
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Mára log
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Mára log
Logfile of random's system information tool 1.09 (written by random/random)
Run by Seladon at 2012-10-26 22:30:59
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 183 GB (77%) free of 238 GB
Total RAM: 2047 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:31:17, on 26.10.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\TuneUp Utilities 2008\Integrator.exe
C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe
C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\WINDOWS\System32\TuneUpDefragService.exe
C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe
C:\Program Files\TuneUp Utilities 2008\DiskDoctor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Seladon\Dokumenty\Stažené soubory\RSIT(1).exe
C:\Program Files\trend micro\Seladon.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: WinToFlash Suggestor - {FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD} - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Creative KSRun Persistence Module] RunDll32 KSRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [Module Loader] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe -StartUpRun
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Otevřít obrázek v aplikaci &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1029\phdintl.dll/phdContext.htm
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Stáhnout &Mass Downloaderem - C:\Program Files\Mass Downloader\Add_Url.htm
O8 - Extra context menu item: Stáhnout &vše Mass Downloaderem - C:\Program Files\Mass Downloader\Add_All.htm
O9 - Extra button: Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - C:\Program Files\Mass Downloader\massdown.exe
O9 - Extra 'Tools' menuitem: &Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - C:\Program Files\Mass Downloader\massdown.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WinToFlash Suggestor - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll
O9 - Extra 'Tools' menuitem: WinToFlash Suggestor options - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ashampoo Anti-Malware Service (AAMWService) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe
O23 - Service: Ashampoo Anti-Malware WSC Service (AAMW_WSC_Service_XP) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 10334 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default
prefs.js - "browser.startup.homepage" - "http://www.ahoolly.com/"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.5.3&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\extensions\
cs@dictionaries.addons.mozilla.org
facebook-translate@oliver.schloebe.de
{1018e4d6-728f-4b20-ad56-37578a4de76b}
{800b5000-a755-47e1-992b-48a1c1357f07}
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
C:\Documents and Settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\searchplugins\
icqplugin-1.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD}]
WinToFlash Suggestor - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll [2012-05-25 281424]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-01-05 872448]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-05-11 472632]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-08-27 59280]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2012-04-18 421888]
"Creative KSRun Persistence Module"=RunDll32 KSRun.dll,RunDLLEntry []
"Module Loader"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2007-07-23 57344]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"=C:\Program Files\TGTSoft\StyleXP\StyleXP.exe [2006-05-24 1372160]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-07-21 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Seladon\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Seladon\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux3"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux4"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux5"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux6"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"aux9"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-10-26 09:18:11 ----D---- C:\rsit
2012-10-26 09:18:11 ----D---- C:\Program Files\trend micro
2012-10-12 01:13:04 ----D---- C:\Program Files\WinToFlash Suggestor
2012-10-11 23:09:06 ----A---- C:\WINDOWS\UPGRADE.TXT
2012-10-11 20:33:09 ----N---- C:\WINDOWS\system32\CTSVCCTL.EXE
2012-10-11 20:33:09 ----N---- C:\WINDOWS\system32\CTSVCCDA.EXE
2012-10-11 20:32:55 ----HD---- C:\Program Files\Creative Installation Information
2012-10-11 20:32:55 ----D---- C:\Program Files\Common Files\Creative
2012-10-11 20:27:51 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Creative
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscemdm.sys
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscemdfl.sys
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscecmnt.sys
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscecm.sys
2012-10-08 16:50:41 ----A---- C:\WINDOWS\system32\drivers\sscewhnt.sys
2012-10-08 16:50:41 ----A---- C:\WINDOWS\system32\drivers\sscewh.sys
2012-10-08 16:50:41 ----A---- C:\WINDOWS\system32\drivers\sscebus.sys
2012-10-08 16:08:35 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2012-10-08 16:08:35 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2012-10-08 16:08:35 ----A---- C:\WINDOWS\system32\ChCfg.exe
2012-10-08 16:08:35 ----A---- C:\WINDOWS\soundman.exe
2012-10-08 16:08:34 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2012-10-08 16:07:39 ----D---- C:\Program Files\Realtek AC97
2012-10-08 16:07:32 ----A---- C:\WINDOWS\alcupd.exe
2012-10-08 16:07:32 ----A---- C:\WINDOWS\alcrmv.exe
2012-10-07 15:35:29 ----D---- C:\Program Files\OpenAL
2012-10-06 19:02:17 ----D---- C:\Program Files\iPod
2012-10-06 19:02:01 ----D---- C:\Program Files\iTunes
2012-10-06 19:02:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-06 18:37:16 ----D---- C:\Program Files\QuickTime
======List of files/folders modified in the last 1 month======
2012-10-26 22:31:00 ----D---- C:\WINDOWS\Temp
2012-10-26 22:20:27 ----D---- C:\WINDOWS\system32
2012-10-26 22:20:27 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-10-26 22:15:39 ----RD---- C:\Program Files\Mozilla Maintenance Service
2012-10-26 22:14:57 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-10-26 22:14:35 ----D---- C:\WINDOWS\system32\config
2012-10-26 14:43:48 ----D---- C:\WINDOWS\Prefetch
2012-10-26 09:18:11 ----RD---- C:\Program Files
2012-10-26 07:48:18 ----D---- C:\Program Files\TuneUp Utilities 2008
2012-10-26 07:17:27 ----D---- C:\Program Files\01
2012-10-26 01:57:30 ----RD---- C:\Program Files\Mozilla Firefox
2012-10-25 14:22:39 ----A---- C:\WINDOWS\phd2dll.INI
2012-10-24 14:28:06 ----D---- C:\WINDOWS\system32\CatRoot2
2012-10-24 13:19:21 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Skype
2012-10-16 07:59:09 ----RSD---- C:\WINDOWS\Fonts
2012-10-16 00:42:58 ----D---- C:\WINDOWS\Minidump
2012-10-16 00:42:58 ----D---- C:\WINDOWS
2012-10-11 22:47:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Creative
2012-10-11 22:37:42 ----SHD---- C:\System Volume Information
2012-10-11 22:37:42 ----D---- C:\WINDOWS\system32\Restore
2012-10-11 20:33:49 ----HD---- C:\Program Files\InstallShield Installation Information
2012-10-11 20:33:04 ----D---- C:\Program Files\Creative
2012-10-11 00:44:56 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-10-10 22:53:06 ----RD---- C:\Program Files\MP3Recorder
2012-10-10 22:06:43 ----D---- C:\Program Files\Samsung
2012-10-10 22:06:43 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Samsung
2012-10-10 22:06:41 ----SHD---- C:\WINDOWS\Installer
2012-10-10 22:06:41 ----SHD---- C:\Config.Msi
2012-10-10 22:06:41 ----D---- C:\WINDOWS\system32\drivers
2012-10-10 22:06:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Samsung
2012-10-10 22:04:39 ----RSD---- C:\WINDOWS\assembly
2012-10-10 20:50:22 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-10-10 18:14:29 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Dropbox
2012-10-09 17:46:50 ----D---- C:\WINDOWS\Microsoft.NET
2012-10-08 16:52:34 ----D---- C:\WINDOWS\system32\CatRoot
2012-10-08 16:51:10 ----HD---- C:\WINDOWS\inf
2012-10-08 16:51:01 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-10-08 16:46:33 ----D---- C:\WINDOWS\WinSxS
2012-10-08 01:03:05 ----SD---- C:\Documents and Settings\Seladon\Data aplikací\Microsoft
