
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
FB vir
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: FB vir
V pohodě, nikam nespěchám. 
Oba antiviry jsou virem poškozené a nepůjdou odinstalovat. Musíš je odebrat přes tzv. "removery".
Zde je remover pro ESET a zde první remover pro MSE a potom použij tento druhý remover pro MSE.
Pokud máš ESET legální = zakoupená licence (
), tak jej pak musíš nainstalovat znova.
Pokud byl ESET cracknutý, vrať si tam zpět třeba ten MSE - odkaz zde.
Re: FB vir
Ahoj
podarilo sa mi odinstalovat obidva antiviry. Mam vsak probelm nainstalovat naspat MSE. Vyhadzuje mi error ktory som dal do prilohy
podarilo sa mi odinstalovat obidva antiviry. Mam vsak probelm nainstalovat naspat MSE. Vyhadzuje mi error ktory som dal do prilohy
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: FB vir
Re: FB vir
Nakoniac som naistaloval Aviru.
Dakujem velmi pekne za pomoc
Dakujem velmi pekne za pomoc
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: FB vir
OK, tak aspoň, že ta Avira vyšla.
Ještě mi sem hoď log ze RSITu pro kontrolu, nemáme ještě hotovo.
Ještě mi sem hoď log ze RSITu pro kontrolu, nemáme ještě hotovo.
Re: FB vir
Logfile of random's system information tool 1.09 (written by random/random)
Run by Juraj Stevanka at 2011-09-22 21:21:58
Microsoft Windows XP Professional Service Pack 3
System drive C: has 33 GB (35%) free of 95 GB
Total RAM: 2046 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:22:00, on 22.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Avira\AntiVir Desktop\update.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
c:\program files\avira\antivir desktop\avgnt.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Documents and Settings\Juraj Stevanka\My Documents\Preberanie\RSIT.exe
C:\Program Files\trend micro\Juraj Stevanka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10w_Plugin.exe -update plugin
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0336779765
O17 - HKLM\System\CCS\Services\Tcpip\..\{130E46B2-0A02-468A-B66E-C7BAEEE2B1D9}: NameServer = 88.83.241.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
--
End of file - 4831 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Juraj Stevanka\Application Data\Mozilla\Firefox\Profiles\z0rxhbw4.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "en-US@dictionaries.addons.mozilla.org:5.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
yahoo.xml
zoznam-sk.xml
C:\Documents and Settings\Juraj Stevanka\Application Data\Mozilla\Firefox\Profiles\z0rxhbw4.default\extensions\
en-US@dictionaries.addons.mozilla.org
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2004-08-10 59392]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-04-21 281768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"=c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\WINDOWS\system32\Macromed\Flash\FlashUtil10w_Plugin.exe [2011-09-15 243360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-12-02 47104]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"EnableSecureUIAPaths"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoStartMenuPinnedList"=0
"NoStartMenuMFUprogramsList"=0
"NoUserNameInStartMenu"=0
"NoStartMenuSubFolders"=0
"NoCommonGroups"=0
"NoPrinterTabs"=0
"NoDeletePrinter"=0
"NoAddPrinter"=0
"NoPrinters"=0
"NoFavoritesMenu"=0
"NoDrives"=0
"NoRecentDocsNetHood"=0
"NoChangeAnimation"=0
"NoChangeKeyboardNavigationIndicators"=0
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.DIVX"=divx.dll
"vidc.XVID"=xvidvfw.dll
"msacm.lameacm"=lameACM.acm
"vidc.3iv2"=3ivxVfWCodec.dll
"VIDC.wmv3"=wmv9vcm.dll
"VIDC.VP60"=vp6vfw.dll
"VIDC.VP61"=vp6vfw.dll
"VIDC.VP62"=vp6vfw.dll
"VIDC.VP70"=vp7vfw.dll
"VIDC.VP31"=vp31vfw.dll
"vidc.MPG4"=Mpg4c32.dll
"vidc.MP42"=Mpg4c32.dll
"vidc.MP43"=Mpg4c32.dll
"msacm.ac3acm"=ac3acm.acm
======List of files/folders created in the last 1 month======
2012-02-09 20:34:49 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\TS3Client
2012-01-21 23:36:05 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\Godlike
2012-01-08 00:09:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2012-01-08 00:09:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2012-01-08 00:09:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2012-01-08 00:06:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2012-01-08 00:05:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2012-01-08 00:05:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2503658$
2012-01-08 00:04:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2012-01-08 00:04:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2497640$
2012-01-08 00:04:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-01-08 00:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2511455$
2012-01-08 00:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2012-01-08 00:01:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-12-14 22:18:07 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\Google
2011-12-14 21:32:18 ----D---- C:\Program Files\Google
2011-12-14 21:19:50 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\pdfforge
2011-12-13 23:38:17 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-12-13 23:38:16 ----D---- C:\Program Files\PDFCreator
2011-12-13 23:38:16 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-09-21 21:00:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676-v2$
2011-09-21 19:20:57 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\Avira
2011-09-20 21:37:42 ----D---- C:\WINDOWS\system32\NtmsData
2011-09-20 21:33:52 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2011-09-20 21:33:46 ----D---- C:\Program Files\Avira
2011-09-20 21:33:46 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2011-09-18 14:34:13 ----SHD---- C:\RECYCLER
2011-09-18 14:26:21 ----D---- C:\WINDOWS\temp
2011-09-18 14:26:20 ----A---- C:\ComboFix.txt
2011-09-18 10:47:00 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2011-09-16 06:37:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-09-16 06:36:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-16 06:33:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-16 06:09:34 ----A---- C:\WINDOWS\NIRCMD.exe
2011-09-15 14:57:39 ----A---- C:\Boot.bak
2011-09-15 14:57:33 ----RASHD---- C:\cmdcons
2011-09-15 14:55:04 ----D---- C:\WINDOWS\CSC
2011-09-15 14:40:52 ----A---- C:\WINDOWS\zip.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\SWSC.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\SWREG.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\sed.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\PEV.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\MBR.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\grep.exe
2011-09-15 12:10:05 ----D---- C:\WINDOWS\ERDNT
2011-09-15 12:04:18 ----D---- C:\Qoobox
2011-09-15 11:58:12 ----D---- C:\Program Files\Common Files\Adobe
2011-09-15 11:58:12 ----D---- C:\Program Files\Adobe
2011-09-15 10:32:09 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-09-15 10:17:40 ----D---- C:\Program Files\ATI
2011-09-10 11:58:54 ----D---- C:\ATI
2011-09-10 11:58:29 ----D---- C:\rsit
2011-09-10 11:58:29 ----D---- C:\Program Files\trend micro
======List of files/folders modified in the last 1 month======
2012-01-21 23:38:48 ----D---- C:\Program Files\Mozilla Firefox
2012-01-21 23:36:00 ----D---- C:\Program Files\WinTools Software
2011-12-07 14:21:56 ----SD---- C:\Documents and Settings\Juraj Stevanka\Application Data\Microsoft
2011-09-22 21:20:58 ----D---- C:\WINDOWS\Prefetch
2011-09-22 21:18:15 ----A---- C:\WINDOWS\ModemLog_AC97 Soft Data Fax Modem with SmartCP.txt
2011-09-22 21:18:07 ----D---- C:\WINDOWS\Registration
2011-09-22 21:18:00 ----D---- C:\WINDOWS
2011-09-22 21:17:54 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-21 22:02:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-21 21:01:13 ----HD---- C:\WINDOWS\inf
2011-09-21 21:00:57 ----D---- C:\WINDOWS\system32
2011-09-21 20:04:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-20 21:37:41 ----D---- C:\WINDOWS\repair
2011-09-20 21:33:52 ----D---- C:\WINDOWS\system32\drivers
2011-09-20 21:33:46 ----RD---- C:\Program Files
2011-09-20 21:11:32 ----D---- C:\WINDOWS\pchealth
2011-09-20 21:11:28 ----SHD---- C:\WINDOWS\Installer
2011-09-20 21:11:25 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-09-20 21:10:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-09-20 20:13:48 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-18 14:59:29 ----D---- C:\WINDOWS\WinSxS
2011-09-18 14:58:15 ----D---- C:\WINDOWS\system32\config
2011-09-18 14:38:33 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-09-18 14:24:56 ----A---- C:\WINDOWS\system.ini
2011-09-18 14:23:38 ----D---- C:\WINDOWS\AppPatch
2011-09-18 14:23:34 ----D---- C:\Program Files\Common Files
2011-09-18 14:13:05 ----SD---- C:\WINDOWS\Tasks
2011-09-18 13:49:35 ----D---- C:\WINDOWS\Debug
2011-09-16 06:36:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-16 06:34:16 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-16 06:15:21 ----D---- C:\WINDOWS\system32\drivers\etc
