zasekávání programů ve win 7 Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
abrit
Level 1
Level 1
Příspěvky: 83
Registrován: březen 08
Pohlaví: Muž
Stav:
Offline

zasekávání programů ve win 7

Příspěvekod abrit » 23 úno 2010 19:08

Dělal jsem odinstalaci v revo uninstaler a nechtělo to dokončit prohlídku v registrech. Čekal jsem asi půl hodiny a pořád to bylo na stejné úrovni. Naběhlo vyhledávání zbytků v registrech a ve 2/3 mse to seklo. Při kroku zpět se to pak ve stejném místě pořád seklo. V klasickém odinstalování nebo v ccleaner se odinstalace normálně dokončila. Ale zbytky v registrech zůstaly. Totéž se mi stává s wise disk cleaner. Program stále pracuje, ale nic nenachází 1/2 hodiny stále hledá. Mám win 7.

Obrázek

Dále se mi zpomaluje se mi PC, a i když nic nedělám, tak to stále hrabe. Toto nesouvisí s výše uvedeným. Pustím PC a po naběhnutí windows ještě po asi 15 min to stále něco hrabe. Všechno je v klidu, není spuštěna žádná aplikace.



Posílám dva logy. Snad to ukáže chyby. Díky.

log RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Juraj at 2010-02-23 19:00:05
Microsoft Windows 7 Ultimate
System drive C: has 63 GB (63%) free of 100 GB
Total RAM: 3071 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:00:14, on 23.2.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\VM305_STI.EXE
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
C:\Users\Juraj\Desktop\RSIT.exe
C:\Program Files\trend micro\Juraj.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [BigDog305] C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKLM\..\Policies\Explorer\Run: [ati2sgav] "C:\Windows\system32\ati2sgav.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: CpsuboliMsi - {D401E3DC-E916-4016-8D20-B4E6392481F9} - C:\Windows\system32\cpsuboli.dll
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 5072 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2010-01-22 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-28 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-01-29 1095872]
"BigDog305"=C:\Windows\VM305_STI.EXE [2005-08-05 61440]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"ati2sgav"=C:\Windows\system32\ati2sgav.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
CpsuboliMsi - {D401E3DC-E916-4016-8D20-B4E6392481F9} - C:\Windows\system32\cpsuboli.dll [2009-12-14 131072]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vgasave.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-02-23 19:00:05 ----D---- C:\rsit
2010-02-23 13:36:32 ----D---- C:\Users\Juraj\AppData\Roaming\Malwarebytes
2010-02-23 13:36:26 ----D---- C:\ProgramData\Malwarebytes
2010-02-23 13:36:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-23 09:33:41 ----D---- C:\Program Files\trend micro
2010-02-22 20:43:08 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-02-22 20:43:08 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-20 21:57:32 ----A---- C:\Windows\system32\themeui.dll.backup
2010-02-20 21:57:21 ----A---- C:\Windows\system32\uxtheme.dll.backup
2010-02-20 21:57:18 ----A---- C:\Windows\system32\themeservice.dll.backup
2010-02-20 21:47:32 ----A---- C:\Windows\system32\zipfldr.dll.bak
2010-02-20 21:47:32 ----A---- C:\Windows\system32\shell32.dll.bak
2010-02-20 21:47:32 ----A---- C:\Windows\system32\imagesp1.dll.bak
2010-02-20 21:47:32 ----A---- C:\Windows\system32\imageres.dll.bak
2010-02-19 08:49:38 ----D---- C:\Program Files\Microsoft Security Essentials
2010-02-19 01:28:40 ----D---- C:\Users\Juraj\AppData\Roaming\Zoner
2010-02-19 01:27:11 ----D---- C:\Program Files\Zoner
2010-02-17 20:34:27 ----D---- C:\ProgramData\Symantec
2010-02-17 20:34:27 ----D---- C:\ProgramData\Norton
2010-02-17 20:34:25 ----D---- C:\ProgramData\NortonInstaller
2010-02-17 19:53:19 ----D---- C:\Program Files\PowerISO
2010-02-14 19:25:37 ----D---- C:\Program Files\Common Files\Windows Live
2010-02-13 23:47:25 ----D---- C:\Users\Juraj\AppData\Roaming\GRETECH
2010-02-13 23:46:51 ----D---- C:\Program Files\GRETECH
2010-02-10 11:28:13 ----D---- C:\Users\Juraj\AppData\Roaming\Media Player Classic
2010-02-10 10:24:23 ----D---- C:\Program Files\Essentials Codec Pack
2010-02-09 20:33:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-09 20:33:40 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-09 20:33:40 ----A---- C:\Windows\system32\kernel32.dll
2010-02-09 20:33:40 ----A---- C:\Windows\system32\apphelp.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\quartz.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\msyuv.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\msrle32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\avifil32.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-09 20:33:37 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-09 20:33:37 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-09 20:33:36 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-09 00:10:05 ----D---- C:\Program Files\NVIDIA Corporation
2010-02-02 11:17:29 ----D---- C:\Program Files\Electronic Arts
2010-01-28 23:41:00 ----D---- C:\ProgramData\Easy CD-DA Extractor
2010-01-28 23:40:56 ----D---- C:\Program Files\Easy CD-DA Extractor
2010-01-27 13:21:38 ----A---- C:\Windows\system32\winlogon.exe
2010-01-27 13:21:38 ----A---- C:\Windows\explorer.exe
2010-01-25 23:25:23 ----D---- C:\Program Files\Ubisoft
2010-01-25 19:38:14 ----D---- C:\ProgramData\Solidshield
2010-01-25 19:22:46 ----A---- C:\Windows\system32\XAudio2_4.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\D3DX9_41.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\d3dx10_41.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\XAudio2_3.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\xactengine3_4.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\xactengine3_3.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\XAudio2_2.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\xactengine3_2.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\D3DX9_39.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\xinput1_3.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xinput1_2.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\d3dx10.dll
2010-01-25 19:22:37 ----A---- C:\Windows\system32\xinput1_1.dll
2010-01-25 19:22:37 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-01-25 19:22:37 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_26.dll
2010-01-25 19:22:32 ----A---- C:\Windows\system32\d3dx9_25.dll
2010-01-25 19:22:32 ----A---- C:\Windows\system32\d3dx9_24.dll
2010-01-25 12:45:13 ----D---- C:\ProgramData\FLEXnet

======List of files/folders modified in the last 1 months======

2010-02-23 19:00:14 ----D---- C:\Windows\Prefetch
2010-02-23 18:52:49 ----D---- C:\Windows\Tasks
2010-02-23 18:52:41 ----HD---- C:\Windows\Temp
2010-02-23 13:37:17 ----D---- C:\Windows\System32
2010-02-23 13:37:17 ----D---- C:\Windows\inf
2010-02-23 13:37:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-02-23 13:36:28 ----D---- C:\Windows\system32\drivers
2010-02-23 13:36:26 ----HD---- C:\ProgramData
2010-02-23 13:36:25 ----RD---- C:\Program Files
2010-02-23 13:25:49 ----D---- C:\Windows
2010-02-23 10:21:44 ----SHD---- C:\System Volume Information
2010-02-23 08:45:11 ----D---- C:\Users\Juraj\AppData\Roaming\uTorrent
2010-02-23 08:40:06 ----D---- C:\Program Files\uTorrent
2010-02-23 08:35:27 ----D---- C:\Program Files\Wise Disk Cleaner
2010-02-23 08:12:30 ----D---- C:\Windows\system32\config
2010-02-23 01:51:16 ----D---- C:\Windows\system32\wfp
2010-02-23 01:51:14 ----D---- C:\Windows\system32\wbem
2010-02-23 01:50:31 ----SHD---- C:\Windows\BitLockerDiscoveryVolumeContents
2010-02-23 01:50:31 ----D---- C:\Windows\system32\DriverStore
2010-02-23 01:50:31 ----D---- C:\Windows\system32\catroot2
2010-02-23 01:50:27 ----D---- C:\Windows\system32\Tasks
2010-02-23 01:50:22 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-02-23 01:50:22 ----D---- C:\Users\Juraj\AppData\Roaming\GHISLER
2010-02-23 01:50:21 ----D---- C:\ProgramData\Skype
2010-02-23 01:50:21 ----D---- C:\ProgramData\PC Drivers HeadQuarters
2010-02-23 01:50:21 ----D---- C:\ProgramData\Nero
2010-02-23 01:50:21 ----AD---- C:\ProgramData\Temp
2010-02-23 01:50:20 ----SD---- C:\ProgramData\Microsoft
2010-02-23 01:50:20 ----D---- C:\ProgramData\Microsoft Help
2010-02-23 01:50:20 ----D---- C:\Program Files\VS Revo Group
2010-02-23 01:50:13 ----D---- C:\Windows\registration
2010-02-23 01:49:58 ----SD---- C:\Users\Juraj\AppData\Roaming\Microsoft
2010-02-23 01:49:57 ----D---- C:\ProgramData\TuneUp Software
2010-02-23 01:49:54 ----D---- C:\ProgramData\EPSON
2010-02-23 01:49:54 ----D---- C:\ProgramData\CyberLink
2010-02-21 18:06:27 ----D---- C:\Windows\system32\NDF
2010-02-21 18:06:22 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-20 21:57:32 ----A---- C:\Windows\system32\themeui.dll
2010-02-20 21:57:21 ----A---- C:\Windows\system32\uxtheme.dll
2010-02-20 21:57:18 ----A---- C:\Windows\system32\themeservice.dll
2010-02-19 11:31:56 ----D---- C:\Windows\system32\catroot
2010-02-19 08:49:52 ----SHD---- C:\Windows\Installer
2010-02-14 19:25:37 ----D---- C:\Program Files\Common Files
2010-02-14 13:42:13 ----D---- C:\Users\Juraj\AppData\Roaming\Skype
2010-02-14 13:23:25 ----D---- C:\Users\Juraj\AppData\Roaming\skypePM
2010-02-13 12:58:58 ----D---- C:\Windows\debug
2010-02-09 22:43:48 ----D---- C:\Windows\winsxs
2010-02-09 21:43:30 ----RSD---- C:\Windows\assembly
2010-02-09 08:58:44 ----RSD---- C:\Windows\Fonts
2010-02-09 08:58:41 ----D---- C:\Program Files\Common Files\microsoft shared
2010-02-09 08:58:35 ----D---- C:\Program Files\Microsoft Works
2010-02-09 00:39:41 ----D---- C:\Program Files\Mozilla Firefox
2010-02-09 00:10:41 ----D---- C:\ProgramData\NVIDIA
2010-02-03 13:04:39 ----D---- C:\Program Files\WinRAR
2010-02-02 11:04:06 ----D---- C:\Program Files\AGEIA Technologies
2010-02-01 20:26:20 ----A---- C:\Windows\system32\MRT.exe
2010-02-01 06:59:36 ----D---- C:\Program Files\Google
2010-01-31 22:55:18 ----RD---- C:\Program Files\Skype
2010-01-29 22:11:50 ----A---- C:\Windows\NeroDigital.ini
2010-01-28 23:28:43 ----D---- C:\Windows\Easy CD-DA Extractor 11.9.9 build 668
2010-01-27 14:01:39 ----D---- C:\Program Files\Internet Explorer
2010-01-25 19:22:34 ----D---- C:\Windows\Microsoft.NET
2010-01-25 19:22:08 ----D---- C:\Windows\Logs


Log Malwarebytes
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3779
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

23.2.2010 14:48:33
mbam-log-2010-02-23 (14-48-25).txt

Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 102943
Uplynulý čas: 4 minute(s), 50 second(s)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 2
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 1

Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované hodnoty registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ati2sgav (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\kr_done1 (Malware.Trace) -> No action taken.

Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)

Infikované soubory:
C:\Windows\System32\kr_done1 (Malware.Trace) -> No action taken.

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod jaro3 » 23 úno 2010 21:56

Máš Microsoft Security Essentials, takže buď odinstaluj Spybot - Search & Destroy, nebo u něj trvale vypni rez. ochranu.

Na odinstalaci NORTON /SYMANTEC použij toto:
ftp://ftp.symantec.com/public/english_u ... l_Tool.exe

Pak smaž tyto složky:
C:\ProgramData\Symantec
C:\ProgramData\Norton
C:\ProgramData\NortonInstaller

/////////////////
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
//////////////////
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

Můžeš sem pak vložit log z MbAM.
//////////////////////////
Vypni rez. ochrany a firewall u Microsoft Security Essentials.

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah


///////////////////////////
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\Windows\system32\cpsuboli.dll
Vlož sem pak odkaz na stránku s výsledky.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
abrit
Level 1
Level 1
Příspěvky: 83
Registrován: březen 08
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod abrit » 23 úno 2010 22:54

Spy bot nainstalovaný nemám. Udělal jsem obnovvení systému a možná zbylo něco někde?? Norton removal mi nejde doinstalovat. naběhne stránka s přeinstalací podle verze, ale ta, kterou jsem stáhl z odkazu tam není. Složku v system32 vidím na disku, ale virustotal ji neukáže. Vymazal jsem v mbam nálezy a combofix jsem ještě nepoužil. ALT cleaner použit podle návodu. V essential nemám firewall a vypnout nejde. V nastavení antiviru není nic takového. Mám ho v češtině a je tam jen plánovaný scan. Co dělám špatně?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod jaro3 » 23 úno 2010 23:09

C:\ProgramData\Spybot - Search & Destroy
C:\Program Files\Spybot - Search & Destroy
zkus ho odinstalovat v CCleaneru.

Microsoft Security Essentials nemám , tak Ti neporadím jak ho vypnout.

Udělal jsem obnovení systému --to si dělal teď? Pak jsme zase na začátku.

Složku v system32 vidím na disku, ale virustotal ji neukáže.---je to soubor, ne složka, do okénka na virustotal vlož toto:
C:\Windows\system32\cpsuboli.dll
a dej otestovat.

Spusť Combofix a odklikej případně hlášky ohledně zapnutého antiviru a antispywaru ( firewall má taky , pokud se nepletu).
Zítra se kouknu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
abrit
Level 1
Level 1
Příspěvky: 83
Registrován: březen 08
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod abrit » 24 úno 2010 00:13

Odkaz z virustotal -

http://www.virustotal.com/cs/analisis/c ... 1266042711

Obnovení systému jsem dělal někdy brzo odpoledne. Všechno, co tu dávám do příspěvku je po obnově.


Spybot zkusím znovu instalovat a pak opět odinstalovat, protože opravdu je vidět jen ve files, ale není tam spouštěcí soubor. Přeinstaloval jsem ho a v ccleaneru odinstal. Potom zbytek smazán ručně ve složkách.

Udělal jsem combofix před opětovnou instalací a odinstalací spybot. Psalo to o antiviru i antispywaru, Udělal se sám po spuštění comba restart. Potom jsem odinstaloval spybot a opět udělal combofix. Vytvářel se nový bod obnovy. To už během aplikace neproběhl restart ani po vylogování. Žádné hlášky o vypínání antiviru ani antispywaru se neukázaly. Tady je nový log z combofixu.

ComboFix 10-02-23.03 - Juraj 23.02.2010 23:46:23.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3071.2167 [GMT 1:00]
Spuštěný z: c:\users\Juraj\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-01-23 do 2010-02-23 )))))))))))))))))))))))))))))))
.

2010-02-23 22:54 . 2010-02-23 22:54 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-02-23 22:54 . 2010-02-23 22:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-23 22:16 . 2010-02-23 22:54 -------- d-----w- c:\users\Juraj\AppData\Local\temp
2010-02-23 18:00 . 2010-02-23 20:01 -------- d-----w- C:\rsit
2010-02-23 12:36 . 2010-02-23 12:36 -------- d-----w- c:\users\Juraj\AppData\Roaming\Malwarebytes
2010-02-23 12:36 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 12:36 . 2010-02-23 12:36 -------- d-----w- c:\programdata\Malwarebytes
2010-02-23 12:36 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 12:36 . 2010-02-23 12:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 08:33 . 2010-02-23 20:00 -------- d-----w- c:\program files\trend micro
2010-02-22 23:53 . 2010-02-22 23:53 -------- d-----w- c:\users\Juraj\AppData\Local\VS Revo Group
2010-02-19 07:49 . 2010-02-19 07:49 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-19 00:28 . 2010-02-19 00:28 -------- d-----w- c:\users\Juraj\AppData\Roaming\Zoner
2010-02-19 00:28 . 2010-02-19 00:28 -------- d-----w- c:\users\Juraj\AppData\Local\Zoner
2010-02-19 00:27 . 2010-02-19 00:27 -------- d-----w- c:\program files\Zoner
2010-02-17 19:34 . 2010-02-17 19:37 -------- d-----w- c:\programdata\Norton
2010-02-17 19:34 . 2010-02-17 19:34 -------- d-----w- c:\programdata\NortonInstaller
2010-02-17 18:53 . 2010-02-17 18:53 -------- d-----w- c:\program files\PowerISO
2010-02-14 18:25 . 2010-02-14 18:25 -------- d-----w- c:\program files\Common Files\Windows Live
2010-02-13 22:47 . 2010-02-23 00:50 -------- d-----w- c:\users\Juraj\AppData\Roaming\GRETECH
2010-02-13 22:46 . 2010-02-23 00:50 -------- d-----w- c:\program files\GRETECH
2010-02-10 10:28 . 2010-02-10 10:28 -------- d-----w- c:\users\Juraj\AppData\Roaming\Media Player Classic
2010-02-10 09:24 . 2010-02-10 09:24 -------- d-----w- c:\program files\Essentials Codec Pack
2010-02-09 00:21 . 2010-02-09 00:21 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-02-08 23:10 . 2010-02-08 23:10 -------- d-----w- c:\program files\NVIDIA Corporation
2010-02-02 10:17 . 2010-02-14 13:06 -------- d-----w- c:\program files\Electronic Arts
2010-01-28 22:41 . 2010-01-28 22:41 -------- d-----w- c:\programdata\Easy CD-DA Extractor
2010-01-28 22:40 . 2010-01-28 22:40 -------- d-----w- c:\program files\Easy CD-DA Extractor
2010-01-27 23:05 . 2010-01-27 23:05 -------- d-----w- c:\users\Juraj\AppData\Local\RapidShare
2010-01-27 12:21 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-01-27 12:21 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-01-25 22:25 . 2010-02-21 17:06 -------- d-----w- c:\program files\Ubisoft
2010-01-25 18:38 . 2010-01-25 18:38 -------- d-----w- c:\programdata\Solidshield
2010-01-25 11:45 . 2010-01-29 11:32 -------- d-----w- c:\programdata\FLEXnet