2012-10-07 15:35:29 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2012-10-07 15:35:28 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2012-10-07 02:26:31 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Apple Computer
2012-10-06 19:02:14 ----D---- C:\Program Files\Common Files\Apple
2012-10-02 10:15:22 ----D---- C:\WINDOWS\Help
2012-09-28 14:31:14 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-11-16 96408]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 StyleXPHelper;StyleXPHelper; \??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-02-05 281600]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-07-21 2363904]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2012-08-06 1123328]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2007-02-14 530861]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2007-02-14 30459]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2007-02-14 868298]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-02-14 149123]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2007-02-14 67960]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-12 250776]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2008-04-28 9344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-18 9600]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\system32\DRIVERS\ew_jubusenum.sys [2011-09-09 73984]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-01-18 220640]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-04-19 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 AAMWRegFilter;AAMWRegFilter; \??\C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys []
S3 ASW3Scan;ASW3Scan; \??\C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys []
S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\WINDOWS\system32\DRIVERS\ew_usbenumfilter.sys [2010-03-20 11136]
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
S3 ksaud;Creative USB Audio Driver; C:\WINDOWS\system32\drivers\ksaud.sys [2009-12-15 857472]
S3 ksaudfl;ksaudfl; C:\WINDOWS\system32\drivers\ksaudfl.sys [2008-10-24 1830912]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\WINDOWS\system32\DRIVERS\sscebus.sys [2012-06-27 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\WINDOWS\system32\DRIVERS\sscemdfl.sys [2012-06-27 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\WINDOWS\system32\DRIVERS\sscemdm.sys [2012-06-27 123648]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AAMW_WSC_Service_XP;Ashampoo Anti-Malware WSC Service; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe [2010-03-01 53248]
R2 AAMWService;Ashampoo Anti-Malware Service; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe [2010-08-30 1309528]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-07-21 483328]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-02-06 266295]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2009-08-28 286720]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
R2 StyleXPService;StyleXPService; C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe [2006-05-24 372736]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2012-09-01 355584]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-11 250808]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-09-11 79360]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-09-09 821648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-26 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S4 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
-----------------EOF-----------------
Run by Seladon at 2012-10-26 22:30:59
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 183 GB (77%) free of 238 GB
Total RAM: 2047 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:31:17, on 26.10.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\TuneUp Utilities 2008\Integrator.exe
C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe
C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\WINDOWS\System32\TuneUpDefragService.exe
C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe
C:\Program Files\TuneUp Utilities 2008\DiskDoctor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Seladon\Dokumenty\Stažené soubory\RSIT(1).exe
C:\Program Files\trend micro\Seladon.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: WinToFlash Suggestor - {FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD} - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Creative KSRun Persistence Module] RunDll32 KSRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [Module Loader] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe -StartUpRun
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Otevřít obrázek v aplikaci &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1029\phdintl.dll/phdContext.htm
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Stáhnout &Mass Downloaderem - C:\Program Files\Mass Downloader\Add_Url.htm
O8 - Extra context menu item: Stáhnout &vše Mass Downloaderem - C:\Program Files\Mass Downloader\Add_All.htm
O9 - Extra button: Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - C:\Program Files\Mass Downloader\massdown.exe
O9 - Extra 'Tools' menuitem: &Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - C:\Program Files\Mass Downloader\massdown.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WinToFlash Suggestor - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll
O9 - Extra 'Tools' menuitem: WinToFlash Suggestor options - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ashampoo Anti-Malware Service (AAMWService) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe
O23 - Service: Ashampoo Anti-Malware WSC Service (AAMW_WSC_Service_XP) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 10334 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default
prefs.js - "browser.startup.homepage" - "http://www.ahoolly.com/"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.5.3&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\extensions\
cs@dictionaries.addons.mozilla.org
facebook-translate@oliver.schloebe.de
{1018e4d6-728f-4b20-ad56-37578a4de76b}
{800b5000-a755-47e1-992b-48a1c1357f07}
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
C:\Documents and Settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\searchplugins\
icqplugin-1.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD}]
WinToFlash Suggestor - C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll [2012-05-25 281424]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-01-05 872448]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-05-11 472632]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-08-27 59280]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2012-04-18 421888]
"Creative KSRun Persistence Module"=RunDll32 KSRun.dll,RunDLLEntry []
"Module Loader"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2007-07-23 57344]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"=C:\Program Files\TGTSoft\StyleXP\StyleXP.exe [2006-05-24 1372160]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-07-21 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Seladon\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Seladon\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux3"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux4"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux5"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux6"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"aux9"=wdmaud.drv
======List of files/folders created in the last 1 month======
2012-10-26 09:18:11 ----D---- C:\rsit
2012-10-26 09:18:11 ----D---- C:\Program Files\trend micro
2012-10-12 01:13:04 ----D---- C:\Program Files\WinToFlash Suggestor
2012-10-11 23:09:06 ----A---- C:\WINDOWS\UPGRADE.TXT
2012-10-11 20:33:09 ----N---- C:\WINDOWS\system32\CTSVCCTL.EXE
2012-10-11 20:33:09 ----N---- C:\WINDOWS\system32\CTSVCCDA.EXE
2012-10-11 20:32:55 ----HD---- C:\Program Files\Creative Installation Information
2012-10-11 20:32:55 ----D---- C:\Program Files\Common Files\Creative
2012-10-11 20:27:51 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Creative
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscemdm.sys
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscemdfl.sys
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscecmnt.sys
2012-10-08 16:50:42 ----A---- C:\WINDOWS\system32\drivers\sscecm.sys
2012-10-08 16:50:41 ----A---- C:\WINDOWS\system32\drivers\sscewhnt.sys
2012-10-08 16:50:41 ----A---- C:\WINDOWS\system32\drivers\sscewh.sys
