Stránka 1 z 3

Modrá smrt

Napsal: 09 čer 2009 13:51
od danty
Poslední dobou mi častěji padá systém.Zkoušel sem reinstalaci wydlí ale pády pokračují.Mám 2 harddisky a 3 op.sistémy 2x XP pro a 1x Win 7.Pády se vyskytují jen většinou jen u 1 wydlí,2 mám jen na hry. Většinou padá systém chvilku po naběhnutí woken,ukáže se modrá obrazovka a po odpočítávání naběhnou znova a už v klidu.Občas se ale stává že spadnou wonka i během používání.Vyzkoušel sem několik skenrů na šmejdy,i online antiviry ale nic se nenašlo.Už netuším v čem může být chyba a tak prosím o radu,co stím.Aktualizace mám pravidelné,antivir i antispyvare programy nainstalovány,firewale též.Předem děkuji za rady.



Obrázek
Přikládám log

Logfile of random's system information tool 1.06 (written by random/random)
Run by xx at 2009-06-09 14:45:42
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 20 GB (49%) free of 41 GB
Total RAM: 959 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:45:45, on 9.6.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\3xHybridRMT.exe
C:\program files\giovanni software\počítačové kukačky\pckukacky.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\Program Files\VisualTaskTips\VisualTaskTips.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\xx\Plocha\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\xx.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\3xHybridRMT.exe
O4 - HKLM\..\Run: [pckukacky] c:\program files\giovanni software\počítačové kukačky\pckukacky.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [Thumbnail preview images for your taskbar.] C:\Program Files\VisualTaskTips\VisualTaskTips.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: CamTrack.lnk = C:\Program Files\DigitalPeers\CamTrack\camtrack.exe (User 'Default user')
O4 - Startup: Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c9b8897e950f2) (gupdate1c9b8897e950f2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe

--
End of file - 10189 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-04-07 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-05-20 312928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-07 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-04-07 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-04-07 520192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-01-15 13680640]
"nwiz"=nwiz.exe /install []
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"TV Card Remote Control Device Monitor"=C:\WINDOWS\3xHybridRMT.exe [2006-07-27 417792]
"pckukacky"=c:\program files\giovanni software\počítačové kukačky\pckukacky.exe [2004-12-12 81920]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-08-01 16049664]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-01-15 86016]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [1980-01-01 15360]
"TuneUp MemOptimizer"=C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe [2007-05-13 312840]
"Thumbnail preview images for your taskbar."=C:\Program Files\VisualTaskTips\VisualTaskTips.exe [2008-06-22 65536]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]

C:\Documents and Settings\xx\Nabídka Start\Programy\Po spuštění
Alienware Dock.lnk - C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="wbsys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files\AlienGUIse\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\Windows Defender\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"Q:\programy\BlueSoleil_3.2.2.8_Vista_compatible_by_tomukazz\BlueSoleil v3.2.2.8 Vista compatible\C R A C K\BlueSoleil.exe"="Q:\programy\BlueSoleil_3.2.2.8_Vista_compatible_by_tomukazz\BlueSoleil v3.2.2.8 Vista compatible\C R A C K\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======List of files/folders created in the last 1 months======

2009-06-09 14:45:42 ----D---- C:\rsit
2009-06-09 14:41:13 ----D---- C:\Program Files\WhoCrashed
2009-06-05 23:06:29 ----D---- C:\Documents and Settings\xx\Data aplikací\vlc
2009-05-31 19:12:47 ----D---- C:\Documents and Settings\xx\Data aplikací\Spy Emergency
2009-05-31 19:12:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\NETGATE
2009-05-31 18:29:09 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-31 18:29:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2009-05-24 22:10:13 ----D---- C:\Program Files\AWD česká republika s.r.o
2009-05-24 10:30:53 ----D---- C:\Documents and Settings\xx\Data aplikací\Desktopicon
2009-05-24 10:30:23 ----D---- C:\Program Files\DsNET Corp
2009-05-21 12:07:44 ----D---- C:\Program Files\DigitalPeers
2009-05-20 17:55:28 ----HDC---- C:\WINDOWS\$NtUninstallKB909394$
2009-05-20 17:54:52 ----D---- C:\Program Files\Microsoft ActiveSync
2009-05-20 17:47:27 ----D---- C:\Program Files\Common Files\xing shared
2009-05-20 01:40:03 ----D---- C:\Documents and Settings\xx\Data aplikací\CamTrack
2009-05-18 14:17:47 ----D---- C:\Documents and Settings\xx\Data aplikací\Zoner
2009-05-18 14:17:02 ----D---- C:\Program Files\Zoner
2009-05-11 20:47:30 ----D---- C:\Program Files\WeFi
2009-05-11 20:45:17 ----A---- C:\WINDOWS\system32\ZDPN50.DLL
2009-05-11 20:45:15 ----D---- C:\Program Files\IEEE 802.11g USB Wireless LAN
2009-05-11 20:45:15 ----A---- C:\WINDOWS\system32\ZyDelReg.exe
2009-05-11 20:45:15 ----A---- C:\WINDOWS\system32\InsDrvZD64.DLL
2009-05-11 20:45:15 ----A---- C:\WINDOWS\system32\InsDrvZD.dll
2009-05-11 18:56:59 ----SHD---- C:\$RECYCLE.BIN
2009-05-11 01:34:21 ----RASH---- C:\BOOTSECT.BAK
2009-05-11 01:34:20 ----H---- C:\Boot.BAK
2009-05-11 01:34:19 ----SHD---- C:\Boot
2009-05-10 17:04:34 ----D---- C:\WINDOWS\NV2524192.TMP
2009-05-10 17:03:29 ----D---- C:\Program Files\DIFX
2009-05-10 17:03:26 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-05-10 12:33:15 ----D---- C:\Program Files\Common Files\Stardock
2009-05-10 12:33:15 ----D---- C:\Program Files\AlienGUIse
2009-05-10 12:33:15 ----A---- C:\WINDOWS\wb.ini
2009-05-10 12:33:15 ----A---- C:\WINDOWS\system32\wbsys.dll
2009-05-10 12:30:08 ----D---- C:\Program Files\VisualTaskTips

