
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o preventivní kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
prosím o preventivní kontrolu logu
Logfile of random's system information tool 1.08 (written by random/random)
Run by Uživatel at 2011-07-05 10:35:47
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 43 GB (64%) free of 67 GB
Total RAM: 2999 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:35:52, on 5.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
C:\Windows\System32\ico.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\FSRremoS.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files\ICQ7.5\ICQ.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Uživatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sk27211/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Google Update] "C:\Users\Uživatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
--
End of file - 6025 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2011-02-28 1048888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-06-24 1822600]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 136216]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 170520]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-04-28 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2010-03-22 496184]
"Mouse Suite 98 Daemon"=C:\Windows\system32\ICO.EXE [2004-07-14 57344]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-01-25 421160]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2011-05-29 1047656]
"Easy-PrintToolBox"=C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2004-01-14 409600]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-05-29 449584]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-05-29 449584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Uživatel\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-24 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Center Agent]
C:\Program Files\Genius Multimedia\HyperMediaCenter\DTVR\Scheduled.exe [2008-11-07 1520128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Uživatel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
C:\PROGRA~1\GENIUS~2\GENIUS~1\AFRCtl.exe [2009-03-25 81920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-08-25 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-07-05 10:35:47 ----D---- C:\rsit
2011-07-03 18:30:49 ----D---- C:\Program Files\Unlocker
2011-07-02 19:16:04 ----A---- C:\Windows\system32\pdfcmnnt.dll
2011-07-02 19:16:03 ----A---- C:\Windows\system32\MSMPIDE.DLL
2011-07-02 19:16:02 ----D---- C:\Program Files\PDFCreator
2011-06-28 21:09:12 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-28 21:09:09 ----A---- C:\Windows\system32\mssrch.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\tquery.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\mssph.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssvp.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-17 15:42:13 ----D---- C:\Program Files\Google
2011-06-16 22:17:13 ----D---- C:\ProgramData\eLicenser
2011-06-16 22:17:13 ----D---- C:\Program Files\eLicenser
2011-06-16 22:17:10 ----A---- C:\Windows\system32\SYNSOPOS.exe.cfg
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-16 11:15:43 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-16 11:15:42 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-16 11:15:41 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-16 11:15:36 ----A---- C:\Windows\system32\mshtml.dll
2011-06-16 11:15:35 ----A---- C:\Windows\system32\ieframe.dll
2011-06-16 11:15:34 ----A---- C:\Windows\system32\urlmon.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\wininet.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\ieui.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\iertutil.dll
2011-06-16 11:15:31 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-14 13:48:25 ----D---- C:\Program Files\VirtualDJ
2011-06-14 13:08:23 ----DC---- C:\ProgramData\{4A818508-3355-4FBC-B302-D53B599DD9D5}
======List of files/folders modified in the last 1 months======
2011-07-05 10:35:53 ----D---- C:\Windows\Prefetch
2011-07-05 10:35:52 ----D---- C:\Program Files\trend micro
2011-07-05 10:28:49 ----D---- C:\Windows\Temp
2011-07-05 10:27:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-05 10:26:59 ----D---- C:\Windows\system32\drivers
2011-07-05 10:25:06 ----D---- C:\Users\Uživatel\AppData\Roaming\Media Player Classic
2011-07-05 10:25:04 ----D---- C:\Windows
2011-07-05 10:21:21 ----D---- C:\Windows\system32\config
2011-07-05 10:10:50 ----D---- C:\Users\Uživatel\AppData\Roaming\ICQ
2011-07-04 20:25:44 ----D---- C:\Windows\System32
2011-07-04 20:25:44 ----D---- C:\Windows\inf
2011-07-04 20:25:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-03 23:08:35 ----SHD---- C:\System Volume Information
