Tak vše vpořádku moc a moc díky..hned bych tě pozval na pivo..

ještě jednou dík

THX hned bych ti přidal hvězdičku..
SDFix: Version 1.208 Run by Tom on so 26.07.2008 at 19:00
Microsoft Windows XP [Verze 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value
Restoring Windows ProductId To Remove Fake Virus Alert
Restoring Time Format To Remove Fake Virus Alert
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\EODA.EXE - Deleted
C:\Documents and Settings\Tom\Data aplikacˇ\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.redtube.com\settings.sol - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\bindsrv2.exe.bat - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\dssc32.exe.bat - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\scksexde.exe.bat - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\smchk.exe.bat - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\vistasp1.exe.bat - Deleted
C:\WINDOWS\nfavxwdblwf.dll - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\bindsrv2.exe - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\bindsrv2.exe.bat - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\s1265.php.bat - Deleted
C:\DOCUME~1\Tom\LOCALS~1\Temp\vistasp1.exe - Deleted
C:\WINDOWS\grswptdl.exe - Deleted
Could Not Remove C:\WINDOWS\system32\WinCtrl32.dll
Folder C:\Documents and Settings\Tom\Data aplikacˇ\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.redtube.com - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-26 19:05:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:68,fb,63,b6,37,c7,ef,27,91,06,d6,6b,30,7e,6a,94,96,9f,33,73,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,16,16,c5,03,3e,c7,8a,4e,4a,5c,6a,a8,06,9d,e5,7f,d8,..
"khjeh"=hex:3d,91,03,9d,16,f6,7f,3a,77,74,14,e1,c0,e5,d4,13,16,28,e7,a3,21,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:59,8a,90,a6,62,30,98,6d,67,db,ad,41,41,cd,92,84,6b,ff,e0,ac,bc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:68,fb,63,b6,37,c7,ef,27,91,06,d6,6b,30,7e,6a,94,96,9f,33,73,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,16,16,c5,03,3e,c7,8a,4e,4a,5c,6a,a8,06,9d,e5,7f,d8,..
"khjeh"=hex:3d,91,03,9d,16,f6,7f,3a,77,74,14,e1,c0,e5,d4,13,16,28,e7,a3,21,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:59,8a,90,a6,62,30,98,6d,67,db,ad,41,41,cd,92,84,6b,ff,e0,ac,bc,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?v?e?l?k?é?)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?n?e?j?v?\e\1t?a\1í?)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"
scanning hidden files ...
MOJE HLAVA\tady bylo moje péčko..xD trochu dlouhej list ...byl totiž My private folder zamčeny prostě...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1045
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\QIP\\qip.exe"="C:\\Program Files\\QIP\\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\\Program Files\\ICQ6\\ICQ.exe"="C:\\Program Files\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
"C:\\Games\\battlefield 2\\BF2.exe"="C:\\Games\\battlefield 2\\BF2.exe:*:Enabled:BF2"
"C:\\Games\\Call of Duty 2\\CoD2MP_s.exe"="C:\\Games\\Call of Duty 2\\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\\Games\\Lotr\\game.dat"="C:\\Games\\Lotr\\game.dat:*:Enabled:Battle for Middle-earth"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Ramjets\\ramjets.exe"="C:\\Program Files\\Ramjets\\ramjets.exe:*:Enabled:ramjets"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Games\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Games\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\\Games\\Cod4\\iw3mp.exe"="C:\\Games\\Cod4\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"="C:\\Program Files\\Sierra\\FEAR\\FEAR.exe:*:Enabled:FEAR"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"C:\\Games\\Warcraft III\\War3.exe"="C:\\Games\\Warcraft III\\War3.exe:*:Enabled:Warcraft III"
"C:\\Games\\Call of Duty 4\\iw3mp.exe"="C:\\Games\\Call of Duty 4\\iw3mp.exe:*:Enabled:iw3mp"
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"E:\\SETUP.EXE"="E:\\SETUP.EXE:*:Enabled:SETUP"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
C:\WINDOWS\system32\WinCtrl32.dll Found
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Tue 1 Jul 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a5f16949630e8c407182e4928048db02\BIT30.tmp"
Sun 2 Mar 2008 462,848 A.SH. --- "C:\Documents and Settings\Tom\Dokumenty\Fotky a videa\FOTO\Dovolen \SIVEE.tmp"
Sun 2 Mar 2008 229,376 A.SH. --- "C:\Documents and Settings\Tom\Dokumenty\Fotky a videa\FOTO\Dovolen \SIVEF.tmp"
Sun 2 Mar 2008 151,552 A.SH. --- "C:\Documents and Settings\Tom\Dokumenty\Fotky a videa\FOTO\Dovolen \SIVF0.tmp"
Finished!