- C:\Windows\system32\XAudio2_0.dll
2012-07-23 11:23:49 ----A---- C:\Windows\system32\D3DX9_38.dll
2012-07-23 11:23:48 ----A---- C:\Windows\system32\xactengine3_0.dll
2012-07-23 11:23:48 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2012-07-23 11:23:48 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2012-07-23 11:23:47 ----A---- C:\Windows\system32\xactengine2_10.dll
2012-07-23 11:23:47 ----A---- C:\Windows\system32\D3DX9_37.dll
2012-07-23 11:23:47 ----A---- C:\Windows\system32\d3dx10_37.dll
2012-07-23 11:23:45 ----A---- C:\Windows\system32\d3dx9_36.dll
2012-07-23 11:23:45 ----A---- C:\Windows\system32\d3dx10_36.dll
2012-07-23 11:23:45 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2012-07-23 11:23:44 ----A---- C:\Windows\system32\xactengine2_9.dll
2012-07-23 11:23:44 ----A---- C:\Windows\system32\d3dx10_35.dll
2012-07-23 11:23:44 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2012-07-23 11:23:43 ----A---- C:\Windows\system32\xactengine2_8.dll
2012-07-23 11:23:43 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2012-07-23 11:23:43 ----A---- C:\Windows\system32\d3dx9_35.dll
2012-07-23 11:23:42 ----A---- C:\Windows\system32\d3dx9_34.dll
2012-07-23 11:23:42 ----A---- C:\Windows\system32\d3dx10_34.dll
2012-07-23 11:23:42 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2012-07-23 11:23:41 ----A---- C:\Windows\system32\xinput1_3.dll
2012-07-23 11:23:41 ----A---- C:\Windows\system32\xactengine2_7.dll
2012-07-23 11:23:41 ----A---- C:\Windows\system32\d3dx10_33.dll
2012-07-23 11:23:41 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2012-07-23 11:23:40 ----A---- C:\Windows\system32\d3dx9_33.dll
2012-07-23 11:23:39 ----A---- C:\Windows\system32\xactengine2_6.dll
2012-07-23 11:23:39 ----A---- C:\Windows\system32\xactengine2_5.dll
2012-07-23 11:23:39 ----A---- C:\Windows\system32\d3dx10.dll
2012-07-23 11:23:38 ----A---- C:\Windows\system32\xactengine2_4.dll
2012-07-23 11:23:38 ----A---- C:\Windows\system32\x3daudio1_1.dll
2012-07-23 11:23:38 ----A---- C:\Windows\system32\d3dx9_32.dll
2012-07-23 11:23:38 ----A---- C:\Windows\system32\d3dx9_31.dll
2012-07-23 11:23:37 ----A---- C:\Windows\system32\xinput1_2.dll
2012-07-23 11:23:37 ----A---- C:\Windows\system32\xactengine2_3.dll
2012-07-23 11:23:37 ----A---- C:\Windows\system32\xactengine2_2.dll
2012-07-23 11:23:36 ----A---- C:\Windows\system32\xinput1_1.dll
2012-07-23 11:23:36 ----A---- C:\Windows\system32\xactengine2_1.dll
2012-07-23 11:23:26 ----A---- C:\Windows\system32\xactengine2_0.dll
2012-07-23 11:23:26 ----A---- C:\Windows\system32\x3daudio1_0.dll
2012-07-23 11:23:26 ----A---- C:\Windows\system32\d3dx9_30.dll
2012-07-23 11:23:26 ----A---- C:\Windows\system32\d3dx9_29.dll
2012-07-23 11:23:25 ----A---- C:\Windows\system32\d3dx9_28.dll
2012-07-23 11:23:25 ----A---- C:\Windows\system32\d3dx9_27.dll
2012-07-23 11:23:24 ----A---- C:\Windows\system32\d3dx9_26.dll
2012-07-23 11:23:23 ----A---- C:\Windows\system32\d3dx9_25.dll
2012-07-23 11:23:23 ----A---- C:\Windows\system32\d3dx9_24.dll
2012-07-23 10:45:19 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2012-07-23 10:23:59 ----A---- C:\Windows\system32\FNTCACHE.DAT
2012-07-23 10:16:52 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-07-23 10:16:23 ----D---- C:\Users\natsof\AppData\Roaming\DAEMON Tools Lite
2012-07-23 10:16:20 ----D---- C:\Program Files\DAEMON Tools Lite
2012-07-23 10:15:40 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-07-22 13:07:55 ----D---- C:\Program Files\CCleaner
2012-07-18 12:32:58 ----HD---- C:\VritualRoot
2012-07-15 20:51:16 ----A---- C:\Windows\system32\setup.bat
2012-07-15 20:45:04 ----D---- C:\ProgramData\CPA_VA
2012-07-15 13:29:11 ----D---- C:\Users\natsof\AppData\Roaming\Skype
2012-07-15 13:28:36 ----D---- C:\Program Files\Common Files\Skype
2012-07-15 13:28:35 ----RD---- C:\Program Files\Skype
2012-07-15 13:28:11 ----D---- C:\ProgramData\Skype
2012-07-15 13:03:11 ----A---- C:\Windows\system32\drivers\sfi.dat
2012-07-15 13:01:50 ----D---- C:\ProgramData\Comodo
2012-07-15 13:01:45 ----D---- C:\Program Files\Comodo
2012-07-15 13:01:44 ----A---- C:\Windows\system32\msvcr71.dll
2012-07-15 13:01:44 ----A---- C:\Windows\system32\mfc71.dll
2012-07-15 13:01:44 ----A---- C:\Windows\system32\gdiplus.dll
2012-07-14 23:13:49 ----D---- C:\Windows\Panther
2012-07-14 23:13:39 ----RASH---- C:\BOOTSECT.BAK
2012-07-14 23:13:38 ----SHD---- C:\Boot
2012-07-14 23:13:38 ----H---- C:\Boot.BAK
2012-07-14 23:04:00 ----D---- C:\Windows.old
2012-07-14 22:39:01 ----D---- C:\Users\natsof\AppData\Roaming\Opera
2012-07-14 22:38:56 ----D---- C:\Program Files\Opera
2012-07-14 22:32:31 ----A---- C:\Windows\system32\msvcrt3.dll
2012-07-14 22:30:33 ----D---- C:\Windows\system32\Wat
2012-07-14 22:30:04 ----A---- C:\Windows\system32\zxurintaomh.exe
2012-07-14 22:29:44 ----D---- C:\ProgramData\SweetIM
2012-07-14 22:29:44 ----D---- C:\Program Files\SweetIM
2012-07-14 22:29:41 ----SHD---- C:\Windows\Installer
2012-07-14 22:29:26 ----D---- C:\Users\natsof\AppData\Roaming\WinRAR
2012-07-14 22:29:23 ----D---- C:\Program Files\WinRAR
2012-07-14 22:28:48 ----D---- C:\Users\natsof\AppData\Roaming\Macromedia
2012-07-14 22:28:48 ----D---- C:\Users\natsof\AppData\Roaming\Adobe
2012-07-14 22:28:44 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-07-14 22:28:43 ----D---- C:\Windows\system32\Macromed
2012-07-14 22:24:36 ----D---- C:\Users\natsof\AppData\Roaming\Identities
2012-07-14 22:24:26 ----SD---- C:\Users\natsof\AppData\Roaming\Microsoft
2012-07-14 22:24:26 ----D---- C:\Users\natsof\AppData\Roaming\Media Center Programs
2012-07-14 22:24:09 ----SHD---- C:\Recovery
2012-07-14 22:24:09 ----SHD---- C:\ProgramData\Šablony
2012-07-14 22:24:09 ----SHD---- C:\ProgramData\Plocha
2012-07-14 22:24:09 ----SHD---- C:\ProgramData\Oblíbené položky
2012-07-14 22:24:09 ----SHD---- C:\ProgramData\Nabídka Start
2012-07-14 22:24:09 ----SHD---- C:\ProgramData\Dokumenty
2012-07-14 22:24:09 ----SHD---- C:\ProgramData\Data aplikací
2012-07-14 22:18:23 ----D---- C:\Windows\SoftwareDistribution
2012-07-14 22:16:06 ----D---- C:\Windows\Prefetch
2012-07-14 22:15:14 ----ASH---- C:\hiberfil.sys
2012-07-12 20:37:15 ----D---- C:\Nová složka (2)
2012-07-09 10:34:28 ----D---- C:\stahuj
2012-07-04 10:39:31 ----SHD---- C:\found.000
2012-07-01 14:12:12 ----D---- C:\Tošovice 2012
2012-06-28 20:29:49 ----D---- C:\NVIDIA
2012-06-28 15:53:49 ----D---- C:\Nová složka
2012-06-28 15:48:58 ----SHD---- C:\System Volume Information
2012-06-28 15:44:51 ----ASH---- C:\pagefile.sys
2012-06-28 15:41:00 ----D---- C:\NVIDIA_258.96_Win7_Vista32
2012-06-28 15:37:53 ----D---- C:\driver
2012-06-28 15:37:21 ----A---- C:\motherboard_driver_chipset_nvidia_vistax86.exe
2012-06-28 14:03:48 ----RASH---- C:\MSDOS.SYS
2012-06-28 14:03:48 ----RASH---- C:\IO.SYS