2011-07-03 18:30:49 ----RD---- C:\Program Files
2011-07-01 10:05:33 ----SHD---- C:\Windows\Installer
2011-07-01 10:05:31 ----D---- C:\Users\Uživatel\AppData\Roaming\Mozilla
2011-07-01 09:35:38 ----D---- C:\Program Files\ICQ7.5
2011-06-29 09:01:04 ----D---- C:\Windows\winsxs
2011-06-29 08:59:55 ----RSD---- C:\Windows\Fonts
2011-06-28 21:10:08 ----D---- C:\Program Files\Microsoft Office
2011-06-28 21:09:03 ----D---- C:\Windows\system32\catroot
2011-06-28 21:09:02 ----D---- C:\Windows\system32\catroot2
2011-06-28 14:29:25 ----D---- C:\Program Files\rajce
2011-06-18 15:58:19 ----D---- C:\Windows\Microsoft.NET
2011-06-18 15:58:18 ----RSD---- C:\Windows\assembly
2011-06-17 16:04:43 ----D---- C:\Program Files\VstPlugins
2011-06-17 15:58:03 ----D---- C:\Program Files\Arturia
2011-06-17 15:42:19 ----D---- C:\Windows\Tasks
2011-06-17 15:42:19 ----D---- C:\Windows\system32\Tasks
2011-06-17 00:51:26 ----D---- C:\Windows\debug
2011-06-16 22:18:04 ----D---- C:\Windows\system32\DriverStore
2011-06-16 22:17:36 ----D---- C:\Program Files\Syncrosoft
2011-06-16 22:17:13 ----HD---- C:\ProgramData
2011-06-16 22:15:26 ----D---- C:\ProgramData\Arturia
2011-06-16 20:05:58 ----D---- C:\Program Files\Internet Explorer
2011-06-16 20:05:57 ----D---- C:\Windows\system32\migration
2011-06-16 20:03:40 ----A---- C:\Windows\system32\MRT.exe
2011-06-16 20:03:26 ----A---- C:\Windows\win.ini
2011-06-12 11:40:34 ----D---- C:\Program Files\ICQ6Toolbar
2011-06-12 10:23:20 ----D---- C:\ProgramData\ICQ
2011-06-08 17:50:09 ----D---- C:\Windows\SoftwareDistribution
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsl42d5ecb3;MpKsl42d5ecb3; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C189CF72-8ADF-4B68-A0A8-8A576A8F015B}\MpKsl42d5ecb3.sys [2011-07-05 28752]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2010-06-18 3764800]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2010-01-18 514104]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-06-22 130560]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-08-25 9024512]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-05-29 22712]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AF15BDA;AF9015 BDA Filter; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pelmouse;Mouse Suite Driver; C:\Windows\system32\DRIVERS\pelmouse.sys [2003-01-10 16384]
S3 pelusblf;USB Mouse Low Filter Driver; C:\Windows\system32\DRIVERS\pelusblf.sys [2003-02-11 9216]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-12 189984]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\Windows\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\Windows\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\Windows\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SynasUSB;SynasUSB; C:\Windows\system32\drivers\SynasUSB.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-09-28 41984]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2011-02-28 247096]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 820008]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-11 1343400]
-----------------EOF-----------------
Run by Uživatel at 2011-07-05 10:35:47
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 43 GB (64%) free of 67 GB
Total RAM: 2999 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:35:52, on 5.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
C:\Windows\System32\ico.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\FSRremoS.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files\ICQ7.5\ICQ.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Uživatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sk27211/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Google Update] "C:\Users\Uživatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
--
End of file - 6025 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2011-02-28 1048888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-06-24 1822600]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 136216]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 170520]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-04-28 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2010-03-22 496184]
"Mouse Suite 98 Daemon"=C:\Windows\system32\ICO.EXE [2004-07-14 57344]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-01-25 421160]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2011-05-29 1047656]
"Easy-PrintToolBox"=C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2004-01-14 409600]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-05-29 449584]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-05-29 449584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Uživatel\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-24 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Center Agent]
