Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosim o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

prosim o kontrolu

#1 Příspěvek od singels »

Zdravim po dlhsom case som spustil kontrolu a naslo mi toto...SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/25/2012 at 12:00 PM

Application Version : 5.0.1142

Core Rules Database Version : 8164
Trace Rules Database Version: 5976

Scan type : Quick Scan
Total Scan Time : 00:04:49

Operating System Information
Windows 7 Professional 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned : 503
Memory threats detected : 0
Registry items scanned : 30921
Registry threats detected : 0
File items scanned : 10366
File threats detected : 217

Adware.Tracking Cookie
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\7MZR1N1O.txt [ /atdmt.com ]
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\ZZOGZOAP.txt [ /doubleclick.net ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\UK7ZU7TM.txt [ /c.atdmt.com ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\8MXJQ613.txt [ /advertising.com ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\USERS\UNIVERSAL\Cookies\ZZOGZOAP.txt [ Cookie:universal@doubleclick.net/ ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\USERS\UNIVERSAL\Cookies\UK7ZU7TM.txt [ Cookie:universal@c.atdmt.com/ ]
C:\USERS\UNIVERSAL\Cookies\8MXJQ613.txt [ Cookie:universal@advertising.com/ ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.yieldmanager.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.pro-market.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.burstbeacon.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstbeacon.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.lucidmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
server.adformdsp.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adformdsp.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.r1-ads.ace.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
advert.uloz.to [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ads.ventivmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ww25.embed.livesexdownload.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.userporn.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.192com.112.2o7.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.googleads.g.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adxpose.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.afe2.specificclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.www.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.pornrabbit.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.stats.ebay.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.paypal.112.2o7.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.view.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.bs.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tribalfusion.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.aimfar.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www4.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.247realmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
oasn-en1.247realmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
sk.static.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.toplist.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15713
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: prosim o kontrolu

#2 Příspěvek od JaRon »

ahoj,
mozes dat vsetko zmazat ,,, cookies vsak nepredstavuju vyznamnejsiu hrozbu, takze nabuduce sa ozvi ak SaS najde aj cosi ine ako cookies :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

Re: prosim o kontrolu

#3 Příspěvek od singels »

OK DAKUJEM PRE ISTOTU POSIELAM LOG.Logfile of random's system information tool 1.09 (written by random/random)
Run by universal at 2012-01-25 12:22:08
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 22 GB (15%) free of 146 GB
Total RAM: 2814 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:22:13, on 25/01/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
c:\program files (x86)\real\realplayer\update\realsched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\trend micro\universal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cas.sk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1320680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... nkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
R3 - URLSearchHook: (no name) - {f92a9fe4-2850-4198-b9d5-279880e49b16} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\universal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8344 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a9e263c0-5289-4dd8-9267-58da62ea8e22 -SystemEventPortName:HostProcess-03daa10f-e42b-4b47-9e9e-ffdbb738dead -IoCancelEventPortName:HostProcess-5f09130f-1cc3-4979-afd4-8c9d480a9e8a -NonStateChangingEventPortName:HostProcess-7cc37bcc-3b17-4cc6-aaa1-b9cae737baad -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d4d3286e-da7b-4c02-a164-a4b380bd99b8
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSLoader.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
"C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3356.d2477b0.539878765 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 3356 "\\.\pipe\gecko-crash-server-pipe.3356" plugin
"c:\program files (x86)\real\realplayer\update\realsched.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\universal\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT13206 ... hSource=13"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94, {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "chrome://browser-region/locale/region.properties"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0]
"Description"=DivX® Content Upload Plugin
"Path"=C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666]
"Description"=12.0.1.666
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsjsrealplayerplugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npDivxPlayerPlugin.dll
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll
nsIDivxPlayerPlugin.xpt
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
amazondotcom.xml
babylon.xml
bing.xml
eBay.xml
google.xml
SearchResults.xml
twitter.xml
wikipedia.xml
yahoo.xml

