Ahoj, žádný uninstaller jsem nenašel, nevím asi blbě hledám, ale prostě nic moc. Za chvíli dodám CF.
EDIT:Jestli by to bylo možné třeba přes ten CF, tak by bylo asi dobré odinstalovat oba 2, stejně to moc nepoužívám.
LOG z CF:
ComboFix 09-10-26.06 - Marek 27.10.2009 18:24.22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.608 [GMT 1:00]
Spuštěný z: c:\documents and settings\Marek\Plocha\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-09-27 do 2009-10-27 )))))))))))))))))))))))))))))))
.
2009-10-26 15:01 . 2009-10-26 15:01 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-10-26 15:01 . 2009-10-26 15:01 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-25 17:47 . 2009-10-26 15:10 -------- d-----w- c:\program files\Alwil Software
2009-10-25 16:49 . 2009-10-25 16:49 -------- dcsh--w- c:\documents and settings\Administrator\IETldCache
2009-10-25 15:36 . 2009-10-25 15:36 -------- d---a-w- c:\windows\rundll16.exe
2009-10-25 15:36 . 2009-10-25 15:36 -------- d---a-w- c:\windows\logo1_.exe
2009-10-25 14:37 . 2009-10-25 14:37 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2009-10-25 14:25 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-25 13:32 . 2009-10-25 13:32 -------- d-----w- c:\program files\AskBardis
2009-10-25 13:24 . 2009-10-25 13:24 -------- dc----w- C:\_OTM
2009-10-25 12:45 . 2009-10-25 12:46 -------- dc----w- C:\rsit
2009-10-24 06:56 . 2009-10-24 06:56 -------- d---a-w- c:\windows\system32\runouce.exe
2009-10-24 06:55 . 2009-10-24 06:55 632064 ----a-w- c:\windows\system32\msvcr80.dll
2009-10-24 06:55 . 2009-10-24 06:55 554240 ----a-w- c:\windows\system32\msvcp80.dll
2009-10-24 06:55 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2009-10-24 06:55 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2009-10-24 06:55 . 2009-10-24 06:55 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-10-23 18:09 . 2009-10-23 18:09 -------- dc----w- C:\Sun
2009-10-23 17:36 . 2009-10-23 18:07 -------- d-----w- c:\documents and settings\Marek\.SunDownloadManager
2009-10-20 18:53 . 2009-10-20 18:53 -------- dc----w- c:\documents and settings\MaxDamage - uživatel
2009-10-20 14:53 . 2009-10-20 14:53 -------- d--h--w- c:\windows\PIF
2009-10-19 17:20 . 2009-10-25 16:13 -------- d-----w- c:\program files\HTV
2009-10-18 19:00 . 2009-10-20 18:53 -------- d-----w- c:\program files\COMODO
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\VDLL.DLL
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\RUNDL132.EXE
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\logo_1.exe
2009-10-18 07:33 . 2009-10-18 07:33 28672 ----a-w- c:\windows\system32\eEmpty.exe
2009-10-17 18:54 . 2009-10-17 18:54 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-10-17 18:54 . 2009-10-17 18:54 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-10-17 18:54 . 2009-10-17 18:54 -------- d-----w- c:\program files\Prevx
2009-10-17 17:22 . 2009-10-17 17:22 -------- d-----w- c:\program files\Conduit
2009-10-17 17:22 . 2009-10-17 19:28 -------- d-----w- c:\program files\free-downloads.net
2009-10-11 17:11 . 2009-10-11 17:11 -------- d-----w- c:\program files\Opera
2009-10-11 16:39 . 2001-08-17 20:07 101888 -c--a-w- c:\windows\system32\dllcache\adpu160m.sys
2009-10-11 16:39 . 2004-08-03 20:32 10880 -c--a-w- c:\windows\system32\dllcache\admjoy.sys
2009-10-11 16:39 . 2001-08-17 18:11 46112 -c--a-w- c:\windows\system32\dllcache\adptsf50.sys
2009-10-11 16:39 . 2001-08-17 18:19 747392 -c--a-w- c:\windows\system32\dllcache\adm8830.sys
2009-10-11 16:39 . 2001-08-17 18:19 553984 -c--a-w- c:\windows\system32\dllcache\adm8820.sys
2009-10-11 16:39 . 2001-08-17 18:19 584448 -c--a-w- c:\windows\system32\dllcache\adm8810.sys
2009-10-11 16:37 . 2001-10-24 10:24 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-10-10 16:29 . 2009-10-10 16:29 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-10 11:03 . 2009-10-10 11:04 -------- dc----w- C:\iPod Photo Cache
2009-10-05 17:22 . 2009-10-05 17:22 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-10-05 17:21 . 2009-10-12 13:47 -------- d-----w- c:\windows\Internet Logs
2009-10-05 17:11 . 2009-10-10 16:14 -------- d-----w- c:\program files\JockerSoft
2009-10-05 15:14 . 2009-10-05 15:29 -------- d-----w- c:\program files\Vuze
2009-10-05 15:04 . 2009-10-10 16:13 -------- d-----w- c:\program files\BitLord
2009-10-04 17:50 . 2009-10-04 17:50 -------- d-----w- c:\program files\wxDownload Fast
2009-10-04 17:33 . 2009-10-04 17:33 -------- dc----w- C:\Downloads
2009-10-04 16:15 . 2009-10-11 13:26 -------- d-----w- c:\program files\Star Downloader
2009-10-02 15:51 . 2009-10-02 15:51 -------- d-----w- c:\program files\Avanquest update
2009-10-02 09:33 . 2009-10-02 09:33 -------- d-----w- c:\program files\Total Video Converter
2009-10-02 05:37 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-10-01 10:53 . 2009-10-19 16:44 -------- d-----w- c:\program files\IObit
2009-10-01 10:52 . 2009-10-01 10:52 65928 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-30 11:59 . 2009-09-30 11:59 -------- d-----w- c:\program files\iPod
2009-09-30 11:58 . 2009-09-30 12:02 -------- d-----w- c:\program files\iTunes
2009-09-30 11:24 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-30 11:24 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-30 06:41 . 2009-09-30 06:41 -------- d-----w- c:\program files\QuickTime
2009-09-30 06:40 . 2009-09-30 06:40 -------- d-----w- c:\program files\Apple Software Update
2009-09-30 06:39 . 2009-08-28 17:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-09-30 06:39 . 2009-08-28 17:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-09-30 06:39 . 2009-09-30 11:59 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-26 18:05 . 2009-07-30 11:56 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-26 16:14 . 2009-09-19 09:33 -------- d-----w- c:\program files\ESET
2009-10-25 11:53 . 2008-06-02 12:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-25 11:27 . 2009-08-04 11:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-25 10:41 . 2004-08-18 12:00 90996 ----a-w- c:\windows\system32\perfc005.dat
2009-10-25 10:41 . 2004-08-18 12:00 457400 ----a-w- c:\windows\system32\perfh005.dat
2009-10-24 13:40 . 2009-07-28 13:57 -------- d-----w- c:\program files\VS Revo Group
2009-10-23 17:25 . 2006-09-09 18:51 -------- d-----w- c:\program files\Java
2009-10-21 17:29 . 2006-07-10 07:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-18 10:48 . 2006-12-16 12:12 -------- d-----w- c:\program files\EA SPORTS
2009-10-04 17:40 . 2009-09-01 16:33 -------- d-----w- c:\program files\Bonjour
2009-10-02 15:51 . 2006-07-04 06:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-02 09:02 . 2006-08-25 09:21 -------- d-----w- c:\program files\Sony Ericsson
2009-10-01 11:27 . 2006-09-10 10:19 -------- d-----w- c:\program files\VDMSound
2009-10-01 11:21 . 2006-11-08 13:23 -------- d-----w- c:\program files\Nvu
2009-10-01 11:21 . 2009-07-28 08:44 -------- d-----w- c:\program files\Trend Micro
2009-10-01 11:21 . 2009-06-13 15:47 -------- d-----w- c:\program files\World of Warcraft
2009-10-01 11:21 . 2009-05-06 17:54 -------- d-----w- c:\program files\Stykz
2009-10-01 11:21 . 2009-05-06 16:03 -------- d-----w- c:\program files\VirtualDJ
2009-10-01 11:21 . 2008-02-03 17:51 -------- d-----w- c:\program files\Toribash-3.1
2009-10-01 11:21 . 2007-06-19 17:21 -------- d-----w- c:\program files\RADVideo
2009-10-01 11:21 . 2007-01-09 19:27 -------- d-----w- c:\program files\Video DVD Maker FREE
2009-10-01 11:21 . 2006-12-31 18:52 -------- d-----w- c:\program files\Teamspeak2_RC2
2009-09-26 19:18 . 2009-09-26 19:18 4484 ----a-w- c:\windows\system32\drivers\cpuidlep.sys
2009-09-25 12:11 . 2009-09-25 12:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-23 14:02 . 2009-09-23 14:02 -------- d-----w- c:\program files\Warp
2009-09-19 15:31 . 2009-09-19 15:30 -------- d-----w- c:\program files\Security Task Manager
2009-09-18 17:23 . 2009-09-18 17:23 12 ----a-w- c:\documents and settings\Marek\USERDATA.DAT
2009-09-12 16:03 . 2009-09-12 15:56 -------- d-----w- c:\program files\ICQ6.5
