
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Log z RSIT nejde vytvorit, PC je pomale
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Log z RSIT nejde vytvorit, PC je pomale
OTL:
========== OTL ==========
Process explorer.exe killed successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Mirabilis ICQ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz not found.
File C:\WINDOWS\System32\nwiz.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\VGAUtil not found.
File C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Magentic not found.
File C:\Program Files\Magentic\bin\Magentic.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Flag not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\Dvbpws.dll not found.
========== COMMANDS ==========
OTL by OldTimer - Version 3.0.10.7 log created on 09262009_100133
========== OTL ==========
Process explorer.exe killed successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Mirabilis ICQ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz not found.
File C:\WINDOWS\System32\nwiz.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\VGAUtil not found.
File C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Magentic not found.
File C:\Program Files\Magentic\bin\Magentic.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Flag not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\Dvbpws.dll not found.
========== COMMANDS ==========
OTL by OldTimer - Version 3.0.10.7 log created on 09262009_100133
Re: Log z RSIT nejde vytvorit, PC je pomale
Jak to ted vypadá s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Log z RSIT nejde vytvorit, PC je pomale
slape rychleji, ale stale dost dlouho vypinani, tzn. nez naskoci okno s moznosti vypnout...
Re: Log z RSIT nejde vytvorit, PC je pomale

Stáhněte z mého podpisu program StartUpLite
vypíše seznam zbytečně spouštěných programů po startu, vyberete které chcete zastavit,u nich zaškrtnete Disable a klikněte na Continue


-nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner
záložka Registry
-klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy

-kliknete opravit všechny problémy


Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.

TFC (http://oldtimer.geekstogo.com/TFC.exe)

start-spustit - napište cleanmgr - ok..ok
-dát fajfku temporary ,,,offline,,koš,,,dočasné soubory - ok,
start-spustit - napište cleanmgr - ok..ok
-další možnosti - obnovení systému - vyčistit - ok

-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat

start - ovládací panely - nástroje pro správu - správa počítače - defragmentace disku
-můžete použít i jiný nástroj na defragmentaci, ten ve windows není nic moc
Za sebe můžu doporučit JK defrag, který se neinstaluje
http://www.slunecnice.cz/sw/jkdefrag/


-udělejte sken a sem vložte ten správný kus logu, ze spodního okenka

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Log z RSIT nejde vytvorit, PC je pomale
Tak tady je ten log, jinak vse krome defragmentace delam bezne a udelala jsem i nyni.
Invalid Entry DllName = appmgmts.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}). Action Taken: Deleting Registry Key {c6dc5466-785a-11d2-84d0-00c04fb169f7}.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Spyware.NetScreenWatch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "Windows Police PRO Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "Windows Police PRO Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "Windows Police PRO Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "PersonalAntispy Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Entry "HKCR\DVDWzApp.Application" refers to invalid object "{5432567D-A901-4635-B450-8A6A15C311AA}". Action Taken: No Action Taken.
Entry "HKCR\FILECONTROL.FileControlCtrl.1" refers to invalid object "{221002E4-4DB7-4345-9A33-A285B90E53F0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE.1" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE.1" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE.1" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE.1" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE.1" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE.1" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE.1" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE.1" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE.1" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\IAManager.Manager.1" refers to invalid object "{EE1BBA18-F0C8-477E-8AC8-C28B94F1B7DC}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter.1" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client.1" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper.1" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.SipxPhoneManager.1" refers to invalid object "{54BDE6EC-F42F-4500-AC46-905177444300}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl.1" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow.1" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature.1" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface.1" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents.1" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo.1" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin.1" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper.1" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper.1" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection.1" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager.1" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MServer.TMServer" refers to invalid object "{A8924043-D52C-11D2-B2E9-0000E8CD952D}". Action Taken: No Action Taken.
Entry "HKCR\MXtra.DhtmlWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector.1" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object ""D:\data\cdw32.exe"". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Beauty Pilot_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Farm Mania_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "FastStone Image Viewer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QIP2005". Action Taken: No Action Taken.
File C:\WINDOWS\of3u2a.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.
Invalid Entry DllName = appmgmts.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}). Action Taken: Deleting Registry Key {c6dc5466-785a-11d2-84d0-00c04fb169f7}.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Spyware.NetScreenWatch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "Windows Police PRO Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "Windows Police PRO Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "Windows Police PRO Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "PersonalAntispy Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Entry "HKCR\DVDWzApp.Application" refers to invalid object "{5432567D-A901-4635-B450-8A6A15C311AA}". Action Taken: No Action Taken.
Entry "HKCR\FILECONTROL.FileControlCtrl.1" refers to invalid object "{221002E4-4DB7-4345-9A33-A285B90E53F0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE.1" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE.1" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE.1" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE.1" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE.1" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE.1" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE.1" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE.1" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE.1" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\IAManager.Manager.1" refers to invalid object "{EE1BBA18-F0C8-477E-8AC8-C28B94F1B7DC}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter.1" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client.1" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper.1" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.SipxPhoneManager.1" refers to invalid object "{54BDE6EC-F42F-4500-AC46-905177444300}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl.1" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow.1" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature.1" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface.1" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents.1" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo.1" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin.1" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper.1" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper.1" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection.1" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager.1" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MServer.TMServer" refers to invalid object "{A8924043-D52C-11D2-B2E9-0000E8CD952D}". Action Taken: No Action Taken.
Entry "HKCR\MXtra.DhtmlWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector.1" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object ""D:\data\cdw32.exe"". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Beauty Pilot_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Farm Mania_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "FastStone Image Viewer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QIP2005". Action Taken: No Action Taken.
File C:\WINDOWS\of3u2a.dll infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.
Re: Log z RSIT nejde vytvorit, PC je pomale

C:\WINDOWS\of3u2a.dll

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Log z RSIT nejde vytvorit, PC je pomale
Smazano, vypadalo to s PC lepe, ale kdyz je dele pustene porad se dlouho vypina. Posilam novy log z MWAW.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Spyware.NetScreenWatch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "PersonalAntispy Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Entry "HKCR\DVDWzApp.Application" refers to invalid object "{5432567D-A901-4635-B450-8A6A15C311AA}". Action Taken: No Action Taken.
Entry "HKCR\FILECONTROL.FileControlCtrl.1" refers to invalid object "{221002E4-4DB7-4345-9A33-A285B90E53F0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE.1" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE.1" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE.1" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE.1" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE.1" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE.1" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE.1" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE.1" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE.1" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\IAManager.Manager.1" refers to invalid object "{EE1BBA18-F0C8-477E-8AC8-C28B94F1B7DC}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter.1" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client.1" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper.1" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.SipxPhoneManager.1" refers to invalid object "{54BDE6EC-F42F-4500-AC46-905177444300}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl.1" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow.1" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature.1" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface.1" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents.1" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo.1" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin.1" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper.1" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper.1" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection.1" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager.1" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MServer.TMServer" refers to invalid object "{A8924043-D52C-11D2-B2E9-0000E8CD952D}". Action Taken: No Action Taken.
Entry "HKCR\MXtra.DhtmlWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector.1" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object ""D:\data\cdw32.exe"". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Beauty Pilot_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Farm Mania_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "FastStone Image Viewer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QIP2005". Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Spyware.NetScreenWatch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "MalwareScanner Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Object "PersonalAntispy Corrupted Adware/Spyware" found in File System! Action Taken: No Action Taken.
Entry "HKCR\DVDWzApp.Application" refers to invalid object "{5432567D-A901-4635-B450-8A6A15C311AA}". Action Taken: No Action Taken.
Entry "HKCR\FILECONTROL.FileControlCtrl.1" refers to invalid object "{221002E4-4DB7-4345-9A33-A285B90E53F0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.AnimationControllerGE.1" refers to invalid object "{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ApplicationGE.1" refers to invalid object "{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.CameraInfoGE.1" refers to invalid object "{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureCollectionGE.1" refers to invalid object "{9059C329-4661-49B2-9984-8753C45DB7B9}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.FeatureGE.1" refers to invalid object "{CBD4FB70-F00B-4963-B249-4B056E6A981A}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.PointOnTerrainGE.1" refers to invalid object "{1796A329-04C1-4C07-B28E-E4A807935C06}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.SearchControllerGE.1" refers to invalid object "{A4F65992-5738-475B-9C16-CF102BCDE153}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TimeIntervalGE.1" refers to invalid object "{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.TourControllerGE.1" refers to invalid object "{77C4C807-E257-43AD-BB3F-7CA88760BD29}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\GoogleEarth.ViewExtentsGE.1" refers to invalid object "{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}". Action Taken: No Action Taken.
Entry "HKCR\IAManager.Manager.1" refers to invalid object "{EE1BBA18-F0C8-477E-8AC8-C28B94F1B7DC}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQBasic.LiteDBConverter.1" refers to invalid object "{B29DEB73-0511-4372-95E2-0EB539D929C9}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQLite.Client.1" refers to invalid object "{F0BA1D5B-6311-4B9F-9FE6-E17AB974F4FF}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.MPortsMapper.1" refers to invalid object "{6BC0F888-74CA-41CF-B2B9-310C8B29F977}". Action Taken: No Action Taken.
Entry "HKCR\ICQPhone.SipxPhoneManager.1" refers to invalid object "{54BDE6EC-F42F-4500-AC46-905177444300}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcControl.ICQRtcControl.1" refers to invalid object "{76BACFF2-D763-4af0-ABD3-E8C2BBE9BAEC}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\ICQRtcWindow.MCRtcWindow.1" refers to invalid object "{6D7A43A3-0766-4c36-96F5-A38A88051EEB}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHFeature.1" refers to invalid object "{B153D707-447A-4538-913E-6146B3FDEE02}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHInterface.1" refers to invalid object "{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewExtents.1" refers to invalid object "{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Keyhole.KHViewInfo.1" refers to invalid object "{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.ActiveXPlugin.1" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.DhtmlPluginWrapper.1" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.FlashPluginWrapper.1" refers to invalid object "{60889EB6-622F-4CAC-A370-4511DC48A7CD}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.KeyValueCollection.1" refers to invalid object "{FAC0ABDB-622D-4BC9-9830-C8D36C277CC2}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MISB.PluginManager.1" refers to invalid object "{481CBFEB-860E-438F-BF1E-9E30D89949E8}". Action Taken: No Action Taken.
Entry "HKCR\MServer.TMServer" refers to invalid object "{A8924043-D52C-11D2-B2E9-0000E8CD952D}". Action Taken: No Action Taken.
Entry "HKCR\MXtra.DhtmlWrapper" refers to invalid object "{8D18DFF4-0943-4347-8BCA-0C57033F6820}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCR\protector_dll.Protector.1" refers to invalid object "{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}". Action Taken: No Action Taken.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object ""D:\data\cdw32.exe"". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Beauty Pilot_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Farm Mania_is1". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "FastStone Image Viewer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QIP2005". Action Taken: No Action Taken.
Re: Log z RSIT nejde vytvorit, PC je pomale
Co našel mwaw, jsou jen zbytky po infekci a neplatné klíče v registrech, je to neškodné
.
Je možné, pokud máte po delším používání pc spuštěno hodně procesů, že se pomaleji pc ukončuje.

Je možné, pokud máte po delším používání pc spuštěno hodně procesů, že se pomaleji pc ukončuje.
Pro rychlejší vypnutí pc vyzkoušejte tohle:
Start -> Spustit ->do okénka napište
regedit
-vyhledejte
HKEY_LOCAL_MACHINE -> System -> CurrentControlSet -> Control
- Klikněte na složku "Control" a na pravé straně okna vyhledejte "WaitToKillServiceTimeout"
- 2x klikněte a změňte na 1000 (default je 20000)
Start -> Spustit ->do okénka napište
regedit
- Vyhledejte
HKEY_CURRENT_USER -> Control Panel -> Desktop
- Klik na složku "Desktop" a na pravé straně vyhledejte "WaitToKillAppTimeout" a "HungAppTimeout"
- 2x klikněte na obě položky a zmeňte jejich hodnoty na 1000 (default 20000)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Log z RSIT nejde vytvorit, PC je pomale
OK, provedeno. Dam jeste vedet.
Diky moc a peknou nedeli
Diky moc a peknou nedeli
Re: Log z RSIT nejde vytvorit, PC je pomale
Pak dejte vědět, zda to pomohlo.
Není zač, vám také hezkou neděli i pondělí
.
Není zač, vám také hezkou neděli i pondělí

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Log z RSIT nejde vytvorit, PC je pomale
Chtela jsem se zeptat na tu defragmentaci? Neni nebezpecna? Nespadnou mi okna? Slysela jsem o tom spoustu bludu, tak nevim...
Re: Log z RSIT nejde vytvorit, PC je pomale
Já defragmentuji každý měsíc a zatím se nic nestalo
.
Stát s pc se Vám může kdykoliv cokoliv
. Důležité data by měly být vždy zálohovány. Defragmentace se nebojte.

Stát s pc se Vám může kdykoliv cokoliv

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Log z RSIT nejde vytvorit, PC je pomale
Doplnim kolegyni.
Svych 700GB na sedmi logickych jednotkach defragmentuji kazdy den - pouzivam System Mechanic 5 - cca 3-5 min...
Svych 700GB na sedmi logickych jednotkach defragmentuji kazdy den - pouzivam System Mechanic 5 - cca 3-5 min...
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
Re: Log z RSIT nejde vytvorit, PC je pomale
Ok, diky. Jeste pred tou defragmentaci posilam pro kontrolu log z Hijacku (RSIT mi stale nejde).
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:30:14, on 21.12.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\MSI\MSI2\BlueSoleil.exe
C:\tiskárna\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\MSI\MSI2\BTNtService.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\odvirovani\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/skins/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [Zástupce stránky vlastností sběrnice High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1858025970-79857088-3581336864-1007\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = C:\MSI\MSI2\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Kilerka\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Kilerka\ICQ6.5\ICQ.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0007622B-D286-4534-80EA-14782CA6EF5C}: NameServer = 213.195.215.200,81.30.224.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{003EFDD8-7CD0-4203-9971-CB426C826324}: NameServer = 213.195.215.200,81.30.224.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{91CE46DB-6DB5-4E2A-9F31-0952CB2F0F7C}: NameServer = 213.195.215.200,81.30.244.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\MSI\MSI2\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://www.uschovna.cz/images/save.gif
--
End of file - 8331 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:30:14, on 21.12.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\MSI\MSI2\BlueSoleil.exe
C:\tiskárna\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\MSI\MSI2\BTNtService.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\odvirovani\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/skins/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [Zástupce stránky vlastností sběrnice High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 4.0 Suite\Ulead Quick-Drop 1.0\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1858025970-79857088-3581336864-1007\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = C:\MSI\MSI2\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Kilerka\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Kilerka\ICQ6.5\ICQ.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0007622B-D286-4534-80EA-14782CA6EF5C}: NameServer = 213.195.215.200,81.30.224.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{003EFDD8-7CD0-4203-9971-CB426C826324}: NameServer = 213.195.215.200,81.30.224.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{91CE46DB-6DB5-4E2A-9F31-0952CB2F0F7C}: NameServer = 213.195.215.200,81.30.244.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\MSI\MSI2\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://www.uschovna.cz/images/save.gif
--
End of file - 8331 bytes
Re: Log z RSIT nejde vytvorit, PC je pomale
A jeste dotaz, kde sezenu System Mechanic 5? na stahuj jsem nasla System Mechanic 8.0.1.5 Professional, je to taky ok? Na hadru mam cca 38GB volnych a 111GB plnych, staci to volne misto pro defragmentaci?(nekde jsem slysela, ze kdyz je malo mista, padaji okna:)