Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

worman (KONTROLA LOGOV) NOVÉ ..

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118323
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

#16 Příspěvek od Rudy »

Rádo se stalo!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

#17 Příspěvek od worman »

:arrow: Som to poprecistoval a ponahadzoval, tak poprosim kontrolu :wink:

Logfile of HijackThis v1.99.1
Scan saved at 15:37:27, on 29.12.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ICQLite\ICQLite.exe
D:\Best Programs in PC\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Peko\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118323
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

#18 Příspěvek od Rudy »

Log vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

iwigirl
VIP
VIP
Příspěvky: 331
Registrován: 25 dub 2005 18:27
Bydliště: Praha-Bubeneč
Kontaktovat uživatele:

#19 Příspěvek od iwigirl »

worman, jen prosíme- maximálně jeden log za den :wink:
:arrow: Chcete se stát vzorným návštěvníkem? Podrobnosti naleznete ZDE.
:arrow: VIRY řešte zde na fóru, pokud máte technický dotaz či dotaz související s chodem fóra, pište na iwi(zavináč)forum.viry.cz
:arrow: pomohla Vám moje rada? podpořte fórum smskou, přes SuperCash nebo nově přes PayPal :)
__________________________________________

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

#20 Příspěvek od worman »

:arrow: Zase som nieco nachytal, pls o kontrolu :idea: dik
:arrow:
Logfile of HijackThis v1.99.1
Scan saved at 4:23:33, on 24.3.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\WinRAR\WinRAR.exe
D:\Best Programs in my PC\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/sk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - (no file)
O3 - Toolbar: (no name) - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\RunOnce: [WMC_0] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\mp4sds32.ax"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Peko\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

#21 Příspěvek od worman »

:o :???:

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

#22 Příspěvek od riffman »

Log vypada OK

zkuste sken CureIt - http://download.drweb.com/win/
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

#23 Příspěvek od worman »

:arrow: Reinstal windows, please about control :wink: THX :D

:arrow:

Logfile of HijackThis v1.99.1
Scan saved at 1:28:02, on 9.4.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Opera\Opera.exe
D:\Best Programs in my PC\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118323
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

#24 Příspěvek od Rudy »

Fixněte v HijackThis:


O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

#25 Příspěvek od worman »

Logfile of HijackThis v1.99.1
Scan saved at 18:28:13, on 8.4.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Opera\Opera.exe
D:\Best Programs in my PC\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118323
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

#26 Příspěvek od Rudy »

Log vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

Re: worman (HIS ALL PROBLEMS IN PC)

#27 Příspěvek od worman »

KONTROLA LOGU

Logfile of HijackThis v1.99.1
Scan saved at 17:23:47, on 11. 6. 2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Windows\BR040286.exe
C:\Acer\Empowering Technology\eDSMSNfix.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\My Programs\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60327
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://breedband.telenet.be
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://breedband.telenet.be
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telenet Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pac.telenet.be:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [BisonInst0402] C:\Windows\BR040286.exe
O4 - HKLM\..\Run: [eDSMSNfix] C:\Acer\Empowering Technology\eDSMSNfix.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AdVantage Setup] C:\Program Files\DAEMON Tools Lite\AdVantageSetup.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Empowering Technology Launcher.lnk
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: eNetHook.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: JNS - Sysinternals - www.sysinternals.com - C:\Users\Pekowski\AppData\Local\Temp\JNS.exe
O23 - Service: KKGLMLO - Sysinternals - www.sysinternals.com - C:\Users\Pekowski\AppData\Local\Temp\KKGLMLO.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: YBZNHXLKK - Sysinternals - www.sysinternals.com - C:\Users\Pekowski\AppData\Local\Temp\YBZNHXLKK.exe

KONTROLA LOGU ZO SPYVARE TERMINATOR

Logfile of Spyware Terminator v2.2.1.433 (db:1.000.000.000)
Scan Time: 11. 6. 2008 17:19:24 length: 53 s
Platform: VISTA (6.0.0.6000)
User: Admin
Boot Mode: Normal
Scan type: Fast_Spyware_Scan
Scanned Objects: 18749 (Critical:0)
Filter: No System items, No Safe items, No Invalid items

