trojský kůn Vyřešeno

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: trojský kůn

Příspěvekod Dokyxxx » 26 srp 2011 12:11

========== Driver Services (All) ==========

DRV - (NwlnkFwd) -- File not found
DRV - (NwlnkFlt) -- File not found
DRV - (IpInIp) -- File not found
DRV - (FSLX) -- File not found
DRV - (epfwwfpr) -- File not found
DRV - (ehdrv) -- File not found
DRV - (eamonm) -- File not found
DRV - (ggsemc) -- C:\Windows\System32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) -- C:\Windows\System32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (mrxsmb10) -- C:\Windows\System32\drivers\mrxsmb10.sys (Microsoft Corporation)
DRV - (dtsoftbus01) -- C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (Tcpip6) -- C:\Windows\System32\drivers\tcpip.sys (Microsoft Corporation)
DRV - (Tcpip) -- C:\Windows\System32\drivers\tcpip.sys (Microsoft Corporation)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (srv2) -- C:\Windows\System32\drivers\srv2.sys (Microsoft Corporation)
DRV - (srvnet) -- C:\Windows\System32\drivers\srvnet.sys (Microsoft Corporation)
DRV - (mrxsmb20) -- C:\Windows\System32\drivers\mrxsmb20.sys (Microsoft Corporation)
DRV - (mrxsmb) -- C:\Windows\System32\drivers\mrxsmb.sys (Microsoft Corporation)
DRV - (AFD) -- C:\Windows\system32\drivers\afd.sys (Microsoft Corporation)
DRV - (DfsC) -- C:\Windows\System32\drivers\dfsc.sys (Microsoft Corporation)
DRV - (bowser) -- C:\Windows\System32\drivers\bowser.sys (Microsoft Corporation)
DRV - (srv) -- C:\Windows\System32\drivers\srv.sys (Microsoft Corporation)
DRV - (DXGKrnl) -- C:\Windows\System32\drivers\dxgkrnl.sys (Microsoft Corporation)
DRV - (HTTP) -- C:\Windows\System32\drivers\http.sys (Microsoft Corporation)
DRV - (tcpipreg) -- C:\Windows\System32\drivers\tcpipreg.sys (Microsoft Corporation)
DRV - (KSecDD) -- C:\Windows\System32\Drivers\ksecdd.sys (Microsoft Corporation)
DRV - (volmgrx) -- C:\Windows\System32\drivers\volmgrx.sys (Microsoft Corporation)
DRV - (volsnap) -- C:\Windows\system32\drivers\volsnap.sys (Microsoft Corporation)
DRV - (pci) -- C:\Windows\system32\drivers\pci.sys (Microsoft Corporation)
DRV - (TermDD) -- C:\Windows\System32\drivers\termdd.sys (Microsoft Corporation)
DRV - (Ntfs) -- C:\Windows\System32\drivers\ntfs.sys (Společnost Microsoft)
DRV - (NDIS) -- C:\Windows\system32\drivers\ndis.sys (Microsoft Corporation)
DRV - (ACPI) -- C:\Windows\system32\drivers\acpi.sys (Microsoft Corporation)
DRV - (CLFS) Common Log (CLFS) -- C:\Windows\System32\clfs.sys (Microsoft Corporation)
DRV - (FltMgr) -- C:\Windows\system32\drivers\fltmgr.sys (Společnost Microsoft)
DRV - (iScsiPrt) -- C:\Windows\System32\drivers\msiscsi.sys (Microsoft Corporation)
DRV - (MsRPC) -- C:\Windows\System32\drivers\msrpc.sys (Microsoft Corporation)
DRV - (Ecache) -- C:\Windows\System32\drivers\ecache.sys (Microsoft Corporation)
DRV - (partmgr) -- C:\Windows\System32\drivers\partmgr.sys (Microsoft Corporation)
DRV - (disk) -- C:\Windows\system32\drivers\disk.sys (Microsoft Corporation)
DRV - (Mup) -- C:\Windows\System32\Drivers\mup.sys (Microsoft Corporation)
DRV - (rdpdr) -- C:\Windows\System32\drivers\rdpdr.sys (Microsoft Corporation)
DRV - (RDPWD) -- C:\Windows\System32\drivers\rdpwd.sys (Microsoft Corporation)
DRV - (RasSstp) Připojení WAN Miniport (SSTP) -- C:\Windows\System32\drivers\rassstp.sys (Microsoft Corporation)
DRV - (NdisWan) -- C:\Windows\System32\drivers\ndiswan.sys (Microsoft Corporation)
DRV - (RasPppoe) -- C:\Windows\System32\drivers\raspppoe.sys (Microsoft Corporation)
DRV - (tdx) -- C:\Windows\System32\drivers\tdx.sys (Microsoft Corporation)
DRV - (PSched) -- C:\Windows\System32\drivers\pacer.sys (Microsoft Corporation)
DRV - (netbt) -- C:\Windows\System32\drivers\netbt.sys (Microsoft Corporation)
DRV - (Smb) Protokol TCP/IP a TCP/IPv6 orientovaný na zprávy (relace SMB) -- C:\Windows\System32\drivers\smb.sys (Microsoft Corporation)
DRV - (NativeWifiP) -- C:\Windows\System32\drivers\nwifi.sys (Microsoft Corporation)
DRV - (usbhub) -- C:\Windows\System32\drivers\usbhub.sys (Microsoft Corporation)
DRV - (ohci1394) -- C:\Windows\System32\drivers\ohci1394.sys (Microsoft Corporation)
DRV - (HdAudAddService) -- C:\Windows\System32\drivers\HdAudio.sys (Microsoft Corporation)
DRV - (usbaudio) Ovladač zvuků USB (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (USBSTOR) -- C:\Windows\System32\drivers\USBSTOR.SYS (Microsoft Corporation)
DRV - (usbehci) -- C:\Windows\System32\drivers\usbehci.sys (Microsoft Corporation)
DRV - (HidUsb) -- C:\Windows\System32\drivers\hidusb.sys (Microsoft Corporation)
DRV - (HDAudBus) -- C:\Windows\System32\drivers\hdaudbus.sys (Microsoft Corporation)
DRV - (cdrom) -- C:\Windows\System32\drivers\cdrom.sys (Microsoft Corporation)
DRV - (CSC) -- C:\Windows\System32\drivers\csc.sys (Microsoft Corporation)
DRV - (MRxDAV) -- C:\Windows\system32\drivers\mrxdav.sys (Microsoft Corporation)
DRV - (rdbss) -- C:\Windows\System32\drivers\rdbss.sys (Microsoft Corporation)
DRV - (Npfs) -- C:\Windows\System32\drivers\npfs.sys (Microsoft Corporation)
DRV - (udfs) -- C:\Windows\System32\drivers\udfs.sys (Microsoft Corporation)
DRV - (fastfat) -- C:\Windows\System32\drivers\fastfat.sys (Microsoft Corporation)