======List of files/folders modified in the last 1 months======

2009-06-09 14:42:04 ----D---- C:\WINDOWS
2009-06-09 14:42:04 ----A---- C:\WINDOWS\MAILTRAN.INI
2009-06-09 14:41:59 ----D---- C:\WINDOWS\Temp
2009-06-09 14:41:58 ----D---- C:\Program Files\Mozilla Firefox
2009-06-09 14:41:25 ----D---- C:\WINDOWS\Prefetch
2009-06-09 14:41:13 ----SD---- C:\Program Files
2009-06-09 14:37:22 ----D---- C:\Documents and Settings\xx\Data aplikací\Skype
2009-06-09 09:20:56 ----A---- C:\WINDOWS\TRNCOM.INI
2009-06-09 08:03:55 ----D---- C:\Documents and Settings\xx\Data aplikací\skypePM
2009-06-09 02:32:37 ----SD---- C:\WINDOWS\Tasks
2009-06-08 17:55:33 ----D---- C:\Documents and Settings\xx\Data aplikací\OpenOffice.org2
2009-06-08 10:16:35 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-06-08 10:16:35 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-07 15:03:48 ----HD---- C:\WINDOWS\inf
2009-06-06 15:27:03 ----SHD---- C:\System Volume Information
2009-06-06 14:34:32 ----A---- C:\WINDOWS\wincmd.ini
2009-06-06 12:34:37 ----D---- C:\Documents and Settings\xx\Data aplikací\dvdcss
2009-06-06 12:22:28 ----D---- C:\Documents and Settings\xx\Data aplikací\esmska
2009-06-05 23:40:55 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2009-06-05 23:05:41 ----D---- C:\Program Files\VideoLAN
2009-06-05 22:38:43 ----D---- C:\WINDOWS\Minidump
2009-06-05 14:06:17 ----SD---- C:\Documents and Settings\xx\Data aplikací\Microsoft
2009-06-04 16:47:01 ----SHD---- C:\WINDOWS\Installer
2009-06-04 16:47:00 ----HD---- C:\Config.Msi
2009-06-04 16:46:17 ----D---- C:\WINDOWS\system32\drivers
2009-05-31 21:42:19 ----SHD---- C:\Documents and Settings\xx\Data aplikací\.#
2009-05-31 19:12:47 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2009-05-31 18:28:59 ----D---- C:\WINDOWS\WinSxS
2009-05-31 00:08:51 ----D---- C:\WINDOWS\system32
2009-05-31 00:08:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-30 17:58:53 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-05-30 17:51:31 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-30 17:49:14 ----D---- C:\WINDOWS\Help
2009-05-24 10:50:02 ----D---- C:\Documents and Settings\xx\Data aplikací\Vso
2009-05-21 12:11:37 ----D---- C:\Program Files\Share Rapid Uploader
2009-05-20 17:54:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-20 17:47:27 ----D---- C:\Program Files\Common Files
2009-05-20 17:47:18 ----D---- C:\Program Files\Common Files\Real
2009-05-20 17:47:16 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-05-20 17:47:01 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-05-20 17:47:01 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-05-20 17:46:57 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-05-19 23:13:46 ----D---- C:\WINDOWS\Debug
2009-05-18 14:40:34 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-05-18 14:17:10 ----RSD---- C:\WINDOWS\Fonts
2009-05-16 03:49:17 ----D---- C:\WINDOWS\system32\config
2009-05-16 03:48:59 ----D---- C:\WINDOWS\system32\wbem
2009-05-16 03:48:58 ----D---- C:\WINDOWS\Registration
2009-05-16 01:03:15 ----RSH---- C:\boot.ini
2009-05-14 15:16:15 ----D---- C:\Program Files\Google
2009-05-11 20:45:15 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-10 17:04:39 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-05-10 17:02:43 ----A---- C:\WINDOWS\Ascd_tmp.ini
2009-05-10 16:57:54 ----D---- C:\Program Files\Common Files\Adobe
2009-05-10 12:25:42 ----D---- C:\Program Files\Outlook Express
2009-05-10 12:25:42 ----D---- C:\Program Files\Movie Maker
2009-05-10 12:25:42 ----D---- C:\Program Files\Internet Explorer
2009-05-10 12:25:41 ----D---- C:\WINDOWS\system32\usmt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 SbFw;SbFw; C:\WINDOWS\system32\drivers\SbFw.sys [2008-07-16 269736]
R1 sbhips;Sunbelt HIPS Driver; C:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-11-02 56572]
R1 SpyEmrg;Spy Emergency Driver; C:\WINDOWS\System32\Drivers\spyemrg.sys [2009-02-04 12344]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
R2 WinFl32;WinFl32; \??\C:\WINDOWS\system32\WinFl32.sys []
R2 WinVd32;WinVd32; \??\C:\WINDOWS\system32\WinVd32.sys []
R3 3xHybrid;SAA7135 TV Card Service; C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-05-20 710784]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-02-05 23152]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-03-05 34576]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-03-05 39184]
R3 dptrackerd;CamTrack Webcam Driver; C:\WINDOWS\system32\drivers\dptrackerd.sys [2008-04-30 108488]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [1980-01-01 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-08-01 4356608]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [1980-01-01 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-01-15 6301248]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-07-11 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-07-11 20480]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-04-12 47360]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [1980-01-01 5888]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [1980-01-01 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [1980-01-01 57600]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [1980-01-01 17024]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [1980-01-01 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [1980-01-01 20480]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 ZSMC301b;Look 312P; C:\WINDOWS\System32\Drivers\usbVM31b.sys [2004-03-19 90968]
S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [1980-01-01 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [1980-01-01 10880]
S3 SIVDRIVER;SIV Kernel Driver; \??\C:\WINDOWS\system32\Drivers\SIVX32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [1980-01-01 11136]
S3 SpyEmrgAccess;Spy Emergency OnAccess Driver; C:\WINDOWS\System32\Drivers\spyemrg_access.sys [2009-04-21 18232]
S3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver; C:\WINDOWS\System32\Drivers\spyemrg_guard.sys [2009-02-04 14392]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [1980-01-01 15360]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [1980-01-01 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZD1211BU(WLAN);IEEE 802.11g USB Wireless LAN(WLAN); C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 402432]
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2004-10-25 17664]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-04-03 20543]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2006-07-13 131131]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-07-13 65599]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-01-15 163908]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 SbPF.Launcher;SbPF.Launcher; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-07-30 95528]
R2 SPF4;Sunbelt Personal Firewall 4; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-07-30 1361192]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
R3 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-05-04 654848]
S3 gupdate1c9b8897e950f2;Google Update Service (gupdate1c9b8897e950f2); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-08 133104]
S3 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-04-07 152984]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Start BT in service;Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-04-21 52080]
S3 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [1980-01-01 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [1980-01-01 14336]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
S4 SpyEmrgSrv;Spy Emergency Engine Service; C:\Program Files\NETGATE\Spy Emergency 2009\SpyEmergencySrv.exe []