2009-09-12 15:57 . 2008-05-29 15:58 -------- d-----w- c:\program files\ICQ6
2009-09-11 14:19 . 2004-08-18 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 12:54 . 2009-09-25 12:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-09-25 12:11 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:05 . 2004-08-18 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-02 09:26 . 2008-11-06 15:38 -------- d-----w- c:\program files\NextUp Talker
2009-09-01 16:43 . 2009-09-01 16:41 -------- d-----w- c:\program files\Common Files\Jasc Software Inc
2009-09-01 16:41 . 2009-09-01 16:40 -------- d-----w- c:\program files\Jasc Software Inc
2009-09-01 16:05 . 2009-09-01 16:05 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-09-01 14:34 . 2009-09-01 14:34 160285 ----a-w- c:\windows\Sqirlz Morph Uninstaller.exe
2009-09-01 14:34 . 2009-09-01 14:34 -------- d-----w- c:\program files\Sqirlz Morph
2009-08-31 13:54 . 2009-04-13 16:45 -------- d-----w- c:\program files\Free Power Word to Pdf Converter
2009-08-31 13:54 . 2009-04-13 16:34 -------- d-----w- c:\program files\Free PDF to Word Doc Converter
2009-08-31 13:39 . 2006-08-25 09:21 -------- d-----w- c:\program files\Common Files\Teleca Shared
2009-08-31 13:37 . 2008-11-05 19:11 -------- d-----w- c:\program files\Text to Speech Maker
2009-08-31 13:23 . 2009-06-30 11:44 -------- d-----w- c:\program files\MumboJumbo
2009-08-31 13:23 . 2009-02-24 13:08 -------- d-----w- c:\program files\Wanadoo Edition
2009-08-31 13:13 . 2009-08-03 15:13 -------- d-----w- c:\program files\Actual Drawing
2009-08-31 13:13 . 2009-05-06 16:55 -------- d-----w- c:\program files\Acoustica Mixcraft
2009-08-29 07:58 . 2004-08-18 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:02 . 2004-08-18 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 17:24 . 2006-07-03 14:57 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2006-07-03 14:57 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2006-07-04 06:38 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2006-07-03 14:57 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2006-07-03 14:57 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2004-08-18 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2006-07-03 14:57 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2008-06-01 13:30 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 17:23 . 2006-07-03 14:57 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-18 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 20:59 . 2004-08-18 12:00 2191360 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 17:29 . 2004-08-17 15:45 2068224 ------w- c:\windows\system32\ntkrnlpa.exe
2004-08-23 21:38 . 2004-08-23 21:38 3371 ----a-w- c:\program files\!!!readme.txt
2004-08-23 19:08 . 2004-08-23 19:08 83968 -c--a-w- c:\program files\NB_NB_2_12_37.xls
.
((((((((((((((((((((((((((((( SnapShot@2009-10-25_17.38.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-27 16:55 . 2009-10-27 16:55 16384 c:\windows\temp\Perflib_Perfdata_51c.dat
+ 2009-10-26 15:42 . 2009-10-26 16:16 97360 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\egui.exe
- 2009-10-25 14:55 . 2009-10-25 14:55 97360 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\egui.exe
+ 2009-10-26 15:42 . 2009-10-26 16:16 10134 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\callmsi.exe
- 2009-10-25 14:55 . 2009-10-25 14:55 10134 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\callmsi.exe
+ 2009-10-26 15:42 . 2009-10-26 15:42 1139712 c:\windows\Installer\453ad.msi
+ 2009-10-26 16:16 . 2009-10-26 16:16 1139712 c:\windows\Installer\37718.msi
+ 2009-09-19 09:27 . 2009-09-19 09:27 36209152 c:\windows\Installer\453aa.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
"utorrent.exe"="c:\documents and settings\Marek\Plocha\utorrent.exe" [2009-10-05 289072]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-25 149280]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrB"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\Electronic Arts\\Need For Speed III\\nfs3.exe"=
"c:\\Program Files\\Sierra\\SWAT 4\\Content\\System\\Swat4.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Illusion Softworks\\Hidden & Dangerous 2\\hd2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Sierra\\CoolPool\\coolpool.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\keyclone\\keyclone.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.1-to-3.0.2-enGB-Win-Update-downloader.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Marek\\Plocha\\utorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"11001:TCP"= 11001:TCP:H&D2 port 11001
"11001:UDP"= 11001:UDP:H&D2 port 11001
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"12001:UDP"= 12001:UDP:SMART WebServer Handshake Multicast Port
"6112:TCP"= 6112:TCP:Blizzard Downloader
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [17.10.2009 19:54 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [17.10.2009 19:54 27656]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [3.2.2009 16:39 63096]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15.9.2009 10:42 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15.9.2009 10:42 74480]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14.5.2009 15:47 731840]
S2 gupdate1ca18e6298cdd6;Google Update Service (gupdate1ca18e6298cdd6);c:\program files\Google\Update\GoogleUpdate.exe [9.8.2009 12:39 133104]
S3 axskbus;axskbus;c:\windows\system32\DRIVERS\axskbus.sys --> c:\windows\system32\DRIVERS\axskbus.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [20.2.2008 19:49 13352]
S3 M1000Srv;M5603C USB2.0 Camera Driver;c:\windows\system32\Drivers\M1000KNT.sys --> c:\windows\system32\Drivers\M1000KNT.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15.9.2009 10:42 7408]
S4 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [17.10.2009 19:54 4368952]
S4 SMART Web Server;SMART Web Server;c:\program files\SMART Technologies Inc\SMART Board Software\WebServer.exe [19.4.2007 6:42 759312]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Obsah adresáře 'Naplánované úlohy'
2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-10-26 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-10-19 07:22]
2009-10-27 c:\windows\Tasks\User_Feed_Synchronization-{CB8F93AA-F0A1-41BE-9268-229B640A54CD}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
2009-10-27 c:\windows\Tasks\User_Feed_Synchronization-{D8C6849B-BD9A-4B92-970F-E7635BC45510}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Doplňkový sken -------
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Marek\Data aplikací\Mozilla\Firefox\Profiles\j2ggv3xx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.cz
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-27 18:34
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1409082233-220523388-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:df,62,2c,55,b4,92,8c,81,8f,81,d7,2e,f6,2f,99,2a,af,76,f8,bb,39,8e,53,
3b,98,84,f3,a1,74,26,e8,39,f4,22,d8,75,d3,12,9d,76,c2,c3,f8,38,95,43,4a,2c,\
"??"=hex:a9,1b,d4,2d,84,8a,c8,cc,72,9b,3f,aa,56,b9,ca,9f
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\Marek\Data aplikací\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
- - - - - - - > 'explorer.exe'(2992)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2009-10-27 18:38
ComboFix-quarantined-files.txt 2009-10-27 17:37
ComboFix2.txt 2009-10-25 17:41
Před spuštěním: Volných bajtů: 111 133 347 840
Po spuštění: Volných bajtů: 111 114 002 432
- - End Of File - - 75F98EDF795D801787565E4D31262782
Nespustitelnost CD/DvD Vyřešeno
- MaxDamageCZ
- Level 2.5
- Příspěvky: 355
- Registrován: červenec 09
- Bydliště: Ostrava
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Nespustitelnost CD/DvD
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý
Iphone 3g 16gb černý
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Nespustitelnost CD/DvD
Nemáš tam virtuální mechaniky? Pokud ano , bylo by lépe znovu nainstalovat , zrušit mechaniky a pak odinstalovat.