DRV - (exfat) -- C:\Windows\System32\drivers\exfat.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (iaStor) -- C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (e1yexpress) Intel(R) -- C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (NAL) -- C:\Windows\System32\drivers\iqvw32.sys (Intel Corporation )
DRV - (WUDFRd) -- C:\Windows\System32\drivers\WUDFRd.sys (Microsoft Corporation)
DRV - (tssecsrv) -- C:\Windows\System32\drivers\tssecsrv.sys (Microsoft Corporation)
DRV - (Modem) -- C:\Windows\System32\drivers\modem.sys (Microsoft Corporation)
DRV - (Rasl2tp) Připojení WAN Miniport (L2TP) -- C:\Windows\System32\drivers\rasl2tp.sys (Microsoft Corporation)
DRV - (PptpMiniport) Připojení WAN Miniport (PPTP) -- C:\Windows\System32\drivers\raspptp.sys (Microsoft Corporation)
DRV - (Ndisuio) -- C:\Windows\System32\drivers\ndisuio.sys (Microsoft Corporation)
DRV - (VgaSave) -- C:\Windows\System32\drivers\vga.sys (Microsoft Corporation)
DRV - (MSKSSRV) -- C:\Windows\System32\drivers\mskssrv.sys (Microsoft Corporation)
DRV - (MSTEE) -- C:\Windows\System32\drivers\mstee.sys (Microsoft Corporation)
DRV - (MSPCLOCK) -- C:\Windows\System32\drivers\mspclock.sys (Microsoft Corporation)
DRV - (MSPQM) -- C:\Windows\System32\drivers\mspqm.sys (Microsoft Corporation)
DRV - (RDPENCDD) -- C:\Windows\System32\drivers\RDPENCDD.sys (Microsoft Corporation)
DRV - (mpsdrv) -- C:\Windows\System32\drivers\mpsdrv.sys (Microsoft Corporation)
DRV - (nsiproxy) -- C:\Windows\System32\drivers\nsiproxy.sys (Microsoft Corporation)
DRV - (ws2ifsl) -- C:\Windows\system32\drivers\ws2ifsl.sys (Microsoft Corporation)
DRV - (IpFilterDriver) -- C:\Windows\System32\drivers\ipfltdrv.sys (Microsoft Corporation)
DRV - (luafv) -- C:\Windows\system32\drivers\luafv.sys (Microsoft Corporation)
DRV - (rspndr) -- C:\Windows\System32\drivers\rspndr.sys (Microsoft Corporation)
DRV - (lltdio) -- C:\Windows\System32\drivers\lltdio.sys (Microsoft Corporation)
DRV - (IPNAT) -- C:\Windows\System32\drivers\ipnat.sys (Microsoft Corporation)
DRV - (tunnel) -- C:\Windows\System32\drivers\tunnel.sys (Microsoft Corporation)
DRV - (tunmp) -- C:\Windows\System32\drivers\TUNMP.SYS (Microsoft Corporation)
DRV - (Wanarpv6) -- C:\Windows\System32\drivers\wanarp.sys (Microsoft Corporation)
DRV - (Wanarp) -- C:\Windows\System32\drivers\wanarp.sys (Microsoft Corporation)
DRV - (NDProxy) -- C:\Windows\System32\drivers\ndproxy.sys (Microsoft Corporation)
DRV - (NdisTapi) -- C:\Windows\System32\drivers\ndistapi.sys (Microsoft Corporation)
DRV - (Filetrace) -- C:\Windows\System32\drivers\filetrace.sys (Microsoft Corporation)
DRV - (NetBIOS) -- C:\Windows\System32\drivers\netbios.sys (Microsoft Corporation)
DRV - (RasAcd) -- C:\Windows\System32\drivers\rasacd.sys (Microsoft Corporation)
DRV - (spldr) -- C:\Windows\System32\drivers\spldr.sys (Microsoft Corporation)
DRV - (TDTCP) -- C:\Windows\System32\drivers\tdtcp.sys (Microsoft Corporation)
DRV - (TDPIPE) -- C:\Windows\System32\drivers\tdpipe.sys (Microsoft Corporation)
DRV - (RDPCDD) -- C:\Windows\System32\drivers\RDPCDD.sys (Microsoft Corporation)
DRV - (AsyncMac) -- C:\Windows\System32\drivers\asyncmac.sys (Microsoft Corporation)
DRV - (FileInfo) -- C:\Windows\system32\drivers\fileinfo.sys (Microsoft Corporation)
DRV - (IRENUM) -- C:\Windows\System32\drivers\irenum.sys (Microsoft Corporation)
DRV - (Wdf01000) -- C:\Windows\system32\drivers\Wdf01000.sys (Microsoft Corporation)
DRV - (cdfs) -- C:\Windows\System32\drivers\cdfs.sys (Microsoft Corporation)
DRV - (Msfs) -- C:\Windows\System32\drivers\msfs.sys (Microsoft Corporation)
DRV - (Null) -- C:\Windows\System32\drivers\null.sys (Microsoft Corporation)
DRV - (MountMgr) -- C:\Windows\System32\drivers\mountmgr.sys (Microsoft Corporation)
DRV - (Beep) -- C:\Windows\System32\drivers\beep.sys (Microsoft Corporation)
DRV - (QWAVEdrv) -- C:\Windows\system32\drivers\qwavedrv.sys (Microsoft Corporation)
DRV - (MegaSR) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (usbvideo) Zobrazovací zařízení USB (WDM) -- C:\Windows\System32\drivers\usbvideo.sys (Microsoft Corporation)
DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Microsoft Corporation)
DRV - (circlass) -- C:\Windows\system32\drivers\circlass.sys (Microsoft Corporation)
DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel(R) -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (Wd) -- C:\Windows\system32\drivers\wd.sys (Microsoft Corporation)
DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (kbdclass) -- C:\Windows\System32\drivers\kbdclass.sys (Microsoft Corporation)
DRV - (kbdhid) -- C:\Windows\system32\drivers\kbdhid.sys (Microsoft Corporation)
DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (umbus) -- C:\Windows\System32\drivers\umbus.sys (Microsoft Corporation)
DRV - (sffdisk) -- C:\Windows\system32\drivers\sffdisk.sys (Microsoft Corporation)
DRV - (sffp_mmc) -- C:\Windows\system32\drivers\sffp_mmc.sys (Microsoft Corporation)
DRV - (sffp_sd) -- C:\Windows\system32\drivers\sffp_sd.sys (Microsoft Corporation)
DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (IPMIDRV) -- C:\Windows\system32\drivers\ipmidrv.sys (Microsoft Corporation)
DRV - (gagp30kx) -- C:\Windows\system32\drivers\gagp30kx.sys (Microsoft Corporation)
DRV - (uagp35) -- C:\Windows\system32\drivers\uagp35.sys (Microsoft Corporation)
DRV - (monitor) -- C:\Windows\System32\drivers\monitor.sys (Microsoft Corporation)