C:\Program Files\Genius Multimedia\HyperMediaCenter\DTVR\Scheduled.exe [2008-11-07 1520128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Uživatel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
C:\PROGRA~1\GENIUS~2\GENIUS~1\AFRCtl.exe [2009-03-25 81920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-08-25 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-07-05 10:35:47 ----D---- C:\rsit
2011-07-03 18:30:49 ----D---- C:\Program Files\Unlocker
2011-07-02 19:16:04 ----A---- C:\Windows\system32\pdfcmnnt.dll
2011-07-02 19:16:03 ----A---- C:\Windows\system32\MSMPIDE.DLL
2011-07-02 19:16:02 ----D---- C:\Program Files\PDFCreator
2011-06-28 21:09:12 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-28 21:09:09 ----A---- C:\Windows\system32\mssrch.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\tquery.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\mssph.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssvp.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-17 15:42:13 ----D---- C:\Program Files\Google
2011-06-16 22:17:13 ----D---- C:\ProgramData\eLicenser
2011-06-16 22:17:13 ----D---- C:\Program Files\eLicenser
2011-06-16 22:17:10 ----A---- C:\Windows\system32\SYNSOPOS.exe.cfg
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-16 11:15:43 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-16 11:15:42 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-16 11:15:41 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-16 11:15:36 ----A---- C:\Windows\system32\mshtml.dll
2011-06-16 11:15:35 ----A---- C:\Windows\system32\ieframe.dll
2011-06-16 11:15:34 ----A---- C:\Windows\system32\urlmon.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\wininet.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\ieui.dll
2011-06-16 11:15:33 ----A---- C:\Windows\system32\iertutil.dll
2011-06-16 11:15:31 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-14 13:48:25 ----D---- C:\Program Files\VirtualDJ
2011-06-14 13:08:23 ----DC---- C:\ProgramData\{4A818508-3355-4FBC-B302-D53B599DD9D5}
======List of files/folders modified in the last 1 months======
2011-07-05 10:35:53 ----D---- C:\Windows\Prefetch
2011-07-05 10:35:52 ----D---- C:\Program Files\trend micro
2011-07-05 10:28:49 ----D---- C:\Windows\Temp
2011-07-05 10:27:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-05 10:26:59 ----D---- C:\Windows\system32\drivers
2011-07-05 10:25:06 ----D---- C:\Users\Uživatel\AppData\Roaming\Media Player Classic
2011-07-05 10:25:04 ----D---- C:\Windows
2011-07-05 10:21:21 ----D---- C:\Windows\system32\config
2011-07-05 10:10:50 ----D---- C:\Users\Uživatel\AppData\Roaming\ICQ
2011-07-04 20:25:44 ----D---- C:\Windows\System32
2011-07-04 20:25:44 ----D---- C:\Windows\inf
2011-07-04 20:25:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-03 23:08:35 ----SHD---- C:\System Volume Information
2011-07-03 18:30:49 ----RD---- C:\Program Files
2011-07-01 10:05:33 ----SHD---- C:\Windows\Installer
2011-07-01 10:05:31 ----D---- C:\Users\Uživatel\AppData\Roaming\Mozilla
2011-07-01 09:35:38 ----D---- C:\Program Files\ICQ7.5
2011-06-29 09:01:04 ----D---- C:\Windows\winsxs
2011-06-29 08:59:55 ----RSD---- C:\Windows\Fonts
2011-06-28 21:10:08 ----D---- C:\Program Files\Microsoft Office
2011-06-28 21:09:03 ----D---- C:\Windows\system32\catroot
2011-06-28 21:09:02 ----D---- C:\Windows\system32\catroot2
2011-06-28 14:29:25 ----D---- C:\Program Files\rajce
2011-06-18 15:58:19 ----D---- C:\Windows\Microsoft.NET
2011-06-18 15:58:18 ----RSD---- C:\Windows\assembly
2011-06-17 16:04:43 ----D---- C:\Program Files\VstPlugins
2011-06-17 15:58:03 ----D---- C:\Program Files\Arturia
2011-06-17 15:42:19 ----D---- C:\Windows\Tasks
2011-06-17 15:42:19 ----D---- C:\Windows\system32\Tasks
2011-06-17 00:51:26 ----D---- C:\Windows\debug
2011-06-16 22:18:04 ----D---- C:\Windows\system32\DriverStore
2011-06-16 22:17:36 ----D---- C:\Program Files\Syncrosoft
2011-06-16 22:17:13 ----HD---- C:\ProgramData
2011-06-16 22:15:26 ----D---- C:\ProgramData\Arturia
2011-06-16 20:05:58 ----D---- C:\Program Files\Internet Explorer
2011-06-16 20:05:57 ----D---- C:\Windows\system32\migration
2011-06-16 20:03:40 ----A---- C:\Windows\system32\MRT.exe
2011-06-16 20:03:26 ----A---- C:\Windows\win.ini
2011-06-12 11:40:34 ----D---- C:\Program Files\ICQ6Toolbar
2011-06-12 10:23:20 ----D---- C:\ProgramData\ICQ
2011-06-08 17:50:09 ----D---- C:\Windows\SoftwareDistribution
