Prosím o kontrolu
Napsal: 22 bře 2013 11:09
Ahoj, prosím o kontrolu, udělal jsem ComboFix Log a MWAV - Scan&Clean. Oba logy jsou níže. Počítač mírně zamrzá, vždy tak na deset až patnáct sekund... MWAV něco našel, ale moc prosím, jestli mi to ještě zkontrolujete??? Prosím....
Tady z MWAV o tom co našel (přepsáno z okénka):
Virus Log Information:
C:\WINDOWS\system32\DRIVERS\hcdriver.sys: Forget File - Suspicious Rootkit
Object "Backdoor (IRCBot) Trojans Spyware/Adware" found in File System! Action Taken: Entries Removed
Object "AntiSpyware Pro XP Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed
Log z HJT:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:44:54, on 22.3.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\WINDOWS\system32\nlssrv32.exe
C:\WINDOWS\system32\IoctlSvc.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
C:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\umonit.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Bluetooth Software\BTTray.exe
C:\DOCUME~1\Alan\LOCALS~1\temp\mexetmp.ex~
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Documents and Settings\Alan\Plocha\SECURITY\HijackThis.exe
C:\WINDOWS\system32\WISPTIS.EXE
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\system32\umonit.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 0109700281
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 3773112609
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Adaptec - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\nlssrv32.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
O23 - Service: Wacom Consumer Touch Service (TouchServicePen) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
O23 - Service: WD Backup (WDBackup) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: WD Rules (WDRulesService) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
--
End of file - 12294 bytes
A ještě MWAV:
22 III 2013 09:40:35 - **********************************************************
22 III 2013 09:40:35 - eScan Anti Virus & Spyware Toolkit Utility.
22 III 2013 09:40:35 - Copyright © MicroWorld Technologies
22 III 2013 09:40:35 - **********************************************************
22 III 2013 09:40:35 - Source: C:\DOCUME~1\Alan\Plocha\mwav.exe
22 III 2013 09:40:35 - Version 14.0.56 (C:\DOCUMENTS AND SETTINGS\ALAN\LOCAL SETTINGS\TEMP\MEXETMP.EX~)
22 III 2013 09:40:35 - Log File: C:\Documents and Settings\Alan\Local Settings\temp\MWAV.LOG
22 III 2013 09:40:35 - Last Scan Date and Time: 20.12.2012 04:20:44
22 III 2013 09:40:35 - MWAV Registered: TRUE
22 III 2013 09:40:35 - User Account: Alan (Administrator Mode)
22 III 2013 09:40:35 - OS Type: Windows Workstation
22 III 2013 09:40:35 - OS: Windows XP [OS Install Date: 26 Jul 2012 21:41:52]
22 III 2013 09:40:35 - Ver: Professional Service Pack 3 (Build 2600)
22 III 2013 09:40:35 - System Up Time: 9 Minutes, 32 Seconds
22 III 2013 09:40:35 - Windows Root Folder: C:\WINDOWS
22 III 2013 09:40:35 - Windows Sys32 Folder: C:\WINDOWS\system32
22 III 2013 09:40:36 - DHCP NameServer: 192.168.0.1
22 III 2013 09:40:36 - Interface0 DHCPNameServer: 192.168.0.1
22 III 2013 09:40:36 - Local Fixed Drives: c:\,d:\,e:\,f:\,g:\
22 III 2013 09:40:36 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
22 III 2013 09:40:36 - [CREATED ZIP FILE: C:\Documents and Settings\Alan\Local Settings\temp\pinfect.zip]
22 III 2013 09:40:36 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
22 III 2013 09:40:39 - C:\WINDOWS\R.COM (147968), 22-Mar-2013 [Added C:\WINDOWS\R.COM to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\FlashPlayerApp.exe (693976), 13-Mar-2013 [Added C:\WINDOWS\system32\FlashPlayerApp.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl (73432), 13-Mar-2013 [Added C:\WINDOWS\system32\FlashPlayerCPLApp.cpl to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\MRT.exe (69796088), 14-Mar-2013
22 III 2013 09:40:40 - C:\WINDOWS\system32\T.COM (137216), 22-Mar-2013 [Added C:\WINDOWS\system32\T.COM to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\TASKMGR.COM (137216), 22-Mar-2013 [Added C:\WINDOWS\system32\TASKMGR.COM to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\dllcache\usb8023.sys (12928), 22-Mar-2013 [Added C:\WINDOWS\system32\dllcache\usb8023.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\dllcache\usb8023x.sys (12928), 22-Mar-2013 [Added C:\WINDOWS\system32\dllcache\usb8023x.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\drivers\SWDUMon.sys (13464), 20-Mar-2013 [Added C:\WINDOWS\system32\drivers\SWDUMon.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\BACKUP.86519351.mexe.com (2353736), 22-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\bdc.exe (91904), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\bdc.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\bdfltlib2k.dll (231944), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\bdfltlib2k.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\DEVCON.EXE (61184), 22-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\encdec.dll (120328), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\encdec.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\erootdrv.sys (13832), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\erootdrv.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\mexe.com (779560), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\mexe.com to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\msvclnt.dll (236040), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\msvclnt.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\mwavdwnl.exe (934920), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\mwavdwnl.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\MWAVSCAN.COM (2353736), 22-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins.htm (3498), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins.htm to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\red32.dll (10248), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\red32.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\reload.exe (154632), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\reload.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\setpriv.exe (64008), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\setpriv.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\unregx.exe (61960), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\unregx.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\UPDLL10.DLL (1125096), 19-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\viewtcp.exe (573960), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\viewtcp.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\$NtUninstallWdf01009$, 10-Jan-2013 [H] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\CSC, 08-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\Fonts, 04-Jan-2011 [SR] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\Web, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\system32\dllcache, 04-Jan-2011 [HSR] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\system32\Microsoft, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\cmdcons, 17-Feb-2011 [HSR] [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\AVCBack, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\FtpTemp, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\FtpTempF, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\Log, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\nro.log, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugtmp, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\VBE, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\Word8.0, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\Microsoft, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Dokumenty, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\IECompatCache, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\IETldCache, 04-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Local Settings, 04-Jan-2011 [H] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Oblíbené položky, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\PrivacIE, 04-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Recent, 16-Mar-2013 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\UserData, 04-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\All Users\Data aplikací\Common Files, 16-Dec-2012 [H] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\All Users\Data aplikací\Microsoft, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\All Users\Data aplikací\..\DRM, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Program Files\Mozilla Firefox, 10-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\Program Files\SlimDrivers, 20-Mar-2013 [Folder]
22 III 2013 09:40:40 - *********************************************************************************************
22 III 2013 09:40:40 - Command Line Options Given: /xsign
22 III 2013 09:40:40 - Latest Date of files inside MWAV: Mon Apr 26 13:46:18 2010.
22 III 2013 09:40:40 - Sign Version: 7.31392
22 III 2013 09:40:41 - ** Deleted Value of "RPSessionInterval" in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore". Its value was DWORD:0.
22 III 2013 09:40:41 - Loading/Creating FileScan Cache Database C:\Documents and Settings\All Users\Data aplikací\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Documents and Settings\Alan\Local Settings\temp\ESCANDB.LOG]