Running Processes
Ati2evxx.exe [ATI Technologies Inc.] : C:\Windows\system32\Ati2evxx.exe
SLsvc.exe [Microsoft Corporation] : C:\Windows\system32\SLsvc.exe
Ati2evxx.exe [ATI Technologies Inc.] : C:\Windows\system32\Ati2evxx.exe
AluSchedulerSvc.exe [Symantec Corporation] : C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
eDSService.exe [HiTRSUT] : C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
eLockServ.exe [Acer Inc.] : C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
eNet Service.exe [Acer Inc.] : C:\Acer\Empowering Technology\eNet\eNet Service.exe
LSSrvc.exe [Hewlett-Packard Company] : C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PIFSvc.exe [Symantec Corporation] : C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
MobilityService.exe : C:\Acer\Mobility Center\MobilityService.exe
RichVideo.exe : C:\Program Files\CyberLink\Shared Files\RichVideo.exe
XAudio.exe [Conexant Systems, Inc.] : C:\Windows\system32\drivers\XAudio.exe
eRecoveryService.exe [Acer Inc.] : C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
capuserv.exe : C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
ePowerSvc.exe [acer] : C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
RtHDVCpl.exe [Realtek Semiconductor] : C:\Windows\RtHDVCpl.exe
eDSloader.exe [HiTRUST] : C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
BR040286.exe [Bison Inc.] : C:\Windows\BR040286.exe
eDSMSNfix.exe [HiTRUST co.] : C:\Acer\Empowering Technology\eDSMSNfix.exe
LManager.exe [Dritek System Inc.] : C:\Program Files\Launch Manager\LManager.exe
PIFSvc.exe [Symantec Corporation] : C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
sidebar.exe [Microsoft Corporation] : C:\Program Files\Windows Sidebar\sidebar.exe
eNMTray.exe [Acer Inc.] : C:\Acer\Empowering Technology\eNet\eNMTray.exe
ePower_DMC.exe [Acer Inc.] : C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
eRAgent.exe [Acer Inc.] : C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

Internet Settings
R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar = http://www.crawler.com/search/dispatche ... tbid=60327
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://breedband.telenet.be
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant =
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

BHO
02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - [Adobe Systems Incorporated] : C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
02 - BHO: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - : C:\Program Files\PC Translator\webie.dll
02 - BHO: MenuItem3 Class - {CC963627-B1DC-40E0-B52A-CF21EE748450} - : C:\Program Files\PC Translator\webie.dll
02 - BHO: MenuItem2 Class - {CC963627-B1DC-40E0-B52A-CF21EE748451} - : C:\Program Files\PC Translator\webie.dll
02 - BHO: MenuItem1 Class - {CC963627-B1DC-40E0-B52A-CF21EE748452} - : C:\Program Files\PC Translator\webie.dll

Toolbars
03 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - [HiTRUST] : C:\Windows\system32\eDStoolbar.dll
03 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - : C:\Program Files\PC Translator\webie.dll

StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Sidebar : [Microsoft Corporation] : C:\Program Files\Windows Sidebar\sidebar.exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Acer Tour Reminder : [Acer Inc.] : C:\Acer\AcerTour\Reminder.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, RtHDVCpl : [Realtek Semiconductor] : C:\Windows\RtHDVCpl.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, eDataSecurity Loader : [HiTRUST] : C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BisonInst0402 : [Bison Inc.] : C:\Windows\BR040286.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, eDSMSNfix : [HiTRUST co.] : C:\Acer\Empowering Technology\eDSMSNfix.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, LManager : [Dritek System Inc.] : C:\Program Files\Launch Manager\LManager.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, WarReg_PopUp : [Acer Inc.] : C:\Acer\WR_PopUp\WarReg_PopUp.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Acer Tour Reminder : [Acer Inc.] : C:\Acer\AcerTour\Reminder.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Symantec PIF AlertEng : [Symantec Corporation] : C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, AdVantage Setup : [AdVantage] : C:\Program Files\DAEMON Tools Lite\AdVantageSetup.exe
04 - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs : [acer] : C:\Windows\system32\eNetHook.dll
04 - Startup: %STARTUPALL%\Empowering Technology Launcher.lnk [Acer Inc.] : C:\Acer\Empowering Technology\eAPLauncher.exe

Shell Extensions
CLSID_PreviewMime - {92dbad9f-5025-49b0-9078-2d78f935e341} - [Microsoft Corporation] : C:\Windows\system32\inetcomm.dll
CLSID_PreviewEmail - {b9815375-5d7f-4ce2-9245-c9d4da436930} - [Microsoft Corporation] : C:\Windows\system32\inetcomm.dll
CLSID_PreviewHtml - {f8b8412b-dea3-4130-b36c-5e8be73106ac} - [Microsoft Corporation] : C:\Windows\system32\inetcomm.dll
Shell Message Handler - {5FA29220-36A1-40f9-89C6-F4B384B7642E} - [Microsoft Corporation] : C:\Windows\system32\inetcomm.dll
CompressedFolder - {E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} - [Microsoft Corporation] : C:\Windows\system32\zipfldr.dll
Compressed (zipped) Folder Right Drag Handler - {BD472F60-27FA-11cf-B8B4-444553540000} - [Microsoft Corporation] : C:\Windows\system32\zipfldr.dll
Compressed (zipped) Folder SendTo Target - {888DCA60-FC0A-11CF-8F0F-00C04FD7D062} - [Microsoft Corporation] : C:\Windows\system32\zipfldr.dll
Compressed (zipped) Folder Context Menu - {b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af} - [Microsoft Corporation] : C:\Windows\system32\zipfldr.dll
Compressed (zipped) Folder DropHandler - {ed9d80b9-d157-457b-9192-0e7280313bf0} - [Microsoft Corporation] : C:\Windows\system32\zipfldr.dll
&Windows Media Player - {0a4286ea-e355-44fb-8086-af3df7645bd9} - [Microsoft Corporation] : C:\Program Files\Windows Media Player\wmpband.dll
- {BB6B2374-3D79-41DB-87F4-896C91846510} - [Microsoft Corporation] : C:\Windows\system32\emdmgmt.dll
Windows Photo Gallery Viewer Autoplay Handler - {9D687A4C-1404-41ef-A089-883B6FBECDE6} - [Microsoft Corporation] : C:\Windows\system32\RUNDLL32.EXE
Portable Media Devices - {640167b4-59b0-47a6-b335-a6b3c0695aea} - [Microsoft Corporation] : C:\Windows\system32\audiodev.dll
- {2F603045-309F-11CF-9774-0020AFD0CFF6} - [Synaptics, Inc.] : C:\Program Files\Synaptics\SynTP\SynTPCpl.dll
SimpleShlExt Class - {5E2121EE-0300-11D4-8D3B-444553540000} - : C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll

Protocol Handler
MHTML Asynchronous Pluggable Protocol Handler - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - [Microsoft Corporation] : C:\Windows\system32\inetcomm.dll
IEProtocolHandler Class - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - [Skype Technologies] : C:\Program Files\Common Files\Skype\Skype4COM.dll

Services
23 - [ALWIL Software] : C:\Windows\system32\DRIVERS\aswFsBlk.sys
23 - [ALWIL Software] : C:\Windows\system32\DRIVERS\aswMonFlt.sys
23 - [ATI Technologies Inc.] : C:\Windows\system32\Ati2evxx.exe
23 - [ATI Technologies Inc.] : C:\Windows\system32\DRIVERS\atikmdag.sys
23 - [Symantec Corporation] : C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
23 - [Bison Electronics. Inc.] : C:\Windows\system32\Drivers\BisonC07.sys
23 - [Dritek System Inc.] : C:\Windows\system32\DRIVERS\DKbFltr.sys
23 - [Dritek System Inc.] : C:\Program Files\Launch Manager\DPortIO.sys
23 - [HiTRSUT] : C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
23 - [Acer Inc.] : C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
23 - [ENE Technology Inc.] : C:\Windows\system32\DRIVERS\EMS7SK.sys
23 - [Acer Inc.] : C:\Acer\Empowering Technology\eNet\eNet Service.exe
23 - [Acer Inc.] : C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
23 - [ENE Technology Inc.] : C:\Windows\system32\DRIVERS\ESD7SK.sys
23 - : C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
23 - [ENE Technology Inc.] : C:\Windows\system32\DRIVERS\ESM7SK.sys
23 - [Conexant Systems, Inc.] : C:\Windows\system32\DRIVERS\HSX_DPV.sys
23 - [Conexant Systems, Inc.] : C:\Windows\system32\DRIVERS\HSXHWAZL.sys
23 - : C:\Acer\Empowering Technology\eRecovery\int15.sys
23 - [Realtek Semiconductor Corp.] : C:\Windows\system32\drivers\RTKVHDA.sys
23 - [Hewlett-Packard Company] : C:\Program Files\Common Files\LightScribe\LSSrvc.exe
23 - [Symantec Corporation] : C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
23 - [Conexant] : C:\Windows\system32\DRIVERS\mdmxsdk.sys
23 - [NewTech Infosystems, Inc.] : C:\Windows\system32\DRIVERS\NTIDrvr.sys
23 - [HiTRUST] : C:\Windows\system32\DRIVERS\psdfilter.sys
23 - [HiTRUST] : C:\Windows\system32\drivers\PSDNServ.sys
23 - [HiTRUST] : C:\Windows\system32\drivers\psdvdisk.sys
23 - [Sonic Solutions] : C:\Windows\system32\Drivers\PxHelp20.sys
23 - : C:\Program Files\CyberLink\Shared Files\RichVideo.exe
23 - [Realtek Semiconductor Corporation] : C:\Windows\system32\DRIVERS\Rtnicxp.sys
23 - [Microsoft Corporation] : C:\Windows\system32\SLsvc.exe
23 - : C:\Windows\system32\Drivers\sptd.sys
23 - [Crawler.com] : C:\Windows\system32\drivers\sp_rsdrv2.sys
23 - [Synaptics, Inc.] : C:\Windows\system32\DRIVERS\SynTP.sys
23 - [Conexant Systems, Inc.] : C:\Windows\system32\DRIVERS\HSX_CNXT.sys
23 - [acer] : C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
23 - [Conexant Systems, Inc.] : C:\Windows\system32\DRIVERS\xaudio.sys
23 - [Conexant Systems, Inc.] : C:\Windows\system32\drivers\XAudio.exe