2012-10-08 16:50:41 ----A---- C:\WINDOWS\system32\drivers\sscebus.sys
2012-10-08 16:08:35 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2012-10-08 16:08:35 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2012-10-08 16:08:35 ----A---- C:\WINDOWS\system32\ChCfg.exe
2012-10-08 16:08:35 ----A---- C:\WINDOWS\soundman.exe
2012-10-08 16:08:34 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2012-10-08 16:07:39 ----D---- C:\Program Files\Realtek AC97
2012-10-08 16:07:32 ----A---- C:\WINDOWS\alcupd.exe
2012-10-08 16:07:32 ----A---- C:\WINDOWS\alcrmv.exe
2012-10-07 15:35:29 ----D---- C:\Program Files\OpenAL
2012-10-06 19:02:17 ----D---- C:\Program Files\iPod
2012-10-06 19:02:01 ----D---- C:\Program Files\iTunes
2012-10-06 19:02:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-06 18:37:16 ----D---- C:\Program Files\QuickTime
======List of files/folders modified in the last 1 month======
2012-10-26 22:31:00 ----D---- C:\WINDOWS\Temp
2012-10-26 22:20:27 ----D---- C:\WINDOWS\system32
2012-10-26 22:20:27 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-10-26 22:15:39 ----RD---- C:\Program Files\Mozilla Maintenance Service
2012-10-26 22:14:57 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-10-26 22:14:35 ----D---- C:\WINDOWS\system32\config
2012-10-26 14:43:48 ----D---- C:\WINDOWS\Prefetch
2012-10-26 09:18:11 ----RD---- C:\Program Files
2012-10-26 07:48:18 ----D---- C:\Program Files\TuneUp Utilities 2008
2012-10-26 07:17:27 ----D---- C:\Program Files\01
2012-10-26 01:57:30 ----RD---- C:\Program Files\Mozilla Firefox
2012-10-25 14:22:39 ----A---- C:\WINDOWS\phd2dll.INI
2012-10-24 14:28:06 ----D---- C:\WINDOWS\system32\CatRoot2
2012-10-24 13:19:21 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Skype
2012-10-16 07:59:09 ----RSD---- C:\WINDOWS\Fonts
2012-10-16 00:42:58 ----D---- C:\WINDOWS\Minidump
2012-10-16 00:42:58 ----D---- C:\WINDOWS
2012-10-11 22:47:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Creative
2012-10-11 22:37:42 ----SHD---- C:\System Volume Information
2012-10-11 22:37:42 ----D---- C:\WINDOWS\system32\Restore
2012-10-11 20:33:49 ----HD---- C:\Program Files\InstallShield Installation Information
2012-10-11 20:33:04 ----D---- C:\Program Files\Creative
2012-10-11 00:44:56 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-10-10 22:53:06 ----RD---- C:\Program Files\MP3Recorder
2012-10-10 22:06:43 ----D---- C:\Program Files\Samsung
2012-10-10 22:06:43 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Samsung
2012-10-10 22:06:41 ----SHD---- C:\WINDOWS\Installer
2012-10-10 22:06:41 ----SHD---- C:\Config.Msi
2012-10-10 22:06:41 ----D---- C:\WINDOWS\system32\drivers
2012-10-10 22:06:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Samsung
2012-10-10 22:04:39 ----RSD---- C:\WINDOWS\assembly
2012-10-10 20:50:22 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-10-10 18:14:29 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Dropbox
2012-10-09 17:46:50 ----D---- C:\WINDOWS\Microsoft.NET
2012-10-08 16:52:34 ----D---- C:\WINDOWS\system32\CatRoot
2012-10-08 16:51:10 ----HD---- C:\WINDOWS\inf
2012-10-08 16:51:01 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-10-08 16:46:33 ----D---- C:\WINDOWS\WinSxS
2012-10-08 01:03:05 ----SD---- C:\Documents and Settings\Seladon\Data aplikací\Microsoft
2012-10-07 15:35:29 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2012-10-07 15:35:28 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2012-10-07 02:26:31 ----D---- C:\Documents and Settings\Seladon\Data aplikací\Apple Computer
2012-10-06 19:02:14 ----D---- C:\Program Files\Common Files\Apple
2012-10-02 10:15:22 ----D---- C:\WINDOWS\Help
2012-09-28 14:31:14 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-11-16 96408]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 StyleXPHelper;StyleXPHelper; \??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-02-05 281600]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-07-21 2363904]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2012-08-06 1123328]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2007-02-14 530861]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2007-02-14 30459]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2007-02-14 868298]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-02-14 149123]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2007-02-14 67960]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-12 250776]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2008-04-28 9344]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-18 9600]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\system32\DRIVERS\ew_jubusenum.sys [2011-09-09 73984]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-01-18 220640]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-04-19 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 AAMWRegFilter;AAMWRegFilter; \??\C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys []
S3 ASW3Scan;ASW3Scan; \??\C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys []
S3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\WINDOWS\system32\DRIVERS\ew_usbenumfilter.sys [2010-03-20 11136]
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
S3 ksaud;Creative USB Audio Driver; C:\WINDOWS\system32\drivers\ksaud.sys [2009-12-15 857472]
S3 ksaudfl;ksaudfl; C:\WINDOWS\system32\drivers\ksaudfl.sys [2008-10-24 1830912]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\WINDOWS\system32\DRIVERS\sscebus.sys [2012-06-27 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\WINDOWS\system32\DRIVERS\sscemdfl.sys [2012-06-27 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\WINDOWS\system32\DRIVERS\sscemdm.sys [2012-06-27 123648]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AAMW_WSC_Service_XP;Ashampoo Anti-Malware WSC Service; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe [2010-03-01 53248]
R2 AAMWService;Ashampoo Anti-Malware Service; C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe [2010-08-30 1309528]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-07-21 483328]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-02-06 266295]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2009-08-28 286720]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
R2 StyleXPService;StyleXPService; C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe [2006-05-24 372736]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-18 14336]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2012-09-01 355584]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-11 250808]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-09-11 79360]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-09-09 821648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-26 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S4 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119520
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mára log
Log je v zásadě OK. Jaký máte problém?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Re: Mára log
Ahoj,Rudy píše:Log je v zásadě OK. Jaký máte problém?
děkuji za zprávu.
Problém je v tom, že mám neskutečně zpomalený net i pc.
Používám Firefox, v procesech se chová celkem normálně.
Jiné procesy jsou vypnuté.
Nevím čím to může být, ale přijde mi to dost divné.
Nod nic nezaznamenal, přes ashampoo anti-malware a Tune up- utilities, jsem se snažil vše vyčistit a optimalizovat.
Žádné potíže mi nic nehlásí.
Na zbytek jsem asi už laik...
- Rudy
- Site Admin
- Příspěvky: 119520
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mára log
OK. Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se
jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine
aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,
pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k
nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Re: Mára log
ComboFix 12-10-26.05 - Seladon 28.10.2012 7:17.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1239 [GMT 1:00]
Spuštěný z: c:\documents and settings\Seladon\Plocha\ComboFix.exe
AV: Ashampoo Anti-MalWare *Enabled/Updated* {91BDFB4E-BA7E-4ABC-9472-A79BA394CA4B}
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ashampoo_anti-malware_1.21_7713(1).exe
c:\program files\WinToFlash Suggestor\WiNToflashsuggestor.dll
c:\windows\system32\kernel1.exe
c:\windows\system32\muzapp.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-28 do 2012-10-28 )))))))))))))))))))))))))))))))
.
.