22 III 2013 09:40:41 - Loaded/Created FileScan Cache Database...
22 III 2013 09:40:41 - Loading AV Library [DB]...
22 III 2013 09:40:42 - ArchiveScan: DISABLED
22 III 2013 09:40:46 - AV Library Loaded [DB-DIRECT].
22 III 2013 09:40:46 - MWAV doing self scanning...
22 III 2013 09:40:47 - MWAV files are clean.
22 III 2013 09:41:06 - ArchiveScan: DISABLED
22 III 2013 09:41:06 - Virus Database Date: 26 Apr 2010
22 III 2013 09:41:06 - Virus Database Count: 5690871
22 III 2013 09:41:08 - Downloading AntiVirus and Anti-Spyware Databases...
22 III 2013 09:41:12 - Nothing new to download. Updates are the latest.
22 III 2013 09:44:48 - **********************************************************
22 III 2013 09:44:48 - eScan Anti Virus & Spyware Toolkit Utility.
22 III 2013 09:44:48 - Copyright © MicroWorld Technologies
22 III 2013 09:44:48 -
22 III 2013 09:44:48 - Support: support@escanav.com
22 III 2013 09:44:48 - Web: http://www.escanav.com
22 III 2013 09:44:48 - **********************************************************
22 III 2013 09:44:48 - Version 14.0.56[DB] (C:\DOCUMENTS AND SETTINGS\ALAN\LOCAL SETTINGS\TEMP\MEXETMP.EX~)
22 III 2013 09:44:48 - Log File: C:\Documents and Settings\Alan\Local Settings\temp\MWAV.LOG
22 III 2013 09:44:48 - User Account: Alan (Administrator Mode)
22 III 2013 09:44:48 - Windows Root Folder: C:\WINDOWS
22 III 2013 09:44:48 - Windows Sys32 Folder: C:\WINDOWS\system32
22 III 2013 09:44:48 - OS: Windows XP [OS Install Date: 26 Jul 2012 21:41:52]
22 III 2013 09:44:48 - Ver: Professional Service Pack 3 (Build 2600)
22 III 2013 09:44:48 - Latest Date of files inside MWAV: Mon Apr 26 13:46:18 2010.
22 III 2013 09:44:48 - Sign Version: 7.31392
22 III 2013 09:44:49 - Options Selected by User:
22 III 2013 09:44:49 - Memory Check: Enabled
22 III 2013 09:44:49 - Registry Check: Enabled
22 III 2013 09:44:49 - StartUp Folder Check: Enabled
22 III 2013 09:44:49 - System Folder Check: Enabled
22 III 2013 09:44:49 - Services Check: Enabled
22 III 2013 09:44:49 - Scan Spyware: Enabled
22 III 2013 09:44:49 - Scan Archives: Disabled
22 III 2013 09:44:49 - Drive Check: Enabled
22 III 2013 09:44:49 - All Drive Check
isabled
22 III 2013 09:44:49 - Drive Selected = C:\
22 III 2013 09:44:49 - Folder Check: Disabled
22 III 2013 09:44:49 - SCAN: All_Files
22 III 2013 09:44:49 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
22 III 2013 09:44:49 - Scanning DNS Records...
22 III 2013 09:44:49 - Scanning Master Boot Record (Kernel)...
22 III 2013 09:44:51 - Scanning Logical Boot Records...
22 III 2013 09:44:51 - ***** Scanning For Hidden Rootkit Processes *****
22 III 2013 09:44:51 - ***** Scanning For Hidden Rootkit Services *****
22 III 2013 09:44:53 - Walk through registry failed!
22 III 2013 09:44:53 - ***** Scanning Memory Files *****
22 III 2013 09:45:44 - ScanFile (C:\Program Files\Mozilla Firefox\nss3.dll) took 5329 ms
22 III 2013 09:46:09 - ***** Scanning Registry Files *****
22 III 2013 09:46:12 - ***** Scanning StartUp Folders *****
22 III 2013 09:46:49 - ScanFile (C:\Documents and Settings\Alan\Plocha\mwav.exe) took 22360 ms
22 III 2013 09:46:49 - Scanning of C:\Documents and Settings\Alan\Plocha\mwav.exe Timed out!!!
22 III 2013 09:46:49 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Plocha\mwav.exe
22 III 2013 09:47:01 - ScanFile (C:\Documents and Settings\Alan\Plocha\TFC.exe) took 6828 ms
22 III 2013 09:53:24 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e not Scanned. Possibly password protected...
22 III 2013 09:53:24 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e
22 III 2013 09:53:24 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d not Scanned. Possibly password protected...
22 III 2013 09:53:24 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d