Advanced Files Report
%SYSDIR%\Ati2evxx.exe [ATI Technologies Inc.] [ATI External Event Utility for Windows] MD5=A63B95991D0036D8D5A188BB4A31CF18 SIZE=569344
%SYSDIR%\RtkAPO.dll [Realtek Semiconductor Corp.] [Realtek(r) LFX/GFX DSP component] MD5=3ECFFF6C69A056B0BEAD2CD7F96F9961 SIZE=1766912
%SYSDIR%\SLsvc.exe [Microsoft Corporation] [Microsoft® Windows® Operating System] MD5=A1DCD30534835CB67733AD00175125A6 SIZE=2605568
%SYSDIR%\Ati2edxx.dll [ATI Technologies, Inc.] [ATI External Device Utility] MD5=3C787DFBA7EACB458701EEEF664FA5D4 SIZE=42496
%SYSDIR%\atipdlxx.dll [ATI Technologies, Inc.] [ATI Desktop Component] MD5=CB37DE08F9E8998E623B875A0E82D79B SIZE=249856
%SYSDIR%\ati2evxx.dll [ATI Technologies Inc.] [ATI External Event Utility for Windows] MD5=0F02E1CA8519BB4E4D7A4B050CCABBD6 SIZE=233472
%SYSDIR%\MsnChatHook.dll [HiTRUST Inc.] [MsnChatHook] MD5=81ADB60C39DECB86676D1C6F9578E68B SIZE=94208
%SYSDIR%\ShowErrMsg.dll [ShowErrMsg] MD5=DBC8E6FF0168A4F4BEA32565878571E0 SIZE=63488
%SYSDIR%\sysenv.dll [HiTRUST] [SysEnv] MD5=26114324A6F9A71DADC97413B22FF8AD SIZE=286720
%SYSDIR%\BatchCrypto.dll [BatchCrypto Dynamic Link Library] MD5=7135365E28F2502D56FBEDB5854D1B9C SIZE=28672
%SYSDIR%\CryptoAPI.dll [HiTRUST] [CryptoAPI] MD5=DF53B8BD2C2D86E8CFEB4BB488B5EA37 SIZE=401408
%SYSDIR%\keyManager.dll [HiTRSUT] [keyManager] MD5=998883A579D77E07F0833D84CE46593B SIZE=237568
%SystemDiskRoot%\Acer\Empowering Technology\EPOWER\SysHook.dll [SysHook Dynamic Link Library] MD5=C9E79E2DA051AA36EFDD269F4D59CDC9 SIZE=28672
%SYSDIR%\atiumdag.dll [ATI Technologies Inc.] [ATI Technologies Inc. Radeon DirectX Universal Driver] MD5=69AC44D2D7332A82A8039416D5F77620 SIZE=2791424
%SYSDIR%\atiumdva.dll [ATI Technologies Inc.] [ATI Technologies Inc. Radeon Video Acceleration Universal Driver] MD5=21C737636A04EB92EA2D771EB004ECBA SIZE=2730496
%SYSDIR%\eDSshellExt.dll [HiTRUST] [eDSshellExt Module] MD5=8A8CB6FA490DE82B6C6456A421B56F83 SIZE=315392
%PROGRAMFILES%\Acer Arcade Deluxe\DVDivine\Kernel\Video\CLImageVSD.ax [CyberLink Corp.] [CyberLink PowerDVD] MD5=34B9DD5BC6468DF892E7C5C05516C908 SIZE=512000
%SYSDIR%\atitmmxx.dll [TMM Com Clone Control Module] MD5=C48214D477D5EB414F9126595614B75C SIZE=159744
%PROGRAMFILES%\Symantec\LiveUpdate\AluSchedulerSvc.exe [Symantec Corporation] [LiveUpdate] MD5=B5D974C1FD078A68C7536C561B031D39 SIZE=554352
%SystemDiskRoot%\Acer\Empowering Technology\eDataSecurity\eDSService.exe [HiTRSUT] [eDataSecurity Management] MD5=F87DDE13D57062DA8EBA2368667D8130 SIZE=457512
%SYSDIR%\PSDUtil.dll [HiTRUST] MD5=8FF15B0E7C6F4627C007EAF3ADAFA083 SIZE=121344
%SystemDiskRoot%\Acer\Empowering Technology\eLock\Service\eLockServ.exe [Acer Inc.] [Acer eLock Management] MD5=7A9E8C1BE235D0B0CA784A13FC960B6A SIZE=24576
%SystemDiskRoot%\Acer\Empowering Technology\eLock\Service\eLock.Serv.Main.dll [Acer Inc.] [Acer eLock Management] MD5=1E1820625B98FD044515D69C5C881979 SIZE=61440
%SystemDiskRoot%\Acer\Empowering Technology\eLock\Service\eLock.Serv.Interface.dll [Acer Inc.] [Acer eLock Management] MD5=3A2FBD3703D21D27226D85A9DC5A55CB SIZE=20480
%SystemDiskRoot%\Acer\Empowering Technology\eLock\Service\eLock.Serv.Library.dll [Acer Inc.] [Acer eLock Management] MD5=ACDA12B8412BEEABB21310C5AF481C22 SIZE=102400
%SystemDiskRoot%\Acer\Empowering Technology\eLock\Service\log4net.dll [The Apache Software Foundation] [log4net] MD5=CA8C34CFB6573800B9D6AF99C419228C SIZE=249856