-----------------EOF-----------------

Re: Modrá smrt

Napsal: 09 čer 2009 17:01
od Damned
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Re: Modrá smrt

Napsal: 09 čer 2009 17:22
od danty
Malwarebytes' Anti-Malware 1.37
Verze databáze: 2254
Windows 5.1.2600 Service Pack 2

9.6.2009 17:13:55
mbam-log-2009-06-09 (17-13-55).txt

Typ skenu: Rychlý sken
Objektu skenováno: 90986
Uplynulý cas: 4 minute(s), 26 second(s)

Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)

Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)

Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované složky:
(Žádné zákerné položky nebyly zjišteny)

Infikované soubory:
(Žádné zákerné položky nebyly zjišteny)

Re: Modrá smrt

Napsal: 09 čer 2009 17:53
od Damned
Pracuje se mi lépe s ComboFixem.
Proto:
Vypni rezidentní štít antiviru (pokud máš tak i antispyware).
Stáhni si ComboFix (by sUBs)
nebo ComboFix (subs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah

Re: Modrá smrt

Napsal: 09 čer 2009 18:43
od danty
ComboFix 09-06-08.05 - xx 09.06.2009 18:20.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.959.478 [GMT 2:00]
Spuštěný z: c:\documents and settings\xx\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090608-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ActiveArmor Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
FW: Sunbelt Personal Firewall *enabled* {F61A549E-9C8A-4859-8BFE-2A4A018BBA4A}
SP: Spy Emergency *disabled* (Updated) {82117492-906E-4b02-A33A-84D42A2DD907}
SP: Windows Defender *disabled* (Updated) {FDFE477F-8FE7-4B17-A05C-9D1F9EB603CB}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\xx\Data aplikací\Microsoft\Internet Explorer\Quick Launch\avast! Antivirus.lnk
c:\documents and settings\xx\Data aplikací\Microsoft\Internet Explorer\Quick Launch\xp-AntiSpy.lnk
c:\windows\system32\Ijl11.dll
c:\windows\system32\setup.ini

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-05-09 do 2009-06-09 )))))))))))))))))))))))))))))))
.

2009-06-09 15:08 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-09 15:07 . 2009-06-09 15:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-09 15:07 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-09 12:45 . 2009-06-09 12:45 -------- d-----w- C:\rsit
2009-06-09 12:41 . 2009-06-09 12:41 -------- d-----w- c:\program files\WhoCrashed
2009-06-08 16:23 . 2009-06-08 16:28 332 ----a-w- c:\windows\desctemp.dat
2009-05-31 17:12 . 2009-04-21 15:55 18232 ----a-w- c:\windows\system32\drivers\spyemrg_access.sys
2009-05-31 17:12 . 2009-02-04 16:42 14392 ----a-w- c:\windows\system32\drivers\spyemrg_guard.sys
2009-05-31 17:12 . 2009-02-04 16:42 12344 ----a-w- c:\windows\system32\drivers\spyemrg.sys
2009-05-24 20:10 . 2009-05-24 20:10 -------- d-----w- c:\program files\AWD česká republika s.r.o
2009-05-24 08:30 . 2009-05-24 08:30 -------- d-----w- c:\program files\DsNET Corp
2009-05-21 10:07 . 2009-05-21 10:07 -------- d-----w- c:\program files\DigitalPeers
2009-05-20 15:55 . 2005-10-21 01:47 12800 ------w- c:\windows\system32\drivers\usb8023x.sys
2009-05-20 15:55 . 2005-10-21 01:47 30592 ------w- c:\windows\system32\drivers\rndismpx.sys
2009-05-20 15:54 . 2009-05-30 15:49 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-05-20 15:47 . 2009-05-20 15:47 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-19 23:11 . 2008-04-30 19:01 108488 ----a-w- c:\windows\system32\drivers\dptrackerd.sys
2009-05-18 19:52 . 2009-05-15 05:01 49656 ----a-w- c:\windows\system32\drivers\SIVX32.sys
2009-05-18 12:17 . 2009-05-18 12:40 -------- d-----w- c:\program files\Zoner
2009-05-16 01:48 . 2009-05-16 01:48 -------- d-----w- c:\windows\system32\wbem\Repository
2009-05-11 18:47 . 2009-05-31 19:05 -------- d-----w- c:\program files\WeFi
2009-05-11 18:45 . 2005-10-28 09:38 402432 ----a-w- c:\windows\system32\drivers\ZD1211BU.sys
2009-05-11 18:45 . 2005-06-08 16:44 29184 ----a-w- c:\windows\system32\drivers\BRGSp50a64.sys
2009-05-11 18:45 . 2005-06-08 16:44 20608 ----a-w- c:\windows\system32\drivers\BRGSp50.sys
2009-05-11 18:45 . 2004-10-25 11:40 17664 ----a-w- c:\windows\system32\drivers\ZDPSp50.sys
2009-05-11 18:45 . 2004-01-14 09:30 17151 ----a-w- c:\windows\system32\ZDPNDIS5.SYS
2009-05-11 18:45 . 2004-01-14 09:25 81920 ----a-w- c:\windows\system32\ZDPN50.DLL
2009-05-11 18:45 . 2009-05-11 18:45 -------- d-----w- c:\program files\IEEE 802.11g USB Wireless LAN
2009-05-11 18:45 . 2005-07-12 12:44 15872 ----a-w- c:\windows\system32\InsDrvZD64.DLL
2009-05-11 18:45 . 2004-03-23 14:38 28672 ----a-w- c:\windows\system32\InsDrvZD.dll
2009-05-11 18:45 . 2003-03-14 10:24 24576 ----a-w- c:\windows\system32\ZyDelReg.exe
2009-05-10 23:34 . 2009-05-15 23:03 -------- d-sh--w- C:\Boot