22 III 2013 09:53:25 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333 not Scanned. Possibly password protected...
22 III 2013 09:53:25 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333
22 III 2013 09:53:27 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e not Scanned. Possibly password protected...
22 III 2013 09:53:27 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e
22 III 2013 09:53:28 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf not Scanned. Possibly password protected...
22 III 2013 09:53:28 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf
22 III 2013 09:53:29 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f not Scanned. Possibly password protected...
22 III 2013 09:53:29 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f
22 III 2013 09:53:30 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf not Scanned. Possibly password protected...
22 III 2013 09:53:30 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf
22 III 2013 09:53:31 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067 not Scanned. Possibly password protected...
22 III 2013 09:53:31 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067
22 III 2013 09:53:31 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455 not Scanned. Possibly password protected...
22 III 2013 09:53:31 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455
22 III 2013 09:53:33 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb not Scanned. Possibly password protected...
22 III 2013 09:53:33 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb
22 III 2013 09:53:33 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c not Scanned. Possibly password protected...
22 III 2013 09:53:33 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c
22 III 2013 09:53:34 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967 not Scanned. Possibly password protected...
22 III 2013 09:53:34 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967
22 III 2013 09:53:39 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8 not Scanned. Possibly password protected...
22 III 2013 09:53:39 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8
22 III 2013 09:53:40 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348 not Scanned. Possibly password protected...
22 III 2013 09:53:40 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348
22 III 2013 09:54:59 - C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin not Scanned. Possibly password protected...
22 III 2013 09:54:59 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin
22 III 2013 09:55:10 - ***** Scanning Service Files *****
22 III 2013 09:56:10 - C:\WINDOWS\system32\DRIVERS\hcdriver.sys: Forged File - Suspicious Rootkit
22 III 2013 09:57:39 - ***** Scanning Registry and File system for Adware/Spyware *****
22 III 2013 09:57:41 - Loading Spyware Signatures from new External Database [Name: C:\DOCUME~1\Alan\LOCALS~1\temp\spydb.avs, Size: 463768]...
22 III 2013 09:57:41 - Indexed Spyware Databases Successfully Created...
22 III 2013 09:57:58 - Offending Registry Entry found: HKCU\Software\Microsoft\OLE
22 III 2013 09:57:58 - System found infected with Backdoor (IRCBot) Trojans Spyware/Adware (HKCU\Software\Microsoft\OLE)! Action taken: Entries Removed.
22 III 2013 09:57:58 - Object "Backdoor (IRCBot) Trojans Spyware/Adware" found in File System! Action Taken: Entries Removed.
22 III 2013 09:57:58 - Offending Registry Entry found: HKCU\Software\Microsoft\Windows\CurrentVersion\Drivers
22 III 2013 09:57:58 - System found infected with AntiSpyware Pro XP Corrupted Adware/Spyware (HKCU\Software\Microsoft\Windows\CurrentVersion\Drivers)! Action taken: Entries Removed.