======List of files/folders modified in the last 1 month======

2012-07-24 18:02:44 ----RD---- C:\Program Files
2012-07-24 17:59:33 ----D---- C:\Windows\System32
2012-07-24 17:59:25 ----D---- C:\Windows\system32\drivers
2012-07-24 17:53:53 ----D---- C:\Windows
2012-07-24 17:53:50 ----D---- C:\Windows\system32\Tasks
2012-07-24 12:14:26 ----D---- C:\Windows\Temp
2012-07-24 11:53:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-07-24 11:53:44 ----D---- C:\Windows\inf
2012-07-24 11:43:11 ----HD---- C:\ProgramData
2012-07-23 11:23:36 ----RSD---- C:\Windows\assembly
2012-07-23 11:23:29 ----D---- C:\Windows\Microsoft.NET
2012-07-23 11:21:14 ----D---- C:\Windows\Logs
2012-07-23 11:09:01 ----D---- C:\Program Files\Common Files\microsoft shared
2012-07-23 10:45:50 ----D---- C:\Windows\system32\catroot
2012-07-23 10:45:48 ----D---- C:\Windows\system32\DriverStore
2012-07-22 13:11:42 ----D---- C:\Windows\debug
2012-07-21 22:27:18 ----D---- C:\Windows\system32\wdi
2012-07-17 22:00:44 ----SD---- C:\ProgramData\Microsoft
2012-07-17 22:00:36 ----D---- C:\Windows\system32\drivers\UMDF
2012-07-15 13:28:36 ----D---- C:\Program Files\Common Files
2012-07-14 22:30:41 ----A---- C:\Windows\system32\slwga.dll
2012-07-14 22:30:40 ----A---- C:\Windows\system32\systemcpl.dll
2012-07-14 22:30:39 ----A---- C:\Windows\system32\user32.dll
2012-07-14 22:30:37 ----D---- C:\Windows\winsxs
2012-07-14 22:30:29 ----D---- C:\Windows\system32\CodeIntegrity
2012-07-14 22:30:09 ----D---- C:\Windows\system32\restore
2012-07-14 22:28:48 ----D---- C:\Windows\Downloaded Program Files
2012-07-14 22:28:44 ----D---- C:\Windows\Tasks
2012-07-14 22:24:34 ----SHD---- C:\$Recycle.Bin
2012-07-14 22:24:23 ----RD---- C:\Users
2012-07-14 22:24:09 ----D---- C:\Program Files\Windows NT
2012-07-14 22:22:35 ----D---- C:\Windows\rescache
2012-07-14 22:22:14 ----D---- C:\Windows\system32\config
2012-07-14 22:19:31 ----D---- C:\Windows\system32\catroot2
2012-07-14 22:19:20 ----D---- C:\Windows\system32\sysprep
2012-07-14 22:16:01 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-07-23 477240]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2011-12-19 19600]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2011-12-19 491816]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-12-19 39640]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-07-23 242240]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-12-19 82400]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
R3 RegGuard;RegGuard; \??\C:\Windows\system32\Drivers\regguard.sys [2012-07-24 24416]
S0 Partizan;Partizan; C:\Windows\system32\drivers\Partizan.sys [2012-07-24 35816]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atcgx6nk;atcgx6nk; C:\Windows\system32\drivers\atcgx6nk.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-20 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-20 25600]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CLPSLS;COMODO livePCsupport Service; C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1052472]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2011-12-19 1960584]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-03 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 250056]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-14 1343400]

-----------------EOF-----------------




info.txt logfile of random's system information tool 1.09 2012-07-24 18:02:57

======Uninstall list======

Adobe Flash Player 11 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil32_11_3_300_265_ActiveX.exe -maintain activex
Adobe Flash Player 11 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil32_11_3_300_265_Plugin.exe -maintain plugin
Advanced Performance Platform Revenuestreaming.-->C:\Windows\system32\zxurintaomh.exe /u="C:\Windows\system32\lzmgidqtxhmz.dll" /d="zxurintaomh"
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Comodo Dragon-->"C:\Program Files\Comodo\Dragon\uninstall.exe"
COMODO GeekBuddy-->C:\Program Files\COMODO\COMODO GeekBuddy\uninstall.exe
COMODO Internet Security-->MsiExec.exe /I{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
Internet Explorer Toolbar 4.6 by SweetPacks-->MsiExec.exe /X{774C0434-9948-4DEE-A14E-69CDD316E36C}
London 2012: The Official Video Game of the Olympic Games-->"D:\ol\London 2012 The Official Video Game of the Olympic Games\unins000.exe"
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-->MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}
Opera 12.00-->"C:\Program Files\Opera\Opera.exe" /uninstall
Skype™ 5.10-->MsiExec.exe /X{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}
UnHackMe 5.99 release-->"C:\Program Files\UnHackMe\unins000.exe"
Update Manager for SweetPacks 1.0-->MsiExec.exe /X{FB697452-8CA4-46B4-98B1-165C922A2EF3}
WinRAR 4.20 (32-bit)-->C:\Program Files\WinRAR\uninstall.exe

======System event log======

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Plug and Play byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20101120215742.697406-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 20010
Message: Došlo ke změně jednoho nebo více podsystémů služby Plug and Play.

Povolený instalační podsystém služby PlugPlay: 'false'
Povolený podsystém mezipaměti služby PlugPlay: 'false'

Record Number: 4
Source Name: Microsoft-Windows-UserPnp
Time Written: 20101120215742.697406-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Software Protection byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20101120215742.479005-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Windows Event Log byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20101120215742.338605-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Volume Shadow Copy byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20101120215742.323005-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247F27-08
Event Code: 8212
Message: Služba Stínová kopie svazku: Modul pro zápis s názvem BITS Writer a ID {4969d978-be47-48b0-b100-f328f07ac1e0} se pokusil o přihlášení během instalace.