Moc jsem toho tam nenašel.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Moc jsem toho tam nenašel.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
File::
c:\windows\VDLL.DLL
c:\windows\logo_1.exe
c:\windows\system32\eEmpty.exe
c:\windows\system32\mlfcache.dat
c:\program files\DAEMON Tools Lite\daemon.exe
Folder::
c:\program files\DAEMON Tools Toolbar
c:\program files\AskBardis
c:\windows\system32\runouce.exe
c:\program files\DAEMON Tools Lite
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=-
Firefox::
FF - ProfilePath - c:\documents and settings\Marek\Data aplikací\Mozilla\Firefox\Profiles\j2ggv3xx.default\
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- MaxDamageCZ
- Level 2.5
- Příspěvky: 355
- Registrován: červenec 09
- Bydliště: Ostrava
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Nespustitelnost CD/DvD
ComboFix 09-10-27.07 - Marek 28.10.2009 12:42.23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.582 [GMT 1:00]
Spuštěný z: c:\documents and settings\Marek\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Marek\Plocha\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Vytvořen nový Bod Obnovení
FILE ::
"c:\program files\DAEMON Tools Lite\daemon.exe"
"c:\windows\logo_1.exe"
"c:\windows\system32\eEmpty.exe"
"c:\windows\system32\mlfcache.dat"
"c:\windows\VDLL.DLL"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskBardis
c:\program files\AskBardis\bar\Settings\prevCfg2.htm
c:\program files\DAEMON Tools Lite
c:\program files\DAEMON Tools Lite\daemon.exe
c:\program files\DAEMON Tools Lite\DTCommonRes.dll
c:\program files\DAEMON Tools Lite\Engine.dll
c:\program files\DAEMON Tools Lite\imgengine.dll
c:\program files\DAEMON Tools Lite\Lang\ARA.dll
c:\program files\DAEMON Tools Lite\Lang\BGR.dll
c:\program files\DAEMON Tools Lite\Lang\BIH.dll
c:\program files\DAEMON Tools Lite\Lang\CAT.dll
c:\program files\DAEMON Tools Lite\Lang\CSY.dll
c:\program files\DAEMON Tools Lite\Lang\DAN.dll
c:\program files\DAEMON Tools Lite\Lang\DEU.dll
c:\program files\DAEMON Tools Lite\Lang\ELL.dll
c:\program files\DAEMON Tools Lite\Lang\ENU.dll
c:\program files\DAEMON Tools Lite\Lang\ESN.dll
c:\program files\DAEMON Tools Lite\Lang\FIN.dll
c:\program files\DAEMON Tools Lite\Lang\FRA.dll
c:\program files\DAEMON Tools Lite\Lang\HEB.dll
c:\program files\DAEMON Tools Lite\Lang\HRV.dll
c:\program files\DAEMON Tools Lite\Lang\HUN.dll
c:\program files\DAEMON Tools Lite\Lang\CHS.dll
c:\program files\DAEMON Tools Lite\Lang\CHT.dll
c:\program files\DAEMON Tools Lite\Lang\ITA.dll
c:\program files\DAEMON Tools Lite\Lang\JPN.dll
c:\program files\DAEMON Tools Lite\Lang\KAT.dll
c:\program files\DAEMON Tools Lite\Lang\KOR.dll
c:\program files\DAEMON Tools Lite\Lang\LTH.dll
c:\program files\DAEMON Tools Lite\Lang\LVI.dll
c:\program files\DAEMON Tools Lite\Lang\NLB.dll
c:\program files\DAEMON Tools Lite\Lang\NOR.dll
c:\program files\DAEMON Tools Lite\Lang\PLK.dll
c:\program files\DAEMON Tools Lite\Lang\PTB.dll
c:\program files\DAEMON Tools Lite\Lang\ROM.dll
c:\program files\DAEMON Tools Lite\Lang\RUS.dll
c:\program files\DAEMON Tools Lite\Lang\SKY.dll
c:\program files\DAEMON Tools Lite\Lang\SLV.dll
c:\program files\DAEMON Tools Lite\Lang\SRL.dll
c:\program files\DAEMON Tools Lite\Lang\SVE.dll
c:\program files\DAEMON Tools Lite\Lang\TRK.dll
c:\program files\DAEMON Tools Lite\Lang\UKR.dll
c:\program files\DAEMON Tools Lite\mfc80u.dll
c:\program files\DAEMON Tools Lite\Microsoft.VC80.ATL.manifest
c:\program files\DAEMON Tools Lite\Microsoft.VC80.CRT.manifest
c:\program files\DAEMON Tools Lite\Microsoft.VC80.MFC.manifest
c:\program files\DAEMON Tools Lite\Microsoft.VC80.MFCLOC.manifest
c:\program files\DAEMON Tools Lite\msvcp80.dll
c:\program files\DAEMON Tools Lite\msvcr80.dll
c:\program files\DAEMON Tools Lite\uninst.exe
c:\program files\DAEMON Tools Toolbar
c:\windows\system32\eEmpty.exe
c:\windows\system32\mlfcache.dat
c:\windows\system32\runouce.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-09-28 do 2009-10-28 )))))))))))))))))))))))))))))))
.
2009-10-25 17:47 . 2009-10-26 15:10 -------- d-----w- c:\program files\Alwil Software
2009-10-25 16:49 . 2009-10-25 16:49 -------- dcsh--w- c:\documents and settings\Administrator\IETldCache
2009-10-25 15:36 . 2009-10-25 15:36 -------- d---a-w- c:\windows\rundll16.exe
2009-10-25 15:36 . 2009-10-25 15:36 -------- d---a-w- c:\windows\logo1_.exe
2009-10-25 14:37 . 2009-10-25 14:37 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2009-10-25 14:25 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-25 13:24 . 2009-10-25 13:24 -------- dc----w- C:\_OTM
2009-10-25 12:45 . 2009-10-25 12:46 -------- dc----w- C:\rsit
2009-10-24 06:55 . 2009-10-24 06:55 632064 ----a-w- c:\windows\system32\msvcr80.dll
2009-10-24 06:55 . 2009-10-24 06:55 554240 ----a-w- c:\windows\system32\msvcp80.dll
2009-10-24 06:55 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2009-10-24 06:55 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2009-10-24 06:55 . 2009-10-24 06:55 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-10-23 18:09 . 2009-10-23 18:09 -------- dc----w- C:\Sun
2009-10-23 17:36 . 2009-10-23 18:07 -------- d-----w- c:\documents and settings\Marek\.SunDownloadManager
2009-10-20 18:53 . 2009-10-20 18:53 -------- dc----w- c:\documents and settings\MaxDamage - uživatel
2009-10-20 14:53 . 2009-10-20 14:53 -------- d--h--w- c:\windows\PIF
2009-10-19 17:20 . 2009-10-25 16:13 -------- d-----w- c:\program files\HTV
2009-10-18 19:00 . 2009-10-20 18:53 -------- d-----w- c:\program files\COMODO
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\VDLL.DLL
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\RUNDL132.EXE
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\logo_1.exe
2009-10-17 18:54 . 2009-10-17 18:54 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-10-17 18:54 . 2009-10-17 18:54 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-10-17 18:54 . 2009-10-17 18:54 -------- d-----w- c:\program files\Prevx
2009-10-17 17:22 . 2009-10-17 17:22 -------- d-----w- c:\program files\Conduit
2009-10-17 17:22 . 2009-10-17 19:28 -------- d-----w- c:\program files\free-downloads.net
2009-10-11 17:11 . 2009-10-11 17:11 -------- d-----w- c:\program files\Opera
2009-10-11 16:39 . 2001-08-17 20:07 101888 -c--a-w- c:\windows\system32\dllcache\adpu160m.sys
2009-10-11 16:39 . 2004-08-03 20:32 10880 -c--a-w- c:\windows\system32\dllcache\admjoy.sys
2009-10-11 16:39 . 2001-08-17 18:11 46112 -c--a-w- c:\windows\system32\dllcache\adptsf50.sys
2009-10-11 16:39 . 2001-08-17 18:19 747392 -c--a-w- c:\windows\system32\dllcache\adm8830.sys
2009-10-11 16:39 . 2001-08-17 18:19 553984 -c--a-w- c:\windows\system32\dllcache\adm8820.sys
2009-10-11 16:39 . 2001-08-17 18:19 584448 -c--a-w- c:\windows\system32\dllcache\adm8810.sys
2009-10-11 16:37 . 2001-10-24 10:24 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-10-10 16:29 . 2009-10-10 16:29 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-10 11:03 . 2009-10-10 11:04 -------- dc----w- C:\iPod Photo Cache
2009-10-05 17:22 . 2009-10-05 17:22 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-10-05 17:21 . 2009-10-12 13:47 -------- d-----w- c:\windows\Internet Logs
2009-10-05 17:11 . 2009-10-10 16:14 -------- d-----w- c:\program files\JockerSoft
2009-10-05 15:14 . 2009-10-05 15:29 -------- d-----w- c:\program files\Vuze
2009-10-05 15:04 . 2009-10-10 16:13 -------- d-----w- c:\program files\BitLord
2009-10-04 17:50 . 2009-10-04 17:50 -------- d-----w- c:\program files\wxDownload Fast
2009-10-04 17:33 . 2009-10-04 17:33 -------- dc----w- C:\Downloads
2009-10-04 16:15 . 2009-10-11 13:26 -------- d-----w- c:\program files\Star Downloader
2009-10-02 15:51 . 2009-10-02 15:51 -------- d-----w- c:\program files\Avanquest update
2009-10-02 09:33 . 2009-10-02 09:33 -------- d-----w- c:\program files\Total Video Converter
2009-10-02 05:37 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-10-01 10:53 . 2009-10-19 16:44 -------- d-----w- c:\program files\IObit
2009-09-30 11:59 . 2009-09-30 11:59 -------- d-----w- c:\program files\iPod
2009-09-30 11:58 . 2009-09-30 12:02 -------- d-----w- c:\program files\iTunes
2009-09-30 11:24 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-30 11:24 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-30 06:41 . 2009-09-30 06:41 -------- d-----w- c:\program files\QuickTime
2009-09-30 06:40 . 2009-09-30 06:40 -------- d-----w- c:\program files\Apple Software Update
2009-09-30 06:39 . 2009-08-28 17:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-09-30 06:39 . 2009-08-28 17:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-09-30 06:39 . 2009-09-30 11:59 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-26 18:05 . 2009-07-30 11:56 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-26 16:14 . 2009-09-19 09:33 -------- d-----w- c:\program files\ESET
2009-10-25 11:53 . 2008-06-02 12:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-25 11:27 . 2009-08-04 11:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-25 10:41 . 2004-08-18 12:00 90996 ----a-w- c:\windows\system32\perfc005.dat
2009-10-25 10:41 . 2004-08-18 12:00 457400 ----a-w- c:\windows\system32\perfh005.dat
2009-10-24 13:40 . 2009-07-28 13:57 -------- d-----w- c:\program files\VS Revo Group
2009-10-23 17:25 . 2006-09-09 18:51 -------- d-----w- c:\program files\Java
2009-10-21 17:29 . 2006-07-10 07:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-18 10:48 . 2006-12-16 12:12 -------- d-----w- c:\program files\EA SPORTS
2009-10-04 17:40 . 2009-09-01 16:33 -------- d-----w- c:\program files\Bonjour
2009-10-02 15:51 . 2006-07-04 06:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-02 09:02 . 2006-08-25 09:21 -------- d-----w- c:\program files\Sony Ericsson
2009-10-01 11:27 . 2006-09-10 10:19 -------- d-----w- c:\program files\VDMSound
2009-10-01 11:21 . 2006-11-08 13:23 -------- d-----w- c:\program files\Nvu
2009-10-01 11:21 . 2009-07-28 08:44 -------- d-----w- c:\program files\Trend Micro
2009-10-01 11:21 . 2009-06-13 15:47 -------- d-----w- c:\program files\World of Warcraft
2009-10-01 11:21 . 2009-05-06 17:54 -------- d-----w- c:\program files\Stykz
2009-10-01 11:21 . 2009-05-06 16:03 -------- d-----w- c:\program files\VirtualDJ
2009-10-01 11:21 . 2008-02-03 17:51 -------- d-----w- c:\program files\Toribash-3.1
2009-10-01 11:21 . 2007-06-19 17:21 -------- d-----w- c:\program files\RADVideo
2009-10-01 11:21 . 2007-01-09 19:27 -------- d-----w- c:\program files\Video DVD Maker FREE
2009-10-01 11:21 . 2006-12-31 18:52 -------- d-----w- c:\program files\Teamspeak2_RC2
2009-09-26 19:18 . 2009-09-26 19:18 4484 ----a-w- c:\windows\system32\drivers\cpuidlep.sys
2009-09-25 12:11 . 2009-09-25 12:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-23 14:02 . 2009-09-23 14:02 -------- d-----w- c:\program files\Warp
2009-09-19 15:31 . 2009-09-19 15:30 -------- d-----w- c:\program files\Security Task Manager
2009-09-18 17:23 . 2009-09-18 17:23 12 ----a-w- c:\documents and settings\Marek\USERDATA.DAT
2009-09-12 16:03 . 2009-09-12 15:56 -------- d-----w- c:\program files\ICQ6.5
2009-09-12 15:57 . 2008-05-29 15:58 -------- d-----w- c:\program files\ICQ6
2009-09-11 14:19 . 2004-08-18 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 12:54 . 2009-09-25 12:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-09-25 12:11 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:05 . 2004-08-18 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-02 09:26 . 2008-11-06 15:38 -------- d-----w- c:\program files\NextUp Talker
2009-09-01 16:43 . 2009-09-01 16:41 -------- d-----w- c:\program files\Common Files\Jasc Software Inc
2009-09-01 16:41 . 2009-09-01 16:40 -------- d-----w- c:\program files\Jasc Software Inc
2009-09-01 16:05 . 2009-09-01 16:05 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-09-01 14:34 . 2009-09-01 14:34 160285 ----a-w- c:\windows\Sqirlz Morph Uninstaller.exe
2009-09-01 14:34 . 2009-09-01 14:34 -------- d-----w- c:\program files\Sqirlz Morph
2009-08-31 13:54 . 2009-04-13 16:45 -------- d-----w- c:\program files\Free Power Word to Pdf Converter
2009-08-31 13:54 . 2009-04-13 16:34 -------- d-----w- c:\program files\Free PDF to Word Doc Converter
2009-08-31 13:39 . 2006-08-25 09:21 -------- d-----w- c:\program files\Common Files\Teleca Shared
2009-08-31 13:37 . 2008-11-05 19:11 -------- d-----w- c:\program files\Text to Speech Maker
2009-08-31 13:23 . 2009-06-30 11:44 -------- d-----w- c:\program files\MumboJumbo
2009-08-31 13:23 . 2009-02-24 13:08 -------- d-----w- c:\program files\Wanadoo Edition
2009-08-31 13:13 . 2009-08-03 15:13 -------- d-----w- c:\program files\Actual Drawing
2009-08-31 13:13 . 2009-05-06 16:55 -------- d-----w- c:\program files\Acoustica Mixcraft
2009-08-29 07:58 . 2004-08-18 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:02 . 2004-08-18 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 17:24 . 2006-07-03 14:57 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2006-07-03 14:57 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2006-07-04 06:38 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2006-07-03 14:57 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2006-07-03 14:57 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2004-08-18 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2006-07-03 14:57 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2008-06-01 13:30 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 17:23 . 2006-07-03 14:57 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-18 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 20:59 . 2004-08-18 12:00 2191360 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 17:29 . 2004-08-17 15:45 2068224 ------w- c:\windows\system32\ntkrnlpa.exe
2004-08-23 21:38 . 2004-08-23 21:38 3371 ----a-w- c:\program files\!!!readme.txt
2004-08-23 19:08 . 2004-08-23 19:08 83968 -c--a-w- c:\program files\NB_NB_2_12_37.xls
.