%SystemDiskRoot%\Acer\Empowering Technology\eNet\eNet Service.exe [Acer Inc.] [Acer eNet Management] MD5=50CCDBEAF80876F9AB378FE5B8FC6D69 SIZE=131072
%SystemDiskRoot%\Acer\Empowering Technology\eNet\eNetHook.dll [acer] [acer eNetManagement] MD5=649664E7B90580AA849BDC05B3EF07C7 SIZE=90112
%SystemDiskRoot%\Acer\Empowering Technology\eNet\eNetServiceInterface.dll [Acer Inc.] [Acer eNet Management] MD5=3866DAE90080A2C58EF4D867F30DCE50 SIZE=34816
%COMMONFILES%\LightScribe\LSSrvc.exe [Hewlett-Packard Company] [LightScribe] MD5=559C9B7800FAC92FC515CD0003D7C631 SIZE=61440
%COMMONFILES%\LightScribe\LSSProxy.dll [Hewlett-Packard Company] [LightScribe] MD5=938437451AFFAE8F76E0145D81D7960C SIZE=81920
%COMMONFILES%\LightScribe\LSLog.dll [Hewlett-Packard Company] [LightScribe] MD5=CF259D14E763F6EF88767655F9D64D0E SIZE=32768
%COMMONFILES%\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll [Symantec Corporation] [LiveUpdate Notice] MD5=DCE009C00BDAEF1DCBE6FE92C7CB3B3B SIZE=537992
%COMMONFILES%\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PollMgr.dll [Symantec Corporation] [LiveUpdate Notice] MD5=D15BE463DC3ED0A35B146302E5E59FA3 SIZE=607624
%SystemDiskRoot%\Acer\Mobility Center\MobilityService.exe MD5=842684E0DF20A59E293DA1C6F0DFE261 SIZE=107008
%SystemDiskRoot%\Acer\Mobility Center\MobilityInterface.dll MD5=30A8C2FBE6A8585A4A7151EDF1F61F79 SIZE=33280
%PROGRAMFILES%\CyberLink\Shared Files\RichVideo.exe [RichVideo Module] MD5=C1C132455200AD4704142442C89D0FA4 SIZE=262247
%SYSDIR%\drivers\XAudio.exe [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=28DC5D626E036A75A572556F0A6EB1F6 SIZE=386560
%SystemDiskRoot%\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [Acer Inc.] [eRecoveryService] MD5=A2580C15D2664D18C3E140C7F98B366C SIZE=53248
%SystemDiskRoot%\Acer\Empowering Technology\eRecovery\ServiceInterface.dll [ServiceInterface] MD5=1F8F142EDDCD886BA81A832EF2136C68 SIZE=16384
%SystemDiskRoot%\Acer\Empowering Technology\eRecovery\IERYETF.dll [IERYETF] MD5=6C05BAB88EB6A65A56BBE7A3DBF72E0A SIZE=16384
%SystemDiskRoot%\Acer\Empowering Technology\eSettings\Service\capuserv.exe [Service] MD5=D411B3C7005917470F5D9B9C8F48DD96 SIZE=24576
%SystemDiskRoot%\Acer\Empowering Technology\eSettings\Service\log4net.dll [The Apache Software Foundation] [log4net] MD5=5F3BD963F02108C36592B5728FA725C5 SIZE=270336
%SystemDiskRoot%\Acer\Empowering Technology\eSettings\Service\eSettings.Model.Computer.dll [Computer] MD5=DA3BE52A6B2E8323E3BA38CA57FDC88B SIZE=114688
%SystemDiskRoot%\Acer\Empowering Technology\eSettings\Service\eSettings.Model.ComputerInterfaces.dll [ComputerInterfaces] MD5=CF41B9C53A2DCA2231F6D01F6337AA64 SIZE=32768
%SystemDiskRoot%\Acer\Empowering Technology\eSettings\Service\eSettings.Model.Library.dll [Library] MD5=066006C8CF464D90BABC851215AD7C69 SIZE=114688
%SystemDiskRoot%\Acer\Empowering Technology\eSettings\Service\CPUID.dll MD5=F9F8DAA8FD5A70A0A1D577264C498286 SIZE=6656
%SystemDiskRoot%\Acer\Empowering Technology\ePower\ePowerSvc.exe [acer] [Acer ePower Management] MD5=D4DBD5DF926A2A16F6F148559E006075 SIZE=135168
%SystemDiskRoot%\Acer\Empowering Technology\ePower\WMIInterface.dll [acer] [WMIInter Dynamic Link Library] MD5=882FD60A4AEAF817949A62E4C772C349 SIZE=33792
%SYSDIR%\SynCOM.dll [Synaptics, Inc.] [COM SDK] MD5=E493E371430C618215F0CB16634A993E SIZE=163840
%SYSDIR%\SynTPAPI.dll [Synaptics, Inc.] [Synaptics Pointing Device Driver] MD5=59EF9873EEDC76E870F3461B561F61E1 SIZE=143360
%SYSDIR%\ADMIN_CLASS_LIB.dll [HiTRUST] [eDataSecurity Aministration Core Class library] MD5=4D9367904655D53D46CDD74A8B202B73 SIZE=123392