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-05 21:05 . 2009-04-07 16:46 -------- d-----w- c:\program files\VideoLAN
2009-05-31 19:41 . 2009-04-29 17:34 6024 --sha-w- c:\windows\system32\sys_drv.dat
2009-05-30 22:08 . 1980-01-01 00:00 74606 ----a-w- c:\windows\system32\perfc005.dat
2009-05-30 22:08 . 1980-01-01 00:00 402000 ----a-w- c:\windows\system32\perfh005.dat
2009-05-21 10:11 . 2009-04-14 21:07 -------- d-----w- c:\program files\Share Rapid Uploader
2009-05-20 18:47 . 2009-05-10 10:33 -------- d-----w- c:\program files\AlienGUIse
2009-05-20 15:47 . 2009-04-08 17:10 -------- d-----w- c:\program files\Common Files\Real
2009-05-18 12:40 . 2009-04-07 15:31 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-14 13:16 . 2009-04-08 20:31 -------- d-----w- c:\program files\Google
2009-05-11 18:45 . 2009-04-07 15:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-10 15:03 . 2009-05-10 15:03 -------- d-----w- c:\program files\DIFX
2009-05-10 14:57 . 2009-04-07 16:18 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-10 10:33 . 2009-05-10 10:33 -------- d-----w- c:\program files\Common Files\Stardock
2009-05-10 10:30 . 2009-05-10 10:30 -------- d-----w- c:\program files\VisualTaskTips
2009-05-09 12:23 . 2009-05-09 12:23 -------- d-----w- c:\program files\MediaCoder
2009-05-08 18:04 . 2009-05-08 17:50 5654 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2009-05-08 18:04 . 2009-04-07 16:03 71634 ----a-w- c:\windows\BricoPackUninst.cmd
2009-05-08 18:04 . 1980-01-01 00:00 219648 ----a-w- c:\windows\system32\uxtheme.dll
2009-05-08 17:00 . 2009-04-07 14:35 23544 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-06 17:44 . 2009-05-06 17:44 -------- d-----w- c:\program files\Trend Micro
2009-05-04 17:18 . 2009-05-04 17:18 -------- d-----w- c:\program files\Bonjour
2009-05-04 17:10 . 2009-05-04 17:10 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-05-04 17:02 . 2009-05-04 15:20 -------- d-----w- c:\program files\CamSpace
2009-04-29 17:39 . 2009-04-29 17:28 180224 ----a-w- c:\windows\system32\WinVd32.sys
2009-04-29 17:39 . 2009-04-29 17:28 16384 ----a-w- c:\windows\system32\WinFl32.sys
2009-04-29 17:39 . 2009-04-29 17:13 -------- d-----w- c:\program files\Folder Lock 6
2009-04-26 09:33 . 2009-04-26 09:33 -------- d-----w- c:\program files\uTorrent
2009-04-25 12:11 . 2009-04-25 12:11 -------- d-----w- c:\program files\Tuning Car Studio
2009-04-24 22:30 . 2009-04-24 22:28 -------- d-----w- c:\program files\Your Uninstaller 2008
2009-04-22 15:40 . 2009-04-21 20:42 -------- d-----w- c:\program files\SMS posílač Treca
2009-04-19 18:38 . 2009-04-19 18:38 -------- d-----w- c:\program files\Windows Defender
2009-04-19 18:37 . 2009-04-19 18:37 -------- d-----w- c:\program files\Photo Story 3 for Windows
2009-04-18 18:29 . 2009-04-18 18:28 -------- d-----w- c:\program files\Accuracy trainer
2009-04-17 20:15 . 2009-04-17 20:15 -------- d-----w- c:\program files\Stellarium
2009-04-16 15:56 . 2009-04-07 17:02 -------- d-----w- c:\program files\Unlocker
2009-04-13 21:25 . 2009-04-13 21:25 -------- d-----w- c:\program files\7-Zip
2009-04-13 21:05 . 2009-04-13 21:05 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-13 21:01 . 2009-04-13 21:01 -------- d-----w- c:\program files\MSXML 4.0
2009-04-13 19:50 . 2009-04-13 19:50 -------- d-----w- c:\program files\Microsoft
2009-04-13 19:49 . 2009-04-13 19:49 -------- d-----w- c:\program files\Windows Live
2009-04-13 19:49 . 2009-04-13 19:49 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-04-13 19:45 . 2009-04-13 19:45 -------- d-----w- c:\program files\Common Files\Windows Live
2009-04-13 12:37 . 2009-04-13 12:36 -------- d-----w- c:\program files\ScreenShots
2009-04-13 12:35 . 2009-04-13 12:35 -------- d-----w- c:\program files\JPEG Resampler
2009-04-12 20:48 . 2009-04-12 20:48 -------- d-----w- c:\program files\Giovanni Software
2009-04-12 18:11 . 2009-04-12 18:11 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-04-12 18:11 . 2009-04-12 18:11 -------- d-----w- c:\program files\VSO
2009-04-12 12:33 . 2009-04-12 12:33 -------- d-----w- c:\program files\IVT Corporation
2009-04-10 16:59 . 2009-04-07 14:38 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-10 16:59 . 2009-04-07 14:38 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-04-10 16:58 . 2009-04-07 14:38 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-04-08 15:34 . 2009-04-08 15:35 737280 ----a-w- c:\windows\iun6002.exe
2009-04-07 18:48 . 2009-04-07 18:33 112835 ----a-w- c:\windows\hpoins07.dat
2009-04-07 17:12 . 2009-04-07 17:12 45056 ----a-w- c:\windows\TRNOEH.DLL
2009-04-07 17:12 . 2009-04-07 17:12 26624 ----a-w- c:\windows\OETRN.EXE
2009-04-07 17:12 . 2009-04-07 17:12 200704 ----a-w- c:\windows\TRNOET.DLL
2009-04-07 17:11 . 2009-04-07 17:11 516096 ----a-w- c:\windows\UN32.EXE
2009-04-07 16:36 . 2009-04-07 16:36 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-04-07 16:20 . 2009-04-07 16:20 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-07 15:23 . 2009-04-07 15:23 0 ----a-w- c:\windows\nsreg.dat
2009-04-07 14:58 . 2009-04-07 14:56 6422528 ----a-w- c:\windows\system32\SET6C.tmp
.