((((((((((((((((((((((((((((( SnapShot@2009-10-25_17.38.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-28 11:54 . 2009-10-28 11:54 16384 c:\windows\temp\Perflib_Perfdata_7a4.dat
+ 2009-10-28 11:54 . 2009-10-28 11:54 16384 c:\windows\temp\Perflib_Perfdata_708.dat
- 2009-09-01 16:44 . 2009-09-01 16:44 25214 c:\windows\Installer\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}\ARPPRODUCTICON.exe
+ 2009-09-01 16:44 . 2009-10-27 19:10 25214 c:\windows\Installer\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}\ARPPRODUCTICON.exe
+ 2009-10-26 15:42 . 2009-10-28 11:34 97360 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\egui.exe
- 2009-10-25 14:55 . 2009-10-25 14:55 97360 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\egui.exe
+ 2009-10-26 15:42 . 2009-10-28 11:34 10134 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\callmsi.exe
- 2009-10-25 14:55 . 2009-10-25 14:55 10134 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\callmsi.exe
+ 2009-10-26 15:42 . 2009-10-26 15:42 1139712 c:\windows\Installer\453ad.msi
+ 2009-10-26 16:16 . 2009-10-26 16:16 1139712 c:\windows\Installer\37718.msi
+ 2009-09-19 09:27 . 2009-09-19 09:27 36209152 c:\windows\Installer\453aa.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
"utorrent.exe"="c:\documents and settings\Marek\Plocha\utorrent.exe" [2009-10-05 289072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-25 149280]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrB"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\Electronic Arts\\Need For Speed III\\nfs3.exe"=
"c:\\Program Files\\Sierra\\SWAT 4\\Content\\System\\Swat4.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Illusion Softworks\\Hidden & Dangerous 2\\hd2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Sierra\\CoolPool\\coolpool.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\keyclone\\keyclone.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.1-to-3.0.2-enGB-Win-Update-downloader.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Marek\\Plocha\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"11001:TCP"= 11001:TCP:H&D2 port 11001
"11001:UDP"= 11001:UDP:H&D2 port 11001
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"12001:UDP"= 12001:UDP:SMART WebServer Handshake Multicast Port
"6112:TCP"= 6112:TCP:Blizzard Downloader
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [17.10.2009 19:54 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [17.10.2009 19:54 27656]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [3.2.2009 16:39 63096]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15.9.2009 10:42 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15.9.2009 10:42 74480]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14.5.2009 15:47 731840]
S2 gupdate1ca18e6298cdd6;Google Update Service (gupdate1ca18e6298cdd6);c:\program files\Google\Update\GoogleUpdate.exe [9.8.2009 12:39 133104]
S3 axskbus;axskbus;c:\windows\system32\DRIVERS\axskbus.sys --> c:\windows\system32\DRIVERS\axskbus.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [20.2.2008 19:49 13352]
S3 M1000Srv;M5603C USB2.0 Camera Driver;c:\windows\system32\Drivers\M1000KNT.sys --> c:\windows\system32\Drivers\M1000KNT.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15.9.2009 10:42 7408]
S4 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [17.10.2009 19:54 4368952]
S4 SMART Web Server;SMART Web Server;c:\program files\SMART Technologies Inc\SMART Board Software\WebServer.exe [19.4.2007 6:42 759312]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - mbr
.
Obsah adresáře 'Naplánované úlohy'
2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-10-28 c:\windows\Tasks\User_Feed_Synchronization-{CB8F93AA-F0A1-41BE-9268-229B640A54CD}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
2009-10-28 c:\windows\Tasks\User_Feed_Synchronization-{D8C6849B-BD9A-4B92-970F-E7635BC45510}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Doplňkový sken -------
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Marek\Data aplikací\Mozilla\Firefox\Profiles\j2ggv3xx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.cz
FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-28 12:56
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys sfsync02.sys atapi.sys spdm.sys >>UNKNOWN [0x87190938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
prosync1.sys @ 0xF798D000 0x1BE0 bytes
\Driver\prosync1 IRP hooks not detected
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
sfsync02.sys @ 0xF74D7000 0x9000 bytes
error reading "sfsync02.sys" driver IRP handlers
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
atapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF798D6E1 prosync1.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7200B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1409082233-220523388-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:df,62,2c,55,b4,92,8c,81,8f,81,d7,2e,f6,2f,99,2a,af,76,f8,bb,39,8e,53,
3b,98,84,f3,a1,74,26,e8,39,f4,22,d8,75,d3,12,9d,76,c2,c3,f8,38,95,43,4a,2c,\
"??"=hex:a9,1b,d4,2d,84,8a,c8,cc,72,9b,3f,aa,56,b9,ca,9f
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\Marek\Data aplikací\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
- - - - - - - > 'explorer.exe'(3436)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\SMART Technologies Inc\SMART Board Software\SMARTBoardService.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\combofix\CF9872.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Celkový čas: 2009-10-28 13:08 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-10-28 12:06
ComboFix2.txt 2009-10-27 17:38
ComboFix3.txt 2009-10-25 17:41
Před spuštěním: Volných bajtů: 111 031 693 312
Po spuštění: Volných bajtů: 111 003 078 656
- - End Of File - - B690986EEF40DF48C5BB09893B60FAA2
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.582 [GMT 1:00]
Spuštěný z: c:\documents and settings\Marek\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Marek\Plocha\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Vytvořen nový Bod Obnovení
FILE ::
"c:\program files\DAEMON Tools Lite\daemon.exe"
"c:\windows\logo_1.exe"
"c:\windows\system32\eEmpty.exe"
"c:\windows\system32\mlfcache.dat"
"c:\windows\VDLL.DLL"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskBardis
c:\program files\AskBardis\bar\Settings\prevCfg2.htm
c:\program files\DAEMON Tools Lite
c:\program files\DAEMON Tools Lite\daemon.exe
c:\program files\DAEMON Tools Lite\DTCommonRes.dll
c:\program files\DAEMON Tools Lite\Engine.dll
c:\program files\DAEMON Tools Lite\imgengine.dll
c:\program files\DAEMON Tools Lite\Lang\ARA.dll
c:\program files\DAEMON Tools Lite\Lang\BGR.dll
c:\program files\DAEMON Tools Lite\Lang\BIH.dll
c:\program files\DAEMON Tools Lite\Lang\CAT.dll
c:\program files\DAEMON Tools Lite\Lang\CSY.dll
c:\program files\DAEMON Tools Lite\Lang\DAN.dll
c:\program files\DAEMON Tools Lite\Lang\DEU.dll
c:\program files\DAEMON Tools Lite\Lang\ELL.dll
c:\program files\DAEMON Tools Lite\Lang\ENU.dll
c:\program files\DAEMON Tools Lite\Lang\ESN.dll
c:\program files\DAEMON Tools Lite\Lang\FIN.dll
c:\program files\DAEMON Tools Lite\Lang\FRA.dll
c:\program files\DAEMON Tools Lite\Lang\HEB.dll
c:\program files\DAEMON Tools Lite\Lang\HRV.dll
c:\program files\DAEMON Tools Lite\Lang\HUN.dll
c:\program files\DAEMON Tools Lite\Lang\CHS.dll
c:\program files\DAEMON Tools Lite\Lang\CHT.dll
c:\program files\DAEMON Tools Lite\Lang\ITA.dll
c:\program files\DAEMON Tools Lite\Lang\JPN.dll
c:\program files\DAEMON Tools Lite\Lang\KAT.dll
c:\program files\DAEMON Tools Lite\Lang\KOR.dll
c:\program files\DAEMON Tools Lite\Lang\LTH.dll
c:\program files\DAEMON Tools Lite\Lang\LVI.dll
c:\program files\DAEMON Tools Lite\Lang\NLB.dll
c:\program files\DAEMON Tools Lite\Lang\NOR.dll
c:\program files\DAEMON Tools Lite\Lang\PLK.dll
c:\program files\DAEMON Tools Lite\Lang\PTB.dll
c:\program files\DAEMON Tools Lite\Lang\ROM.dll
c:\program files\DAEMON Tools Lite\Lang\RUS.dll
c:\program files\DAEMON Tools Lite\Lang\SKY.dll
c:\program files\DAEMON Tools Lite\Lang\SLV.dll
c:\program files\DAEMON Tools Lite\Lang\SRL.dll
c:\program files\DAEMON Tools Lite\Lang\SVE.dll
c:\program files\DAEMON Tools Lite\Lang\TRK.dll
c:\program files\DAEMON Tools Lite\Lang\UKR.dll
c:\program files\DAEMON Tools Lite\mfc80u.dll
c:\program files\DAEMON Tools Lite\Microsoft.VC80.ATL.manifest
c:\program files\DAEMON Tools Lite\Microsoft.VC80.CRT.manifest
c:\program files\DAEMON Tools Lite\Microsoft.VC80.MFC.manifest
c:\program files\DAEMON Tools Lite\Microsoft.VC80.MFCLOC.manifest
c:\program files\DAEMON Tools Lite\msvcp80.dll
c:\program files\DAEMON Tools Lite\msvcr80.dll
c:\program files\DAEMON Tools Lite\uninst.exe
c:\program files\DAEMON Tools Toolbar
c:\windows\system32\eEmpty.exe
c:\windows\system32\mlfcache.dat
c:\windows\system32\runouce.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-09-28 do 2009-10-28 )))))))))))))))))))))))))))))))
.
2009-10-25 17:47 . 2009-10-26 15:10 -------- d-----w- c:\program files\Alwil Software
2009-10-25 16:49 . 2009-10-25 16:49 -------- dcsh--w- c:\documents and settings\Administrator\IETldCache
2009-10-25 15:36 . 2009-10-25 15:36 -------- d---a-w- c:\windows\rundll16.exe
2009-10-25 15:36 . 2009-10-25 15:36 -------- d---a-w- c:\windows\logo1_.exe
2009-10-25 14:37 . 2009-10-25 14:37 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2009-10-25 14:25 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-25 13:24 . 2009-10-25 13:24 -------- dc----w- C:\_OTM
2009-10-25 12:45 . 2009-10-25 12:46 -------- dc----w- C:\rsit
2009-10-24 06:55 . 2009-10-24 06:55 632064 ----a-w- c:\windows\system32\msvcr80.dll
2009-10-24 06:55 . 2009-10-24 06:55 554240 ----a-w- c:\windows\system32\msvcp80.dll
2009-10-24 06:55 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2009-10-24 06:55 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2009-10-24 06:55 . 2009-10-24 06:55 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-10-23 18:09 . 2009-10-23 18:09 -------- dc----w- C:\Sun
2009-10-23 17:36 . 2009-10-23 18:07 -------- d-----w- c:\documents and settings\Marek\.SunDownloadManager
2009-10-20 18:53 . 2009-10-20 18:53 -------- dc----w- c:\documents and settings\MaxDamage - uživatel
2009-10-20 14:53 . 2009-10-20 14:53 -------- d--h--w- c:\windows\PIF
2009-10-19 17:20 . 2009-10-25 16:13 -------- d-----w- c:\program files\HTV
2009-10-18 19:00 . 2009-10-20 18:53 -------- d-----w- c:\program files\COMODO
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\VDLL.DLL
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\RUNDL132.EXE
2009-10-18 07:35 . 2009-10-18 07:35 -------- d---a-w- c:\windows\logo_1.exe
2009-10-17 18:54 . 2009-10-17 18:54 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-10-17 18:54 . 2009-10-17 18:54 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-10-17 18:54 . 2009-10-17 18:54 -------- d-----w- c:\program files\Prevx
2009-10-17 17:22 . 2009-10-17 17:22 -------- d-----w- c:\program files\Conduit
2009-10-17 17:22 . 2009-10-17 19:28 -------- d-----w- c:\program files\free-downloads.net
2009-10-11 17:11 . 2009-10-11 17:11 -------- d-----w- c:\program files\Opera
2009-10-11 16:39 . 2001-08-17 20:07 101888 -c--a-w- c:\windows\system32\dllcache\adpu160m.sys
2009-10-11 16:39 . 2004-08-03 20:32 10880 -c--a-w- c:\windows\system32\dllcache\admjoy.sys
2009-10-11 16:39 . 2001-08-17 18:11 46112 -c--a-w- c:\windows\system32\dllcache\adptsf50.sys
2009-10-11 16:39 . 2001-08-17 18:19 747392 -c--a-w- c:\windows\system32\dllcache\adm8830.sys
2009-10-11 16:39 . 2001-08-17 18:19 553984 -c--a-w- c:\windows\system32\dllcache\adm8820.sys
2009-10-11 16:39 . 2001-08-17 18:19 584448 -c--a-w- c:\windows\system32\dllcache\adm8810.sys
2009-10-11 16:37 . 2001-10-24 10:24 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-10-10 16:29 . 2009-10-10 16:29 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-10 11:03 . 2009-10-10 11:04 -------- dc----w- C:\iPod Photo Cache
2009-10-05 17:22 . 2009-10-05 17:22 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-10-05 17:21 . 2009-10-12 13:47 -------- d-----w- c:\windows\Internet Logs
2009-10-05 17:11 . 2009-10-10 16:14 -------- d-----w- c:\program files\JockerSoft
2009-10-05 15:14 . 2009-10-05 15:29 -------- d-----w- c:\program files\Vuze
2009-10-05 15:04 . 2009-10-10 16:13 -------- d-----w- c:\program files\BitLord
2009-10-04 17:50 . 2009-10-04 17:50 -------- d-----w- c:\program files\wxDownload Fast
2009-10-04 17:33 . 2009-10-04 17:33 -------- dc----w- C:\Downloads
2009-10-04 16:15 . 2009-10-11 13:26 -------- d-----w- c:\program files\Star Downloader
2009-10-02 15:51 . 2009-10-02 15:51 -------- d-----w- c:\program files\Avanquest update
2009-10-02 09:33 . 2009-10-02 09:33 -------- d-----w- c:\program files\Total Video Converter
2009-10-02 05:37 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-10-01 10:53 . 2009-10-19 16:44 -------- d-----w- c:\program files\IObit
2009-09-30 11:59 . 2009-09-30 11:59 -------- d-----w- c:\program files\iPod
2009-09-30 11:58 . 2009-09-30 12:02 -------- d-----w- c:\program files\iTunes
2009-09-30 11:24 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-30 11:24 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-30 06:41 . 2009-09-30 06:41 -------- d-----w- c:\program files\QuickTime
2009-09-30 06:40 . 2009-09-30 06:40 -------- d-----w- c:\program files\Apple Software Update
2009-09-30 06:39 . 2009-08-28 17:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-09-30 06:39 . 2009-08-28 17:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-09-30 06:39 . 2009-09-30 11:59 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-26 18:05 . 2009-07-30 11:56 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-26 16:14 . 2009-09-19 09:33 -------- d-----w- c:\program files\ESET
2009-10-25 11:53 . 2008-06-02 12:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-25 11:27 . 2009-08-04 11:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-25 10:41 . 2004-08-18 12:00 90996 ----a-w- c:\windows\system32\perfc005.dat
2009-10-25 10:41 . 2004-08-18 12:00 457400 ----a-w- c:\windows\system32\perfh005.dat
2009-10-24 13:40 . 2009-07-28 13:57 -------- d-----w- c:\program files\VS Revo Group
2009-10-23 17:25 . 2006-09-09 18:51 -------- d-----w- c:\program files\Java
2009-10-21 17:29 . 2006-07-10 07:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-18 10:48 . 2006-12-16 12:12 -------- d-----w- c:\program files\EA SPORTS
2009-10-04 17:40 . 2009-09-01 16:33 -------- d-----w- c:\program files\Bonjour
2009-10-02 15:51 . 2006-07-04 06:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-02 09:02 . 2006-08-25 09:21 -------- d-----w- c:\program files\Sony Ericsson
2009-10-01 11:27 . 2006-09-10 10:19 -------- d-----w- c:\program files\VDMSound
2009-10-01 11:21 . 2006-11-08 13:23 -------- d-----w- c:\program files\Nvu
2009-10-01 11:21 . 2009-07-28 08:44 -------- d-----w- c:\program files\Trend Micro
