Kontrola HJT: totalne zashitovanej PC

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

hadic
Level 1.5
Level 1.5
Příspěvky: 113
Registrován: březen 07
Bydliště: Ústí nad Orlicí
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Kontrola HJT: totalne zashitovanej PC

Příspěvekod hadic » 23 říj 2009 23:40

cau, bratr stahl dnes jakejsi keygen a samozrejme to byl vir. a jak jsem zjistil tak od zadnyho zacatecnika :evil:

Posilam lig z HJT a jeste dodam ze je zavirovanej explorer.exe, services.exe a jeste par dalsich dulezitejch procesu :x

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:34:40, on 23.10.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\system32\nlp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Razer\Copperhead\razertra.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\já\Plocha\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.mywebsearch.com/mywebsear ... AAuSnkCecA
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LPT LED Effect] C:\Documents and Settings\já\Plocha\lle-1\LLE.exe hide
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"
O4 - HKLM\..\Run: [HomeKeyLogger] C:\Program Files\HomeKeylogger\KeyLogger.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [nlp] C:\WINDOWS\system32\nlp.exe \u
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [VoipCheapCom] "C:\Program Files\VoipCheapCom\VoipCheapCom.exe" -nosplash -minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A05FD30-C819-4DCF-AAE7-D6342936C338}: NameServer = 192.168.124.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{5A05FD30-C819-4DCF-AAE7-D6342936C338}: NameServer = 192.168.124.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{5A05FD30-C819-4DCF-AAE7-D6342936C338}: NameServer = 192.168.124.1
O20 - AppInit_DLLs: ms32clod.dll
O21 - SSODL: HOpJa - {EC3A47FA-4690-ED50-B2DA-FF14BFB326CF} - C:\WINDOWS\System32\sxph.dll (file missing)
O23 - Service: Správa aplikací (AppMgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Zvuk systému Windows (AudioSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
O23 - Service: Služba inteligentního přenosu na pozadí (BITS) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Prohledávání počítačů (Browser) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Šifrování (CryptSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Spouštěč procesů serveru DCOM (DcomLaunch) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Klient DHCP (Dhcp) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Správce logických disků (dmserver) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Klient DNS (Dnscache) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Zasílání zpráv o chybách (ERSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Protokol událostí (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Systém událostí modelu COM+ (EventSystem) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Kompatibilita pro rychlé přepínání uživatelů (FastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Služba Google Update (gupdate1ca0b59fbbe09ff) (gupdate1ca0b59fbbe09ff) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Nápověda a odborná pomoc (helpsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: HID Input Service (HidServ) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Server (lanmanserver) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Pracovní stanice (lanmanworkstation) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Podpora rozhraní NetBIOS nad protokolem TCP/IP (LmHosts) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Přihlašování k síti (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe
O23 - Service: Síťová připojení (Netman) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Sledování umístění v síti (NLA) (Nla) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Zprostředkovatel zabezpečení NT LM (NtLmSsp) - Unknown owner - C:\WINDOWS\system32\lsass.exe
O23 - Service: Vyměnitelné úložiště (NtmsSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Služby IPSEC (PolicyAgent) - Unknown owner - C:\WINDOWS\system32\lsass.exe
O23 - Service: Chráněné úložiště (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsass.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Správce automatického připojení pomocí vzdáleného přístupu (RasAuto) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Správce vzdáleného přístupu (RasMan) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Vzdálený registr (RemoteRegistry) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Vzdálené volání procedur (RPC) (RpcSs) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Správce zabezpečení účtů (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe
O23 - Service: Plánovač úloh (Schedule) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Sekundární přihlašování (seclogon) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Oznamování systémových událostí (SENS) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Brána Firewall / Sdílení připojení k Internetu (ICS) (SharedAccess) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Rozpoznávání hardwaru (ShellHWDetection) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Služba obnovení systému (srservice) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Služba rozpoznávání pomocí protokolu SSDP (SSDPSRV) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Načítání obrázků (WIA) (stisvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Telefonní subsystém (TapiSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Terminálová služba (TermService) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Motivy (Themes) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Klient služby sledování distribuovaných propojení (TrkWks) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Hostitel zařízení UPnP (upnphost) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Systémový čas (W32Time) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Webový klient (WebClient) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Služba WMI (winmgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Služba sériového čísla přenosného zařízení (WmdmPmSN) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Rozšíření ovladače WMI (Wmi) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Automatické aktualizace (wuauserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe
O23 - Service: Automatická konfigurace bezdrátových zařízení (WZCSVC) - Unknown owner - C:\WINDOWS\System32\svchost.exe
O23 - Service: Služba pro síťová ustanovení (xmlprov) - Unknown owner - C:\WINDOWS\System32\svchost.exe

--
End of file - 13436 bytes

Reklama
Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod Damned » 23 říj 2009 23:53

Odinstaluj MyWeb Search (FunWeb apod.) a Kasperskyho. Vypni v procesech instalátor avastu (avast.setup).

Spusť HJT (HijackThis), vypni prohlížeče, odpoj se od internetu a fixni (spustit HJT, "Do a system scan only",
zatrhnout políčko před hodnotou, zmáčknout "Fix checked" a poté "Ano"):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.mywebsearch.com/mywebsear ... AAuSnkCecA
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LPT LED Effect] C:\Documents and Settings\já\Plocha\lle-1\LLE.exe hide
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HomeKeyLogger] C:\Program Files\HomeKeylogger\KeyLogger.exe
O4 - HKLM\..\Run: [nlp] C:\WINDOWS\system32\nlp.exe \u
O21 - SSODL: HOpJa - {EC3A47FA-4690-ED50-B2DA-FF14BFB326CF} - C:\WINDOWS\System32\sxph.dll (file missing)
*****************************************************************************************************************************************
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

hadic
Level 1.5
Level 1.5
Příspěvky: 113
Registrován: březen 07
Bydliště: Ústí nad Orlicí
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod hadic » 24 říj 2009 10:30

Tak, ted uz nemuzu delat vubec nic v normalnim stavu takze jsem vse delal v nouzovym rezimu tudiz se mi nepodarilo vymazat ten kaspersky a mywebsearch.

log z antimalware:
Malwarebytes' Anti-Malware 1.36
Verze databáze: 2159
Windows 5.1.2600 Service Pack 2

24.10.2009 10:03:22
mbam-log-2009-10-24 (10-03-18).txt

Typ skenu: Rychlý sken
Objektu skenováno: 79151
Uplynulý cas: 2 minute(s), 38 second(s)

Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 11
Infikované hodnoty registru: 1
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 1

Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)

Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)

Infikované klíce registru:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.

Infikované hodnoty registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\kr_done1 (Malware.Trace) -> No action taken.

Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované složky:
(Žádné zákerné položky nebyly zjišteny)

Infikované soubory:
C:\WINDOWS\system32\kr_done1 (Malware.Trace) -> No action taken.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod jaro3 » 24 říj 2009 12:05

Na Kaspersky je tam odinstalator, tak to zkus.

Jen vsuvka , pokračovat bude Damned.

. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

Můžeš sem pak vložit log z MbAM.


Vypni rez. ochrany antiviru+antispywaru.


Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

hadic
Level 1.5
Level 1.5
Příspěvky: 113
Registrován: březen 07
Bydliště: Ústí nad Orlicí
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod hadic » 24 říj 2009 13:58

kaspersky se mi nepodarilo odinstalovat, zde je chybova hlaska: http://img148.imageshack.us/img148/985/uninstallz.jpg

log z combofix-
ComboFix 09-10-23.01 - já 24.10.2009 13:46.1.2 - NTFSx86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1983.1625 [GMT 2:00]
Spuštěný z: c:\documents and settings\já\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 091022-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system\msvbvm60.dll
c:\windows\system32\ieuinit.inf
c:\windows\system32\pst.dat
c:\windows\system32\winio.vxd

c:\windows\system32\lsass.exe . . . je infikován!!

c:\windows\system32\services.exe . . . je infikován!!

c:\windows\system32\svchost.exe . . . je infikován!!

c:\windows\explorer.exe . . . je infikován!!

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-09-24 do 2009-10-24 )))))))))))))))))))))))))))))))
.