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsl42d5ecb3;MpKsl42d5ecb3; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C189CF72-8ADF-4B68-A0A8-8A576A8F015B}\MpKsl42d5ecb3.sys [2011-07-05 28752]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2010-06-18 3764800]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2010-01-18 514104]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-06-22 130560]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-08-25 9024512]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-05-29 22712]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AF15BDA;AF9015 BDA Filter; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pelmouse;Mouse Suite Driver; C:\Windows\system32\DRIVERS\pelmouse.sys [2003-01-10 16384]
S3 pelusblf;USB Mouse Low Filter Driver; C:\Windows\system32\DRIVERS\pelusblf.sys [2003-02-11 9216]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-12 189984]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\Windows\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\Windows\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\Windows\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SynasUSB;SynasUSB; C:\Windows\system32\drivers\SynasUSB.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-09-28 41984]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2011-02-28 247096]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 820008]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-11 1343400]
-----------------EOF-----------------
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: prosím o preventivní kontrolu logu
Dobrý večer 
Odinstalovat ICQtoolbar + všechny nepotřebné toolbary
aktualizace IE 9 + všechny dostupné aktualizace systému
Spustíme si HijackThis
(Pokud nenajdeme nebo nemáme,tak stáhneme ZDE )
Otevřeme si Služby
TFC

Údržba PC:
1)Čištění dočasných složek + neplatné registry
Ccleaner
Defraggler
FileHippo.com Update Checker
Vy jste něco mazal s Malwarebytes? Jak se chová PC 





Kód: Vybrat vše
C:\Program Files\trend micro\Uživatel.exe
- Dále klikneme na tlačítko Do a system scan only
- Najdeme a označíme následující položky:
Kód: Vybrat vše
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sk27211/ R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll R3 - URLSearchHook: (no name) - - (no file) O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [Google Update] "C:\Users\Uživatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
- klikneme na položku Fix checked a potvrdíme tlačítkem Ano


- Stiskněte klávesovou kombinaci WIN+R( nebo start-spustit ),čímž se vám otevře okno pro zadání příkazu pro spuštění. Zkopírujte a vložte sem následujíci text: services.msc a dejte enter
- Otevře se vám okno se službami vašeho pc,najděte následující služby,dvojklikem rozklikněte,klikneme na Zastavit a dále nastavte Typ spuštění:Zakázano
Kód: Vybrat vše
Služba Google Update (gupdate) Služba Google Update (gupdatem)


- Stáhneme a spustíme program
- Klikneme na Start a potvrdíme OK
- Program začne uklízet,poté restartuje pc
- po použití program smažte

Údržba PC:
1)Čištění dočasných složek + neplatné registry

- Stáhneme a nainstalujeme program
- Spustíme program
-
ČISTIČ
Windows zde necháme vše jak je (pokud používáme IE,tak odškrkneme jeho položky) a zaškrkneme položky Start Menu zástupci a Zástupci na ploše
Aplikace - necháme jak je,ale pokud používáme nějaký prohlížeč (Google chrome,Firefox,Opera..) tak odškrkneme jeho položky
>Stiskeneme tlačítko Analyzovat a poté Spustit Cleaner - Registry
>Stiskneme tlačítko Hledej problémy,program začne hledat neplatné registry..podé zvolíme Opravit vybrané problémy..
>Program se zeptá,zda chceme vytvořit zálohu registrů,zvolíme ano a uložíme si někde zálohu(kdyby byli po opravení registru s něčím problémy,tak zálohu
obnovíme tak,že spustíme uloženou zálohu a potvrdíme ano),dále zvolíme Opravit všechny problémy a Zavřít
>opakujte dokud nebude registr bez problémů - Program používáme 1x 14dní (záleží na používání pc,můžeme i jednou týdně)


- Stáhneme a nainstalujeme program
- Spustíme program
- Vybereme disk ( C:,D:..prostě který používáme)
- Pokud je ve sloupci Fragmentace více než 5% dejte Defragmentovat
- Proveďte se všemi používanými disky
- Provádíme 1x za měsíc


- Stáhneme a nainstalujeme program(Při instalaci odškrkneme volbu Run at Startup )
- Spustíme program
- Program vyhledá nainstalované programy v PC a zjistí dostupné aktualizace
- Poté se vám otevře internetová stránka,kde budou nabídnuté aplikace k aktualizování
>X Updates Detected..to jsou dostupné aktualizace..
> klikneme na zelenou šipečku a stáhneme program,poté nainstalujeme jeho aktuální verzi
>X Beta Updates Detected..tyto aktualizace nestahujte,jedná se o betaverze,které jsou ve vývoji a jsou nestabilní
- Provádíme 1x za 14 dní nebo jednou za měsíc


Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: prosím o preventivní kontrolu logu
Děkuji za rady, asi jsem malwarebytes něco smazal... je nějaký problém?
