Stránka 1 z 2

Prolém s Sunbelt Kerio Firewall 4

Napsal: 23 pro 2007 16:49
od NIESRA
Mam takovy problem, kdyz mam zaply kerio tak po chvili se mi zacne ukazovat tabulka. Kdyz dam zavrit tak se mi ukaze znova a to do nekonecna az vypnu kompletne kerio. Nevite co to je a jak to vypnu? Diky

Napsal: 23 pro 2007 16:50
od Baron Prášil
pošli log z hijackthis (návod v podpisu)

Napsal: 23 pro 2007 22:14
od NIESRA
tady to je

Logfile of HijackThis v1.99.1
Scan saved at 22:12:08, on 23.12.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Seznam\Postak\Postak.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\Seznam\Postak\Postak .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui .exe
C:\Program Files\QIP\qip .exe
C:\Program Files\DAEMON Tools Lite\daemon .exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\explorer.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro .exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Futuremark\3DMark06\3DMark06.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli .exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli .exe
C:\Program Files\ATI Technologies\ATI.ACE\cli .exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\NIESRA\Plocha\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F3 - REG:win.ini: load=C:\WINDOWS\system32\geede.exe
O2 - BHO: (no name) - {58A35367-0297-47F7-93B6-9F0FCA31C77A} - C:\WINDOWS\system32\geede.dll
O2 - BHO: (no name) - {73F24B2F-4F7A-4BC2-A685-0333C49D1042} - C:\WINDOWS\system32\opnnlij.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: opnnlij - C:\WINDOWS\SYSTEM32\opnnlij.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe

Napsal: 23 pro 2007 22:26
od X
Průnik, někdo se ti chce hacknout do počítače a třeba ho (harddisk) kompletně smáznout :P

Napsal: 23 pro 2007 22:47
od NIESRA
Tak co mam delat aby mi to porad neukazovalo a zablokovalo ho to poradne?

Napsal: 24 pro 2007 00:06
od fredik
Baron tu momentálně není tak tě nasměruji já.

Stáhni si ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem klávesy 1
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah

Napsal: 24 pro 2007 12:43
od NIESRA
Tak udelalo mi to tohle:

ComboFix 07-12-21.4 - NIESRA 2007-12-24 12:27:49.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.1593 [GMT 1:00]
Running from: C:\Documents and Settings\NIESRA\Plocha\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\edeeg.ini
C:\WINDOWS\system32\edeeg.ini2
C:\WINDOWS\system32\geede.dll
C:\WINDOWS\system32\opnnlij.dll
C:\WINDOWS\system32\vtuvvsr.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.

Napsal: 24 pro 2007 14:01
od fredik
Ten log není celý! Mrkni se na C:\ po něm a pokud tam bude jen to co jsi sem vložil tak spusť znovu ComboFix a vlož sem log který se ti zobrazí po proběhnutí programu.

Napsal: 24 pro 2007 20:39
od NIESRA
Tak sem to udelal, ale je to porad to samy co sem uz tady vkladal vyse.

Napsal: 24 pro 2007 21:30
od fredik
Stáhni si Deckard's System Scanner (DSS) a ulož si ho na plochu
- ukonči všechna aktivní okna a spusť ho
- potvrď licenční podmínky a postupuj podle pokynů
- začne prohlídka systému
- po ukončení kontroly program vytvoří dva logy a zobrazí je: main.txt a extra.txt, tak sem vlož obsah souboru/logu main.txt
- jinak jsou logy uloženy v adresáři: c:\Deckard\System Scanner\

Napsal: 27 pro 2007 00:26
od NIESRA
tak tady to je:

Deckard's System Scanner v20071014.68
Run by NIESRA on 2007-12-27 00:21:15
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
36: 2007-12-26 23:21:18 UTC - RP36 - Deckard's System Scanner Restore Point
35: 2007-12-26 02:10:48 UTC - RP35 - Nainstalováno rozhraní DirectX
34: 2007-12-26 01:59:45 UTC - RP34 - Nainstalováno: Crysis(R).
33: 2007-12-26 00:16:50 UTC - RP33 - Advanced WindowsCare RestorePoint
32: 2007-12-25 23:57:51 UTC - RP32 - Installed Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch


-- First Restore Point --
1: 2007-12-24 20:07:34 UTC - RP1 - Kontrolní bod systému


Backed up registry hives.
Performed disk cleanup.

System Drive C: has 5.43 GiB (less than 15%) free.