2009-10-23 20:44 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-23 20:44 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-23 20:44 . 2009-08-17 16:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-23 20:44 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-23 20:44 . 2009-08-17 16:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-23 20:44 . 2009-08-17 16:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-23 20:44 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-23 20:44 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-23 20:44 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-23 20:44 . 2009-10-23 20:44 -------- d-----w- c:\program files\Alwil Software
2009-10-23 18:57 . 2009-10-23 18:57 -------- d-----w- c:\windows\USB Vibration
2009-10-23 18:57 . 2009-10-23 18:57 -------- d-----w- c:\program files\USB Vibration
2009-10-23 18:56 . 2009-10-24 11:39 0 ----a-w- c:\windows\system32\sck236jn.dat
2009-10-23 18:55 . 2009-10-23 18:55 27648 ----a-w- c:\windows\system32\nlp.exe
2009-10-23 18:55 . 2009-10-23 18:55 19456 ----a-w- c:\windows\system32\perfc5932.dat
2009-10-23 18:55 . 2009-10-23 18:55 1 ----a-w- c:\windows\system32\perfc7683.dat
2009-10-21 13:08 . 2009-10-21 13:08 -------- d-----w- c:\program files\IVT Corporation
2009-10-20 20:38 . 2009-10-20 20:38 -------- d-----w- C:\ZAV_DOMA
2009-10-11 21:11 . 2009-10-11 21:11 -------- d-----w- c:\windows\system32\cs-CZ
2009-10-11 21:11 . 2009-10-11 21:11 -------- d-----w- c:\program files\MSBuild
2009-10-11 21:09 . 2009-10-11 21:11 -------- d-----w- c:\windows\system32\XPSViewer
2009-10-11 21:08 . 2009-10-11 21:08 -------- d-----w- c:\program files\Reference Assemblies
2009-10-11 21:08 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-10-11 20:54 . 2009-10-11 20:54 -------- d-----r- C:\MSOCache
2009-10-10 14:59 . 2004-08-17 13:49 54272 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll
2009-10-08 16:36 . 2009-10-08 16:36 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-08 16:02 . 2009-10-08 16:02 -------- d-----w- c:\program files\Biromsoft
2009-10-08 15:53 . 2004-08-09 15:43 94208 ----a-w- c:\windows\amcap.exe
2009-10-08 15:53 . 2004-07-30 16:50 286720 ----a-w- c:\windows\vsnpstd3.exe
2009-10-08 15:53 . 2004-06-15 13:18 53248 ----a-w- c:\windows\system32\dsnpstd3.dll
2009-10-08 15:53 . 2009-10-08 15:53 -------- d-----w- c:\program files\Common Files\snpstd3
2009-10-08 15:53 . 2004-08-06 13:48 20480 ----a-w- c:\windows\usnpstd3.exe
2009-10-08 15:52 . 2004-02-16 11:59 61440 ----a-w- c:\windows\system32\csnpstd3.dll
2009-10-08 15:52 . 2004-11-05 09:21 57344 ----a-w- c:\windows\system32\rsnpstd3.dll
2009-10-08 15:52 . 2004-08-30 09:00 36864 ----a-w- c:\windows\system32\vsnpstd3.dll
2009-10-08 15:52 . 2005-11-21 10:51 53248 ----a-r- c:\windows\system\dsnpstd3.dll
2009-10-08 15:51 . 2004-10-29 11:52 413696 ----a-w- c:\windows\system32\drivers\snpstd3.sys
2009-10-08 15:49 . 2004-08-17 13:49 54272 ----a-w- c:\windows\system\vfwwdm32.dll
2009-10-08 09:30 . 2009-10-08 09:30 -------- d-----w- c:\windows\nview
2009-10-08 09:30 . 2008-02-25 04:29 360448 ----a-w- c:\windows\system32\nvudisp.exe
2009-10-08 09:29 . 2008-01-25 11:48 360448 ----a-r- c:\windows\system32\nvraiins.dll
2009-10-08 09:29 . 2008-01-25 11:48 360448 ----a-r- c:\windows\system32\nvraidco.dll
2009-10-08 09:29 . 2008-02-19 10:13 199168 ----a-r- c:\windows\system32\fdco1.dll
2009-10-08 09:29 . 2008-01-29 04:37 54016 ----a-r- c:\windows\system32\drivers\NVENETFD.sys
2009-10-08 09:29 . 2008-03-06 09:23 442368 ----a-w- c:\windows\system32\nvunrm.exe
2009-10-08 09:28 . 2008-01-29 04:36 9216 ----a-r- c:\windows\system32\bdco1.dll
2009-10-08 09:28 . 2008-01-29 04:13 35840 ----a-r- c:\windows\system32\nvconrm.dll
2009-10-08 09:28 . 2008-01-29 04:37 950272 ----a-r- c:\windows\system32\drivers\nvnrm.sys
2009-10-08 09:28 . 2008-01-29 04:37 22016 ----a-r- c:\windows\system32\drivers\nvnetbus.sys
2009-10-08 09:28 . 2008-04-02 07:32 442368 ----a-r- c:\windows\system32\nvusmu.exe
2009-10-08 09:28 . 2008-02-15 07:15 14336 ----a-r- c:\windows\system32\drivers\nvsmu.sys
2009-10-08 09:28 . 2008-02-13 04:27 35840 ----a-r- c:\windows\system32\NVCOSMU.DLL
2009-10-08 09:28 . 2008-01-10 06:30 442368 ----a-r- c:\windows\system32\nvusmb.exe
2009-10-08 09:28 . 2008-04-02 07:32 442368 ----a-r- c:\windows\system32\NVUNINST.EXE
2009-10-07 15:52 . 2009-10-24 11:25 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-25 13:44 . 2009-09-25 13:45 -------- d-----w- c:\program files\HomeKeylogger

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-24 11:42 . 2009-10-24 11:39 763260 ----a-w- c:\windows\system32\jf6wmj.tmp
2009-10-24 11:39 . 2009-10-24 11:39 950 ----a-w- c:\windows\system32\pzyoi5.tmp
2009-10-24 11:39 . 2009-10-24 11:39 407 ----a-w- c:\windows\system32\ojt61k.tmp
2009-10-24 11:39 . 2009-10-24 11:39 1104 ----a-w- c:\windows\system32\m4vc02.tmp
2009-10-24 11:39 . 2009-10-24 11:39 138 ----a-w- c:\windows\system32\pp411n.tmp
2009-10-24 11:28 . 2009-10-24 11:28 66 ----a-w- c:\windows\system32\61jq08.tmp
2009-10-24 11:28 . 2009-10-24 11:28 61 ----a-w- c:\windows\system32\r2cbju.tmp
2009-10-24 11:28 . 2009-10-24 11:28 47 ----a-w- c:\windows\system32\n64p32.tmp
2009-10-24 11:25 . 2009-10-24 11:25 34 ----a-w- c:\windows\system32\b47y3g.tmp
2009-10-24 11:24 . 2009-10-24 11:24 34 ----a-w- c:\windows\system32\rijq3g.tmp
2009-10-24 08:30 . 2009-10-24 08:27 799326 ----a-w- c:\windows\system32\7aqa6c.tmp
2009-10-23 19:42 . 2009-10-23 19:42 26336 ----a-w- c:\windows\system32\k4gqte.tmp
2009-10-23 19:42 . 2009-10-23 19:42 10036 ----a-w- c:\windows\system32\o5be8t.tmp
2009-10-23 19:42 . 2009-10-23 19:42 885 ----a-w- c:\windows\system32\2lhcws.tmp
2009-10-23 19:42 . 2009-10-23 19:42 433 ----a-w- c:\windows\system32\2pqa3r.tmp
2009-10-23 19:42 . 2009-10-23 19:39 792901 ----a-w- c:\windows\system32\atsy18.tmp
2009-10-23 18:57 . 2009-03-24 18:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 17:56 . 2009-09-22 12:34 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-14 17:56 . 2009-09-22 12:34 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-11 21:11 . 2001-10-25 11:00 76516 ----a-w- c:\windows\system32\perfc005.dat
2009-10-11 21:11 . 2001-10-25 11:00 424082 ----a-w- c:\windows\system32\perfh005.dat
2009-10-08 09:02 . 2009-04-24 11:14 -------- d-----w- c:\program files\Ubisoft
2009-10-08 09:01 . 2009-04-24 11:16 -------- d-----w- c:\program files\3DO
2009-10-08 08:55 . 2009-03-31 13:27 -------- d-----w- c:\program files\Google
2009-09-22 12:45 . 2009-09-22 12:45 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-09-22 12:33 . 2009-09-22 12:33 -------- d-----w- c:\program files\Kaspersky Lab
2009-09-20 17:12 . 2009-09-20 17:12 -------- d-----w- c:\program files\ReadManiac
2009-09-10 20:11 . 2009-04-23 21:01 -------- d-----w- c:\program files\vanBasco's Karaoke Player
2009-08-28 12:54 . 2009-08-28 11:15 17549 ----a-w- c:\windows\War3Unin.dat
2009-08-28 11:15 . 2009-08-28 11:15 2829 ----a-w- c:\windows\War3Unin.pif
2009-08-28 11:15 . 2009-08-28 11:15 126976 ----a-w- c:\windows\War3Unin.exe
2009-08-28 11:15 . 2009-08-28 11:14 -------- d-----w- c:\program files\Warcraft III
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-23 12:03 . 2009-05-23 12:03 8 --sh--r- c:\windows\system32\494EAFDBB2.sys
2009-05-28 16:29 . 2009-05-06 14:04 88 --sh--r- c:\windows\system32\88EADAF55C.sys
2009-05-28 20:25 . 2009-05-06 14:04 2620 --sha-w- c:\windows\system32\KGyGaAvL.sys
2004-08-17 13:49 . 2004-08-17 13:49 161513 --sha-r- c:\windows\system32\uqtmsd.dll
.