%PROGRAMFILES%\Launch Manager\ComFnUtl.dll [Dritek System Inc.] [ComFnUtl.dll] MD5=F44F5CF7F050191602523A828B327EBB SIZE=98378
%PROGRAMFILES%\Launch Manager\SzUPFUtl.dll [Dritek System Inc.] [Dritek System Inc. SzUPFUtl 6.28.2000 ( VC60 )] MD5=35EAFA4F987A2B05F110C54173836066 SIZE=61440
%PROGRAMFILES%\Launch Manager\OSDUtl.dll [Dritek System Inc.] [Dritek System Inc. OSD Library] MD5=9FCE388428CB6466534AE7A12ACDF60C SIZE=147530
%PROGRAMFILES%\Launch Manager\RgnMaker.dll [Dritek System Inc.] [Dritek System Inc. RgnMaker] MD5=5A1822B18FEE8807EB7EB33BA8CF9B0F SIZE=49152
%PROGRAMFILES%\Launch Manager\CDRomUtl.dll [Dritek System Inc.] [Dritek System Inc. CDRomUtl 6.14.2000 ( VC60 )] MD5=1D45A7FF7949628D466E0E884EECAA85 SIZE=40960
%PROGRAMFILES%\Launch Manager\MixerUtl.dll [Dritek System Inc.] [Dritek System Inc. MixerUtl 6.14.2000 ( VC60 )] MD5=8E3122A02C3981A9681C814E2AE102F1 SIZE=61440
%PROGRAMFILES%\Launch Manager\Wnd2File.dll [Dritek System Inc.] [Dritek System Inc. Wnd2File 12.23.1999 ( VC60 )] MD5=C9A8F1D76F468EB1C6E05949F5485B0D SIZE=53248
%PROGRAMFILES%\Launch Manager\SzPtcUtl.dll [Dritek System Inc.] [Dritek System Inc. SzPtcUtl 7.25.2000 ( VC60 )] MD5=5D2BB75DD7B79D7C5CFDAA3DFB2C7B4F SIZE=49152
%PROGRAMFILES%\Launch Manager\PowerUtl.dll MD5=5B2F136FFB0291EFB259F2AB22CD35A2 SIZE=57344
%PROGRAMFILES%\Launch Manager\LgKCUtl.Dll [Dritek System Inc.] [LgKCUtl.DLL] MD5=0EDF40E039D92EA5EB26BF01BE9ECC50 SIZE=77824
%PROGRAMFILES%\Launch Manager\PtIOUtl.DLL [Dritek System Inc.] [Dritek System Inc. PtIOUTL] MD5=D208280F5AE538A4AF526DBD758B97F7 SIZE=57344
%PROGRAMFILES%\Launch Manager\DialCnt.Dll [Dritek System Inc.] [Dritek System Inc. Dialer Center] MD5=1656D5759B75480A1EF340B6AC49430D SIZE=57344
%PROGRAMFILES%\Launch Manager\VistaVol.DLL [Dritek System Inc.] [Windows Vista Master Volume Control Library] MD5=0BC06A98B88EA45C9214BBD973E2CCFC SIZE=151552
%PROGRAMFILES%\Launch Manager\MMDUtl.DLL [Dritek System Inc.] [Dritek Display Toggle Hotkey Library.] MD5=836E2DC5495668FA4DDF96046A9E9DC5 SIZE=221184
%COMMONFILES%\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll [Symantec Corporation] [LiveUpdate Notice] MD5=81A1312CCF521CFA56FB28B097E0C722 SIZE=398728
%COMMONFILES%\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertUi.dll [Symantec Corporation] [LiveUpdate Notice] MD5=85553A46B1370B21AAAF9243B02FEAA2 SIZE=353672
%SystemDiskRoot%\Acer\Empowering Technology\eNet\eNMTray.exe [Acer Inc.] [Acer eNet Management] MD5=C7E94EF1C9A313C56D316480D14E69EA SIZE=749568
%SystemDiskRoot%\Acer\Empowering Technology\ENET\eNMIPCmm.dll [Acer Inc.] [Acer eNet Management] MD5=C045EC4D58D00CB46F171763F622AC10 SIZE=77824
%SystemDiskRoot%\Acer\Empowering Technology\ENET\Network.dll [Acer Inc.] [Acer eNet Management] MD5=B33198E53C97888A0BB1E6C6FAC26D35 SIZE=135168
%SystemDiskRoot%\Acer\Empowering Technology\ENET\NetworkCardMgr.dll [Acer Inc.] [Acer eNet Management] MD5=C6E93AC236196D33B4D8985D70CC99F3 SIZE=11776
%SystemDiskRoot%\Acer\Empowering Technology\eNet\ICmdDispatcher.dll [Acer Inc.] [Acer eNet Management] MD5=83D42D8B523AB8FB4BCB37E4D3AD6899 SIZE=43520
%SystemDiskRoot%\Acer\Empowering Technology\eNet\PfMgr.dll [Acer Inc.] [Acer eNet Management] MD5=4E929A6B733BD2D01282DFA2C89FB975 SIZE=114688
%SystemDiskRoot%\Acer\Empowering Technology\eNet\Wlan.dll [Acer Inc.] [Acer eNet Management] MD5=17E049FEDFE0379D58A6F1F11009B8C8 SIZE=75264