2009-10-01 11:21 . 2009-06-13 15:47 -------- d-----w- c:\program files\World of Warcraft
2009-10-01 11:21 . 2009-05-06 17:54 -------- d-----w- c:\program files\Stykz
2009-10-01 11:21 . 2009-05-06 16:03 -------- d-----w- c:\program files\VirtualDJ
2009-10-01 11:21 . 2008-02-03 17:51 -------- d-----w- c:\program files\Toribash-3.1
2009-10-01 11:21 . 2007-06-19 17:21 -------- d-----w- c:\program files\RADVideo
2009-10-01 11:21 . 2007-01-09 19:27 -------- d-----w- c:\program files\Video DVD Maker FREE
2009-10-01 11:21 . 2006-12-31 18:52 -------- d-----w- c:\program files\Teamspeak2_RC2
2009-09-26 19:18 . 2009-09-26 19:18 4484 ----a-w- c:\windows\system32\drivers\cpuidlep.sys
2009-09-25 12:11 . 2009-09-25 12:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-23 14:02 . 2009-09-23 14:02 -------- d-----w- c:\program files\Warp
2009-09-19 15:31 . 2009-09-19 15:30 -------- d-----w- c:\program files\Security Task Manager
2009-09-18 17:23 . 2009-09-18 17:23 12 ----a-w- c:\documents and settings\Marek\USERDATA.DAT
2009-09-12 16:03 . 2009-09-12 15:56 -------- d-----w- c:\program files\ICQ6.5
2009-09-12 15:57 . 2008-05-29 15:58 -------- d-----w- c:\program files\ICQ6
2009-09-11 14:19 . 2004-08-18 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 12:54 . 2009-09-25 12:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-09-25 12:11 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:05 . 2004-08-18 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-02 09:26 . 2008-11-06 15:38 -------- d-----w- c:\program files\NextUp Talker
2009-09-01 16:43 . 2009-09-01 16:41 -------- d-----w- c:\program files\Common Files\Jasc Software Inc
2009-09-01 16:41 . 2009-09-01 16:40 -------- d-----w- c:\program files\Jasc Software Inc
2009-09-01 16:05 . 2009-09-01 16:05 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-09-01 14:34 . 2009-09-01 14:34 160285 ----a-w- c:\windows\Sqirlz Morph Uninstaller.exe
2009-09-01 14:34 . 2009-09-01 14:34 -------- d-----w- c:\program files\Sqirlz Morph
2009-08-31 13:54 . 2009-04-13 16:45 -------- d-----w- c:\program files\Free Power Word to Pdf Converter
2009-08-31 13:54 . 2009-04-13 16:34 -------- d-----w- c:\program files\Free PDF to Word Doc Converter
2009-08-31 13:39 . 2006-08-25 09:21 -------- d-----w- c:\program files\Common Files\Teleca Shared
2009-08-31 13:37 . 2008-11-05 19:11 -------- d-----w- c:\program files\Text to Speech Maker
2009-08-31 13:23 . 2009-06-30 11:44 -------- d-----w- c:\program files\MumboJumbo
2009-08-31 13:23 . 2009-02-24 13:08 -------- d-----w- c:\program files\Wanadoo Edition
2009-08-31 13:13 . 2009-08-03 15:13 -------- d-----w- c:\program files\Actual Drawing
2009-08-31 13:13 . 2009-05-06 16:55 -------- d-----w- c:\program files\Acoustica Mixcraft
2009-08-29 07:58 . 2004-08-18 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:02 . 2004-08-18 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 17:24 . 2006-07-03 14:57 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2006-07-03 14:57 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2006-07-04 06:38 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2006-07-03 14:57 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2006-07-03 14:57 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2004-08-18 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2006-07-03 14:57 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2008-06-01 13:30 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 17:23 . 2006-07-03 14:57 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-18 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 20:59 . 2004-08-18 12:00 2191360 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 17:29 . 2004-08-17 15:45 2068224 ------w- c:\windows\system32\ntkrnlpa.exe
2004-08-23 21:38 . 2004-08-23 21:38 3371 ----a-w- c:\program files\!!!readme.txt
2004-08-23 19:08 . 2004-08-23 19:08 83968 -c--a-w- c:\program files\NB_NB_2_12_37.xls
.
((((((((((((((((((((((((((((( SnapShot@2009-10-25_17.38.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-28 11:54 . 2009-10-28 11:54 16384 c:\windows\temp\Perflib_Perfdata_7a4.dat
+ 2009-10-28 11:54 . 2009-10-28 11:54 16384 c:\windows\temp\Perflib_Perfdata_708.dat
- 2009-09-01 16:44 . 2009-09-01 16:44 25214 c:\windows\Installer\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}\ARPPRODUCTICON.exe
+ 2009-09-01 16:44 . 2009-10-27 19:10 25214 c:\windows\Installer\{F843C6A3-224D-4615-94F8-3C461BD9AEA0}\ARPPRODUCTICON.exe
+ 2009-10-26 15:42 . 2009-10-28 11:34 97360 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\egui.exe
- 2009-10-25 14:55 . 2009-10-25 14:55 97360 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\egui.exe
+ 2009-10-26 15:42 . 2009-10-28 11:34 10134 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\callmsi.exe
- 2009-10-25 14:55 . 2009-10-25 14:55 10134 c:\windows\Installer\{8075BC83-7F8F-4FE0-9792-685723B06713}\callmsi.exe
+ 2009-10-26 15:42 . 2009-10-26 15:42 1139712 c:\windows\Installer\453ad.msi
+ 2009-10-26 16:16 . 2009-10-26 16:16 1139712 c:\windows\Installer\37718.msi
+ 2009-09-19 09:27 . 2009-09-19 09:27 36209152 c:\windows\Installer\453aa.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
"utorrent.exe"="c:\documents and settings\Marek\Plocha\utorrent.exe" [2009-10-05 289072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-25 149280]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrB"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\Electronic Arts\\Need For Speed III\\nfs3.exe"=
"c:\\Program Files\\Sierra\\SWAT 4\\Content\\System\\Swat4.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Illusion Softworks\\Hidden & Dangerous 2\\hd2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Sierra\\CoolPool\\coolpool.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\keyclone\\keyclone.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.1-to-3.0.2-enGB-Win-Update-downloader.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Marek\\Plocha\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"11001:TCP"= 11001:TCP:H&D2 port 11001
"11001:UDP"= 11001:UDP:H&D2 port 11001
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"12001:UDP"= 12001:UDP:SMART WebServer Handshake Multicast Port
"6112:TCP"= 6112:TCP:Blizzard Downloader
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [17.10.2009 19:54 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [17.10.2009 19:54 27656]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [3.2.2009 16:39 63096]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15.9.2009 10:42 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15.9.2009 10:42 74480]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14.5.2009 15:47 731840]
S2 gupdate1ca18e6298cdd6;Google Update Service (gupdate1ca18e6298cdd6);c:\program files\Google\Update\GoogleUpdate.exe [9.8.2009 12:39 133104]
S3 axskbus;axskbus;c:\windows\system32\DRIVERS\axskbus.sys --> c:\windows\system32\DRIVERS\axskbus.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [20.2.2008 19:49 13352]
S3 M1000Srv;M5603C USB2.0 Camera Driver;c:\windows\system32\Drivers\M1000KNT.sys --> c:\windows\system32\Drivers\M1000KNT.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15.9.2009 10:42 7408]
S4 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [17.10.2009 19:54 4368952]
S4 SMART Web Server;SMART Web Server;c:\program files\SMART Technologies Inc\SMART Board Software\WebServer.exe [19.4.2007 6:42 759312]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - mbr
.