Operace:
Inicializace modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {4969d978-be47-48b0-b100-f328f07ac1e0}
Název modulu pro zápis: BITS Writer
Record Number: 5
Source Name: VSS
Time Written: 20120714201812.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20120714201611.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20120714201607.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20120714201601.525200-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247F27-08
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20120714201601.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: 37L4247F27-08
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247F27-08$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120714201540.730400-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247F27-08$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120714201540.714800-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x239b9
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120714201540.356000-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120714201538.733600-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120714201538.686800-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: preventivni log

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Doporucuji odinstalovat (pokud nepouzivate) toolbary (listy prohlizecu) v Přidat nebo odebrat programy

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

Re: preventivni log

#3 Příspěvek od jacktenrek »

[00:00:0000] Has crashed before : Yes
[00:00:0000] ***** Global Init *****
[00:00:0000] Create mutex : RogueKiller
[00:00:0000] Mutex Created : 0xd0
[00:00:0000] Fill lists
[00:00:0000] OS Language : Czech
[00:00:0000] Take Privileges
[00:00:0016] Modify Token
[00:00:0016] Set priority to HIGH
[00:00:0016] Getting Operating System
[00:00:0016] Os Getted : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
[00:00:0016] ***** Global Init OK *****
[00:00:0016] ***** GUI Init *****
[00:00:0031] Get build number
[00:00:0031] build number : RogueKiller (by Tigzy) -- v7.6.4
[00:00:0219] ***** GUI Init OK *****
[00:00:0219] ***** PreScan *****
[00:00:0234] Clear ListViews
[00:00:0234] Clear Objects
[00:00:0234] [Check Window] Eula - Please read
[00:00:0250] [Check Window] Debug log sending
[00:00:0250] [Check Window] Přepínání úloh
[00:00:0250] [Check Window] Start
[00:00:0250] [Check Window] CiceroUIWndFrame
[00:00:0265] [Check Window] natsof
[00:00:0265] [Check Window] Nabídka Start
[00:00:0265] [Check Window] View Available Networks (Tooltip)
[00:00:0265] [Check Window] View Available Networks
[00:00:0281] [Check Window] Network Flyout
[00:00:0281] [Check Window] CiceroUIWndFrame
[00:00:0281] [Check Window] TF_FloatingLangBar_WndTitle
[00:00:0281] [Check Window] RogueKiller (by Tigzy) -- v7.6.4
[00:00:0297] [Check Window] Skype™ - haloli13
[00:00:0297] [Check Window] Msg
[00:00:0297] [Check Window] 畄浭坹湩潤汷獥sᣄ推␬揃拺掾䫊揉␬揃抿掱䝓揅嫀揱䝛揅鄖揜搎搎岅揅寺揅ᣄ推␬揃拺掾䫊揉␬揃抿掱䠪揅嫀揱䷴揅鄖揜䣳揅挫掮岅揅寺揅慭汩潴
[00:00:0328] [Check Window] Msg
[00:00:0328] [Check Window] 畄浭坹湩潤汷獥sᣄ推␬揃拺掾䫊揉␬揃抿掱䝓揅嫀揱䝛揅鄖揜搎搎岅揅寺揅ᣄ推␬揃拺掾䫊揉␬揃抿掱䠪揅嫀揱䷴揅鄖揜䣳揅挫掮岅揅寺揅慭汩潴
[00:00:0359] [Check Window] UnHackMe Monitor
[00:00:0359] [Check Window] UnHackMe Monitor
[00:00:0359] [Check Window] Msg
[00:00:0375] [Check Window] Msg
[00:00:0375] [Check Window] 畄浭坹湩潤汷獥sᣄ推␬揃拺掾䫊揉␬揃抿掱䝓揅嫀揱䝛揅鄖揜搎搎岅揅寺揅ᣄ推␬揃拺掾䫊揉␬揃抿掱䠪揅嫀揱䷴揅鄖揜䣳揅挫掮岅揅寺揅慭汩潴
[00:00:0406] [Check Window] Msg
[00:00:0406] [Check Window] Msg
[00:00:0406] [Check Window] 畄浭坹湩潤汷獥sᣄ推␬揃拺掾䫊揉␬揃抿掱䝓揅嫀揱䝛揅鄖揜搎搎岅揅寺揅ᣄ推␬揃拺掾䫊揉␬揃抿掱䠪揅嫀揱䷴揅鄖揜䣳揅挫掮岅揅寺揅慭汩潴
[00:00:0437] [Check Window] Msg
[00:00:0437] [Check Window] Msg
[00:00:0437] [Check Window] 畄浭坹湩潤汷獥sᣄ推␬揃拺掾䫊揉␬揃抿掱䝓揅嫀揱䝛揅鄖揜搎搎岅揅寺揅ᣄ推␬揃拺掾䫊揉␬揃抿掱䠪揅嫀揱䷴揅鄖揜䣳揅挫掮岅揅寺揅慭汩潴
[00:00:0468] [Check Window] Opera
[00:00:0468] [Check Window] Opera
[00:00:0468] [Check Window] BluetoothNotificationAreaIconWindowClass
[00:00:0484] [Check Window] MS_WebcheckMonitor
[00:00:0484] [Check Window] HiddenFaxWindow
[00:00:0484] [Check Window] Media Center SSO
[00:00:0484] [Check Window] DAEMON Tools
[00:00:0499] [Check Window] Měřič baterie
[00:00:0499] [Check Window] DeviceManager
[00:00:0499] [Check Window] DDE Server Window
[00:00:0499] [Check Window] GeekBuddy
[00:00:0515] [Check Window] GeekBuddy
[00:00:0515] [Check Window] GeekBuddy
[00:00:0515] [Check Window] GeekBuddy
[00:00:0515] [Check Window] GeekBuddy
[00:00:0515] [Check Window] GeekBuddy
[00:00:0531] [Check Window] GeekBuddy
[00:00:0531] [Check Window] GeekBuddy
[00:00:0531] [Check Window] GDI+ Window
[00:00:0531] [Check Window] C:\Users\natsof\AppData\Roaming\Skype
[00:00:0531] [Check Window] GDI+ Window
[00:00:0546] [Check Window] SidebarBroadcastWatcher
[00:00:0546] [Check Window] GDI+ Window
[00:00:0546] [Check Window] Seznam odkazů
[00:00:0546] [Check Window] DDE Server Window
[00:00:0562] [Check Window] MCI command handling window
[00:00:0562] [Check Window] Task Host Window
[00:00:0562] [Check Window] DWM Notification Window
[00:00:0562] [Check Window] Temp
[00:00:0577] [Check Window] VIRY.CZ • Zobrazit téma - preventivni log - Opera
[00:00:0577] [Check Window] Program Manager
[00:00:0577] [Check Window] Default IME
[00:00:0577] [Check Window] MSCTFIME UI
[00:00:0593] [Check Window] Default IME
[00:00:0593] [Check Window] MSCTFIME UI
[00:00:0593] [Check Window] Default IME
[00:00:0593] [Check Window] MSCTFIME UI
[00:00:0593] [Check Window] Default IME
[00:00:0609] [Check Window] MSCTFIME UI
[00:00:0609] [Check Window] Default IME
[00:00:0609] [Check Window] MSCTFIME UI
[00:00:0609] [Check Window] Default IME
[00:00:0624] [Check Window] Default IME
[00:00:0624] [Check Window] Default IME
[00:00:0624] [Check Window] Default IME
[00:00:0624] [Check Window] Default IME
[00:00:0624] [Check Window] Default IME
[00:00:0640] [Check Window] MSCTFIME UI
[00:00:0640] [Check Window] Default IME
[00:00:0640] [Check Window] Default IME
[00:00:0640] [Check Window] Default IME
[00:00:0655] [Check Window] Default IME
[00:00:0655] [Check Window] Default IME
[00:00:0655] [Check Window] MSCTFIME UI
[00:00:0655] [Check Window] Default IME
[00:00:0671] [Check Window] Default IME
[00:00:0671] [Check Window] Default IME
[00:00:0671] [Check Window] Default IME
[00:00:0671] [Check Window] Default IME
[00:00:0671] [Check Window] Default IME
[00:00:0687] [Check Window] Default IME
[00:00:0687] [Check Window] MSCTFIME UI
[00:00:0687] [Check Window] Default IME
[00:00:0687] [Check Window] MSCTFIME UI
[00:00:0702] [Check Window] Default IME
[00:00:0702] [Check Window] MSCTFIME UI
[00:00:0702] [Check Window] Default IME
[00:00:0702] [Check Processes] Service PID : 544
[00:00:0718] [Check Processes] [0] [System Process]
[00:00:0718] [Check Processes] [4] System
[00:00:0718] [Check Processes] [308] smss.exe
[00:00:0718] [Check Processes] [428] csrss.exe
[00:00:0733] [Check Processes] [484] wininit.exe
[00:00:0733] [Check Processes] [504] csrss.exe
[00:00:0733] [Check Processes] [544] services.exe
[00:00:0733] [Check Processes] [568] lsass.exe
[00:00:0749] [Check Processes] [576] lsm.exe
[00:00:0749] [Check Processes] [628] winlogon.exe
[00:00:0749] [Check Processes] [740] svchost.exe
[00:00:0749] [Check Processes] [800] CLPSLS.exe
[00:00:0765] Get sections OK ; Section table : 0x1f0 -- 0x400
[00:00:0765] Nb sections : 5
[00:00:0765] Parsing section : [6] .text
[00:00:0765] Parsing section at 0x400
[00:00:0765] Parsing section : [7] .rdata
[00:00:0765] Parsing section at 0x86800
[00:00:0780] Parsing section : [6] .data
[00:00:0780] Parsing section at 0xe3200
[00:00:0780] Parsing section : [6] .rsrc
[00:00:0780] Parsing section at 0xf4600
[00:00:0780] Parsing section : [7] .reloc
[00:00:0780] Parsing section at 0xf4c00
[00:00:0780] [Check Processes] [836] svchost.exe
[00:00:0796] [Check Processes] [888] cmdagent.exe
[00:00:0796] Get sections OK ; Section table : 0x1f8 -- 0x400
[00:00:0796] Nb sections : 4
[00:00:0796] Parsing section : [6] .text
[00:00:0796] Parsing section at 0x400
[00:00:0827] Parsing section : [7] .rdata
[00:00:0827] Parsing section at 0x16a600
[00:00:0827] Parsing section : [6] .data
[00:00:0827] Parsing section at 0x1cc800
[00:00:0827] Parsing section : [6] .rsrc
[00:00:0827] Parsing section at 0x1d8200
[00:00:0843] [Check Processes] [972] svchost.exe
[00:00:0843] [Check Processes] [1016] svchost.exe
[00:00:0843] [Check Processes] [1048] svchost.exe
[00:00:0843] [Check Processes] [1092] svchost.exe
[00:00:0858] [Check Processes] [1268] svchost.exe
[00:00:0858] [Check Processes] [1532] spoolsv.exe
[00:00:0858] [Check Processes] [1560] svchost.exe
[00:00:0874] [Check Processes] [1648] svchost.exe
[00:00:0874] [Check Processes] [1916] taskhost.exe
[00:00:0874] Get sections OK ; Section table : 0x1e0 -- 0x400
[00:00:0874] Nb sections : 4
[00:00:0874] Parsing section : [6] .text
[00:00:0874] Parsing section at 0x400
[00:00:0874] Parsing section : [6] .data
[00:00:0874] Parsing section at 0xa800
[00:00:0874] Parsing section : [6] .rsrc
[00:00:0874] Parsing section at 0xaa00
[00:00:0889] Parsing section : [7] .reloc
[00:00:0889] Parsing section at 0xb000
[00:00:0889] [Check Processes] [1996] dwm.exe
[00:00:0889] [Check Processes] [112] explorer.exe
[00:00:0889] [Check DLLs] Explorer.EXE
[00:00:0889] [Check DLLs] ntdll.dll
[00:00:0905] [Check DLLs] kernel32.dll
[00:00:0905] [Check DLLs] KERNELBASE.dll
[00:00:0905] [Check DLLs] ADVAPI32.dll
[00:00:0905] [Check DLLs] msvcrt.dll
[00:00:0905] [Check DLLs] sechost.dll
[00:00:0905] [Check DLLs] RPCRT4.dll
[00:00:0905] [Check DLLs] GDI32.dll
[00:00:0921] [Check DLLs] USER32.dll
[00:00:0921] [Check DLLs] LPK.dll
[00:00:0921] [Check DLLs] USP10.dll
[00:00:0921] [Check DLLs] SHLWAPI.dll
[00:00:0921] [Check DLLs] SHELL32.dll
[00:00:0921] [Check DLLs] ole32.dll
[00:00:0921] [Check DLLs] OLEAUT32.dll
[00:00:0936] [Check DLLs] EXPLORERFRAME.dll
[00:00:0936] [Check DLLs] DUser.dll
[00:00:0936] [Check DLLs] DUI70.dll
[00:00:0936] [Check DLLs] IMM32.dll
[00:00:0936] [Check DLLs] MSCTF.dll
[00:00:0936] [Check DLLs] UxTheme.dll
[00:00:0936] [Check DLLs] POWRPROF.dll
[00:00:0952] [Check DLLs] SETUPAPI.dll
[00:00:0952] [Check DLLs] CFGMGR32.dll
[00:00:0952] [Check DLLs] DEVOBJ.dll
[00:00:0952] [Check DLLs] dwmapi.dll
[00:00:0952] [Check DLLs] slc.dll
[00:00:0952] [Check DLLs] gdiplus.dll
[00:00:0952] [Check DLLs] Secur32.dll
[00:00:0967] [Check DLLs] SSPICLI.DLL
[00:00:0967] [Check DLLs] PROPSYS.dll
[00:00:0967] [Check DLLs] guard32.dll
[00:00:0967] [Check DLLs] VERSION.dll
[00:00:0967] [Check DLLs] fltlib.dll
[00:00:0967] [Check DLLs] WINSTA.dll
[00:00:0967] [Check DLLs] CRYPTBASE.dll
[00:00:0967] [Check DLLs] comctl32.dll
[00:00:0983] [Check DLLs] WindowsCodecs.dll
[00:00:0983] [Check DLLs] profapi.dll
[00:00:0983] [Check DLLs] apphelp.dll
[00:00:0983] [Check DLLs] CLBCatQ.DLL
[00:00:0983] [Check DLLs] EhStorShell.dll
[00:00:0983] [Check DLLs] cscui.dll
[00:00:0999] [Check DLLs] CSCDLL.dll
[00:00:0999] [Check DLLs] CSCAPI.dll
[00:00:0999] [Check DLLs] ntshrui.dll
[00:00:0999] [Check DLLs] srvcli.dll
[00:00:0999] [Check DLLs] CRYPTSP.dll
[00:00:0999] [Check DLLs] rsaenh.dll
[00:00:0999] [Check DLLs] RpcRtRemote.dll
[00:01:0014] [Check DLLs] SndVolSSO.DLL
[00:01:0014] [Check DLLs] HID.DLL
[00:01:0014] [Check DLLs] MMDevApi.dll
[00:01:0030] [Check DLLs] timedate.cpl
[00:01:0030] [Check DLLs] ATL.DLL
[00:01:0045] [Check DLLs] actxprxy.dll
[00:01:0045] [Check DLLs] ntmarta.dll
[00:01:0077] [Check DLLs] WLDAP32.dll
[00:01:0108] [Check DLLs] shdocvw.dll
[00:01:0123] [Check DLLs] LINKINFO.dll
[00:01:0123] [Check DLLs] msutb.dll
[00:01:0123] [Check DLLs] USERENV.dll
[00:01:0123] [Check DLLs] SAMLIB.dll
[00:01:0139] [Check DLLs] samcli.dll
[00:01:0170] [Check DLLs] netutils.dll