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-12-27 00:22:55
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Seznam\Postak\Postak.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Seznam\Postak\Postak .exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI .exe
C:\Program Files\QIP\qip.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui .exe
C:\Program Files\QIP\qip .exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI .exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI .exe
C:\Program Files\uTorrent\utorrent.exe
C:\Documents and Settings\NIESRA\Plocha\dss.exe
C:\WINDOWS\system32\svchost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F0 - win.ini: load=C:\WINDOWS\system32\geede.exe
F3 - REG:win.ini: Load=C:\WINDOWS\system32\userinit.exe,
O2 - BHO: (no name) - {AE1063D7-7A71-44D0-925A-C8AAA30317F0} - C:\WINDOWS\system32\geede.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\RunOnceEx: [Flag] 2
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip .exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe


--
End of file - 4643 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

S3 catchme - c:\docume~1\niesra\locals~1\temp\catchme.sys (file missing)
S3 ENTECH - c:\windows\system32\drivers\entech.sys <Not Verified; EnTech Taiwan; PowerStrip>
S3 GMSIPCI - e:\install\gmsipci.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\7CD00310DC00
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\7CD00310DC00
Service: NIC1394


-- Files created between 2007-11-27 and 2007-12-27 -----------------------------

2007-12-26 01:16:20 0 d-------- C:\Program Files\IObit
2007-12-25 23:40:40 0 d-------- C:\Program Files\Midkemia Updater
2007-12-25 23:20:19 0 d-------- C:\Program Files\GamePark
2007-12-24 23:43:14 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-12-24 23:42:21 0 d-------- C:\Program Files\Common Files\Adobe
2007-12-24 21:07:24 7735 --ahs---- C:\WINDOWS\system32\edeeg.ini2
2007-12-24 20:46:02 0 d-------- C:\WINDOWS\system32\DX9
2007-12-24 20:45:15 0 d-------- C:\WINDOWS\system32\WinFox
2007-12-24 20:45:15 0 d-------- C:\WINDOWS\system32\WinFast
2007-12-24 20:45:15 9469 --a------ C:\WINDOWS\system32\drivers\WINFOXIO.sys <Not Verified; Leadtek Research Inc.; WinFox I/O Device (Windows 2000/XP)>
2007-12-24 14:20:16 0 d-------- C:\Program Files\Labels
2007-12-24 13:34:48 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2007-12-24 13:34:45 38912 --a------ C:\WINDOWS\system32\picn20.dll <Not Verified; Pegasus Imaging Corp.; PEGASUS>
2007-12-24 13:34:44 544768 --a------ C:\WINDOWS\system32\imagx5.dll <Not Verified; Pegasus Software, LLC; ImagXpress>
2007-12-24 13:34:44 569344 --a------ C:\WINDOWS\system32\imagr5.dll <Not Verified; Pegasus Software,LLC; ImagXpress>
2007-12-24 13:34:34 483328 --a------ C:\WINDOWS\system32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
2007-12-24 13:34:34 0 d-------- C:\Program Files\Common Files\Ahead
2007-12-24 13:34:30 0 d-------- C:\Program Files\Ahead
2007-12-24 13:31:09 0 d-------- C:\Program Files\Mv2Player
2007-12-24 12:47:46 0 d-------- C:\WINDOWS\SHELLNEW
2007-12-24 12:47:45 0 d-------- C:\Program Files\Microsoft.NET
2007-12-24 12:38:54 0 dr-h----- C:\MSOCache
2007-12-24 12:35:06 323072 --a------ C:\WINDOWS\system32\geede.dll
2007-12-23 17:35:49 4096 --a------ C:\WINDOWS\system32\crash
2007-12-23 17:18:25 0 d-------- C:\Program Files\Common Files\ATI Technologies
2007-12-23 17:13:03 0 d-------- C:\WINDOWS\system32\URTTEMP
2007-12-23 17:11:46 520192 --a------ C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2007-12-23 17:11:01 0 d-------- C:\Program Files\ATI Technologies
2007-12-23 16:44:14 3972 --a------ C:\WINDOWS\system32\drivers\PciBus.sys
2007-12-23 16:44:14 5632 --a------ C:\WINDOWS\system32\drivers\Entech64.sys <Not Verified; EnTech Taiwan; EnTech.sys>
2007-12-23 16:44:13 21664 --a------ C:\WINDOWS\system32\drivers\Entech.sys <Not Verified; EnTech Taiwan; PowerStrip>
2007-12-23 16:44:12 0 d-------- C:\WINDOWS\system32\Futuremark
2007-12-23 16:43:19 0 d-------- C:\Program Files\Futuremark
2007-12-23 12:03:56 0 d-------- C:\Program Files\vghd
2007-12-23 00:54:51 0 d-------- C:\Program Files\Sunbelt Software
2007-12-23 00:33:13 0 d--hs---- C:\WINDOWS\ftpcache
2007-12-22 21:36:17 0 d-------- C:\Program Files\Lavasoft
2007-12-22 21:34:41 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-22 21:06:19 0 d-------- C:\WINDOWS\system32\LogFiles
2007-12-22 21:02:17 0 d-------- C:\Program Files\Seznam
2007-12-22 20:05:00 442368 -ra------ C:\WINDOWS\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2007-12-22 18:06:33 326656 --a------ C:\WINDOWS\system32\geede.exe
2007-12-22 17:40:05 0 d-------- C:\Program Files\HellFIRE Screensaver
2007-12-22 17:13:33 0 d-------- C:\Games
2007-12-22 17:11:47 0 d-------- C:\Program Files\DAEMON Tools Lite
2007-12-22 17:01:30 0 d-------- C:\WINDOWS\RegisteredPackages
2007-12-22 16:59:29 0 d-------- C:\Program Files\Winamp
2007-12-22 16:36:19 715248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-22 16:32:19 737280 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-12-22 16:32:17 0 d-------- C:\Program Files\Codec Pack - All In 1
2007-12-22 16:25:29 0 d-------- C:\Program Files\Opera
2007-12-22 16:19:40 0 d-------- C:\Program Files\AMD
2007-12-22 16:05:24 0 d-------- C:\Program Files\YourWare Solutions
2007-12-22 16:03:10 8440 --a------ C:\WINDOWS\system32\drivers\LANPkt.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
2007-12-22 15:43:55 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2007-12-22 15:33:20 0 d-------- C:\WINDOWS\system32\Data
2007-12-22 15:15:29 0 d-------- C:\Program Files\uTorrent
2007-12-22 15:15:29 0 d-------- C:\Program Files\QIP
2007-12-22 15:15:12 0 d-------- C:\totalcmd
2007-12-22 15:14:40 0 d-------- C:\Downloads