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 12:37 . 2009-07-14 08:44 622422 ----a-w- c:\windows\system32\perfh005.dat
2010-02-23 12:37 . 2009-07-14 08:44 118604 ----a-w- c:\windows\system32\perfc005.dat
2010-02-23 07:45 . 2010-01-01 14:19 -------- d-----w- c:\users\Juraj\AppData\Roaming\uTorrent
2010-02-23 07:40 . 2010-01-01 14:19 -------- d-----w- c:\program files\uTorrent
2010-02-23 07:35 . 2010-01-01 14:57 -------- d-----w- c:\program files\Wise Disk Cleaner
2010-02-23 00:50 . 2009-12-30 22:48 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-02-23 00:50 . 2009-12-28 14:09 -------- d-----w- c:\users\Juraj\AppData\Roaming\GHISLER
2010-02-23 00:50 . 2010-01-05 07:23 -------- d-----w- c:\programdata\Nero
2010-02-23 00:50 . 2009-12-30 22:14 -------- d-----w- c:\programdata\Skype
2010-02-23 00:50 . 2009-12-28 14:34 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2010-02-23 00:50 . 2009-12-28 17:56 -------- d-----w- c:\program files\VS Revo Group
2010-02-23 00:50 . 2009-12-28 14:50 -------- d-----w- c:\programdata\Microsoft Help
2010-02-23 00:49 . 2009-12-30 22:48 -------- d-----w- c:\programdata\TuneUp Software
2010-02-23 00:49 . 2010-01-05 14:22 -------- d-----w- c:\programdata\EPSON
2010-02-23 00:49 . 2009-12-28 17:45 -------- d-----w- c:\programdata\CyberLink
2010-02-21 17:06 . 2009-12-28 17:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-20 20:57 . 2009-07-13 23:39 2755072 ----a-w- c:\windows\system32\themeui.dll
2010-02-20 20:57 . 2009-07-13 23:40 249856 ----a-w- c:\windows\system32\uxtheme.dll
2010-02-20 20:57 . 2009-07-13 23:39 37376 ----a-w- c:\windows\system32\themeservice.dll
2010-02-14 12:42 . 2009-12-30 22:14 -------- d-----w- c:\users\Juraj\AppData\Roaming\Skype
2010-02-14 12:23 . 2009-12-30 22:16 -------- d-----w- c:\users\Juraj\AppData\Roaming\skypePM
2010-02-09 18:23 . 2009-12-28 14:34 107072 ----a-w- c:\users\Juraj\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-09 07:58 . 2009-12-28 14:55 -------- d-----w- c:\program files\Microsoft Works
2010-02-08 23:10 . 2010-01-16 15:39 -------- d-----w- c:\programdata\NVIDIA
2010-02-02 10:04 . 2009-12-28 19:44 -------- d-----w- c:\program files\AGEIA Technologies
2010-02-01 05:59 . 2010-01-22 22:52 -------- d-----w- c:\program files\Google
2010-01-31 21:55 . 2009-12-30 22:14 -------- d-----r- c:\program files\Skype
2010-01-22 22:52 . 2010-01-22 22:52 -------- d-----w- c:\programdata\Google Updater
2010-01-20 20:17 . 2010-01-20 20:17 -------- d-----w- c:\users\Juraj\AppData\Roaming\DivX
2010-01-19 07:07 . 2010-01-14 19:45 -------- d-----w- c:\program files\ESET
2010-01-18 23:29 . 2010-02-09 19:33 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-09 19:33 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-09 19:33 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-09 19:33 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-09 19:33 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-09 19:33 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-09 19:33 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-09 19:33 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-16 15:48 . 2010-01-16 15:49 298104 ----a-w- c:\windows\system32\imon.dll
2010-01-14 20:55 . 2009-12-28 18:28 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-14 10:12 . 2009-12-28 13:56 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-12 06:51 . 2010-01-12 06:51 -------- d-----w- c:\program files\MOJOSOFT
2010-01-11 21:18 . 2010-01-11 21:18 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-11 21:18 . 2010-01-11 21:18 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-11 21:18 . 2010-01-11 21:18 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-11 21:18 . 2010-01-11 21:18 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-11 07:57 . 2010-01-10 17:36 -------- d-----w- c:\users\Juraj\AppData\Roaming\inkscape
2010-01-10 12:52 . 2010-01-10 12:52 -------- d-----w- c:\users\Juraj\AppData\Roaming\mojosoft
2010-01-08 03:18 . 2010-02-09 19:33 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-09 19:33 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-01-06 21:56 . 2010-01-06 21:56 -------- d-----w- c:\program files\CCleaner
2010-01-05 19:49 . 2010-01-05 19:49 -------- d-----w- c:\program files\MSXML 4.0
2010-01-05 18:31 . 2010-01-05 18:31 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-01-05 18:31 . 2010-01-05 18:31 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-05 18:06 . 2010-01-05 14:25 -------- d-----w- c:\program files\ABBYY FineReader 6.0 Sprint
2010-01-05 18:04 . 2010-01-05 14:55 -------- d-----w- c:\users\Juraj\AppData\Roaming\EPSON
2010-01-05 18:03 . 2010-01-05 18:02 -------- d-----w- c:\users\Juraj\AppData\Roaming\Scan2PDF
2010-01-05 18:02 . 2010-01-05 18:02 -------- d-----w- c:\program files\Scan2PDF
2010-01-05 14:26 . 2010-01-05 14:26 -------- d-----w- c:\programdata\UDL
2010-01-05 14:26 . 2010-01-05 14:26 -------- d-----w- c:\program files\Epson Software
2010-01-05 14:24 . 2010-01-05 14:21 -------- d-----w- c:\program files\epson
2010-01-05 07:44 . 2010-01-05 07:44 -------- d-----w- c:\users\Juraj\AppData\Roaming\Nero
2010-01-05 07:40 . 2010-01-05 07:23 -------- d-----w- c:\program files\Common Files\Nero
2010-01-05 07:33 . 2010-01-05 07:23 -------- d-----w- c:\program files\Nero
2010-01-05 06:50 . 2009-12-30 22:49 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-01-04 20:43 . 2010-01-04 20:43 -------- d-----w- c:\program files\OO Software
2010-01-04 13:39 . 2010-01-04 13:24 -------- d-----w- c:\program files\GoldWave
2010-01-01 19:43 . 2010-01-01 19:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-01-01 14:08 . 2010-01-01 14:07 -------- d-----w- c:\users\Juraj\AppData\Roaming\Vso
2010-01-01 14:07 . 2010-01-01 14:07 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-01-01 14:07 . 2010-01-01 14:07 47360 ----a-w- c:\users\Juraj\AppData\Roaming\pcouffin.sys
2010-01-01 14:07 . 2010-01-01 14:07 -------- d-----w- c:\program files\DVDFab 6
2010-01-01 13:05 . 2009-12-31 09:44 -------- d-----w- c:\users\Juraj\AppData\Roaming\dvdcss
2009-12-30 22:49 . 2009-12-30 22:49 -------- d-----w- c:\users\Juraj\AppData\Roaming\TuneUp Software
2009-12-30 22:16 . 2009-12-30 22:16 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-30 22:14 . 2009-12-30 22:14 -------- d-----w- c:\program files\Common Files\Skype
2009-12-30 21:16 . 2009-12-30 21:16 -------- d-----w- c:\users\Juraj\AppData\Roaming\Canon
2009-12-30 21:16 . 2009-12-30 21:16 -------- d-----w- c:\program files\Canon
2009-12-30 21:16 . 2009-12-30 21:16 -------- d-----w- c:\program files\Common Files\Canon
2009-12-30 21:00 . 2009-12-28 17:43 505128 ----a-w- c:\windows\system32\msvcp71.dll
2009-12-30 21:00 . 2009-12-28 17:43 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-30 21:00 . 2009-12-28 17:43 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-12-30 20:52 . 2009-12-28 17:44 -------- d-----w- c:\program files\CyberLink
2009-12-30 20:24 . 2009-12-30 20:24 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-28 22:27 . 2009-12-28 22:26 -------- d-----w- c:\users\Juraj\AppData\Roaming\Ashampoo
2009-12-28 22:26 . 2009-12-28 22:26 -------- d-----w- c:\programdata\ashampoo
2009-12-28 22:26 . 2009-12-28 22:26 -------- d-----w- c:\program files\Ashampoo
2009-12-28 22:23 . 2009-12-28 22:23 -------- d-----w- c:\program files\7-Zip
2009-12-28 21:34 . 2009-12-28 21:34 -------- d-----w- c:\program files\Codec Pack - All In 1
2009-12-28 21:34 . 2009-12-28 21:34 737280 ----a-w- c:\windows\iun6002.exe
2009-12-28 21:31 . 2009-12-28 21:31 -------- d-----w- c:\users\Juraj\AppData\Roaming\vlc
2009-12-28 21:30 . 2009-12-28 21:30 -------- d-----w- c:\program files\VideoLAN
2009-12-28 21:29 . 2009-12-28 21:25 262860 ----a-w- c:\windows\IPUI_DivXG400.exe
2009-12-28 20:19 . 2009-12-28 20:19 -------- d-----w- c:\users\Juraj\AppData\Roaming\Touchstone
2009-12-28 19:45 . 2009-12-28 19:45 -------- d-----w- c:\program files\Touchstone
2009-12-28 19:43 . 2009-12-28 19:43 -------- d-----w- c:\users\Juraj\AppData\Roaming\InstallShield
2009-12-28 19:17 . 2009-12-28 19:15 -------- d-----w- c:\program files\PDF Reader for Windows 7
2009-12-28 18:34 . 2009-12-28 18:34 -------- d-----w- c:\program files\Adobe Media Player
2009-12-28 18:33 . 2009-12-28 18:33 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-28 18:30 . 2009-12-28 18:30 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-01-29 1095872]
"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{D401E3DC-E916-4016-8D20-B4E6392481F9}"= "c:\windows\system32\cpsuboli.dll" [2009-12-14 131072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-07-14 01:14 1173504 ----a-w- c:\program files\Windows Sidebar\sidebar.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Juraj\AppData\Local\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"

R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/12/30 21:13];c:\program files\CyberLink\PowerDVD9\000.fcl [30.3.2009 17:53 87536]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [17.11.2009 10:15 1021256]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [2.12.2009 15:23 42368]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\System32\drivers\Rt86win7.sys [1.3.2009 23:05 139776]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
R3 ZSMC0305;A4 TECH PC Camera V;c:\windows\System32\drivers\usbVM305.sys [8.5.2006 17:24 391688]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [28.12.2009 19:23 691696]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [22.1.2010 23:53 135664]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-02-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-22 22:52]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-22 22:53]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-22 22:53]

2010-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001Core.job
- c:\users\Juraj\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-28 15:44]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001UA.job
- c:\users\Juraj\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-28 15:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\users\Juraj\AppData\Roaming\Mozilla\Firefox\Profiles\um3l6l9d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Juraj\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="DB5057C13AD3421E473ECA46CDEAE6F20D041777D58AC66715F1A4F0E1D9F3A72358BDC95DF86ABB3FCB1EC77F32EBDD2847A75B4A067C215D1913F21A74D9EE3498C299BC2B14C8FD3E16E9ADF6316840F25CC94607DD217A4846821501AB1EF86C771BBB68EB67427B9C0AD7510B398699983609648632AC62BBC9F834F0FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA2D97226D213B555A9C6AECB7A5D14073675077BA7231529A07CC5252B7A42019CAA5A091AC9208812DECC13B2E1B0DF2911F20CA778D55DEF51E3D277B7219655E32F2C8A5EF9E9EBE4E794A0EC14280B7F8A3317E1AFC4B1B41E50F40E34954032355FCC6C8F2B7EB4BD996D956A2DF9071A2DE23B31D029000CEF44B9E65B661D753059B0C5B1B82AE00B053BB87D67F261DA0AA31DDCEC0EBBAC9BB9D8A9A33468513A2D3CC8D8A056F166FE3A0B991013BD237D69A3E6BE2EA2C3D2DB2728847B190CA6C19EF37B1B7EA3485A302932D8FED370414557755912988DFA5A7726130082265AC6F4A01E03E5BF3D2605AF4FEBD9E60347CF99A4E00EB6ED32E8AE03A5E3F7C03517F7C076E6D4350D6E6404F18591C012B7186D97A75CA601A7BD164A8AAFDF46EAEFDBF276B9CE677BAC7C27BAE14171C8DE85637ED4C77AB4F10B55E49F5838D57AB9397863451E156D32C2F0907E9593E2319440B6A8B963EF13CF73637FAB908D99AAE28D8CFBFA0C0E9EB618A893799AA9A02FDE56B95BE053E64E55DCA92822AECEC2B4C7313C73F1BDA937A063B2039B9F1F6E8EDE197267ED1F1AAD1BFBB69E50B51CD14FC091B1C200717E61479B294FF947C4EBEAD3DC5AA49462CD434B067FEFC837CE42DA1675800E8BCE996766903D93A10CF53AB646B06D1FF5846773CCB886BA8A4CC4D9C1891846CE5A6E5D67F93E804C31DD68EE29933CA89D94E9506BE1D043444A2D37095E61E98FBB09FD56F7711E69FB5EB609B7C7603FDEDF44F5AEA31B5CE9348A8574C30E96DF5C2189B43656BDD57523DFCD7F7CEC58C10ADC029019A0A587139532080A9B6D3C40E12DC72E21AE7F5E4C905BBD02186D21B736A9AA6E85334DE431FB13A1FC007241DBD0445DCE443708FB80CB29B6B5333169331EF692B65836D023C002AAF6ED1D8332980C847B1EDBD14E31E3D16309097D2825BFDC85F7DB3633906594E192FDA6FC911EA055292697D35B078BAF139219B4D9A4760995BFC596E24A5EF25F808DFAF7D6F5F193D815551EBB0AC9E333A53BB6D0F59D3BDC2D6CFA8431D6F8D6C4287A4F5E68397B584C2EFC75D53268D2519A47F6909A43D88701BAB828A9469B31A87137431EA7B3E4A69E7BE957C0913F485E96A88597FE6E836723795D2827FB797F"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'Explorer.exe'(3076)
c:\windows\system32\cpsuboli.dll
.
Celkový čas: 2010-02-24 00:01:37
ComboFix-quarantined-files.txt 2010-02-23 23:01

Před spuštěním: Volných bajtů: 65 332 621 312
Po spuštění: Volných bajtů: 65 279 361 024

- - End Of File - - 78B6EF9DAF0412395A5522A3D1940FD1

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod jaro3 » 24 úno 2010 06:30

OK.

Na odinstalaci NORTON /SYMANTEC použij toto:
ftp://ftp.symantec.com/public/english_u ... l_Tool.exe
Na odinstalaci ESET:
http://www.nod32.nl/download/tool/nod32removal.exe

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.

Ve správci úloh zastav proces :
cpsuboli.dll

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KIllAll::
File::
c:\windows\system32\imon.dll
c:\windows\system32\ezsidmv.dat
c:\windows\system32\cpsuboli.dll

Folder::
c:\programdata\Norton
c:\programdata\NortonInstaller
c:\program files\ESET

Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]   
"{D401E3DC-E916-4016-8D20-B4E6392481F9}"=-

DDS::
uInternet Settings,ProxyOverride = local

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
abrit
Level 1
Level 1
Příspěvky: 83
Registrován: březen 08
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod abrit » 24 úno 2010 13:14

Odinstalátor Nod se ani nespustil. Napsalo to spustit a po potvrzení nic. A NOD nemám nainstalovaný. Měl jsem ho po instalaci systému, ale dělal problémy, tak jsem tam dal Avast a později essential. Vše bylo bez firewallu. Jedině, že jsou někde zbytky starých antivirů. Ale kde? Ten Norton Symantec mě po odklikáni OK odkáže na stáhnutí nové aplikace, ale ta moje tam není. Kterou mám stáhnout? Je jich tam 10.

http://www.symantec.com/cs/cz/norton/su ... d=Symantec

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod jaro3 » 24 úno 2010 14:34

Zkus toto:
http://service1.symantec.com/SUPPORT/ts ... 250066dc94
nevím ,jaký z jakého je roku.Když to nepůjde , tak to nech a pokračuj dál.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
abrit
Level 1
Level 1
Příspěvky: 83
Registrován: březen 08
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod abrit » 24 úno 2010 14:53

Udělal jsem ComboFix, RSIT a tady posílám logy. Ve správci úloh jsem nenašel cpsuboli.dll, tak jsem to nezastavil. NOD nevidím ani v regeditu. Jinak jsem udělal všechno podle tvých rad. Tady jsou logy:

ComboFix:
ComboFix 10-02-23.04 - Juraj 24.02.2010 14:03:57.4.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3071.2397 [GMT 1:00]
Spuštěný z: c:\users\Juraj\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Juraj\Desktop\CFScript.txt

FILE ::
"c:\windows\system32\cpsuboli.dll"
"c:\windows\system32\ezsidmv.dat"
"c:\windows\system32\imon.dll"
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-01-24 do 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-24 13:12 . 2010-02-24 13:13 -------- d-----w- c:\users\Juraj\AppData\Local\temp
2010-02-24 13:12 . 2010-02-24 13:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-23 12:36 . 2010-02-23 12:36 -------- d-----w- c:\users\Juraj\AppData\Roaming\Malwarebytes
2010-02-23 12:36 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 12:36 . 2010-02-23 12:36 -------- d-----w- c:\programdata\Malwarebytes
2010-02-23 12:36 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 12:36 . 2010-02-23 12:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 08:33 . 2010-02-23 20:00 -------- d-----w- c:\program files\trend micro
2010-02-22 23:53 . 2010-02-22 23:53 -------- d-----w- c:\users\Juraj\AppData\Local\VS Revo Group
2010-02-19 07:49 . 2010-02-19 07:49 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-19 00:28 . 2010-02-19 00:28 -------- d-----w- c:\users\Juraj\AppData\Roaming\Zoner
2010-02-19 00:28 . 2010-02-19 00:28 -------- d-----w- c:\users\Juraj\AppData\Local\Zoner
2010-02-19 00:27 . 2010-02-19 00:27 -------- d-----w- c:\program files\Zoner
2010-02-17 18:53 . 2010-02-17 18:53 -------- d-----w- c:\program files\PowerISO
2010-02-14 18:25 . 2010-02-14 18:25 -------- d-----w- c:\program files\Common Files\Windows Live
2010-02-13 22:47 . 2010-02-23 00:50 -------- d-----w- c:\users\Juraj\AppData\Roaming\GRETECH
2010-02-13 22:46 . 2010-02-23 00:50 -------- d-----w- c:\program files\GRETECH
2010-02-10 10:28 . 2010-02-10 10:28 -------- d-----w- c:\users\Juraj\AppData\Roaming\Media Player Classic
2010-02-10 09:24 . 2010-02-10 09:24 -------- d-----w- c:\program files\Essentials Codec Pack
2010-02-09 00:21 . 2010-02-09 00:21 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-02-08 23:10 . 2010-02-08 23:10 -------- d-----w- c:\program files\NVIDIA Corporation
2010-02-02 10:17 . 2010-02-14 13:06 -------- d-----w- c:\program files\Electronic Arts
2010-01-28 22:41 . 2010-01-28 22:41 -------- d-----w- c:\programdata\Easy CD-DA Extractor
2010-01-28 22:40 . 2010-01-28 22:40 -------- d-----w- c:\program files\Easy CD-DA Extractor
2010-01-27 23:05 . 2010-01-27 23:05 -------- d-----w- c:\users\Juraj\AppData\Local\RapidShare
2010-01-27 12:21 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-01-27 12:21 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-01-25 22:25 . 2010-02-21 17:06 -------- d-----w- c:\program files\Ubisoft
2010-01-25 18:38 . 2010-01-25 18:38 -------- d-----w- c:\programdata\Solidshield