OTL logfile created on: 24.7.2012 21:18:57 - Run 1
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\natsof\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,25 Gb Total Physical Memory | 1,88 Gb Available Physical Memory | 57,93% Memory free
6,50 Gb Paging File | 5,02 Gb Available in Paging File | 77,26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,65 Gb Total Space | 67,68 Gb Free Space | 69,30% Space Free | Partition Type: NTFS
Drive D: | 195,31 Gb Total Space | 175,41 Gb Free Space | 89,81% Space Free | Partition Type: NTFS
Drive E: | 172,79 Gb Total Space | 172,69 Gb Free Space | 99,95% Space Free | Partition Type: NTFS
Drive F: | 108,29 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 7,46 Gb Total Space | 5,12 Gb Free Space | 68,62% Space Free | Partition Type: NTFS
Drive H: | 6,27 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: NATSOF-PC | User Name: natsof | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012.07.24 21:16:45 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\natsof\Desktop\OTL.exe
PRC - [2012.07.14 22:38:57 | 000,874,384 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2012.07.14 22:38:57 | 000,800,656 | ---- | M] (Opera Software) -- C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe
PRC - [2012.06.27 16:01:36 | 000,595,216 | ---- | M] (Greatis Software) -- C:\Program Files\UnHackMe\hackmon.exe
PRC - [2012.04.17 17:19:32 | 002,614,080 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
PRC - [2011.12.19 18:59:00 | 001,960,584 | ---- | M] (COMODO) -- C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
PRC - [2011.12.19 18:58:38 | 006,676,808 | ---- | M] (COMODO) -- C:\Program Files\Comodo\COMODO Internet Security\cfp.exe
PRC - [2011.11.23 12:27:04 | 001,052,472 | ---- | M] (COMODO) -- C:\Program Files\Comodo\COMODO GeekBuddy\CLPSLS.exe
PRC - [2011.11.23 12:27:04 | 000,992,056 | ---- | M] (COMODO) -- C:\Program Files\Comodo\COMODO GeekBuddy\CLPS.exe
PRC - [2010.11.20 23:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 23:29:19 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010.11.20 23:29:07 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe


========== Modules (No Company Name) ==========

MOD - [2012.07.15 13:36:50 | 009,465,032 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_265.dll
MOD - [2012.07.14 22:38:58 | 000,783,360 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dll
MOD - [2012.07.14 22:38:58 | 000,316,928 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll
MOD - [2012.07.14 22:38:58 | 000,276,480 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll
MOD - [2012.07.14 22:38:58 | 000,168,448 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
MOD - [2012.07.14 22:38:58 | 000,099,840 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll
MOD - [2012.07.14 22:38:58 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll
MOD - [2012.07.14 22:38:58 | 000,098,816 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll
MOD - [2012.07.14 22:38:58 | 000,078,336 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll
MOD - [2012.07.14 22:38:58 | 000,076,800 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll
MOD - [2012.07.14 22:38:58 | 000,068,608 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll
MOD - [2012.07.14 22:38:58 | 000,064,000 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll
MOD - [2012.07.14 22:38:58 | 000,046,592 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll
MOD - [2012.07.14 22:38:58 | 000,045,568 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gsttypefindfunctions.dll


========== Win32 Services (SafeList) ==========

SRV - [2012.07.15 13:36:50 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.14 22:30:31 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2012.07.03 13:19:28 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011.12.19 18:59:00 | 001,960,584 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011.11.23 12:27:04 | 001,052,472 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\Comodo\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (atcgx6nk)
DRV - [2012.07.24 17:59:25 | 000,024,416 | ---- | M] (Greatis Software) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\regguard.sys -- (RegGuard)
DRV - [2012.07.24 11:44:46 | 000,035,816 | ---- | M] (Greatis Software) [Kernel | Boot | Unknown] -- C:\Windows\System32\drivers\Partizan.sys -- (Partizan)
DRV - [2012.07.23 10:45:19 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012.07.23 10:16:52 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2011.12.19 18:59:16 | 000,082,400 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\inspect.sys -- (inspect)
DRV - [2011.12.19 18:59:14 | 000,491,816 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011.12.19 18:59:14 | 000,039,640 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011.12.19 18:59:12 | 000,019,600 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmderd.sys -- (cmderd)
DRV - [2010.11.20 23:29:34 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010.11.20 23:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010.11.20 23:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 23:29:03 | 000,112,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - [2010.11.20 23:29:03 | 000,077,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV - [2010.11.20 23:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010.11.20 23:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 23:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 23:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010.11.20 23:29:03 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\terminpt.sys -- (terminpt)
DRV - [2010.11.20 23:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 23:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009.06.10 23:19:48 | 009,853,248 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
IE - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found



O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {BC1A4275-EBD7-C096-4DF4-0F02699F086C} - No CLSID value found.
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [COMODO] C:\Program Files\Comodo\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\Comodo\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun- = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun- = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 253
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun- = 0
O7 - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun- = 0
O7 - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3734077389-2202423189-3181031338-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 253
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4D53C84A-A3E1-4DA4-BE13-E59740CC5739}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2012.07.24 11:43:07 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.07.24 11:43:07 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.07.24 11:43:07 | 000,000,000 | RHSD | M] - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.07.24 11:43:07 | 000,000,000 | RHSD | M] - G:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.06.29 00:39:27 | 000,000,063 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (Partizan)
O34 - HKLM BootExecute: (ootExecute settings...)
O34 - HKLM BootExecute: (ount)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012.07.24 21:16:45 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\natsof\Desktop\OTL.exe
[2012.07.24 21:14:04 | 000,000,000 | ---D | C] -- C:\Users\natsof\Desktop\RK_Quarantine
[2012.07.24 18:02:44 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.07.24 18:02:42 | 000,000,000 | ---D | C] -- C:\rsit
[2012.07.24 17:59:25 | 000,024,416 | ---- | C] (Greatis Software) -- C:\Windows\System32\drivers\regguard.sys
[2012.07.24 17:53:45 | 000,012,800 | ---- | C] (Greatis Software, LLC.) -- C:\Windows\System32\drivers\UnHackMeDrv.sys
[2012.07.24 17:53:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
[2012.07.24 17:53:37 | 000,000,000 | ---D | C] -- C:\Program Files\UnHackMe
[2012.07.24 11:44:46 | 000,039,184 | ---- | C] (Greatis Software) -- C:\Windows\System32\Partizan.exe
[2012.07.24 11:44:46 | 000,035,816 | ---- | C] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2012.07.24 11:43:11 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2012.07.24 11:43:07 | 000,000,000 | RHSD | C] -- C:\comment.htt
[2012.07.24 11:43:07 | 000,000,000 | RHSD | C] -- C:\autorun.inf
[2012.07.24 11:42:31 | 000,000,000 | ---D | C] -- C:\Users\natsof\Documents\RegRun2
[2012.07.24 11:36:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegRun Security Suite
[2012.07.24 11:36:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
[2012.07.24 11:36:36 | 001,385,232 | ---- | C] (Greatis Software) -- C:\Windows\RunGuard.exe
[2012.07.24 11:35:16 | 000,000,000 | ---D | C] -- C:\Program Files\Greatis
[2012.07.23 14:23:41 | 000,000,000 | ---D | C] -- C:\Users\natsof\AppData\Local\FLT
[2012.07.23 14:23:41 | 000,000,000 | ---D | C] -- C:\Users\natsof\AppData\Local\2012
[2012.07.23 11:24:01 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2012.07.23 11:24:01 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2012.07.23 11:24:01 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2012.07.23 11:24:01 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2012.07.23 11:24:01 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2012.07.23 11:24:01 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2012.07.23 11:24:00 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2012.07.23 11:24:00 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2012.07.23 11:24:00 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2012.07.23 11:24:00 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2012.07.23 11:23:59 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2012.07.23 11:23:59 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2012.07.23 11:23:59 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2012.07.23 11:23:59 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2012.07.23 11:23:58 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2012.07.23 11:23:58 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2012.07.23 11:23:57 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2012.07.23 11:23:57 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2012.07.23 11:23:57 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2012.07.23 11:23:57 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2012.07.23 11:23:57 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2012.07.23 11:23:56 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2012.07.23 11:23:56 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2012.07.23 11:23:56 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2012.07.23 11:23:56 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2012.07.23 11:23:55 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2012.07.23 11:23:55 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2012.07.23 11:23:55 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2012.07.23 11:23:55 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2012.07.23 11:23:54 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2012.07.23 11:23:54 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2012.07.23 11:23:54 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2012.07.23 11:23:54 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2012.07.23 11:23:53 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2012.07.23 11:23:53 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2012.07.23 11:23:53 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2012.07.23 11:23:52 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2012.07.23 11:23:52 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2012.07.23 11:23:52 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2012.07.23 11:23:51 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2012.07.23 11:23:51 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2012.07.23 11:23:51 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2012.07.23 11:23:50 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2012.07.23 11:23:50 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2012.07.23 11:23:50 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2012.07.23 11:23:49 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2012.07.23 11:23:49 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2012.07.23 11:23:48 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2012.07.23 11:23:48 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2012.07.23 11:23:48 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2012.07.23 11:23:47 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2012.07.23 11:23:47 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2012.07.23 11:23:47 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2012.07.23 11:23:45 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2012.07.23 11:23:45 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2012.07.23 11:23:45 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2012.07.23 11:23:44 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2012.07.23 11:23:44 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2012.07.23 11:23:44 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2012.07.23 11:23:43 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2012.07.23 11:23:43 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2012.07.23 11:23:43 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2012.07.23 11:23:42 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2012.07.23 11:23:42 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2012.07.23 11:23:42 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2012.07.23 11:23:41 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2012.07.23 11:23:41 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2012.07.23 11:23:41 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2012.07.23 11:23:41 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2012.07.23 11:23:40 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2012.07.23 11:23:39 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2012.07.23 11:23:39 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2012.07.23 11:23:39 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2012.07.23 11:23:38 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2012.07.23 11:23:38 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2012.07.23 11:23:38 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2012.07.23 11:23:38 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2012.07.23 11:23:37 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2012.07.23 11:23:37 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2012.07.23 11:23:37 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2012.07.23 11:23:36 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2012.07.23 11:23:36 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2012.07.23 11:23:26 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2012.07.23 11:23:26 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2012.07.23 11:23:26 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2012.07.23 11:23:26 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2012.07.23 11:23:25 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2012.07.23 11:23:25 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2012.07.23 11:23:24 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2012.07.23 11:23:23 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2012.07.23 11:23:23 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2012.07.23 11:21:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\London 2012 The Official Video Game of the Olympic Games
[2012.07.23 10:45:19 | 000,242,240 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012.07.23 10:16:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2012.07.23 10:16:52 | 000,477,240 | ---- | C] (Duplex Secure Ltd.) -- C:\Windows\System32\drivers\sptd.sys
[2012.07.23 10:16:23 | 000,000,000 | ---D | C] -- C:\Users\natsof\AppData\Roaming\DAEMON Tools Lite
[2012.07.23 10:16:20 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2012.07.23 10:15:40 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2012.07.22 13:07:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.07.22 13:07:55 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.07.18 12:32:58 | 000,000,000 | -H-D | C] -- C:\VritualRoot