2007-12-22 15:02:13 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-12-22 15:00:22 0 d-------- C:\Program Files\Common Files\InstallShield
2007-12-22 14:59:56 0 d-------- C:\ATI
2007-12-22 14:55:44 0 d-------- C:\WINDOWS\SoftwareDistribution
2007-12-22 14:55:43 0 d---s---- C:\WINDOWS\system32\Microsoft
2007-12-22 14:55:43 0 d-------- C:\WINDOWS\Prefetch
2007-12-22 14:54:35 0 d--hs---- C:\WINDOWS\Installer
2007-12-22 14:54:34 0 d-------- C:\Program Files\Common Files\ODBC
2007-12-22 14:54:32 0 d-------- C:\Program Files\Common Files\SpeechEngines
2007-12-22 14:54:31 0 dr------- C:\Program Files
2007-12-22 14:54:31 0 d-------- C:\Program Files\Common Files
2007-12-22 14:53:53 0 d-------- C:\WINDOWS\system32\CatRoot2
2007-12-22 14:53:53 0 d-------- C:\WINDOWS\system32\CatRoot
2007-12-22 14:53:23 0 d--hs---- C:\System Volume Information
2007-12-22 14:53:23 0 d-------- C:\Documents and Settings
2007-12-22 14:52:38 0 d-------- C:\WINDOWS\system32\xircom
2007-12-22 14:52:38 0 d-------- C:\Program Files\microsoft frontpage
2007-12-22 14:52:23 0 -rahs---- C:\MSDOS.SYS
2007-12-22 14:52:23 0 -rahs---- C:\IO.SYS
2007-12-22 14:52:23 0 --a------ C:\CONFIG.SYS
2007-12-22 14:52:23 0 --a------ C:\AUTOEXEC.BAT
2007-12-22 14:51:28 0 dr------- C:\WINDOWS\Offline Web Pages
2007-12-22 14:51:28 0 d---s---- C:\WINDOWS\Downloaded Program Files
2007-12-22 14:51:20 0 d--h----- C:\Program Files\WindowsUpdate
2007-12-22 14:51:16 0 d-------- C:\Program Files\Online Services
2007-12-22 14:51:03 0 d-------- C:\WINDOWS\system32\DirectX
2007-12-22 14:50:27 0 d---s---- C:\WINDOWS\Tasks
2007-12-22 14:50:26 0 d-------- C:\Program Files\Common Files\MSSoap
2007-12-22 14:50:22 0 d-------- C:\WINDOWS\srchasst
2007-12-22 14:50:21 0 d-------- C:\WINDOWS\system32\Macromed
2007-12-22 14:50:14 0 d-------- C:\Program Files\Movie Maker
2007-12-22 14:50:07 0 d-------- C:\WINDOWS\system32\Restore
2007-12-22 14:49:28 21812 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-12-22 14:49:13 0 d-------- C:\WINDOWS\Registration
2007-12-22 14:49:02 0 d-------- C:\Program Files\Messenger
2007-12-22 14:48:58 0 d-------- C:\Program Files\MSN Gaming Zone
2007-12-22 14:48:31 0 d-------- C:\Program Files\Windows NT
2007-12-22 14:48:28 0 d-------- C:\WINDOWS\system32\MsDtc
2007-12-22 14:48:26 0 d-------- C:\WINDOWS\system32\Com
2007-12-22 14:47:08 0 d-------- C:\WINDOWS
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\WinSxS
2007-12-22 14:47:08 0 dr------- C:\WINDOWS\Web
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\twain_32
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\wins
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\wbem
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\usmt
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\spool
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\ShellExt
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\Setup
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\ras
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\oobe
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\npp
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\mui
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\inetsrv
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\IME
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\icsxml
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\ias
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\export
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\drivers
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\drivers\etc
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\drivers\disdn
2007-12-22 14:47:08 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\dhcp
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\config
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\3com_dmi
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\3076
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\2052
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1054
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1042
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1041
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1037
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1033
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1031
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1029
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1028
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system32\1025
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\system
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\security
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Resources
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\repair
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Provisioning
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\pchealth
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\PeerNet
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\mui
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\msapps
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\msagent
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Media
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\java
2007-12-22 14:47:08 0 d--h----- C:\WINDOWS\inf
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\ime
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Help
2007-12-22 14:47:08 0 dr--s---- C:\WINDOWS\Fonts
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\ehome
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Driver Cache
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Debug
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Cursors
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Connection Wizard
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\Config
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\AppPatch
2007-12-22 14:47:08 0 d-------- C:\WINDOWS\addins


