
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Preventivka po 1. krát
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Preventivka po 1. krát
Dobrý deň.
Chcem vedieť či je všetko v poriadku. Budem rád ak sa mi na to pozriete.
LOG:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Milka at 2010-08-17 10:26:31
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 10 GB (10%) free of 96 GB
Total RAM: 1789 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:27:00, on 17. 8. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Milka\Documents\RSIT.exe
C:\Program Files\trend micro\Milka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-18\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Unknown owner - C:\Windows\system32\IoctlSvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
--
End of file - 5499 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AWC Startup.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"StartCCC"=c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-04-01 6025216]
"SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-08-17 102400]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-03-13 1443072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FSCRecovery]
c:\Program Files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe [2008-05-08 268096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotkeyApp]
C:\Program Files\Launch Manager\HotkeyApp.exe [2008-03-26 188416]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.2\ICQ.exe [2010-07-19 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMgrOSD]
C:\Program Files\Launch Manager\OSDCtrl.exe [2007-12-25 241664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMgrVolOSD]
C:\Program Files\Launch Manager\OSD.exe [2008-03-04 258048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
C:\Windows\Skytel.exe [2007-11-20 1826816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM]
C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe [2010-07-21 198864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-06-17 85160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WisKeyState]
C:\Program Files\Launch Manager\WisKeyState.exe [2008-03-08 208896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XA5RJ9EADJ]
C:\Users\Milka\AppData\Local\Temp\Pxh.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-08-17 10:24:47 ----D---- C:\rsit
2010-08-17 10:24:47 ----D---- C:\Program Files\trend micro
2010-08-16 10:39:06 ----D---- C:\Users\Milka\AppData\Roaming\Microsoft Games
2010-08-16 10:39:06 ----D---- C:\ProgramData\Microsoft Games
2010-08-13 22:30:28 ----A---- C:\Windows\system32\iccvid.dll
2010-08-13 22:30:16 ----A---- C:\Windows\system32\schannel.dll
2010-08-13 22:30:03 ----A---- C:\Windows\system32\mshtml.dll
2010-08-13 22:30:00 ----A---- C:\Windows\system32\ieframe.dll
2010-08-13 22:29:59 ----A---- C:\Windows\system32\wininet.dll
2010-08-13 22:29:59 ----A---- C:\Windows\system32\urlmon.dll
2010-08-13 22:29:58 ----A---- C:\Windows\system32\mshtmled.dll
2010-08-13 22:29:57 ----A---- C:\Windows\system32\iepeers.dll
2010-08-13 22:29:57 ----A---- C:\Windows\system32\ieencode.dll
2010-08-13 22:29:57 ----A---- C:\Windows\system32\ieapfltr.dll
2010-08-13 22:29:55 ----A---- C:\Windows\system32\win32k.sys
2010-08-13 22:29:53 ----A---- C:\Windows\system32\rtutils.dll
2010-08-13 22:29:35 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-13 22:29:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-13 22:29:31 ----A---- C:\Windows\system32\msxml3.dll
2010-08-13 22:29:29 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-13 22:29:28 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-13 22:29:26 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-05 09:12:38 ----D---- C:\Users\Milka\AppData\Roaming\Leadertech
2010-08-05 09:04:03 ----D---- C:\Program Files\EA Games
2010-08-05 09:04:02 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-08-05 09:04:00 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xinput1_2.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\d3dx10.dll
2010-08-05 09:03:57 ----A---- C:\Windows\system32\xinput1_1.dll