2012-10-26 22:15 . 2012-10-26 22:15 -------- d-----w- c:\program files\MarkAny
2012-10-26 22:15 . 2012-09-26 18:57 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2012-10-26 22:15 . 2012-09-26 18:57 821824 ----a-w- c:\windows\system32\dgderapi.dll
2012-10-26 22:15 . 2012-09-26 18:57 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
2012-10-26 07:18 . 2012-10-27 12:47 -------- d-----w- c:\program files\trend micro
2012-10-26 07:18 . 2012-10-26 07:18 -------- d-----w- C:\rsit
2012-10-11 23:13 . 2012-10-28 06:20 -------- d-----w- c:\program files\WinToFlash Suggestor
2012-10-11 18:33 . 1999-12-12 23:01 44032 ------w- c:\windows\system32\CTSVCCDA.EXE
2012-10-11 18:33 . 1999-11-17 23:00 25088 ------w- c:\windows\system32\CTSVCCTL.EXE
2012-10-11 18:32 . 2012-10-11 18:32 -------- d--h--w- c:\program files\Creative Installation Information
2012-10-11 18:32 . 2012-10-11 18:32 -------- d-----w- c:\program files\Common Files\Creative
2012-10-11 18:27 . 2012-10-11 18:27 -------- d-----w- c:\documents and settings\Seladon\Data aplikací\Creative
2012-10-08 14:53 . 2004-08-18 12:00 25600 ----a-w- c:\documents and settings\LocalService\Data aplikací\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2012-10-08 14:50 . 2012-06-27 08:37 14848 ----a-w- c:\windows\system32\drivers\sscemdfl.sys
2012-10-08 14:50 . 2012-06-27 08:37 12416 ----a-w- c:\windows\system32\drivers\sscecmnt.sys
2012-10-08 14:50 . 2012-06-27 08:37 12416 ----a-w- c:\windows\system32\drivers\sscecm.sys
2012-10-08 14:50 . 2012-06-27 08:37 123648 ----a-w- c:\windows\system32\drivers\sscemdm.sys
2012-10-08 14:50 . 2012-06-27 08:37 100352 ----a-w- c:\windows\system32\drivers\ssceserd.sys
2012-10-08 14:50 . 2012-06-27 08:37 98560 ----a-w- c:\windows\system32\drivers\sscebus.sys
2012-10-08 14:50 . 2012-06-27 08:37 12288 ----a-w- c:\windows\system32\drivers\sscewhnt.sys
2012-10-08 14:50 . 2012-06-27 08:37 12288 ----a-w- c:\windows\system32\drivers\sscewh.sys
2012-10-08 14:08 . 2008-09-24 08:40 4122368 ----a-r- c:\windows\system32\drivers\alcxwdm.sys
2012-10-08 14:08 . 2007-04-16 13:28 577536 ----a-w- c:\windows\soundman.exe
2012-10-08 14:08 . 2006-10-18 00:53 147456 ----a-w- c:\windows\system32\RtlCPAPI.dll
2012-10-08 14:08 . 2006-08-01 13:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
2012-10-08 14:08 . 2006-12-08 13:20 10528768 ----a-w- c:\windows\system32\RTLCPL.exe
2012-10-08 14:08 . 2006-11-17 03:40 18804736 ----a-w- c:\windows\system32\alsndmgr.cpl
2012-10-08 14:07 . 2012-10-08 14:07 -------- d-----w- c:\program files\Realtek AC97
2012-10-08 14:07 . 2006-07-31 09:27 217088 ----a-w- c:\windows\alcrmv.exe
2012-10-08 14:07 . 2006-07-31 09:19 315392 ----a-w- c:\windows\alcupd.exe
2012-10-08 14:04 . 2006-02-07 13:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-10-08 14:04 . 2006-02-07 13:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-10-08 14:04 . 2006-02-07 13:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-10-08 14:04 . 2006-02-07 13:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-10-08 14:04 . 2005-11-13 21:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-10-08 14:04 . 2012-10-08 14:04 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-10-08 14:04 . 2012-10-08 14:04 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-10-07 13:35 . 2012-10-07 13:35 -------- d-----w- c:\program files\OpenAL
2012-10-06 17:02 . 2012-10-06 17:02 -------- d-----w- c:\program files\iPod
2012-10-06 17:02 . 2012-10-06 17:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-06 17:02 . 2012-10-06 17:03 -------- d-----w- c:\program files\iTunes
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-10-06 16:37 . 2012-10-06 16:37 -------- d-----w- c:\program files\QuickTime
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 22:44 . 2012-08-06 17:38 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-10 22:44 . 2012-08-06 17:38 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-07 13:35 . 2012-09-11 18:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-07 13:35 . 2012-09-11 18:30 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-09-26 18:57 . 2011-01-20 02:04 4659712 ----a-w- c:\windows\system32\Redemption.dll
2012-09-26 18:57 . 2012-09-26 18:57 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2012-09-26 18:57 . 2012-09-26 18:57 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-09-26 18:57 . 2012-09-26 18:57 30568 ----a-w- c:\windows\MusiccityDownload.exe
2012-09-26 18:57 . 2012-09-26 18:57 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2012-09-26 18:57 . 2012-09-26 18:57 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 569344 ----a-w- c:\windows\system32\muzdecode.ax
2012-09-26 18:57 . 2012-09-26 18:57 491520 ----a-w- c:\windows\system32\muzapp.dll
2012-09-26 18:57 . 2012-09-26 18:57 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2012-09-26 18:57 . 2012-09-26 18:57 45320 ----a-w- c:\windows\system32\MAMACExtract.dll
2012-09-26 18:57 . 2012-09-26 18:57 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2012-09-26 18:57 . 2012-09-26 18:57 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2012-09-26 18:57 . 2012-09-26 18:57 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2012-09-26 18:57 . 2012-09-26 18:57 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2012-09-26 18:57 . 2012-09-26 18:57 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2012-09-26 18:57 . 2012-09-26 18:57 245760 ----a-w- c:\windows\system32\MSCLib.dll
2012-09-26 18:57 . 2012-09-26 18:57 24576 ----a-w- c:\windows\system32\MASetupCleaner.exe
2012-09-26 18:57 . 2012-09-26 18:57 200704 ----a-w- c:\windows\system32\muzwmts.dll
2012-09-26 18:57 . 2012-09-26 18:57 155648 ----a-w- c:\windows\system32\MSFLib.dll
2012-09-26 18:57 . 2012-09-26 18:57 143360 ----a-w- c:\windows\system32\3DAudio.ax
2012-09-26 18:57 . 2012-09-26 18:57 135168 ----a-w- c:\windows\system32\muzaf1.dll
2012-09-26 18:57 . 2012-09-26 18:57 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2012-09-26 18:57 . 2012-09-26 18:57 122880 ----a-w- c:\windows\system32\muzeffect.ax
2012-09-26 18:57 . 2012-09-26 18:57 118784 ----a-w- c:\windows\system32\MaDRM.dll
2012-09-26 18:57 . 2012-09-26 18:57 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2012-09-01 18:47 . 2012-09-01 18:47 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2012-08-21 11:01 . 2012-08-18 00:06 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2012-08-18 00:06 106928 ----a-w- c:\windows\system32\GEARAspi.dll
2012-08-06 15:47 . 2012-08-06 15:47 87328 ----a-w- c:\windows\system32\bcmwlcoi.dll
2012-08-06 15:47 . 2012-08-06 15:47 1123328 ----a-w- c:\windows\system32\drivers\BCMWL5.SYS
2012-10-27 14:28 . 2012-10-27 14:28 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 1372160]
"KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2012-10-11 966072]
"KiesAirMessage"="c:\program files\Samsung\Kies\KiesAirMessage.exe" [2012-10-09 580096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-05-11 472632]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-06-03 177456]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"Creative KSRun Persistence Module"="KSRun.dll" [2009-12-07 24064]
"Module Loader"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-10-11 309688]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /minimized /regrun
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Ashampoo Anti-Malware Guard"="c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe"
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Seladon\\Data aplikací\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 8:03 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 8:06 96408]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 8:04 735960]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [6.8.2012 16:56 193840]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [22.9.2012 6:38 73984]
S2 AAMW_WSC_Service_XP;Ashampoo Anti-Malware WSC Service;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe [2.9.2012 12:31 53248]
S2 AAMWService;Ashampoo Anti-Malware Service;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe [2.9.2012 12:32 1309528]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 12:28 160944]
S3 AAMWRegFilter;AAMWRegFilter;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys [2.9.2012 12:32 18584]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6.8.2012 18:38 250808]
S3 ASW3Scan;ASW3Scan;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys [2.9.2012 12:32 17816]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [11.9.2012 19:29 79360]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [26.10.2012 23:15 20032]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [22.9.2012 6:38 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [22.9.2012 6:38 11136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [12.8.2012 9:13 36640]
S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [15.12.2009 9:25 857472]
S3 ksaudfl;ksaudfl;c:\windows\system32\drivers\ksaudfl.sys [24.10.2008 17:27 1830912]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [6.8.2012 17:50 115168]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [8.10.2012 15:50 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [8.10.2012 15:50 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [8.10.2012 15:50 123648]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\drivers\ssceserd.sys [8.10.2012 15:50 100352]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2012-10-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 07:09]
.
2012-10-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-06 22:44]
.
2012-10-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Otevřít obrázek v aplikaci &Microsoft PhotoDraw - c:\progra~1\MICROS~2\Office\1029\phdintl.dll/phdContext.htm
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Stáhnout &Mass Downloaderem - c:\program files\Mass Downloader\Add_Url.htm
IE: Stáhnout &vše Mass Downloaderem - c:\program files\Mass Downloader\Add_All.htm
TCP: DhcpNameServer = 81.90.240.2 81.90.240.1 8.8.8.8
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\documents and settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ahoolly.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=
FF - ExtSQL: 2012-09-06 14:08; cs@dictionaries.addons.mozilla.org; c:\documents and settings\Seladon\Data aplikacĂÂ\Mozilla\Firefox\Profiles\k9n61z3o.default\extensions\cs@dictionaries.addons.mozilla.org
FF - user.js: network.http.max-persistent-connections-per-server - 2
FF - user.js: nglayout.initialpaint.delay - 100
FF - user.js: content.notify.interval - 750000
FF - user.js: content.max.tokenizing.time - 1500000
FF - user.js: content.switch.threshold - 750000
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
FF - user.js: network.http.max-connections-per-server - 4
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-28 07:21
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2012-10-28 07:22:17
ComboFix-quarantined-files.txt 2012-10-28 06:22
.
Před spuštěním: Volných bajtů: 195 097 280 512
Po spuštění: Volných bajtů: 195 573 825 536
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (bootscreen)" /noexecute=optin /fastdetect /KERNEL=kernel1.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - B3674AC35DA90A969E49EBC45ED9DF5C
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1239 [GMT 1:00]
Spuštěný z: c:\documents and settings\Seladon\Plocha\ComboFix.exe
AV: Ashampoo Anti-MalWare *Enabled/Updated* {91BDFB4E-BA7E-4ABC-9472-A79BA394CA4B}
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ashampoo_anti-malware_1.21_7713(1).exe
c:\program files\WinToFlash Suggestor\WiNToflashsuggestor.dll
c:\windows\system32\kernel1.exe
c:\windows\system32\muzapp.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-28 do 2012-10-28 )))))))))))))))))))))))))))))))
.
.
2012-10-26 22:15 . 2012-10-26 22:15 -------- d-----w- c:\program files\MarkAny
2012-10-26 22:15 . 2012-09-26 18:57 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2012-10-26 22:15 . 2012-09-26 18:57 821824 ----a-w- c:\windows\system32\dgderapi.dll
2012-10-26 22:15 . 2012-09-26 18:57 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
2012-10-26 07:18 . 2012-10-27 12:47 -------- d-----w- c:\program files\trend micro
2012-10-26 07:18 . 2012-10-26 07:18 -------- d-----w- C:\rsit
2012-10-11 23:13 . 2012-10-28 06:20 -------- d-----w- c:\program files\WinToFlash Suggestor
2012-10-11 18:33 . 1999-12-12 23:01 44032 ------w- c:\windows\system32\CTSVCCDA.EXE
2012-10-11 18:33 . 1999-11-17 23:00 25088 ------w- c:\windows\system32\CTSVCCTL.EXE
2012-10-11 18:32 . 2012-10-11 18:32 -------- d--h--w- c:\program files\Creative Installation Information
2012-10-11 18:32 . 2012-10-11 18:32 -------- d-----w- c:\program files\Common Files\Creative
2012-10-11 18:27 . 2012-10-11 18:27 -------- d-----w- c:\documents and settings\Seladon\Data aplikací\Creative
2012-10-08 14:53 . 2004-08-18 12:00 25600 ----a-w- c:\documents and settings\LocalService\Data aplikací\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2012-10-08 14:50 . 2012-06-27 08:37 14848 ----a-w- c:\windows\system32\drivers\sscemdfl.sys
2012-10-08 14:50 . 2012-06-27 08:37 12416 ----a-w- c:\windows\system32\drivers\sscecmnt.sys
2012-10-08 14:50 . 2012-06-27 08:37 12416 ----a-w- c:\windows\system32\drivers\sscecm.sys
2012-10-08 14:50 . 2012-06-27 08:37 123648 ----a-w- c:\windows\system32\drivers\sscemdm.sys
2012-10-08 14:50 . 2012-06-27 08:37 100352 ----a-w- c:\windows\system32\drivers\ssceserd.sys
2012-10-08 14:50 . 2012-06-27 08:37 98560 ----a-w- c:\windows\system32\drivers\sscebus.sys
2012-10-08 14:50 . 2012-06-27 08:37 12288 ----a-w- c:\windows\system32\drivers\sscewhnt.sys
2012-10-08 14:50 . 2012-06-27 08:37 12288 ----a-w- c:\windows\system32\drivers\sscewh.sys
2012-10-08 14:08 . 2008-09-24 08:40 4122368 ----a-r- c:\windows\system32\drivers\alcxwdm.sys
2012-10-08 14:08 . 2007-04-16 13:28 577536 ----a-w- c:\windows\soundman.exe
2012-10-08 14:08 . 2006-10-18 00:53 147456 ----a-w- c:\windows\system32\RtlCPAPI.dll
2012-10-08 14:08 . 2006-08-01 13:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
2012-10-08 14:08 . 2006-12-08 13:20 10528768 ----a-w- c:\windows\system32\RTLCPL.exe
2012-10-08 14:08 . 2006-11-17 03:40 18804736 ----a-w- c:\windows\system32\alsndmgr.cpl
2012-10-08 14:07 . 2012-10-08 14:07 -------- d-----w- c:\program files\Realtek AC97
2012-10-08 14:07 . 2006-07-31 09:27 217088 ----a-w- c:\windows\alcrmv.exe
2012-10-08 14:07 . 2006-07-31 09:19 315392 ----a-w- c:\windows\alcupd.exe
2012-10-08 14:04 . 2006-02-07 13:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-10-08 14:04 . 2006-02-07 13:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-10-08 14:04 . 2006-02-07 13:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-10-08 14:04 . 2006-02-07 13:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-10-08 14:04 . 2005-11-13 21:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-10-08 14:04 . 2012-10-08 14:04 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-10-08 14:04 . 2012-10-08 14:04 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-10-07 13:35 . 2012-10-07 13:35 -------- d-----w- c:\program files\OpenAL
2012-10-06 17:02 . 2012-10-06 17:02 -------- d-----w- c:\program files\iPod
2012-10-06 17:02 . 2012-10-06 17:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-06 17:02 . 2012-10-06 17:03 -------- d-----w- c:\program files\iTunes
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-10-06 16:37 . 2012-10-06 16:37 -------- d-----w- c:\program files\QuickTime
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 22:44 . 2012-08-06 17:38 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-10 22:44 . 2012-08-06 17:38 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-07 13:35 . 2012-09-11 18:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-07 13:35 . 2012-09-11 18:30 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-09-26 18:57 . 2011-01-20 02:04 4659712 ----a-w- c:\windows\system32\Redemption.dll
2012-09-26 18:57 . 2012-09-26 18:57 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2012-09-26 18:57 . 2012-09-26 18:57 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-09-26 18:57 . 2012-09-26 18:57 30568 ----a-w- c:\windows\MusiccityDownload.exe
2012-09-26 18:57 . 2012-09-26 18:57 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2012-09-26 18:57 . 2012-09-26 18:57 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 569344 ----a-w- c:\windows\system32\muzdecode.ax
2012-09-26 18:57 . 2012-09-26 18:57 491520 ----a-w- c:\windows\system32\muzapp.dll
2012-09-26 18:57 . 2012-09-26 18:57 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2012-09-26 18:57 . 2012-09-26 18:57 45320 ----a-w- c:\windows\system32\MAMACExtract.dll
2012-09-26 18:57 . 2012-09-26 18:57 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2012-09-26 18:57 . 2012-09-26 18:57 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2012-09-26 18:57 . 2012-09-26 18:57 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2012-09-26 18:57 . 2012-09-26 18:57 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2012-09-26 18:57 . 2012-09-26 18:57 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2012-09-26 18:57 . 2012-09-26 18:57 245760 ----a-w- c:\windows\system32\MSCLib.dll
2012-09-26 18:57 . 2012-09-26 18:57 24576 ----a-w- c:\windows\system32\MASetupCleaner.exe