22 III 2013 09:57:58 - Object "AntiSpyware Pro XP Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed.
22 III 2013 09:57:59 - ***** Scanning Registry Files *****
22 III 2013 09:58:00 - ** Value in HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
22 III 2013 09:58:00 - ** Value in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = http://www.msn.com/
22 III 2013 09:58:00 - ** Value in HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\main/Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
22 III 2013 09:58:00 - ***** Scanning System32 Folders *****
22 III 2013 09:59:05 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\mexe.com) took 8484 ms
22 III 2013 09:59:16 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\mwavdwnl.exe) took 8468 ms
22 III 2013 09:59:21 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\MWAVL.exe) took 5406 ms
22 III 2013 09:59:32 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\mwavscan.exe) took 8438 ms
22 III 2013 10:00:03 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\Portuguese.lic) took 11469 ms
22 III 2013 10:02:00 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\viewtcp.exe) took 8563 ms
22 III 2013 10:02:01 - ***** Scanning Drive C:\ *****
22 III 2013 10:07:06 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e not Scanned. Possibly password protected...
22 III 2013 10:07:06 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e
22 III 2013 10:07:07 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d not Scanned. Possibly password protected...
22 III 2013 10:07:07 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d
22 III 2013 10:07:08 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333 not Scanned. Possibly password protected...
22 III 2013 10:07:08 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333
22 III 2013 10:07:09 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e not Scanned. Possibly password protected...
22 III 2013 10:07:09 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e
22 III 2013 10:07:09 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf not Scanned. Possibly password protected...
22 III 2013 10:07:09 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf
22 III 2013 10:07:10 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f not Scanned. Possibly password protected...
22 III 2013 10:07:10 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f
22 III 2013 10:07:10 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf not Scanned. Possibly password protected...
22 III 2013 10:07:10 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf
22 III 2013 10:07:11 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067 not Scanned. Possibly password protected...
22 III 2013 10:07:11 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067
22 III 2013 10:07:11 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455 not Scanned. Possibly password protected...
22 III 2013 10:07:11 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455
22 III 2013 10:07:12 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb not Scanned. Possibly password protected...
22 III 2013 10:07:12 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb
22 III 2013 10:07:13 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c not Scanned. Possibly password protected...
22 III 2013 10:07:13 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c
22 III 2013 10:07:13 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967 not Scanned. Possibly password protected...
22 III 2013 10:07:13 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967
22 III 2013 10:07:18 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8 not Scanned. Possibly password protected...
22 III 2013 10:07:18 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8
22 III 2013 10:07:18 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348 not Scanned. Possibly password protected...
22 III 2013 10:07:18 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348
22 III 2013 10:11:08 - C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin not Scanned. Possibly password protected...
22 III 2013 10:11:08 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin
22 III 2013 10:22:01 - C:\Program Files\Zoner\Photo Studio 13\pack.dat not Scanned. Possibly password protected...
22 III 2013 10:22:01 - ERROR(3)!!! ScanFile fails for C:\Program Files\Zoner\Photo Studio 13\pack.dat
22 III 2013 10:29:19 - C:\WINDOWS\SoftwareDistribution\EventCache\{6C7C3833-DE76-40A1-99E5-F298093C96E6}.bin not Scanned. Possibly password protected...
22 III 2013 10:29:19 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{6C7C3833-DE76-40A1-99E5-F298093C96E6}.bin
22 III 2013 10:29:24 - C:\WINDOWS\system32\CatRoot2\tmp.edb not Scanned. Possibly password protected...
22 III 2013 10:29:24 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\CatRoot2\tmp.edb
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\default not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\default
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\SAM not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\SAM
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\software not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\software
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\system not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\system
22 III 2013 10:30:07 - ***** Checking for specific ITW Viruses *****
22 III 2013 10:30:08 - ***** Scanning complete. *****
22 III 2013 10:30:08 - Total Objects Scanned: 285274
22 III 2013 10:30:08 - Total Critical Objects: 2
22 III 2013 10:30:08 - Total Disinfected Objects: 0
22 III 2013 10:30:08 - Total Objects Renamed: 0
22 III 2013 10:30:08 - Total Deleted Objects: 2
22 III 2013 10:30:08 - Total Errors: 0
22 III 2013 10:30:08 - Time Elapsed: 00:45:18
22 III 2013 10:30:08 - Virus Database Date: 26 Apr 2010
22 III 2013 10:30:08 - Virus Database Count: 5690871
22 III 2013 10:30:08 - Scan Completed.
Tady z MWAV o tom co našel (přepsáno z okénka):
Virus Log Information:
C:\WINDOWS\system32\DRIVERS\hcdriver.sys: Forget File - Suspicious Rootkit
Object "Backdoor (IRCBot) Trojans Spyware/Adware" found in File System! Action Taken: Entries Removed
Object "AntiSpyware Pro XP Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed
Log z HJT:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:44:54, on 22.3.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\WINDOWS\system32\nlssrv32.exe
C:\WINDOWS\system32\IoctlSvc.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
C:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\umonit.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Bluetooth Software\BTTray.exe
C:\DOCUME~1\Alan\LOCALS~1\temp\mexetmp.ex~
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Capture.exe
C:\Program Files\Corel\CorelDRAW Graphics Suite X5\Programs\Cap.exe
C:\Documents and Settings\Alan\Plocha\SECURITY\HijackThis.exe
C:\WINDOWS\system32\WISPTIS.EXE
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\system32\umonit.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 0109700281
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 3773112609
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Adaptec - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\nlssrv32.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
O23 - Service: Wacom Consumer Touch Service (TouchServicePen) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
O23 - Service: WD Backup (WDBackup) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: WD Rules (WDRulesService) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
--
End of file - 12294 bytes
A ještě MWAV:
22 III 2013 09:40:35 - **********************************************************
22 III 2013 09:40:35 - eScan Anti Virus & Spyware Toolkit Utility.
22 III 2013 09:40:35 - Copyright © MicroWorld Technologies
22 III 2013 09:40:35 - **********************************************************
22 III 2013 09:40:35 - Source: C:\DOCUME~1\Alan\Plocha\mwav.exe
22 III 2013 09:40:35 - Version 14.0.56 (C:\DOCUMENTS AND SETTINGS\ALAN\LOCAL SETTINGS\TEMP\MEXETMP.EX~)
22 III 2013 09:40:35 - Log File: C:\Documents and Settings\Alan\Local Settings\temp\MWAV.LOG
22 III 2013 09:40:35 - Last Scan Date and Time: 20.12.2012 04:20:44
22 III 2013 09:40:35 - MWAV Registered: TRUE
22 III 2013 09:40:35 - User Account: Alan (Administrator Mode)
22 III 2013 09:40:35 - OS Type: Windows Workstation
22 III 2013 09:40:35 - OS: Windows XP [OS Install Date: 26 Jul 2012 21:41:52]
22 III 2013 09:40:35 - Ver: Professional Service Pack 3 (Build 2600)
22 III 2013 09:40:35 - System Up Time: 9 Minutes, 32 Seconds
22 III 2013 09:40:35 - Windows Root Folder: C:\WINDOWS
22 III 2013 09:40:35 - Windows Sys32 Folder: C:\WINDOWS\system32
22 III 2013 09:40:36 - DHCP NameServer: 192.168.0.1
22 III 2013 09:40:36 - Interface0 DHCPNameServer: 192.168.0.1
22 III 2013 09:40:36 - Local Fixed Drives: c:\,d:\,e:\,f:\,g:\
22 III 2013 09:40:36 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
22 III 2013 09:40:36 - [CREATED ZIP FILE: C:\Documents and Settings\Alan\Local Settings\temp\pinfect.zip]
22 III 2013 09:40:36 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
22 III 2013 09:40:39 - C:\WINDOWS\R.COM (147968), 22-Mar-2013 [Added C:\WINDOWS\R.COM to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\FlashPlayerApp.exe (693976), 13-Mar-2013 [Added C:\WINDOWS\system32\FlashPlayerApp.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\FlashPlayerCPLApp.cpl (73432), 13-Mar-2013 [Added C:\WINDOWS\system32\FlashPlayerCPLApp.cpl to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\MRT.exe (69796088), 14-Mar-2013
22 III 2013 09:40:40 - C:\WINDOWS\system32\T.COM (137216), 22-Mar-2013 [Added C:\WINDOWS\system32\T.COM to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\TASKMGR.COM (137216), 22-Mar-2013 [Added C:\WINDOWS\system32\TASKMGR.COM to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\dllcache\usb8023.sys (12928), 22-Mar-2013 [Added C:\WINDOWS\system32\dllcache\usb8023.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\dllcache\usb8023x.sys (12928), 22-Mar-2013 [Added C:\WINDOWS\system32\dllcache\usb8023x.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\system32\drivers\SWDUMon.sys (13464), 20-Mar-2013 [Added C:\WINDOWS\system32\drivers\SWDUMon.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\BACKUP.86519351.mexe.com (2353736), 22-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\bdc.exe (91904), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\bdc.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\bdfltlib2k.dll (231944), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\bdfltlib2k.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\DEVCON.EXE (61184), 22-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\encdec.dll (120328), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\encdec.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\erootdrv.sys (13832), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\erootdrv.sys to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\mexe.com (779560), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\mexe.com to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\msvclnt.dll (236040), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\msvclnt.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\mwavdwnl.exe (934920), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\mwavdwnl.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\MWAVSCAN.COM (2353736), 22-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins.htm (3498), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins.htm to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\red32.dll (10248), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\red32.dll to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\reload.exe (154632), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\reload.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\setpriv.exe (64008), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\setpriv.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\unregx.exe (61960), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\unregx.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\UPDLL10.DLL (1125096), 19-Mar-2013
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\viewtcp.exe (573960), 22-Mar-2013 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\viewtcp.exe to ZIP FILE]
22 III 2013 09:40:40 - C:\WINDOWS\$NtUninstallWdf01009$, 10-Jan-2013 [H] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\CSC, 08-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\Fonts, 04-Jan-2011 [SR] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\Web, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\system32\dllcache, 04-Jan-2011 [HSR] [Folder]
22 III 2013 09:40:40 - C:\WINDOWS\system32\Microsoft, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\cmdcons, 17-Feb-2011 [HSR] [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\AVCBack, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\FtpTemp, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\FtpTempF, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\Log, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\nro.log, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins, 22-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugtmp, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\VBE, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\DOCUME~1\Alan\LOCALS~1\Temp\Word8.0, 17-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\Microsoft, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Dokumenty, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\IECompatCache, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\IETldCache, 04-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Local Settings, 04-Jan-2011 [H] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Oblíbené položky, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\PrivacIE, 04-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\Recent, 16-Mar-2013 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\Alan\Data aplikací\..\UserData, 04-Jan-2011 [HS] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\All Users\Data aplikací\Common Files, 16-Dec-2012 [H] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\All Users\Data aplikací\Microsoft, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Documents and Settings\All Users\Data aplikací\..\DRM, 04-Jan-2011 [S] [Folder]