2010-08-05 09:03:57 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-08-05 09:03:57 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-08-05 09:03:49 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-08-05 09:03:48 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-08-05 09:03:48 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-08-04 14:47:00 ----A---- C:\Windows\system32\PnkBstrA.exe
2010-08-04 14:46:37 ----A---- C:\Windows\system32\drivers\PnkBstrK.sys
2010-08-04 14:46:31 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-08-04 14:25:13 ----D---- C:\Program Files\Electronic Arts
2010-08-04 14:25:12 ----A---- C:\Windows\system32\xinput1_3.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-08-04 14:25:11 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-08-04 14:25:11 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-08-04 14:25:11 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-08-04 14:06:20 ----D---- C:\Program Files\Elaborate Bytes
2010-08-03 09:49:38 ----A---- C:\Windows\system32\shell32.dll
2010-07-28 12:48:51 ----D---- C:\Program Files\Lionhead Studios
2010-07-26 14:30:10 ----D---- C:\Users\Milka\AppData\Roaming\Malwarebytes
2010-07-26 14:30:00 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-07-26 14:29:59 ----D---- C:\ProgramData\Malwarebytes
2010-07-26 14:29:58 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-26 14:29:58 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-07-26 09:53:24 ----D---- C:\ProgramData\IObit
2010-07-26 09:48:01 ----D---- C:\Users\Milka\AppData\Roaming\IObit
2010-07-26 09:48:01 ----D---- C:\Program Files\IObit
2010-07-19 14:12:32 ----D---- C:\Program Files\ICQ7.2
2010-07-19 09:31:58 ----D---- C:\Program Files\Valve
======List of files/folders modified in the last 1 months======
2010-08-17 10:26:36 ----D---- C:\Windows\temp
2010-08-17 10:24:47 ----RD---- C:\Program Files
2010-08-17 10:22:23 ----D---- C:\Windows\Debug
2010-08-17 10:22:23 ----D---- C:\Windows
2010-08-17 09:58:07 ----D---- C:\Windows\Prefetch
2010-08-17 09:46:40 ----A---- C:\Windows\win.ini
2010-08-17 08:43:31 ----D---- C:\Windows\system32\config
2010-08-16 23:29:29 ----SHD---- C:\System Volume Information
2010-08-16 11:42:52 ----D---- C:\Program Files\Microsoft Games
2010-08-16 10:39:06 ----D---- C:\ProgramData
2010-08-16 07:53:18 ----D---- C:\Windows\Microsoft.NET
2010-08-16 07:52:55 ----RSD---- C:\Windows\assembly
2010-08-16 07:41:51 ----D---- C:\Windows\winsxs
2010-08-16 07:26:47 ----D---- C:\Windows\System32
2010-08-16 07:26:46 ----D---- C:\Program Files\Movie Maker
2010-08-16 07:26:44 ----D---- C:\Windows\system32\drivers
2010-08-15 22:01:20 ----D---- C:\Windows\system32\catroot
2010-08-15 22:01:14 ----D---- C:\Program Files\Windows Mail
2010-08-14 08:16:35 ----SHD---- C:\Windows\Installer
2010-08-14 08:16:26 ----D---- C:\Config.Msi
2010-08-14 08:16:21 ----D---- C:\Program Files\Opera
2010-08-13 22:29:19 ----D---- C:\Windows\system32\catroot2
2010-08-09 16:08:16 ----D---- C:\Users\Milka\AppData\Roaming\ICQ
2010-08-05 08:47:13 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-08-05 08:47:12 ----D---- C:\Windows\inf
2010-08-04 14:45:24 ----D---- C:\Windows\system32\LogFiles
2010-08-04 14:14:10 ----D---- C:\Windows\system32\Tasks
2010-08-03 20:09:31 ----A---- C:\Windows\system32\mrt.exe
2010-07-28 12:48:50 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-26 15:33:26 ----D---- C:\Windows\Tasks
2010-07-26 09:58:55 ----RD---- C:\DRIVER
2010-07-26 09:58:55 ----D---- C:\Windows\Panther
2010-07-26 09:58:55 ----D---- C:\Users\Milka\AppData\Roaming\BitTorrent
2010-07-26 09:58:55 ----D---- C:\Program Files\Vivid WorkshopData ATI
2010-07-26 09:58:54 ----D---- C:\TMP
2010-07-19 14:15:45 ----D---- C:\Program Files\ICQ6.5
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ahcix86s;ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [2008-04-15 170000]
R0 AtiPcie;ATI PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 7680]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-07-04 691696]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-03-13 29704]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 epfwtdir;epfwtdir; C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