------- Sigcheck -------

[-] 1980-01-01 00:00 215552 A77219A971029DC2FB683E8513713803 c:\windows\system32\termsrv.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [1980-01-01 15360]
"Thumbnail preview images for your taskbar."="c:\program files\VisualTaskTips\VisualTaskTips.exe" [2008-06-22 65536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"TV Card Remote Control Device Monitor"="c:\windows\3xHybridRMT.exe" [2006-07-27 417792]
"pckukacky"="c:\program files\giovanni software\počítačové kukačky\pckukacky.exe" [2004-12-12 81920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [1980-01-01 159232]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-05-26 414480]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-01-15 1657376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-08-01 16049664]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [1980-01-01 15360]

c:\documents and settings\Default User\Nabˇdka Start\Programy\Po spuçtŘnˇ\
CamTrack.lnk - c:\program files\DigitalPeers\CamTrack\camtrack.exe [2009-5-21 468584]

c:\documents and settings\Default User\Nabˇdka Start\Programy\Po spuçtŘnˇ\
CamTrack.lnk - c:\program files\DigitalPeers\CamTrack\camtrack.exe [2009-5-21 468584]

c:\documents and settings\xx\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Alienware Dock.lnk - c:\program files\AlienGUIse\AlienwareDock\ObjectDock.exe [2009-5-10 2074360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 21:34 24576 ----a-w- c:\program files\AlienGUIse\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"q:\\programy\\BlueSoleil_3.2.2.8_Vista_compatible_by_tomukazz\\BlueSoleil v3.2.2.8 Vista compatible\\C R A C K\\BlueSoleil.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7.4.2009 17:18 114768]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [7.4.2009 17:15 269736]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R1 SpyEmrg;Spy Emergency Driver;c:\windows\system32\drivers\spyemrg.sys [31.5.2009 19:12 12344]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7.4.2009 17:18 20560]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9.6.2009 17:08 194832]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [30.7.2008 10:36 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [30.7.2008 10:36 1361192]
R3 3xHybrid;SAA7135 TV Card Service;c:\windows\system32\drivers\3xHybrid.sys [7.4.2009 20:29 710784]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9.6.2009 17:07 19096]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [7.4.2009 17:15 65576]
S3 CrystalSysInfo;CrystalSysInfo;c:\program files\MediaCoder\SysInfo.sys [25.9.2007 16:59 15152]
S3 gupdate1c9b8897e950f2;Google Update Service (gupdate1c9b8897e950f2);c:\program files\Google\Update\GoogleUpdate.exe [8.4.2009 22:31 133104]
S3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\drivers\SIVX32.sys [18.5.2009 21:52 49656]
S3 SpyEmrgAccess;Spy Emergency OnAccess Driver;c:\windows\system32\drivers\spyemrg_access.sys [31.5.2009 19:12 18232]
S3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver;c:\windows\system32\drivers\spyemrg_guard.sys [31.5.2009 19:12 14392]
S3 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [21.4.2007 14:54 52080]
S3 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
S3 ZD1211BU(WLAN);IEEE 802.11g USB Wireless LAN(WLAN);c:\windows\system32\drivers\ZD1211BU.sys [11.5.2009 20:45 402432]
S4 SpyEmrgSrv;Spy Emergency Engine Service;c:\program files\NETGATE\Spy Emergency 2009\SpyEmergencySrv.exe --> c:\program files\NETGATE\Spy Emergency 2009\SpyEmergencySrv.exe [?]

--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - MBAMSERVICE
.
Obsah adresáře 'Naplánované úlohy'

2009-06-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-05-20 17:17]

2009-06-08 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-08 20:31]

2009-06-09 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

SafeBoot-procexp90.Sys


.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
FF - ProfilePath - c:\documents and settings\xx\Data aplikací\Mozilla\Firefox\Profiles\a1v66d00.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-09 18:28
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Device Monitor = c:\windows\3xHybridRMT.exe?|??????6~????????????X???????????}??f????????????X?????????6~????????????4???????????@??????f????????????X?????6~??<~<???@?????6~Y?6~??????6~??????????6~???????????f????W?9~`?6~????Y?6~4?6~????????????X?????6~??????A???????@??KA???B

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1343024091-764733703-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1124)
c:\program files\AlienGUIse\fastload.dll
.
Celkový čas: 2009-06-09 18:31
ComboFix-quarantined-files.txt 2009-06-09 16:31

Před spuštěním: Volných bajtů: 21 065 637 888
Po spuštění: Volných bajtů: 21 076 537 344

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT /TUTAG=ROGLNQ NOGUIBOOT /USEPMTIMER
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT /USEPMTIMER

281 --- E O F --- 2009-06-04 14:49

Re: Modrá smrt

Napsal: 09 čer 2009 19:47
od Damned
Odinstaluj Folder lock . Soubor: c:\windows\3xHybridRMT.exe otestuj na Virustotalu .

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

File::
c:\windows\system32\SET6C.tmp


DirLook::
C:\Boot
c:\program files\DIFX




Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.


Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.
Obrázek

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Re: Modrá smrt

Napsal: 09 čer 2009 20:34
od El Diablo
Prověř RAM memtestem, HDD utilitou od výrobce!

Re: Modrá smrt

Napsal: 09 čer 2009 20:36
od danty
Tak vše přesně provedeno,zde logy

ComboFix 09-06-08.05 - xx 09.06.2009 20:12.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.959.249 [GMT 2:00]
Spuštěný z: c:\documents and settings\xx\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\xx\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090608-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ActiveArmor Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
FW: Sunbelt Personal Firewall *enabled* {F61A549E-9C8A-4859-8BFE-2A4A018BBA4A}
SP: Spy Emergency *disabled* (Updated) {82117492-906E-4b02-A33A-84D42A2DD907}
SP: Windows Defender *disabled* (Updated) {FDFE477F-8FE7-4B17-A05C-9D1F9EB603CB}

FILE ::
"c:\windows\system32\SET6C.tmp"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\SET6C.tmp

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-05-09 do 2009-06-09 )))))))))))))))))))))))))))))))
.