%SystemDiskRoot%\Acer\Empowering Technology\eNet\Acer.Empowering.Windows.Forms.dll [Acer inc.] [Acer Empowering UI Components] MD5=96292347CB7780EAF177C1FCD29EB686 SIZE=1499136
%SystemDiskRoot%\Acer\Empowering Technology\eNet\MultiLang.dll [Acer Inc.] [Acer eNet Management] MD5=C876E198B04A1F3F5DA86822D14DF620 SIZE=39424
%SystemDiskRoot%\Acer\Empowering Technology\eNet\ProfileSwitch.dll [Acer Inc.] [Acer eNet Management] MD5=AF2A452C49FB42B8D7C8C7977DCCCAD4 SIZE=88064
%SystemDiskRoot%\Acer\Empowering Technology\eNet\Diagnosis.dll [Acer Inc.] [Acer eNet Management] MD5=5A4BFAA696F0B902F121C058C02335AA SIZE=80896
%SystemDiskRoot%\Acer\Empowering Technology\ePower\ePower_DMC.exe [Acer Inc.] [Acer ePower Management] MD5=6614BB708D98A56FBC8B7421F65D2542 SIZE=462848
%SystemDiskRoot%\Acer\Empowering Technology\eRecovery\eRAgent.exe [Acer Inc.] [Acer eRecovery Management] MD5=4F779AD993A2975D945EE6985CAC0FEA SIZE=397312
%SystemDiskRoot%\Acer\Empowering Technology\eAPLauncher.exe [Acer Inc.] [Acer eAP Launch Tool] MD5=C849D57292E58A9E1C55559930FD1082 SIZE=528384
%SYSDIR%\inetcomm.dll [Microsoft Corporation] [Microsoft® Windows® Operating System] MD5=0D444215D80FC50E43F02E4B5A43877D SIZE=737792
%SYSDIR%\zipfldr.dll [Microsoft Corporation] [Microsoft® Windows® Operating System] MD5=C9F8C752ED450D74A51FC4DA40B0DA16 SIZE=338432
%PROGRAMFILES%\Windows Media Player\wmpband.dll [Microsoft Corporation] [Microsoft® Windows® Operating System] MD5=4AEED1FBB53F915CBE30671793776A80 SIZE=99328
%SYSDIR%\emdmgmt.dll [Microsoft Corporation] [Microsoft® Windows® Operating System] MD5=3226FDA08988526E819E364E8CCE4CEE SIZE=560640
%SYSDIR%\RUNDLL32.EXE [Microsoft Corporation] [Microsoft® Windows® Operating System] MD5=4B555106290BD117334E9A08761C035A SIZE=44544
%SYSDIR%\audiodev.dll [Microsoft Corporation] [Microsoft® Windows® Operating System] MD5=BC59360E14159C67FF257FB424F3B723 SIZE=244224
%PROGRAMFILES%\Synaptics\SynTP\SynTPCpl.dll [Synaptics, Inc.] [Synaptics Pointing Device Driver] MD5=29F41D77755D8E843972132A8ADFF391 SIZE=880640
epm-po.dll
%PROGRAMFILES%\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll [ACE Context Menu] MD5=3A9F70479A886DCC8E5151326156472D SIZE=73728
%SYSDIR%\svchost.exe -k netsvcs
%SYSDIR%\DRIVERS\aswFsBlk.sys [ALWIL Software] [avast! Antivirus System] MD5=922C09ED986C31D6D4445DC937465103 SIZE=20560
%SYSDIR%\DRIVERS\aswMonFlt.sys [ALWIL Software] [avast! Antivirus System] MD5=1329D1B7F101E313EEDEEDE7D0AFBE70 SIZE=50768
%SYSDIR%\DRIVERS\atikmdag.sys [ATI Technologies Inc.] [ATI Radeon Family] MD5=DACA081E9DC82D4A05B0D21E8AA93DF8 SIZE=2464768
%SYSDIR%\svchost.exe -k LocalSystemNetworkRestricted
%SYSDIR%\svchost.exe -k LocalServiceNetworkRestricted
%SYSDIR%\svchost.exe -k LocalServiceNoNetwork
%SYSDIR%\Drivers\BisonC07.sys [Bison Electronics. Inc.] [BisonCam UVC, USB 2.0 Camera] MD5=900DD2388B5C452307EEBFC451E2C6D9 SIZE=761904
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\svchost.exe -k DcomLaunch
%SYSDIR%\DRIVERS\DKbFltr.sys [Dritek System Inc.] [Dritek Keyboard Filter Driver] MD5=73BAF270D24FE726B9CD7F80BB17A23D SIZE=21264
%PROGRAMFILES%\Launch Manager\DPortIO.sys [Dritek System Inc.] [DPortIO] MD5=5C918D413F5837E67A85775C9873775E SIZE=20112
%SYSDIR%\DRIVERS\EMS7SK.sys [ENE Technology Inc.] [ENE PCI Memory Stick Card Reader Driver] MD5=1FA3F9DF8983873746FA6B72DD7E3C2C SIZE=62208
%SYSDIR%\DRIVERS\ESD7SK.sys [ENE Technology Inc.] [ENE PCI Secure Digital / MMC Card Reader Driver] MD5=9C7487253AAD6BF61F9BC83D50E32CCC SIZE=42240