------- Sigcheck -------

[-] 2004-08-17 . 4623013EE7F55E16A8A4316444D599A3 . 14848 . . [5.1.2600.2180] . . c:\windows\system32\lsass.exe

[-] 2004-08-17 . 10CE8946066015D48C180F18578523B3 . 110592 . . [5.1.2600.2180] . . c:\windows\system32\services.exe


[-] 2004-08-17 . 0388CD01DF51C4AB3AEF0384C3478DBA . 506368 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe

[-] 2004-08-17 . 6282E29E40FDCA9AB57496A58531237D . 17408 . . [5.1.2600.2180] . . c:\windows\system32\svchost.exe

[-] 2004-08-17 . 38B63F224A9AE55A91303D4E4D72A597 . 1035264 . . [6.00.2900.2180] . . c:\windows\explorer.exe

c:\windows\system32\spoolsv.exe ... chybí !!
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-17 2289664]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-17 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-09 198160]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"razer"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-10-08 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"snpstd3"="c:\windows\vsnpstd3.exe" [2004-07-30 286720]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-04-10 16861184]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-02-25 1626112]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\j \Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-5-17 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
Rychl‚ spuçtŘnˇ aplikace HP Image Zone.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-29 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\já\\Plocha\\Já\\qipinfium9000\\infium.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\EverStep\\Program\\EverStep.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Documents and Settings\\já\\ocuf.exe"=
"c:\\WINDOWS\\system32\\nlp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4736:TCP"= 4736:TCP:pekzbf

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13.5.2009 17:46 31760]
R3 Razerlow;Razer Copperhead Driver;c:\windows\system32\drivers\Razerlow.sys [21.8.2009 15:45 19020]
R3 xTouch;xTouch;c:\windows\system32\drivers\xTouch.sys [28.7.2009 10:38 67968]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15.12.2008 20:41 33808]
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [23.10.2009 22:44 114768]
S1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [16.4.2009 21:05 2996]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23.10.2009 22:44 20560]
S2 gupdate1ca0b59fbbe09ff;Služba Google Update (gupdate1ca0b59fbbe09ff);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S2 hisxjgt;Image Support;c:\windows\system32\svchost.exe -k netsvcs [17.8.2004 15:49 17408]
S3 EGXFilter;EGXFilter;c:\windows\system32\drivers\EGXFilter.sys [28.7.2009 10:38 80896]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\J1EA6~1\LOCALS~1\Temp\LYY86.tmp --> c:\docume~1\J1EA6~1\LOCALS~1\Temp\LYY86.tmp [?]
S3 iywpvx;iywpvx;\??\c:\windows\system32\03.tmp --> c:\windows\system32\03.tmp [?]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16.5.2009 20:59 19472]

--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - HISXJGT

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
hisxjgt

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = iexplore
TCP: {5A05FD30-C819-4DCF-AAE7-D6342936C338} = 192.168.124.1
FF - ProfilePath - c:\documents and settings\já\Data aplikací\Mozilla\Firefox\Profiles\0fpnruwx.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: browser.startup.homepage - hxxp://cs.start2.mozilla.com/firefox?cl ... s:official
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redi ... searchfor=
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-VoipCheapCom - c:\program files\VoipCheapCom\VoipCheapCom.exe
HKLM-Run-c:\program files\Free Video Zilla\FVZilla.exe - (no file)
AddRemove-Cestina pro SL - c:\program files\Cestina pro SL\UninstallCZProSL_1_22.exe
AddRemove-_{63218538-4A69-497F-8455-904261B0E9E4} - c:\program files\Corel\CorelDRAW Graphics Suite 13\Programs\MSILauncher {63218538-4A69-497F-8455-904261B0E9E4}



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-24 13:48
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\J1EA6~1\LOCALS~1\Temp\LYY86.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iywpvx]
"ImagePath"="\??\c:\windows\system32\03.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hisxjgt]
"ServiceDll"="c:\windows\system32\uqtmsd.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{21627ef5-5dc7-47a2-9392-427ba2634d93}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b3
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):09,36,02,17,49,ad,c4,6e,11,e1,1b,0b,57,6f,b5,67,0e,74,08,fe,d9,
7d,05,08,32,a8,e9,f3,8d,54,37,06,03,83,80,05,32,e5,94,96,00,00,00,00,00,00,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\ms32clod.dll

- - - - - - - > 'lsass.exe'(948)
c:\windows\system32\ms32clod.dll
.
Celkový čas: 2009-10-24 13:49
ComboFix-quarantined-files.txt 2009-10-24 11:49

Před spuštěním: Volných bajtů: 199 469 776 896
Po spuštění: Volných bajtů: 208 923 193 344

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 678ECBF6A7A3E4D0FA9089327F3DE806

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod Damned » 24 říj 2009 16:11

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok).
Zkopíruj do něj následující celý text označený zeleně:

KillAll::
File::
c:\windows\system32\sck236jn.dat
c:\windows\system32\nlp.exe
c:\windows\system32\perfc5932.dat
c:\windows\system32\perfc7683.dat
c:\windows\system32\ezsidmv.dat
c:\windows\system32\d3d9caps.dat
c:\windows\system32\ojt61k.tmp
c:\windows\system32\m4vc02.tmp
c:\windows\system32\pp411n.tmp
c:\windows\system32\61jq08.tmp
c:\windows\system32\r2cbju.tmp
c:\windows\system32\n64p32.tmp
c:\windows\system32\b47y3g.tmp
c:\windows\system32\rijq3g.tmp
c:\windows\system32\7aqa6c.tmp
c:\windows\system32\k4gqte.tmp
c:\windows\system32\o5be8t.tmp
c:\windows\system32\2lhcws.tmp
c:\windows\system32\2pqa3r.tmp
c:\windows\system32\atsy18.tmp
c:\windows\system32\drivers\ISwift3.dat
c:\windows\system32\494EAFDBB2.sys
c:\windows\system32\88EADAF55C.sys
c:\windows\system32\KGyGaAvL.sys
c:\windows\system32\03.tmp
c:\docume~1\J1EA6~1\LOCALS~1\Temp\LYY86.tmp

Firefox::
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redi ... searchfor=

Driver::
hisxjgt;Image Support
hisxjgt
GarenaPEngine;GarenaPEngine
GarenaPEngine
iywpvx;iywpvx
iywpvx

NetSvc::
hisxjgt

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4736:TCP"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iywpvx]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hisxjgt]



Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.


Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.
Obrázek

- Automaticky se spustí ComboFix, oprava může trvat i déle než 10 minut. ! Nech ComboFix dokončit svou práci !
- Vlož sem log, který vyběhne v závěru čistícího procesu
*****************************************************************************************************************************************
Stáhni si OTL na Plochu.
Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Output klikni na minimal Output.Pod Standard Registry změň na All. Zatrhni LOP Check a Purity Check. Klikni na Run Scan. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj
*****************************************************************************************************************************************
Takže pak tu budu mít tři logy. Logy vlož samostatně do příspěvků. První ComboFix.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

hadic
Level 1.5
Level 1.5
Příspěvky: 113
Registrován: březen 07
Bydliště: Ústí nad Orlicí
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod hadic » 24 říj 2009 17:01

Tak, ted uz muzu byt v normalnim rezimu ale zase po pouziti combofixu nemuzu spustit proces explorer.exe coz je dost na prd :huh: No, dam sem log z CF a jdu na ten dalsi program

ComboFix 09-10-23.01 - já 24.10.2009 16:35.2.2 - NTFSx86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1983.1678 [GMT 2:00]
Spuštěný z: c:\documents and settings\já\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\já\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 091022-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}

FILE ::
"c:\docume~1\J1EA6~1\LOCALS~1\Temp\LYY86.tmp"
"c:\windows\system32\03.tmp"
"c:\windows\system32\2lhcws.tmp"
"c:\windows\system32\2pqa3r.tmp"
"c:\windows\system32\494EAFDBB2.sys"
"c:\windows\system32\61jq08.tmp"
"c:\windows\system32\7aqa6c.tmp"
"c:\windows\system32\88EADAF55C.sys"
"c:\windows\system32\atsy18.tmp"
"c:\windows\system32\b47y3g.tmp"
"c:\windows\system32\d3d9caps.dat"
"c:\windows\system32\drivers\ISwift3.dat"
"c:\windows\system32\ezsidmv.dat"
"c:\windows\system32\k4gqte.tmp"
"c:\windows\system32\KGyGaAvL.sys"
"c:\windows\system32\m4vc02.tmp"
"c:\windows\system32\n64p32.tmp"
"c:\windows\system32\nlp.exe"
"c:\windows\system32\o5be8t.tmp"
"c:\windows\system32\ojt61k.tmp"
"c:\windows\system32\perfc5932.dat"
"c:\windows\system32\perfc7683.dat"
"c:\windows\system32\pp411n.tmp"
"c:\windows\system32\r2cbju.tmp"
"c:\windows\system32\rijq3g.tmp"
"c:\windows\system32\sck236jn.dat"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\2lhcws.tmp
c:\windows\system32\2pqa3r.tmp
c:\windows\system32\494EAFDBB2.sys
c:\windows\system32\61jq08.tmp
c:\windows\system32\7aqa6c.tmp
c:\windows\system32\88EADAF55C.sys
c:\windows\system32\atsy18.tmp
c:\windows\system32\b47y3g.tmp
c:\windows\system32\d3d9caps.dat
c:\windows\system32\drivers\ISwift3.dat
c:\windows\system32\ezsidmv.dat
c:\windows\system32\k4gqte.tmp
c:\windows\system32\KGyGaAvL.sys
c:\windows\system32\m4vc02.tmp
c:\windows\system32\n64p32.tmp
c:\windows\system32\nlp.exe
c:\windows\system32\o5be8t.tmp
c:\windows\system32\ojt61k.tmp
c:\windows\system32\perfc5932.dat
c:\windows\system32\perfc7683.dat
c:\windows\system32\pp411n.tmp
c:\windows\system32\r2cbju.tmp
c:\windows\system32\rijq3g.tmp
c:\windows\system32\sck236jn.dat

c:\windows\system32\lsass.exe . . . je infikován!!

c:\windows\system32\services.exe . . . je infikován!!

c:\windows\system32\svchost.exe . . . je infikován!!

c:\windows\explorer.exe . . . je infikován!!

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_GARENAPENGINE
-------\Legacy_HISXJGT
-------\Legacy_IYWPVX
-------\Service_hisxjgt


((((((((((((((((((((((((( Soubory vytvořené od 2009-09-24 do 2009-10-24 )))))))))))))))))))))))))))))))
.