DRV - (crcdisk) -- C:\Windows\system32\drivers\crcdisk.sys (Microsoft Corporation)
DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (mpio) -- C:\Windows\system32\drivers\mpio.sys (Microsoft Corporation)
DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (msdsm) -- C:\Windows\system32\drivers\msdsm.sys (Microsoft Corporation)
DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (drmkaud) -- C:\Windows\System32\drivers\drmkaud.sys (Microsoft Corporation)
DRV - (b57nd60x) -- C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (usbccgp) -- C:\Windows\System32\drivers\usbccgp.sys (Microsoft Corporation)
DRV - (i8042prt) -- C:\Windows\System32\drivers\i8042prt.sys (Microsoft Corporation)
DRV - (mouclass) -- C:\Windows\System32\drivers\mouclass.sys (Microsoft Corporation)
DRV - (fdc) -- C:\Windows\System32\drivers\fdc.sys (Microsoft Corporation)
DRV - (flpydisk) -- C:\Windows\System32\drivers\flpydisk.sys (Microsoft Corporation)
DRV - (sermouse) -- C:\Windows\system32\drivers\sermouse.sys (Microsoft Corporation)
DRV - (mouhid) -- C:\Windows\System32\drivers\mouhid.sys (Microsoft Corporation)
DRV - (i2omp) -- C:\Windows\system32\drivers\i2omp.sys (Microsoft Corporation)
DRV - (vga) -- C:\Windows\System32\drivers\vgapnp.sys (Microsoft Corporation)
DRV - (usbuhci) -- C:\Windows\System32\drivers\usbuhci.sys (Microsoft Corporation)
DRV - (Serial) -- C:\Windows\System32\drivers\serial.sys (Microsoft Corporation)
DRV - (Parport) -- C:\Windows\System32\drivers\parport.sys (Microsoft Corporation)
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys (Microsoft Corporation)
DRV - (Serenum) -- C:\Windows\System32\drivers\serenum.sys (Microsoft Corporation)
DRV - (Parvdm) -- C:\Windows\System32\drivers\parvdm.sys (Microsoft Corporation)
DRV - (nv_agp) -- C:\Windows\system32\drivers\nv_agp.sys (Microsoft Corporation)
DRV - (uliagpkx) -- C:\Windows\system32\drivers\uliagpkx.sys (Microsoft Corporation)
DRV - (amdagp) -- C:\Windows\system32\drivers\amdagp.sys (Microsoft Corporation)
DRV - (viaagp) -- C:\Windows\system32\drivers\viaagp.sys (Microsoft Corporation)
DRV - (agp440) -- C:\Windows\system32\drivers\agp440.sys (Microsoft Corporation)
DRV - (sisagp) -- C:\Windows\system32\drivers\sisagp.sys (Microsoft Corporation)
DRV - (volmgr) -- C:\Windows\system32\drivers\volmgr.sys (Microsoft Corporation)
DRV - (isapnp) -- C:\Windows\system32\drivers\isapnp.sys (Microsoft Corporation)
DRV - (AmdK8) -- C:\Windows\system32\drivers\amdk8.sys (Microsoft Corporation)
DRV - (ViaC7) -- C:\Windows\system32\drivers\viac7.sys (Microsoft Corporation)
DRV - (intelppm) -- C:\Windows\System32\drivers\intelppm.sys (Microsoft Corporation)
DRV - (AmdK7) -- C:\Windows\system32\drivers\amdk7.sys (Microsoft Corporation)
DRV - (Processor) -- C:\Windows\system32\drivers\processr.sys (Microsoft Corporation)
DRV - (Crusoe) -- C:\Windows\system32\drivers\crusoe.sys (Microsoft Corporation)
DRV - (mssmbios) -- C:\Windows\System32\drivers\mssmbios.sys (Microsoft Corporation)
DRV - (msahci) -- C:\Windows\system32\drivers\msahci.sys (Microsoft Corporation)
DRV - (atapi) -- C:\Windows\system32\drivers\atapi.sys (Microsoft Corporation)
DRV - (Compbatt) -- C:\Windows\system32\drivers\compbatt.sys (Microsoft Corporation)
DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (intelide) -- C:\Windows\system32\drivers\intelide.sys (Microsoft Corporation)
DRV - (amdide) -- C:\Windows\system32\drivers\amdide.sys (Microsoft Corporation)
DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (pciide) -- C:\Windows\system32\drivers\pciide.sys (Microsoft Corporation)
DRV - (msisadrv) -- C:\Windows\system32\drivers\msisadrv.sys (Microsoft Corporation)
DRV - (swenum) -- C:\Windows\System32\drivers\swenum.sys (Microsoft Corporation)
DRV - (WmiAcpi) -- C:\Windows\System32\drivers\wmiacpi.sys (Microsoft Corporation)
DRV - (ErrDev) -- C:\Windows\system32\drivers\errdev.sys (Microsoft Corporation)
DRV - (pcmcia) -- C:\Windows\system32\drivers\pcmcia.sys (Microsoft Corporation)
DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (sbp2port) -- C:\Windows\system32\drivers\sbp2port.sys (Microsoft Corporation)
DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (usbprint) -- C:\Windows\system32\drivers\usbprint.sys (Microsoft Corporation)
DRV - (PEAUTH) -- C:\Windows\System32\drivers\PEAuth.sys (Microsoft Corporation)
DRV - (BTHMODEM) -- C:\Windows\system32\drivers\bthmodem.sys (Microsoft Corporation)
DRV - (HidBth) -- C:\Windows\system32\drivers\hidbth.sys (Microsoft Corporation)
DRV - (usbcir) eHome Infrared Receiver (USBCIR) -- C:\Windows\system32\drivers\usbcir.sys (Microsoft Corporation)
DRV - (usbohci) -- C:\Windows\system32\drivers\usbohci.sys (Microsoft Corporation)
DRV - (HidIr) -- C:\Windows\system32\drivers\hidir.sys (Microsoft Corporation)
DRV - (WacomPen) -- C:\Windows\system32\drivers\wacompen.sys (Microsoft Corporation)
DRV - (sfloppy) -- C:\Windows\system32\drivers\sfloppy.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (secdrv) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.seznam.cz"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2011.06.30 16:57:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011.08.21 20:55:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.07.03 15:52:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.07 18:58:33 | 000,000,000 | ---D | M]