%SYSDIR%\DRIVERS\ESM7SK.sys [ENE Technology Inc.] [ENE PCI SmartMedia / XD Card Reader Driver] MD5=99589D975DA04F8BD31F124428FCC797 SIZE=76928
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\DRIVERS\HSX_DPV.sys [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=9EFA5FEC26CEC696A66A891AC90B412D SIZE=986624
%SYSDIR%\DRIVERS\HSXHWAZL.sys [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=7E775360ECE92156CED6ED3B1DAF6208 SIZE=206848
%SystemDiskRoot%\Acer\Empowering Technology\eRecovery\int15.sys MD5=9D64201C9E5AC8D1F088762BA00FF3AB SIZE=76584
%SYSDIR%\drivers\RTKVHDA.sys [Realtek Semiconductor Corp.] [Realtek(r) High Definition Audio Function Driver] MD5=04BEF1C4AA990E0D5851C7532FC8642C SIZE=1655464
%SYSDIR%\DRIVERS\mdmxsdk.sys [Conexant] [Diagnostic Interface x86 Driver] MD5=0CEA2D0D3FA284B85ED5B68365114F76 SIZE=12672
%SystemDiskRoot%\Acer\Mobility Center\MobilityService.exe -p
%SYSDIR%\DRIVERS\NTIDrvr.sys [NewTech Infosystems, Inc.] MD5=7F1C1F78D709C4A54CBB46EDE7E0B48D SIZE=6144
%SYSDIR%\svchost.exe -k NetworkServiceNetworkRestricted
%SYSDIR%\DRIVERS\psdfilter.sys [HiTRUST] MD5=C2821F33B846A52FDC25FF554ACF11F2 SIZE=20264
%SYSDIR%\drivers\PSDNServ.sys [HiTRUST] MD5=28D3A91FE7791B970E6B15C88F98DFBD SIZE=16680
%SYSDIR%\drivers\psdvdisk.sys [HiTRUST] MD5=3A66F69459052DE13EF8A0F77D728A73 SIZE=60712
%SYSDIR%\Drivers\PxHelp20.sys [Sonic Solutions] [PxHelp20] MD5=183EF96BCC2EC3D5294CB2C2C0ECBCD1 SIZE=20640
%SYSDIR%\svchost.exe -k rpcss
%SYSDIR%\DRIVERS\Rtnicxp.sys [Realtek Semiconductor Corporation] [Realtek 10/100 NIC Family all in one NDIS Driver] MD5=FDDE6B3598660D3C51CB45EB3A95FE67 SIZE=51200
%SYSDIR%\Drivers\sptd.sys SIZE=715248
%SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [Spyware Terminator] MD5=CCD6E6C387E3EFA3BA5FE0E7883821C1 SIZE=141312
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\DRIVERS\SynTP.sys [Synaptics, Inc.] [Synaptics Pointing Device Driver] MD5=F7A4250BB3E3AFCD4AF100E551509352 SIZE=179896
%SYSDIR%\svchost.exe -k WerSvcGroup
%SYSDIR%\DRIVERS\HSX_CNXT.sys [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=CF27EDAC75C87F2B776D9218F02F8301 SIZE=659968
%SYSDIR%\svchost.exe -k secsvcs
%SYSDIR%\SearchIndexer.exe \Embedding
%SYSDIR%\DRIVERS\xaudio.sys [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=5A7FF9A18FF6D7E0527FE3ABF9204EF8 SIZE=8192
%COMMONFILES%\Skype\Skype4COM.dll [Skype Technologies] [Skype4COM] MD5=2F7520EFE75CA986F9E41B53162B7144 SIZE=1942864

End of Report

ĎAKUJEM :thumbsup:
Obrázek
Obrázek

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

Re: worman (HIS ALL PROBLEMS IN PC)

#28 Příspěvek od worman »

Myslim, ze sa na mna zabudlo :o Sorry za spam.
Obrázek
Obrázek

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: worman (HIS ALL PROBLEMS IN PC)

#29 Příspěvek od riffman »

ale nezabudlo :)

otazka 1 - http://breedband.telenet.be znate?

otazka 2 - msconfig si po startu spoustite umyslne?
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

worman
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 29 črc 2005 10:19
Bydliště: Europe

Re: worman (HIS ALL PROBLEMS IN PC)

#30 Příspěvek od worman »

riffman píše:ale nezabudlo :)

otazka 1 - http://breedband.telenet.be znate?

otazka 2 - msconfig si po startu spoustite umyslne?
Prvej otazke nechapem, ten telenet je moj pokytovatel internetu.
A msconfig si nespustam umyselne, preco? Iba mam vypnute nejake halusky co sa zapinaju pri starte :roll:
Obrázek
Obrázek

Odpovědět