2011-09-16 05:58:15 ----D---- C:\WINDOWS\system32\CatRoot
2011-09-15 14:57:40 ----RASH---- C:\boot.ini
2011-09-15 14:33:21 ----D---- C:\Documents and Settings
2011-09-15 11:58:34 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-09-10 12:01:14 ----SHD---- C:\System Volume Information
2011-09-10 12:01:14 ----D---- C:\WINDOWS\system32\Restore
2011-09-09 11:12:13 ----A---- C:\WINDOWS\system32\crypt32.dll
2011-09-06 19:19:21 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\vlc
2011-08-29 09:28:13 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2004-08-10 19840]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-10-05 691696]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-10-05 278728]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2011-09-21 66616]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-10-05 25416]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-12-02 1412608]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2008-10-23 1391104]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camc6aud.sys [2005-08-02 38016]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camc6hal.sys [2005-08-02 349312]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-08-23 1035008]
R3 HSFHWATI;HSFHWATI; C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-23 231424]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-08-23 718464]
S1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-09-21 138192]
S3 a3ij3v2y;a3ij3v2y; C:\WINDOWS\system32\drivers\a3ij3v2y.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\JURAJS~1\LOCALS~1\Temp\catchme.sys []
S3 massfilter;ZTE Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter.sys []
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-09-21 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-12-02 393216]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2004-08-10 194560]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2004-08-10 102912]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
-----------------EOF-----------------
Run by Juraj Stevanka at 2011-09-22 21:21:58
Microsoft Windows XP Professional Service Pack 3
System drive C: has 33 GB (35%) free of 95 GB
Total RAM: 2046 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:22:00, on 22.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Avira\AntiVir Desktop\update.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
c:\program files\avira\antivir desktop\avgnt.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Documents and Settings\Juraj Stevanka\My Documents\Preberanie\RSIT.exe
C:\Program Files\trend micro\Juraj Stevanka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10w_Plugin.exe -update plugin
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0336779765
O17 - HKLM\System\CCS\Services\Tcpip\..\{130E46B2-0A02-468A-B66E-C7BAEEE2B1D9}: NameServer = 88.83.241.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
--
End of file - 4831 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Juraj Stevanka\Application Data\Mozilla\Firefox\Profiles\z0rxhbw4.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "en-US@dictionaries.addons.mozilla.org:5.0.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
yahoo.xml
zoznam-sk.xml
C:\Documents and Settings\Juraj Stevanka\Application Data\Mozilla\Firefox\Profiles\z0rxhbw4.default\extensions\
en-US@dictionaries.addons.mozilla.org
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2004-08-10 59392]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-04-21 281768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"=c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\WINDOWS\system32\Macromed\Flash\FlashUtil10w_Plugin.exe [2011-09-15 243360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-12-02 47104]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"EnableSecureUIAPaths"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoStartMenuPinnedList"=0
"NoStartMenuMFUprogramsList"=0
"NoUserNameInStartMenu"=0
"NoStartMenuSubFolders"=0
"NoCommonGroups"=0
"NoPrinterTabs"=0
"NoDeletePrinter"=0
"NoAddPrinter"=0
"NoPrinters"=0
"NoFavoritesMenu"=0
"NoDrives"=0
"NoRecentDocsNetHood"=0
"NoChangeAnimation"=0
"NoChangeKeyboardNavigationIndicators"=0
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.DIVX"=divx.dll
"vidc.XVID"=xvidvfw.dll
"msacm.lameacm"=lameACM.acm
"vidc.3iv2"=3ivxVfWCodec.dll
"VIDC.wmv3"=wmv9vcm.dll
"VIDC.VP60"=vp6vfw.dll
"VIDC.VP61"=vp6vfw.dll
"VIDC.VP62"=vp6vfw.dll
"VIDC.VP70"=vp7vfw.dll
"VIDC.VP31"=vp31vfw.dll
"vidc.MPG4"=Mpg4c32.dll
"vidc.MP42"=Mpg4c32.dll
"vidc.MP43"=Mpg4c32.dll
"msacm.ac3acm"=ac3acm.acm
======List of files/folders created in the last 1 month======
2012-02-09 20:34:49 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\TS3Client
2012-01-21 23:36:05 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\Godlike
2012-01-08 00:09:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2012-01-08 00:09:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2012-01-08 00:09:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2506223$
2012-01-08 00:06:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2012-01-08 00:05:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2012-01-08 00:05:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2503658$
2012-01-08 00:04:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2012-01-08 00:04:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2497640$
2012-01-08 00:04:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-01-08 00:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2511455$
2012-01-08 00:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2012-01-08 00:01:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-12-14 22:18:07 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\Google
2011-12-14 21:32:18 ----D---- C:\Program Files\Google
2011-12-14 21:19:50 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\pdfforge
2011-12-13 23:38:17 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-12-13 23:38:16 ----D---- C:\Program Files\PDFCreator
2011-12-13 23:38:16 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-09-21 21:00:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676-v2$
2011-09-21 19:20:57 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\Avira
2011-09-20 21:37:42 ----D---- C:\WINDOWS\system32\NtmsData
2011-09-20 21:33:52 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2011-09-20 21:33:47 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2011-09-20 21:33:46 ----D---- C:\Program Files\Avira
2011-09-20 21:33:46 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2011-09-18 14:34:13 ----SHD---- C:\RECYCLER
2011-09-18 14:26:21 ----D---- C:\WINDOWS\temp
2011-09-18 14:26:20 ----A---- C:\ComboFix.txt
2011-09-18 10:47:00 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2011-09-16 06:37:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-09-16 06:36:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-16 06:33:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-16 06:09:34 ----A---- C:\WINDOWS\NIRCMD.exe
2011-09-15 14:57:39 ----A---- C:\Boot.bak
2011-09-15 14:57:33 ----RASHD---- C:\cmdcons
2011-09-15 14:55:04 ----D---- C:\WINDOWS\CSC
2011-09-15 14:40:52 ----A---- C:\WINDOWS\zip.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\SWSC.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\SWREG.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\sed.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\PEV.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\MBR.exe
2011-09-15 14:40:52 ----A---- C:\WINDOWS\grep.exe
2011-09-15 12:10:05 ----D---- C:\WINDOWS\ERDNT
2011-09-15 12:04:18 ----D---- C:\Qoobox
2011-09-15 11:58:12 ----D---- C:\Program Files\Common Files\Adobe
2011-09-15 11:58:12 ----D---- C:\Program Files\Adobe
2011-09-15 10:32:09 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-09-15 10:17:40 ----D---- C:\Program Files\ATI
2011-09-10 11:58:54 ----D---- C:\ATI
2011-09-10 11:58:29 ----D---- C:\rsit
2011-09-10 11:58:29 ----D---- C:\Program Files\trend micro
======List of files/folders modified in the last 1 month======
2012-01-21 23:38:48 ----D---- C:\Program Files\Mozilla Firefox
2012-01-21 23:36:00 ----D---- C:\Program Files\WinTools Software
2011-12-07 14:21:56 ----SD---- C:\Documents and Settings\Juraj Stevanka\Application Data\Microsoft
2011-09-22 21:20:58 ----D---- C:\WINDOWS\Prefetch
2011-09-22 21:18:15 ----A---- C:\WINDOWS\ModemLog_AC97 Soft Data Fax Modem with SmartCP.txt
2011-09-22 21:18:07 ----D---- C:\WINDOWS\Registration
2011-09-22 21:18:00 ----D---- C:\WINDOWS
2011-09-22 21:17:54 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-21 22:02:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-21 21:01:13 ----HD---- C:\WINDOWS\inf
2011-09-21 21:00:57 ----D---- C:\WINDOWS\system32
2011-09-21 20:04:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-20 21:37:41 ----D---- C:\WINDOWS\repair
2011-09-20 21:33:52 ----D---- C:\WINDOWS\system32\drivers
2011-09-20 21:33:46 ----RD---- C:\Program Files
2011-09-20 21:11:32 ----D---- C:\WINDOWS\pchealth
2011-09-20 21:11:28 ----SHD---- C:\WINDOWS\Installer