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 12:37 . 2009-07-14 08:44 622422 ----a-w- c:\windows\system32\perfh005.dat
2010-02-23 12:37 . 2009-07-14 08:44 118604 ----a-w- c:\windows\system32\perfc005.dat
2010-02-23 07:45 . 2010-01-01 14:19 -------- d-----w- c:\users\Juraj\AppData\Roaming\uTorrent
2010-02-23 07:40 . 2010-01-01 14:19 -------- d-----w- c:\program files\uTorrent
2010-02-23 07:35 . 2010-01-01 14:57 -------- d-----w- c:\program files\Wise Disk Cleaner
2010-02-23 00:50 . 2009-12-30 22:48 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-02-23 00:50 . 2009-12-28 14:09 -------- d-----w- c:\users\Juraj\AppData\Roaming\GHISLER
2010-02-23 00:50 . 2010-01-05 07:23 -------- d-----w- c:\programdata\Nero
2010-02-23 00:50 . 2009-12-30 22:14 -------- d-----w- c:\programdata\Skype
2010-02-23 00:50 . 2009-12-28 14:34 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2010-02-23 00:50 . 2009-12-28 17:56 -------- d-----w- c:\program files\VS Revo Group
2010-02-23 00:50 . 2009-12-28 14:50 -------- d-----w- c:\programdata\Microsoft Help
2010-02-23 00:49 . 2009-12-30 22:48 -------- d-----w- c:\programdata\TuneUp Software
2010-02-23 00:49 . 2010-01-05 14:22 -------- d-----w- c:\programdata\EPSON
2010-02-23 00:49 . 2009-12-28 17:45 -------- d-----w- c:\programdata\CyberLink
2010-02-21 17:06 . 2009-12-28 17:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-20 20:57 . 2009-07-13 23:39 2755072 ----a-w- c:\windows\system32\themeui.dll
2010-02-20 20:57 . 2009-07-13 23:40 249856 ----a-w- c:\windows\system32\uxtheme.dll
2010-02-20 20:57 . 2009-07-13 23:39 37376 ----a-w- c:\windows\system32\themeservice.dll
2010-02-14 12:42 . 2009-12-30 22:14 -------- d-----w- c:\users\Juraj\AppData\Roaming\Skype
2010-02-14 12:23 . 2009-12-30 22:16 -------- d-----w- c:\users\Juraj\AppData\Roaming\skypePM
2010-02-09 18:23 . 2009-12-28 14:34 107072 ----a-w- c:\users\Juraj\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-09 07:58 . 2009-12-28 14:55 -------- d-----w- c:\program files\Microsoft Works
2010-02-08 23:10 . 2010-01-16 15:39 -------- d-----w- c:\programdata\NVIDIA
2010-02-02 10:04 . 2009-12-28 19:44 -------- d-----w- c:\program files\AGEIA Technologies
2010-02-01 05:59 . 2010-01-22 22:52 -------- d-----w- c:\program files\Google
2010-01-31 21:55 . 2009-12-30 22:14 -------- d-----r- c:\program files\Skype
2010-01-29 11:32 . 2010-01-25 11:45 -------- d-----w- c:\programdata\FLEXnet
2010-01-22 22:52 . 2010-01-22 22:52 -------- d-----w- c:\programdata\Google Updater
2010-01-20 20:17 . 2010-01-20 20:17 -------- d-----w- c:\users\Juraj\AppData\Roaming\DivX
2010-01-18 23:29 . 2010-02-09 19:33 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-09 19:33 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-09 19:33 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-09 19:33 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-09 19:33 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-09 19:33 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-09 19:33 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-09 19:33 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-14 20:55 . 2009-12-28 18:28 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-14 10:12 . 2009-12-28 13:56 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-12 06:51 . 2010-01-12 06:51 -------- d-----w- c:\program files\MOJOSOFT
2010-01-11 21:18 . 2010-01-11 21:18 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-11 21:18 . 2010-01-11 21:18 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-11 21:18 . 2010-01-11 21:18 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-11 21:18 . 2010-01-11 21:18 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-11 07:57 . 2010-01-10 17:36 -------- d-----w- c:\users\Juraj\AppData\Roaming\inkscape
2010-01-10 12:52 . 2010-01-10 12:52 -------- d-----w- c:\users\Juraj\AppData\Roaming\mojosoft
2010-01-08 03:18 . 2010-02-09 19:33 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-09 19:33 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-01-06 21:56 . 2010-01-06 21:56 -------- d-----w- c:\program files\CCleaner
2010-01-05 19:49 . 2010-01-05 19:49 -------- d-----w- c:\program files\MSXML 4.0
2010-01-05 18:31 . 2010-01-05 18:31 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-01-05 18:31 . 2010-01-05 18:31 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-05 18:06 . 2010-01-05 14:25 -------- d-----w- c:\program files\ABBYY FineReader 6.0 Sprint
2010-01-05 18:04 . 2010-01-05 14:55 -------- d-----w- c:\users\Juraj\AppData\Roaming\EPSON
2010-01-05 18:03 . 2010-01-05 18:02 -------- d-----w- c:\users\Juraj\AppData\Roaming\Scan2PDF
2010-01-05 18:02 . 2010-01-05 18:02 -------- d-----w- c:\program files\Scan2PDF
2010-01-05 14:26 . 2010-01-05 14:26 -------- d-----w- c:\programdata\UDL
2010-01-05 14:26 . 2010-01-05 14:26 -------- d-----w- c:\program files\Epson Software
2010-01-05 14:24 . 2010-01-05 14:21 -------- d-----w- c:\program files\epson
2010-01-05 07:44 . 2010-01-05 07:44 -------- d-----w- c:\users\Juraj\AppData\Roaming\Nero
2010-01-05 07:40 . 2010-01-05 07:23 -------- d-----w- c:\program files\Common Files\Nero
2010-01-05 07:33 . 2010-01-05 07:23 -------- d-----w- c:\program files\Nero
2010-01-05 06:50 . 2009-12-30 22:49 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-01-04 20:43 . 2010-01-04 20:43 -------- d-----w- c:\program files\OO Software
2010-01-04 13:39 . 2010-01-04 13:24 -------- d-----w- c:\program files\GoldWave
2010-01-01 19:43 . 2010-01-01 19:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-01-01 14:08 . 2010-01-01 14:07 -------- d-----w- c:\users\Juraj\AppData\Roaming\Vso
2010-01-01 14:07 . 2010-01-01 14:07 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-01-01 14:07 . 2010-01-01 14:07 47360 ----a-w- c:\users\Juraj\AppData\Roaming\pcouffin.sys
2010-01-01 14:07 . 2010-01-01 14:07 -------- d-----w- c:\program files\DVDFab 6
2010-01-01 13:05 . 2009-12-31 09:44 -------- d-----w- c:\users\Juraj\AppData\Roaming\dvdcss
2009-12-30 22:49 . 2009-12-30 22:49 -------- d-----w- c:\users\Juraj\AppData\Roaming\TuneUp Software
2009-12-30 22:14 . 2009-12-30 22:14 -------- d-----w- c:\program files\Common Files\Skype
2009-12-30 21:16 . 2009-12-30 21:16 -------- d-----w- c:\users\Juraj\AppData\Roaming\Canon
2009-12-30 21:16 . 2009-12-30 21:16 -------- d-----w- c:\program files\Canon
2009-12-30 21:16 . 2009-12-30 21:16 -------- d-----w- c:\program files\Common Files\Canon
2009-12-30 21:00 . 2009-12-28 17:43 505128 ----a-w- c:\windows\system32\msvcp71.dll
2009-12-30 21:00 . 2009-12-28 17:43 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-30 21:00 . 2009-12-28 17:43 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-12-30 20:52 . 2009-12-28 17:44 -------- d-----w- c:\program files\CyberLink
2009-12-30 20:24 . 2009-12-30 20:24 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-28 22:27 . 2009-12-28 22:26 -------- d-----w- c:\users\Juraj\AppData\Roaming\Ashampoo
2009-12-28 22:26 . 2009-12-28 22:26 -------- d-----w- c:\programdata\ashampoo
2009-12-28 22:26 . 2009-12-28 22:26 -------- d-----w- c:\program files\Ashampoo
2009-12-28 22:23 . 2009-12-28 22:23 -------- d-----w- c:\program files\7-Zip
2009-12-28 21:34 . 2009-12-28 21:34 -------- d-----w- c:\program files\Codec Pack - All In 1
2009-12-28 21:34 . 2009-12-28 21:34 737280 ----a-w- c:\windows\iun6002.exe
2009-12-28 21:31 . 2009-12-28 21:31 -------- d-----w- c:\users\Juraj\AppData\Roaming\vlc
2009-12-28 21:30 . 2009-12-28 21:30 -------- d-----w- c:\program files\VideoLAN
2009-12-28 21:29 . 2009-12-28 21:25 262860 ----a-w- c:\windows\IPUI_DivXG400.exe
2009-12-28 20:19 . 2009-12-28 20:19 -------- d-----w- c:\users\Juraj\AppData\Roaming\Touchstone
2009-12-28 19:45 . 2009-12-28 19:45 -------- d-----w- c:\program files\Touchstone
2009-12-28 19:43 . 2009-12-28 19:43 -------- d-----w- c:\users\Juraj\AppData\Roaming\InstallShield
2009-12-28 19:17 . 2009-12-28 19:15 -------- d-----w- c:\program files\PDF Reader for Windows 7
2009-12-28 18:34 . 2009-12-28 18:34 -------- d-----w- c:\program files\Adobe Media Player
2009-12-28 18:33 . 2009-12-28 18:33 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-28 18:30 . 2009-12-28 18:30 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-28 18:26 . 2009-12-28 18:23 -------- d-----w- c:\users\Juraj\AppData\Roaming\DAEMON Tools Lite
2009-12-28 18:23 . 2009-12-28 18:23 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-02-23_22.09.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-28 14:25 . 2010-02-24 13:01 35260 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-02-24 13:01 46470 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-12-28 13:49 . 2010-02-23 22:00 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-28 13:49 . 2010-02-24 13:13 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-28 13:49 . 2010-02-24 13:13 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-28 13:49 . 2010-02-23 22:00 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:41 . 2010-02-23 22:00 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:41 . 2010-02-24 13:13 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-28 13:53 . 2010-02-24 13:13 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-28 13:53 . 2010-02-23 22:02 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-28 13:53 . 2010-02-23 22:02 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-28 13:53 . 2010-02-24 13:13 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-28 13:53 . 2010-02-23 22:02 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-28 13:53 . 2010-02-24 13:13 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-28 13:59 . 2010-02-23 22:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-28 13:59 . 2010-02-24 13:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-28 13:59 . 2010-02-23 22:03 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-28 13:59 . 2010-02-24 13:00 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-28 13:59 . 2010-02-24 13:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-28 13:59 . 2010-02-23 22:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-28 14:00 . 2010-02-24 13:01 9846 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-493450829-1978892065-3572238591-1001_UserData.bin
+ 2010-02-24 12:59 . 2010-02-24 13:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-02-23 22:00 . 2010-02-23 22:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-02-24 12:59 . 2010-02-24 13:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-02-23 22:00 . 2010-02-23 22:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-01-29 1095872]
"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-07-14 01:14 1173504 ----a-w- c:\program files\Windows Sidebar\sidebar.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Juraj\AppData\Local\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"

R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/12/30 21:13];c:\program files\CyberLink\PowerDVD9\000.fcl [30.3.2009 17:53 87536]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [17.11.2009 10:15 1021256]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [2.12.2009 15:23 42368]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\System32\drivers\Rt86win7.sys [1.3.2009 23:05 139776]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 7:24 10064]
R3 ZSMC0305;A4 TECH PC Camera V;c:\windows\System32\drivers\usbVM305.sys [8.5.2006 17:24 391688]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [22.1.2010 23:53 135664]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-02-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-22 22:52]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-22 22:53]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-22 22:53]