R1 Hotkey;Hotkey; C:\Windows\system32\drivers\Hotkey.sys [2003-04-28 9867]
R1 NetworkX;NetworkX; C:\Windows\system32\ckldrv.sys [2006-01-10 31846]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-03-13 40456]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-03-19 903680]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-04-23 3551232]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-04-01 2113624]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-04-11 84240]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-02-14 118784]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-08-17 190512]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S3 a2bm7fvs;a2bm7fvs; C:\Windows\system32\drivers\a2bm7fvs.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2007-08-23 313344]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\Windows\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\Windows\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2007-09-30 308248]
S4 JRAID;JRAID; C:\Windows\system32\drivers\jraid.sys [2008-04-03 76688]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-04-22 671744]
R2 Crypkey License;Crypkey License; C:\Windows\system32\crypserv.exe [2006-09-22 69632]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-03-13 472320]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-08-05 66872]
R2 TestHandler;Fujitsu Siemens Computers Diagnostic Testhandler; C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe [2008-02-29 307200]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe []
S2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe []
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-03-13 19200]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WisLMSvc;WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [2008-01-16 118784]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
-----------------EOF-----------------
Dopredu Ďakujem
Chcem vedieť či je všetko v poriadku. Budem rád ak sa mi na to pozriete.
LOG:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Milka at 2010-08-17 10:26:31
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 10 GB (10%) free of 96 GB
Total RAM: 1789 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:27:00, on 17. 8. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Milka\Documents\RSIT.exe
C:\Program Files\trend micro\Milka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-18\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Unknown owner - C:\Windows\system32\IoctlSvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
--
End of file - 5499 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AWC Startup.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"StartCCC"=c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-04-01 6025216]
"SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-08-17 102400]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-03-13 1443072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FSCRecovery]
c:\Program Files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe [2008-05-08 268096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotkeyApp]
C:\Program Files\Launch Manager\HotkeyApp.exe [2008-03-26 188416]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.2\ICQ.exe [2010-07-19 133368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMgrOSD]
C:\Program Files\Launch Manager\OSDCtrl.exe [2007-12-25 241664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMgrVolOSD]
C:\Program Files\Launch Manager\OSD.exe [2008-03-04 258048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
C:\Windows\Skytel.exe [2007-11-20 1826816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM]
C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe [2010-07-21 198864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-06-17 85160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WisKeyState]
C:\Program Files\Launch Manager\WisKeyState.exe [2008-03-08 208896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XA5RJ9EADJ]
C:\Users\Milka\AppData\Local\Temp\Pxh.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-08-17 10:24:47 ----D---- C:\rsit