2012-09-26 18:57 . 2012-09-26 18:57 200704 ----a-w- c:\windows\system32\muzwmts.dll
2012-09-26 18:57 . 2012-09-26 18:57 155648 ----a-w- c:\windows\system32\MSFLib.dll
2012-09-26 18:57 . 2012-09-26 18:57 143360 ----a-w- c:\windows\system32\3DAudio.ax
2012-09-26 18:57 . 2012-09-26 18:57 135168 ----a-w- c:\windows\system32\muzaf1.dll
2012-09-26 18:57 . 2012-09-26 18:57 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2012-09-26 18:57 . 2012-09-26 18:57 122880 ----a-w- c:\windows\system32\muzeffect.ax
2012-09-26 18:57 . 2012-09-26 18:57 118784 ----a-w- c:\windows\system32\MaDRM.dll
2012-09-26 18:57 . 2012-09-26 18:57 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2012-09-01 18:47 . 2012-09-01 18:47 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2012-08-21 11:01 . 2012-08-18 00:06 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2012-08-18 00:06 106928 ----a-w- c:\windows\system32\GEARAspi.dll
2012-08-06 15:47 . 2012-08-06 15:47 87328 ----a-w- c:\windows\system32\bcmwlcoi.dll
2012-08-06 15:47 . 2012-08-06 15:47 1123328 ----a-w- c:\windows\system32\drivers\BCMWL5.SYS
2012-10-27 14:28 . 2012-10-27 14:28 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 1372160]
"KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2012-10-11 966072]
"KiesAirMessage"="c:\program files\Samsung\Kies\KiesAirMessage.exe" [2012-10-09 580096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-05-11 472632]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-06-03 177456]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"Creative KSRun Persistence Module"="KSRun.dll" [2009-12-07 24064]
"Module Loader"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-10-11 309688]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /minimized /regrun
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Ashampoo Anti-Malware Guard"="c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe"
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Seladon\\Data aplikací\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 8:03 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 8:06 96408]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 8:04 735960]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [6.8.2012 16:56 193840]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [22.9.2012 6:38 73984]
S2 AAMW_WSC_Service_XP;Ashampoo Anti-Malware WSC Service;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe [2.9.2012 12:31 53248]
S2 AAMWService;Ashampoo Anti-Malware Service;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe [2.9.2012 12:32 1309528]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 12:28 160944]
S3 AAMWRegFilter;AAMWRegFilter;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys [2.9.2012 12:32 18584]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6.8.2012 18:38 250808]
S3 ASW3Scan;ASW3Scan;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys [2.9.2012 12:32 17816]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [11.9.2012 19:29 79360]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [26.10.2012 23:15 20032]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [22.9.2012 6:38 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [22.9.2012 6:38 11136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [12.8.2012 9:13 36640]
S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [15.12.2009 9:25 857472]
S3 ksaudfl;ksaudfl;c:\windows\system32\drivers\ksaudfl.sys [24.10.2008 17:27 1830912]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [6.8.2012 17:50 115168]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [8.10.2012 15:50 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [8.10.2012 15:50 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [8.10.2012 15:50 123648]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\drivers\ssceserd.sys [8.10.2012 15:50 100352]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2012-10-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 07:09]
.
2012-10-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-06 22:44]
.
2012-10-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Otevřít obrázek v aplikaci &Microsoft PhotoDraw - c:\progra~1\MICROS~2\Office\1029\phdintl.dll/phdContext.htm
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Stáhnout &Mass Downloaderem - c:\program files\Mass Downloader\Add_Url.htm
IE: Stáhnout &vše Mass Downloaderem - c:\program files\Mass Downloader\Add_All.htm
TCP: DhcpNameServer = 81.90.240.2 81.90.240.1 8.8.8.8
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\documents and settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ahoolly.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=
FF - ExtSQL: 2012-09-06 14:08; cs@dictionaries.addons.mozilla.org; c:\documents and settings\Seladon\Data aplikacĂÂ\Mozilla\Firefox\Profiles\k9n61z3o.default\extensions\cs@dictionaries.addons.mozilla.org
FF - user.js: network.http.max-persistent-connections-per-server - 2
FF - user.js: nglayout.initialpaint.delay - 100
FF - user.js: content.notify.interval - 750000
FF - user.js: content.max.tokenizing.time - 1500000
FF - user.js: content.switch.threshold - 750000
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
FF - user.js: network.http.max-connections-per-server - 4
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-28 07:21
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2012-10-28 07:22:17
ComboFix-quarantined-files.txt 2012-10-28 06:22
.
Před spuštěním: Volných bajtů: 195 097 280 512
Po spuštění: Volných bajtů: 195 573 825 536
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (bootscreen)" /noexecute=optin /fastdetect /KERNEL=kernel1.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - B3674AC35DA90A969E49EBC45ED9DF5C
- Rudy
- Site Admin
- Příspěvky: 119520
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mára log
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:

Uložte na plochu jako CFScript.txt. pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.Firefox::
FF - ProfilePath - c:\documents and settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ahoolly.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... r=1.5.3&q=
FF - user.js: network.http.max-persistent-connections-per-server - 2
FF - user.js: nglayout.initialpaint.delay - 100
FF - user.js: content.notify.interval - 750000
FF - user.js: content.max.tokenizing.time - 1500000
FF - user.js: content.switch.threshold - 750000
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
FF - user.js: network.http.max-connections-per-server - 4
Reboot::

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Re: Mára log
Rudy píše:Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako CFScript.txt. pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.Firefox::
FF - ProfilePath - c:\documents and settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ahoolly.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... r=1.5.3&q=
FF - user.js: network.http.max-persistent-connections-per-server - 2
FF - user.js: nglayout.initialpaint.delay - 100
FF - user.js: content.notify.interval - 750000
FF - user.js: content.max.tokenizing.time - 1500000
FF - user.js: content.switch.threshold - 750000
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
FF - user.js: network.http.max-connections-per-server - 4
Reboot::
ComboFix 12-10-26.05 - Seladon 28.10.2012 12:02:18.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1151 [GMT 1:00]
Spuštěný z: c:\documents and settings\Seladon\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Seladon\Plocha\CFScript.txt..txt
AV: Ashampoo Anti-MalWare *Enabled/Outdated* {91BDFB4E-BA7E-4ABC-9472-A79BA394CA4B}
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-28 do 2012-10-28 )))))))))))))))))))))))))))))))
.
.
2012-10-26 22:15 . 2012-10-26 22:15 -------- d-----w- c:\program files\MarkAny
2012-10-26 22:15 . 2012-09-26 18:57 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2012-10-26 22:15 . 2012-09-26 18:57 821824 ----a-w- c:\windows\system32\dgderapi.dll
2012-10-26 22:15 . 2012-09-26 18:57 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
2012-10-26 07:18 . 2012-10-27 12:47 -------- d-----w- c:\program files\trend micro
2012-10-26 07:18 . 2012-10-26 07:18 -------- d-----w- C:\rsit
2012-10-11 23:13 . 2012-10-28 06:20 -------- d-----w- c:\program files\WinToFlash Suggestor
2012-10-11 18:33 . 1999-12-12 23:01 44032 ------w- c:\windows\system32\CTSVCCDA.EXE
2012-10-11 18:33 . 1999-11-17 23:00 25088 ------w- c:\windows\system32\CTSVCCTL.EXE
2012-10-11 18:32 . 2012-10-11 18:32 -------- d--h--w- c:\program files\Creative Installation Information
2012-10-11 18:32 . 2012-10-11 18:32 -------- d-----w- c:\program files\Common Files\Creative
2012-10-11 18:27 . 2012-10-11 18:27 -------- d-----w- c:\documents and settings\Seladon\Data aplikací\Creative
2012-10-08 14:53 . 2004-08-18 12:00 25600 ----a-w- c:\documents and settings\LocalService\Data aplikací\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2012-10-08 14:50 . 2012-06-27 08:37 14848 ----a-w- c:\windows\system32\drivers\sscemdfl.sys
2012-10-08 14:50 . 2012-06-27 08:37 12416 ----a-w- c:\windows\system32\drivers\sscecmnt.sys
2012-10-08 14:50 . 2012-06-27 08:37 12416 ----a-w- c:\windows\system32\drivers\sscecm.sys
2012-10-08 14:50 . 2012-06-27 08:37 123648 ----a-w- c:\windows\system32\drivers\sscemdm.sys
2012-10-08 14:50 . 2012-06-27 08:37 100352 ----a-w- c:\windows\system32\drivers\ssceserd.sys
2012-10-08 14:50 . 2012-06-27 08:37 98560 ----a-w- c:\windows\system32\drivers\sscebus.sys
2012-10-08 14:50 . 2012-06-27 08:37 12288 ----a-w- c:\windows\system32\drivers\sscewhnt.sys
2012-10-08 14:50 . 2012-06-27 08:37 12288 ----a-w- c:\windows\system32\drivers\sscewh.sys
2012-10-08 14:08 . 2008-09-24 08:40 4122368 ----a-r- c:\windows\system32\drivers\alcxwdm.sys
2012-10-08 14:08 . 2007-04-16 13:28 577536 ----a-w- c:\windows\soundman.exe
2012-10-08 14:08 . 2006-10-18 00:53 147456 ----a-w- c:\windows\system32\RtlCPAPI.dll
2012-10-08 14:08 . 2006-08-01 13:02 49152 ----a-w- c:\windows\system32\ChCfg.exe
2012-10-08 14:08 . 2006-12-08 13:20 10528768 ----a-w- c:\windows\system32\RTLCPL.exe
2012-10-08 14:08 . 2006-11-17 03:40 18804736 ----a-w- c:\windows\system32\alsndmgr.cpl
2012-10-08 14:07 . 2012-10-08 14:07 -------- d-----w- c:\program files\Realtek AC97
2012-10-08 14:07 . 2006-07-31 09:27 217088 ----a-w- c:\windows\alcrmv.exe
2012-10-08 14:07 . 2006-07-31 09:19 315392 ----a-w- c:\windows\alcupd.exe
2012-10-08 14:04 . 2006-02-07 13:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-10-08 14:04 . 2006-02-07 13:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-10-08 14:04 . 2006-02-07 13:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-10-08 14:04 . 2006-02-07 13:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-10-08 14:04 . 2005-11-13 21:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-10-08 14:04 . 2012-10-08 14:04 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-10-08 14:04 . 2012-10-08 14:04 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-10-07 13:35 . 2012-10-07 13:35 -------- d-----w- c:\program files\OpenAL
2012-10-06 17:02 . 2012-10-06 17:02 -------- d-----w- c:\program files\iPod
2012-10-06 17:02 . 2012-10-06 17:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-06 17:02 . 2012-10-06 17:03 -------- d-----w- c:\program files\iTunes
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-10-06 16:37 . 2012-10-06 16:37 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-10-06 16:37 . 2012-10-06 16:37 -------- d-----w- c:\program files\QuickTime
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-10 22:44 . 2012-08-06 17:38 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-10 22:44 . 2012-08-06 17:38 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-07 13:35 . 2012-09-11 18:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-07 13:35 . 2012-09-11 18:30 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-09-26 18:57 . 2011-01-20 02:04 4659712 ----a-w- c:\windows\system32\Redemption.dll
2012-09-26 18:57 . 2012-09-26 18:57 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2012-09-26 18:57 . 2012-09-26 18:57 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-09-26 18:57 . 2012-09-26 18:57 30568 ----a-w- c:\windows\MusiccityDownload.exe
2012-09-26 18:57 . 2012-09-26 18:57 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2012-09-26 18:57 . 2012-09-26 18:57 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2012-09-26 18:57 . 2012-09-26 18:57 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2012-09-26 18:57 . 2012-09-26 18:57 569344 ----a-w- c:\windows\system32\muzdecode.ax
2012-09-26 18:57 . 2012-09-26 18:57 491520 ----a-w- c:\windows\system32\muzapp.dll
2012-09-26 18:57 . 2012-09-26 18:57 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2012-09-26 18:57 . 2012-09-26 18:57 45320 ----a-w- c:\windows\system32\MAMACExtract.dll
2012-09-26 18:57 . 2012-09-26 18:57 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2012-09-26 18:57 . 2012-09-26 18:57 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2012-09-26 18:57 . 2012-09-26 18:57 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2012-09-26 18:57 . 2012-09-26 18:57 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2012-09-26 18:57 . 2012-09-26 18:57 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2012-09-26 18:57 . 2012-09-26 18:57 245760 ----a-w- c:\windows\system32\MSCLib.dll
2012-09-26 18:57 . 2012-09-26 18:57 24576 ----a-w- c:\windows\system32\MASetupCleaner.exe
2012-09-26 18:57 . 2012-09-26 18:57 200704 ----a-w- c:\windows\system32\muzwmts.dll
2012-09-26 18:57 . 2012-09-26 18:57 155648 ----a-w- c:\windows\system32\MSFLib.dll
2012-09-26 18:57 . 2012-09-26 18:57 143360 ----a-w- c:\windows\system32\3DAudio.ax
2012-09-26 18:57 . 2012-09-26 18:57 135168 ----a-w- c:\windows\system32\muzaf1.dll
2012-09-26 18:57 . 2012-09-26 18:57 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2012-09-26 18:57 . 2012-09-26 18:57 122880 ----a-w- c:\windows\system32\muzeffect.ax
2012-09-26 18:57 . 2012-09-26 18:57 118784 ----a-w- c:\windows\system32\MaDRM.dll
2012-09-26 18:57 . 2012-09-26 18:57 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2012-09-01 18:47 . 2012-09-01 18:47 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2012-08-21 11:01 . 2012-08-18 00:06 26840 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-08-21 11:01 . 2012-08-18 00:06 106928 ----a-w- c:\windows\system32\GEARAspi.dll
2012-08-06 15:47 . 2012-08-06 15:47 87328 ----a-w- c:\windows\system32\bcmwlcoi.dll
2012-08-06 15:47 . 2012-08-06 15:47 1123328 ----a-w- c:\windows\system32\drivers\BCMWL5.SYS
2012-10-27 14:28 . 2012-10-27 14:28 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 1372160]
"KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2012-10-11 966072]
"KiesAirMessage"="c:\program files\Samsung\Kies\KiesAirMessage.exe" [2012-10-09 580096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-05-11 472632]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-06-03 177456]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"Creative KSRun Persistence Module"="KSRun.dll" [2009-12-07 24064]
"Module Loader"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-10-11 309688]
"Ashampoo Anti-Malware Guard"="c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe" [2010-08-26 3314176]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /minimized /regrun
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Ashampoo Anti-Malware Guard"="c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Guard.exe"
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Seladon\\Data aplikací\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 8:03 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 8:06 96408]
R2 AAMW_WSC_Service_XP;Ashampoo Anti-Malware WSC Service;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_XP.exe [2.9.2012 12:31 53248]
R2 AAMWService;Ashampoo Anti-Malware Service;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe [2.9.2012 12:32 1309528]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 8:04 735960]
R3 AAMWRegFilter;AAMWRegFilter;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys [2.9.2012 12:32 18584]
R3 ASW3Scan;ASW3Scan;c:\program files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys [2.9.2012 12:32 17816]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [6.8.2012 16:56 193840]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [22.9.2012 6:38 73984]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 12:28 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6.8.2012 18:38 250808]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [11.9.2012 19:29 79360]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [26.10.2012 23:15 20032]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [22.9.2012 6:38 102784]
S3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\drivers\ew_usbenumfilter.sys [22.9.2012 6:38 11136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [12.8.2012 9:13 36640]
S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [15.12.2009 9:25 857472]
S3 ksaudfl;ksaudfl;c:\windows\system32\drivers\ksaudfl.sys [24.10.2008 17:27 1830912]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [6.8.2012 17:50 115168]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [8.10.2012 15:50 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [8.10.2012 15:50 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [8.10.2012 15:50 123648]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\drivers\ssceserd.sys [8.10.2012 15:50 100352]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2012-10-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 07:09]
.