C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\extensions\
{3189af69-c0a1-4318-b2b9-610e0ba6a775}
{872b5b88-9db5-4310-bdd0-ac189557e5f5}
{f92a9fe4-2850-4198-b9d5-279880e49b16}

C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\searchplugins\
conduit.xml
SearchResults.xml
uloto.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll [2008-07-29 378416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-09-10 414416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll [2008-07-29 181296]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-07-29 142896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-07-28 16334880]
"eDataSecurity Loader"=C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe [2008-07-29 561200]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"=C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [2010-08-09 248832]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-12-16 5486464]
"Google Update"=C:\Users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 136176]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"TkBellExe"=c:\program files (x86)\real\realplayer\Update\realsched.exe [2011-09-10 273528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-01-25 12:22:08 ----D---- C:\rsit
2012-01-16 20:50:35 ----D---- C:\Windows\Minidump
2012-01-11 18:18:56 ----A---- C:\Windows\system32\quartz.dll
2012-01-11 18:18:55 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-01-11 18:18:55 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-01-11 18:18:54 ----A---- C:\Windows\system32\qdvd.dll
2012-01-11 18:18:53 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-01-11 18:18:53 ----A---- C:\Windows\system32\ntdll.dll
2012-01-11 18:18:52 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-01-11 18:18:52 ----A---- C:\Windows\system32\packager.dll
2012-01-01 19:28:59 ----D---- C:\Users\universal\AppData\Roaming\iWin
2012-01-01 19:24:00 ----A---- C:\Windows\SYSWOW64\Statistics.txt
2012-01-01 19:23:43 ----A---- C:\Windows\GPlrLanc.dat

======List of files/folders modified in the last 1 month======

2012-01-25 12:22:13 ----D---- C:\Windows\Prefetch
2012-01-25 12:22:12 ----D---- C:\Program Files\trend micro
2012-01-25 12:22:00 ----D---- C:\Windows\Temp
2012-01-25 07:23:26 ----D---- C:\Windows\system32\config
2012-01-24 13:27:46 ----D---- C:\Windows\system32\catroot2
2012-01-24 12:48:10 ----D---- C:\Windows\winsxs
2012-01-24 12:48:08 ----SHD---- C:\Windows\Installer
2012-01-24 12:47:52 ----SHD---- C:\System Volume Information
2012-01-23 15:56:50 ----D---- C:\Users\universal\AppData\Roaming\Skype
2012-01-22 10:47:07 ----D---- C:\Windows
2012-01-21 09:53:23 ----D---- C:\Windows\System32
2012-01-21 09:53:23 ----D---- C:\Windows\inf
2012-01-21 09:53:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-14 11:19:55 ----D---- C:\Windows\debug
2012-01-12 22:16:09 ----D---- C:\Windows\system32\wdi
2012-01-11 21:03:40 ----D---- C:\Windows\SysWOW64
2012-01-11 21:03:40 ----D---- C:\Windows\ehome
2012-01-11 20:15:48 ----A---- C:\Windows\system32\MRT.exe
2012-01-11 18:18:46 ----D---- C:\Windows\system32\catroot
2012-01-11 03:43:47 ----D---- C:\Windows\Microsoft.NET
2012-01-11 03:43:24 ----RSD---- C:\Windows\assembly
2012-01-10 23:18:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-09 20:52:05 ----A---- C:\Users\universal\AppData\Roaming\burnaware.ini
2012-01-08 11:00:33 ----D---- C:\Windows\system32\NDF
2012-01-05 12:03:10 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-05 12:03:02 ----D---- C:\Windows\system32\drivers
2012-01-02 12:28:23 ----RD---- C:\Program Files (x86)
2012-01-02 12:20:56 ----D---- C:\Windows\SYSWOW64\drivers
2012-01-01 20:44:43 ----D---- C:\Windows\system32\Tasks
2012-01-01 20:44:32 ----HD---- C:\ProgramData
2012-01-01 20:44:32 ----D---- C:\Windows\Downloaded Program Files
2011-12-26 20:54:06 ----D---- C:\Program Files (x86)\Google
2011-12-26 20:52:35 ----D---- C:\Windows\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-07-29 22064]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-10 503352]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 MpKslc42c43e2;MpKslc42c43e2; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CFB5E570-20E8-43FD-B38F-4AA24CA62AFB}\MpKslc42c43e2.sys [2012-01-25 35664]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 21040]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60976]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 winbondcir;Winbond IR Transceiver; C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 46592]
S1 chxkdnhe;chxkdnhe; \??\C:\Windows\system32\drivers\chxkdnhe.sys []
S1 DritekPortIO;Dritek General Port I/O; \??\C:\Program Files (x86)\Launch Manager\DPortIO.sys []
S1 gccaphui;gccaphui; \??\C:\Windows\system32\drivers\gccaphui.sys []
S3 ajt7r0nc;ajt7r0nc; C:\Windows\system32\drivers\ajt7r0nc.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2010-04-14 54824]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-12-10 23152]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 s716bus;Sony Ericsson Device 716 driver (WDM); C:\Windows\system32\DRIVERS\s716bus.sys [2007-04-04 108296]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-18 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-07-28 382496]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-28 1255736]
S4 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15713
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: prosim o kontrolu