2009-06-09 15:08 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-09 15:07 . 2009-06-09 15:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-09 15:07 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-09 12:45 . 2009-06-09 12:45 -------- d-----w- C:\rsit
2009-06-09 12:41 . 2009-06-09 12:41 -------- d-----w- c:\program files\WhoCrashed
2009-06-08 16:23 . 2009-06-08 16:28 332 ----a-w- c:\windows\desctemp.dat
2009-05-31 17:12 . 2009-04-21 15:55 18232 ----a-w- c:\windows\system32\drivers\spyemrg_access.sys
2009-05-31 17:12 . 2009-02-04 16:42 14392 ----a-w- c:\windows\system32\drivers\spyemrg_guard.sys
2009-05-31 17:12 . 2009-02-04 16:42 12344 ----a-w- c:\windows\system32\drivers\spyemrg.sys
2009-05-24 20:10 . 2009-05-24 20:10 -------- d-----w- c:\program files\AWD česká republika s.r.o
2009-05-24 08:30 . 2009-05-24 08:30 -------- d-----w- c:\program files\DsNET Corp
2009-05-21 10:07 . 2009-05-21 10:07 -------- d-----w- c:\program files\DigitalPeers
2009-05-20 15:55 . 2005-10-21 01:47 12800 ------w- c:\windows\system32\drivers\usb8023x.sys
2009-05-20 15:55 . 2005-10-21 01:47 30592 ------w- c:\windows\system32\drivers\rndismpx.sys
2009-05-20 15:54 . 2009-05-30 15:49 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-05-20 15:47 . 2009-05-20 15:47 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-19 23:11 . 2008-04-30 19:01 108488 ----a-w- c:\windows\system32\drivers\dptrackerd.sys
2009-05-18 19:52 . 2009-05-15 05:01 49656 ----a-w- c:\windows\system32\drivers\SIVX32.sys
2009-05-18 12:17 . 2009-05-18 12:40 -------- d-----w- c:\program files\Zoner
2009-05-16 01:48 . 2009-05-16 01:48 -------- d-----w- c:\windows\system32\wbem\Repository
2009-05-11 18:47 . 2009-05-31 19:05 -------- d-----w- c:\program files\WeFi
2009-05-11 18:45 . 2005-10-28 09:38 402432 ----a-w- c:\windows\system32\drivers\ZD1211BU.sys
2009-05-11 18:45 . 2005-06-08 16:44 29184 ----a-w- c:\windows\system32\drivers\BRGSp50a64.sys
2009-05-11 18:45 . 2005-06-08 16:44 20608 ----a-w- c:\windows\system32\drivers\BRGSp50.sys
2009-05-11 18:45 . 2004-10-25 11:40 17664 ----a-w- c:\windows\system32\drivers\ZDPSp50.sys
2009-05-11 18:45 . 2004-01-14 09:30 17151 ----a-w- c:\windows\system32\ZDPNDIS5.SYS
2009-05-11 18:45 . 2004-01-14 09:25 81920 ----a-w- c:\windows\system32\ZDPN50.DLL
2009-05-11 18:45 . 2009-05-11 18:45 -------- d-----w- c:\program files\IEEE 802.11g USB Wireless LAN
2009-05-11 18:45 . 2005-07-12 12:44 15872 ----a-w- c:\windows\system32\InsDrvZD64.DLL
2009-05-11 18:45 . 2004-03-23 14:38 28672 ----a-w- c:\windows\system32\InsDrvZD.dll
2009-05-11 18:45 . 2003-03-14 10:24 24576 ----a-w- c:\windows\system32\ZyDelReg.exe
2009-05-10 23:34 . 2009-05-15 23:03 -------- d-sh--w- C:\Boot

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 17:59 . 2009-04-29 17:34 4016 --sha-w- c:\windows\system32\sys_drv.dat
2009-06-05 21:05 . 2009-04-07 16:46 -------- d-----w- c:\program files\VideoLAN
2009-05-30 22:08 . 1980-01-01 00:00 74606 ----a-w- c:\windows\system32\perfc005.dat
2009-05-30 22:08 . 1980-01-01 00:00 402000 ----a-w- c:\windows\system32\perfh005.dat
2009-05-21 10:11 . 2009-04-14 21:07 -------- d-----w- c:\program files\Share Rapid Uploader
2009-05-20 18:47 . 2009-05-10 10:33 -------- d-----w- c:\program files\AlienGUIse
2009-05-20 15:47 . 2009-04-08 17:10 -------- d-----w- c:\program files\Common Files\Real
2009-05-18 12:40 . 2009-04-07 15:31 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-14 13:16 . 2009-04-08 20:31 -------- d-----w- c:\program files\Google
2009-05-11 18:45 . 2009-04-07 15:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-10 15:03 . 2009-05-10 15:03 -------- d-----w- c:\program files\DIFX
2009-05-10 14:57 . 2009-04-07 16:18 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-10 10:33 . 2009-05-10 10:33 -------- d-----w- c:\program files\Common Files\Stardock
2009-05-10 10:30 . 2009-05-10 10:30 -------- d-----w- c:\program files\VisualTaskTips
2009-05-09 12:23 . 2009-05-09 12:23 -------- d-----w- c:\program files\MediaCoder
2009-05-08 18:04 . 2009-05-08 17:50 5654 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2009-05-08 18:04 . 2009-04-07 16:03 71634 ----a-w- c:\windows\BricoPackUninst.cmd
2009-05-08 18:04 . 1980-01-01 00:00 219648 ----a-w- c:\windows\system32\uxtheme.dll
2009-05-08 17:00 . 2009-04-07 14:35 23544 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-06 17:44 . 2009-05-06 17:44 -------- d-----w- c:\program files\Trend Micro
2009-05-04 17:18 . 2009-05-04 17:18 -------- d-----w- c:\program files\Bonjour
2009-05-04 17:10 . 2009-05-04 17:10 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-05-04 17:02 . 2009-05-04 15:20 -------- d-----w- c:\program files\CamSpace
2009-04-29 17:39 . 2009-04-29 17:28 180224 ----a-w- c:\windows\system32\WinVd32.sys
2009-04-29 17:39 . 2009-04-29 17:28 16384 ----a-w- c:\windows\system32\WinFl32.sys
2009-04-26 09:33 . 2009-04-26 09:33 -------- d-----w- c:\program files\uTorrent
2009-04-25 12:11 . 2009-04-25 12:11 -------- d-----w- c:\program files\Tuning Car Studio
2009-04-24 22:30 . 2009-04-24 22:28 -------- d-----w- c:\program files\Your Uninstaller 2008
2009-04-22 15:40 . 2009-04-21 20:42 -------- d-----w- c:\program files\SMS posílač Treca
2009-04-19 18:38 . 2009-04-19 18:38 -------- d-----w- c:\program files\Windows Defender
2009-04-19 18:37 . 2009-04-19 18:37 -------- d-----w- c:\program files\Photo Story 3 for Windows
2009-04-18 18:29 . 2009-04-18 18:28 -------- d-----w- c:\program files\Accuracy trainer
2009-04-17 20:15 . 2009-04-17 20:15 -------- d-----w- c:\program files\Stellarium
2009-04-16 15:56 . 2009-04-07 17:02 -------- d-----w- c:\program files\Unlocker
2009-04-13 21:25 . 2009-04-13 21:25 -------- d-----w- c:\program files\7-Zip
2009-04-13 21:05 . 2009-04-13 21:05 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-13 21:01 . 2009-04-13 21:01 -------- d-----w- c:\program files\MSXML 4.0
2009-04-13 19:50 . 2009-04-13 19:50 -------- d-----w- c:\program files\Microsoft
2009-04-13 19:49 . 2009-04-13 19:49 -------- d-----w- c:\program files\Windows Live
2009-04-13 19:49 . 2009-04-13 19:49 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-04-13 19:45 . 2009-04-13 19:45 -------- d-----w- c:\program files\Common Files\Windows Live
2009-04-13 12:37 . 2009-04-13 12:36 -------- d-----w- c:\program files\ScreenShots
2009-04-13 12:35 . 2009-04-13 12:35 -------- d-----w- c:\program files\JPEG Resampler
2009-04-12 20:48 . 2009-04-12 20:48 -------- d-----w- c:\program files\Giovanni Software
2009-04-12 18:11 . 2009-04-12 18:11 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-04-12 18:11 . 2009-04-12 18:11 -------- d-----w- c:\program files\VSO
2009-04-12 12:33 . 2009-04-12 12:33 -------- d-----w- c:\program files\IVT Corporation
2009-04-10 16:59 . 2009-04-07 14:38 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-10 16:59 . 2009-04-07 14:38 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-04-10 16:58 . 2009-04-07 14:38 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-04-08 15:34 . 2009-04-08 15:35 737280 ----a-w- c:\windows\iun6002.exe
2009-04-07 18:48 . 2009-04-07 18:33 112835 ----a-w- c:\windows\hpoins07.dat
2009-04-07 17:12 . 2009-04-07 17:12 45056 ----a-w- c:\windows\TRNOEH.DLL
2009-04-07 17:12 . 2009-04-07 17:12 26624 ----a-w- c:\windows\OETRN.EXE
2009-04-07 17:12 . 2009-04-07 17:12 200704 ----a-w- c:\windows\TRNOET.DLL
2009-04-07 17:11 . 2009-04-07 17:11 516096 ----a-w- c:\windows\UN32.EXE
2009-04-07 16:36 . 2009-04-07 16:36 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-04-07 16:20 . 2009-04-07 16:20 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-07 15:23 . 2009-04-07 15:23 0 ----a-w- c:\windows\nsreg.dat
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Boot ----