2010-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001Core.job
- c:\users\Juraj\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-28 15:44]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001UA.job
- c:\users\Juraj\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-28 15:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\users\Juraj\AppData\Roaming\Mozilla\Firefox\Profiles\um3l6l9d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Juraj\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x84F7E1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xe5726854
SecurityProcedure -> 0x1
QueryNameProcedure -> 0x8be05d96
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="DB5057C13AD3421E473ECA46CDEAE6F20D041777D58AC66715F1A4F0E1D9F3A72358BDC95DF86ABB3FCB1EC77F32EBDD2847A75B4A067C215D1913F21A74D9EE3498C299BC2B14C8FD3E16E9ADF6316840F25CC94607DD217A4846821501AB1EF86C771BBB68EB67427B9C0AD7510B398699983609648632AC62BBC9F834F0FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA2D97226D213B555A9C6AECB7A5D14073675077BA7231529A07CC5252B7A42019CAA5A091AC9208812DECC13B2E1B0DF2911F20CA778D55DEF51E3D277B7219655E32F2C8A5EF9E9EBE4E794A0EC14280B7F8A3317E1AFC4B1B41E50F40E34954032355FCC6C8F2B7EB4BD996D956A2DF9071A2DE23B31D029000CEF44B9E65B661D753059B0C5B1B82AE00B053BB87D67F261DA0AA31DDCEC0EBBAC9BB9D8A9A33468513A2D3CC8D8A056F166FE3A0B991013BD237D69A3E6BE2EA2C3D2DB2728847B190CA6C19EF37B1B7EA3485A302932D8FED370414557755912988DFA5A7726130082265AC6F4A01E03E5BF3D2605AF4FEBD9E60347CF99A4E00EB6ED32E8AE03A5E3F7C03517F7C076E6D4350D6E6404F18591C012B7186D97A75CA601A7BD164A8AAFDF46EAEFDBF276B9CE677BAC7C27BAE14171C8DE85637ED4C77AB4F10B55E49F5838D57AB9397863451E156D32C2F0907E9593E2319440B6A8B963EF13CF73637FAB908D99AAE28D8CFBFA0C0E9EB618A893799AA9A02FDE56B95BE053E64E55DCA92822AECEC2B4C7313C73F1BDA937A063B2039B9F1F6E8EDE197267ED1F1AAD1BFBB69E50B51CD14FC091B1C200717E61479B294FF947C4EBEAD3DC5AA49462CD434B067FEFC837CE42DA1675800E8BCE996766903D93A10CF53AB646B06D1FF5846773CCB886BA8A4CC4D9C1891846CE5A6E5D67F93E804C31DD68EE29933CA89D94E9506BE1D043444A2D37095E61E98FBB09FD56F7711E69FB5EB609B7C7603FDEDF44F5AEA31B5CE9348A8574C30E96DF5C2189B43656BDD57523DFCD7F7CEC58C10ADC029019A0A587139532080A9B6D3C40E12DC72E21AE7F5E4C905BBD02186D21B736A9AA6E85334DE431FB13A1FC007241DBD0445DCE443708FB80CB29B6B5333169331EF692B65836D023C002AAF6ED1D8332980C847B1EDBD14E31E3D16309097D2825BFDC85F7DB3633906594E192FDA6FC911EA055292697D35B078BAF139219B4D9A4760995BFC596E24A5EF25F808DFAF7D6F5F193D815551EBB0AC9E333A53BB6D0F59D3BDC2D6CFA8431D6F8D6C4287A4F5E68397B584C2EFC75D53268D2519A47F6909A43D88701BAB828A9469B31A87137431EA7B3E4A69E7BE957C0913F485E96A88597FE6E836723795D2827FB797F"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\programdata\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\programdata\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\oodag.exe
c:\windows\system32\conhost.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2010-02-24 14:20:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-24 13:20
ComboFix2.txt 2010-02-24 12:53
ComboFix3.txt 2010-02-23 23:01

Před spuštěním: Volných bajtů: 65 153 187 840
Po spuštění: Volných bajtů: 65 040 011 264

- - End Of File - - BF25658A8C8E3C2254B4D15D3652CEE8

Uživatelský avatar
abrit
Level 1
Level 1
Příspěvky: 83
Registrován: březen 08
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod abrit » 24 úno 2010 14:54

A tady je log RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Juraj at 2010-02-24 14:21:54
Microsoft Windows 7 Ultimate Service Pack 3
System drive C: has 62 GB (62%) free of 100 GB
Total RAM: 3071 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:22:52, on 24.2.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\VM305_STI.EXE
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Windows\Explorer.exe
C:\Users\Juraj\Desktop\RSIT.exe
C:\Program Files\trend micro\Juraj.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [BigDog305] C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 3977 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-493450829-1978892065-3572238591-1001UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2010-01-22 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-28 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-01-29 1095872]
"BigDog305"=C:\Windows\VM305_STI.EXE [2005-08-05 61440]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-02-24 14:21:54 ----D---- C:\rsit
2010-02-24 14:20:24 ----D---- C:\Windows\temp
2010-02-24 14:20:22 ----A---- C:\ComboFix.txt
2010-02-24 14:13:30 ----D---- C:\$RECYCLE.BIN
2010-02-24 13:58:38 ----A---- C:\Windows\SWXCACLS.exe
2010-02-23 23:00:16 ----A---- C:\Windows\zip.exe
2010-02-23 23:00:16 ----A---- C:\Windows\SWREG.exe
2010-02-23 23:00:16 ----A---- C:\Windows\sed.exe
2010-02-23 23:00:16 ----A---- C:\Windows\PEV.exe
2010-02-23 23:00:16 ----A---- C:\Windows\NIRCMD.exe
2010-02-23 23:00:16 ----A---- C:\Windows\MBR.exe
2010-02-23 23:00:16 ----A---- C:\Windows\grep.exe
2010-02-23 23:00:15 ----A---- C:\Windows\SWSC.exe
2010-02-23 23:00:06 ----D---- C:\Windows\ERDNT
2010-02-23 22:58:51 ----D---- C:\Qoobox
2010-02-23 13:36:32 ----D---- C:\Users\Juraj\AppData\Roaming\Malwarebytes
2010-02-23 13:36:26 ----D---- C:\ProgramData\Malwarebytes
2010-02-23 13:36:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-23 09:33:41 ----D---- C:\Program Files\trend micro
2010-02-20 21:57:32 ----A---- C:\Windows\system32\themeui.dll.backup
2010-02-20 21:57:21 ----A---- C:\Windows\system32\uxtheme.dll.backup
2010-02-20 21:57:18 ----A---- C:\Windows\system32\themeservice.dll.backup
2010-02-20 21:47:32 ----A---- C:\Windows\system32\zipfldr.dll.bak
2010-02-20 21:47:32 ----A---- C:\Windows\system32\shell32.dll.bak
2010-02-20 21:47:32 ----A---- C:\Windows\system32\imagesp1.dll.bak
2010-02-20 21:47:32 ----A---- C:\Windows\system32\imageres.dll.bak
2010-02-19 08:49:38 ----D---- C:\Program Files\Microsoft Security Essentials
2010-02-19 01:28:40 ----D---- C:\Users\Juraj\AppData\Roaming\Zoner
2010-02-19 01:27:11 ----D---- C:\Program Files\Zoner
2010-02-17 19:53:19 ----D---- C:\Program Files\PowerISO
2010-02-14 19:25:37 ----D---- C:\Program Files\Common Files\Windows Live
2010-02-13 23:47:25 ----D---- C:\Users\Juraj\AppData\Roaming\GRETECH
2010-02-13 23:46:51 ----D---- C:\Program Files\GRETECH
2010-02-10 11:28:13 ----D---- C:\Users\Juraj\AppData\Roaming\Media Player Classic
2010-02-10 10:24:23 ----D---- C:\Program Files\Essentials Codec Pack
2010-02-09 20:33:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-09 20:33:40 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-09 20:33:40 ----A---- C:\Windows\system32\kernel32.dll
2010-02-09 20:33:40 ----A---- C:\Windows\system32\apphelp.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\quartz.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\msyuv.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\msrle32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-09 20:33:39 ----A---- C:\Windows\system32\avifil32.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\secproc.dll
2010-02-09 20:33:37 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-09 20:33:37 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-09 20:33:37 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-09 20:33:36 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-09 00:10:05 ----D---- C:\Program Files\NVIDIA Corporation
2010-02-02 11:17:29 ----D---- C:\Program Files\Electronic Arts
2010-01-28 23:41:00 ----D---- C:\ProgramData\Easy CD-DA Extractor
2010-01-28 23:40:56 ----D---- C:\Program Files\Easy CD-DA Extractor
2010-01-27 13:21:38 ----A---- C:\Windows\system32\winlogon.exe
2010-01-27 13:21:38 ----A---- C:\Windows\explorer.exe
2010-01-25 23:25:23 ----D---- C:\Program Files\Ubisoft
2010-01-25 19:38:14 ----D---- C:\ProgramData\Solidshield
2010-01-25 19:22:46 ----A---- C:\Windows\system32\XAudio2_4.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\D3DX9_41.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\d3dx10_41.dll
2010-01-25 19:22:46 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\XAudio2_3.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\xactengine3_4.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\xactengine3_3.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-01-25 19:22:45 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\XAudio2_2.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\xactengine3_2.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\D3DX9_39.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-01-25 19:22:44 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-01-25 19:22:43 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-01-25 19:22:42 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-01-25 19:22:41 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-01-25 19:22:40 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\xinput1_3.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-01-25 19:22:39 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xinput1_2.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-01-25 19:22:38 ----A---- C:\Windows\system32\d3dx10.dll
2010-01-25 19:22:37 ----A---- C:\Windows\system32\xinput1_1.dll
2010-01-25 19:22:37 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-01-25 19:22:37 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-01-25 19:22:33 ----A---- C:\Windows\system32\d3dx9_26.dll
2010-01-25 19:22:32 ----A---- C:\Windows\system32\d3dx9_25.dll
2010-01-25 19:22:32 ----A---- C:\Windows\system32\d3dx9_24.dll
2010-01-25 12:45:13 ----D---- C:\ProgramData\FLEXnet