#4 Příspěvek od JaRon »

cosi drobne sa tam nachadza :)
Presun ComboFix
na plochu (ak tam este nie je)

otvor si Poznamkovy blok - notepad

do neho zkopiruj skript z nasledujiceho okna:

Kód: Vybrat vše

Driver::
chxkdnhe
gccaphui


uloz vytvoreny textovy soubor ako CFScript.txt na plochu

po ulozeni uchop vytvoreny skript lavym tlacitkom mysi a presun ho nad ikonu Combofixu, nad nim skript upust:

Obrázek

po aplikacii by mal vzniknut dalsi log, ten vloz sem :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

Re: prosim o kontrolu

#5 Příspěvek od singels »

ComboFix 12-02-21.02 - universal 21/02/2012 19:34:07.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1033.18.2814.1632 [GMT 0:00]
Running from: c:\users\universal\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Files Created from 2012-01-21 to 2012-02-21 )))))))))))))))))))))))))))))))
.
.
2012-02-21 19:42 . 2012-02-21 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\users\universal\AppData\Roaming\Ashampoo
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\program files (x86)\ConduitEngine
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\program files (x86)\MyAshampoo
2012-02-21 19:03 . 2012-02-21 19:03 -------- d-----w- c:\program files (x86)\Ashampoo
2012-02-21 16:22 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5C977D5E-B18E-46F6-9E36-A08AB339B103}\mpengine.dll
2012-02-21 11:44 . 2012-02-21 11:44 -------- d-----w- c:\program files (x86)\True Burner
2012-02-20 13:01 . 2012-02-20 13:02 -------- d-----w- c:\program files (x86)\PC Speed Up
2012-02-20 12:58 . 2012-02-20 12:58 -------- d-----w- c:\program files (x86)\DealPly
2012-02-20 12:44 . 2012-02-20 12:44 -------- d-----w- c:\programdata\NCH Software
2012-02-20 12:44 . 2012-02-20 12:44 -------- d-----w- c:\program files (x86)\NCH Software
2012-02-20 12:44 . 2012-02-20 12:50 -------- d-----w- c:\users\universal\AppData\Roaming\NCH Software
2012-02-15 23:32 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-15 23:32 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-15 23:32 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-15 23:32 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-15 23:32 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-15 23:32 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-15 23:32 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 23:32 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-10 18:04 . 2012-02-10 18:03 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7F5FEF97-6E59-4196-8851-EBC56F583C18}\gapaengine.dll
2012-01-25 12:22 . 2012-01-25 12:22 -------- d-----w- C:\rsit
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-17 16:44 . 2011-05-18 22:56 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-08 07:13 . 2011-02-07 19:18 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-31 12:44 . 2011-01-28 17:06 279656 ------w- c:\windows\system32\MpSigStub.exe
2011-12-14 18:45 . 2011-03-04 11:29 710992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-12-10 15:24 . 2011-02-08 21:15 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-04 06:20 . 2011-02-15 15:16 710992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 15:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2010-11-29 15:26 3908192 ----a-w- c:\program files (x86)\MyAshampoo\tbMyAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 17:52 121392 ----a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-02-05 5487488]