22 III 2013 09:40:40 - C:\Program Files\Mozilla Firefox, 10-Mar-2013 [Folder]
22 III 2013 09:40:40 - C:\Program Files\SlimDrivers, 20-Mar-2013 [Folder]
22 III 2013 09:40:40 - *********************************************************************************************
22 III 2013 09:40:40 - Command Line Options Given: /xsign
22 III 2013 09:40:40 - Latest Date of files inside MWAV: Mon Apr 26 13:46:18 2010.
22 III 2013 09:40:40 - Sign Version: 7.31392
22 III 2013 09:40:41 - ** Deleted Value of "RPSessionInterval" in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore". Its value was DWORD:0.
22 III 2013 09:40:41 - Loading/Creating FileScan Cache Database C:\Documents and Settings\All Users\Data aplikací\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Documents and Settings\Alan\Local Settings\temp\ESCANDB.LOG]
22 III 2013 09:40:41 - Loaded/Created FileScan Cache Database...
22 III 2013 09:40:41 - Loading AV Library [DB]...
22 III 2013 09:40:42 - ArchiveScan: DISABLED
22 III 2013 09:40:46 - AV Library Loaded [DB-DIRECT].
22 III 2013 09:40:46 - MWAV doing self scanning...
22 III 2013 09:40:47 - MWAV files are clean.
22 III 2013 09:41:06 - ArchiveScan: DISABLED
22 III 2013 09:41:06 - Virus Database Date: 26 Apr 2010
22 III 2013 09:41:06 - Virus Database Count: 5690871
22 III 2013 09:41:08 - Downloading AntiVirus and Anti-Spyware Databases...
22 III 2013 09:41:12 - Nothing new to download. Updates are the latest.
22 III 2013 09:44:48 - **********************************************************
22 III 2013 09:44:48 - eScan Anti Virus & Spyware Toolkit Utility.
22 III 2013 09:44:48 - Copyright © MicroWorld Technologies
22 III 2013 09:44:48 -
22 III 2013 09:44:48 - Support: support@escanav.com
22 III 2013 09:44:48 - Web: http://www.escanav.com
22 III 2013 09:44:48 - **********************************************************
22 III 2013 09:44:48 - Version 14.0.56[DB] (C:\DOCUMENTS AND SETTINGS\ALAN\LOCAL SETTINGS\TEMP\MEXETMP.EX~)
22 III 2013 09:44:48 - Log File: C:\Documents and Settings\Alan\Local Settings\temp\MWAV.LOG
22 III 2013 09:44:48 - User Account: Alan (Administrator Mode)
22 III 2013 09:44:48 - Windows Root Folder: C:\WINDOWS
22 III 2013 09:44:48 - Windows Sys32 Folder: C:\WINDOWS\system32
22 III 2013 09:44:48 - OS: Windows XP [OS Install Date: 26 Jul 2012 21:41:52]
22 III 2013 09:44:48 - Ver: Professional Service Pack 3 (Build 2600)
22 III 2013 09:44:48 - Latest Date of files inside MWAV: Mon Apr 26 13:46:18 2010.
22 III 2013 09:44:48 - Sign Version: 7.31392
22 III 2013 09:44:49 - Options Selected by User:
22 III 2013 09:44:49 - Memory Check: Enabled
22 III 2013 09:44:49 - Registry Check: Enabled
22 III 2013 09:44:49 - StartUp Folder Check: Enabled
22 III 2013 09:44:49 - System Folder Check: Enabled
22 III 2013 09:44:49 - Services Check: Enabled
22 III 2013 09:44:49 - Scan Spyware: Enabled
22 III 2013 09:44:49 - Scan Archives: Disabled
22 III 2013 09:44:49 - Drive Check: Enabled
22 III 2013 09:44:49 - All Drive Check