2012-10-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-06 22:44]
.
2012-10-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Otevřít obrázek v aplikaci &Microsoft PhotoDraw - c:\progra~1\MICROS~2\Office\1029\phdintl.dll/phdContext.htm
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Stáhnout &Mass Downloaderem - c:\program files\Mass Downloader\Add_Url.htm
IE: Stáhnout &vše Mass Downloaderem - c:\program files\Mass Downloader\Add_All.htm
TCP: DhcpNameServer = 81.90.240.2 81.90.240.1 8.8.8.8
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\documents and settings\Seladon\Data aplikací\Mozilla\Firefox\Profiles\k9n61z3o.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - ExtSQL: 2012-09-06 14:08; cs@dictionaries.addons.mozilla.org; c:\documents and settings\Seladon\Data aplikacĂÂ\Mozilla\Firefox\Profiles\k9n61z3o.default\extensions\cs@dictionaries.addons.mozilla.org
pref('extensions.shownSelectionUI',true);
pref('extensions.autoDisableScopes',0);
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-28 12:07
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(916)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2388)
c:\documents and settings\Seladon\Data aplikací\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\RunDll32.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
.
**************************************************************************
.
Celkový čas: 2012-10-28 12:11:34 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-10-28 11:11
ComboFix2.txt 2012-10-28 06:22
.
Před spuštěním: Volných bajtů: 195 583 266 816
Po spuštění: Volných bajtů: 195 579 772 928
.
- - End Of File - - 6344835B688CB3C82614207327C356E9
- Rudy
- Site Admin
- Příspěvky: 119520
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mára log
Vše smazáno, log již vypadá OK. V PC běží 2 antiviry (Ashampoo Anti-Malware a Eset). Jedn z nich si vyberte a druhý odinstalujte, aby nedocházelo k sw kolizím.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Re: Mára log
Ok,Rudy píše:Vše smazáno, log již vypadá OK. V PC běží 2 antiviry (Ashampoo Anti-Malware a Eset). Jedn z nich si vyberte a druhý odinstalujte, aby nedocházelo k sw kolizím.
děkuji za pomoc.
Jinak tedy musím říci, že tyto dva antiviry ,mám nainstalované už dlouho a můj problém se začal projevovat až v posledním týdnu.
Software mi nepadá, ale Mozilla ano.
Prohlížení je také zpomaleno. Například nyní když píšu, chviličku je odezva stisknuté klávesy ihned a dost často se děje to, že napíšu větu a teprve se mi zobrazují první dvě slova třeba z 10ti.
Takže píšu do prázdna.
A teď jak tak koukám při psaní této zprávy, smajlíci umístěny vlevo se slušně nepravidelně sekají třeba na 2sec. někdy na 5sec. někdy na půl sec.
Nevím sis s tím vážně rady

- Rudy
- Site Admin
- Příspěvky: 119520
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mára log
Dva antiviry se rozhodně nedoporučují. Zkuste odinstalovat, nebo alespoň u jednoho z nich vypnout rezidentní šít a vyzkoušejte chod PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Re: Mára log
nic se nezměniloRudy píše:Dva antiviry se rozhodně nedoporučují. Zkuste odinstalovat, nebo alespoň u jednoho z nich vypnout rezidentní šít a vyzkoušejte chod PC.

- Rudy
- Site Admin
- Příspěvky: 119520
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mára log
Co jste instaloval těsně před tím, než se problém objevil?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Re: Mára log
Rudy píše:Co jste instaloval těsně před tím, než se problém objevil?
Právě že nic
- Rudy
- Site Admin
- Příspěvky: 119520
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Mára log
Start>ovl. panely>system>správce zařízení. Rozklikněte řadiče IDE/ATA a na jednotlivých kanálech pravým myšítkem vlastnosti>upřesnit nastavení. Zkontrolujte, zda je zapnut režim DMA. Pokud ne, zapněte, nastavení uložte a restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 9
- Registrován: 26 říj 2012 21:34
Re: Mára log
Nikde bohužel nevidím "upřesnit nastavení" a kde mám zkontrolovat DMA?Rudy píše:Start>ovl. panely>system>správce zařízení. Rozklikněte řadiče IDE/ATA a na jednotlivých kanálech pravým myšítkem vlastnosti>upřesnit nastavení. Zkontrolujte, zda je zapnut režim DMA. Pokud ne, zapněte, nastavení uložte a restartujte PC.
Večer jsem zkusil obnovení systému asi o 14 dní zpět a doposud to šlapalo v pořádku.
Ovšem chtělo to po mě aktualizaci Mozilly na verzi 16.
To jsem udělal a do pár minut mi to opět začalo dělat znovu.
Seká se mi prohlížeč, občas spadne úplně a nedá se prohlížet anipsát.
Každé 2-3 vteřiny je zásek

Win mám poměrně nedávno nově celé nahrané (sice starší verzi, ale jsem s nimi nejspokojenější), přes ashampoo anti malware a tune up utilities jsem pročistil vše co se dalo, uvolnil místo kde se dalo, na disku mám celkem dost místa a přesto přetrvává neustále tento problém.
Pomohlo by Vám, kdybychom nasdíleli mou plochu a podíval byste se mi na to osobně?
Moc byste mi pomohl, kdybyste mi problém dokázal odstarnit.
S pozdravem,
Marek