[2011.07.01 12:38:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Standard\AppData\Roaming\mozilla\Extensions
[2011.07.21 18:55:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions
[2011.07.21 18:55:14 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.07.02 14:17:58 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\DTToolbar@toolbarnet.com
[2011.07.02 14:17:53 | 000,002,059 | ---- | M] () -- C:\Users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\searchplugins\daemon-search.xml
[2011.07.01 12:37:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.07.03 15:52:22 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) --
[2011.08.21 20:55:37 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2011.06.30 16:57:10 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.07.03 15:52:21 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007.04.10 17:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2011.07.03 15:52:19 | 000,002,364 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2011.07.03 15:52:18 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.07.03 15:52:18 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.07.03 15:52:18 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.07.03 15:52:18 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.07.03 15:52:18 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2011.08.23 15:18:04 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Společnost Microsoft)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\System32\sysdm.cpl (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img18.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.08.26 11:49:14 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011.08.25 15:00:40 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Users\Standard\Desktop\OTH.scr
[2011.08.23 15:22:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.08.23 15:18:08 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.08.22 18:08:48 | 000,000,000 | ---D | C] -- C:\Users\Standard\AppData\Local\temp
[2011.08.22 17:13:26 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.08.22 17:13:26 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.08.22 17:13:26 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.08.22 17:13:20 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.08.22 16:56:17 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.08.22 16:35:40 | 000,000,000 | ---D | C] -- C:\Users\Standard\AppData\Roaming\Malwarebytes
[2011.08.22 16:35:37 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011.08.22 16:35:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.08.22 16:35:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011.08.22 16:35:34 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.08.22 16:35:34 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.08.21 21:13:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.08.21 21:13:47 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.08.21 20:55:48 | 000,309,848 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011.08.21 20:55:48 | 000,019,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011.08.21 20:55:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011.08.21 20:55:46 | 000,025,432 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011.08.21 20:55:45 | 000,441,176 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011.08.21 20:55:44 | 000,054,104 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011.08.21 20:55:35 | 000,199,304 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011.08.21 20:55:35 | 000,040,112 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2011.08.21 20:27:14 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011.08.21 20:27:14 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011.08.10 16:33:32 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.08.10 16:33:31 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011.08.10 16:33:31 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.08.10 16:33:31 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011.08.10 16:33:30 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011.08.10 16:28:30 | 000,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2011.08.10 16:28:21 | 003,602,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011.08.10 16:28:21 | 003,550,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011.08.06 08:27:35 | 000,000,000 | ---D | C] -- C:\Users\Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome

========== Files - Modified Within 30 Days ==========

[2011.08.26 11:58:17 | 000,657,188 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.08.26 11:58:17 | 000,645,410 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.08.26 11:58:17 | 000,136,602 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.08.26 11:58:17 | 000,122,238 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.08.26 11:51:13 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.08.26 11:51:13 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.08.26 11:51:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.08.26 11:51:07 | 3757,232,128 | -HS- | M] () -- C:\hiberfil.sys
[2011.08.25 19:48:14 | 000,007,836 | ---- | M] () -- C:\Users\Standard\AppData\Local\d3d9caps.dat
[2011.08.25 15:12:51 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Users\Standard\Desktop\OTH.scr
[2011.08.24 18:36:46 | 000,000,048 | ---- | M] () -- C:\boot.ini
[2011.08.23 15:18:04 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.08.22 17:13:17 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2011.08.22 16:35:37 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.08.21 21:14:24 | 000,037,504 | ---- | M] () -- C:\Users\Standard\Documents\cc_20110821_211417.reg
[2011.08.21 21:13:48 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.08.21 20:55:49 | 000,001,829 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011.08.21 20:47:15 | 000,012,288 | ---- | M] () -- C:\Users\Standard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.08.12 17:51:09 | 000,002,395 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.08.01 18:28:59 | 000,003,943 | ---- | M] () -- C:\Users\Standard\Documents\perard.xml

========== Files Created - No Company Name ==========

[2011.08.26 11:51:06 | 3757,232,128 | -HS- | C] () -- C:\hiberfil.sys
[2011.08.24 18:36:46 | 000,000,048 | ---- | C] () -- C:\boot.ini
[2011.08.22 17:13:26 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.08.22 17:13:26 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.08.22 17:13:26 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.08.22 17:13:26 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.08.22 17:13:26 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.08.22 16:35:37 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.08.21 21:14:22 | 000,037,504 | ---- | C] () -- C:\Users\Standard\Documents\cc_20110821_211417.reg
[2011.08.21 21:13:48 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.08.21 20:55:49 | 000,001,829 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011.08.01 17:53:52 | 000,003,943 | ---- | C] () -- C:\Users\Standard\Documents\perard.xml
[2011.07.01 12:37:48 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.07.01 12:34:12 | 000,012,288 | ---- | C] () -- C:\Users\Standard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.06.30 18:27:00 | 000,657,188 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2011.06.30 18:27:00 | 000,286,912 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2011.06.30 18:27:00 | 000,136,602 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2011.06.30 18:27:00 | 000,034,724 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2011.06.30 13:13:39 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011.06.30 13:13:30 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011.06.30 13:12:34 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011.06.30 13:12:34 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011.06.30 10:53:27 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.06.30 09:58:28 | 000,007,836 | ---- | C] () -- C:\Users\Standard\AppData\Local\d3d9caps.dat
[2011.06.30 08:52:56 | 000,000,731 | ---- | C] () -- C:\Windows\System32\McOEMAppRules.dat
[2011.05.25 04:24:16 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2011.05.24 23:44:26 | 000,059,904 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011.04.20 18:30:06 | 000,233,765 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011.03.17 19:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2006.11.02 14:56:48 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:43 | 000,372,696 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 12:33:01 | 000,645,410 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,122,238 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2011.07.01 09:04:15 | 000,000,000 | ---D | M] -- C:\Users\Standard\AppData\Roaming\Ashampoo
[2011.08.23 19:27:08 | 000,000,000 | ---D | M] -- C:\Users\Standard\AppData\Roaming\DAEMON Tools Lite
[2011.08.21 19:29:30 | 000,000,000 | ---D | M] -- C:\Users\Standard\AppData\Roaming\DVDVideoSoft
[2011.07.21 19:00:55 | 000,000,000 | ---D | M] -- C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers
[2011.07.01 09:07:38 | 000,000,000 | ---D | M] -- C:\Users\Standard\AppData\Roaming\GHISLER
[2011.08.23 19:51:23 | 000,000,000 | ---D | M] -- C:\Users\Standard\AppData\Roaming\IrfanView
[2011.08.19 21:08:53 | 000,032,556 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: trojský kůn