2009-05-14 11:49 . 2009-04-21 20:34 43600 ----a-w- c:\boot\cs-CZ\memtest.exe.mui
2009-05-10 23:34 . 2009-06-07 12:32 33792 --sha-w- c:\boot\BCD.LOG
2009-05-10 23:34 . 2009-05-10 23:34 0 --sha-w- c:\boot\BCD.LOG1
2009-05-10 23:34 . 2009-05-10 23:34 0 --sha-w- c:\boot\BCD.LOG2
2009-05-10 23:34 . 2009-06-07 12:34 36864 --sha-w- c:\boot\BCD
2009-05-10 23:34 . 2009-05-15 23:03 65536 --sha-w- c:\boot\bootstat.dat
2009-05-10 23:34 . 2009-03-20 15:21 47452 ----a-w- c:\boot\Fonts\wgl4_boot.ttf
2009-05-10 23:34 . 2009-03-20 15:21 2371360 ----a-w- c:\boot\Fonts\kor_boot.ttf
2009-05-10 23:34 . 2009-03-20 15:21 1984228 ----a-w- c:\boot\Fonts\jpn_boot.ttf
2009-05-10 23:34 . 2009-03-20 15:21 3876772 ----a-w- c:\boot\Fonts\cht_boot.ttf
2009-05-10 23:34 . 2009-03-20 15:21 3694080 ----a-w- c:\boot\Fonts\chs_boot.ttf
2009-05-10 23:34 . 2009-04-22 05:23 70224 ----a-w- c:\boot\zh-TW\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 75344 ----a-w- c:\boot\zh-HK\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 87120 ----a-w- c:\boot\tr-TR\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 70736 ----a-w- c:\boot\zh-CN\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 90192 ----a-w- c:\boot\ru-RU\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 87632 ----a-w- c:\boot\sv-SE\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 90192 ----a-w- c:\boot\pt-BR\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 89680 ----a-w- c:\boot\pt-PT\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 90704 ----a-w- c:\boot\pl-PL\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 90704 ----a-w- c:\boot\nl-NL\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 88144 ----a-w- c:\boot\nb-NO\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:24 484944 ----a-w- c:\boot\memtest.exe
2009-05-10 23:34 . 2009-04-22 05:23 77904 ----a-w- c:\boot\ko-KR\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 74832 ----a-w- c:\boot\ja-JP\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 90704 ----a-w- c:\boot\it-IT\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 90704 ----a-w- c:\boot\hu-HU\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 93776 ----a-w- c:\boot\fr-FR\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 89168 ----a-w- c:\boot\fi-FI\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 90192 ----a-w- c:\boot\es-ES\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 10:20 43584 ----a-w- c:\boot\en-US\memtest.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 85072 ----a-w- c:\boot\en-US\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 94288 ----a-w- c:\boot\el-GR\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 91728 ----a-w- c:\boot\de-DE\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 87632 ----a-w- c:\boot\da-DK\bootmgr.exe.mui
2009-05-10 23:34 . 2009-04-22 05:23 89168 ----a-w- c:\boot\cs-CZ\bootmgr.exe.mui

---- Directory of c:\program files\DIFX ----

2009-05-10 15:03 . 2006-04-14 08:07 4846 ----a-w- c:\program files\DIFX\Icons\C4405F83D7397BC7CA10DA3372216ECD1F705041.ico
2009-05-10 15:03 . 2006-04-14 08:07 2916264 ----a-w- c:\program files\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe


------- Sigcheck -------

[-] 1980-01-01 00:00 215552 A77219A971029DC2FB683E8513713803 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-09_16.28.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-09 16:44 . 2009-06-09 16:44 16384 c:\windows\Temp\Perflib_Perfdata_9c.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [1980-01-01 15360]
"Thumbnail preview images for your taskbar."="c:\program files\VisualTaskTips\VisualTaskTips.exe" [2008-06-22 65536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"TV Card Remote Control Device Monitor"="c:\windows\3xHybridRMT.exe" [2006-07-27 417792]
"pckukacky"="c:\program files\giovanni software\počítačové kukačky\pckukacky.exe" [2004-12-12 81920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-05-26 414480]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-01-15 1657376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-08-01 16049664]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [1980-01-01 15360]

c:\documents and settings\Default User\Nabˇdka Start\Programy\Po spuçtŘnˇ\
CamTrack.lnk - c:\program files\DigitalPeers\CamTrack\camtrack.exe [2009-5-21 468584]

c:\documents and settings\Default User\Nabˇdka Start\Programy\Po spuçtŘnˇ\
CamTrack.lnk - c:\program files\DigitalPeers\CamTrack\camtrack.exe [2009-5-21 468584]

c:\documents and settings\xx\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Alienware Dock.lnk - c:\program files\AlienGUIse\AlienwareDock\ObjectDock.exe [2009-5-10 2074360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 21:34 24576 ----a-w- c:\program files\AlienGUIse\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"q:\\programy\\BlueSoleil_3.2.2.8_Vista_compatible_by_tomukazz\\BlueSoleil v3.2.2.8 Vista compatible\\C R A C K\\BlueSoleil.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7.4.2009 17:18 114768]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [7.4.2009 17:15 269736]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R1 SpyEmrg;Spy Emergency Driver;c:\windows\system32\drivers\spyemrg.sys [31.5.2009 19:12 12344]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7.4.2009 17:18 20560]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9.6.2009 17:08 194832]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [30.7.2008 10:36 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [30.7.2008 10:36 1361192]
R3 3xHybrid;SAA7135 TV Card Service;c:\windows\system32\drivers\3xHybrid.sys [7.4.2009 20:29 710784]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9.6.2009 17:07 19096]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [7.4.2009 17:15 65576]
S3 CrystalSysInfo;CrystalSysInfo;c:\program files\MediaCoder\SysInfo.sys [25.9.2007 16:59 15152]
S3 gupdate1c9b8897e950f2;Google Update Service (gupdate1c9b8897e950f2);c:\program files\Google\Update\GoogleUpdate.exe [8.4.2009 22:31 133104]
S3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\drivers\SIVX32.sys [18.5.2009 21:52 49656]
S3 SpyEmrgAccess;Spy Emergency OnAccess Driver;c:\windows\system32\drivers\spyemrg_access.sys [31.5.2009 19:12 18232]
S3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver;c:\windows\system32\drivers\spyemrg_guard.sys [31.5.2009 19:12 14392]
S3 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [21.4.2007 14:54 52080]
S3 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
S3 ZD1211BU(WLAN);IEEE 802.11g USB Wireless LAN(WLAN);c:\windows\system32\drivers\ZD1211BU.sys [11.5.2009 20:45 402432]
S4 SpyEmrgSrv;Spy Emergency Engine Service;c:\program files\NETGATE\Spy Emergency 2009\SpyEmergencySrv.exe --> c:\program files\NETGATE\Spy Emergency 2009\SpyEmergencySrv.exe [?]
.
Obsah adresáře 'Naplánované úlohy'

2009-06-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-05-20 17:17]

2009-06-09 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-08 20:31]

2009-06-09 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
FF - ProfilePath - c:\documents and settings\xx\Data aplikací\Mozilla\Firefox\Profiles\a1v66d00.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-09 20:20
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Device Monitor = c:\windows\3xHybridRMT.exe?|??????6~????????????X???????????}??f????????????X?????????6~????????????4???????????@??????f????????????X?????6~??<~<???@?????6~Y?6~??????6~??????????6~???????????f????W?9~`?6~????Y?6~4?6~????????????X?????6~??????A???????@??KA???B

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1343024091-764733703-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1120)
c:\program files\AlienGUIse\fastload.dll
.
Celkový čas: 2009-06-09 20:23
ComboFix-quarantined-files.txt 2009-06-09 18:23
ComboFix2.txt 2009-06-09 16:31

Před spuštěním: Volných bajtů: 21 038 669 824
Po spuštění: Volných bajtů: 21 024 886 784

308 --- E O F --- 2009-06-04 14:49
----------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:28:03, on 9.6.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\3xHybridRMT.exe
C:\program files\giovanni software\počítačové kukačky\pckukacky.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\VisualTaskTips\VisualTaskTips.exe
C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\viphone communicator\viphone communicator.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\3xHybridRMT.exe
O4 - HKLM\..\Run: [pckukacky] c:\program files\giovanni software\počítačové kukačky\pckukacky.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Thumbnail preview images for your taskbar.] C:\Program Files\VisualTaskTips\VisualTaskTips.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: CamTrack.lnk = C:\Program Files\DigitalPeers\CamTrack\camtrack.exe (User 'Default user')
O4 - Startup: Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\wbsys.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c9b8897e950f2) (gupdate1c9b8897e950f2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe

--
End of file - 10164 bytes

Re: Modrá smrt

Napsal: 09 čer 2009 20:59
od danty
El Diablo píše:Prověř RAM memtestem, HDD utilitou od výrobce!


Můžu poprosit o bližší info o co jde? Případně kde to hledat? Bohužel mé zkušenosti nejsou až tak daleké.Díky

Re: Modrá smrt

Napsal: 09 čer 2009 21:10
od Damned
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

File::
c:\windows\system32\WinVd32.sys
c:\windows\system32\WinFl32.sys

Folder::
C:\Boot

Driver::
SpyEmrgSrv;Spy Emergency Engine Service;
SpyEmrgSrv
WinVd32
WinFl32




Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.


Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.
Obrázek

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT


Ten "Spy Emergency" jsi odinstaloval? Já jen že tam máš jeho služby. A ještě odkaz na kontrolu toho souboru.

Re: Modrá smrt

Napsal: 10 čer 2009 02:07
od danty
Super.Ten sajrait Spy Emergenci byl sice před časem odinstalován ale ten humus dál zůstal.Ted už mašinka jede zas jak má,bez modrý obrazovky.Moc děkuji za pomoc :D :number1:

Re: Modrá smrt

Napsal: 10 čer 2009 05:22
od Damned
Ještě to není všechno!!!! Potřebuju ty logy ke kontrole! Jinak zas přijde zubatá!!! Je to proto, že ty šmejdí můžou těsně před svým smazáním vytvořit další, sobě rovný soubor, jen s jiným názvem a škodit budou dál. Takže teď je dobrej začátek, ale konec ještě není.