========== Files - Modified Within 7 Days ==========

[2012.07.24 21:21:52 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.07.24 21:16:45 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\natsof\Desktop\OTL.exe
[2012.07.24 20:36:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.07.24 17:59:25 | 000,024,416 | ---- | M] (Greatis Software) -- C:\Windows\System32\drivers\regguard.sys
[2012.07.24 17:53:46 | 000,000,917 | ---- | M] () -- C:\Users\natsof\Desktop\UnHackMe.lnk
[2012.07.24 11:55:56 | 000,336,321 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat
[2012.07.24 11:53:45 | 000,622,422 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2012.07.24 11:53:45 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.07.24 11:53:45 | 000,118,604 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2012.07.24 11:53:45 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.07.24 11:52:33 | 000,000,041 | ---- | M] () -- C:\Windows\System32\Partizan.RRI
[2012.07.24 11:46:54 | 000,348,494 | ---- | M] () -- C:\Windows\System32\msvcrt3.dll
[2012.07.24 11:46:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.07.24 11:46:04 | 2616,893,440 | -HS- | M] () -- C:\hiberfil.sys
[2012.07.24 11:44:46 | 000,039,184 | ---- | M] (Greatis Software) -- C:\Windows\System32\Partizan.exe
[2012.07.24 11:44:46 | 000,035,816 | ---- | M] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2012.07.24 11:42:37 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012.07.24 11:42:37 | 000,001,688 | ---- | M] () -- C:\Windows\System32\autoexec.nt
[2012.07.24 11:42:37 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2012.07.24 11:36:38 | 000,001,058 | ---- | M] () -- C:\Users\natsof\Desktop\RegRun Control Center.lnk
[2012.07.23 11:21:10 | 000,000,877 | ---- | M] () -- C:\Users\Public\Desktop\London 2012 The Official Video Game of the Olympic Games.lnk
[2012.07.23 10:45:19 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2012.07.23 10:24:09 | 000,265,880 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.07.23 10:17:30 | 000,001,900 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.07.22 13:15:47 | 000,093,108 | ---- | M] () -- C:\Users\natsof\Documents\cc_20120722_131534.reg
[2012.07.22 13:07:58 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.18 00:09:27 | 000,001,652 | ---- | M] () -- C:\Windows\System32\setup.reg
[2012.07.18 00:09:27 | 000,000,020 | ---- | M] () -- C:\Windows\System32\setup.bat
[2012.07.17 22:00:44 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf

========== Files Created - No Company Name ==========

[2012.07.24 21:21:52 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.07.24 17:53:46 | 000,000,917 | ---- | C] () -- C:\Users\natsof\Desktop\UnHackMe.lnk
[2012.07.24 11:52:33 | 000,000,041 | ---- | C] () -- C:\Windows\System32\Partizan.RRI
[2012.07.24 11:42:37 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2012.07.24 11:36:38 | 000,001,058 | ---- | C] () -- C:\Users\natsof\Desktop\RegRun Control Center.lnk
[2012.07.24 11:36:37 | 000,057,556 | ---- | C] () -- C:\Windows\guard.bmp
[2012.07.24 11:36:36 | 000,020,240 | ---- | C] () -- C:\Windows\WinBait.org
[2012.07.24 11:36:35 | 000,020,240 | ---- | C] () -- C:\Windows\WinBait.exe
[2012.07.23 11:21:10 | 000,000,877 | ---- | C] () -- C:\Users\Public\Desktop\London 2012 The Official Video Game of the Olympic Games.lnk
[2012.07.23 10:23:59 | 000,265,880 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.07.23 10:17:30 | 000,001,900 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2012.07.22 13:15:42 | 000,093,108 | ---- | C] () -- C:\Users\natsof\Documents\cc_20120722_131534.reg
[2012.07.22 13:07:58 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.07.17 22:00:44 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012.07.15 13:03:11 | 000,336,321 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat
[2012.07.14 22:32:31 | 000,348,494 | ---- | C] () -- C:\Windows\System32\msvcrt3.dll
[2012.07.14 22:30:04 | 000,061,305 | ---- | C] () -- C:\Windows\System32\zxurintaomh.exe
[2011.04.12 03:37:20 | 000,622,422 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2011.04.12 03:37:20 | 000,292,004 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2011.04.12 03:37:20 | 000,118,604 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2011.04.12 03:37:20 | 000,036,232 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2010.11.20 23:29:34 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2010.11.20 23:29:26 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe

========== LOP Check ==========

[2012.07.23 10:45:28 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\DAEMON Tools Lite
[2012.07.14 22:39:01 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\Opera
[2009.07.14 06:53:46 | 000,005,570 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< >

< >

< MD5 for: ATAPI.SYS >
[2009.09.28 15:48:24 | 017,815,748 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp3.cab:atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 03:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\Windows.old\Windows\system32\drivers\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\Windows.old\Windows\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\Windows.old\Windows\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\Windows.old\Windows\system32\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\Windows.old\Windows\system32\dllcache\autochk.exe
[2010.11.20 23:29:06 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\System32\autochk.exe
[2010.11.20 23:29:06 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe

< MD5 for: CDROM.SYS >
[2009.09.28 15:48:24 | 017,815,748 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.05.02 10:49:40 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\Windows.old\Windows\system32\dllcache\cdrom.sys
[2009.09.28 15:33:04 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\Windows.old\Windows\system32\drivers\cdrom.sys
[2010.11.20 23:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\System32\drivers\cdrom.sys
[2010.11.20 23:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.sys
[2010.11.20 23:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_61b0c5ce02098355\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2010.11.20 23:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\explorer.exe
[2010.11.20 23:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2009.09.28 15:33:17 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\Windows.old\Windows\explorer.exe
[2009.09.28 15:33:17 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\Windows.old\Windows\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2009.09.28 15:48:24 | 017,815,748 | ---- | M] () .cab file -- C:\Windows.old\Windows\Driver Cache\i386\sp3.cab:hal.dll
[2010.11.20 23:29:19 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\System32\hal.dll
[2010.11.20 23:29:19 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_ad305c8fb7ec5060\hal.dll
[2009.09.28 15:33:25 | 000,134,528 | ---- | M] (Microsoft Corporation) MD5=E33DE9C65B3625BDD00C1313179DA5A5 -- C:\Windows.old\Windows\system32\hal.dll

< MD5 for: SCECLI.DLL >
[2010.11.20 23:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 23:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\Windows.old\Windows\system32\dllcache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\Windows.old\Windows\system32\scecli.dll

< MD5 for: SVCHOST.EXE >
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.09.28 15:35:47 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\Windows.old\Windows\system32\dllcache\svchost.exe
[2009.09.28 15:35:47 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\Windows.old\Windows\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2009.09.28 15:35:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\Windows.old\Windows\system32\dllcache\tcpip.sys
[2009.09.28 15:35:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\Windows.old\Windows\system32\drivers\tcpip.sys
[2010.11.20 23:29:20 | 001,290,112 | ---- | M] (Microsoft Corporation) MD5=37E8FA3779668837CA9E2C36D2415949 -- C:\Windows\System32\drivers\tcpip.sys
[2010.11.20 23:29:20 | 001,290,112 | ---- | M] (Microsoft Corporation) MD5=37E8FA3779668837CA9E2C36D2415949 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01\tcpip.sys

< MD5 for: USERINIT.EXE >
[2010.11.20 23:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 23:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\Windows.old\Windows\system32\dllcache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\Windows.old\Windows\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009.09.28 15:36:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\Windows.old\Windows\system32\dllcache\winlogon.exe
[2009.09.28 15:36:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\Windows.old\Windows\system32\winlogon.exe
[2010.11.20 23:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 23:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe

< >

< %systemroot%*.* /U /s >
[3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[6 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[168 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >
[2012.06.28 15:10:08 | 035,832,930 | ---- | M] () -- C:\motherboard_driver_chipset_nvidia_vistax86.exe

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.07.14 22:28:48 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\Adobe
[2012.07.23 10:45:28 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\DAEMON Tools Lite
[2012.07.14 22:24:36 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\Identities
[2012.07.14 22:28:48 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\Macromedia
[2011.04.12 03:46:16 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\Media Center Programs
[2012.07.14 22:30:41 | 000,000,000 | --SD | M] -- C:\Users\natsof\AppData\Roaming\Microsoft
[2012.07.14 22:39:01 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\Opera
[2012.07.24 21:27:51 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\Skype
[2012.07.14 22:29:36 | 000,000,000 | ---D | M] -- C:\Users\natsof\AppData\Roaming\WinRAR

< %APPDATA%\*.exe /s >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job >
[2012.07.24 20:36:00 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >
[2012.07.23 10:45:19 | 000,242,240 | ---- | M] (DT Soft Ltd) -- C:\Windows\system32\drivers\dtsoftbus01.sys
[2012.07.24 11:44:46 | 000,035,816 | ---- | M] (Greatis Software) -- C:\Windows\system32\drivers\Partizan.sys
[2012.07.24 17:59:25 | 000,024,416 | ---- | M] (Greatis Software) -- C:\Windows\system32\drivers\regguard.sys
[2012.07.23 10:16:52 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) -- C:\Windows\system32\drivers\sptd.sys

< %systemroot%\system32\*.* /3 >
[2012.07.24 11:42:37 | 000,001,688 | ---- | M] () -- C:\Windows\system32\autoexec.nt
[2012.07.24 11:42:37 | 000,002,577 | ---- | M] () -- C:\Windows\system32\config.nt
[2012.07.23 10:24:09 | 000,265,880 | ---- | M] () -- C:\Windows\system32\FNTCACHE.DAT
[2012.07.24 11:46:54 | 000,348,494 | ---- | M] () -- C:\Windows\system32\msvcrt3.dll
[2012.07.24 11:44:46 | 000,039,184 | ---- | M] (Greatis Software) -- C:\Windows\system32\Partizan.exe
[2012.07.24 11:52:33 | 000,000,041 | ---- | M] () -- C:\Windows\system32\Partizan.RRI
[2012.07.24 11:46:04 | 000,000,260 | ---- | M] () -- C:\Windows\system32\PARTIZAN.TXT
[2012.07.24 11:53:45 | 000,118,604 | ---- | M] () -- C:\Windows\system32\perfc005.dat
[2012.07.24 11:53:45 | 000,103,370 | ---- | M] () -- C:\Windows\system32\perfc009.dat
[2012.07.24 11:53:45 | 000,622,422 | ---- | M] () -- C:\Windows\system32\perfh005.dat
[2012.07.24 11:53:45 | 000,606,992 | ---- | M] () -- C:\Windows\system32\perfh009.dat
[2012.07.24 11:53:45 | 001,445,734 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI

< %SYSTEMDRIVE%\*.exe >
[2012.06.28 15:10:08 | 035,832,930 | ---- | M] () -- C:\motherboard_driver_chipset_nvidia_vistax86.exe

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Skype" = "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun -- [2012.07.03 13:23:52 | 017,417,392 | R--- | M] (Skype Technologies S.A.)
"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun -- [2012.04.17 17:19:40 | 003,671,872 | ---- | M] (DT Soft Ltd)
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2010.11.20 23:29:41 | 001,174,016 | ---- | M] (Microsoft Corporation)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2010.11.20 23:29:33 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 -- C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >
[2012.07.14 22:38:57 | 000,874,384 | ---- | M] (Opera Software) MD5=308AB9B6B7BEDF60E458D1B950F5CD80 -- C:\Program Files\Opera\opera.exe

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.07.24 21:21:52 | 000,000,512 | ---- | M] () MD5=CE0C54C87FE0FAD264B66B07F63BB92C -- C:\PhysicalMBR.bin