Obsah adresáře 'Naplánované úlohy'
2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-10-28 c:\windows\Tasks\User_Feed_Synchronization-{CB8F93AA-F0A1-41BE-9268-229B640A54CD}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
2009-10-28 c:\windows\Tasks\User_Feed_Synchronization-{D8C6849B-BD9A-4B92-970F-E7635BC45510}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Doplňkový sken -------
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Marek\Data aplikací\Mozilla\Firefox\Profiles\j2ggv3xx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - www.google.cz
FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-28 12:56
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys sfsync02.sys atapi.sys spdm.sys >>UNKNOWN [0x87190938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
prosync1.sys @ 0xF798D000 0x1BE0 bytes
\Driver\prosync1 IRP hooks not detected
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
sfsync02.sys @ 0xF74D7000 0x9000 bytes
error reading "sfsync02.sys" driver IRP handlers
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
atapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF798D6E1 prosync1.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7200B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7200B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1409082233-220523388-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:df,62,2c,55,b4,92,8c,81,8f,81,d7,2e,f6,2f,99,2a,af,76,f8,bb,39,8e,53,
3b,98,84,f3,a1,74,26,e8,39,f4,22,d8,75,d3,12,9d,76,c2,c3,f8,38,95,43,4a,2c,\
"??"=hex:a9,1b,d4,2d,84,8a,c8,cc,72,9b,3f,aa,56,b9,ca,9f
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\Marek\Data aplikací\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
- - - - - - - > 'explorer.exe'(3436)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\SMART Technologies Inc\SMART Board Software\SMARTBoardService.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\combofix\CF9872.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Celkový čas: 2009-10-28 13:08 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-10-28 12:06
ComboFix2.txt 2009-10-27 17:38
ComboFix3.txt 2009-10-25 17:41
Před spuštěním: Volných bajtů: 111 031 693 312
Po spuštění: Volných bajtů: 111 003 078 656
- - End Of File - - B690986EEF40DF48C5BB09893B60FAA2
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý
Iphone 3g 16gb černý
- MaxDamageCZ
- Level 2.5
- Příspěvky: 355
- Registrován: červenec 09
- Bydliště: Ostrava
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Nespustitelnost CD/DvD
TFC provedeno
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý
Iphone 3g 16gb černý
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Nespustitelnost CD/DvD
Jak vypadá načítání CD/DVD?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- MaxDamageCZ
- Level 2.5
- Příspěvky: 355
- Registrován: červenec 09
- Bydliště: Ostrava
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Nespustitelnost CD/DvD
no, v tento počítač je hafo mechanik (asi virtuálních z alcohol 120%), ale u každé mi to hlásí, že tam nemám vložený disk, přestože tam disk vložený mám, takže to vypadá, že tam v té nabídce ani opravdická mechanika není 

AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý
Iphone 3g 16gb černý
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Nespustitelnost CD/DvD
Zkus všechny mechaniky odebrat a restartovat PC. Mrkni se v BIOSu , zda tam máš vůbec nějakou mechaniku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- MaxDamageCZ
- Level 2.5
- Příspěvky: 355
- Registrován: červenec 09
- Bydliště: Ostrava
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Nespustitelnost CD/DvD
Takže, byl jsem v biosu, ale bohužel nevím, kde takovýto hardware hledat. Už je to dávno, co jsem tam "brouzdal". Nakonec se mi podařilo ten Alcohol odinstalovat, DvD mechanika se v tento počítač objevila, ale problém stále přetrvává. Je pod jménem disku, co se v ní nachází, ikonu má takovou, jako soubor, který win neumí rozpoznat (takový bílý papír, uprostřed okno s ikonami). Už fakt nevím, co dělat. Ten můj pc ale umí být záhadný
viz. viewtopic.php?f=47&t=42998&start=120 (chyba, kterou mám na světě jen já
atd.
)



AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý
Iphone 3g 16gb černý
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Nespustitelnost CD/DvD
Každý BIOS je trochu jiný, ale měl bys to mít na záložce Main
Primary IDE Master
Primary IDE Slave
SATA1
Sata2
......... podle druhu připojení mechaniky
Nejlépe by bylo znovu (postupně) nainstalovat Alcohol, odinstalovat virt. mechaniky , poté program.
Dále nainstalovat Daemon Tools, odinstalovat mechaniky a pak program.
Poté:
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Ulož si ho jako na Plochu jako fix.reg a jako typ všechny soubory , najdi tento soubor na Ploše a poklepáním ho spusť. Budeš dotázán na přidání hodnoty do registru. Potvrď.
Primary IDE Master
Primary IDE Slave
SATA1
Sata2
......... podle druhu připojení mechaniky
Nejlépe by bylo znovu (postupně) nainstalovat Alcohol, odinstalovat virt. mechaniky , poté program.
Dále nainstalovat Daemon Tools, odinstalovat mechaniky a pak program.
Poté:
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CDRom]
"AutoRun"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=-
"NoDriveAutoRun"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=-
"NoDriveAutoRun"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=-
"NoDriveAutoRun"=-
Ulož si ho jako na Plochu jako fix.reg a jako typ všechny soubory , najdi tento soubor na Ploše a poklepáním ho spusť. Budeš dotázán na přidání hodnoty do registru. Potvrď.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- MaxDamageCZ
- Level 2.5
- Příspěvky: 355
- Registrován: červenec 09
- Bydliště: Ostrava
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Nespustitelnost CD/DvD
Bohužel, nepomohlo. A k tomu BIOSu, prostě nevím, jak to najít. Takhle to vypadá, jsem správně? Na co mám v tom okně kliknout? (viz screen)

Sry, je to trochu rozmazané, bylo málo světla a já pohnul s foťákem

Sry, je to trochu rozmazané, bylo málo světla a já pohnul s foťákem
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý
Iphone 3g 16gb černý
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Nespustitelnost CD/DvD
Zkus to první vlevo, pak druhé vlevo , nějde tam to najdeš, už si to nepamatuju, mám novější , ale tehle jsem měl, už je to dýl.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
- MaxDamageCZ
- Level 2.5
- Příspěvky: 355
- Registrován: červenec 09
- Bydliště: Ostrava
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Nespustitelnost CD/DvD
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý
Iphone 3g 16gb černý
Zpět na “Problémy s hardwarem”
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 9 hostů