Prosím o kontrolu logu
Napsal: 19 črc 2007 16:49
Zdravím všechny! Nějak se mi zpomalil PC a tak prosím o kontrolu logu z HiJackThis a přikládám ještě výpis z MWAV logu. Tam je to asi nepřesný. MWAV mi našel 12 kritických a celkem 63 chyb. Já toho tolik nenašel Díky za pomoc.
Logfile of HijackThis v1.99.1
Scan saved at 16:40:03, on 19.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Timer Wizard\Timer Wizard.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Timer Wizard.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - C:\WINDOWS\system32\OOD2000.exe
MWAV
Thu Jul 19 14:07:50 2007 => **********************************************************
Thu Jul 19 14:07:50 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Thu Jul 19 14:07:50 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Thu Jul 19 14:07:50 2007 => **********************************************************
Thu Jul 19 14:07:50 2007 => Source: C:\mwav.exe
Thu Jul 19 14:07:50 2007 => Verze 9.3.1 (C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\mexe.com)
Thu Jul 19 14:07:50 2007 => Log soubor: C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\MWAV.LOG
Thu Jul 19 14:07:50 2007 => Datum a čas posledního testu: 13.07.2007 23:44:47
Thu Jul 19 14:07:50 2007 => MWAV Registered: FALSE.
Thu Jul 19 14:07:50 2007 => User Account: Blue Spirit
Thu Jul 19 14:07:50 2007 => OS Type: Windows Workstation
Thu Jul 19 14:07:50 2007 => OS: Windows XP
Thu Jul 19 14:07:50 2007 => Ver: Service Pack 2 (Build 2600)
Thu Jul 19 14:07:50 2007 => Windows Root Folder: C:\WINDOWS
Thu Jul 19 14:07:50 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Thu Jul 19 14:07:50 2007 => DHCP NameServer: 172.16.0.1
Thu Jul 19 14:07:50 2007 => Interface0 DHCPNameServer: 172.16.0.1
Thu Jul 19 14:07:50 2007 => Local Fixed Drives: c:\,d:\,e:\
Thu Jul 19 14:07:50 2007 => MWAV Mode: Only Scan files.
C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\virus.avi
C:\Documents and Settings\Blue Spirit\.gimp-2.2\environ]
C:\Documents and Settings\Blue Spirit\Local Settings\Temp\virus.avi
C:\HRY_INSTALAČKY\Plane_Arc_R\Plane Arcade\Models\spitfire\enviro.bmp
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702f-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27032-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27034-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702d-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702e-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27031-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27033-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27036-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:45 2007 => Offending Key found: HKCU\\ssubtimer6.gsubclass !!!
Thu Jul 19 14:09:45 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:09:45 2007 => Offending Key found: HKCU\\ssubtimer6.isubclass !!!
Thu Jul 19 14:09:45 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:09:52 2007 => Offending file found: C:\WINDOWS\system32\unzip32.dll
Thu Jul 19 14:09:52 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:54 2007 => Checking MountPoints2 Registry Key...
Thu Jul 19 14:09:54 2007 => Invalid Command Found in {408d2b7d-2adc-11dc-ba0c-00120e2edf0c}\Shell\AutoRun\command: H:\LaunchU3.exe -a
Thu Jul 19 14:09:54 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c} !!!
Thu Jul 19 14:09:54 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
C:\WINDOWS\system32\netware.drvC:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\Spyware.sdb
C:\Documents and Settings\Blue Spirit\Local Settings\Temp\Spyware.sdb
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27032-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27034-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702d-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702e-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27031-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27033-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27036-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.ctimer !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.gsubclass !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.isubclass !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:21 2007 => Offending file found: C:\WINDOWS\system32\unzip32.dll
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:23 2007 => Checking MountPoints2 Registry Key...
Thu Jul 19 14:23:23 2007 => Invalid Command Found in {408d2b7d-2adc-11dc-ba0c-00120e2edf0c}\Shell\AutoRun\command: H:\LaunchU3.exe -a
Thu Jul 19 14:23:23 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c} !!!