2009-10-24 14:38 . 2009-10-24 14:38 604140 ------w- c:\windows\system32\drivers\ISwift3.dat
2009-10-23 20:44 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-23 20:44 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-23 20:44 . 2009-08-17 16:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-23 20:44 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-23 20:44 . 2009-08-17 16:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-23 20:44 . 2009-08-17 16:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-23 20:44 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-23 20:44 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-23 20:44 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-23 20:44 . 2009-10-23 20:44 -------- d-----w- c:\program files\Alwil Software
2009-10-23 18:57 . 2009-10-23 18:57 -------- d-----w- c:\windows\USB Vibration
2009-10-23 18:57 . 2009-10-23 18:57 -------- d-----w- c:\program files\USB Vibration
2009-10-21 13:08 . 2009-10-21 13:08 -------- d-----w- c:\program files\IVT Corporation
2009-10-20 20:38 . 2009-10-20 20:38 -------- d-----w- C:\ZAV_DOMA
2009-10-11 21:11 . 2009-10-11 21:11 -------- d-----w- c:\windows\system32\cs-CZ
2009-10-11 21:11 . 2009-10-11 21:11 -------- d-----w- c:\program files\MSBuild
2009-10-11 21:09 . 2009-10-11 21:11 -------- d-----w- c:\windows\system32\XPSViewer
2009-10-11 21:08 . 2009-10-11 21:08 -------- d-----w- c:\program files\Reference Assemblies
2009-10-11 21:08 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-10-11 20:54 . 2009-10-11 20:54 -------- d-----r- C:\MSOCache
2009-10-10 14:59 . 2004-08-17 13:49 54272 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll
2009-10-08 16:02 . 2009-10-08 16:02 -------- d-----w- c:\program files\Biromsoft
2009-10-08 15:53 . 2004-08-09 15:43 94208 ----a-w- c:\windows\amcap.exe
2009-10-08 15:53 . 2004-07-30 16:50 286720 ----a-w- c:\windows\vsnpstd3.exe
2009-10-08 15:53 . 2004-06-15 13:18 53248 ----a-w- c:\windows\system32\dsnpstd3.dll
2009-10-08 15:53 . 2009-10-08 15:53 -------- d-----w- c:\program files\Common Files\snpstd3
2009-10-08 15:53 . 2004-08-06 13:48 20480 ----a-w- c:\windows\usnpstd3.exe
2009-10-08 15:52 . 2004-02-16 11:59 61440 ----a-w- c:\windows\system32\csnpstd3.dll
2009-10-08 15:52 . 2004-11-05 09:21 57344 ----a-w- c:\windows\system32\rsnpstd3.dll
2009-10-08 15:52 . 2004-08-30 09:00 36864 ----a-w- c:\windows\system32\vsnpstd3.dll
2009-10-08 15:52 . 2005-11-21 10:51 53248 ----a-r- c:\windows\system\dsnpstd3.dll
2009-10-08 15:51 . 2004-10-29 11:52 413696 ----a-w- c:\windows\system32\drivers\snpstd3.sys
2009-10-08 15:49 . 2004-08-17 13:49 54272 ----a-w- c:\windows\system\vfwwdm32.dll
2009-10-08 09:30 . 2009-10-08 09:30 -------- d-----w- c:\windows\nview
2009-10-08 09:30 . 2008-02-25 04:29 360448 ----a-w- c:\windows\system32\nvudisp.exe
2009-10-08 09:29 . 2008-01-25 11:48 360448 ----a-r- c:\windows\system32\nvraiins.dll
2009-10-08 09:29 . 2008-01-25 11:48 360448 ----a-r- c:\windows\system32\nvraidco.dll
2009-10-08 09:29 . 2008-02-19 10:13 199168 ----a-r- c:\windows\system32\fdco1.dll
2009-10-08 09:29 . 2008-01-29 04:37 54016 ----a-r- c:\windows\system32\drivers\NVENETFD.sys
2009-10-08 09:29 . 2008-03-06 09:23 442368 ----a-w- c:\windows\system32\nvunrm.exe
2009-10-08 09:28 . 2008-01-29 04:36 9216 ----a-r- c:\windows\system32\bdco1.dll
2009-10-08 09:28 . 2008-01-29 04:13 35840 ----a-r- c:\windows\system32\nvconrm.dll
2009-10-08 09:28 . 2008-01-29 04:37 950272 ----a-r- c:\windows\system32\drivers\nvnrm.sys
2009-10-08 09:28 . 2008-01-29 04:37 22016 ----a-r- c:\windows\system32\drivers\nvnetbus.sys
2009-10-08 09:28 . 2008-04-02 07:32 442368 ----a-r- c:\windows\system32\nvusmu.exe
2009-10-08 09:28 . 2008-02-15 07:15 14336 ----a-r- c:\windows\system32\drivers\nvsmu.sys
2009-10-08 09:28 . 2008-02-13 04:27 35840 ----a-r- c:\windows\system32\NVCOSMU.DLL
2009-10-08 09:28 . 2008-01-10 06:30 442368 ----a-r- c:\windows\system32\nvusmb.exe
2009-10-08 09:28 . 2008-04-02 07:32 442368 ----a-r- c:\windows\system32\NVUNINST.EXE
2009-09-25 13:44 . 2009-09-25 13:45 -------- d-----w- c:\program files\HomeKeylogger

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-24 11:42 . 2009-10-24 11:39 763260 ----a-w- c:\windows\system32\jf6wmj.tmp
2009-10-24 11:39 . 2009-10-24 11:39 950 ----a-w- c:\windows\system32\pzyoi5.tmp
2009-10-23 18:57 . 2009-03-24 18:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 17:56 . 2009-09-22 12:34 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-14 17:56 . 2009-09-22 12:34 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-11 21:11 . 2001-10-25 11:00 76516 ----a-w- c:\windows\system32\perfc005.dat
2009-10-11 21:11 . 2001-10-25 11:00 424082 ----a-w- c:\windows\system32\perfh005.dat
2009-10-08 09:02 . 2009-04-24 11:14 -------- d-----w- c:\program files\Ubisoft
2009-10-08 09:01 . 2009-04-24 11:16 -------- d-----w- c:\program files\3DO
2009-10-08 08:55 . 2009-03-31 13:27 -------- d-----w- c:\program files\Google
2009-09-22 12:33 . 2009-09-22 12:33 -------- d-----w- c:\program files\Kaspersky Lab
2009-09-20 17:12 . 2009-09-20 17:12 -------- d-----w- c:\program files\ReadManiac
2009-09-10 20:11 . 2009-04-23 21:01 -------- d-----w- c:\program files\vanBasco's Karaoke Player
2009-08-28 12:54 . 2009-08-28 11:15 17549 ----a-w- c:\windows\War3Unin.dat
2009-08-28 11:15 . 2009-08-28 11:15 2829 ----a-w- c:\windows\War3Unin.pif
2009-08-28 11:15 . 2009-08-28 11:15 126976 ----a-w- c:\windows\War3Unin.exe
2009-08-28 11:15 . 2009-08-28 11:14 -------- d-----w- c:\program files\Warcraft III
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2004-08-17 13:49 . 2004-08-17 13:49 161513 --sha-r- c:\windows\system32\uqtmsd.dll
.

------- Sigcheck -------

[-] 2004-08-17 13:49 . !HASH: COULD NOT OPEN FILE !!!!! . 14848 . . [------] . . c:\windows\system32\lsass.exe

[-] 2004-08-17 13:49 . !HASH: COULD NOT OPEN FILE !!!!! . 110592 . . [------] . . c:\windows\system32\services.exe


[-] 2004-08-17 13:49 . !HASH: COULD NOT OPEN FILE !!!!! . 506368 . . [------] . . c:\windows\system32\winlogon.exe

[-] 2004-08-17 13:49 . !HASH: COULD NOT OPEN FILE !!!!! . 17408 . . [------] . . c:\windows\system32\svchost.exe

[-] 2004-08-17 13:49 . !HASH: COULD NOT OPEN FILE !!!!! . 1035264 . . [------] . . c:\windows\explorer.exe

c:\windows\system32\spoolsv.exe ... chybí !!
.
((((((((((((((((((((((((((((( SnapShot@2009-10-24_11.48.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-24 14:38 . 2009-10-24 14:38 16384 c:\windows\temp\Perflib_Perfdata_6dc.dat
+ 2009-10-24 14:38 . 2009-10-24 14:38 16384 c:\windows\temp\Perflib_Perfdata_488.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-17 2289664]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-17 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-09 198160]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"razer"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-10-08 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"snpstd3"="c:\windows\vsnpstd3.exe" [2004-07-30 286720]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-04-10 16861184]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-02-25 1626112]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\j \Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-5-17 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
Rychl‚ spuçtŘnˇ aplikace HP Image Zone.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-29 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\já\\Plocha\\Já\\qipinfium9000\\infium.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\EverStep\\Program\\EverStep.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Documents and Settings\\já\\ocuf.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15.12.2008 20:41 33808]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [23.10.2009 22:44 114768]
R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [16.4.2009 21:05 2996]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23.10.2009 22:44 20560]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13.5.2009 17:46 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16.5.2009 20:59 19472]
R3 Razerlow;Razer Copperhead Driver;c:\windows\system32\drivers\Razerlow.sys [21.8.2009 15:45 19020]
R3 xTouch;xTouch;c:\windows\system32\drivers\xTouch.sys [28.7.2009 10:38 67968]
S2 gupdate1ca0b59fbbe09ff;Služba Google Update (gupdate1ca0b59fbbe09ff);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 EGXFilter;EGXFilter;c:\windows\system32\drivers\EGXFilter.sys [28.7.2009 10:38 80896]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
.
------- Doplňkový sken -------
.
uInternet Connection Wizard,ShellNext = iexplore
TCP: {5A05FD30-C819-4DCF-AAE7-D6342936C338} = 192.168.124.1
FF - ProfilePath - c:\documents and settings\já\Data aplikací\Mozilla\Firefox\Profiles\0fpnruwx.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: browser.startup.homepage - hxxp://cs.start2.mozilla.com/firefox?cl ... s:official
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redi ... searchfor=
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-24 16:39
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{21627ef5-5dc7-47a2-9392-427ba2634d93}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b3
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):09,36,02,17,49,ad,c4,6e,11,e1,1b,0b,57,6f,b5,67,0e,74,08,fe,d9,
7d,05,08,32,a8,e9,f3,8d,54,37,06,03,83,80,05,32,e5,94,96,00,00,00,00,00,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Protexis\License Service\PSIService.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\combofix\CF10514.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Razer\Copperhead\razertra.exe
c:\program files\Razer\Copperhead\razerofa.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\IVT Corporation\BlueSoleil\BlueSoleil_.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Celkový čas: 2009-10-24 16:43 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-10-24 14:43
ComboFix2.txt 2009-10-24 11:49