======List of files/folders modified in the last 1 months======

2010-02-24 14:22:06 ----D---- C:\Windows\Prefetch
2010-02-24 14:20:25 ----D---- C:\Windows\system32\drivers
2010-02-24 14:20:24 ----D---- C:\Windows
2010-02-24 14:15:31 ----D---- C:\Windows\Tasks
2010-02-24 14:13:34 ----A---- C:\Windows\system.ini
2010-02-24 14:10:14 ----D---- C:\Windows\System32
2010-02-24 14:10:14 ----D---- C:\Windows\AppPatch
2010-02-24 14:10:14 ----D---- C:\Program Files\Common Files
2010-02-24 13:45:07 ----D---- C:\ProgramData
2010-02-24 13:03:51 ----RD---- C:\Program Files
2010-02-24 12:59:45 ----SHD---- C:\System Volume Information
2010-02-23 22:15:33 ----D---- C:\Windows\system32\Tasks
2010-02-23 20:58:06 ----D---- C:\Windows\Microsoft.NET
2010-02-23 20:06:38 ----D---- C:\Windows\system32\config
2010-02-23 13:37:17 ----D---- C:\Windows\inf
2010-02-23 13:37:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-02-23 08:45:11 ----D---- C:\Users\Juraj\AppData\Roaming\uTorrent
2010-02-23 08:40:06 ----D---- C:\Program Files\uTorrent
2010-02-23 08:35:27 ----D---- C:\Program Files\Wise Disk Cleaner
2010-02-23 01:51:16 ----D---- C:\Windows\system32\wfp
2010-02-23 01:51:14 ----D---- C:\Windows\system32\wbem
2010-02-23 01:50:31 ----SHD---- C:\Windows\BitLockerDiscoveryVolumeContents
2010-02-23 01:50:31 ----D---- C:\Windows\system32\DriverStore
2010-02-23 01:50:31 ----D---- C:\Windows\system32\catroot2
2010-02-23 01:50:22 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-02-23 01:50:22 ----D---- C:\Users\Juraj\AppData\Roaming\GHISLER
2010-02-23 01:50:21 ----D---- C:\ProgramData\Skype
2010-02-23 01:50:21 ----D---- C:\ProgramData\PC Drivers HeadQuarters
2010-02-23 01:50:21 ----D---- C:\ProgramData\Nero
2010-02-23 01:50:21 ----AD---- C:\ProgramData\Temp
2010-02-23 01:50:20 ----SD---- C:\ProgramData\Microsoft
2010-02-23 01:50:20 ----D---- C:\ProgramData\Microsoft Help
2010-02-23 01:50:20 ----D---- C:\Program Files\VS Revo Group
2010-02-23 01:50:13 ----D---- C:\Windows\registration
2010-02-23 01:49:58 ----SD---- C:\Users\Juraj\AppData\Roaming\Microsoft
2010-02-23 01:49:57 ----D---- C:\ProgramData\TuneUp Software
2010-02-23 01:49:54 ----D---- C:\ProgramData\EPSON
2010-02-23 01:49:54 ----D---- C:\ProgramData\CyberLink
2010-02-21 18:06:27 ----D---- C:\Windows\system32\NDF
2010-02-21 18:06:22 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-20 21:57:32 ----A---- C:\Windows\system32\themeui.dll
2010-02-20 21:57:21 ----A---- C:\Windows\system32\uxtheme.dll
2010-02-20 21:57:18 ----A---- C:\Windows\system32\themeservice.dll
2010-02-19 11:31:56 ----D---- C:\Windows\system32\catroot
2010-02-19 08:49:52 ----SHD---- C:\Windows\Installer
2010-02-14 13:42:13 ----D---- C:\Users\Juraj\AppData\Roaming\Skype
2010-02-14 13:23:25 ----D---- C:\Users\Juraj\AppData\Roaming\skypePM
2010-02-13 12:58:58 ----D---- C:\Windows\debug
2010-02-09 22:43:48 ----D---- C:\Windows\winsxs
2010-02-09 21:43:30 ----RSD---- C:\Windows\assembly
2010-02-09 08:58:44 ----RSD---- C:\Windows\Fonts
2010-02-09 08:58:41 ----D---- C:\Program Files\Common Files\microsoft shared
2010-02-09 08:58:35 ----D---- C:\Program Files\Microsoft Works
2010-02-09 00:39:41 ----D---- C:\Program Files\Mozilla Firefox
2010-02-09 00:10:41 ----D---- C:\ProgramData\NVIDIA
2010-02-03 13:04:39 ----D---- C:\Program Files\WinRAR
2010-02-02 11:04:06 ----D---- C:\Program Files\AGEIA Technologies
2010-02-01 20:26:20 ----A---- C:\Windows\system32\MRT.exe
2010-02-01 06:59:36 ----D---- C:\Program Files\Google
2010-01-31 22:55:18 ----RD---- C:\Program Files\Skype
2010-01-29 22:11:50 ----A---- C:\Windows\NeroDigital.ini
2010-01-28 23:28:43 ----D---- C:\Windows\Easy CD-DA Extractor 11.9.9 build 668
2010-01-27 14:01:39 ----D---- C:\Program Files\Internet Explorer
2010-01-25 19:22:08 ----D---- C:\Windows\Logs