Příspěvekod jaro3 » 26 srp 2011 21:45

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
SRV - (ekrn) -- File not found
SRV - (EhttpSrv) -- File not found
DRV - (NwlnkFwd) -- File not found
DRV - (NwlnkFlt) -- File not found
DRV - (IpInIp) -- File not found
DRV - (FSLX) -- File not found
DRV - (epfwwfpr) -- File not found
DRV - (ehdrv) -- File not found
DRV - (eamonm) -- File not found
[2011.07.01 12:38:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Standard\AppData\Roaming\mozilla\Extensions
[2011.07.02 14:17:58 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\DTToolbar@toolbarnet.com
[2011.07.02 14:17:53 | 000,002,059 | ---- | M] () -- C:\Users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\searchplugins\daemon-search.xml
[2011.07.01 12:37:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.07.03 15:52:22 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) --
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
[2011.08.26 11:58:17 | 000,657,188 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.08.26 11:58:17 | 000,645,410 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.08.26 11:58:17 | 000,136,602 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.08.26 11:58:17 | 000,122,238 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.06.30 18:27:00 | 000,657,188 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2011.06.30 18:27:00 | 000,286,912 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2011.06.30 18:27:00 | 000,136,602 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2011.06.30 18:27:00 | 000,034,724 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2006.11.02 12:33:01 | 000,645,410 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,122,238 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SWREG.exe
C:\Windows\NIRCMD.exe
C:\Qoobox
C:\Users\Standard\AppData\Local\d3d9caps.dat
C:\Windows\PEV.exe
C:\Windows\MBR.exe
C:\Windows\sed.exe
C:\Windows\grep.exe
C:\Windows\zip.exe
C:\Users\Standard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Windows\ativpsrm.bin

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Aktualizuj javu:
Java SE Runtime Environment 7

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: trojský kůn

Příspěvekod Dokyxxx » 27 srp 2011 15:08

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Service ekrn stopped successfully!
Service ekrn deleted successfully!
File File not found not found.
Service EhttpSrv stopped successfully!
Service EhttpSrv deleted successfully!
File File not found not found.
Service NwlnkFwd stopped successfully!
Service NwlnkFwd deleted successfully!
File File not found not found.
Service NwlnkFlt stopped successfully!
Service NwlnkFlt deleted successfully!
File File not found not found.
Service IpInIp stopped successfully!
Service IpInIp deleted successfully!
File File not found not found.
Service FSLX stopped successfully!
Service FSLX deleted successfully!
File File not found not found.
Service epfwwfpr stopped successfully!
Service epfwwfpr deleted successfully!
File File not found not found.
Service ehdrv stopped successfully!
Service ehdrv deleted successfully!
File File not found not found.
Service eamonm stopped successfully!
Service eamonm deleted successfully!
File File not found not found.
C:\Users\Standard\AppData\Roaming\mozilla\Extensions folder moved successfully.
C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\DTToolbar@toolbarnet.com\components\Resources folder moved successfully.
C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\DTToolbar@toolbarnet.com\components folder moved successfully.
C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\DTToolbar@toolbarnet.com\chrome\content folder moved successfully.
C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\DTToolbar@toolbarnet.com\chrome folder moved successfully.
C:\Users\Standard\AppData\Roaming\mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\DTToolbar@toolbarnet.com folder moved successfully.
C:\Users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\searchplugins\daemon-search.xml moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions folder moved successfully.
Folder C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1\\http deleted successfully.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
C:\Windows\System32\perfh005.dat moved successfully.
C:\Windows\System32\perfh009.dat moved successfully.
C:\Windows\System32\perfc005.dat moved successfully.
C:\Windows\System32\perfc009.dat moved successfully.
File C:\Windows\System32\perfh005.dat not found.
C:\Windows\System32\perfi005.dat moved successfully.
File C:\Windows\System32\perfc005.dat not found.
C:\Windows\System32\perfd005.dat moved successfully.
File C:\Windows\System32\perfh009.dat not found.
C:\Windows\System32\perfi009.dat moved successfully.
File C:\Windows\System32\perfc009.dat not found.
C:\Windows\System32\perfd009.dat moved successfully.
File rity] not found.
File ptytemp] not found.
File art explorer] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.26.5 log created on 08272011_150508

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Uživatelský avatar
bledulka
Level 5
Level 5
Příspěvky: 2242
Registrován: srpen 09
Pohlaví: Žena
Stav:
Offline

Re: trojský kůn

Příspěvekod bledulka » 27 srp 2011 19:20

Fajn, co počítač?

Stáhni T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusť,pro potvrzení volby mačkej klávesu A, Enter
-po použití prográmek vymaž.Pozor,antiviry ho mohou falešně označit za vir



Stahni CCleaner http://www.filehippo.com/download_cclea ... cbae6b492/
-nainstaluj (neinstaluj Yahoo toolbar)

-zvol záložku Čistič
-nechej v levém sloupečku zatrhnuté vše jak je a zmáčkni tlačítko analyzovat
-pak potvrď tlačítko Spustit Ccleaner
-tím se vyčistí počítač od dočasných soubborů, doporučuji pravidelně používat.