Před spuštěním: Volných bajtů: 208 931 627 008
Po spuštění: Volných bajtů: 208 829 394 944

- - End Of File - - E696672732C6EBCAA440204CD677D7A9

hadic
Level 1.5
Level 1.5
Příspěvky: 113
Registrován: březen 07
Bydliště: Ústí nad Orlicí
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod hadic » 24 říj 2009 17:15

OLT.txt
OTL logfile created on: 24.10.2009 17:04:03 - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\já\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,94 Gb Total Physical Memory | 1,34 Gb Available Physical Memory | 69,17% Memory free
3,78 Gb Paging File | 3,32 Gb Available in Paging File | 87,88% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 194,51 Gb Free Space | 83,52% Space Free | Partition Type: NTFS
Drive D: | 1,38 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded

Computer Name: FILIP
Current User Name: já
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\já\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe (IVT Corporation.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe (Kaspersky Lab)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Razer\Copperhead\razerhid.exe ()
PRC - C:\Program Files\Razer\Copperhead\razerofa.exe (Razer Inc.)
PRC - C:\Program Files\Razer\Copperhead\razertra.exe ()
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\System32\lsass.exe ()
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\System32\services.exe ()
PRC - C:\WINDOWS\System32\svchost.exe ()
PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\winlogon.exe ()
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (AVP [Auto | Running]) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Eventlog [Auto | Running]) -- C:\WINDOWS\System32\services.exe ()
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1ca0b59fbbe09ff [Auto | Stopped]) -- File not found
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LightScribeService [Auto | Running]) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (Netlogon [On_Demand | Stopped]) -- C:\WINDOWS\System32\lsass.exe ()
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NtLmSsp [On_Demand | Stopped]) -- C:\WINDOWS\System32\lsass.exe ()
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PlugPlay [Auto | Running]) -- C:\WINDOWS\System32\services.exe ()
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (PolicyAgent [Auto | Running]) -- C:\WINDOWS\System32\lsass.exe ()
SRV - (ProtectedStorage [Auto | Running]) -- C:\WINDOWS\System32\lsass.exe ()
SRV - (ProtexisLicensing [Auto | Start_Pending]) -- C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
SRV - (SamSs [Auto | Running]) -- C:\WINDOWS\System32\lsass.exe ()
SRV - (Spooler [Auto | Stopped]) -- File not found
SRV - (StarWindServiceAE [Auto | Running]) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) -- C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (aswFsBlk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (BlueletAudio [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\blueletaudio.sys (IVT Corporation.)
DRV - (BlueletSCOAudio [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\btnetdrv.sys (IVT Corporation.)
DRV - (Btcsrusb [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\btcusb.sys (IVT Corporation.)
DRV - (BTHidEnum [Boot | Running]) -- C:\WINDOWS\System32\Drivers\vbtenum.sys (IVT Corporation.)
DRV - (BTHidMgr [Boot | Running]) -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (catchme [On_Demand | Running]) -- File not found
DRV - (EGXFilter [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\egxfilter.sys ()
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows (R) Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (hwinterface [System | Running]) -- C:\WINDOWS\System32\Drivers\hwinterface.sys (Buzz)
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (kl1 [Boot | Running]) -- C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab)
DRV - (klbg [Boot | Running]) -- C:\WINDOWS\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (KLIF [System | Running]) -- C:\WINDOWS\System32\DRIVERS\klif.sys (Kaspersky Lab)
DRV - (klim5 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\klim5.sys (Kaspersky Lab)
DRV - (klmouflt [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\klmouflt.sys (Kaspersky Lab)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvgts [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvsmu [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nvsmu.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Razerlow [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\Razerlow.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (ROOTMODEM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys ()
DRV - (SNPSTD3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\snpstd3.sys ()
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (VComm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\VComm.sys (IVT Corporation.)
DRV - (VcommMgr [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\VcommMgr.sys (IVT Corporation.)
DRV - (xTouch [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\xtouch.sys ()

========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\já\Plocha\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\shdocvw.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "MyWebSearch"
FF - prefs.js..browser.startup.homepage: "http://cs.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official"
FF - prefs.js..extensions.enabledItems: check4change-owner@mozdev.org:1.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.463
FF - prefs.js..extensions.enabledItems: dave2x@download:0.5.9
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=GRfox000&fl=0&ptb=vIrGd.dBMUw.AAuSnkCecA&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor="

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009.03.31 15:25:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009.04.09 22:32:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.09.17 15:37:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009.10.05 20:39:58 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2009.03.24 20:35:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\mozilla\Extensions
[2009.03.24 20:35:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.10.22 15:38:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\mozilla\Firefox\Profiles\0fpnruwx.default\extensions
[2009.04.27 09:10:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\mozilla\Firefox\Profiles\0fpnruwx.default\extensions\dave2x@download
[2009.04.03 23:48:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\mozilla\Firefox\Profiles\0fpnruwx.default\extensions\check4change-owner@mozdev.org
[2009.10.05 19:20:14 | 00,009,941 | ---- | M] () -- C:\Documents and Settings\já\Data aplikací\Mozilla\FireFox\Profiles\0fpnruwx.default\searchplugins\mywebsearch.xml
[2009.10.22 15:38:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009.09.13 20:30:26 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009.03.31 15:26:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009.09.22 14:34:27 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\linkfilter@kaspersky.ru
[2009.09.13 20:30:22 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009.09.13 20:30:22 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009.02.24 21:34:32 | 01,044,480 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\libdivx.dll
[2009.03.31 15:25:56 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009.02.24 21:34:14 | 01,337,648 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2009.02.24 21:34:22 | 00,098,304 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009.04.05 22:34:08 | 00,072,960 | ---- | M] (Foxit Software Company) -- C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2009.09.13 20:30:22 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009.02.24 21:34:32 | 00,200,704 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
[2008.04.16 06:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008.03.31 21:06:24 | 00,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2008.03.31 21:06:24 | 00,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2008.01.27 11:57:20 | 00,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2008.01.27 11:57:20 | 00,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2008.03.31 21:06:24 | 00,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\ShellBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Odkazy) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [avp] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe ()
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Rychlé spuštění aplikace HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\já\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\System32\klogon.dll (Kaspersky Lab)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Společnost Microsoft)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Proces mezipaměti kategorií součástí - C:\WINDOWS\System32\browseui.dll (Společnost Microsoft)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.24 19:55:03 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[18 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009.10.06 11:14:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Microsoft Games
[2009.10.08 18:28:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Skype
[2009.10.08 18:50:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\webcamXP 5
[2009.10.06 11:14:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\já\Data aplikací\Microsoft Games
[2009.10.08 18:36:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\já\Data aplikací\skypePM
[2009.10.10 11:39:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\já\Data aplikací\VoipCheapCom
[2009.10.12 21:53:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\já\Local Settings\Data aplikací\Deployment
[2009.10.08 17:53:18 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\snpstd3
[2009.10.23 22:44:03 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009.10.08 18:02:08 | 00,000,000 | ---D | C] -- C:\Program Files\Biromsoft
[2009.09.25 15:44:52 | 00,000,000 | ---D | C] -- C:\Program Files\HomeKeylogger
[2009.10.21 15:08:52 | 00,000,000 | ---D | C] -- C:\Program Files\IVT Corporation
[2009.10.11 22:54:29 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2009.10.11 23:11:28 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009.10.11 23:08:46 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009.10.23 20:57:14 | 00,000,000 | ---D | C] -- C:\Program Files\USB Vibration
[2009.10.24 17:02:01 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\já\Plocha\OTL.exe
[2009.10.24 16:36:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009.10.24 16:34:17 | 00,000,000 | ---D | C] -- C:\ComboFix
[2009.10.24 13:45:43 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009.10.24 13:43:28 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009.10.24 13:43:28 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009.10.24 13:43:28 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009.10.24 13:43:28 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009.10.24 13:43:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009.10.24 13:43:03 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009.10.24 10:18:11 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009.10.24 09:59:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\já\Plocha\backups
[2009.10.23 22:44:16 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009.10.23 22:44:16 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009.10.23 22:44:16 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009.10.23 22:44:16 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009.10.23 22:44:15 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009.10.23 22:44:15 | 00,094,160 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009.10.23 22:44:15 | 00,093,392 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009.10.23 22:44:15 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009.10.23 22:44:04 | 01,279,456 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009.10.23 20:57:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\USB Vibration
[2009.10.20 22:38:23 | 00,000,000 | ---D | C] -- C:\ZAV_DOMA
[2009.10.12 22:01:39 | 24,274,3296 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\dotnetfx35.exe
[2009.10.12 21:53:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\já\Plocha\multi-poster
[2009.10.11 23:11:58 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\cs-CZ
[2009.10.11 23:09:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009.10.11 23:09:08 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2009.10.11 23:08:32 | 00,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2009.10.11 22:56:12 | 02,945,816 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\dotnetfx3setup.exe
[2009.10.11 22:54:16 | 00,000,000 | R--D | C] -- C:\MSOCache
[2009.10.11 22:51:18 | 02,869,264 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\dotNetFx35setup.exe
[2009.10.11 22:50:44 | 12,307,656 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\wdviewer.exe
[2009.10.10 16:59:00 | 00,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kswdmcap.ax
[2009.10.10 16:59:00 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kstvtune.ax
[2009.10.10 16:59:00 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\vfwwdm32.dll
[2009.10.10 16:59:00 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\vidcap.ax
[2009.10.10 16:58:59 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ksxbar.ax
[2009.10.08 18:04:54 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSTEE.sys
[2009.10.08 18:04:54 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstee.sys
[2009.10.08 18:04:48 | 00,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\NdisIP.sys
[2009.10.08 18:04:48 | 00,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndisip.sys
[2009.10.08 18:04:47 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsink.ax
[2009.10.08 18:04:47 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsink.ax
[2009.10.08 18:04:47 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\StreamIP.sys
[2009.10.08 18:04:47 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\streamip.sys
[2009.10.08 18:04:44 | 00,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\SLIP.sys
[2009.10.08 18:04:44 | 00,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\slip.sys
[2009.10.08 18:04:41 | 00,019,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WSTCODEC.SYS
[2009.10.08 18:04:41 | 00,019,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wstcodec.sys
[2009.10.08 18:04:38 | 00,085,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\NABTSFEC.sys
[2009.10.08 18:04:38 | 00,085,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nabtsfec.sys
[2009.10.08 18:04:36 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\CCDECODE.sys
[2009.10.08 18:04:36 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ccdecode.sys
[2009.10.08 18:04:17 | 00,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kswdmcap.ax
[2009.10.08 18:04:17 | 00,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kswdmcap.ax
[2009.10.08 18:04:17 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax
[2009.10.08 18:04:17 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vidcap.ax
[2009.10.08 18:04:16 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kstvtune.ax
[2009.10.08 18:04:16 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kstvtune.ax
[2009.10.08 18:04:16 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll
[2009.10.08 18:04:16 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2009.10.08 18:04:16 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksxbar.ax
[2009.10.08 18:04:16 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksxbar.ax
[2009.10.08 17:53:35 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\amcap.exe
[2009.10.08 17:52:13 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2009.10.08 17:52:05 | 00,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2009.10.08 17:52:04 | 00,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2009.10.08 17:52:02 | 00,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\dsnpstd3.ax
[2009.10.08 17:49:30 | 00,091,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\kswdmcap.ax
[2009.10.08 17:49:30 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\kstvtune.ax
[2009.10.08 17:49:30 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\vidcap.ax
[2009.10.08 17:49:29 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\vfwwdm32.dll
[2009.10.08 17:49:28 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\ksxbar.ax
[2009.10.08 11:30:40 | 00,360,448 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvudisp.exe
[2009.10.08 11:30:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview
[2009.10.08 11:29:28 | 00,360,448 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvraiins.dll
[2009.10.08 11:29:28 | 00,360,448 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvraidco.dll
[2009.10.08 11:29:13 | 00,199,168 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\fdco1.dll
[2009.10.08 11:29:12 | 00,054,016 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\NVENETFD.sys
[2009.10.08 11:29:00 | 00,442,368 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvunrm.exe
[2009.10.08 11:28:58 | 00,035,840 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvconrm.dll
[2009.10.08 11:28:58 | 00,009,216 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\bdco1.dll
[2009.10.08 11:28:57 | 00,950,272 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nvnrm.sys
[2009.10.08 11:28:56 | 00,022,016 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nvnetbus.sys
[2009.10.08 11:28:48 | 00,442,368 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvusmu.exe
[2009.10.08 11:28:48 | 00,035,840 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\NVCOSMU.DLL
[2009.10.08 11:28:48 | 00,014,336 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nvsmu.sys
[2009.10.08 11:28:46 | 00,442,368 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvusmb.exe
[2009.10.08 11:28:35 | 00,442,368 | R--- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\NVUNINST.EXE
[2009.10.07 16:05:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt

========== Files - Modified Within 30 Days ==========

[18 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009.10.24 17:02:02 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\já\Plocha\OTL.exe
[2009.10.24 16:39:37 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009.10.24 16:39:08 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009.10.24 16:38:43 | 00,604,140 | ---- | M] () -- C:\WINDOWS\System32\drivers\ISwift3.dat
[2009.10.24 16:38:05 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009.10.24 16:38:01 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009.10.24 13:45:45 | 00,000,293 | RHS- | M] () -- C:\boot.ini
[2009.10.24 13:42:13 | 03,352,189 | R--- | M] () -- C:\Documents and Settings\já\Plocha\ComboFix.exe
[2009.10.24 13:32:03 | 00,014,442 | ---- | M] () -- C:\Documents and Settings\já\Plocha\uninstall.JPG
[2009.10.24 13:25:30 | 00,002,415 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Run Audiosurf.lnk
[2009.10.23 22:44:16 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\avast! Antivirus.lnk
[2009.10.23 22:44:15 | 00,002,553 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009.10.23 22:19:02 | 00,106,203 | ---- | M] () -- C:\Documents and Settings\já\Plocha\cbp.JPG
[2009.10.23 21:49:20 | 37,624,016 | ---- | M] () -- C:\Documents and Settings\já\Plocha\setupcze.exe
[2009.10.23 16:52:21 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009.10.21 15:25:50 | 00,001,886 | ---- | M] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BlueSoleil.lnk
[2009.10.21 15:25:50 | 00,001,874 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\BlueSoleil.lnk
[2009.10.21 15:25:50 | 00,000,032 | ---- | M] () -- C:\WINDOWS\0
[2009.10.20 22:38:24 | 00,000,491 | ---- | M] () -- C:\Documents and Settings\já\Plocha\Výuka ZAV.lnk
[2009.10.18 21:37:07 | 00,009,062 | ---- | M] () -- C:\Documents and Settings\já\Plocha\lr.JPG
[2009.10.18 15:39:25 | 00,015,360 | ---- | M] () -- C:\Documents and Settings\já\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.10.18 01:33:38 | 02,112,528 | -H-- | M] () -- C:\Documents and Settings\já\Local Settings\Data aplikací\IconCache.db
[2009.10.15 17:59:16 | 00,849,410 | ---- | M] () -- C:\Documents and Settings\já\Plocha\Gaming Consoles Wholesale List 23231.zip
[2009.10.15 17:59:11 | 00,008,848 | ---- | M] () -- C:\Documents and Settings\já\Plocha\Plasma TV Wholesale List 334356.zip
[2009.10.15 17:14:44 | 00,168,454 | ---- | M] () -- C:\Documents and Settings\já\Plocha\Car stereo Wholesale List 151321.zip
[2009.10.14 19:56:01 | 00,108,059 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat
[2009.10.14 19:56:01 | 00,095,259 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat
[2009.10.12 22:44:42 | 02,514,241 | ---- | M] () -- C:\Documents and Settings\já\Plocha\barenaked_ladies_-_big_bang_theory_theme.mp3
[2009.10.12 22:37:52 | 24,274,3296 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\dotnetfx35.exe
[2009.10.12 21:52:32 | 00,208,377 | ---- | M] () -- C:\Documents and Settings\já\Plocha\multi-poster.rar
[2009.10.12 18:48:08 | 02,424,788 | ---- | M] () -- C:\Documents and Settings\já\Plocha\Extreme Warez Multi-Poster_1_3_2_0.rar
[2009.10.12 07:45:01 | 00,212,880 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009.10.11 23:13:19 | 00,046,864 | ---- | M] () -- C:\Documents and Settings\já\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2009.10.11 23:11:46 | 01,002,572 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009.10.11 23:11:46 | 00,427,592 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009.10.11 23:11:46 | 00,424,082 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2009.10.11 23:11:46 | 00,076,516 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2009.10.11 23:11:46 | 00,066,376 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009.10.11 23:11:24 | 05,457,810 | ---- | M] () -- C:\Documents and Settings\já\Plocha\Extreme_Warez_Multi-Poster.rar
[2009.10.11 23:06:06 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009.10.11 22:56:33 | 02,945,816 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\dotnetfx3setup.exe
[2009.10.11 22:52:52 | 12,307,656 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\wdviewer.exe
[2009.10.11 22:52:03 | 02,869,264 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\já\Plocha\dotNetFx35setup.exe
[2009.10.11 08:10:09 | 00,236,544 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009.10.09 14:10:32 | 00,140,694 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009.10.08 21:59:22 | 40,994,964 | ---- | M] () -- C:\Documents and Settings\já\Plocha\white_crosses.rar
[2009.10.08 21:57:12 | 41,225,750 | ---- | M] () -- C:\Documents and Settings\já\Plocha\vico.rar
[2009.10.08 18:51:28 | 00,000,995 | ---- | M] () -- C:\WINDOWS\win.ini
[2009.10.08 17:32:10 | 00,000,596 | ---- | M] () -- C:\Documents and Settings\já\Plocha\Zástupce - ZAV.exe.lnk
[2009.10.08 11:29:41 | 00,000,223 | ---- | M] () -- C:\Boot.bak

========== Files - No Company Name ==========
[2009.10.24 16:38:43 | 00,604,140 | ---- | C] () -- C:\WINDOWS\System32\drivers\ISwift3.dat
[2009.10.24 13:45:45 | 00,000,223 | ---- | C] () -- C:\Boot.bak
[2009.10.24 13:45:43 | 00,261,312 | ---- | C] () -- C:\cmldr
[2009.10.24 13:43:28 | 00,236,544 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009.10.24 13:43:28 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009.10.24 13:43:28 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009.10.24 13:43:28 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009.10.24 13:42:13 | 03,352,189 | R--- | C] () -- C:\Documents and Settings\já\Plocha\ComboFix.exe
[2009.10.24 13:32:03 | 00,014,442 | ---- | C] () -- C:\Documents and Settings\já\Plocha\uninstall.JPG
[2009.10.23 22:44:16 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\avast! Antivirus.lnk
[2009.10.23 22:44:04 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009.10.23 22:19:02 | 00,106,203 | ---- | C] () -- C:\Documents and Settings\já\Plocha\cbp.JPG
[2009.10.23 21:43:59 | 37,624,016 | ---- | C] () -- C:\Documents and Settings\já\Plocha\setupcze.exe
[2009.10.21 15:25:50 | 00,001,886 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\BlueSoleil.lnk
[2009.10.21 15:25:50 | 00,001,874 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\BlueSoleil.lnk
[2009.10.20 22:38:24 | 00,000,491 | ---- | C] () -- C:\Documents and Settings\já\Plocha\Výuka ZAV.lnk
[2009.10.18 21:37:07 | 00,009,062 | ---- | C] () -- C:\Documents and Settings\já\Plocha\lr.JPG
[2009.10.15 17:59:13 | 00,849,410 | ---- | C] () -- C:\Documents and Settings\já\Plocha\Gaming Consoles Wholesale List 23231.zip
[2009.10.15 17:59:10 | 00,008,848 | ---- | C] () -- C:\Documents and Settings\já\Plocha\Plasma TV Wholesale List 334356.zip
[2009.10.15 17:14:43 | 00,168,454 | ---- | C] () -- C:\Documents and Settings\já\Plocha\Car stereo Wholesale List 151321.zip
[2009.10.12 22:44:24 | 02,514,241 | ---- | C] () -- C:\Documents and Settings\já\Plocha\barenaked_ladies_-_big_bang_theory_theme.mp3
[2009.10.12 21:52:32 | 00,208,377 | ---- | C] () -- C:\Documents and Settings\já\Plocha\multi-poster.rar
[2009.10.12 18:44:55 | 02,424,788 | ---- | C] () -- C:\Documents and Settings\já\Plocha\Extreme Warez Multi-Poster_1_3_2_0.rar
[2009.10.11 23:10:44 | 05,457,810 | ---- | C] () -- C:\Documents and Settings\já\Plocha\Extreme_Warez_Multi-Poster.rar
[2009.10.08 21:42:33 | 40,994,964 | ---- | C] () -- C:\Documents and Settings\já\Plocha\white_crosses.rar
[2009.10.08 21:39:37 | 41,225,750 | ---- | C] () -- C:\Documents and Settings\já\Plocha\vico.rar
[2009.10.08 17:53:22 | 00,286,720 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe
[2009.10.08 17:53:22 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\dsnpstd3.dll
[2009.10.08 17:53:18 | 00,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd3.exe
[2009.10.08 17:52:06 | 00,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2009.10.08 17:52:06 | 00,013,023 | ---- | C] () -- C:\WINDOWS\snpstd3.src
[2009.10.08 17:52:01 | 00,053,248 | R--- | C] () -- C:\WINDOWS\System\dsnpstd3.dll
[2009.10.08 17:51:59 | 00,413,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd3.sys
[2009.10.08 17:32:10 | 00,000,596 | ---- | C] () -- C:\Documents and Settings\já\Plocha\Zástupce - ZAV.exe.lnk
[2009.10.08 11:31:11 | 00,140,694 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml
[2009.10.08 11:30:40 | 00,017,525 | ---- | C] () -- C:\WINDOWS\System32\nvdisp.nvu
[2009.10.08 11:30:03 | 00,009,417 | R--- | C] () -- C:\WINDOWS\System32\nvide.nvu
[2009.10.08 11:29:00 | 00,005,836 | R--- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2009.10.08 11:28:48 | 00,000,682 | R--- | C] () -- C:\WINDOWS\System32\nvsmu.nvu
[2009.10.08 11:28:46 | 00,002,016 | R--- | C] () -- C:\WINDOWS\System32\nvsmb.nvu
[2009.10.01 21:27:24 | 04,652,688 | ---- | C] () -- C:\Documents and Settings\já\Plocha\dj disco.mp3
[2009.08.22 23:19:58 | 00,001,440 | ---- | C] () -- C:\WINDOWS\cvgvw16.ini
[2009.07.28 10:38:38 | 00,080,896 | ---- | C] () -- C:\WINDOWS\System32\drivers\EGXFilter.sys
[2009.07.28 10:38:38 | 00,070,144 | ---- | C] () -- C:\WINDOWS\System32\drivers\SerTouch.sys
[2009.07.28 10:38:38 | 00,067,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\xTouch.sys
[2009.07.21 23:43:52 | 00,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009.04.16 21:04:27 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\inpout32.dll
[2009.04.10 13:30:43 | 02,112,528 | -H-- | C] () -- C:\Documents and Settings\já\Local Settings\Data aplikací\IconCache.db
[2009.04.09 22:33:24 | 00,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009.04.07 16:11:59 | 00,015,360 | ---- | C] () -- C:\Documents and Settings\já\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.04.03 23:31:05 | 00,000,067 | ---- | C] () -- C:\WINDOWS\SpeederXP.INI
[2009.03.29 09:23:26 | 00,046,864 | ---- | C] () -- C:\Documents and Settings\já\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2009.03.29 09:23:11 | 00,000,122 | ---- | C] () -- C:\Documents and Settings\já\Local Settings\Data aplikací\fusioncache.dat
[2009.03.28 21:36:55 | 00,001,321 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2009.03.26 22:07:03 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009.03.25 03:43:35 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
[2009.03.24 20:24:57 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\já\Data aplikací\desktop.ini
[2008.02.25 06:29:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008.02.25 06:29:00 | 01,482,752 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008.02.25 06:29:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008.02.25 06:29:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008.02.25 06:29:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2004.08.17 15:49:10 | 00,174,080 | ---- | C] () -- C:\WINDOWS\System32\ms32clod.dll
[2004.08.17 15:49:10 | 00,161,513 | RHS- | C] () -- C:\WINDOWS\System32\uqtmsd.dll
[2004.08.17 15:49:10 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004.07.17 11:36:38 | 00,028,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001.10.25 13:00:00 | 00,000,995 | ---- | C] () -- C:\WINDOWS\win.ini
[2001.10.25 13:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

========== LOP Check ==========

[2009.10.08 18:50:10 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Data aplikací
[2009.10.10 16:57:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Bluetooth
[2009.05.28 18:26:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Corel
[2009.04.26 19:43:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2009.03.24 23:31:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LightScribe
[2009.10.08 20:12:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\webcamXP 5
[2009.10.10 18:57:47 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\já\Data aplikací
[2009.03.24 23:30:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Acoustica
[2009.04.29 06:51:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Ahead
[2009.07.28 22:56:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Broad Intelligence
[2009.04.30 18:42:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\BSplayer
[2009.04.29 21:03:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\BSplayer Pro
[2009.05.28 18:29:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Corel
[2009.08.24 08:23:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Crayon Physics Deluxe
[2009.10.08 10:56:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\DMCache
[2009.04.05 22:34:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Foxit
[2009.05.31 00:33:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\FVZilla
[2009.03.02 18:24:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\GARMIN
[2009.07.17 01:21:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Music Recognition
[2009.03.28 21:31:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\OpenOffice.org
[2009.04.06 20:03:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\SecondLife
[2009.07.28 22:25:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\TeamViewer
[2009.08.22 23:12:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\Thinstall
[2009.08.30 23:01:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\uTorrent
[2009.10.10 11:58:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\VoipCheapCom
[2009.04.09 22:22:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\já\Data aplikací\zbusoft
[2001.10.25 13:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009.10.24 16:38:05 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2009.10.22 17:00:41 | 03,325,052 | ---- | C] ()(C:\Documents and Settings\já\Plocha\??? - ?????.mp3) -- C:\Documents and Settings\já\Plocha\试音碟 - 英文的士高.mp3
[2009.09.18 11:34:02 | 03,325,052 | ---- | M] ()(C:\Documents and Settings\já\Plocha\??? - ?????.mp3) -- C:\Documents and Settings\já\Plocha\试音碟 - 英文的士高.mp3
< End of report >

hadic
Level 1.5
Level 1.5
Příspěvky: 113
Registrován: březen 07
Bydliště: Ústí nad Orlicí
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod hadic » 24 říj 2009 17:18

predchazejici log jsem "zkratil" o nenainstalovany disky (G, H, I) protoze log mel 60060 znaku :lol:
extras.txt

OTL Extras logfile created on: 24.10.2009 17:04:03 - Run 1
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\já\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,94 Gb Total Physical Memory | 1,34 Gb Available Physical Memory | 69,17% Memory free
3,78 Gb Paging File | 3,32 Gb Available in Paging File | 87,88% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 194,51 Gb Free Space | 83,52% Space Free | Partition Type: NTFS
Drive D: | 1,38 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FILIP
Current User Name: já
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L ()
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L ()
Drive [find] -- %SystemRoot%\Explorer.exe ()
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\já\Plocha\Já\qipinfium9000\infium.exe" = C:\Documents and Settings\já\Plocha\Já\qipinfium9000\infium.exe:*:Enabled:QIP Infium Beta -- (QIP)
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe" = C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application -- (TeamViewer GmbH)
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:*:Enabled:BlueSoleil -- (IVT Corporation.)
"C:\Program Files\Garena\Garena.exe" = C:\Program Files\Garena\Garena.exe:*:Enabled:Garena -- (Garena Interactive PTE LTD)
"C:\Program Files\EverStep\Program\EverStep.exe" = C:\Program Files\EverStep\Program\EverStep.exe:*:Enabled:EverStep -- (http://www.musicgames.com)
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment)
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil -- ()
"C:\Documents and Settings\já\ocuf.exe" = C:\Documents and Settings\já\ocuf.exe:*:Enabled:ENABLE -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BBDD6C0-ED6F-43C3-8A9C-84E3249A5615}" = Twin USB Vibration Gamepad
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2F71F2BA-B513-4113-969C-18A84D238E27}" = 1310
"{32A72502-BC2C-4C39-ACEA-BC3D463F0697}" = EN
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{438BB9B4-65FE-4626-91D9-A8F57B18001D}" = Bluesoleil2.6.0.8 Release 070517
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}" = FontNav
"{564D0000-547B-4ED8-8070-85286CC8C9BF}" = OpenOffice.org 3.0
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{63218538-4A69-497F-8455-904261B0E9E4}" = CorelDRAW Graphics Suite X3
"{6D316D67-DA52-4659-9C98-F479963534D6}" = Audiosurf
"{6EF72FC6-842E-4FE6-BF88-BFBF03C9DA74}" = Windows Workflow Foundation CS Language Pack
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7F947BFE-C2DF-4779-9909-5BEE746BD0C4}" = Microsoft .NET Framework 2.0 Language Pack - CSY
"{80413011-029C-4D6B-B3AD-725DDE60B81C}" = 1310Trb
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9DE9E293-5D7B-4312-88C2-BDFAEC5310AE}" = Microsoft .NET Framework 3.0
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAB6D0F8-02B3-4E89-B24C-0BB153C21445}" = Windows Presentation Foundation Language Pack (CSY)
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C0BE2E64-6D5F-45CD-A53E-D4C68EEC153C}" = TOPO 50 v4
"{C6A750AE-6029-4435-9A8D-06507AA46798}" =
"{C94E45B0-6AA6-4FB9-9AAE-22085F631880}" = VBA
"{CA567AD5-33A4-403D-86D1-EE2D38251951}_is1" = VDownloader 0.82
"{D6D5CFB3-7095-4073-B6B7-B7E909838C57}" = Razer Copperhead
"{D8979435-753B-40AE-9318-5E712C160A71}" = Windows Communication Foundation Language Pack - CSY
"{E21658D0-8C83-4ADD-937B-6ED07F335ABA}" = 1310Tour
"{E90BEB5B-CFA0-418E-9ABB-4C4A7B0D9483}" = 1310_Help
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC CAM-168
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}" = Update Manager
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FB09515C-8E3E-4E0F-A1F2-032F38DEC185}" = Microsoft .NET Framework 3.0 Czech Language Pack
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"µTorrent CZ_is1" = µTorrent CZ 1.8.4 (build 16150)
"Acoustica CD/DVD Label Maker" = Acoustica CD/DVD Label Maker
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast!" = avast! Antivirus
"BSPlayerf" = BS.Player FREE
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DzSoftPPSlideShowConv_is1" = PowerPoint Slide Show Converter 3.0
"FL Studio 8" = FL Studio 8
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader" = Foxit Reader
"Garena" = Garena
"Heroes of Might and Magic IV" = Heroes of Might and Magic® IV
"HijackThis" = HijackThis 2.0.2
"HomeKeyLogger" = Home Key Logger Free Edition v1.70 (remove only)
"HP Photo & Imaging" = HP Image Zone 4.2
"IL Download Manager" = IL Download Manager
"InstallWIX_{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 2.0 Language Pack - CSY" = Microsoft .NET Framework 2.0 Language Pack - CSY
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft .NET Framework 3.0 Czech Language Pack" = Microsoft .NET Framework 3.0 Czech Language Pack
"Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14)
"Nero - Burning Rom!UninstallKey" = Ahead Nero OEM
"NVIDIA Drivers" = NVIDIA Drivers
"ReadManiac_is1" = ReadManiac 2.5.1
"RealPlayer 6.0" = RealPlayer
"SpeederXP_is1" = SpeederXP v2.32
"TeamViewer 4" = TeamViewer 4
"TouchKit" = Touch Kit
"VMidi" = vanBasco's Karaoke Player
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"ZAV_DOMA_is1" = ZAV 4.48

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Balloons and Static Electricity" = Balloons and Static Electricity
"Electric Field Hockey - derived from work by Ruth Chabay" = Electric Field Hockey - derived from work by Ruth Chabay
"Generator" = Generator
"Magnets and Electromagnets" = Magnets and Electromagnets
"PhotoZoom Pro 3" = BenVista PhotoZoom Pro 3.0.2
"Simplified MRI" = Simplified MRI
"States of Matter" = States of Matter
"Travoltage" = Travoltage
"Warcraft III" = Warcraft III

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 24.10.2009 11:05:12 | Computer Name = FILIP | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of C:\WINDOWS\System32\uqtmsd.dll failed, 00000005.

[ Application Events ]
Error - 11.9.2009 14:33:46 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 12.9.2009 1:32:02 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 13.9.2009 3:48:12 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 13.9.2009 5:52:02 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 13.9.2009 13:02:55 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 14.9.2009 1:47:35 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 14.9.2009 10:25:50 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 14.9.2009 11:36:27 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 15.9.2009 1:12:38 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

Error - 15.9.2009 6:13:31 | Computer Name = FILIP | Source = Application Error | ID = 1000
Description = Chybující aplikace idman.exe, verze 5.17.5.0, chybující modul idman.exe,
verze 5.17.5.0, adresa chyby 0x002b4000.

[ System Events ]
Error - 24.10.2009 10:30:04 | Computer Name = FILIP | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby StiSvc
s argumenty za účelem spuštění serveru: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 24.10.2009 10:35:11 | Computer Name = FILIP | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
PEVSystemStart.

Error - 24.10.2009 10:36:57 | Computer Name = FILIP | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
PEVSystemStart.

Error - 24.10.2009 10:36:59 | Computer Name = FILIP | Source = PlugPlayManager | ID = 11
Description = Zařízení Root\LEGACY_GARENAPENGINE\0000 se již v systému nenachází,
přestože nebylo nejdříve připraveno k odebrání.

Error - 24.10.2009 10:37:00 | Computer Name = FILIP | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
PEVSystemStart.

Error - 24.10.2009 10:37:00 | Computer Name = FILIP | Source = PlugPlayManager | ID = 11
Description = Zařízení Root\LEGACY_IYWPVX\0000 se již v systému nenachází, přestože
nebylo nejdříve připraveno k odebrání.

Error - 24.10.2009 10:37:03 | Computer Name = FILIP | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 24.10.2009 10:38:41 | Computer Name = FILIP | Source = Service Control Manager | ID = 7000
Description = Služba Spooler neuspěla při spuštění v důsledku následující chyby:
%%2

Error - 24.10.2009 10:38:41 | Computer Name = FILIP | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate1ca0b59fbbe09ff) neuspěla při
spuštění v důsledku následující chyby: %%2

Error - 24.10.2009 10:38:41 | Computer Name = FILIP | Source = Service Control Manager | ID = 7000
Description = Služba Načítání obrázků (WIA) neuspěla při spuštění v důsledku následující
chyby: %%5


< End of report >

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod jaro3 » 25 říj 2009 00:13

No tohle je síla...

Stáhni si :Dr. Web CureIt
dej update , po aktualizaci dej start.
Tlacitky dole muzeš soubor léčit, smazat, přesunout nebo přejmenovat

Stáhni si Dial-a-fix
Klikni na kladívko-další možnosti:
SFC scan - Spustí nástroj pro kontrolu systémových souborů (případná potřeba instalačního media Windows).
Klikni na službu a pak na GO.

Poté znovu proveď Combofix....jdu spát.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

hadic
Level 1.5
Level 1.5
Příspěvky: 113
Registrován: březen 07
Bydliště: Ústí nad Orlicí
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod hadic » 25 říj 2009 15:27

sry ze jsem ted neodpovidal driv, nedostal jem se na PC. Ten Dr.web nasel 6 viru, vsechny vylecil (5 z nich byly systemovy soubory). Co se tyce Dial a fix tak tam ta moznost SFC scan neni...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Kontrola HJT: totalne zashitovanej PC

Příspěvekod jaro3 » 25 říj 2009 15:59

Je tam , v hlavním oknu klikni na Klikni na kladívko-další možnosti (viz výše).
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 7 hostů