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: prosím o preventivní kontrolu logu
Není,ale MBAM má občas falešné detekce,tak je třeba nechat zkontrolovat,než smažete
Poprosil bych ještě o novou úplnou kontrolu s MBAM a sem mi vložte log,předem nic NEMAZAT 
Až budete mít vše,co jsem vám radil provedené,tak mi sem vložte log z RSITu na kontrolu


Až budete mít vše,co jsem vám radil provedené,tak mi sem vložte log z RSITu na kontrolu

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: prosím o preventivní kontrolu logu
Zde jsou ty logy:
Malwarebytes' Anti-Malware 1.51.0.1200
http://www.malwarebytes.org
Verze databáze: 7026
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
6.7.2011 10:05:22
mbam-log-2011-07-06 (10-05-22).txt
Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 307604
Uplynulý čas: 1 hodin, 6 minut, 26 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Logfile of random's system information tool 1.08 (written by random/random)
Run by Uživatel at 2011-07-06 10:29:42
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 42 GB (62%) free of 67 GB
Total RAM: 2999 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:29:49, on 6.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
C:\Windows\System32\ico.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\FSRremoS.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\taskhost.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Uživatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
--
End of file - 4979 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-06-24 1822600]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-04-28 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2010-03-22 496184]
"Mouse Suite 98 Daemon"=C:\Windows\system32\ICO.EXE [2004-07-14 57344]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-01-25 421160]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2011-05-29 1047656]
"Easy-PrintToolBox"=C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2004-01-14 409600]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-05-29 449584]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Center Agent]
C:\Program Files\Genius Multimedia\HyperMediaCenter\DTVR\Scheduled.exe [2008-11-07 1520128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Uživatel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
C:\PROGRA~1\GENIUS~2\GENIUS~1\AFRCtl.exe [2009-03-25 81920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-07-06 10:29:42 ----D---- C:\rsit
2011-07-06 00:44:18 ----D---- C:\Program Files\Microsoft Silverlight
2011-07-06 00:42:25 ----A---- C:\Windows\system32\wininet.dll
2011-07-06 00:42:25 ----A---- C:\Windows\system32\urlmon.dll
2011-07-06 00:42:25 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-06 00:42:25 ----A---- C:\Windows\system32\msls31.dll
2011-07-06 00:42:25 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\webcheck.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\url.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-06 00:42:24 ----A---- C:\Windows\system32\msrating.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-06 00:42:24 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieui.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iesetup.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iertutil.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iernonce.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieframe.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-06 00:42:24 ----A---- C:\Windows\system32\icardie.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\wextract.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\vbscript.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\occache.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\mshtml.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\mshta.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\jscript9.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\jscript.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\inseng.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\imgutil.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\iexpress.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\iepeers.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\ieakui.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\admparse.dll
2011-07-06 00:38:35 ----D---- C:\ProgramData\Avanquest
2011-07-02 19:16:04 ----A---- C:\Windows\system32\pdfcmnnt.dll
2011-07-02 19:16:03 ----A---- C:\Windows\system32\MSMPIDE.DLL
2011-07-02 19:16:02 ----D---- C:\Program Files\PDFCreator
2011-06-28 21:09:12 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-28 21:09:09 ----A---- C:\Windows\system32\mssrch.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\tquery.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\mssph.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssvp.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-17 15:42:13 ----D---- C:\Program Files\Google
2011-06-16 22:17:13 ----D---- C:\ProgramData\eLicenser
2011-06-16 22:17:10 ----A---- C:\Windows\system32\SYNSOPOS.exe.cfg
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-16 11:15:43 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-16 11:15:42 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-16 11:15:41 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-14 13:48:25 ----D---- C:\Program Files\VirtualDJ
2011-06-14 13:08:23 ----DC---- C:\ProgramData\{4A818508-3355-4FBC-B302-D53B599DD9D5}
======List of files/folders modified in the last 1 months======
2011-07-06 10:29:48 ----D---- C:\Program Files\trend micro
2011-07-06 10:26:31 ----RD---- C:\Program Files
2011-07-06 10:24:28 ----D---- C:\Windows\system32\config
2011-07-06 10:24:27 ----D---- C:\Windows\Prefetch
2011-07-06 10:22:19 ----D---- C:\Windows\Temp
2011-07-06 10:21:15 ----D---- C:\Windows
2011-07-06 10:11:10 ----D---- C:\Windows\Logs
2011-07-06 10:10:40 ----D---- C:\Users\Uživatel\AppData\Roaming\ICQ
2011-07-06 10:03:16 ----D---- C:\Users\Uživatel\AppData\Roaming\Audacity
2011-07-06 00:50:24 ----D---- C:\Windows\winsxs
2011-07-06 00:49:22 ----D---- C:\Windows\System32
2011-07-06 00:48:33 ----D---- C:\Windows\system32\migration
2011-07-06 00:48:33 ----D---- C:\Windows\system32\cs-CZ
2011-07-06 00:48:33 ----D---- C:\Windows\PolicyDefinitions
2011-07-06 00:48:33 ----D---- C:\Program Files\Internet Explorer
2011-07-06 00:48:32 ----D---- C:\Windows\system32\en-US
2011-07-06 00:44:42 ----SHD---- C:\Windows\Installer
2011-07-06 00:44:41 ----SD---- C:\ProgramData\Microsoft
2011-07-06 00:43:34 ----D---- C:\Windows\system32\drivers
2011-07-06 00:43:29 ----D---- C:\Windows\system32\catroot
2011-07-06 00:43:29 ----D---- C:\Windows\inf
2011-07-06 00:43:28 ----D---- C:\Windows\system32\DriverStore
2011-07-06 00:42:55 ----D---- C:\Windows\system32\catroot2
2011-07-06 00:40:26 ----SHD---- C:\System Volume Information
2011-07-06 00:38:35 ----HD---- C:\ProgramData
2011-07-06 00:38:35 ----D---- C:\Program Files\Avanquest update
2011-07-06 00:34:38 ----D---- C:\Windows\SoftwareDistribution
2011-07-06 00:34:33 ----D---- C:\Users\Uživatel\AppData\Roaming\Media Player Classic
2011-07-05 10:27:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-04 20:25:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-01 10:05:31 ----D---- C:\Users\Uživatel\AppData\Roaming\Mozilla
2011-07-01 09:35:38 ----D---- C:\Program Files\ICQ7.5
2011-06-29 08:59:55 ----RSD---- C:\Windows\Fonts
2011-06-28 21:10:08 ----D---- C:\Program Files\Microsoft Office
2011-06-28 14:29:25 ----D---- C:\Program Files\rajce
2011-06-18 15:58:19 ----D---- C:\Windows\Microsoft.NET
2011-06-18 15:58:18 ----RSD---- C:\Windows\assembly
2011-06-17 15:42:19 ----D---- C:\Windows\Tasks
2011-06-17 15:42:19 ----D---- C:\Windows\system32\Tasks
2011-06-17 00:51:26 ----D---- C:\Windows\debug
2011-06-16 22:15:26 ----D---- C:\ProgramData\Arturia
2011-06-16 20:03:40 ----A---- C:\Windows\system32\MRT.exe
2011-06-16 20:03:26 ----A---- C:\Windows\win.ini
2011-06-12 10:23:20 ----D---- C:\ProgramData\ICQ
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsl300afe50;MpKsl300afe50; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B320E8B1-2E5B-458D-97CB-F26DD78AF4A3}\MpKsl300afe50.sys [2011-07-06 28752]
R1 MpKslf8a2ae6e;MpKslf8a2ae6e; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B320E8B1-2E5B-458D-97CB-F26DD78AF4A3}\MpKslf8a2ae6e.sys [2011-07-06 28752]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2010-06-18 3764800]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2010-01-18 514104]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-06-22 130560]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-05-29 22712]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AF15BDA;AF9015 BDA Filter; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pelmouse;Mouse Suite Driver; C:\Windows\system32\DRIVERS\pelmouse.sys [2003-01-10 16384]
S3 pelusblf;USB Mouse Low Filter Driver; C:\Windows\system32\DRIVERS\pelusblf.sys [2003-02-11 9216]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-12 189984]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-03-21 362600]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\Windows\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\Windows\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\Windows\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SynasUSB;SynasUSB; C:\Windows\system32\drivers\SynasUSB.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-09-28 41984]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 820008]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-11 1343400]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
-----------------EOF-----------------
Malwarebytes' Anti-Malware 1.51.0.1200
http://www.malwarebytes.org
Verze databáze: 7026
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
6.7.2011 10:05:22
mbam-log-2011-07-06 (10-05-22).txt
Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 307604
Uplynulý čas: 1 hodin, 6 minut, 26 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Logfile of random's system information tool 1.08 (written by random/random)
Run by Uživatel at 2011-07-06 10:29:42
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 42 GB (62%) free of 67 GB
Total RAM: 2999 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:29:49, on 6.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
C:\Windows\System32\ico.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\FSRremoS.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\taskhost.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Uživatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
--
End of file - 4979 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3793256071-1351611765-3128880251-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-06-24 1822600]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-04-28 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2010-03-22 496184]
"Mouse Suite 98 Daemon"=C:\Windows\system32\ICO.EXE [2004-07-14 57344]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-01-25 421160]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2011-05-29 1047656]
"Easy-PrintToolBox"=C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2004-01-14 409600]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-05-29 449584]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Center Agent]
C:\Program Files\Genius Multimedia\HyperMediaCenter\DTVR\Scheduled.exe [2008-11-07 1520128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Uživatel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Remote Control.lnk]
C:\PROGRA~1\GENIUS~2\GENIUS~1\AFRCtl.exe [2009-03-25 81920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-07-06 10:29:42 ----D---- C:\rsit
2011-07-06 00:44:18 ----D---- C:\Program Files\Microsoft Silverlight
2011-07-06 00:42:25 ----A---- C:\Windows\system32\wininet.dll
2011-07-06 00:42:25 ----A---- C:\Windows\system32\urlmon.dll
2011-07-06 00:42:25 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-06 00:42:25 ----A---- C:\Windows\system32\msls31.dll
2011-07-06 00:42:25 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\webcheck.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\url.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-06 00:42:24 ----A---- C:\Windows\system32\msrating.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-06 00:42:24 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieui.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iesetup.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iertutil.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iernonce.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieframe.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-06 00:42:24 ----A---- C:\Windows\system32\icardie.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-06 00:42:24 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\wextract.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\vbscript.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\occache.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\mshtml.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\mshta.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\jscript9.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\jscript.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\inseng.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\imgutil.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\iexpress.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-06 00:42:23 ----A---- C:\Windows\system32\iepeers.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\ieakui.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-06 00:42:23 ----A---- C:\Windows\system32\admparse.dll
2011-07-06 00:38:35 ----D---- C:\ProgramData\Avanquest
2011-07-02 19:16:04 ----A---- C:\Windows\system32\pdfcmnnt.dll
2011-07-02 19:16:03 ----A---- C:\Windows\system32\MSMPIDE.DLL
2011-07-02 19:16:02 ----D---- C:\Program Files\PDFCreator
2011-06-28 21:09:12 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-28 21:09:09 ----A---- C:\Windows\system32\mssrch.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\tquery.dll
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-28 21:09:08 ----A---- C:\Windows\system32\mssph.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssvp.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-28 21:09:07 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-17 15:42:13 ----D---- C:\Program Files\Google
2011-06-16 22:17:13 ----D---- C:\ProgramData\eLicenser
2011-06-16 22:17:10 ----A---- C:\Windows\system32\SYNSOPOS.exe.cfg
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-16 11:15:45 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-16 11:15:44 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-16 11:15:43 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-16 11:15:42 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-16 11:15:41 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-16 11:15:29 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-14 13:48:25 ----D---- C:\Program Files\VirtualDJ
2011-06-14 13:08:23 ----DC---- C:\ProgramData\{4A818508-3355-4FBC-B302-D53B599DD9D5}
======List of files/folders modified in the last 1 months======
2011-07-06 10:29:48 ----D---- C:\Program Files\trend micro
2011-07-06 10:26:31 ----RD---- C:\Program Files
2011-07-06 10:24:28 ----D---- C:\Windows\system32\config
2011-07-06 10:24:27 ----D---- C:\Windows\Prefetch
2011-07-06 10:22:19 ----D---- C:\Windows\Temp
2011-07-06 10:21:15 ----D---- C:\Windows
2011-07-06 10:11:10 ----D---- C:\Windows\Logs
2011-07-06 10:10:40 ----D---- C:\Users\Uživatel\AppData\Roaming\ICQ
2011-07-06 10:03:16 ----D---- C:\Users\Uživatel\AppData\Roaming\Audacity
2011-07-06 00:50:24 ----D---- C:\Windows\winsxs
2011-07-06 00:49:22 ----D---- C:\Windows\System32
2011-07-06 00:48:33 ----D---- C:\Windows\system32\migration
2011-07-06 00:48:33 ----D---- C:\Windows\system32\cs-CZ
2011-07-06 00:48:33 ----D---- C:\Windows\PolicyDefinitions
2011-07-06 00:48:33 ----D---- C:\Program Files\Internet Explorer
2011-07-06 00:48:32 ----D---- C:\Windows\system32\en-US
2011-07-06 00:44:42 ----SHD---- C:\Windows\Installer
2011-07-06 00:44:41 ----SD---- C:\ProgramData\Microsoft
2011-07-06 00:43:34 ----D---- C:\Windows\system32\drivers
2011-07-06 00:43:29 ----D---- C:\Windows\system32\catroot
2011-07-06 00:43:29 ----D---- C:\Windows\inf
2011-07-06 00:43:28 ----D---- C:\Windows\system32\DriverStore
2011-07-06 00:42:55 ----D---- C:\Windows\system32\catroot2
2011-07-06 00:40:26 ----SHD---- C:\System Volume Information
2011-07-06 00:38:35 ----HD---- C:\ProgramData
2011-07-06 00:38:35 ----D---- C:\Program Files\Avanquest update
2011-07-06 00:34:38 ----D---- C:\Windows\SoftwareDistribution
2011-07-06 00:34:33 ----D---- C:\Users\Uživatel\AppData\Roaming\Media Player Classic
2011-07-05 10:27:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-04 20:25:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-01 10:05:31 ----D---- C:\Users\Uživatel\AppData\Roaming\Mozilla
2011-07-01 09:35:38 ----D---- C:\Program Files\ICQ7.5
2011-06-29 08:59:55 ----RSD---- C:\Windows\Fonts
2011-06-28 21:10:08 ----D---- C:\Program Files\Microsoft Office
2011-06-28 14:29:25 ----D---- C:\Program Files\rajce
2011-06-18 15:58:19 ----D---- C:\Windows\Microsoft.NET
2011-06-18 15:58:18 ----RSD---- C:\Windows\assembly
2011-06-17 15:42:19 ----D---- C:\Windows\Tasks
2011-06-17 15:42:19 ----D---- C:\Windows\system32\Tasks
2011-06-17 00:51:26 ----D---- C:\Windows\debug
2011-06-16 22:15:26 ----D---- C:\ProgramData\Arturia
2011-06-16 20:03:40 ----A---- C:\Windows\system32\MRT.exe
2011-06-16 20:03:26 ----A---- C:\Windows\win.ini
2011-06-12 10:23:20 ----D---- C:\ProgramData\ICQ
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsl300afe50;MpKsl300afe50; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B320E8B1-2E5B-458D-97CB-F26DD78AF4A3}\MpKsl300afe50.sys [2011-07-06 28752]
R1 MpKslf8a2ae6e;MpKslf8a2ae6e; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B320E8B1-2E5B-458D-97CB-F26DD78AF4A3}\MpKslf8a2ae6e.sys [2011-07-06 28752]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2010-06-18 3764800]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2010-01-18 514104]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-06-22 130560]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-05-29 22712]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AF15BDA;AF9015 BDA Filter; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 pelmouse;Mouse Suite Driver; C:\Windows\system32\DRIVERS\pelmouse.sys [2003-01-10 16384]
S3 pelusblf;USB Mouse Low Filter Driver; C:\Windows\system32\DRIVERS\pelusblf.sys [2003-02-11 9216]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-12 189984]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-03-21 362600]
S3 s117bus;Sony Ericsson Device 117 driver (WDM); C:\Windows\system32\DRIVERS\s117bus.sys [2007-06-25 82984]
S3 s117mdfl;Sony Ericsson Device 117 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s117mdfl.sys [2007-06-25 14888]
S3 s117mdm;Sony Ericsson Device 117 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s117mdm.sys [2007-06-25 108456]
S3 s117mgmt;Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s117mgmt.sys [2007-06-25 100264]
S3 s117nd5;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS); C:\Windows\system32\DRIVERS\s117nd5.sys [2007-06-25 22952]
S3 s117obex;Sony Ericsson Device 117 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s117obex.sys [2007-06-25 98344]
S3 s117unic;Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM); C:\Windows\system32\DRIVERS\s117unic.sys [2007-06-25 98856]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SynasUSB;SynasUSB; C:\Windows\system32\drivers\SynasUSB.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-09-28 41984]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 820008]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-11 1343400]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-06-17 136176]
-----------------EOF-----------------
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: prosím o preventivní kontrolu logu
Výborně
havěť přítomna není...
Jestli máte u Malwarebytes zapnutou ochranu v reálném čase,tak vypnout
Oni ji totiž tuším nabízejí teď na zkoušku zdarma,ale je to zbytečnost pro nás..
Spustíme si HijackThis
(Pokud nenajdeme nebo nemáme,tak stáhneme ZDE )
Jinak je to z mé strany vše,pokud nemáte nějaké dotazy či přání s čím bych vám mohl pomoci 





Kód: Vybrat vše
C:\Program Files\trend micro\Uživatel.exe
- Dále klikneme na tlačítko Do a system scan only
- Najdeme a označíme následující položky:
Kód: Vybrat vše
R3 - URLSearchHook: (no name) - - (no file) O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
- klikneme na položku Fix checked a potvrdíme tlačítkem Ano


Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: prosím o preventivní kontrolu logu
Vše je v pořádku, děkuji moc.
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: prosím o preventivní kontrolu logu
není za co
rád jsem vám pomohl..hezký zbytek dne 


Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2