22 III 2013 09:44:49 - Drive Selected = C:\
22 III 2013 09:44:49 - Folder Check: Disabled
22 III 2013 09:44:49 - SCAN: All_Files
22 III 2013 09:44:49 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
22 III 2013 09:44:49 - Scanning DNS Records...
22 III 2013 09:44:49 - Scanning Master Boot Record (Kernel)...
22 III 2013 09:44:51 - Scanning Logical Boot Records...
22 III 2013 09:44:51 - ***** Scanning For Hidden Rootkit Processes *****
22 III 2013 09:44:51 - ***** Scanning For Hidden Rootkit Services *****
22 III 2013 09:44:53 - Walk through registry failed!
22 III 2013 09:44:53 - ***** Scanning Memory Files *****
22 III 2013 09:45:44 - ScanFile (C:\Program Files\Mozilla Firefox\nss3.dll) took 5329 ms
22 III 2013 09:46:09 - ***** Scanning Registry Files *****
22 III 2013 09:46:12 - ***** Scanning StartUp Folders *****
22 III 2013 09:46:49 - ScanFile (C:\Documents and Settings\Alan\Plocha\mwav.exe) took 22360 ms
22 III 2013 09:46:49 - Scanning of C:\Documents and Settings\Alan\Plocha\mwav.exe Timed out!!!
22 III 2013 09:46:49 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Plocha\mwav.exe
22 III 2013 09:47:01 - ScanFile (C:\Documents and Settings\Alan\Plocha\TFC.exe) took 6828 ms
22 III 2013 09:53:24 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e not Scanned. Possibly password protected...
22 III 2013 09:53:24 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e
22 III 2013 09:53:24 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d not Scanned. Possibly password protected...
22 III 2013 09:53:24 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d
22 III 2013 09:53:25 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333 not Scanned. Possibly password protected...
22 III 2013 09:53:25 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333
22 III 2013 09:53:27 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e not Scanned. Possibly password protected...
22 III 2013 09:53:27 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e
22 III 2013 09:53:28 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf not Scanned. Possibly password protected...
22 III 2013 09:53:28 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf
22 III 2013 09:53:29 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f not Scanned. Possibly password protected...
22 III 2013 09:53:29 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f
22 III 2013 09:53:30 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf not Scanned. Possibly password protected...
22 III 2013 09:53:30 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf
22 III 2013 09:53:31 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067 not Scanned. Possibly password protected...
22 III 2013 09:53:31 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067
22 III 2013 09:53:31 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455 not Scanned. Possibly password protected...
22 III 2013 09:53:31 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455
22 III 2013 09:53:33 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb not Scanned. Possibly password protected...
22 III 2013 09:53:33 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb
22 III 2013 09:53:33 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c not Scanned. Possibly password protected...
22 III 2013 09:53:33 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c
22 III 2013 09:53:34 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967 not Scanned. Possibly password protected...
22 III 2013 09:53:34 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967
22 III 2013 09:53:39 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8 not Scanned. Possibly password protected...
22 III 2013 09:53:39 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8
22 III 2013 09:53:40 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348 not Scanned. Possibly password protected...
22 III 2013 09:53:40 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348
22 III 2013 09:54:59 - C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin not Scanned. Possibly password protected...
22 III 2013 09:54:59 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin
22 III 2013 09:55:10 - ***** Scanning Service Files *****
22 III 2013 09:56:10 - C:\WINDOWS\system32\DRIVERS\hcdriver.sys: Forged File - Suspicious Rootkit
22 III 2013 09:57:39 - ***** Scanning Registry and File system for Adware/Spyware *****
22 III 2013 09:57:41 - Loading Spyware Signatures from new External Database [Name: C:\DOCUME~1\Alan\LOCALS~1\temp\spydb.avs, Size: 463768]...
22 III 2013 09:57:41 - Indexed Spyware Databases Successfully Created...
22 III 2013 09:57:58 - Offending Registry Entry found: HKCU\Software\Microsoft\OLE
22 III 2013 09:57:58 - System found infected with Backdoor (IRCBot) Trojans Spyware/Adware (HKCU\Software\Microsoft\OLE)! Action taken: Entries Removed.
22 III 2013 09:57:58 - Object "Backdoor (IRCBot) Trojans Spyware/Adware" found in File System! Action Taken: Entries Removed.
22 III 2013 09:57:58 - Offending Registry Entry found: HKCU\Software\Microsoft\Windows\CurrentVersion\Drivers
22 III 2013 09:57:58 - System found infected with AntiSpyware Pro XP Corrupted Adware/Spyware (HKCU\Software\Microsoft\Windows\CurrentVersion\Drivers)! Action taken: Entries Removed.
22 III 2013 09:57:58 - Object "AntiSpyware Pro XP Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed.
22 III 2013 09:57:59 - ***** Scanning Registry Files *****
22 III 2013 09:58:00 - ** Value in HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
22 III 2013 09:58:00 - ** Value in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = http://www.msn.com/
22 III 2013 09:58:00 - ** Value in HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\main/Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
22 III 2013 09:58:00 - ***** Scanning System32 Folders *****
22 III 2013 09:59:05 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\mexe.com) took 8484 ms
22 III 2013 09:59:16 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\mwavdwnl.exe) took 8468 ms
22 III 2013 09:59:21 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\MWAVL.exe) took 5406 ms
22 III 2013 09:59:32 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\mwavscan.exe) took 8438 ms
22 III 2013 10:00:03 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\Portuguese.lic) took 11469 ms
22 III 2013 10:02:00 - ScanFile (C:\Documents and Settings\Alan\Local Settings\temp\viewtcp.exe) took 8563 ms
22 III 2013 10:02:01 - ***** Scanning Drive C:\ *****
22 III 2013 10:07:06 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e not Scanned. Possibly password protected...
22 III 2013 10:07:06 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\3a2ece88e28b03adfa37d292a40511fe1213101e
22 III 2013 10:07:07 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d not Scanned. Possibly password protected...
22 III 2013 10:07:07 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4185d9b39a871ebb0ce3d245f381590d3d99a83d
22 III 2013 10:07:08 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333 not Scanned. Possibly password protected...
22 III 2013 10:07:08 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\4b17f4291374c3aab19ceb80239641424b394333
22 III 2013 10:07:09 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e not Scanned. Possibly password protected...
22 III 2013 10:07:09 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5c416520c3d9d14b841f927051cc71ed58e28d5e
22 III 2013 10:07:09 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf not Scanned. Possibly password protected...
22 III 2013 10:07:09 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\5f25ca820494585dc3e8176259b608815b77d8bf
22 III 2013 10:07:10 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f not Scanned. Possibly password protected...
22 III 2013 10:07:10 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\68cd7b346eaf1b52b4bf9ba5a0b03bcd80b0ae3f
22 III 2013 10:07:10 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf not Scanned. Possibly password protected...
22 III 2013 10:07:10 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\6d2cea13a3ead3e155b92bdb3b18ea0953567dbf
22 III 2013 10:07:11 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067 not Scanned. Possibly password protected...
22 III 2013 10:07:11 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\7612c6c0984b29dcc84db328005b3b311a5f8067
22 III 2013 10:07:11 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455 not Scanned. Possibly password protected...
22 III 2013 10:07:11 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\787860856eff37820cae47f5083f599a0514d455
22 III 2013 10:07:12 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb not Scanned. Possibly password protected...
22 III 2013 10:07:12 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\84bb75218f6436abed329b0d042cae3883a3edeb
22 III 2013 10:07:13 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c not Scanned. Possibly password protected...
22 III 2013 10:07:13 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\866e0e9df82b1cd3795b75de246cd528d83c043c
22 III 2013 10:07:13 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967 not Scanned. Possibly password protected...
22 III 2013 10:07:13 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\8e09048661d0cf3f10ccd4d818c06df0d5e69967
22 III 2013 10:07:18 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8 not Scanned. Possibly password protected...
22 III 2013 10:07:18 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c2b1f29c21473da7187da48f7658f269a5280bc8
22 III 2013 10:07:18 - C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348 not Scanned. Possibly password protected...
22 III 2013 10:07:18 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\Alan\Data aplikací\Apple Computer\MobileSync\Backup\34207325cb21c8d1c0cfd9f6a103a8077915953a 1\c8c8948f0c8cfec9f0713b6c79483333b5f76348
22 III 2013 10:11:08 - C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin not Scanned. Possibly password protected...
22 III 2013 10:11:08 - ERROR(3)!!! ScanFile fails for C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin
22 III 2013 10:22:01 - C:\Program Files\Zoner\Photo Studio 13\pack.dat not Scanned. Possibly password protected...
22 III 2013 10:22:01 - ERROR(3)!!! ScanFile fails for C:\Program Files\Zoner\Photo Studio 13\pack.dat
22 III 2013 10:29:19 - C:\WINDOWS\SoftwareDistribution\EventCache\{6C7C3833-DE76-40A1-99E5-F298093C96E6}.bin not Scanned. Possibly password protected...
22 III 2013 10:29:19 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{6C7C3833-DE76-40A1-99E5-F298093C96E6}.bin
22 III 2013 10:29:24 - C:\WINDOWS\system32\CatRoot2\tmp.edb not Scanned. Possibly password protected...
22 III 2013 10:29:24 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\CatRoot2\tmp.edb
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\default not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\default
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\SAM not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\SAM
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\software not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\software
22 III 2013 10:29:25 - C:\WINDOWS\system32\config\system not Scanned. Possibly password protected...
22 III 2013 10:29:25 - ERROR(3)!!! ScanFile fails for C:\WINDOWS\system32\config\system
22 III 2013 10:30:07 - ***** Checking for specific ITW Viruses *****
22 III 2013 10:30:08 - ***** Scanning complete. *****
22 III 2013 10:30:08 - Total Objects Scanned: 285274
22 III 2013 10:30:08 - Total Critical Objects: 2
22 III 2013 10:30:08 - Total Disinfected Objects: 0
22 III 2013 10:30:08 - Total Objects Renamed: 0
22 III 2013 10:30:08 - Total Deleted Objects: 2
22 III 2013 10:30:08 - Total Errors: 0
22 III 2013 10:30:08 - Time Elapsed: 00:45:18
22 III 2013 10:30:08 - Virus Database Date: 26 Apr 2010
22 III 2013 10:30:08 - Virus Database Count: 5690871
22 III 2013 10:30:08 - Scan Completed.