Thu Jul 19 14:23:23 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo prov
Thu Jul 19 15:22:20 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:51:55 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:53:39 2007 => Testování souboru C:\WINDOWS\system32\netware.drv
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Logfile of HijackThis v1.99.1
Scan saved at 16:40:03, on 19.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Timer Wizard\Timer Wizard.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Timer Wizard.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - C:\WINDOWS\system32\OOD2000.exe
MWAV
Thu Jul 19 14:07:50 2007 => **********************************************************
Thu Jul 19 14:07:50 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Thu Jul 19 14:07:50 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Thu Jul 19 14:07:50 2007 => **********************************************************
Thu Jul 19 14:07:50 2007 => Source: C:\mwav.exe
Thu Jul 19 14:07:50 2007 => Verze 9.3.1 (C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\mexe.com)
Thu Jul 19 14:07:50 2007 => Log soubor: C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\MWAV.LOG
Thu Jul 19 14:07:50 2007 => Datum a čas posledního testu: 13.07.2007 23:44:47
Thu Jul 19 14:07:50 2007 => MWAV Registered: FALSE.
Thu Jul 19 14:07:50 2007 => User Account: Blue Spirit
Thu Jul 19 14:07:50 2007 => OS Type: Windows Workstation
Thu Jul 19 14:07:50 2007 => OS: Windows XP
Thu Jul 19 14:07:50 2007 => Ver: Service Pack 2 (Build 2600)
Thu Jul 19 14:07:50 2007 => Windows Root Folder: C:\WINDOWS
Thu Jul 19 14:07:50 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Thu Jul 19 14:07:50 2007 => DHCP NameServer: 172.16.0.1
Thu Jul 19 14:07:50 2007 => Interface0 DHCPNameServer: 172.16.0.1
Thu Jul 19 14:07:50 2007 => Local Fixed Drives: c:\,d:\,e:\
Thu Jul 19 14:07:50 2007 => MWAV Mode: Only Scan files.
C:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\virus.avi
C:\Documents and Settings\Blue Spirit\.gimp-2.2\environ]
C:\Documents and Settings\Blue Spirit\Local Settings\Temp\virus.avi
C:\HRY_INSTALAČKY\Plane_Arc_R\Plane Arcade\Models\spitfire\enviro.bmp
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702f-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27032-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27034-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:43 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702d-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702e-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27031-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27033-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:44 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27036-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:45 2007 => Offending Key found: HKCU\\ssubtimer6.gsubclass !!!
Thu Jul 19 14:09:45 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:09:45 2007 => Offending Key found: HKCU\\ssubtimer6.isubclass !!!
Thu Jul 19 14:09:45 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:09:52 2007 => Offending file found: C:\WINDOWS\system32\unzip32.dll
Thu Jul 19 14:09:52 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:09:54 2007 => Checking MountPoints2 Registry Key...
Thu Jul 19 14:09:54 2007 => Invalid Command Found in {408d2b7d-2adc-11dc-ba0c-00120e2edf0c}\Shell\AutoRun\command: H:\LaunchU3.exe -a
Thu Jul 19 14:09:54 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c} !!!
Thu Jul 19 14:09:54 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
C:\WINDOWS\system32\netware.drvC:\DOCUME~1\BLUESP~1\LOCALS~1\Temp\Spyware.sdb
C:\Documents and Settings\Blue Spirit\Local Settings\Temp\Spyware.sdb
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27032-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27034-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:11 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702d-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a2702e-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27031-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27033-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:12 2007 => System found infected with mybugfreepc Corrupted Adware/Spyware ({71a27036-c7d8-11d2-bef8-525400dfb47a})! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.ctimer !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.gsubclass !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:13 2007 => Offending Key found: HKCU\\ssubtimer6.isubclass !!!
Thu Jul 19 14:23:13 2007 => Objekt "mybugfreepc Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Nic nebylo provedeno.
Thu Jul 19 14:23:21 2007 => Offending file found: C:\WINDOWS\system32\unzip32.dll
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.
Thu Jul 19 14:23:23 2007 => Checking MountPoints2 Registry Key...
Thu Jul 19 14:23:23 2007 => Invalid Command Found in {408d2b7d-2adc-11dc-ba0c-00120e2edf0c}\Shell\AutoRun\command: H:\LaunchU3.exe -a
Thu Jul 19 14:23:23 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{408d2b7d-2adc-11dc-ba0c-00120e2edf0c} !!!
Thu Jul 19 14:23:23 2007 => Objekt "Possible Fujacks-type Worm" nalezen v souborovém systému! Provedené akce: Nic nebylo prov
Thu Jul 19 15:22:20 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:51:55 2007 => ERROR!!! ScanFile fails for C:\WINDOWS\SoftwareDistribution\EventCache\{4DB65473-1ACC-48C8-BAC0-E3A51387CD86}.bin
Thu Jul 19 15:53:39 2007 => Testování souboru C:\WINDOWS\system32\netware.drv
Thu Jul 19 14:23:21 2007 => System found infected with savenow Adware (C:\WINDOWS\system32\unzip32.dll)! Action taken: Nic nebylo provedeno.