-vyber záložku registry
-klikni na tlačítko hledej problémy
-pak klikni na opravit vybrané problémy, potvrď, že chceš udělat zálohu a nech všechno opravit



Stahni Rsit http://images.malwareremoval.com/random/RSIT.exe
-spusť, klikni na tlačítko Continue
-po skenu na tebe vyběhne log.txt,obsah vlož zde

Dokyxxx
Level 1.5
Level 1.5
Příspěvky: 132
Registrován: červenec 09
Pohlaví: Muž
Stav:
Offline

Re: trojský kůn

Příspěvekod Dokyxxx » 27 srp 2011 19:43

Logfile of random's system information tool 1.09 (written by random/random)
Run by Standard at 2011-08-27 19:40:05
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 336 GB (71%) free of 475 GB
Total RAM: 3582 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:40:14, on 27.8.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Program Files\Winamp\winampa.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Standard\Downloads\RSIT.exe
C:\Program Files\trend micro\Standard.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Standard\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe

--
End of file - 4572 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

C:\Program Files\Mozilla Firefox\extensions\
{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npwachk.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Standard\AppData\Roaming\Mozilla\Firefox\Profiles\wi2e3bgs.default\extensions\
{ACAA314B-EEBA-48e4-AD47-84E31C44796C}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-08-27 56712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2008-04-07 318488]
"SetRefresh"=C:\Program Files\HP\SetRefresh\SetRefresh.exe [2003-11-20 525824]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-05-24 336384]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-05-04 252136]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2011-06-30 74752]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-08-27 19:40:05 ----D---- C:\rsit
2011-08-27 19:40:05 ----D---- C:\Program Files\trend micro
2011-08-27 16:10:07 ----D---- C:\Program Files\Winamp Detect
2011-08-27 16:09:59 ----D---- C:\Program Files\Common Files\PX Storage Engine
2011-08-27 16:09:56 ----D---- C:\Users\Standard\AppData\Roaming\Winamp
2011-08-27 16:09:56 ----D---- C:\Program Files\Winamp
2011-08-27 15:14:27 ----D---- C:\ProgramData\Sun
2011-08-27 15:13:46 ----A---- C:\Windows\system32\javaws.exe
2011-08-27 15:13:46 ----A---- C:\Windows\system32\javaw.exe
2011-08-27 15:13:46 ----A---- C:\Windows\system32\java.exe
2011-08-27 15:13:46 ----A---- C:\Windows\system32\deployJava1.dll
2011-08-27 15:13:25 ----D---- C:\Program Files\Java
2011-08-27 15:11:40 ----A---- C:\Windows\system32\PerfStringBackup.TMP
2011-08-27 15:11:08 ----D---- C:\Windows\system32\appmgmt
2011-08-26 13:28:12 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-08-26 13:28:12 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-08-26 13:28:12 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-08-26 13:28:12 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-08-26 13:28:12 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-08-26 13:28:12 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-08-26 13:27:32 ----A---- C:\Windows\avastSS.scr
2011-08-26 13:27:30 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-26 11:57:24 ----A---- C:\Windows\system32\tzres.dll
2011-08-26 11:51:06 ----ASH---- C:\hiberfil.sys
2011-08-26 11:49:14 ----D---- C:\Windows\pss
2011-08-24 18:36:46 ----A---- C:\boot.ini
2011-08-23 15:22:29 ----D---- C:\Windows\temp
2011-08-23 15:18:08 ----SHD---- C:\$RECYCLE.BIN
2011-08-22 17:13:26 ----A---- C:\Windows\zip.exe
2011-08-22 17:13:26 ----A---- C:\Windows\SWSC.exe
2011-08-22 17:13:26 ----A---- C:\Windows\SWREG.exe
2011-08-22 17:13:26 ----A---- C:\Windows\sed.exe
2011-08-22 17:13:26 ----A---- C:\Windows\PEV.exe
2011-08-22 17:13:26 ----A---- C:\Windows\NIRCMD.exe
2011-08-22 17:13:26 ----A---- C:\Windows\MBR.exe
2011-08-22 17:13:26 ----A---- C:\Windows\grep.exe
2011-08-22 17:13:20 ----D---- C:\Windows\ERDNT
2011-08-22 16:56:17 ----D---- C:\Qoobox
2011-08-22 16:35:40 ----D---- C:\Users\Standard\AppData\Roaming\Malwarebytes
2011-08-22 16:35:37 ----D---- C:\ProgramData\Malwarebytes
2011-08-22 16:35:37 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-08-22 16:35:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-08-22 16:35:34 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-08-21 21:13:47 ----D---- C:\Program Files\CCleaner
2011-08-21 20:27:14 ----D---- C:\ProgramData\AVAST Software
2011-08-21 20:27:14 ----D---- C:\Program Files\AVAST Software
2011-08-10 16:33:32 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-10 16:33:32 ----A---- C:\Windows\system32\iertutil.dll
2011-08-10 16:33:31 ----A---- C:\Windows\system32\wininet.dll
2011-08-10 16:33:31 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-10 16:33:31 ----A---- C:\Windows\system32\jscript9.dll
2011-08-10 16:33:31 ----A---- C:\Windows\system32\jscript.dll
2011-08-10 16:33:31 ----A---- C:\Windows\system32\ieui.dll
2011-08-10 16:33:30 ----A---- C:\Windows\system32\urlmon.dll
2011-08-10 16:33:30 ----A---- C:\Windows\system32\url.dll
2011-08-10 16:33:30 ----A---- C:\Windows\system32\ieframe.dll
2011-08-10 16:33:29 ----A---- C:\Windows\system32\mshtml.dll
2011-08-10 16:28:32 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-10 16:28:30 ----A---- C:\Windows\system32\winsrv.dll
2011-08-10 16:28:21 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-10 16:28:21 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-08-10 16:28:06 ----A---- C:\Windows\system32\xmllite.dll
2011-08-10 16:28:05 ----A---- C:\Windows\system32\drivers\tcpip.sys