2010-08-17 10:24:47 ----D---- C:\Program Files\trend micro
2010-08-16 10:39:06 ----D---- C:\Users\Milka\AppData\Roaming\Microsoft Games
2010-08-16 10:39:06 ----D---- C:\ProgramData\Microsoft Games
2010-08-13 22:30:28 ----A---- C:\Windows\system32\iccvid.dll
2010-08-13 22:30:16 ----A---- C:\Windows\system32\schannel.dll
2010-08-13 22:30:03 ----A---- C:\Windows\system32\mshtml.dll
2010-08-13 22:30:00 ----A---- C:\Windows\system32\ieframe.dll
2010-08-13 22:29:59 ----A---- C:\Windows\system32\wininet.dll
2010-08-13 22:29:59 ----A---- C:\Windows\system32\urlmon.dll
2010-08-13 22:29:58 ----A---- C:\Windows\system32\mshtmled.dll
2010-08-13 22:29:57 ----A---- C:\Windows\system32\iepeers.dll
2010-08-13 22:29:57 ----A---- C:\Windows\system32\ieencode.dll
2010-08-13 22:29:57 ----A---- C:\Windows\system32\ieapfltr.dll
2010-08-13 22:29:55 ----A---- C:\Windows\system32\win32k.sys
2010-08-13 22:29:53 ----A---- C:\Windows\system32\rtutils.dll
2010-08-13 22:29:35 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-13 22:29:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-13 22:29:31 ----A---- C:\Windows\system32\msxml3.dll
2010-08-13 22:29:29 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-13 22:29:28 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-13 22:29:26 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-05 09:12:38 ----D---- C:\Users\Milka\AppData\Roaming\Leadertech
2010-08-05 09:04:03 ----D---- C:\Program Files\EA Games
2010-08-05 09:04:02 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-08-05 09:04:02 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-08-05 09:04:01 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-08-05 09:04:00 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xinput1_2.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-08-05 09:03:58 ----A---- C:\Windows\system32\d3dx10.dll
2010-08-05 09:03:57 ----A---- C:\Windows\system32\xinput1_1.dll
2010-08-05 09:03:57 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-08-05 09:03:57 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-08-05 09:03:49 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-08-05 09:03:48 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-08-05 09:03:48 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-08-04 14:47:00 ----A---- C:\Windows\system32\PnkBstrA.exe
2010-08-04 14:46:37 ----A---- C:\Windows\system32\drivers\PnkBstrK.sys
2010-08-04 14:46:31 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-08-04 14:25:13 ----D---- C:\Program Files\Electronic Arts
2010-08-04 14:25:12 ----A---- C:\Windows\system32\xinput1_3.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-08-04 14:25:12 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-08-04 14:25:11 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-08-04 14:25:11 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-08-04 14:25:11 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-08-04 14:06:20 ----D---- C:\Program Files\Elaborate Bytes
2010-08-03 09:49:38 ----A---- C:\Windows\system32\shell32.dll
2010-07-28 12:48:51 ----D---- C:\Program Files\Lionhead Studios
2010-07-26 14:30:10 ----D---- C:\Users\Milka\AppData\Roaming\Malwarebytes
2010-07-26 14:30:00 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-07-26 14:29:59 ----D---- C:\ProgramData\Malwarebytes
2010-07-26 14:29:58 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-26 14:29:58 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-07-26 09:53:24 ----D---- C:\ProgramData\IObit
2010-07-26 09:48:01 ----D---- C:\Users\Milka\AppData\Roaming\IObit
2010-07-26 09:48:01 ----D---- C:\Program Files\IObit
2010-07-19 14:12:32 ----D---- C:\Program Files\ICQ7.2
2010-07-19 09:31:58 ----D---- C:\Program Files\Valve
======List of files/folders modified in the last 1 months======
2010-08-17 10:26:36 ----D---- C:\Windows\temp
2010-08-17 10:24:47 ----RD---- C:\Program Files
2010-08-17 10:22:23 ----D---- C:\Windows\Debug
2010-08-17 10:22:23 ----D---- C:\Windows
2010-08-17 09:58:07 ----D---- C:\Windows\Prefetch
2010-08-17 09:46:40 ----A---- C:\Windows\win.ini
2010-08-17 08:43:31 ----D---- C:\Windows\system32\config
2010-08-16 23:29:29 ----SHD---- C:\System Volume Information
2010-08-16 11:42:52 ----D---- C:\Program Files\Microsoft Games
2010-08-16 10:39:06 ----D---- C:\ProgramData
2010-08-16 07:53:18 ----D---- C:\Windows\Microsoft.NET
2010-08-16 07:52:55 ----RSD---- C:\Windows\assembly
2010-08-16 07:41:51 ----D---- C:\Windows\winsxs
2010-08-16 07:26:47 ----D---- C:\Windows\System32
2010-08-16 07:26:46 ----D---- C:\Program Files\Movie Maker
2010-08-16 07:26:44 ----D---- C:\Windows\system32\drivers
2010-08-15 22:01:20 ----D---- C:\Windows\system32\catroot
2010-08-15 22:01:14 ----D---- C:\Program Files\Windows Mail
2010-08-14 08:16:35 ----SHD---- C:\Windows\Installer
2010-08-14 08:16:26 ----D---- C:\Config.Msi
2010-08-14 08:16:21 ----D---- C:\Program Files\Opera
2010-08-13 22:29:19 ----D---- C:\Windows\system32\catroot2
2010-08-09 16:08:16 ----D---- C:\Users\Milka\AppData\Roaming\ICQ
2010-08-05 08:47:13 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-08-05 08:47:12 ----D---- C:\Windows\inf
2010-08-04 14:45:24 ----D---- C:\Windows\system32\LogFiles
2010-08-04 14:14:10 ----D---- C:\Windows\system32\Tasks
2010-08-03 20:09:31 ----A---- C:\Windows\system32\mrt.exe
2010-07-28 12:48:50 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-26 15:33:26 ----D---- C:\Windows\Tasks
2010-07-26 09:58:55 ----RD---- C:\DRIVER
2010-07-26 09:58:55 ----D---- C:\Windows\Panther
2010-07-26 09:58:55 ----D---- C:\Users\Milka\AppData\Roaming\BitTorrent
2010-07-26 09:58:55 ----D---- C:\Program Files\Vivid WorkshopData ATI
2010-07-26 09:58:54 ----D---- C:\TMP
2010-07-19 14:15:45 ----D---- C:\Program Files\ICQ6.5
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ahcix86s;ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [2008-04-15 170000]
R0 AtiPcie;ATI PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 7680]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-07-04 691696]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-03-13 29704]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R1 epfwtdir;epfwtdir; C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
R1 Hotkey;Hotkey; C:\Windows\system32\drivers\Hotkey.sys [2003-04-28 9867]
R1 NetworkX;NetworkX; C:\Windows\system32\ckldrv.sys [2006-01-10 31846]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-03-13 40456]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-03-19 903680]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-04-23 3551232]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-04-01 2113624]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-04-11 84240]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-02-14 118784]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-08-17 190512]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S3 a2bm7fvs;a2bm7fvs; C:\Windows\system32\drivers\a2bm7fvs.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2007-08-23 313344]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\Windows\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\Windows\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2007-09-30 308248]
S4 JRAID;JRAID; C:\Windows\system32\drivers\jraid.sys [2008-04-03 76688]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-04-22 671744]
R2 Crypkey License;Crypkey License; C:\Windows\system32\crypserv.exe [2006-09-22 69632]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-03-13 472320]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-08-05 66872]
R2 TestHandler;Fujitsu Siemens Computers Diagnostic Testhandler; C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe [2008-02-29 307200]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe []
S2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe []
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-03-13 19200]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WisLMSvc;WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [2008-01-16 118784]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
-----------------EOF-----------------
Dopredu Ďakujem
Re: Preventivka po 1. krát
Zdravim a pekne dopoledne preji
Vas log se studuje
a pracuje se na nem
.
Prosim o strpeni!

Vas log se studuje


Prosim o strpeni!

Re: Preventivka po 1. krát


- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:reg [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{855F3B16-6D32-4fe6-8A56-BBB695989046}"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]¨ [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XA5RJ9EADJ] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=- :files %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp /s C:\Users\Milka\AppData\Local\Temp\ :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH] [CLEARALLRESTOREPOINTS]
- Kliknete na cervene tlacitko MoveIt!
- Sem pote dejte obsah okna Results (pod zelenou carou)
- Pokud budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles


Re: Preventivka po 1. krát
Ďakujem, že ste sa toho ujali. Myslel som, že to bude čiste
Tu davam log:
All processes killed
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XA5RJ9EADJ\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5C42.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8F1C.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp folder moved successfully.
C:\Windows\twain_32\hpqgnds2.tmp moved successfully.
C:\Users\Milka\AppData\Local\temp\6D33.tmp folder moved successfully.
C:\Users\Milka\AppData\Local\temp folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Milka
->Temporary Internet Files folder emptied: 475270 bytes
->Opera cache emptied: 6195084 bytes
->Flash cache emptied: 485 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 86499 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84420 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 7,00 mb
Restore point Set: OTM Restore Point
OTM by OldTimer - Version 3.1.15.0 log created on 08172010_114230
Files moved on Reboot...
Registry entries deleted on Reboot...

Tu davam log:
All processes killed
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XA5RJ9EADJ\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5C42.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8F1C.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp folder moved successfully.
C:\Windows\twain_32\hpqgnds2.tmp moved successfully.
C:\Users\Milka\AppData\Local\temp\6D33.tmp folder moved successfully.
C:\Users\Milka\AppData\Local\temp folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Milka
->Temporary Internet Files folder emptied: 475270 bytes
->Opera cache emptied: 6195084 bytes
->Flash cache emptied: 485 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 86499 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84420 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 7,00 mb
Restore point Set: OTM Restore Point
OTM by OldTimer - Version 3.1.15.0 log created on 08172010_114230
Files moved on Reboot...
Registry entries deleted on Reboot...
Re: Preventivka po 1. krát
No byl tam hazjlik v tempu...
Pro jistotu udelame mbam jestli nekam neschoval kamarady
Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) (viz muj podpis)
Pro jistotu udelame mbam jestli nekam neschoval kamarady

- Provedte aktualizaci - treti zalozka
- Provedte uplny sken - nic nemazte
- MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
Re: Preventivka po 1. krát
Dúfam, že už sa nevrati
MBAM už mam nainštalovaný. Mal som rychly sken pred 2 dňami, nič nenašiel, tak isto aj Eset. Teraz som dal uplný. Bude to troška dlhšie trvať.

MBAM už mam nainštalovaný. Mal som rychly sken pred 2 dňami, nič nenašiel, tak isto aj Eset. Teraz som dal uplný. Bude to troška dlhšie trvať.

Re: Preventivka po 1. krát
Pockam tedy na log z uplneho 

Re: Preventivka po 1. krát
Už to je. Prepač za zdržiavanie
LOG:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Verzia databázy: 4439
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
17. 8. 2010 12:47:15
mbam-log-2010-08-17 (12-47-15).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 250409
Uplynulý čas: 47 min, 29 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)

LOG:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Verzia databázy: 4439
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
17. 8. 2010 12:47:15
mbam-log-2010-08-17 (12-47-15).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 250409
Uplynulý čas: 47 min, 29 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)
Re: Preventivka po 1. krát
Takze cisto
Vubec nezdzujete
Jak se chova PC


Jak se chova PC

Re: Preventivka po 1. krát
Ďakujem,
Pc sa chová lepšie.
Mal by si ešte čas? By som ti tu dal aj RSIT log zo segrineho pc.


Mal by si ešte čas? By som ti tu dal aj RSIT log zo segrineho pc.

Re: Preventivka po 1. krát
Jeste Vase PC procistime a uklidime po utilitach
MBAM muzete odinstalovat nebo nechat na obcasny sken - v pripade nalezu velmi doporucuji dat sem log na posouzeni, at si neodstrelite neco legitimniho
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner (viz muj podpis), pri instalaci dejte fajfku pryc u yahoo toolbaru
Panel čistič
Na sestrin PC zalozte novy topic a do predmetu dejte "pro vyosek" a kolegove mi to prenechaji 


- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy


Re: Preventivka po 1. krát
Všetko urobene
Ccleaner použivam pravidelne
Ešte raz ďakujem
Idem urobiť teda nový topic 


Ešte raz ďakujem


Re: Preventivka po 1. krát
Nemate zac, rad jsem pomohl 