"PCSpeedUp"="c:\program files (x86)\PC Speed Up\PCSpeedUp.lnk" [2012-02-20 2125]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-09-10 273528]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 chxkdnhe;chxkdnhe;c:\windows\system32\drivers\chxkdnhe.sys [x]
R1 gccaphui;gccaphui;c:\windows\system32\drivers\gccaphui.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-18 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 PCSUService;PC Speed Up Service;c:\program files (x86)\PC Speed Up\PCSUService.exe [2011-10-24 235232]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 20:52]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 20:52]
.
2012-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000Core.job
- c:\users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 17:07]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000UA.job
- c:\users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 17:07]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 17:53 50736 ----a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-28 16334880]
"eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-29 561200]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029
uDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
FF - ProfilePath - c:\users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1320680&SearchSource=13
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
URLSearchHooks-{f92a9fe4-2850-4198-b9d5-279880e49b16} - (no file)
Toolbar-10 - (no file)
Toolbar-10 - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-21 19:46:09
ComboFix-quarantined-files.txt 2012-02-21 19:46
ComboFix2.txt 2012-01-25 13:20
.
Pre-Run: 32,325,406,720 bytes free
Post-Run: 32,246,542,336 bytes free
.
- - End Of File - - 5BC128910E8F3A668CCD06DB48D9EC72

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: prosim o kontrolu

#6 Příspěvek od motji »

Jak je na tom počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

Re: prosim o kontrolu

#7 Příspěvek od singels »

zdravim...notebuk ide vsetko aj sa zrychlil ..no nechce sa restartovat len sa vypne...ani cez F8 sa nedostanem do nuzoveho rezimu..trva to asi 15 /20 minut kym sa mi ho podari zapnut

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: prosim o kontrolu

#8 Příspěvek od motji »

:arrow: stáhněte
http://www.slunecnice.cz/sw/crystaldiskinfo/
- spusťte ho a v nabídce zvolte Kopírovat.
-Data ze schránky sem pak vložte pomocí Ctrl+V
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

Re: prosim o kontrolu

#9 Příspěvek od singels »

----------------------------------------------------------------------------
CrystalDiskInfo 4.1.3 (C) 2008-2011 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 SP1 [6.1 Build 7601] (x64)
Date : 2012/02/25 22:30:56

-- Controller Map ----------------------------------------------------------
+ Standard AHCI 1.0 Serial ATA Controller [ATA]
+ ATA Channel 0 (0)
- Hitachi HTS543232L9A300 ATA Device
- ATA Channel 1 (1)
+ ATA Channel 2 (2)
- HL-DT-ST DVDRAM GSA-T50N ATA Device
- ATA Channel 3 (3)
- ATA Channel 4 (4)
- ATA Channel 5 (5)

-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS543232L9A300 : 320.0 GB [0-0-0, pd1]