======List of files/folders modified in the last 1 month======

2011-08-27 19:40:14 ----D---- C:\Windows\Prefetch
2011-08-27 19:40:05 ----RD---- C:\Program Files
2011-08-27 19:38:00 ----D---- C:\Users\Standard\AppData\Roaming\DAEMON Tools Lite
2011-08-27 19:37:47 ----D---- C:\Windows
2011-08-27 16:09:59 ----D---- C:\Program Files\Common Files
2011-08-27 15:46:47 ----SHD---- C:\System Volume Information
2011-08-27 15:14:27 ----SHD---- C:\Windows\Installer
2011-08-27 15:14:27 ----D---- C:\ProgramData
2011-08-27 15:14:26 ----D---- C:\Program Files\Common Files\Java
2011-08-27 15:13:46 ----D---- C:\Windows\System32
2011-08-27 15:11:50 ----D---- C:\Program Files\Mozilla Firefox
2011-08-27 15:11:40 ----D---- C:\Windows\inf
2011-08-27 15:08:04 ----D---- C:\Windows\system32\catroot2
2011-08-27 15:07:51 ----D---- C:\Users\Standard\AppData\Roaming\Mozilla
2011-08-27 15:05:14 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-08-27 11:24:34 ----D---- C:\Windows\rescache
2011-08-27 11:11:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-27 11:09:55 ----D---- C:\Windows\winsxs
2011-08-27 11:09:55 ----D---- C:\Windows\system32\cs-CZ
2011-08-26 13:28:12 ----D---- C:\Windows\system32\drivers
2011-08-26 11:56:14 ----D---- C:\Windows\system32\catroot
2011-08-26 11:54:07 ----D---- C:\Windows\SoftwareDistribution
2011-08-23 19:51:23 ----D---- C:\Users\Standard\AppData\Roaming\IrfanView
2011-08-23 19:27:04 ----D---- C:\Windows\Logs
2011-08-23 19:27:04 ----D---- C:\Windows\Debug
2011-08-23 15:18:09 ----A---- C:\Windows\system.ini
2011-08-23 15:18:04 ----D---- C:\Windows\system32\drivers\etc
2011-08-23 15:15:31 ----D---- C:\Windows\AppPatch
2011-08-21 20:35:14 ----D---- C:\Windows\system32\Msdtc
2011-08-21 20:35:11 ----D---- C:\Windows\system32\wbem
2011-08-21 20:31:01 ----D---- C:\Windows\system32\config
2011-08-21 20:30:51 ----D---- C:\Windows\Tasks
2011-08-21 20:30:51 ----D---- C:\Windows\system32\Tasks
2011-08-21 20:30:51 ----D---- C:\Windows\system32\spool
2011-08-21 20:30:51 ----D---- C:\Users\Standard\AppData\Roaming\vlc
2011-08-21 20:30:49 ----D---- C:\Windows\registration
2011-08-21 19:29:30 ----D---- C:\Users\Standard\AppData\Roaming\DVDVideoSoft
2011-08-12 18:38:20 ----D---- C:\Users\Standard\AppData\Roaming\Skype
2011-08-11 15:48:44 ----D---- C:\Windows\Microsoft.NET
2011-08-11 15:48:28 ----RSD---- C:\Windows\assembly
2011-08-10 21:38:51 ----D---- C:\Windows\system32\migration
2011-08-10 21:38:51 ----D---- C:\Program Files\Windows Mail
2011-08-10 21:38:51 ----D---- C:\Program Files\Internet Explorer
2011-08-10 16:34:18 ----D---- C:\ProgramData\Microsoft Help
2011-08-10 16:32:27 ----A---- C:\Windows\system32\mrt.exe
2011-07-31 19:51:00 ----D---- C:\Program Files\Microsoft Office

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2008-08-13 325144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 43608]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-02 218688]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-05-25 7800832]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-05-25 245760]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver; C:\Windows\system32\DRIVERS\e1y6032.sys [2008-06-13 225920]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-09-24 2171672]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-07-06 22712]
R3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-10 73216]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2011-07-07 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2011-07-07 25512]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NAL;Nal Service ; \??\C:\Windows\system32\Drivers\iqvw32.sys [2008-05-23 30816]
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2008-01-21 45624]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-05-25 176128]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 BcmSqlStartupSvc;Služba spouštění serveru SQL Server aplikace Business Contact Manager; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2009-02-23 30312]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2008-04-07 576024]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]

-----------------EOF-----------------
a jinak pc zdá se že šlape :) a antivir nic nenašel,mam avasta

Uživatelský avatar
bledulka
Level 5
Level 5
Příspěvky: 2242
Registrován: srpen 09
Pohlaví: Žena
Stav:
Offline

Re: trojský kůn  Vyřešeno

Příspěvekod bledulka » 27 srp 2011 19:51

Ještě použij ten t-cleaner, odinstaluje combofix.
A pokud nejsou problémy, můžeš dát zelenou fajfku, vyřešeno.


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 6 hostů