Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Nika Mix hudba hra z nicoho nic

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 pro 2005 20:59
Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#16 Příspěvek od earl »

Dobre,zvolime setrnejsi metodu,ovsem aby uz nebylo pozde...

Odinstalujte Trojan Remover.

:arrow: Stahnete si OTM , spustte (pokud mate vistu spuste run as administrator) a
do leveho policka se zlutym hornim okrajem Paste Instructions for Items to be Moved zkopirujte toto:

Kód: Vybrat vše

:processes
explorer.exe
:files
:services
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"reset"=-
:commands
[emptytemp]
[resethosts]
[start explorer]
[reboot]

Kliknete na MoveIt, v okne se zelenym hornim okrajem Results se objevi vysledek,obsah okna zkopirujte sem. Kdyby OTMoveIt vyzadoval restart - povolit. Nasledujici log najdete v C:\_OTMoveIt\MovedFiles\xxxxx.log (x je zastupny znak) ktery otevrete v poznamkovem bloku.

:arrow: Stahnete GMER , rozbalte a spustte

probehne sken, po jehoz ukonceni na vas vyskoci vysledky

pote kliknete na Save a ulozite tak log, jehoz obsah sem vlozte

pote dle tohoto navodu

absolvujte druhy sken a opet obsah logu sem.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#17 Příspěvek od nemamcas »

Naco je zas toto ?

Ja uz by som isiel spusit ten ComboMix pokial mi tu niekto napise ze sa priapadyn problem da opravit...

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#18 Příspěvek od nemamcas »

Spustil som ComboFix vsetko urobil podla a ked som po 10 min prisiel k PC tak monitor bol cierny dalo sa spustit Spravca Uloh ale na plochu som sa nemohol dostat tak som sa prihlasil a odhlasil ale ten textovy subor co mal vzniknut som nenasiel...

Uživatelský avatar
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 pro 2005 20:59
Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#19 Příspěvek od earl »

Naco je zas toto ?
Pokud vam budu vysvetlovat vsechno,co tu delame,tak tu budeme do jara.Uvedomte si,ze my se touto cinnosti zde na foru zabyvame denne a

pokud by se kazdy uzivatel,co ho tu resime,takto vyptaval a my mu odpovidali,tak toho moc neudelame.

Takze ja napisu co mate delat a vy to udelate a tak porad dokola,dokud neni pc ciste a problemy vyreseny.Je na tom jeste neco nejasneho?

:arrow: Log z ComboFixu je umisten zde - C:/Combofix.txt

Pokud ho nenajdete,aplikujte kroky v mem predchozim postu (OTM a GMER).

Dokud neuvidim odpovidajici logy vami vytvorene,neni z ceho vychazet.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#20 Příspěvek od nemamcas »

Ja som to ComboFix spustil podla navodu on sa restartol PC nabehla tam niaka vec chvilu bolo pocut hudbu z toho virusu potom bolo ze hlada infekcie a ked som prisiel k PC uz tam bola iba cierna obrazovka tak som sa odhlasil a prihlasil nefunguje mi odvtedy Deamon a virus sa furt spusta...

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#21 Příspěvek od nemamcas »

ComboFix 10-09-21.03 - eQ . 09. 2010 14:22:07.2.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3326.2038 [GMT 2:00]
Running from: c:\users\eQ\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
c:\program files\Antbar\Ant.com Toolbar\tbHElper.dll
c:\users\eQ\AppData\Roaming\Desktopicon
c:\users\eQ\AppData\Roaming\Desktopicon\config.ini
c:\users\eQ\AppData\Roaming\Desktopicon\eBayShortcuts.exe
c:\users\eQ\AppData\Roaming\inst.exe
c:\users\eQ\Documents\cc_20100919_153822.reg
c:\windows\system\regsrv.exe
c:\windows\system32\sda
c:\windows\system32\sda\SDRTCPRM.dll
E:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_GoogleUpdateBeta
-------\Service_FLEXnet Licensing Manager


((((((((((((((((((((((((( Files Created from 2010-08-24 to 2010-09-24 )))))))))))))))))))))))))))))))
.

2010-09-24 12:32 . 2010-09-24 12:35 -------- d-----w- c:\users\eQ\AppData\Local\temp
2010-09-24 12:32 . 2010-09-24 12:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-24 12:20 . 2010-09-24 12:21 -------- d-----w- C:\32788R22FWJFW
2010-09-22 13:37 . 2010-09-22 13:37 -------- d-----w- c:\users\eQ\AppData\Local\ESET
2010-09-22 12:45 . 2010-09-22 12:45 202282 ----a-w- c:\windows\system\tubelist.dat
2010-09-20 15:59 . 2010-09-20 15:59 -------- d-----w- c:\program files\ESET
2010-09-19 11:02 . 2010-09-19 11:02 -------- d-----w- c:\program files\CCleaner
2010-09-18 09:12 . 2010-09-18 09:12 -------- d-----w- c:\program files\trend micro
2010-09-18 09:12 . 2010-09-18 09:12 -------- d-----w- C:\rsit
2010-09-17 13:56 . 2010-09-24 12:08 223290 ----a-w- c:\windows\system\latest.dat
2010-09-17 13:56 . 2010-09-24 12:08 124 ----a-w- c:\windows\system\update.dat
2010-09-17 12:40 . 2010-09-18 07:52 -------- d-----w- c:\users\eQ\AppData\Roaming\ArcSoft
2010-09-17 12:40 . 2010-09-17 12:40 -------- d-----w- c:\programdata\ArcSoft
2010-09-17 12:39 . 2010-09-17 12:39 -------- d-----w- c:\program files\ArcSoft
2010-09-17 12:38 . 2010-09-17 12:38 -------- d-----w- c:\windows\Downloaded Installations
2010-09-16 16:57 . 2010-09-16 16:57 -------- d-----w- c:\program files\Combined Community Codec Pack
2010-09-16 16:34 . 2010-09-16 16:34 171276 ---ha-w- c:\windows\system32\mlfcache.dat
2010-09-15 16:02 . 2010-09-15 16:02 -------- d-----w- c:\users\Public\CyberLink
2010-09-15 16:01 . 2010-09-15 16:09 -------- d-----w- c:\users\eQ\AppData\Local\Cyberlink
2010-09-15 16:01 . 2010-09-15 16:04 -------- d-----w- c:\users\eQ\AppData\Roaming\CyberLink
2010-09-15 16:00 . 2010-09-15 16:01 -------- d-----w- c:\programdata\CyberLink
2010-09-15 15:59 . 2010-09-15 15:59 -------- d-----w- c:\program files\Common Files\CyberLink
2010-09-15 15:57 . 2010-09-15 16:00 -------- d-----w- c:\program files\CyberLink
2010-09-15 08:01 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 08:01 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-15 08:01 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 08:00 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-07 13:03 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-09-07 13:03 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-09-07 13:03 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-09-07 13:03 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-09-07 13:03 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-09-07 13:03 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-09-07 13:03 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-09-07 13:03 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-09-07 13:03 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-09-07 12:55 . 2010-09-07 12:55 -------- d-----w- c:\program files\2K Games
2010-09-02 13:38 . 2009-09-02 08:20 652 ----a-w- c:\windows\FIX.reg
2010-09-02 13:38 . 2008-11-01 11:23 280 ----a-w- c:\windows\reset.reg
2010-08-26 06:36 . 2010-08-26 06:36 -------- d-----w- c:\users\eQ\AppData\Roaming\The Creative Assembly
2010-08-26 06:04 . 2010-08-28 09:48 -------- d-----w- c:\program files\Empire Total War
2010-08-25 14:37 . 2010-08-25 14:37 -------- d-----w- c:\users\eQ\AppData\Local\2K Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-24 12:37 . 2009-11-18 13:47 -------- d-----w- c:\program files\Steam
2010-09-24 12:36 . 2010-06-21 15:49 -------- d-----w- c:\users\eQ\AppData\Roaming\Hamachi
2010-09-24 12:36 . 2009-08-21 18:33 -------- d-----w- c:\users\eQ\AppData\Roaming\uTorrent
2010-09-24 12:34 . 2010-02-18 15:25 -------- d-----w- c:\programdata\NVIDIA
2010-09-24 12:33 . 2010-06-24 14:44 0 ----a-w- c:\windows\system32\Access.dat
2010-09-23 12:16 . 2009-08-19 09:03 -------- d-----w- c:\users\eQ\AppData\Roaming\vlc
2010-09-23 11:39 . 2009-10-13 13:49 -------- d-----w- c:\program files\Safari
2010-09-20 15:50 . 2009-08-19 09:29 -------- d-----w- c:\users\eQ\AppData\Roaming\Media Player Classic
2010-09-20 15:34 . 2009-10-08 14:41 -------- d-----w- c:\program files\FreeTime
2010-09-20 15:32 . 2009-09-18 17:25 -------- d-----w- c:\program files\Common Files\Nero
2010-09-20 15:31 . 2009-09-18 15:31 -------- d-----w- c:\programdata\Nero
2010-09-20 15:18 . 2010-05-02 10:28 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-09-20 15:18 . 2010-05-02 10:28 -------- d-----w- c:\program files\AVS4YOU
2010-09-20 15:15 . 2010-03-28 14:23 -------- d-----w- c:\program files\Winnydows
2010-09-19 16:18 . 2009-10-18 15:36 -------- d-----w- c:\users\eQ\AppData\Roaming\Vso
2010-09-18 07:52 . 2009-03-09 12:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-17 16:19 . 2009-08-23 17:20 -------- d-----w- c:\users\eQ\AppData\Roaming\dvdcss
2010-09-16 16:51 . 2010-08-09 18:17 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-09-16 16:47 . 2010-02-27 21:15 -------- d-----w- c:\program files\VistaCodecPack
2010-09-16 16:47 . 2010-02-27 21:14 -------- d-----w- c:\programdata\VistaCodecs
2010-09-15 18:44 . 2009-08-30 18:28 -------- d-----w- c:\programdata\Microsoft Help
2010-09-15 18:40 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-15 15:57 . 2009-03-09 12:51 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-15 15:57 . 2009-03-09 12:51 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-09-09 10:20 . 2009-09-01 08:22 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-08 18:03 . 2009-11-18 14:05 -------- d-----w- c:\program files\Common Files\Steam
2010-09-06 18:36 . 2009-08-30 18:02 -------- d-----w- c:\users\eQ\AppData\Roaming\Skype
2010-09-06 18:09 . 2009-08-30 18:05 -------- d-----w- c:\users\eQ\AppData\Roaming\skypePM
2010-09-03 10:08 . 2009-08-18 16:17 -------- d-----w- c:\programdata\Symantec
2010-09-03 10:08 . 2009-08-18 16:16 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-02 14:07 . 2009-12-11 17:00 -------- d-----w- c:\program files\Norton Security Scan
2010-09-02 14:07 . 2009-10-17 11:49 -------- d-----w- c:\programdata\Norton
2010-09-02 14:05 . 2009-08-18 16:17 -------- d-----w- c:\program files\Symantec
2010-08-25 14:39 . 2009-09-02 10:54 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-25 13:32 . 2009-08-19 07:59 46258 ----a-w- c:\windows\system32\perfh01B.dat
2010-08-25 13:32 . 2009-08-19 07:59 14570 ----a-w- c:\windows\system32\perfc01B.dat
2010-08-12 06:48 . 2010-08-12 06:48 90 ----a-w- c:\users\eQ\AppData\Local\fusioncache.dat
2010-08-12 06:24 . 2010-08-12 06:24 -------- d-----w- c:\program files\SEGA
2010-08-10 21:01 . 2009-08-31 17:02 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-08-10 19:41 . 2009-08-31 16:45 -------- d-----w- c:\program files\Rockstar Games
2010-08-10 19:39 . 2010-06-14 18:12 -------- d-----w- c:\program files\EA GAMES
2010-08-10 19:37 . 2010-06-14 14:15 -------- d-----w- c:\program files\Electronic Arts
2010-08-10 17:30 . 2009-03-09 11:48 1356 ----a-w- c:\users\eQ\AppData\Local\d3d9caps.dat
2010-08-10 17:13 . 2010-08-10 17:13 -------- d-----w- c:\users\eQ\AppData\Roaming\GHISLER
2010-08-09 06:45 . 2010-08-09 06:39 -------- d-----w- c:\program files\CoreCodec
2010-08-07 18:20 . 2009-08-21 17:54 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-07-21 06:11 . 2009-03-09 11:48 133816 ----a-w- c:\users\eQ\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-20 09:16 . 2009-08-19 11:57 1446 ----a-w- c:\windows\eReg.dat
2010-07-14 17:36 . 2010-07-14 17:36 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-07-06 06:05 . 2010-06-16 14:40 6200 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-08-18 18:50 . 2009-08-18 18:50 22 --sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA3D342F-FF20-4E31-9E82-22334155730C}]
2009-06-02 14:51 2695168 ----a-w- c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-07-02 08:18 2215960 ----a-w- c:\program files\BS_Player\tbBS_P.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2009-07-02 2215960]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-10 2153472]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-08-29 328568]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-03-09 26100520]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-11-14 305064]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-05-18 2363392]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"Steam"="c:\program files\Steam\Steam.exe" [2010-08-25 1242448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reset"="regedit" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-08-04 1068424]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-02 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-02 92704]
"RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-03-13 75048]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]

c:\users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2010-7-14 624416]
RsGetPoints.lnk - c:\users\eQ\Downloads\RS_account_premium_v1.2\RS account premium v1.2\RsGetPts.exe [2009-10-8 1214810]
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2009-9-2 49220]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"RequireSignedAppInit_DLLs"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-287188440-3596446558-1827478602-1000]
"EnableNotificationsRef"=dword:00000003

R1 archlp;archlp;c:\windows\system32\drivers\archlp.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 cpuz130;cpuz130;c:\users\eQ\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 GPU-Z;GPU-Z;c:\users\eQ\AppData\Local\Temp\GPU-Z.sys [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\eQ\Downloads\RealTemp_340\WinRing0.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-08-30 721904]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/09/15 17:59];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [2010-03-13 10:58 87536]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-05-14 38240]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-07-14 239648]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2010-02-13 685816]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-11-27 517120]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-11-27 173056]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-05-18 15:54 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-23 c:\windows\Tasks\User_Feed_Synchronization-{4EB8BB25-6DCA-4F8E-9AF3-9C2703B47272}.job
- c:\windows\system32\msfeedssync.exe [2010-08-13 04:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com?o=15187&l=dis
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\eQ\AppData\Roaming\Mozilla\Firefox\Profiles\q9xdv8n2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?o=15187&l=dis
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-HPADVISOR - c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-24 14:34
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-287188440-3596446558-1827478602-1000\Software\SecuROM\License information*]
"datasecu"=hex:2d,ea,e8,05,2d,e7,0c,87,99,aa,03,af,8a,c8,a1,64,6c,1f,9e,70,4e,
e9,7a,04,cc,99,0b,b4,9a,e8,6b,8f,92,3b,e5,46,11,24,a5,d8,a7,9d,8c,6a,b5,98,\
"rkeysecu"=hex:0e,c7,52,01,b3,4c,a4,a6,32,c6,95,f8,10,f3,f9,49
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Rockstar Games\Rockstar Games Social Club\1_0_0_0\RGSC.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Completion time: 2010-09-24 14:46:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-24 12:45

Pre-Run: 39 586 721 792 bytes free
Post-Run: 39 371 182 080 bytes free

- - End Of File - - B4ACAD5ABE348AFA01E49DB25C01D251

Uživatelský avatar
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 pro 2005 20:59
Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#22 Příspěvek od earl »

Jak jsem uz jednou psal:

:arrow: Odinstalujte Trojan Remover.

:arrow: Odinstalujte ESET - mate ho nelegalne a to je protizakonne. :!:

:arrow: Odinstalujte Symantec.

:arrow: Stahnete a nainstalujte Avast - http://www.stahuj.centrum.cz/utility_a_ ... tni/avast/

:arrow: Stahnete OTL

spustte, oznacte "Pro vsechny uzivatele,30 dnů zmente na 7,kliknete na Prohledat,

po skonceni skenu sem vlozte obsah logu z OTL.txt.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#23 Příspěvek od nemamcas »

earl píše:Jak jsem uz jednou psal:

:arrow: Odinstalujte Trojan Remover.

:arrow: Odinstalujte ESET - mate ho nelegalne a to je protizakonne. :!:

:arrow: Odinstalujte Symantec.

:arrow: Stahnete a nainstalujte Avast - http://www.stahuj.centrum.cz/utility_a_ ... tni/avast/

:arrow: Stahnete OTL

spustte, oznacte "Pro vsechny uzivatele,30 dnů zmente na 7,kliknete na Prohledat,

po skonceni skenu sem vlozte obsah logu z OTL.txt.

UZ som sem vlozil ten Log s ComboFix ked som ho pustil 2. krat tak isiel uz normlane a odvtedy sa uz ta hudba nespusta ale vzdy muí vyskoci okno

DEAMON TOOLS:
Je potrebny aspon Windows 2000 SP1 alebo novsie.
Ladenie Jadra vypnuto

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Nika Mix hudba hra z nicoho nic

#24 Příspěvek od cernohous13 »

UZ som sem vlozil ten Log s ComboFix ked som ho pustil 2. krat tak isiel uz normlane a odvtedy sa uz ta hudba nespusta ale vzdy muí vyskoci okno

DEAMON TOOLS:
Je potrebny aspon Windows 2000 SP1 alebo novsie.
Ladenie Jadra vypnuto
Ty nemáš čas? A kdo ho má mít na tvoje problémy, když se absolutně neřídíš pokyny svého rádce?
"earl" ti dal návod a ty si děláš co tě napadne :?:
Pokud si budeš léčení PC řídit sám, tak si oprav i následné problémy
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Uživatelský avatar
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 pro 2005 20:59
Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#25 Příspěvek od earl »

Dokud zde neuvidim log z OTL,jak jsem psal v minulem postu,tak nema smysl pokracovat dal.

Jake okno vyskakuje?

Ten Daemon tools ma znamenat co?
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#26 Příspěvek od nemamcas »

OTL logfile created on: 26. 9. 2010 12:33:22 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\eQ\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 0000041B | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 58,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): c:\pagefile.sys 4989 4989 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 689,70 Gb Total Space | 38,46 Gb Free Space | 5,58% Space Free | Partition Type: NTFS
Drive D: | 3,62 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 8,93 Gb Total Space | 5,69 Gb Free Space | 63,77% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: POU-4MFNE1NDL6B
Current User Name: eQ
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/09/26 12:31:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\eQ\Downloads\OTL.exe
PRC - [2010/09/25 08:35:33 | 000,328,056 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010/03/13 12:58:58 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files\CyberLink\Shared files\brs.exe
PRC - [2010/02/13 02:49:04 | 000,685,816 | ---- | M] (Tunngle.net GmbH) -- C:\Program Files\Tunngle\TnglCtrl.exe
PRC - [2010/02/03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2009/11/05 22:14:44 | 001,794,848 | ---- | M] (Apple Inc.) -- C:\Program Files\Safari\Safari.exe
PRC - [2009/07/14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2009/05/14 15:47:08 | 002,029,640 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/10 23:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2009/03/30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/03/30 16:28:36 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009/02/26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008/01/18 23:38:40 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/12/13 16:36:46 | 000,049,220 | ---- | M] (Samsung) -- C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
PRC - [2007/03/12 13:49:46 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007/03/12 13:49:26 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe


========== Modules (SafeList) ==========

MOD - [2010/09/26 12:31:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\eQ\Downloads\OTL.exe
MOD - [2009/04/10 23:21:40 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/18 23:33:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010/09/08 12:10:55 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/03/18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/13 02:49:04 | 000,685,816 | ---- | M] (Tunngle.net GmbH) [Auto | Running] -- C:\Program Files\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2009/09/25 03:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/08/05 22:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009/07/14 13:28:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/05/14 15:54:22 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009/03/30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009/02/18 11:38:44 | 000,129,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\eQ\Downloads\RealTemp_340\WinRing0.sys -- (WinRing0_1_2_0)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\eQ\AppData\Local\Temp\GPU-Z.sys -- (GPU-Z)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\eQ\AppData\Local\Temp\cpuz130\cpuz_x32.sys -- (cpuz130)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\System32\drivers\archlp.sys -- (archlp)
DRV - [2010/07/14 19:36:52 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2010/03/13 12:58:52 | 000,087,536 | ---- | M] (CyberLink Corp.) [2010/09/15 17:59:37] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl -- ({1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC})
DRV - [2009/11/27 22:16:03 | 000,517,120 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr28.sys -- (netr28)
DRV - [2009/11/27 22:16:00 | 000,172,032 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/11/27 22:15:36 | 000,173,056 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/09/16 08:02:40 | 000,027,136 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle)
DRV - [2009/08/30 20:19:59 | 000,721,904 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009/08/05 22:48:42 | 000,054,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fssfltr.sys -- (fssfltr)
DRV - [2009/05/14 15:49:32 | 000,038,240 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfp.sys -- (epfwwfp)
DRV - [2009/05/14 15:49:26 | 000,033,096 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2009/05/14 15:49:22 | 000,133,000 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfw.sys -- (epfw)
DRV - [2009/05/14 15:47:14 | 000,107,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009/05/14 15:41:10 | 000,114,472 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamon.sys -- (eamon)
DRV - [2008/12/04 20:34:52 | 000,328,728 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2008/12/02 23:11:00 | 007,643,904 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/01/18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006/11/02 11:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006/11/02 11:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006/11/02 11:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006/11/02 11:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006/11/02 11:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006/11/02 11:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006/11/02 11:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006/11/02 11:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006/11/02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 11:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006/11/02 11:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2006/11/02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 11:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006/11/02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2006/11/02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 11:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006/11/02 11:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006/11/02 11:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006/11/02 11:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006/11/02 11:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006/11/02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 11:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006/11/02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 11:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006/11/02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 11:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006/11/02 11:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2006/11/02 11:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2006/11/02 11:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2006/11/02 10:51:30 | 000,079,360 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\parport.sys.vir -- (Parport)
DRV - [2006/11/02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/11/02 09:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2006/11/02 02:50:52 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2006/09/24 15:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
DRV - [2006/08/28 17:12:04 | 000,013,312 | ---- | M] () [Kernel | System | Running] -- C:\Windows\system32\drivers\MTictwl.sys -- (NCPro)
DRV - [2006/08/28 17:12:04 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MTictwl.sys -- (MagicTune)
DRV - [2005/12/12 18:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
DRV - [2005/09/24 00:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [1996/04/03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15187&l=dis
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sk
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 9F 34 E7 D0 44 CA 01 [binary data]
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\URLSearchHook: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.ask.com?o=15187&l=dis"
FF - prefs.js..extensions.enabledItems: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:2.1.0.19
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/16 18:51:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/16 18:51:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Namoroka 3.6a1\extensions\\Components: C:\Program Files\Namoroka 3.6 Alpha 1\components [2009/10/14 14:23:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Namoroka 3.6a1\extensions\\Plugins: C:\Program Files\Namoroka 3.6 Alpha 1\plugins [2009/10/14 14:23:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/09/20 17:59:34 | 000,000,000 | ---D | M]

[2009/08/31 12:55:04 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Extensions
[2010/09/20 17:24:55 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\9n4hmwiy.default\extensions
[2009/08/31 12:50:52 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\9n4hmwiy.default\extensions\DTToolbar@toolbarnet.com
[2010/09/25 17:19:31 | 000,000,000 | ---D | M] -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\q9xdv8n2.default\extensions
[2009/09/17 18:45:13 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\q9xdv8n2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/09 14:15:21 | 000,000,000 | ---D | M] (BS Player Toolbar) -- C:\Users\eQ\AppData\Roaming\mozilla\Firefox\Profiles\q9xdv8n2.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
[2010/09/25 17:19:31 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/09 19:18:08 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/08/09 20:18:14 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010/08/09 20:18:14 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010/08/09 20:18:14 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010/08/09 20:18:14 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010/08/09 20:18:14 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010/08/09 20:18:14 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml

O1 HOSTS File: ([2010/09/24 14:34:21 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (TBSB00982 Class) - {DA3D342F-FF20-4E31-9E82-22334155730C} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (BS Player Toolbar) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\..\Toolbar\WebBrowser: (BS Player Toolbar) - {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:\Program Files\BS_Player\tbBS_P.dll (Conduit Ltd.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [reset] C:\Windows\reset.reg ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (LogMeIn Inc.)
O4 - Startup: C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RsGetPoints.lnk = C:\Users\eQ\Downloads\RS_account_premium_v1.2\RS account premium v1.2\RsGetPts.exe ()
O4 - Startup: C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-287188440-3596446558-1827478602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDow ... ab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDow ... rtScan.cab (NVIDIA Smart Scan)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 85.237.225.250 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\eQ\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O24 - Desktop BackupWallPaper: C:\Users\eQ\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta programu Windows Fotogaléria.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 7 Days ==========

[2010/09/24 14:34:23 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2010/09/24 14:32:39 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/09/24 14:32:39 | 000,000,000 | ---D | C] -- C:\Users\eQ\AppData\Local\temp
[2010/09/24 14:20:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/09/24 14:20:52 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/09/22 15:37:44 | 000,000,000 | ---D | C] -- C:\Users\eQ\AppData\Local\ESET
[2010/09/22 15:33:08 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/09/22 15:33:08 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/09/22 15:33:08 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/09/22 15:32:51 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/09/22 15:28:28 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/09/20 17:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/09/19 13:02:08 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/10/18 17:36:15 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\eQ\AppData\Roaming\pcouffin.sys
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2010/09/26 12:34:46 | 004,194,304 | -HS- | M] () -- C:\Users\eQ\NTUSER.DAT
[2010/09/26 12:20:18 | 000,000,964 | ---- | M] () -- C:\Users\eQ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RsGetPoints.lnk
[2010/09/26 12:19:57 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/26 12:19:57 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/26 12:19:56 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/09/26 12:19:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/26 12:19:51 | 3488,849,920 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/25 17:39:50 | 000,524,288 | -HS- | M] () -- C:\Users\eQ\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/09/25 17:39:50 | 000,065,536 | -HS- | M] () -- C:\Users\eQ\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/09/25 17:39:44 | 000,000,000 | ---- | M] () -- C:\Windows\System32\Access.dat
[2010/09/25 17:39:36 | 004,078,916 | -H-- | M] () -- C:\Users\eQ\AppData\Local\IconCache.db
[2010/09/25 15:54:35 | 000,000,460 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4EB8BB25-6DCA-4F8E-9AF3-9C2703B47272}.job
[2010/09/24 14:34:26 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/09/24 14:34:21 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/09/24 14:08:32 | 000,223,290 | ---- | M] () -- C:\Windows\System\latest.dat
[2010/09/24 14:08:31 | 000,000,124 | ---- | M] () -- C:\Windows\System\update.dat
[2010/09/22 15:20:02 | 003,849,240 | R--- | M] () -- C:\Users\eQ\Desktop\ComboFix.exe
[2010/09/22 14:45:47 | 000,202,282 | ---- | M] () -- C:\Windows\System\tubelist.dat
[2010/09/20 17:13:15 | 000,000,934 | ---- | M] () -- C:\Users\eQ\Documents\cc_20100920_171310.reg
[2010/09/19 18:18:18 | 000,001,041 | ---- | M] () -- C:\Users\eQ\AppData\Roaming\vso_ts_preview.xml
[2010/09/19 16:53:45 | 000,004,966 | ---- | M] () -- C:\Users\eQ\Documents\cc_20100919_165342.reg
[2010/09/19 13:02:09 | 000,000,804 | ---- | M] () -- C:\Users\eQ\Desktop\CCleaner.lnk
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/22 15:33:09 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/09/22 15:33:08 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/09/22 15:33:08 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/09/22 15:33:08 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/09/22 15:33:08 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/09/22 15:19:15 | 003,849,240 | R--- | C] () -- C:\Users\eQ\Desktop\ComboFix.exe
[2010/09/22 14:45:37 | 000,202,282 | ---- | C] () -- C:\Windows\System\tubelist.dat
[2010/09/20 17:13:13 | 000,000,934 | ---- | C] () -- C:\Users\eQ\Documents\cc_20100920_171310.reg
[2010/09/19 16:53:43 | 000,004,966 | ---- | C] () -- C:\Users\eQ\Documents\cc_20100919_165342.reg
[2010/09/19 13:02:09 | 000,000,804 | ---- | C] () -- C:\Users\eQ\Desktop\CCleaner.lnk
[2010/08/12 08:48:14 | 000,000,090 | ---- | C] () -- C:\Users\eQ\AppData\Local\fusioncache.dat
[2010/06/14 15:30:39 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/06/14 15:30:39 | 000,138,056 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\PnkBstrK.sys
[2010/05/05 14:26:16 | 000,000,000 | ---- | C] () -- C:\Windows\WinInit.ini
[2010/04/02 17:17:34 | 000,179,091 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010/02/27 22:46:30 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/02/14 11:32:13 | 000,119,930 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/02/14 11:12:46 | 000,119,930 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/11/27 22:31:02 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/10/18 17:38:15 | 000,001,041 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\vso_ts_preview.xml
[2009/10/18 17:37:56 | 000,000,034 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\pcouffin.log
[2009/10/18 17:36:15 | 000,007,887 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\pcouffin.cat
[2009/10/18 17:36:15 | 000,001,144 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\pcouffin.inf
[2009/10/08 15:49:29 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009/10/02 12:25:55 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys
[2009/09/19 20:13:48 | 000,000,000 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\downloads.m3u
[2009/09/19 11:41:42 | 000,000,723 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\burnaware.ini
[2009/09/19 10:17:46 | 000,000,162 | ---- | C] () -- C:\Users\eQ\AppData\Roaming\default.rss
[2009/09/18 17:39:42 | 000,004,767 | ---- | C] () -- C:\Windows\Irremote.ini
[2009/09/02 14:05:49 | 000,013,312 | ---- | C] () -- C:\Windows\System32\drivers\MTictwl.sys
[2009/08/30 20:05:56 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/08/21 19:54:11 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009/08/19 10:13:14 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/19 09:00:04 | 000,025,088 | ---- | C] () -- C:\Users\eQ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/09 13:48:02 | 000,001,356 | ---- | C] () -- C:\Users\eQ\AppData\Local\d3d9caps.dat
[2007/01/26 03:04:12 | 000,138,752 | ---- | C] () -- C:\Windows\System32\mase32.dll
[2007/01/26 03:04:12 | 000,027,648 | ---- | C] () -- C:\Windows\System32\ma32.dll
[2006/11/02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys

========== Files - Unicode (All) ==========
[2010/04/18 10:37:29 | 000,000,000 | ---D | M](C:\Users\eQ\AppData\Roaming\???????sAppData) -- C:\Users\eQ\AppData\Roaming\敎潲䍄敔灭慬整sAppData
[2010/04/18 10:37:29 | 000,000,000 | ---D | M](C:\Users\eQ\AppData\Roaming\???????sAppData) -- C:\Users\eQ\AppData\Roaming\敎潲䍄敔灭慬整sAppData
(C:\Users\eQ\AppData\Roaming\???????sAppData) -- C:\Users\eQ\AppData\Roaming\敎潲䍄敔灭慬整sAppData

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:890CC2F3
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:66633281
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:0888F409
< End of report >

Uživatelský avatar
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 pro 2005 20:59
Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#27 Příspěvek od earl »

Jeste jednou:

Odinstalujte ten ESET,v dalsim logu uz chci videt Avast nebo Aviru (Avast ma navic emailovy stit).

:arrow: Znovu spustte OTL a zkopirujte do policka pod nazvem "Vlastni skenovani/opravy" zeleny text:

Kód: Vybrat vše

:otl
O4 - HKLM..\Run: [reset] C:\Windows\reset.reg ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
:Files
C:\Windows\reset.reg
:Commands
[EMPTYTEMP]
[RESETHOSTS]
[CREATERESTOREPOINT] 
Kliknete na Opravit, mozna probehne restart,pak se vytvori log, jeho obsah sem zkopirujte. Pokud se log neotevre, najdete ho v miste spusteni OTL.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#28 Příspěvek od nemamcas »

Co som cital tak AVAST neni moc dobry...

Ked som ho mal naposledy tak sa mi zaviroval stary PC

Uživatelský avatar
earl
VIP
VIP
Příspěvky: 1279
Registrován: 14 pro 2005 20:59
Bydliště: Brno

Re: Nika Mix hudba hra z nicoho nic

#29 Příspěvek od earl »

Avast je jeden z nejlepsich free antiviru,to je neoddiskutovatelny fakt.
Ked som ho mal naposledy tak sa mi zaviroval stary PC
To nebylo Avastem,nybrz uzivatelem - to neberte osobne,tak to proste je,ani nejlepsi bezpecnostni reseni neni nic platne,kdyz uzivatel je nezodpovedny

a klika na co muze a chodi na weby tak,kam nema...

Rekl jsem odinstalovat ESET,mate ho nelegalne,o tom tu diskutovat tez nebudeme.

Vlozte sem novy log z OTL at to muzeme dorazit.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
ObrázekAKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ObrázekZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
ObrázekNEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!
Obrázek Obrázek
Obrázek Obrázek
___________________________________________________________
----------------------earl@forum.viry.cz-----------------------

nemamcas
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 18 zář 2010 09:02

Re: Nika Mix hudba hra z nicoho nic

#30 Příspěvek od nemamcas »

Takze mam mat vlastne hrosi antivir jak mam ? alebo jak to mam chapat...

Odpovědět