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 blbdrive;blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys [2009-07-14 35328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 DfsC;@%systemroot%\system32\drivers\dfsc.sys,-101; C:\Windows\System32\Drivers\dfsc.sys [2009-07-14 78336]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys [2009-07-14 16896]
R1 RDPENCDD;@%systemroot%\system32\drivers\RDPENCDD.sys,-101; C:\Windows\system32\drivers\rdpencdd.sys [2009-07-14 6656]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-11-09 59388]
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys [2009-07-14 74240]
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys [2009-07-14 63488]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/12/30 21:13:19]; \??\C:\Program Files\CyberLink\PowerDVD9\000.fcl [2009-03-30 87536]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-08-14 74720]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver; C:\Windows\system32\DRIVERS\lltdio.sys [2009-07-14 48128]
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys [2009-07-14 86528]
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys [2009-07-14 586752]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\Windows\system32\DRIVERS\rspndr.sys [2009-07-14 60928]
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys [2009-07-14 34816]
R3 AmdK8;Ovladač procesoru AMD K8; C:\Windows\system32\DRIVERS\amdk8.sys [2009-07-14 55296]
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys [2009-07-14 69632]
R3 CompositeBus;Ovladač rozpoznávacího modulu složené sběrnice; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys [2009-10-02 728648]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 HDAudBus;Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio; C:\Windows\system32\DRIVERS\HDAudBus.sys [2009-07-14 108544]
R3 monitor;Služba ovladače funkce třídy monitorů Microsoft; C:\Windows\system32\DRIVERS\monitor.sys [2009-07-14 23552]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys [2009-07-14 60416]
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys [2010-01-08 221184]
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys [2009-07-14 95744]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-01-12 11586280]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-01-01 47360]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys [2009-07-14 75264]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys [2009-07-14 306688]
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [2009-12-08 113664]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys [2009-07-14 108544]
R3 umbus;Ovladač sběrnice UMBus Enumerator; C:\Windows\system32\DRIVERS\umbus.sys [2009-07-14 39936]
R3 usbehci;Ovladač miniportu vylepšeného hostitelského řadiče Microsoft USB 2.0; C:\Windows\system32\DRIVERS\usbehci.sys [2009-07-14 41472]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\Windows\system32\DRIVERS\usbhub.sys [2009-07-14 258560]
R3 usbohci;Ovladač miniportu otevřeného hostitelského řadiče Microsoft USB; C:\Windows\system32\DRIVERS\usbohci.sys [2009-07-14 20480]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
R3 ZSMC0305;A4 TECH PC Camera V; C:\Windows\System32\Drivers\usbVM305.sys [2006-05-08 391688]
S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 adp94xx;adp94xx; C:\Windows\system32\DRIVERS\adp94xx.sys [2009-07-14 422976]
S3 adpahci;adpahci; C:\Windows\system32\DRIVERS\adpahci.sys [2009-07-14 297552]
S3 adpu320;adpu320; C:\Windows\system32\DRIVERS\adpu320.sys [2009-07-14 146512]
S3 agp440;Intel AGP Bus Filter; C:\Windows\system32\DRIVERS\agp440.sys [2009-07-14 53312]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 amdide;amdide; C:\Windows\system32\DRIVERS\amdide.sys [2009-07-14 14912]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 arc;arc; C:\Windows\system32\DRIVERS\arc.sys [2009-07-14 76368]
S3 arcsas;arcsas; C:\Windows\system32\DRIVERS\arcsas.sys [2009-07-14 86608]
S3 ay8617qu;ay8617qu; C:\Windows\system32\drivers\ay8617qu.sys []
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver; C:\Windows\system32\DRIVERS\BrFiltLo.sys [2009-07-13 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver; C:\Windows\system32\DRIVERS\BrFiltUp.sys [2009-07-13 5248]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM); C:\Windows\System32\Drivers\Brserid.sys [2009-07-14 272128]
S3 BrSerWdm;Brother WDM Serial driver; C:\Windows\System32\Drivers\BrSerWdm.sys [2009-07-13 62336]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem; C:\Windows\System32\Drivers\BrUsbMdm.sys [2009-07-13 12160]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\Windows\System32\Drivers\BrUsbSer.sys [2009-07-13 11904]
S3 btaudio;Bluetooth Audio Device; C:\Windows\system32\drivers\btaudio.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\Windows\system32\DRIVERS\btport.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\Windows\system32\DRIVERS\bthmodem.sys [2009-07-14 56320]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 BTKRNL;Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\btkrnl.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\Windows\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\Windows\System32\Drivers\btwusb.sys []
S3 catchme;catchme; \??\C:\Users\Juraj\AppData\Local\Temp\catchme.sys []
S3 circlass;Consumer IR Devices; C:\Windows\system32\DRIVERS\circlass.sys [2009-07-14 37888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 Compbatt;Compbatt; C:\Windows\system32\DRIVERS\compbatt.sys [2009-07-14 19024]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 elxstor;elxstor; C:\Windows\system32\DRIVERS\elxstor.sys [2009-07-14 453712]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys [2009-07-14 142336]
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys [2009-07-14 28160]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\system32\DRIVERS\gagp30kx.sys [2009-07-14 57936]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HidBth;Microsoft Bluetooth HID Miniport; C:\Windows\system32\DRIVERS\hidbth.sys [2009-07-14 91136]
S3 HidIr;Microsoft Infrared HID Driver; C:\Windows\system32\DRIVERS\hidir.sys [2009-07-14 37888]
S3 HidUsb;Microsoft HID Class Driver; C:\Windows\system32\DRIVERS\hidusb.sys [2009-07-14 24064]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 iaStorV;iaStorV; C:\Windows\system32\DRIVERS\iaStorV.sys [2009-07-14 332352]
S3 iirsp;iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [2009-07-14 41040]
S3 intelide;intelide; C:\Windows\system32\DRIVERS\intelide.sys [2009-07-14 15424]
S3 intelppm;Intel Processor Driver; C:\Windows\system32\DRIVERS\intelppm.sys [2009-07-14 53760]
S3 IPMIDRV;IPMIDRV; C:\Windows\system32\DRIVERS\IPMIDrv.sys [2009-07-14 65536]
S3 isapnp;isapnp; C:\Windows\system32\DRIVERS\isapnp.sys [2009-07-14 46656]
S3 iScsiPrt;iScsiPort Driver; C:\Windows\system32\DRIVERS\msiscsi.sys [2009-07-14 186960]
S3 kbdhid;Keyboard HID Driver; C:\Windows\system32\DRIVERS\kbdhid.sys [2009-07-14 28160]
S3 LSI_FC;LSI_FC; C:\Windows\system32\DRIVERS\lsi_fc.sys [2009-07-14 95824]
S3 LSI_SAS;LSI_SAS; C:\Windows\system32\DRIVERS\lsi_sas.sys [2009-07-14 89168]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 LSI_SCSI;LSI_SCSI; C:\Windows\system32\DRIVERS\lsi_scsi.sys [2009-07-14 96848]
S3 mbr;mbr; \??\C:\Users\Juraj\AppData\Local\Temp\mbr.sys []
S3 megasas;megasas; C:\Windows\system32\DRIVERS\megasas.sys [2009-07-14 30800]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mouhid;Mouse HID Driver; C:\Windows\system32\DRIVERS\mouhid.sys [2009-07-14 26112]
S3 mpio;mpio; C:\Windows\system32\DRIVERS\mpio.sys [2009-07-14 130624]
S3 msahci;msahci; C:\Windows\system32\DRIVERS\msahci.sys [2009-07-14 27712]
S3 msdsm;msdsm; C:\Windows\system32\DRIVERS\msdsm.sys [2009-07-14 115792]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys [2009-07-14 162896]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NativeWifiP;NativeWiFi Filter; C:\Windows\system32\DRIVERS\nwifi.sys [2009-07-14 267264]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 nfrd960;nfrd960; C:\Windows\system32\DRIVERS\nfrd960.sys [2009-07-14 44624]
S3 nv_agp;NVIDIA nForce AGP Bus Filter; C:\Windows\system32\DRIVERS\nv_agp.sys [2009-07-14 105024]
S3 nvraid;nvraid; C:\Windows\system32\DRIVERS\nvraid.sys [2009-07-14 117312]
S3 nvstor;nvstor; C:\Windows\system32\DRIVERS\nvstor.sys [2009-07-14 142416]
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy); C:\Windows\system32\DRIVERS\ohci1394.sys [2009-07-14 62464]
S3 ql2300;ql2300; C:\Windows\system32\DRIVERS\ql2300.sys [2009-07-14 1383488]
S3 ql40xx;ql40xx; C:\Windows\system32\DRIVERS\ql40xx.sys [2009-07-14 106064]
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys [2009-07-14 31744]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sbp2port;sbp2port; C:\Windows\system32\DRIVERS\sbp2port.sys [2009-07-14 85568]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 sermouse;Serial Mouse Driver; C:\Windows\system32\DRIVERS\sermouse.sys [2009-07-14 19968]
S3 sffdisk;SFF Storage Class Driver; C:\Windows\system32\DRIVERS\sffdisk.sys [2009-07-14 11264]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC; C:\Windows\system32\DRIVERS\sffp_mmc.sys [2009-07-14 12288]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\Windows\system32\DRIVERS\sffp_sd.sys [2009-07-14 12800]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SiSRaid2;SiSRaid2; C:\Windows\system32\DRIVERS\SiSRaid2.sys [2009-07-14 40016]
S3 SiSRaid4;SiSRaid4; C:\Windows\system32\DRIVERS\sisraid4.sys [2009-07-14 77888]
S3 Smb;@%SystemRoot%\system32\tcpipcfg.dll,-50005; C:\Windows\system32\DRIVERS\smb.sys [2009-07-14 71168]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 TCPIP6;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys [2009-07-14 1285712]
S3 tssecsrv;@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101; C:\Windows\System32\DRIVERS\tssecsrv.sys [2009-07-14 30208]
S3 uagp35;Microsoft AGPv3.5 Filter; C:\Windows\system32\DRIVERS\uagp35.sys [2009-07-14 55888]
S3 uliagpkx;Uli AGP Bus Filter; C:\Windows\system32\DRIVERS\uliagpkx.sys [2009-07-14 57424]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\Windows\system32\DRIVERS\usbccgp.sys [2009-07-14 75264]
S3 usbcir;eHome Infrared Receiver (USBCIR); C:\Windows\system32\DRIVERS\usbcir.sys [2009-07-14 86016]
S3 usbprint;Třída USB Printer; C:\Windows\system32\DRIVERS\usbprint.sys [2009-07-14 19968]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\Windows\system32\DRIVERS\USBSTOR.SYS [2009-07-14 74752]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbuhci.sys [2009-07-14 24064]
S3 vga;vga; C:\Windows\system32\DRIVERS\vgapnp.sys [2009-07-14 26112]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vsmraid;vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys [2009-07-14 141904]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WacomPen;Wacom Serial Pen HID Driver; C:\Windows\system32\DRIVERS\wacompen.sys [2009-07-14 21632]
S3 Wd;Wd; C:\Windows\system32\DRIVERS\wd.sys [2009-07-14 19024]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S4 crcdisk;Crcdisk Filter Driver; C:\Windows\system32\DRIVERS\crcdisk.sys [2009-07-14 22096]
S4 ws2ifsl;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\Windows\system32\drivers\ws2ifsl.sys [2009-07-14 16384]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AudioEndpointBuilder;@%SystemRoot%\system32\audiosrv.dll,-204; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 EPSON_EB_RPCV4_01;EPSON V5 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [2007-12-17 143872]
R2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [2007-01-11 113664]
R2 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-01-11 129640]
R2 O&O Defrag;O&O Defrag; C:\Windows\system32\oodag.exe [2008-11-03 1332480]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-11-17 1021256]
R2 UxSms;@%SystemRoot%\system32\dwm.exe,-2000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WMPNetworkSvc;@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101; C:\Program Files\Windows Media Player\wmpnetwk.exe [2009-07-14 1121280]
R2 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 netprofm;@%SystemRoot%\system32\netprofm.dll,-202; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-22 135664]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-22 194032]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-06-10 66384]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\Windows\ehome\ehRecvr.exe [2009-07-14 557056]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\Windows\ehome\ehsched.exe [2009-07-14 94720]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-28 655624]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2009-06-10 42856]
S3 idsvc;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2009-06-10 878416]
S3 IPBusEnum;@%systemroot%\system32\IPBusEnum.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe [2009-07-14 12800]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TBS;@%SystemRoot%\system32\tbssvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2009-07-14 204800]
S3 TuneUp.Defrag;@C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-01-05 435016]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe [2009-07-14 35840]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe [2009-07-14 452608]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinDefend;@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2009-06-10 128848]
S4 WSearch;@%systemroot%\system32\SearchIndexer.exe,-103; C:\Windows\system32\SearchIndexer.exe [2009-07-14 428032]

-----------------EOF-----------------

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43295
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod jaro3 » 24 úno 2010 15:16

Stáhni si MBR Rootkit Detektor
- ulož si ho přímo na disk C a spusť ho
- za chvíli se ti vytvoří jeho log (mbr.log) vlož sem celý jeho obsah.

Jdi přes Start -> Spustit... a napiš do okna tento příkaz označený modře:
C:\mbr.exe -f
a dej Ok.mezi mbr.exe a -f je mezera
- pokud by tě bezpečnostní software upozornil na přepsání MBR tak to povol
- počkej až program proběhne a pak restartuj Pc

////////////////////////
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

vyčisti systém CCleanerem

a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš
////////////////////////////
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


//////////////////////////
Stáhni si program OTM (by OldTimer)
http://www.edisk.cz/stahni/07995/OTMove ... .39KB.html
a ulož si ho na disk C a spusť ho.
- Do levého sloupce (Paste Instructions for Items to be Moved) zkopíruj tyto cesty:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE

Kód: Vybrat vše

:Processes
explorer.exe

:Services

:Reg

:Files
C:\WINDOWS\System32\*.tmp /s
C:\WINDOWS\*.tmp /s
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
c:\windows\Tasks\*.job /s

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

- Po zkopírování klikni na tlačítko MoveIt! a vlož sem následně celý obsah z pravého sloupce, jinak uložený ve složce C:\_OTMoveIt\MovedFiles\, který bude informovat o výsledcích
- Je možné, že pokud nebudou moci být soubory odstraněny, budeš dotázán na restart počítače, v tom případě restart potvrď.

Pak napiš , jak se chová PC.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
abrit
Level 1
Level 1
Příspěvky: 83
Registrován: březen 08
Pohlaví: Muž
Stav:
Offline

Re: zasekávání programů ve win 7

Příspěvekod abrit » 24 úno 2010 16:27

MBR log:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK



Ještě se zeptám, musím při každé operaci zavírat všechny aplikace? včetně netu?


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 111 hostů