-- Find3M Report ---------------------------------------------------------------

2007-12-27 00:21:31 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\uTorrent
2007-12-25 00:01:03 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\Adobe
2007-12-24 13:36:54 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\Ahead
2007-12-23 17:25:25 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\ATI
2007-12-23 17:13:45 398250 --a------ C:\WINDOWS\system32\perfh005.dat
2007-12-23 17:13:45 73506 --a------ C:\WINDOWS\system32\perfc005.dat
2007-12-23 12:03:45 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\vghd
2007-12-22 18:09:56 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\WinRAR
2007-12-22 18:03:21 0 dr-h----- C:\Documents and Settings\NIESRA\Data aplikací\SecuROM
2007-12-22 17:36:25 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\DAEMON Tools
2007-12-22 17:12:36 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\InstallShield
2007-12-22 17:01:51 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\Winamp
2007-12-22 16:49:47 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\Macromedia
2007-12-22 16:26:39 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\Opera
2007-12-22 14:58:04 0 d-------- C:\Documents and Settings\NIESRA\Data aplikací\Identities
2007-12-22 14:54:04 62 --ahs---- C:\Documents and Settings\NIESRA\Data aplikací\desktop.ini


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE1063D7-7A71-44D0-925A-C8AAA30317F0}]
2007-12-24 12:35 323072 --a------ C:\WINDOWS\system32\geede.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-04-12 08:53 C:\WINDOWS\system32\P17.dll]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [2007-12-23 23:10]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-23 23:10]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2007-12-24 12:28]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" []
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-26 22:47]
"QIP2005"="C:\Program Files\QIP\qip .exe" [2007-12-26 22:47]

C:\Documents and Settings\NIESRA\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geede

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule




-- End of Deckard's System Scanner: finished at 2007-12-27 00:24:15 ------------

Napsal: 27 pro 2007 00:54
od melior
Nejsem v tom zas tak zbehly, jen sem parkrat sobe vykopaval smejdy ze systemu, ale tady je moje rada:
*----*

IGNORE ME
radsi sem to odmazal (Melior)

*-----*