< >

< *crack* /s >

< *keygen* /s >

< *loader* /s >
[2012.06.18 12:39:40 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.06.18 12:39:40 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.06.18 12:39:40 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.06.18 12:39:40 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2012.07.23 10:17:27 | 000,057,728 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png
[2012.07.23 10:17:27 | 000,057,728 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png
[2012.07.23 10:17:27 | 000,057,728 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png
[2012.07.23 10:17:28 | 000,057,728 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin3\dt_dadget_loader.png
[2012.07.23 10:17:28 | 000,057,728 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin4\dt_dadget_loader.png
[2012.07.23 10:17:28 | 000,061,770 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin5\dt_dadget_loader.png
[2012.07.23 10:17:28 | 000,061,770 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin6\dt_dadget_loader.png
[2012.07.23 10:26:50 | 000,010,519 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KSVK121E\AdLoader-aee74f28845638b42a47bb02dc06a7c6.min[1].js
[2012.07.24 11:47:01 | 000,000,652 | ---- | M] () -- \Users\natsof\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LO476F19\AdLoader[1].htm
[2012.07.17 14:18:16 | 000,009,051 | ---- | M] () -- \Users\natsof\AppData\Roaming\DAEMON Tools Lite\MediaInfo\img\loader.gif
[2012.07.17 14:18:16 | 000,016,119 | ---- | M] () -- \Users\natsof\AppData\Roaming\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.jpg
[2012.07.17 14:18:16 | 000,018,434 | ---- | M] () -- \Users\natsof\AppData\Roaming\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.png
[2012.07.17 14:18:16 | 000,009,283 | ---- | M] () -- \Users\natsof\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\ImageInfoLoader.js
[2012.07.17 14:18:16 | 000,001,898 | ---- | M] () -- \Users\natsof\AppData\Roaming\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\NewsLoader.js
[2012.05.15 09:59:24 | 000,072,638 | ---- | M] () -- \Windows.old\Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.gif
[2012.05.15 09:59:24 | 000,003,032 | ---- | M] () -- \Windows.old\Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.png
[2012.07.07 21:22:55 | 000,000,652 | ---- | M] () -- \Windows.old\Documents and Settings\natsof\Local Settings\Temporary Internet Files\Content.IE5\3JSJZ1NM\AdLoader[2].htm
[2012.07.08 22:32:55 | 000,010,519 | ---- | M] () -- \Windows.old\Documents and Settings\natsof\Local Settings\Temporary Internet Files\Content.IE5\BL85JFIF\AdLoader-aee74f28845638b42a47bb02dc06a7c6.min[1].js
[2012.07.14 21:32:33 | 000,000,652 | ---- | M] () -- \Windows.old\Documents and Settings\natsof\Local Settings\Temporary Internet Files\Content.IE5\TP1ZAI2B\AdLoader[1].htm
[2007.05.16 09:26:06 | 000,177,712 | ---- | M] () -- \Windows.old\Program Files\Common Files\Ahead\Lib\NeGuideStoreLoader.dll
[2011.10.17 14:10:26 | 000,071,528 | ---- | M] () -- \Windows.old\Program Files\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2011.11.06 11:09:52 | 000,083,816 | ---- | M] () -- \Windows.old\Program Files\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader.dll
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \Windows.old\Windows\system32\dmloader.dll
[1 \Windows.old\Windows\system32\*.tmp files -> \Windows.old\Windows\system32\*.tmp -> ]
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \Windows.old\Windows\system32\dllcache\dmloader.dll
[2012.07.14 22:28:46 | 000,086,866 | ---- | M] () -- \Windows\Prefetch\SOFTONICDOWNLOADER_FOR_WINRAR-5B40F21D.pf
[2009.07.14 03:03:49 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2009.07.14 06:54:01 | 000,003,532 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[2011.04.12 03:37:09 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2011.04.12 03:37:09 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86_winload.exe.mui_3bc5b827
[2011.04.12 03:37:09 | 000,030,272 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86_winresume.exe.mui_ff8b5358
[2010.11.20 23:31:02 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953.manifest
[2010.11.20 23:31:02 | 000,508,904 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953_winload.exe_75835076
[2010.11.20 23:31:02 | 000,442,720 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953_winresume.exe_85cd1215
[2009.07.14 04:17:38 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 04:17:38 | 000,017,472 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23_spldr.sys_98bd87a0
[2011.04.12 03:36:26 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_3318c4cd5e5d0f86.manifest
[2010.11.20 23:23:54 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953.manifest
[2009.07.14 03:52:31 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009.07.14 03:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll

< End of report >

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: preventivni log

#4 Příspěvek od vyosek »

:arrow: Zabalte mi prosim do raru slozku C:\Users\natsof\Desktop\RK_Quarantine a soubor RKreport[1].txt

:arrow: Nasledne uploadnete na LP http://leteckaposta.cz/ a odkaz dejte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

Re: preventivni log

#5 Příspěvek od jacktenrek »


Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: preventivni log

#6 Příspěvek od vyosek »

Spustte znovu RogueKiller a nechte jej dobehnou po volbe "Scan\Prohledat", teprve potom dejte "Report\Zprava"
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

Re: preventivni log

#7 Příspěvek od jacktenrek »

no mě to vyhazovalo v comodu jako malware musel jsem ho vypnout by to šlo ..

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: preventivni log

#8 Příspěvek od vyosek »

Zkuste prosim znovu a predtim Comodo stopnete, malware to neni, je to jedna z utilit...zkusim zabojovat u Comoda at ho vyradi z detekce
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

Re: preventivni log

#9 Příspěvek od jacktenrek »


Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: preventivni log

#10 Příspěvek od vyosek »

Super a dejte mi sem log co se objevil, mel by to byt RKreport[1].txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

Re: preventivni log

#11 Příspěvek od jacktenrek »

RogueKiller V7.6.4 [07/17/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v: Normální režim
Uživatel: natsof [Práva správce]
Mód: Kontrola -- Datum: 07/24/2012 21:59:28

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 2 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤
SSDT[70] : NtCreateKey @ 0x82A02E2A -> HOOKED (\??\C:\Windows\system32\Drivers\regguard.sys @ 0xA19C3AA0)
SSDT[103] : NtDeleteKey @ 0x829ED911 -> HOOKED (\??\C:\Windows\system32\Drivers\regguard.sys @ 0xA19C3DA0)
SSDT[106] : NtDeleteValueKey @ 0x829DF328 -> HOOKED (\??\C:\Windows\system32\Drivers\regguard.sys @ 0xA19C3FC0)
SSDT[182] : NtOpenKey @ 0x82A4D642 -> HOOKED (\??\C:\Windows\system32\Drivers\regguard.sys @ 0xA19C3C70)
SSDT[266] : NtQueryValueKey @ 0x82A4C405 -> HOOKED (\??\C:\Windows\system32\Drivers\regguard.sys @ 0xA19C40E0)
SSDT[358] : NtSetValueKey @ 0x82A0C427 -> HOOKED (\??\C:\Windows\system32\Drivers\regguard.sys @ 0xA19C3EB0)

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST500DM0 02-1BD142 SCSI Disk Device +++++
--- User ---
[MBR] ce0c54c87fe0fad264b66b07f63bb92c
[BSP] fdc4f0f45fe1580d173d69e559e32c22 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 99998 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 204796620 | Size: 376931 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive1: Verbatim STORE N GO USB Device +++++
--- User ---
[MBR] 6e4566267dc0709a2a92934cb8da40db
[BSP] 68a9d02fc733eb2bb650c31f80769756 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 7639 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: preventivni log

#12 Příspěvek od vyosek »

:arrow: Stahnete SytemLook http://jpshortstuff.247fixes.com/SystemLook.exe a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :filefind
    stdrt.exe
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

Re: preventivni log

#13 Příspěvek od jacktenrek »

SystemLook 30.07.11 by jpshortstuff
Log created at 22:10 on 24/07/2012 by natsof
Administrator - Elevation successful

========== filefind ==========

Searching for "stdrt.exe"
C:\Windows\Temp\mrt3A41.tmp\stdrt.exe --a---- 368640 bytes [12:00 21/07/2012] [12:00 21/07/2012] D905F7F23135F5884DD5174B91C454D3
C:\Windows\Temp\mrt47B9.tmp\stdrt.exe --a---- 368640 bytes [10:45 22/07/2012] [10:45 22/07/2012] D905F7F23135F5884DD5174B91C454D3
C:\Windows\Temp\mrt5E83.tmp\stdrt.exe --a---- 368640 bytes [09:29 24/07/2012] [09:29 24/07/2012] D905F7F23135F5884DD5174B91C454D3
C:\Windows\Temp\mrt646C.tmp\stdrt.exe --a---- 368640 bytes [09:46 24/07/2012] [09:46 24/07/2012] D905F7F23135F5884DD5174B91C454D3
C:\Windows\Temp\mrt71A6.tmp\stdrt.exe --a---- 368640 bytes [08:24 23/07/2012] [08:24 23/07/2012] D905F7F23135F5884DD5174B91C454D3

-= EOF =-

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: preventivni log

#14 Příspěvek od vyosek »

OK, pokracovani prosim rano, jdu na kute pac rano brzy vstavam :185:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jacktenrek
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 23 črc 2006 09:18

Re: preventivni log

#15 Příspěvek od jacktenrek »

:D :bye: a i tak :clapping: tak rano nekdy ..dobrou noc

Zamčeno