2011-09-20 21:11:25 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-09-20 21:10:37 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-09-20 20:13:48 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-18 14:59:29 ----D---- C:\WINDOWS\WinSxS
2011-09-18 14:58:15 ----D---- C:\WINDOWS\system32\config
2011-09-18 14:38:33 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2011-09-18 14:24:56 ----A---- C:\WINDOWS\system.ini
2011-09-18 14:23:38 ----D---- C:\WINDOWS\AppPatch
2011-09-18 14:23:34 ----D---- C:\Program Files\Common Files
2011-09-18 14:13:05 ----SD---- C:\WINDOWS\Tasks
2011-09-18 13:49:35 ----D---- C:\WINDOWS\Debug
2011-09-16 06:36:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-16 06:34:16 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-16 06:15:21 ----D---- C:\WINDOWS\system32\drivers\etc
2011-09-16 05:58:15 ----D---- C:\WINDOWS\system32\CatRoot
2011-09-15 14:57:40 ----RASH---- C:\boot.ini
2011-09-15 14:33:21 ----D---- C:\Documents and Settings
2011-09-15 11:58:34 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-09-10 12:01:14 ----SHD---- C:\System Volume Information
2011-09-10 12:01:14 ----D---- C:\WINDOWS\system32\Restore
2011-09-09 11:12:13 ----A---- C:\WINDOWS\system32\crypt32.dll
2011-09-06 19:19:21 ----D---- C:\Documents and Settings\Juraj Stevanka\Application Data\vlc
2011-08-29 09:28:13 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;Texas Instruments OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2004-08-10 19840]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-10-05 691696]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-10-05 278728]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2011-09-21 66616]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-10-05 25416]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-12-02 1412608]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2008-10-23 1391104]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camc6aud.sys [2005-08-02 38016]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camc6hal.sys [2005-08-02 349312]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-08-23 1035008]
R3 HSFHWATI;HSFHWATI; C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-23 231424]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-08-23 718464]
S1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2011-09-21 138192]
S3 a3ij3v2y;a3ij3v2y; C:\WINDOWS\system32\drivers\a3ij3v2y.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\JURAJS~1\LOCALS~1\Temp\catchme.sys []
S3 massfilter;ZTE Mass Storage Filter Driver; C:\WINDOWS\system32\drivers\massfilter.sys []
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 ZTEusbmdm6k;ZTE Proprietary USB Driver; C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys []
S3 ZTEusbnmea;ZTE NMEA Port; C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys []
S3 ZTEusbser6k;ZTE Diagnostic Port; C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-09-21 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-12-02 393216]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2004-08-10 194560]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2004-08-10 102912]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
-----------------EOF-----------------
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: FB vir
Zbytečně se tím vystavuješ riziku a o tom, co se z torrentů stahuje především, nebudeme polemizovat, že?!
- Přejmenuj ComboFix na Uninstall.
- Spusť jej.
- Tohle smaže ComboFix a jeho složky.
- Stáhni a spusť.
- Pro potvrzení volby mačkej A, Enter.
- Po použití utilitu smaž.
- Antiviry mohou tuto utilitu chybně označit jako vir - jedná se o falešný poplach - takže v pohodě stáhni (případně vypni při stahování antivir).
- Stáhni a spusť.
- Klikni na CleanUp a potvrď YES.
- Program uklidí a restartuje PC.
- Stáhni a spusť.
- Klikni na Start a potvrď OK.
- Program uklidí a restartuje PC.
- Po použití utilitu smaž.
- Panel čistič
- Vše nech jak je, jen dej Analyzovat a poté Spustit CCleaner.
- Panel registry
- Klikni na Hledej problémy.
- Následně na Opravit problémy - zálohu registrů doporučuji udělat, oprav všechny problémy.
- Postup opakuj, dokud nebude bez problémů - většinou cca 3x.
- Panel nástroje
- Zde můžeš odinstalovat nepotřebné programy.
A pokud nejsou žádné dotazy, bylo by to z mé strany vše.
Re: FB vir
Dakujem velmi pekne, ze tvoj cas a namahu.
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: FB vir
Rádo se stalo.
Přeji pěkný den. 





Přispějete na provoz fóra?