----------------------------------------------------------------------------
(1) Hitachi HTS543232L9A300
----------------------------------------------------------------------------
Model : Hitachi HTS543232L9A300
Firmware : FB4OC40C
Serial Number : 080918FB2400LEC5WPDA
Disk Size : 320.0 GB (8.4/137.4/320.0)
Buffer Size : 7114 KB
Queue Depth : 32
# of Sectors : 625142448
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 3f
Transfer Mode : SATA/300
Power On Hours : 7940 hod.
Power On Count : 4405 krát
Temparature : 32 C (89 F)
Health Status : Pozor
Features : S.M.A.R.T., APM, AAM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : 80FEh [OFF]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 253 253 _33 000400000000 Čas na roztočení ploten
04 _98 _98 __0 000000001163 Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _82 _82 __0 000000001F04 Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _98 _98 __0 000000001135 Počet cyklů zapnutí zařízení
BF 100 100 __0 000000000000 Počet udalostí zaznamenaných otřesovým senzorem
C0 _96 _96 __0 0000000003C8 Počet vypnutí disku
C1 _91 _91 __0 000000016C93 Počet cyklů načítání/vymazání
C2 171 171 __0 003300070020 Teplota
C4 100 100 __0 000000000002 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000001 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000003 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony

-- IDENTIFY_DEVICE ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 04 5A 3F FF C8 37 00 10 00 00 00 00 00 3F 00 00
010: 00 00 00 00 30 38 30 39 31 38 46 42 32 34 30 30
020: 4C 45 43 35 57 50 44 41 00 03 37 95 00 04 46 42
030: 34 4F 43 34 30 43 48 69 74 61 63 68 69 20 48 54
040: 53 35 34 33 32 33 32 4C 39 41 33 30 30 20 20 20
050: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 80 10
060: 40 00 0F 00 40 00 02 00 02 00 00 07 3F FF 00 10
070: 00 3F FC 10 00 FB 01 10 FF FF 0F FF 00 00 00 07
080: 00 03 00 78 00 78 00 78 00 78 00 00 00 00 00 00
090: 00 00 00 00 00 00 00 1F 17 06 00 00 00 5E 00 40
0A0: 01 FC 00 42 74 6B 7F 69 61 63 74 69 BC 49 61 63
0B0: 40 7F 00 3F 00 40 40 80 00 01 00 00 80 FE 00 00
0C0: 00 00 00 00 00 00 00 00 EA B0 25 42 00 00 00 00
0D0: 00 00 00 00 00 00 88 48 50 00 CC A5 64 C2 AD CD
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 14
0F0: 40 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 29 00 0B 00 09 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 40 01 00 00 80 00 00 00
130: 34 4F 00 00 00 00 74 74 63 63 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 3D 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 15 18 00 00 00 00 00 00 00 00 10 1F 00 21
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 01 00 80 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A7 A5

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: prosim o kontrolu

#10 Příspěvek od motji »

Ten disk pořádně prověříme

:arrow: Stahněte HD tune http://www.slunecnice.cz/sw/hd-tune/
-zvolete poslední záložku Error scan
-dejte skenovat, trvá to kolem hodiny.
-pak napište jestli jste měl nějaká políčka červená
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

Re: prosim o kontrolu

#11 Příspěvek od singels »

zdravim..spustil som ten sken ...cervene policko ziadne...damaged blocks 0.0 percent

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: prosim o kontrolu

#12 Příspěvek od motji »

Ten disk podle mě není uplně v pořádku, může být poškozený nějaký systémový soubor....zazálohujte si svoje data a udělejte kontrolu disku.

:arrow: start-spustit - napište chkdsk /f/r
-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

Re: prosim o kontrolu

#13 Příspěvek od singels »

nepusti mne to tam....napisu dam entr jen problikne a nic se nedeje...ani jako admin mne tam nechce pustit....

singels
Návštěvník
Návštěvník
Příspěvky: 47
Registrován: 30 lis 2010 23:11

Re: prosim o kontrolu

#14 Příspěvek od singels »

este dalsia zavada z nicoho nic mi prestal fungovat burner ,neda sa napalit dvd,skusil som stiahnut i ine programy na vypalovanie no bez vysledku stale mi to hlasi nezdarilo sa vypalovanie...

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: prosim o kontrolu

#15 Příspěvek od motji »

Tento počítač - disk C - klik pravým tlačítkem - vlastnosti - nástroje - kontrola chyb svazku.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět