
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu
Prosím o preventivní kontrolu.Něco mi prý snižuje rychlost netu.Všem moc děkuji
Logfile of random's system information tool 1.08 (written by random/random)
Run by Roman at 2010-07-26 15:51:39
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 360 GB (77%) free of 470 GB
Total RAM: 3070 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:51:45, on 26.7.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Users\Roman\Documents\RSIT.exe
C:\Program Files\trend micro\Roman.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15383&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-277950604-832228221-2599045981-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Míša')
O4 - HKUS\S-1-5-21-277950604-832228221-2599045981-1001\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent (User 'Míša')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD RAIDXpert (AMD_RAIDXpert) - AMD - C:\Program Files\AMD\RAIDXpert\bin\RAIDXpertService.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Broadcom Management Agent (BrcmMgmtAgent) - Broadcom Corporation - C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
--
End of file - 8967 bytes
======Scheduled tasks folder======
C:\Windows\tasks\At1.job
C:\Windows\tasks\AWC Update.job
C:\Windows\tasks\GlaryInitialize.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-21 1619296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2010-04-19 2117704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2010-04-19 2117704]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-06-12 958712]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} -
{D4027C7F-154A-4066-A1AD-4243D8127440} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-03 7596576]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-06-18 563736]
"SetRefresh"=C:\Program Files\HP\SetRefresh\SetRefresh.exe [2003-11-21 525824]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-06-22 2065760]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoSecCpl"=0
"DisableChangePassword"=0
"DisableLockWorkstation"=0
"NoDispCpl"=0
"NoDispScrSavPage"=0
"NoDispAppearancePage"=0
"NoDispSettingsPage"=0
"NoVisualStyleChoice"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDesktop"=0
"NoActiveDesktop"=0
"HideClock"=0
"NoDriveTypeAutoRun"=0
"NoStartMenuPinnedList"=0
"NoStartMenuMFUprogramsList"=0
"NoUserNameInStartMenu"=0
"StartmenuLogoff"=0
"NoStartMenuSubFolders"=0
"NoCommonGroups"=0
"NoPrinterTabs"=0
"NoDeletePrinter"=0
"NoAddPrinter"=0
"NoPrinters"=0
"NoFavoritesMenu"=0
"NoRun"=0
"NoFind"=0
"NoClose"=0
"NoSetFolders"=0
"NoViewContextMenu"=0
"NoDrives"=0
"NoToolbarCustomize"=0
"NoRecentDocsNetHood"=0
"NoChangeAnimation"=0
"NoChangeKeyboardNavigationIndicators"=0
"NoThemesTab"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-07-26 15:51:39 ----D---- C:\rsit
2010-07-26 15:46:05 ----D---- C:\Program Files\trend micro
2010-07-25 00:04:50 ----D---- C:\Windows\Farm Frenzy 3
2010-07-25 00:04:50 ----D---- C:\Program Files\Farm Frenzy 3
2010-07-20 21:06:23 ----D---- C:\Program Files\LeeGTs Games
2010-07-20 18:41:19 ----D---- C:\ProgramData\Adobe
2010-07-20 07:59:42 ----A---- C:\Windows\system32\winhttp.dll
2010-07-20 07:59:36 ----A---- C:\Windows\system32\nshhttp.dll
2010-07-20 07:59:36 ----A---- C:\Windows\system32\httpapi.dll
2010-07-20 07:59:36 ----A---- C:\Windows\system32\drivers\http.sys
2010-07-19 22:25:05 ----A---- C:\Windows\system32\schannel.dll
2010-07-19 22:25:05 ----A---- C:\Windows\system32\kerberos.dll
2010-07-19 11:00:30 ----D---- C:\Users\Roman\AppData\Roaming\iWin
2010-07-19 08:39:40 ----D---- C:\Program Files\WinPcap
2010-07-09 17:24:50 ----A---- C:\Windows\Farm Frenzy 3 Uninstall Log.txt
2010-07-09 17:00:44 ----D---- C:\ProgramData\FarmFrenzy3
2010-07-09 17:00:31 ----D---- C:\ProgramData\AlawarWrapper
2010-07-09 16:59:06 ----A---- C:\Windows\Farm Frenzy 3 Setup Log.txt
2010-07-05 18:27:23 ----D---- C:\ProgramData\VirtualFarm
2010-07-02 16:27:15 ----D---- C:\ProgramData\{4BC12378-A8EB-4DBE-AFD8-B5A9D2CDFEC7}
2010-06-30 18:46:37 ----D---- C:\Program Files\ReflexiveArcade
2010-06-30 17:59:21 ----D---- C:\ProgramData\Trymedia
======List of files/folders modified in the last 1 months======
2010-07-26 15:51:41 ----D---- C:\Windows\Temp
2010-07-26 15:51:05 ----D---- C:\Windows\Prefetch
2010-07-26 15:46:05 ----RD---- C:\Program Files
2010-07-26 14:35:41 ----HD---- C:\ProgramData
2010-07-26 14:31:13 ----D---- C:\Users\Roman\AppData\Roaming\uTorrent
2010-07-26 11:27:54 ----D---- C:\Windows\system32\drivers\Avg
2010-07-26 09:10:44 ----D---- C:\Users\Roman\AppData\Roaming\Vso
2010-07-26 08:38:55 ----D---- C:\Windows\System32
2010-07-26 08:38:55 ----D---- C:\Windows\inf
2010-07-26 08:38:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-26 08:35:40 ----A---- C:\Windows\system32\NapaSet.txt
2010-07-25 10:01:15 ----D---- C:\Windows\Tasks
2010-07-25 10:00:00 ----D---- C:\Program Files\Mozilla Firefox
2010-07-25 09:51:22 ----SHD---- C:\System Volume Information
2010-07-25 00:04:50 ----D---- C:\windows
2010-07-24 08:20:04 ----D---- C:\Windows\system32\catroot2
2010-07-24 00:07:32 ----D---- C:\ProgramData\PDFC
2010-07-22 09:17:38 ----AD---- C:\ProgramData\TEMP
2010-07-20 21:06:37 ----SHD---- C:\Windows\Installer
2010-07-20 19:04:05 ----D---- C:\Program Files\Common Files
2010-07-20 18:43:10 ----D---- C:\Users\Roman\AppData\Roaming\Adobe
2010-07-20 08:50:02 ----D---- C:\Windows\rescache
2010-07-20 08:33:14 ----D---- C:\Windows\system32\drivers\cs-CZ
2010-07-20 08:33:14 ----D---- C:\Windows\system32\drivers
2010-07-20 08:33:14 ----D---- C:\Windows\system32\cs-CZ
2010-07-20 08:26:43 ----D---- C:\Windows\winsxs
2010-07-20 07:59:28 ----D---- C:\Windows\system32\catroot
2010-07-19 01:07:44 ----D---- C:\Program Files\DVDFab 7
2010-07-18 17:25:41 ----D---- C:\Windows\system32\Tasks
2010-07-17 18:42:31 ----D---- C:\Program Files\uTorrent
2010-07-14 21:24:23 ----D---- C:\Program Files\Windows Mail
2010-07-07 19:38:14 ----D---- C:\Users\Roman\AppData\Roaming\LangSoft
2010-07-07 19:38:13 ----D---- C:\ProgramData\LangSoft
2010-07-07 19:38:13 ----A---- C:\Windows\TRNCOM.INI
2010-07-06 09:04:42 ----D---- C:\Users\Roman\AppData\Roaming\Godlike
2010-07-04 17:28:06 ----D---- C:\Program Files\Glary Utilities
2010-07-02 21:39:05 ----A---- C:\Windows\system32\mrt.exe
2010-07-02 16:29:11 ----D---- C:\Program Files\Hewlett-Packard
2010-07-02 16:29:04 ----D---- C:\Windows\Help
2010-07-02 16:28:35 ----D---- C:\Program Files\HP
2010-07-02 16:26:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-02 16:17:06 ----D---- C:\ProgramData\Hewlett-Packard
2010-06-29 19:07:19 ----D---- C:\Windows\Panther
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ahcix86s;ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [2009-08-31 185400]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 14392]
R0 AVGIDSErHrvtx;AVG9IDSErHr; C:\Windows\System32\Drivers\AVGIDSvx.sys [2010-06-22 25168]
R0 AvgRkx86;avgrkx86.sys; C:\Windows\System32\Drivers\avgrkx86.sys [2010-03-14 52872]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-04-15 691696]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-03-14 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-06-22 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-06-01 29584]
R1 AvgTdiX;AVG Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-06-22 243024]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2009-11-16 50704]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-18 11032]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-30 34304]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-02 4994048]
R3 AVGIDSDrivervtx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-06-22 122448]
R3 AVGIDSFiltervtx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-06-22 30288]
R3 AVGIDSShimvtx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-06-22 27216]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-05-31 260648]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-03 2656160]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-03-14 47360]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2008-01-21 45624]
S3 aq5j45dw;aq5j45dw; C:\Windows\system32\drivers\aq5j45dw.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-11-05 507904]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-11-05 30208]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-07-02 176128]
R2 AMD_RAIDXpert;AMD RAIDXpert; C:\Program Files\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-03-16 122880]
R2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2010-06-22 2331032]
R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-06-22 5897808]
R2 BrcmMgmtAgent;Broadcom Management Agent; C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2009-07-11 110592]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-02-22 73728]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-05-01 229944]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Roman at 2010-07-26 15:51:39
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 360 GB (77%) free of 470 GB
Total RAM: 3070 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:51:45, on 26.7.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Users\Roman\Documents\RSIT.exe
C:\Program Files\trend micro\Roman.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15383&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\HP\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-277950604-832228221-2599045981-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Míša')
O4 - HKUS\S-1-5-21-277950604-832228221-2599045981-1001\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent (User 'Míša')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD RAIDXpert (AMD_RAIDXpert) - AMD - C:\Program Files\AMD\RAIDXpert\bin\RAIDXpertService.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Broadcom Management Agent (BrcmMgmtAgent) - Broadcom Corporation - C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
--
End of file - 8967 bytes
======Scheduled tasks folder======
C:\Windows\tasks\At1.job
C:\Windows\tasks\AWC Update.job
C:\Windows\tasks\GlaryInitialize.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-21 1619296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2010-04-19 2117704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2010-04-19 2117704]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-06-12 958712]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} -
{D4027C7F-154A-4066-A1AD-4243D8127440} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-03 7596576]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-06-18 563736]
"SetRefresh"=C:\Program Files\HP\SetRefresh\SetRefresh.exe [2003-11-21 525824]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-06-22 2065760]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoSecCpl"=0
"DisableChangePassword"=0
"DisableLockWorkstation"=0
"NoDispCpl"=0
"NoDispScrSavPage"=0
"NoDispAppearancePage"=0
"NoDispSettingsPage"=0
"NoVisualStyleChoice"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDesktop"=0
"NoActiveDesktop"=0
"HideClock"=0
"NoDriveTypeAutoRun"=0
"NoStartMenuPinnedList"=0
"NoStartMenuMFUprogramsList"=0
"NoUserNameInStartMenu"=0
"StartmenuLogoff"=0
"NoStartMenuSubFolders"=0
"NoCommonGroups"=0
"NoPrinterTabs"=0
"NoDeletePrinter"=0
"NoAddPrinter"=0
"NoPrinters"=0
"NoFavoritesMenu"=0
"NoRun"=0
"NoFind"=0
"NoClose"=0
"NoSetFolders"=0
"NoViewContextMenu"=0
"NoDrives"=0
"NoToolbarCustomize"=0
"NoRecentDocsNetHood"=0
"NoChangeAnimation"=0
"NoChangeKeyboardNavigationIndicators"=0
"NoThemesTab"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-07-26 15:51:39 ----D---- C:\rsit
2010-07-26 15:46:05 ----D---- C:\Program Files\trend micro
2010-07-25 00:04:50 ----D---- C:\Windows\Farm Frenzy 3
2010-07-25 00:04:50 ----D---- C:\Program Files\Farm Frenzy 3
2010-07-20 21:06:23 ----D---- C:\Program Files\LeeGTs Games
2010-07-20 18:41:19 ----D---- C:\ProgramData\Adobe
2010-07-20 07:59:42 ----A---- C:\Windows\system32\winhttp.dll
2010-07-20 07:59:36 ----A---- C:\Windows\system32\nshhttp.dll
2010-07-20 07:59:36 ----A---- C:\Windows\system32\httpapi.dll
2010-07-20 07:59:36 ----A---- C:\Windows\system32\drivers\http.sys
2010-07-19 22:25:05 ----A---- C:\Windows\system32\schannel.dll
2010-07-19 22:25:05 ----A---- C:\Windows\system32\kerberos.dll
2010-07-19 11:00:30 ----D---- C:\Users\Roman\AppData\Roaming\iWin
2010-07-19 08:39:40 ----D---- C:\Program Files\WinPcap
2010-07-09 17:24:50 ----A---- C:\Windows\Farm Frenzy 3 Uninstall Log.txt
2010-07-09 17:00:44 ----D---- C:\ProgramData\FarmFrenzy3
2010-07-09 17:00:31 ----D---- C:\ProgramData\AlawarWrapper
2010-07-09 16:59:06 ----A---- C:\Windows\Farm Frenzy 3 Setup Log.txt
2010-07-05 18:27:23 ----D---- C:\ProgramData\VirtualFarm
2010-07-02 16:27:15 ----D---- C:\ProgramData\{4BC12378-A8EB-4DBE-AFD8-B5A9D2CDFEC7}
2010-06-30 18:46:37 ----D---- C:\Program Files\ReflexiveArcade
2010-06-30 17:59:21 ----D---- C:\ProgramData\Trymedia
======List of files/folders modified in the last 1 months======
2010-07-26 15:51:41 ----D---- C:\Windows\Temp
2010-07-26 15:51:05 ----D---- C:\Windows\Prefetch
2010-07-26 15:46:05 ----RD---- C:\Program Files
2010-07-26 14:35:41 ----HD---- C:\ProgramData
2010-07-26 14:31:13 ----D---- C:\Users\Roman\AppData\Roaming\uTorrent
2010-07-26 11:27:54 ----D---- C:\Windows\system32\drivers\Avg
2010-07-26 09:10:44 ----D---- C:\Users\Roman\AppData\Roaming\Vso
2010-07-26 08:38:55 ----D---- C:\Windows\System32
2010-07-26 08:38:55 ----D---- C:\Windows\inf
2010-07-26 08:38:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-26 08:35:40 ----A---- C:\Windows\system32\NapaSet.txt
2010-07-25 10:01:15 ----D---- C:\Windows\Tasks
2010-07-25 10:00:00 ----D---- C:\Program Files\Mozilla Firefox
2010-07-25 09:51:22 ----SHD---- C:\System Volume Information
2010-07-25 00:04:50 ----D---- C:\windows
2010-07-24 08:20:04 ----D---- C:\Windows\system32\catroot2
2010-07-24 00:07:32 ----D---- C:\ProgramData\PDFC
2010-07-22 09:17:38 ----AD---- C:\ProgramData\TEMP
2010-07-20 21:06:37 ----SHD---- C:\Windows\Installer
2010-07-20 19:04:05 ----D---- C:\Program Files\Common Files
2010-07-20 18:43:10 ----D---- C:\Users\Roman\AppData\Roaming\Adobe
2010-07-20 08:50:02 ----D---- C:\Windows\rescache
2010-07-20 08:33:14 ----D---- C:\Windows\system32\drivers\cs-CZ
2010-07-20 08:33:14 ----D---- C:\Windows\system32\drivers
2010-07-20 08:33:14 ----D---- C:\Windows\system32\cs-CZ
2010-07-20 08:26:43 ----D---- C:\Windows\winsxs
2010-07-20 07:59:28 ----D---- C:\Windows\system32\catroot
2010-07-19 01:07:44 ----D---- C:\Program Files\DVDFab 7
2010-07-18 17:25:41 ----D---- C:\Windows\system32\Tasks
2010-07-17 18:42:31 ----D---- C:\Program Files\uTorrent
2010-07-14 21:24:23 ----D---- C:\Program Files\Windows Mail
2010-07-07 19:38:14 ----D---- C:\Users\Roman\AppData\Roaming\LangSoft
2010-07-07 19:38:13 ----D---- C:\ProgramData\LangSoft
2010-07-07 19:38:13 ----A---- C:\Windows\TRNCOM.INI
2010-07-06 09:04:42 ----D---- C:\Users\Roman\AppData\Roaming\Godlike
2010-07-04 17:28:06 ----D---- C:\Program Files\Glary Utilities
2010-07-02 21:39:05 ----A---- C:\Windows\system32\mrt.exe
2010-07-02 16:29:11 ----D---- C:\Program Files\Hewlett-Packard
2010-07-02 16:29:04 ----D---- C:\Windows\Help
2010-07-02 16:28:35 ----D---- C:\Program Files\HP
2010-07-02 16:26:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-02 16:17:06 ----D---- C:\ProgramData\Hewlett-Packard
2010-06-29 19:07:19 ----D---- C:\Windows\Panther
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ahcix86s;ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [2009-08-31 185400]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 14392]
R0 AVGIDSErHrvtx;AVG9IDSErHr; C:\Windows\System32\Drivers\AVGIDSvx.sys [2010-06-22 25168]
R0 AvgRkx86;avgrkx86.sys; C:\Windows\System32\Drivers\avgrkx86.sys [2010-03-14 52872]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-04-15 691696]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-03-14 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-06-22 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-06-01 29584]
R1 AvgTdiX;AVG Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-06-22 243024]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2009-11-16 50704]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-18 11032]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-30 34304]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-02 4994048]
R3 AVGIDSDrivervtx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-06-22 122448]
R3 AVGIDSFiltervtx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-06-22 30288]
R3 AVGIDSShimvtx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-06-22 27216]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-05-31 260648]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-03 2656160]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-03-14 47360]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2008-01-21 45624]
S3 aq5j45dw;aq5j45dw; C:\Windows\system32\drivers\aq5j45dw.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-11-05 507904]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-11-05 30208]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-07-02 176128]
R2 AMD_RAIDXpert;AMD RAIDXpert; C:\Program Files\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-03-16 122880]
R2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2010-06-22 2331032]
R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-06-22 5897808]
R2 BrcmMgmtAgent;Broadcom Management Agent; C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2009-07-11 110592]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-02-22 73728]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-05-01 229944]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
Re: Prosím o kontrolu
Zdravim a pekny podvecer preji
Jak jste myslel to "pry snizuje"
Vy nic nepocitujete, nebo kde jste prisel na to ze je net pomaly
Doporucuji odinstalovat (pokud nepouzivate) toolbary (listy prohlizecu) v Přidat nebo odebrat programy. AVG Toolbar a hlavne ICQToolbar jsou uzasne zpomalovadla
Spustte HJT a provedeme fixnuti polozek
Stahnete OTM (viz muj podpis)






- HJT najdete zde C:\Program Files\trend micro\Roman.exe
- Otevre se Vam okno, kliknete na Do a system scan only
- V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15383&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)- Kliknete na Fix checked (vlevo dole)
- HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo

- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:files C:\WINDOWS\system32\*.tmp.dll /s C:\WINDOWS\system32\SET*.tmp /s C:\WINDOWS\*.tmp /s C:\Windows\tasks\At*.job :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH] [CLEARALLRESTOREPOINTS]
- Kliknete na cervene tlacitko MoveIt!
- Sem pote dejte obsah okna Results (pod zelenou carou)
- Pokud budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles
Re: Prosím o kontrolu
Měl jsem tady maníka kvůli rychlosti internetu.V lince je rychlost normální ale v kompu poloviční.Tak my bylo řečeno že je v PC nějaká havěť která bere půj rychlosti připojení.
All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2AE7.tmp moved successfully.
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\csp492C.tmp scheduled to be moved on reboot.
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\cspE2E5.tmp scheduled to be moved on reboot.
File/Folder C:\Windows\tasks\At*.job not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
User: Míša
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: Radka
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Roman
->Temp folder emptied: 32233 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 18458641 bytes
->Flash cache emptied: 456 bytes
User: Veronika
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 116840 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes
RecycleBin emptied: 574976 bytes
Total Files Cleaned = 18,00 mb
Restore point Set: OTM Restore Point
OTM by OldTimer - Version 3.1.15.0 log created on 07262010_182647
Files moved on Reboot...
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\csp492C.tmp scheduled to be moved on reboot.
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\cspE2E5.tmp scheduled to be moved on reboot.
C:\Windows\temp\hsperfdata_ROMAN-PC$\2672 moved successfully.
Registry entries deleted on Reboot...
All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\Temp\RAC2AE7.tmp moved successfully.
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\csp492C.tmp scheduled to be moved on reboot.
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\cspE2E5.tmp scheduled to be moved on reboot.
File/Folder C:\Windows\tasks\At*.job not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
User: Míša
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
User: Radka
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Roman
->Temp folder emptied: 32233 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 18458641 bytes
->Flash cache emptied: 456 bytes
User: Veronika
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 116840 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes
RecycleBin emptied: 574976 bytes
Total Files Cleaned = 18,00 mb
Restore point Set: OTM Restore Point
OTM by OldTimer - Version 3.1.15.0 log created on 07262010_182647
Files moved on Reboot...
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\csp492C.tmp scheduled to be moved on reboot.
File move failed. C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\cspE2E5.tmp scheduled to be moved on reboot.
C:\Windows\temp\hsperfdata_ROMAN-PC$\2672 moved successfully.
Registry entries deleted on Reboot...
Re: Prosím o kontrolu


- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy

Re: Prosím o kontrolu
Vše provedeno ale rychlost připojení stále poloviční 

Re: Prosím o kontrolu
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
Re: Prosím o kontrolu
Ať dělám co dělám něco málo proběhne a žádný log a už vůbec ne cituji "Ihned po startu se zobrazi stranka s licencnim ujednanim"to se taky neukáže.Tak nevím co dělám špatně 

Re: Prosím o kontrolu
Spoustite CF jako spravce
Co si mam predstavit pod tim "neco malo probehne"
Obrazovka s licencnim ujednanim vypada takto

Podivejte se na disk C jestli tam nemate C:\ComboFix.txt

Co si mam predstavit pod tim "neco malo probehne"

Obrazovka s licencnim ujednanim vypada takto

Podivejte se na disk C jestli tam nemate C:\ComboFix.txt
Re: Prosím o kontrolu
Pripadne zkuste ComboFix v nouzovem rezimu...
Re: Prosím o kontrolu
už se povedlo
ComboFix 10-07-24.06 - Roman 26.07.2010 21:31:09.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.3070.2149 [GMT 2:00]
Spuštěný z: c:\users\Roman\Documents\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Roman\AppData\Roaming\inst.exe
c:\windows\system32\system
c:\windows\system32\vbzlib1.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-26 do 2010-07-26 )))))))))))))))))))))))))))))))
.
2010-07-26 19:36 . 2010-07-26 19:36 -------- d-----w- c:\users\Roman\AppData\Local\temp
2010-07-26 18:00 . 2010-07-26 18:13 -------- d-----w- C:\$RECYCLE(137).BIN
2010-07-26 17:59 . 2010-07-26 19:05 -------- d-----w- c:\users\Roman\AppData\Local\Temp(229)
2010-07-26 16:38 . 2010-07-26 17:06 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent(241)
2010-07-26 16:38 . 2010-07-26 16:38 -------- d-----w- c:\program files\uTorrent(174)
2010-07-26 14:16 . 2010-07-26 14:16 -------- d-----w- c:\users\Roman\AppData\Roaming\SUPERAntiSpyware.com
2010-07-26 13:46 . 2010-07-26 13:51 -------- d-----w- c:\program files\trend micro
2010-07-24 22:04 . 2010-07-26 15:08 -------- d-----w- c:\program files\Farm Frenzy 3
2010-07-22 11:12 . 2010-07-22 11:12 697965 ----a-w- c:\users\Roman\AppData\Roaming\uTorrent\unins000.exe
2010-07-22 11:12 . 2009-11-30 18:00 289584 ----a-w- c:\users\Roman\AppData\Roaming\uTorrent\utorrent.exe
2010-07-22 11:12 . 2009-09-12 20:20 245248 ----a-w- c:\users\Roman\AppData\Roaming\uTorrent\half-open-fix.exe
2010-07-21 07:38 . 2010-07-21 07:38 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 07:37 . 2010-07-21 07:37 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 07:37 . 2010-07-21 07:37 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-21 07:37 . 2010-07-21 07:37 921440 ----a-w- c:\programdata\avg9\update\backup\avgemc.exe
2010-07-21 07:37 . 2010-07-21 07:37 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-21 05:08 . 2010-07-21 05:08 0 ----a-w- c:\windows\ativpsrm.bin
2010-07-20 19:06 . 2010-07-20 19:06 -------- d-----w- c:\program files\LeeGTs Games
2010-07-20 16:43 . 2010-07-20 17:04 -------- d-----w- c:\users\Roman\AppData\Local\Adobe
2010-07-20 05:59 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-07-20 05:59 . 2009-11-03 21:43 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-07-20 05:59 . 2009-11-03 21:42 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-07-20 05:59 . 2009-11-03 19:41 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-07-19 20:25 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-07-19 20:25 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-07-19 09:00 . 2010-07-20 19:06 -------- d-----w- c:\users\Roman\AppData\Roaming\iWin
2010-07-19 06:39 . 2010-07-19 06:39 -------- d-----w- c:\program files\WinPcap
2010-07-09 15:00 . 2010-07-09 15:06 -------- d-----w- c:\programdata\FarmFrenzy3
2010-07-09 15:00 . 2010-07-26 07:10 -------- d-----w- c:\programdata\AlawarWrapper
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\users\Radka\AppData\Roaming\GlarySoft
2010-07-07 19:16 . 2010-07-07 19:16 -------- d-----w- c:\users\Radka\AppData\Roaming\IObit
2010-07-07 19:14 . 2010-07-07 19:14 -------- d-----w- c:\users\Radka\AppData\Roaming\Godlike
2010-07-05 16:27 . 2010-07-05 16:33 -------- d-----w- c:\programdata\VirtualFarm
2010-07-02 14:27 . 2010-07-02 14:27 -------- d-----w- c:\programdata\{4BC12378-A8EB-4DBE-AFD8-B5A9D2CDFEC7}
2010-07-02 14:16 . 2010-06-18 15:33 1230392 ----a-w- c:\programdata\Hewlett-Packard\HPSAUpgrade\HpSAUpgrade.exe
2010-06-30 16:46 . 2010-06-30 16:46 -------- d-----w- c:\program files\ReflexiveArcade
2010-06-30 15:59 . 2010-06-30 15:59 -------- d-----w- c:\programdata\Trymedia
2010-06-29 07:19 . 2010-06-29 07:19 1039712 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-26 19:33 . 2009-11-05 07:10 598594 ----a-w- c:\windows\system32\perfh005.dat
2010-07-26 19:33 . 2009-11-05 07:10 114786 ----a-w- c:\windows\system32\perfc005.dat
2010-07-26 19:24 . 2010-04-13 07:32 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-26 19:20 . 2010-03-13 23:10 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent
2010-07-26 19:16 . 2009-11-05 06:56 -------- d-----w- c:\programdata\PDFC
2010-07-26 19:13 . 2010-03-13 23:10 -------- d-----w- c:\program files\uTorrent
2010-07-26 19:13 . 2010-03-14 17:31 -------- d-----w- c:\program files\Glary Utilities
2010-07-26 16:24 . 2010-03-14 16:11 0 ----a-w- c:\users\Roman\AppData\Local\prvlcl.dat
2010-07-26 07:10 . 2010-03-14 00:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Vso
2010-07-24 15:01 . 2010-03-21 09:12 680 ----a-w- c:\users\Roman\AppData\Local\d3d9caps.dat
2010-07-23 16:16 . 2010-03-14 07:34 -------- d-----w- c:\users\Radka\AppData\Roaming\ICQ
2010-07-18 23:07 . 2010-04-22 14:30 -------- d-----w- c:\program files\DVDFab 7
2010-07-14 19:24 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-07 19:15 . 2010-03-14 07:33 102056 ----a-w- c:\users\Radka\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\users\Roman\AppData\Roaming\LangSoft
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\programdata\LangSoft
2010-07-07 17:33 . 2010-03-28 14:05 356352 ----a-w- c:\programdata\LangSoft\TrnOutl.dll
2010-07-07 17:33 . 2010-03-28 14:05 299008 ----a-w- c:\programdata\LangSoft\TrnWord.dll
2010-07-06 07:04 . 2010-03-14 08:42 -------- d-----w- c:\users\Roman\AppData\Roaming\Godlike
2010-07-02 14:29 . 2009-11-05 06:52 -------- d-----w- c:\program files\Hewlett-Packard
2010-07-02 14:28 . 2009-11-05 06:56 -------- d-----w- c:\program files\HP
2010-07-02 14:26 . 2009-11-05 06:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-02 14:17 . 2009-11-05 06:54 -------- d-----w- c:\programdata\Hewlett-Packard
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\programdata\cerasus.media
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\users\Roman\AppData\Roaming\cerasus.media
2010-06-22 06:09 . 2010-03-13 22:33 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 06:09 . 2010-06-22 06:09 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 06:09 . 2010-03-13 22:33 25168 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-06-22 06:09 . 2010-03-13 22:34 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-21 07:38 . 2010-06-21 07:38 -------- d-----w- c:\users\Veronika\AppData\Roaming\Ahead
2010-06-21 07:37 . 2010-06-21 07:37 -------- d-----w- c:\users\Veronika\AppData\Roaming\DivX
2010-06-21 07:06 . 2010-03-16 07:38 102056 ----a-w- c:\users\Veronika\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-20 17:16 . 2010-06-20 10:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Photo DVD Maker
2010-06-20 10:03 . 2010-06-20 10:03 -------- d-----w- c:\programdata\Anvsoft
2010-06-20 07:47 . 2010-03-14 00:03 -------- d-----w- c:\program files\VSO
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\programdata\McAfee
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\users\Roman\AppData\Roaming\Arkadium
2010-06-17 13:02 . 2010-07-02 14:29 34164 ----a-w- c:\windows\Help\OEM\Scripts\scriptLibrary.dat
2010-06-17 04:45 . 2010-05-09 16:00 -------- d-----w- c:\program files\ICQ6.5
2010-06-14 15:40 . 2010-03-14 08:40 -------- d-----w- c:\users\Roman\AppData\Roaming\Ahead
2010-06-11 14:07 . 2010-03-17 14:59 -------- d-----w- c:\program files\Music NFO Builder
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-03 17:08 . 2010-06-03 17:08 -------- d-----w- c:\programdata\Blumentals
2010-06-01 16:47 . 2010-06-01 16:38 -------- d-----w- c:\program files\Image Grabber II
2010-06-01 06:16 . 2010-03-13 22:34 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-30 07:55 . 2010-03-13 22:08 102056 ----a-w- c:\users\Roman\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-29 10:18 . 2010-03-14 08:15 -------- d-----w- c:\program files\DsNET Corp
2010-05-29 07:14 . 2010-05-29 07:14 -------- d-----w- c:\users\Roman\AppData\Roaming\Xi
2010-05-26 17:06 . 2010-06-11 09:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-11 09:13 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-04 19:15 . 2010-06-11 09:14 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37 . 2010-06-11 09:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13 . 2010-06-11 09:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2009-11-05 07:23 . 2009-11-05 07:14 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 08:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-03 7596576]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-21 525824]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e5,08,b7,d7,14,c5,ca,01
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-04-15 691696]
S0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSvx.sys [2010-06-22 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-03-14 52872]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-03-13 24856]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-06-22 216400]
S1 AvgTdiX;AVG Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-22 243024]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 176128]
S2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-03-16 122880]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-06-22 2331032]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2009-07-11 110592]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-06-22 122448]
S3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-06-22 30288]
S3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-06-22 27216]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2009-05-31 260648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-02-22 10:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-07-26 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-04-11 15:33]
2010-07-22 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-04-11 14:18]
2010-07-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-14 09:14]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15383&l=dis
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=cs_CZ&c=93&bd=all&pf=cmdt
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yznhq012.default\
FF - prefs.js: browser.search.selectedEngine - WebHledani
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=42&tp=ab&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-26 21:36
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
Celkový čas: 2010-07-26 21:37:52
ComboFix-quarantined-files.txt 2010-07-26 19:37
Před spuštěním: Volných bajtů: 376 913 305 600
Po spuštění: Volných bajtů: 377 042 108 416
- - End Of File - - 179985574A0518988E5E44CE612D5816
ComboFix 10-07-24.06 - Roman 26.07.2010 21:31:09.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.3070.2149 [GMT 2:00]
Spuštěný z: c:\users\Roman\Documents\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Roman\AppData\Roaming\inst.exe
c:\windows\system32\system
c:\windows\system32\vbzlib1.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-26 do 2010-07-26 )))))))))))))))))))))))))))))))
.
2010-07-26 19:36 . 2010-07-26 19:36 -------- d-----w- c:\users\Roman\AppData\Local\temp
2010-07-26 18:00 . 2010-07-26 18:13 -------- d-----w- C:\$RECYCLE(137).BIN
2010-07-26 17:59 . 2010-07-26 19:05 -------- d-----w- c:\users\Roman\AppData\Local\Temp(229)
2010-07-26 16:38 . 2010-07-26 17:06 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent(241)
2010-07-26 16:38 . 2010-07-26 16:38 -------- d-----w- c:\program files\uTorrent(174)
2010-07-26 14:16 . 2010-07-26 14:16 -------- d-----w- c:\users\Roman\AppData\Roaming\SUPERAntiSpyware.com
2010-07-26 13:46 . 2010-07-26 13:51 -------- d-----w- c:\program files\trend micro
2010-07-24 22:04 . 2010-07-26 15:08 -------- d-----w- c:\program files\Farm Frenzy 3
2010-07-22 11:12 . 2010-07-22 11:12 697965 ----a-w- c:\users\Roman\AppData\Roaming\uTorrent\unins000.exe
2010-07-22 11:12 . 2009-11-30 18:00 289584 ----a-w- c:\users\Roman\AppData\Roaming\uTorrent\utorrent.exe
2010-07-22 11:12 . 2009-09-12 20:20 245248 ----a-w- c:\users\Roman\AppData\Roaming\uTorrent\half-open-fix.exe
2010-07-21 07:38 . 2010-07-21 07:38 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 07:37 . 2010-07-21 07:37 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 07:37 . 2010-07-21 07:37 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-21 07:37 . 2010-07-21 07:37 921440 ----a-w- c:\programdata\avg9\update\backup\avgemc.exe
2010-07-21 07:37 . 2010-07-21 07:37 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-21 05:08 . 2010-07-21 05:08 0 ----a-w- c:\windows\ativpsrm.bin
2010-07-20 19:06 . 2010-07-20 19:06 -------- d-----w- c:\program files\LeeGTs Games
2010-07-20 16:43 . 2010-07-20 17:04 -------- d-----w- c:\users\Roman\AppData\Local\Adobe
2010-07-20 05:59 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-07-20 05:59 . 2009-11-03 21:43 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-07-20 05:59 . 2009-11-03 21:42 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-07-20 05:59 . 2009-11-03 19:41 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-07-19 20:25 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-07-19 20:25 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-07-19 09:00 . 2010-07-20 19:06 -------- d-----w- c:\users\Roman\AppData\Roaming\iWin
2010-07-19 06:39 . 2010-07-19 06:39 -------- d-----w- c:\program files\WinPcap
2010-07-09 15:00 . 2010-07-09 15:06 -------- d-----w- c:\programdata\FarmFrenzy3
2010-07-09 15:00 . 2010-07-26 07:10 -------- d-----w- c:\programdata\AlawarWrapper
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\users\Radka\AppData\Roaming\GlarySoft
2010-07-07 19:16 . 2010-07-07 19:16 -------- d-----w- c:\users\Radka\AppData\Roaming\IObit
2010-07-07 19:14 . 2010-07-07 19:14 -------- d-----w- c:\users\Radka\AppData\Roaming\Godlike
2010-07-05 16:27 . 2010-07-05 16:33 -------- d-----w- c:\programdata\VirtualFarm
2010-07-02 14:27 . 2010-07-02 14:27 -------- d-----w- c:\programdata\{4BC12378-A8EB-4DBE-AFD8-B5A9D2CDFEC7}
2010-07-02 14:16 . 2010-06-18 15:33 1230392 ----a-w- c:\programdata\Hewlett-Packard\HPSAUpgrade\HpSAUpgrade.exe
2010-06-30 16:46 . 2010-06-30 16:46 -------- d-----w- c:\program files\ReflexiveArcade
2010-06-30 15:59 . 2010-06-30 15:59 -------- d-----w- c:\programdata\Trymedia
2010-06-29 07:19 . 2010-06-29 07:19 1039712 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-26 19:33 . 2009-11-05 07:10 598594 ----a-w- c:\windows\system32\perfh005.dat
2010-07-26 19:33 . 2009-11-05 07:10 114786 ----a-w- c:\windows\system32\perfc005.dat
2010-07-26 19:24 . 2010-04-13 07:32 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-26 19:20 . 2010-03-13 23:10 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent
2010-07-26 19:16 . 2009-11-05 06:56 -------- d-----w- c:\programdata\PDFC
2010-07-26 19:13 . 2010-03-13 23:10 -------- d-----w- c:\program files\uTorrent
2010-07-26 19:13 . 2010-03-14 17:31 -------- d-----w- c:\program files\Glary Utilities
2010-07-26 16:24 . 2010-03-14 16:11 0 ----a-w- c:\users\Roman\AppData\Local\prvlcl.dat
2010-07-26 07:10 . 2010-03-14 00:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Vso
2010-07-24 15:01 . 2010-03-21 09:12 680 ----a-w- c:\users\Roman\AppData\Local\d3d9caps.dat
2010-07-23 16:16 . 2010-03-14 07:34 -------- d-----w- c:\users\Radka\AppData\Roaming\ICQ
2010-07-18 23:07 . 2010-04-22 14:30 -------- d-----w- c:\program files\DVDFab 7
2010-07-14 19:24 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-07 19:15 . 2010-03-14 07:33 102056 ----a-w- c:\users\Radka\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\users\Roman\AppData\Roaming\LangSoft
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\programdata\LangSoft
2010-07-07 17:33 . 2010-03-28 14:05 356352 ----a-w- c:\programdata\LangSoft\TrnOutl.dll
2010-07-07 17:33 . 2010-03-28 14:05 299008 ----a-w- c:\programdata\LangSoft\TrnWord.dll
2010-07-06 07:04 . 2010-03-14 08:42 -------- d-----w- c:\users\Roman\AppData\Roaming\Godlike
2010-07-02 14:29 . 2009-11-05 06:52 -------- d-----w- c:\program files\Hewlett-Packard
2010-07-02 14:28 . 2009-11-05 06:56 -------- d-----w- c:\program files\HP
2010-07-02 14:26 . 2009-11-05 06:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-02 14:17 . 2009-11-05 06:54 -------- d-----w- c:\programdata\Hewlett-Packard
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\programdata\cerasus.media
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\users\Roman\AppData\Roaming\cerasus.media
2010-06-22 06:09 . 2010-03-13 22:33 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 06:09 . 2010-06-22 06:09 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 06:09 . 2010-03-13 22:33 25168 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-06-22 06:09 . 2010-03-13 22:34 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-21 07:38 . 2010-06-21 07:38 -------- d-----w- c:\users\Veronika\AppData\Roaming\Ahead
2010-06-21 07:37 . 2010-06-21 07:37 -------- d-----w- c:\users\Veronika\AppData\Roaming\DivX
2010-06-21 07:06 . 2010-03-16 07:38 102056 ----a-w- c:\users\Veronika\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-20 17:16 . 2010-06-20 10:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Photo DVD Maker
2010-06-20 10:03 . 2010-06-20 10:03 -------- d-----w- c:\programdata\Anvsoft
2010-06-20 07:47 . 2010-03-14 00:03 -------- d-----w- c:\program files\VSO
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\programdata\McAfee
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\users\Roman\AppData\Roaming\Arkadium
2010-06-17 13:02 . 2010-07-02 14:29 34164 ----a-w- c:\windows\Help\OEM\Scripts\scriptLibrary.dat
2010-06-17 04:45 . 2010-05-09 16:00 -------- d-----w- c:\program files\ICQ6.5
2010-06-14 15:40 . 2010-03-14 08:40 -------- d-----w- c:\users\Roman\AppData\Roaming\Ahead
2010-06-11 14:07 . 2010-03-17 14:59 -------- d-----w- c:\program files\Music NFO Builder
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-03 17:08 . 2010-06-03 17:08 -------- d-----w- c:\programdata\Blumentals
2010-06-01 16:47 . 2010-06-01 16:38 -------- d-----w- c:\program files\Image Grabber II
2010-06-01 06:16 . 2010-03-13 22:34 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-30 07:55 . 2010-03-13 22:08 102056 ----a-w- c:\users\Roman\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-29 10:18 . 2010-03-14 08:15 -------- d-----w- c:\program files\DsNET Corp
2010-05-29 07:14 . 2010-05-29 07:14 -------- d-----w- c:\users\Roman\AppData\Roaming\Xi
2010-05-26 17:06 . 2010-06-11 09:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-11 09:13 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-04 19:15 . 2010-06-11 09:14 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37 . 2010-06-11 09:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13 . 2010-06-11 09:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2009-11-05 07:23 . 2009-11-05 07:14 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 08:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-03 7596576]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-21 525824]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e5,08,b7,d7,14,c5,ca,01
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-04-15 691696]
S0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSvx.sys [2010-06-22 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-03-14 52872]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-03-13 24856]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-06-22 216400]
S1 AvgTdiX;AVG Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-22 243024]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 176128]
S2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-03-16 122880]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-06-22 2331032]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2009-07-11 110592]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-06-22 122448]
S3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-06-22 30288]
S3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-06-22 27216]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2009-05-31 260648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-02-22 10:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-07-26 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-04-11 15:33]
2010-07-22 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-04-11 14:18]
2010-07-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-14 09:14]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15383&l=dis
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=cs_CZ&c=93&bd=all&pf=cmdt
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yznhq012.default\
FF - prefs.js: browser.search.selectedEngine - WebHledani
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=42&tp=ab&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-26 21:36
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
Celkový čas: 2010-07-26 21:37:52
ComboFix-quarantined-files.txt 2010-07-26 19:37
Před spuštěním: Volných bajtů: 376 913 305 600
Po spuštění: Volných bajtů: 377 042 108 416
- - End Of File - - 179985574A0518988E5E44CE612D5816
Re: Prosím o kontrolu
Par polozek smazano, zmenilo se neco 

Re: Prosím o kontrolu
jo určitě právě jsem to zkoušel.Moc děkuji.Na disku C se mi vytvořilo nekolik složek.Mám je tam nechat?
Re: Prosím o kontrolu
Jeste mi neutikejte, docistime a pak nas ceka uklid
Slozky nechte, smaznu je pozdeji - jsou to zalohy...
Pokud nemate, tak presunte Combofix na plochu
Spusste poznamkovy blok
Pretahnete vytvoreny CFScript.txt nad Combofix a pustte

Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci



- Start-spustit-notepad
- Zkopirujte skript nize
Kód: Vybrat vše
DDS:: uStart Page = hxxp://eu.ask.com?o=15383&l=dis mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmdt FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=42&tp=ab&q= FF - prefs.js: browser.search.selectedEngine - WebHledani
- Ulozte vytvoreny TXT jako CFScript.txt




Re: Prosím o kontrolu
ComboFix 10-07-24.06 - Roman 26.07.2010 22:44:36.3.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.3070.1792 [GMT 2:00]
Spuštěný z: c:\users\Roman\Documents\ComboFix.exe
Použité ovládací přepínače :: c:\users\Roman\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-26 do 2010-07-26 )))))))))))))))))))))))))))))))
.
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Roman\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Veronika\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Radka\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-26 20:10 . 2010-07-26 20:10 -------- d-----w- c:\windows\Farm Frenzy 3
2010-07-26 19:54 . 2010-07-26 20:24 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent
2010-07-26 19:54 . 2010-07-26 19:54 -------- d-----w- c:\program files\uTorrent
2010-07-26 18:00 . 2010-07-26 18:13 -------- d-----w- C:\$RECYCLE(137).BIN
2010-07-26 17:59 . 2010-07-26 19:05 -------- d-----w- c:\users\Roman\AppData\Local\Temp(229)
2010-07-26 16:38 . 2010-07-26 17:06 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent(241)
2010-07-26 14:16 . 2010-07-26 14:16 -------- d-----w- c:\users\Roman\AppData\Roaming\SUPERAntiSpyware.com
2010-07-26 13:46 . 2010-07-26 13:51 -------- d-----w- c:\program files\trend micro
2010-07-24 22:04 . 2010-07-26 20:10 -------- d-----w- c:\program files\Farm Frenzy 3
2010-07-21 07:38 . 2010-07-21 07:38 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 07:37 . 2010-07-21 07:37 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 07:37 . 2010-07-21 07:37 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-21 07:37 . 2010-07-21 07:37 921440 ----a-w- c:\programdata\avg9\update\backup\avgemc.exe
2010-07-21 07:37 . 2010-07-21 07:37 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-21 05:08 . 2010-07-21 05:08 0 ----a-w- c:\windows\ativpsrm.bin
2010-07-20 19:06 . 2010-07-20 19:06 -------- d-----w- c:\program files\LeeGTs Games
2010-07-20 16:43 . 2010-07-20 17:04 -------- d-----w- c:\users\Roman\AppData\Local\Adobe
2010-07-20 05:59 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-07-20 05:59 . 2009-11-03 21:43 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-07-20 05:59 . 2009-11-03 21:42 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-07-20 05:59 . 2009-11-03 19:41 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-07-19 20:25 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-07-19 20:25 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-07-19 09:00 . 2010-07-20 19:06 -------- d-----w- c:\users\Roman\AppData\Roaming\iWin
2010-07-19 06:39 . 2010-07-19 06:39 -------- d-----w- c:\program files\WinPcap
2010-07-09 15:00 . 2010-07-09 15:06 -------- d-----w- c:\programdata\FarmFrenzy3
2010-07-09 15:00 . 2010-07-26 07:10 -------- d-----w- c:\programdata\AlawarWrapper
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\users\Radka\AppData\Roaming\GlarySoft
2010-07-07 19:16 . 2010-07-07 19:16 -------- d-----w- c:\users\Radka\AppData\Roaming\IObit
2010-07-07 19:14 . 2010-07-07 19:14 -------- d-----w- c:\users\Radka\AppData\Roaming\Godlike
2010-07-05 16:27 . 2010-07-05 16:33 -------- d-----w- c:\programdata\VirtualFarm
2010-07-02 14:27 . 2010-07-02 14:27 -------- d-----w- c:\programdata\{4BC12378-A8EB-4DBE-AFD8-B5A9D2CDFEC7}
2010-07-02 14:16 . 2010-06-18 15:33 1230392 ----a-w- c:\programdata\Hewlett-Packard\HPSAUpgrade\HpSAUpgrade.exe
2010-06-30 16:46 . 2010-06-30 16:46 -------- d-----w- c:\program files\ReflexiveArcade
2010-06-30 15:59 . 2010-06-30 15:59 -------- d-----w- c:\programdata\Trymedia
2010-06-29 07:19 . 2010-06-29 07:19 1039712 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-26 20:36 . 2009-11-05 07:10 598594 ----a-w- c:\windows\system32\perfh005.dat
2010-07-26 20:36 . 2009-11-05 07:10 114786 ----a-w- c:\windows\system32\perfc005.dat
2010-07-26 20:27 . 2010-04-13 07:32 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-26 20:24 . 2010-03-14 16:11 0 ----a-w- c:\users\Roman\AppData\Local\prvlcl.dat
2010-07-26 19:16 . 2009-11-05 06:56 -------- d-----w- c:\programdata\PDFC
2010-07-26 19:13 . 2010-03-14 17:31 -------- d-----w- c:\program files\Glary Utilities
2010-07-26 07:10 . 2010-03-14 00:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Vso
2010-07-24 15:01 . 2010-03-21 09:12 680 ----a-w- c:\users\Roman\AppData\Local\d3d9caps.dat
2010-07-23 16:16 . 2010-03-14 07:34 -------- d-----w- c:\users\Radka\AppData\Roaming\ICQ
2010-07-18 23:07 . 2010-04-22 14:30 -------- d-----w- c:\program files\DVDFab 7
2010-07-14 19:24 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-07 19:15 . 2010-03-14 07:33 102056 ----a-w- c:\users\Radka\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\users\Roman\AppData\Roaming\LangSoft
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\programdata\LangSoft
2010-07-07 17:33 . 2010-03-28 14:05 356352 ----a-w- c:\programdata\LangSoft\TrnOutl.dll
2010-07-07 17:33 . 2010-03-28 14:05 299008 ----a-w- c:\programdata\LangSoft\TrnWord.dll
2010-07-06 07:04 . 2010-03-14 08:42 -------- d-----w- c:\users\Roman\AppData\Roaming\Godlike
2010-07-02 14:29 . 2009-11-05 06:52 -------- d-----w- c:\program files\Hewlett-Packard
2010-07-02 14:28 . 2009-11-05 06:56 -------- d-----w- c:\program files\HP
2010-07-02 14:26 . 2009-11-05 06:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-02 14:17 . 2009-11-05 06:54 -------- d-----w- c:\programdata\Hewlett-Packard
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\programdata\cerasus.media
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\users\Roman\AppData\Roaming\cerasus.media
2010-06-22 06:09 . 2010-03-13 22:33 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 06:09 . 2010-06-22 06:09 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 06:09 . 2010-03-13 22:33 25168 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-06-22 06:09 . 2010-03-13 22:34 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-21 07:38 . 2010-06-21 07:38 -------- d-----w- c:\users\Veronika\AppData\Roaming\Ahead
2010-06-21 07:37 . 2010-06-21 07:37 -------- d-----w- c:\users\Veronika\AppData\Roaming\DivX
2010-06-21 07:06 . 2010-03-16 07:38 102056 ----a-w- c:\users\Veronika\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-20 17:16 . 2010-06-20 10:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Photo DVD Maker
2010-06-20 10:03 . 2010-06-20 10:03 -------- d-----w- c:\programdata\Anvsoft
2010-06-20 07:47 . 2010-03-14 00:03 -------- d-----w- c:\program files\VSO
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\programdata\McAfee
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\users\Roman\AppData\Roaming\Arkadium
2010-06-17 13:02 . 2010-07-02 14:29 34164 ----a-w- c:\windows\Help\OEM\Scripts\scriptLibrary.dat
2010-06-17 04:45 . 2010-05-09 16:00 -------- d-----w- c:\program files\ICQ6.5
2010-06-14 15:40 . 2010-03-14 08:40 -------- d-----w- c:\users\Roman\AppData\Roaming\Ahead
2010-06-11 14:07 . 2010-03-17 14:59 -------- d-----w- c:\program files\Music NFO Builder
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-03 17:08 . 2010-06-03 17:08 -------- d-----w- c:\programdata\Blumentals
2010-06-01 16:47 . 2010-06-01 16:38 -------- d-----w- c:\program files\Image Grabber II
2010-06-01 06:16 . 2010-03-13 22:34 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-30 07:55 . 2010-03-13 22:08 102056 ----a-w- c:\users\Roman\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-29 10:18 . 2010-03-14 08:15 -------- d-----w- c:\program files\DsNET Corp
2010-05-29 07:14 . 2010-05-29 07:14 -------- d-----w- c:\users\Roman\AppData\Roaming\Xi
2010-05-26 17:06 . 2010-06-11 09:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-11 09:13 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-04 19:15 . 2010-06-11 09:14 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37 . 2010-06-11 09:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13 . 2010-06-11 09:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2009-11-05 07:23 . 2009-11-05 07:14 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 08:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-03 7596576]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-21 525824]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e5,08,b7,d7,14,c5,ca,01
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-04-15 691696]
S0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSvx.sys [2010-06-22 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-03-14 52872]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-03-13 24856]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-06-22 216400]
S1 AvgTdiX;AVG Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-22 243024]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 176128]
S2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-03-16 122880]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-06-22 2331032]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2009-07-11 110592]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-06-22 122448]
S3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-06-22 30288]
S3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-06-22 27216]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2009-05-31 260648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-02-22 10:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-07-26 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-04-11 15:33]
2010-07-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-14 09:14]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yznhq012.default\
FF - prefs.js: browser.search.selectedEngine - WebHledani
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=42&tp=ab&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-26 22:47
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
Celkový čas: 2010-07-26 22:49:37
ComboFix-quarantined-files.txt 2010-07-26 20:49
ComboFix2.txt 2010-07-26 20:39
ComboFix3.txt 2010-07-26 19:37
Před spuštěním: Volných bajtů: 375 427 657 728
Po spuštění: Volných bajtů: 375 394 340 864
- - End Of File - - C30F6090F511E86D34326CE27C56AE43
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.3070.1792 [GMT 2:00]
Spuštěný z: c:\users\Roman\Documents\ComboFix.exe
Použité ovládací přepínače :: c:\users\Roman\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-26 do 2010-07-26 )))))))))))))))))))))))))))))))
.
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Roman\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Veronika\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Radka\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-07-26 20:47 . 2010-07-26 20:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-26 20:10 . 2010-07-26 20:10 -------- d-----w- c:\windows\Farm Frenzy 3
2010-07-26 19:54 . 2010-07-26 20:24 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent
2010-07-26 19:54 . 2010-07-26 19:54 -------- d-----w- c:\program files\uTorrent
2010-07-26 18:00 . 2010-07-26 18:13 -------- d-----w- C:\$RECYCLE(137).BIN
2010-07-26 17:59 . 2010-07-26 19:05 -------- d-----w- c:\users\Roman\AppData\Local\Temp(229)
2010-07-26 16:38 . 2010-07-26 17:06 -------- d-----w- c:\users\Roman\AppData\Roaming\uTorrent(241)
2010-07-26 14:16 . 2010-07-26 14:16 -------- d-----w- c:\users\Roman\AppData\Roaming\SUPERAntiSpyware.com
2010-07-26 13:46 . 2010-07-26 13:51 -------- d-----w- c:\program files\trend micro
2010-07-24 22:04 . 2010-07-26 20:10 -------- d-----w- c:\program files\Farm Frenzy 3
2010-07-21 07:38 . 2010-07-21 07:38 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 07:37 . 2010-07-21 07:37 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 07:37 . 2010-07-21 07:37 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-21 07:37 . 2010-07-21 07:37 921440 ----a-w- c:\programdata\avg9\update\backup\avgemc.exe
2010-07-21 07:37 . 2010-07-21 07:37 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-21 05:08 . 2010-07-21 05:08 0 ----a-w- c:\windows\ativpsrm.bin
2010-07-20 19:06 . 2010-07-20 19:06 -------- d-----w- c:\program files\LeeGTs Games
2010-07-20 16:43 . 2010-07-20 17:04 -------- d-----w- c:\users\Roman\AppData\Local\Adobe
2010-07-20 05:59 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-07-20 05:59 . 2009-11-03 21:43 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-07-20 05:59 . 2009-11-03 21:42 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-07-20 05:59 . 2009-11-03 19:41 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-07-19 20:25 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-07-19 20:25 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-07-19 09:00 . 2010-07-20 19:06 -------- d-----w- c:\users\Roman\AppData\Roaming\iWin
2010-07-19 06:39 . 2010-07-19 06:39 -------- d-----w- c:\program files\WinPcap
2010-07-09 15:00 . 2010-07-09 15:06 -------- d-----w- c:\programdata\FarmFrenzy3
2010-07-09 15:00 . 2010-07-26 07:10 -------- d-----w- c:\programdata\AlawarWrapper
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\users\Radka\AppData\Roaming\GlarySoft
2010-07-07 19:16 . 2010-07-07 19:16 -------- d-----w- c:\users\Radka\AppData\Roaming\IObit
2010-07-07 19:14 . 2010-07-07 19:14 -------- d-----w- c:\users\Radka\AppData\Roaming\Godlike
2010-07-05 16:27 . 2010-07-05 16:33 -------- d-----w- c:\programdata\VirtualFarm
2010-07-02 14:27 . 2010-07-02 14:27 -------- d-----w- c:\programdata\{4BC12378-A8EB-4DBE-AFD8-B5A9D2CDFEC7}
2010-07-02 14:16 . 2010-06-18 15:33 1230392 ----a-w- c:\programdata\Hewlett-Packard\HPSAUpgrade\HpSAUpgrade.exe
2010-06-30 16:46 . 2010-06-30 16:46 -------- d-----w- c:\program files\ReflexiveArcade
2010-06-30 15:59 . 2010-06-30 15:59 -------- d-----w- c:\programdata\Trymedia
2010-06-29 07:19 . 2010-06-29 07:19 1039712 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-26 20:36 . 2009-11-05 07:10 598594 ----a-w- c:\windows\system32\perfh005.dat
2010-07-26 20:36 . 2009-11-05 07:10 114786 ----a-w- c:\windows\system32\perfc005.dat
2010-07-26 20:27 . 2010-04-13 07:32 12 ----a-w- c:\windows\bthservsdp.dat
2010-07-26 20:24 . 2010-03-14 16:11 0 ----a-w- c:\users\Roman\AppData\Local\prvlcl.dat
2010-07-26 19:16 . 2009-11-05 06:56 -------- d-----w- c:\programdata\PDFC
2010-07-26 19:13 . 2010-03-14 17:31 -------- d-----w- c:\program files\Glary Utilities
2010-07-26 07:10 . 2010-03-14 00:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Vso
2010-07-24 15:01 . 2010-03-21 09:12 680 ----a-w- c:\users\Roman\AppData\Local\d3d9caps.dat
2010-07-23 16:16 . 2010-03-14 07:34 -------- d-----w- c:\users\Radka\AppData\Roaming\ICQ
2010-07-18 23:07 . 2010-04-22 14:30 -------- d-----w- c:\program files\DVDFab 7
2010-07-14 19:24 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-07 19:15 . 2010-03-14 07:33 102056 ----a-w- c:\users\Radka\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\users\Roman\AppData\Roaming\LangSoft
2010-07-07 17:38 . 2010-03-28 14:03 -------- d-----w- c:\programdata\LangSoft
2010-07-07 17:33 . 2010-03-28 14:05 356352 ----a-w- c:\programdata\LangSoft\TrnOutl.dll
2010-07-07 17:33 . 2010-03-28 14:05 299008 ----a-w- c:\programdata\LangSoft\TrnWord.dll
2010-07-06 07:04 . 2010-03-14 08:42 -------- d-----w- c:\users\Roman\AppData\Roaming\Godlike
2010-07-02 14:29 . 2009-11-05 06:52 -------- d-----w- c:\program files\Hewlett-Packard
2010-07-02 14:28 . 2009-11-05 06:56 -------- d-----w- c:\program files\HP
2010-07-02 14:26 . 2009-11-05 06:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-02 14:17 . 2009-11-05 06:54 -------- d-----w- c:\programdata\Hewlett-Packard
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\programdata\cerasus.media
2010-06-23 17:34 . 2010-06-23 17:34 -------- d-----w- c:\users\Roman\AppData\Roaming\cerasus.media
2010-06-22 06:09 . 2010-03-13 22:33 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 06:09 . 2010-06-22 06:09 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 06:09 . 2010-03-13 22:33 25168 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-06-22 06:09 . 2010-03-13 22:34 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-21 07:38 . 2010-06-21 07:38 -------- d-----w- c:\users\Veronika\AppData\Roaming\Ahead
2010-06-21 07:37 . 2010-06-21 07:37 -------- d-----w- c:\users\Veronika\AppData\Roaming\DivX
2010-06-21 07:06 . 2010-03-16 07:38 102056 ----a-w- c:\users\Veronika\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-20 17:16 . 2010-06-20 10:03 -------- d-----w- c:\users\Roman\AppData\Roaming\Photo DVD Maker
2010-06-20 10:03 . 2010-06-20 10:03 -------- d-----w- c:\programdata\Anvsoft
2010-06-20 07:47 . 2010-03-14 00:03 -------- d-----w- c:\program files\VSO
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\programdata\McAfee
2010-06-18 16:04 . 2010-06-18 16:04 -------- d-----w- c:\users\Roman\AppData\Roaming\Arkadium
2010-06-17 13:02 . 2010-07-02 14:29 34164 ----a-w- c:\windows\Help\OEM\Scripts\scriptLibrary.dat
2010-06-17 04:45 . 2010-05-09 16:00 -------- d-----w- c:\program files\ICQ6.5
2010-06-14 15:40 . 2010-03-14 08:40 -------- d-----w- c:\users\Roman\AppData\Roaming\Ahead
2010-06-11 14:07 . 2010-03-17 14:59 -------- d-----w- c:\program files\Music NFO Builder
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-09 14:04 . 2010-03-14 00:03 47360 ----a-w- c:\users\Roman\AppData\Roaming\pcouffin.sys
2010-06-03 17:08 . 2010-06-03 17:08 -------- d-----w- c:\programdata\Blumentals
2010-06-01 16:47 . 2010-06-01 16:38 -------- d-----w- c:\program files\Image Grabber II
2010-06-01 06:16 . 2010-03-13 22:34 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-30 07:55 . 2010-03-13 22:08 102056 ----a-w- c:\users\Roman\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-29 10:18 . 2010-03-14 08:15 -------- d-----w- c:\program files\DsNET Corp
2010-05-29 07:14 . 2010-05-29 07:14 -------- d-----w- c:\users\Roman\AppData\Roaming\Xi
2010-05-26 17:06 . 2010-06-11 09:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-11 09:13 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-04 19:15 . 2010-06-11 09:14 834048 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37 . 2010-06-11 09:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-01 14:13 . 2010-06-11 09:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2009-11-05 07:23 . 2009-11-05 07:14 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 08:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-03 7596576]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"SetRefresh"="c:\program files\HP\SetRefresh\SetRefresh.exe" [2003-11-21 525824]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e5,08,b7,d7,14,c5,ca,01
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-04-15 691696]
S0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSvx.sys [2010-06-22 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-03-14 52872]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-03-13 24856]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-06-22 216400]
S1 AvgTdiX;AVG Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-22 243024]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 176128]
S2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files\AMD\RAIDXpert\bin\RAIDXpertService.exe [2009-03-16 122880]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-06-22 2331032]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
S2 BrcmMgmtAgent;Broadcom Management Agent;c:\program files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2009-07-11 110592]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-06-22 122448]
S3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-06-22 30288]
S3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-06-22 27216]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2009-05-31 260648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-02-22 10:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-07-26 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-04-11 15:33]
2010-07-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-14 09:14]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
FF - ProfilePath - c:\users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\yznhq012.default\
FF - prefs.js: browser.search.selectedEngine - WebHledani
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=42&tp=ab&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-26 22:47
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
Celkový čas: 2010-07-26 22:49:37
ComboFix-quarantined-files.txt 2010-07-26 20:49
ComboFix2.txt 2010-07-26 20:39
ComboFix3.txt 2010-07-26 19:37
Před spuštěním: Volných bajtů: 375 427 657 728
Po spuštění: Volných bajtů: 375 394 340 864
- - End Of File - - C30F6090F511E86D34326CE27C56AE43
Re: Prosím o kontrolu


- Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
- Napiste ComboFix /Uninstall
- Stisknete Enter
- Tohle smaze Combofix a jeho slozky

- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy

