Nika Mix hudba hra z nicoho nic

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Avatar uživatele
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 Pro 2005 20:59
Místo/Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#16 Příspěvek od earl »

Dobre,zvolime setrnejsi metodu,ovsem aby uz nebylo pozde...

Odinstalujte Trojan Remover.

:arrow: Stahnete si OTM , spustte (pokud mate vistu spuste run as administrator) a
do leveho policka se zlutym hornim okrajem Paste Instructions for Items to be Moved zkopirujte toto:

Kód: Vybrat vše

:processes
explorer.exe
:files
:services
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"reset"=-
:commands
[emptytemp]
[resethosts]
[start explorer]
[reboot]

Kliknete na MoveIt, v okne se zelenym hornim okrajem Results se objevi vysledek,obsah okna zkopirujte sem. Kdyby OTMoveIt vyzadoval restart - povolit. Nasledujici log najdete v C:\_OTMoveIt\MovedFiles\xxxxx.log (x je zastupny znak) ktery otevrete v poznamkovem bloku.

:arrow: Stahnete GMER , rozbalte a spustte

probehne sken, po jehoz ukonceni na vas vyskoci vysledky

pote kliknete na Save a ulozite tak log, jehoz obsah sem vlozte

pote dle tohoto navodu

absolvujte druhy sken a opet obsah logu sem.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#17 Příspěvek od nemamcas »

Naco je zas toto ?

Ja uz by som isiel spusit ten ComboMix pokial mi tu niekto napise ze sa priapadyn problem da opravit...

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#18 Příspěvek od nemamcas »

Spustil som ComboFix vsetko urobil podla a ked som po 10 min prisiel k PC tak monitor bol cierny dalo sa spustit Spravca Uloh ale na plochu som sa nemohol dostat tak som sa prihlasil a odhlasil ale ten textovy subor co mal vzniknut som nenasiel...

Avatar uživatele
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 Pro 2005 20:59
Místo/Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#19 Příspěvek od earl »

Naco je zas toto ?
Pokud vam budu vysvetlovat vsechno,co tu delame,tak tu budeme do jara.Uvedomte si,ze my se touto cinnosti zde na foru zabyvame denne a

pokud by se kazdy uzivatel,co ho tu resime,takto vyptaval a my mu odpovidali,tak toho moc neudelame.

Takze ja napisu co mate delat a vy to udelate a tak porad dokola,dokud neni pc ciste a problemy vyreseny.Je na tom jeste neco nejasneho?

:arrow: Log z ComboFixu je umisten zde - C:/Combofix.txt

Pokud ho nenajdete,aplikujte kroky v mem predchozim postu (OTM a GMER).

Dokud neuvidim odpovidajici logy vami vytvorene,neni z ceho vychazet.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#20 Příspěvek od nemamcas »

Ja som to ComboFix spustil podla navodu on sa restartol PC nabehla tam niaka vec chvilu bolo pocut hudbu z toho virusu potom bolo ze hlada infekcie a ked som prisiel k PC uz tam bola iba cierna obrazovka tak som sa odhlasil a prihlasil nefunguje mi odvtedy Deamon a virus sa furt spusta...

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#21 Příspěvek od nemamcas »

ComboFix 10-09-21.03 - eQ . 09. 2010 14:22:07.2.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3326.2038 [GMT 2:00]
Running from: c:\users\eQ\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
c:\program files\Antbar\Ant.com Toolbar\tbHElper.dll
c:\users\eQ\AppData\Roaming\Desktopicon
c:\users\eQ\AppData\Roaming\Desktopicon\config.ini
c:\users\eQ\AppData\Roaming\Desktopicon\eBayShortcuts.exe
c:\users\eQ\AppData\Roaming\inst.exe
c:\users\eQ\Documents\cc_20100919_153822.reg
c:\windows\system\regsrv.exe
c:\windows\system32\sda
c:\windows\system32\sda\SDRTCPRM.dll
E:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_GoogleUpdateBeta
-------\Service_FLEXnet Licensing Manager


((((((((((((((((((((((((( Files Created from 2010-08-24 to 2010-09-24 )))))))))))))))))))))))))))))))
.

2010-09-24 12:32 . 2010-09-24 12:35 -------- d-----w- c:\users\eQ\AppData\Local\temp
2010-09-24 12:32 . 2010-09-24 12:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-24 12:20 . 2010-09-24 12:21 -------- d-----w- C:\32788R22FWJFW
2010-09-22 13:37 . 2010-09-22 13:37 -------- d-----w- c:\users\eQ\AppData\Local\ESET
2010-09-22 12:45 . 2010-09-22 12:45 202282 ----a-w- c:\windows\system\tubelist.dat
2010-09-20 15:59 . 2010-09-20 15:59 -------- d-----w- c:\program files\ESET
2010-09-19 11:02 . 2010-09-19 11:02 -------- d-----w- c:\program files\CCleaner
2010-09-18 09:12 . 2010-09-18 09:12 -------- d-----w- c:\program files\trend micro
2010-09-18 09:12 . 2010-09-18 09:12 -------- d-----w- C:\rsit
2010-09-17 13:56 . 2010-09-24 12:08 223290 ----a-w- c:\windows\system\latest.dat
2010-09-17 13:56 . 2010-09-24 12:08 124 ----a-w- c:\windows\system\update.dat
2010-09-17 12:40 . 2010-09-18 07:52 -------- d-----w- c:\users\eQ\AppData\Roaming\ArcSoft
2010-09-17 12:40 . 2010-09-17 12:40 -------- d-----w- c:\programdata\ArcSoft
2010-09-17 12:39 . 2010-09-17 12:39 -------- d-----w- c:\program files\ArcSoft
2010-09-17 12:38 . 2010-09-17 12:38 -------- d-----w- c:\windows\Downloaded Installations
2010-09-16 16:57 . 2010-09-16 16:57 -------- d-----w- c:\program files\Combined Community Codec Pack
2010-09-16 16:34 . 2010-09-16 16:34 171276 ---ha-w- c:\windows\system32\mlfcache.dat
2010-09-15 16:02 . 2010-09-15 16:02 -------- d-----w- c:\users\Public\CyberLink
2010-09-15 16:01 . 2010-09-15 16:09 -------- d-----w- c:\users\eQ\AppData\Local\Cyberlink
2010-09-15 16:01 . 2010-09-15 16:04 -------- d-----w- c:\users\eQ\AppData\Roaming\CyberLink
2010-09-15 16:00 . 2010-09-15 16:01 -------- d-----w- c:\programdata\CyberLink
2010-09-15 15:59 . 2010-09-15 15:59 -------- d-----w- c:\program files\Common Files\CyberLink
2010-09-15 15:57 . 2010-09-15 16:00 -------- d-----w- c:\program files\CyberLink
2010-09-15 08:01 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 08:01 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-15 08:01 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 08:00 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-07 13:03 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-09-07 13:03 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-09-07 13:03 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-09-07 13:03 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-09-07 13:03 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-09-07 13:03 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-09-07 13:03 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-09-07 13:03 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-09-07 12:55 . 2010-09-07 12:55 -------- d-----w- c:\program files\2K Games
2010-09-02 13:38 . 2009-09-02 08:20 652 ----a-w- c:\windows\FIX.reg
2010-09-02 13:38 . 2008-11-01 11:23 280 ----a-w- c:\windows\reset.reg
2010-08-26 06:36 . 2010-08-26 06:36 -------- d-----w- c:\users\eQ\AppData\Roaming\The Creative Assembly
2010-08-26 06:04 . 2010-08-28 09:48 -------- d-----w- c:\program files\Empire Total War
2010-08-25 14:37 . 2010-08-25 14:37 -------- d-----w- c:\users\eQ\AppData\Local\2K Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-24 12:37 . 2009-11-18 13:47 -------- d-----w- c:\program files\Steam
2010-09-24 12:36 . 2010-06-21 15:49 -------- d-----w- c:\users\eQ\AppData\Roaming\Hamachi
2010-09-24 12:36 . 2009-08-21 18:33 -------- d-----w- c:\users\eQ\AppData\Roaming\uTorrent
2010-09-24 12:34 . 2010-02-18 15:25 -------- d-----w- c:\programdata\NVIDIA
2010-09-24 12:33 . 2010-06-24 14:44 0 ----a-w- c:\windows\system32\Access.dat
2010-09-23 12:16 . 2009-08-19 09:03 -------- d-----w- c:\users\eQ\AppData\Roaming\vlc
2010-09-23 11:39 . 2009-10-13 13:49 -------- d-----w- c:\program files\Safari
2010-09-20 15:50 . 2009-08-19 09:29 -------- d-----w- c:\users\eQ\AppData\Roaming\Media Player Classic
2010-09-20 15:34 . 2009-10-08 14:41 -------- d-----w- c:\program files\FreeTime
2010-09-20 15:32 . 2009-09-18 17:25 -------- d-----w- c:\program files\Common Files\Nero
2010-09-20 15:31 . 2009-09-18 15:31 -------- d-----w- c:\programdata\Nero
2010-09-20 15:18 . 2010-05-02 10:28 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-09-20 15:18 . 2010-05-02 10:28 -------- d-----w- c:\program files\AVS4YOU
2010-09-20 15:15 . 2010-03-28 14:23 -------- d-----w- c:\program files\Winnydows
2010-09-19 16:18 . 2009-10-18 15:36 -------- d-----w- c:\users\eQ\AppData\Roaming\Vso
2010-09-18 07:52 . 2009-03-09 12:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-17 16:19 . 2009-08-23 17:20 -------- d-----w- c:\users\eQ\AppData\Roaming\dvdcss
2010-09-16 16:51 . 2010-08-09 18:17 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-09-16 16:47 . 2010-02-27 21:15 -------- d-----w- c:\program files\VistaCodecPack
2010-09-16 16:47 . 2010-02-27 21:14 -------- d-----w- c:\programdata\VistaCodecs
2010-09-15 18:44 . 2009-08-30 18:28 -------- d-----w- c:\programdata\Microsoft Help
2010-09-15 18:40 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-15 15:57 . 2009-03-09 12:51 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-15 15:57 . 2009-03-09 12:51 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-09-09 10:20 . 2009-09-01 08:22 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-08 18:03 . 2009-11-18 14:05 -------- d-----w- c:\program files\Common Files\Steam
2010-09-06 18:36 . 2009-08-30 18:02 -------- d-----w- c:\users\eQ\AppData\Roaming\Skype
2010-09-06 18:09 . 2009-08-30 18:05 -------- d-----w- c:\users\eQ\AppData\Roaming\skypePM
2010-09-03 10:08 . 2009-08-18 16:17 -------- d-----w- c:\programdata\Symantec
2010-09-03 10:08 . 2009-08-18 16:16 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-02 14:07 . 2009-12-11 17:00 -------- d-----w- c:\program files\Norton Security Scan
2010-09-02 14:07 . 2009-10-17 11:49 -------- d-----w- c:\programdata\Norton
2010-09-02 14:05 . 2009-08-18 16:17 -------- d-----w- c:\program files\Symantec
2010-08-25 14:39 . 2009-09-02 10:54 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-25 13:32 . 2009-08-19 07:59 46258 ----a-w- c:\windows\system32\perfh01B.dat
2010-08-25 13:32 . 2009-08-19 07:59 14570 ----a-w- c:\windows\system32\perfc01B.dat
2010-08-12 06:48 . 2010-08-12 06:48 90 ----a-w- c:\users\eQ\AppData\Local\fusioncache.dat
2010-08-12 06:24 . 2010-08-12 06:24 -------- d-----w- c:\program files\SEGA
2010-08-10 21:01 . 2009-08-31 17:02 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-08-10 19:41 . 2009-08-31 16:45 -------- d-----w- c:\program files\Rockstar Games
2010-08-10 19:39 . 2010-06-14 18:12 -------- d-----w- c:\program files\EA GAMES
2010-08-10 19:37 . 2010-06-14 14:15 -------- d-----w- c:\program files\Electronic Arts
2010-08-10 17:30 . 2009-03-09 11:48 1356 ----a-w- c:\users\eQ\AppData\Local\d3d9caps.dat
2010-08-10 17:13 . 2010-08-10 17:13 -------- d-----w- c:\users\eQ\AppData\Roaming\GHISLER
2010-08-09 06:45 . 2010-08-09 06:39 -------- d-----w- c:\program files\CoreCodec
2010-08-07 18:20 . 2009-08-21 17:54 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-07-21 06:11 . 2009-03-09 11:48 133816 ----a-w- c:\users\eQ\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-20 09:16 . 2009-08-19 11:57 1446 ----a-w- c:\windows\eReg.dat
2010-07-14 17:36 . 2010-07-14 17:36 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-07-06 06:05 . 2010-06-16 14:40 6200 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-08-18 18:50 . 2009-08-18 18:50 22 --sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA3D342F-FF20-4E31-9E82-22334155730C}]
2009-06-02 14:51 2695168 ----a-w- c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-07-02 08:18 2215960 ----a-w- c:\program files\BS_Player\tbBS_P.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-10 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-08-29 328568]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-03-09 26100520]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-11-14 305064]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-05-18 2363392]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"Steam"="c:\program files\Steam\Steam.exe" [2010-08-25 1242448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reset"="regedit" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-08-04 1068424]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-02 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-02 92704]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-03-13 75048]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]

c:\users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2010-7-14 624416]
RsGetPoints.lnk - c:\users\eQ\Downloads\RS_account_premium_v1.2\RS account premium v1.2\RsGetPts.exe [2009-10-8 1214810]
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2009-9-2 49220]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"RequireSignedAppInit_DLLs"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-287188440-3596446558-1827478602-1000]
"EnableNotificationsRef"=dword:00000003

R1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 cpuz130;cpuz130;c:\users\eQ\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 GPU-Z;GPU-Z;c:\users\eQ\AppData\Local\Temp\GPU-Z.sys [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\eQ\Downloads\RealTemp_340\WinRing0.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-08-30 721904]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/09/15 17:59];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-03-13 10:58 87536]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-05-14 38240]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-07-14 239648]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2010-02-13 685816]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-11-27 517120]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-11-27 173056]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-05-18 15:54 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-23 c:\windows\Tasks\User_Feed_Synchronization-{4EB8BB25-6DCA-4F8E-9AF3-9C2703B47272}.job
- c:\windows\system32\msfeedssync.exe [2010-08-13 04:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com?o=15187&l=dis
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\eQ\AppData\Roaming\Mozilla\Firefox\Profiles\q9xdv8n2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?o=15187&l=dis
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-HPADVISOR - c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-24 14:34
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-287188440-3596446558-1827478602-1000\Software\SecuROM\License information*]
"datasecu"=hex:2d,ea,e8,05,2d,e7,0c,87,99,aa,03,af,8a,c8,a1,64,6c,1f,9e,70,4e,
e9,7a,04,cc,99,0b,b4,9a,e8,6b,8f,92,3b,e5,46,11,24,a5,d8,a7,9d,8c,6a,b5,98,\
"rkeysecu"=hex:0e,c7,52,01,b3,4c,a4,a6,32,c6,95,f8,10,f3,f9,49
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Rockstar Games\Rockstar Games Social Club\1_0_0_0\RGSC.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Completion time: 2010-09-24 14:46:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-24 12:45

Pre-Run: 39 586 721 792 bytes free
Post-Run: 39 371 182 080 bytes free

- - End Of File - - B4ACAD5ABE348AFA01E49DB25C01D251

Avatar uživatele
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 Pro 2005 20:59
Místo/Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#22 Příspěvek od earl »

Jak jsem uz jednou psal:

:arrow: Odinstalujte Trojan Remover.

:arrow: Odinstalujte ESET - mate ho nelegalne a to je protizakonne. :!:

:arrow: Odinstalujte Symantec.

:arrow: Stahnete a nainstalujte Avast - http://www.stahuj.centrum.cz/utility_a_ ... tni/avast/

:arrow: Stahnete OTL

spustte, oznacte "Pro vsechny uzivatele,30 dnů zmente na 7,kliknete na Prohledat,

po skonceni skenu sem vlozte obsah logu z OTL.txt.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#23 Příspěvek od nemamcas »

earl napsal:Jak jsem uz jednou psal:

:arrow: Odinstalujte Trojan Remover.

:arrow: Odinstalujte ESET - mate ho nelegalne a to je protizakonne. :!:

:arrow: Odinstalujte Symantec.

:arrow: Stahnete a nainstalujte Avast - http://www.stahuj.centrum.cz/utility_a_ ... tni/avast/

:arrow: Stahnete OTL

spustte, oznacte "Pro vsechny uzivatele,30 dnů zmente na 7,kliknete na Prohledat,

po skonceni skenu sem vlozte obsah logu z OTL.txt.

UZ som sem vlozil ten Log s ComboFix ked som ho pustil 2. krat tak isiel uz normlane a odvtedy sa uz ta hudba nespusta ale vzdy muí vyskoci okno

DEAMON TOOLS:
Je potrebny aspon Windows 2000 SP1 alebo novsie.
Ladenie Jadra vypnuto

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Nika Mix hudba hra z nicoho nic

#24 Příspěvek od cernohous13 »

UZ som sem vlozil ten Log s ComboFix ked som ho pustil 2. krat tak isiel uz normlane a odvtedy sa uz ta hudba nespusta ale vzdy muí vyskoci okno

DEAMON TOOLS:
Je potrebny aspon Windows 2000 SP1 alebo novsie.
Ladenie Jadra vypnuto
Ty nemáš čas? A kdo ho má mít na tvoje problémy, když se absolutně neřídíš pokyny svého rádce?
"earl" ti dal návod a ty si děláš co tě napadne :?:
Pokud si budeš léčení PC řídit sám, tak si oprav i následné problémy
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Avatar uživatele
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 Pro 2005 20:59
Místo/Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#25 Příspěvek od earl »

Dokud zde neuvidim log z OTL,jak jsem psal v minulem postu,tak nema smysl pokracovat dal.

Jake okno vyskakuje?

Ten Daemon tools ma znamenat co?
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#26 Příspěvek od nemamcas »

OTL logfile created on: 26. 9. 2010 12:33:22 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\eQ\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 0000041B | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 58,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): c:\pagefile.sys 4989 4989 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 689,70 Gb Total Space | 38,46 Gb Free Space | 5,58% Space Free | Partition Type: NTFS
Drive D: | 3,62 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 8,93 Gb Total Space | 5,69 Gb Free Space | 63,77% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: POU-4MFNE1NDL6B
Current User Name: eQ
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/09/26 12:31:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\eQ\Downloads\OTL.exe
PRC - [2010/09/25 08:35:33 | 000,328,056 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010/03/13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared files\brs.exe
PRC - [2010/02/13 02:49:04 | 000,685,816 | ---- | M] (Tunngle.net GmbH) -- C:\Program Files\Tunngle\TnglCtrl.exe
PRC - [2010/02/03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2009/11/05 22:14:44 | 001,794,848 | ---- | M] (Apple Inc.) -- C:\Program Files\Safari\Safari.exe
PRC - [2009/07/14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2009/05/14 15:47:08 | 002,029,640 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/10 23:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2009/03/30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/03/30 16:28:36 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009/02/26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008/01/18 23:38:40 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/12/13 16:36:46 | 000,049,220 | ---- | M] (Samsung) -- C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
PRC - [2007/03/12 13:49:46 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007/03/12 13:49:26 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe


========== Modules (SafeList) ==========

MOD - [2010/09/26 12:31:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\eQ\Downloads\OTL.exe
MOD - [2009/04/10 23:21:40 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/18 23:33:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010/09/08 12:10:55 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/03/18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/13 02:49:04 | 000,685,816 | ---- | M] (Tunngle.net GmbH) [Auto | Running] -- C:\Program Files\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2009/09/25 03:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/08/05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009/07/14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/05/14 15:54:22 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009/03/30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009/02/18 11:38:44 | 000,129,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\eQ\Downloads\RealTemp_340\WinRing0.sys -- (WinRing0_1_2_0)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\eQ\AppData\Local\Temp\GPU-Z.sys -- (GPU-Z)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\eQ\AppData\Local\Temp\cpuz130\cpuz_x32.sys -- (cpuz130)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\System32\drivers\archlp.sys -- (archlp)
DRV - [2010/07/14 19:36:52 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2010/03/13 12:58:52 | 000,087,536 | ---- | M] (CyberLink Corp.) [2010/09/15 17:59:37] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl -- ({1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC})
DRV - [2009/11/27 22:16:03 | 000,517,120 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr28.sys -- (netr28)
DRV - [2009/11/27 22:16:00 | 000,172,032 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/11/27 22:15:36 | 000,173,056 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/09/16 08:02:40 | 000,027,136 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle)
DRV - [2009/08/30 20:19:59 | 000,721,904 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009/08/05 22:48:42 | 000,054,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fssfltr.sys -- (fssfltr)
DRV - [2009/05/14 15:49:32 | 000,038,240 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfp.sys -- (epfwwfp)
DRV - [2009/05/14 15:49:26 | 000,033,096 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2009/05/14 15:49:22 | 000,133,000 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfw.sys -- (epfw)
DRV - [2009/05/14 15:47:14 | 000,107,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009/05/14 15:41:10 | 000,114,472 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamon.sys -- (eamon)
DRV - [2008/12/04 20:34:52 | 000,328,728 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2008/12/02 23:11:00 | 007,643,904 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/01/18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006/11/02 11:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006/11/02 11:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006/11/02 11:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006/11/02 11:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006/11/02 11:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006/11/02 11:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006/11/02 11:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006/11/02 11:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006/11/02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 11:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006/11/02 11:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2006/11/02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 11:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2006/11/02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 11:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006/11/02 11:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006/11/02 11:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006/11/02 11:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006/11/02 11:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006/11/02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 11:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006/11/02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 11:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006/11/02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 11:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006/11/02 11:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2006/11/02 11:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2006/11/02 11:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2006/11/02 10:51:30 | 000,079,360 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\parport.sys.vir -- (Parport)
DRV - [2006/11/02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/11/02 09:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2006/11/02 02:50:52 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2006/09/24 15:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
DRV - [2006/08/28 17:12:04 | 000,013,312 | ---- | M] () [Kernel | System | Running] -- C:\Windows\system32\drivers\MTictwl.sys -- (NCPro)
DRV - [2006/08/28 17:12:04 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MTictwl.sys -- (MagicTune)
DRV - [2005/12/12 18:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
DRV - [2005/09/24 00:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [1996/04/03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15187&l=dis
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sk
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 9F 34 E7 D0 44 CA 01 [binary data]
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\URLSearchHook: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.ask.com?o=15187&l=dis"
FF - prefs.js..extensions.enabledItems: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:2.1.0.19
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/16 18:51:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/16 18:51:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Namoroka 3.6a1\extensions\\Components: C:\Program Files\Namoroka 3.6 Alpha 1\components [2009/10/14 14:23:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Namoroka 3.6a1\extensions\\Plugins: C:\Program Files\Namoroka 3.6 Alpha 1\plugins [2009/10/14 14:23:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/09/20 17:59:34 | 000,000,000 | ---D | M]

[2009/08/31 12:55:04 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Extensions
[2010/09/20 17:24:55 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\9n4hmwiy.default\extensions
[2009/08/31 12:50:52 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\9n4hmwiy.default\extensions\DTToolbar@toolbarnet.com
[2010/09/25 17:19:31 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\q9xdv8n2.default\extensions
[2009/09/17 18:45:13 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\q9xdv8n2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/09 14:15:21 | 000,000,000 | ---D | M] (BS Player Toolbar) -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\q9xdv8n2.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
[2010/09/25 17:19:31 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/09 19:18:08 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/08/09 20:18:14 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010/08/09 20:18:14 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010/08/09 20:18:14 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010/08/09 20:18:14 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010/08/09 20:18:14 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010/08/09 20:18:14 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml

O1 HOSTS File: ([2010/09/24 14:34:21 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (TBSB00982 Class) - {DA3D342F-FF20-4E31-9E82-22334155730C} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [reset] C:\Windows\reset.reg ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (LogMeIn Inc.)
O4 - Startup: C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RsGetPoints.lnk = C:\Users\eQ\Downloads\RS_account_premium_v1.2\RS account premium v1.2\RsGetPts.exe ()
O4 - Startup: C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDow ... ab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 85.237.225.250 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\eQ\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O24 - Desktop BackupWallPaper: C:\Users\eQ\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 7 Days ==========

[2010/09/24 14:34:23 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2010/09/24 14:32:39 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/09/24 14:32:39 | 000,000,000 | ---D | C] -- C:\Users\eQ\AppData\Local\temp
[2010/09/24 14:20:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/09/24 14:20:52 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/09/22 15:37:44 | 000,000,000 | ---D | C] -- C:\Users\eQ\AppData\Local\ESET
[2010/09/22 15:33:08 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/09/22 15:33:08 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/09/22 15:33:08 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/09/22 15:32:51 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/09/22 15:28:28 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/09/20 17:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/09/19 13:02:08 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/10/18 17:36:15 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\eQ\AppData\Roaming\pcouffin.sys
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2010/09/26 12:34:46 | 004,194,304 | -HS- | M] () -- C:\Users\eQ\NTUSER.DAT
[2010/09/26 12:20:18 | 000,000,964 | ---- | M] () -- C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RsGetPoints.lnk
[2010/09/26 12:19:57 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/26 12:19:57 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/26 12:19:56 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/09/26 12:19:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/26 12:19:51 | 3488,849,920 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/25 17:39:50 | 000,524,288 | -HS- | M] () -- C:\Users\eQ\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/09/25 17:39:50 | 000,065,536 | -HS- | M] () -- C:\Users\eQ\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/09/25 17:39:44 | 000,000,000 | ---- | M] () -- C:\Windows\System32\Access.dat
[2010/09/25 17:39:36 | 004,078,916 | -H-- | M] () -- C:\Users\eQ\AppData\Local\IconCache.db
[2010/09/25 15:54:35 | 000,000,460 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4EB8BB25-6DCA-4F8E-9AF3-9C2703B47272}.job
[2010/09/24 14:34:26 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/09/24 14:34:21 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/09/24 14:08:32 | 000,223,290 | ---- | M] () -- C:\Windows\System\latest.dat
[2010/09/24 14:08:31 | 000,000,124 | ---- | M] () -- C:\Windows\System\update.dat
[2010/09/22 15:20:02 | 003,849,240 | R--- | M] () -- C:\Users\eQ\Desktop\ComboFix.exe
[2010/09/22 14:45:47 | 000,202,282 | ---- | M] () -- C:\Windows\System\tubelist.dat
[2010/09/20 17:13:15 | 000,000,934 | ---- | M] () -- C:\Users\eQ\Documents\cc_20100920_171310.reg
[2010/09/19 18:18:18 | 000,001,041 | ---- | M] () -- C:\Users\eQ\AppData\Roaming\vso_ts_preview.xml
[2010/09/19 16:53:45 | 000,004,966 | ---- | M] () -- C:\Users\eQ\Documents\cc_20100919_165342.reg
[2010/09/19 13:02:09 | 000,000,804 | ---- | M] () -- C:\Users\eQ\Desktop\CCleaner.lnk
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/22 15:33:09 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/09/22 15:33:08 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/09/22 15:33:08 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/09/22 15:33:08 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/09/22 15:33:08 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/09/22 15:19:15 | 003,849,240 | R--- | C] () -- C:\Users\eQ\Desktop\ComboFix.exe
[2010/09/22 14:45:37 | 000,202,282 | ---- | C] () -- C:\Windows\System\tubelist.dat
[2010/09/20 17:13:13 | 000,000,934 | ---- | C] () -- C:\Users\eQ\Documents\cc_20100920_171310.reg
[2010/09/19 16:53:43 | 000,004,966 | ---- | C] () -- C:\Users\eQ\Documents\cc_20100919_165342.reg
[2010/09/19 13:02:09 | 000,000,804 | ---- | C] () -- C:\Users\eQ\Desktop\CCleaner.lnk
[2010/08/12 08:48:14 | 000,000,090 | ---- | C] () -- C:\Users\eQ\AppData\Local\fusioncache.dat
[2010/06/14 15:30:39 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/06/14 15:30:39 | 000,138,056 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\PnkBstrK.sys
[2010/05/05 14:26:16 | 000,000,000 | ---- | C] () -- C:\Windows\WinInit.ini
[2010/04/02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010/02/27 22:46:30 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/02/14 11:32:13 | 000,119,930 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/02/14 11:12:46 | 000,119,930 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/11/27 22:31:02 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/10/18 17:38:15 | 000,001,041 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\vso_ts_preview.xml
[2009/10/18 17:37:56 | 000,000,034 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\pcouffin.log
[2009/10/18 17:36:15 | 000,007,887 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\pcouffin.cat
[2009/10/18 17:36:15 | 000,001,144 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\pcouffin.inf
[2009/10/08 15:49:29 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009/10/02 12:25:55 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys
[2009/09/19 20:13:48 | 000,000,000 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\downloads.m3u
[2009/09/19 11:41:42 | 000,000,723 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\burnaware.ini
[2009/09/19 10:17:46 | 000,000,162 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\default.rss
[2009/09/18 17:39:42 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
[2009/09/02 14:05:49 | 000,013,312 | ---- | C] () -- C:\Windows\System32\drivers\MTictwl.sys
[2009/08/30 20:05:56 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/08/21 19:54:11 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009/08/19 10:13:14 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/19 09:00:04 | 000,025,088 | ---- | C] () -- C:\Users\eQ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/09 13:48:02 | 000,001,356 | ---- | C] () -- C:\Users\eQ\AppData\Local\d3d9caps.dat
[2007/01/26 03:04:12 | 000,138,752 | ---- | C] () -- C:\Windows\System32\mase32.dll
[2007/01/26 03:04:12 | 000,027,648 | ---- | C] () -- C:\Windows\System32\ma32.dll
[2006/11/02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys

========== Files - Unicode (All) ==========
[2010/04/18 10:37:29 | 000,000,000 | ---D | M](C:\Users\eQ\AppData\Roaming\???????sAppData) -- C:\Users\eQ\AppData\Roaming\敎潲䍄敔灭慬整sAppData
[2010/04/18 10:37:29 | 000,000,000 | ---D | M](C:\Users\eQ\AppData\Roaming\???????sAppData) -- C:\Users\eQ\AppData\Roaming\敎潲䍄敔灭慬整sAppData
(C:\Users\eQ\AppData\Roaming\???????sAppData) -- C:\Users\eQ\AppData\Roaming\敎潲䍄敔灭慬整sAppData

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:890CC2F3
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:66633281
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:0888F409
< End of report >

Avatar uživatele
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 Pro 2005 20:59
Místo/Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#27 Příspěvek od earl »

Jeste jednou:

Odinstalujte ten ESET,v dalsim logu uz chci videt Avast nebo Aviru (Avast ma navic emailovy stit).

:arrow: Znovu spustte OTL a zkopirujte do policka pod nazvem "Vlastni skenovani/opravy" zeleny text:

Kód: Vybrat vše

:otl
O4 - HKLM..\Run: [reset] C:\Windows\reset.reg ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
:Files
C:\Windows\reset.reg
:Commands
[EMPTYTEMP]
[RESETHOSTS]
[CREATERESTOREPOINT] 
Kliknete na Opravit, mozna probehne restart,pak se vytvori log, jeho obsah sem zkopirujte. Pokud se log neotevre, najdete ho v miste spusteni OTL.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#28 Příspěvek od nemamcas »

Co som cital tak AVAST neni moc dobry...

Ked som ho mal naposledy tak sa mi zaviroval stary PC

Avatar uživatele
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 Pro 2005 20:59
Místo/Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#29 Příspěvek od earl »

Avast je jeden z nejlepsich free antiviru,to je neoddiskutovatelny fakt.
Ked som ho mal naposledy tak sa mi zaviroval stary PC
To nebylo Avastem,nybrz uzivatelem - to neberte osobne,tak to proste je,ani nejlepsi bezpecnostni reseni neni nic platne,kdyz uzivatel je nezodpovedny

a klika na co muze a chodi na weby tak,kam nema...

Rekl jsem odinstalovat ESET,mate ho nelegalne,o tom tu diskutovat tez nebudeme.

Vlozte sem novy log z OTL at to muzeme dorazit.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 Zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#30 Příspěvek od nemamcas »

Takze mam mat vlastne hrosi antivir jak mam ? alebo jak to mam chapat...

Odpovědět