Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosím o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

prosím o kontrolu

#1 Příspěvek od out_of_space »

Prosím o kontrolu

Logfile of random's system information tool 1.08 (written by random/random)
Run by James at 2010-10-01 14:55:19
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 20 GB (20%) free of 100 GB
Total RAM: 3070 MB (78% free)


======Scheduled tasks folder======

C:\WINDOWS\tasks\Automatic troubleshooting.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{014DA6C1-189F-421a-88CD-07CFE51CFF10}]
My Search BHO - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL [2009-07-28 253952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-05-12 50376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2010-01-17 520192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
ZoneAlarm Toolbar - C:\Program Files\ZoneAlarm\tbZone.dll [2010-05-09 2517088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Security Engine Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2010-05-18 591336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{014DA6C9-189F-421a-88CD-07CFE51CFF10} - My Search Bar - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL [2009-07-28 253952]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2010-01-17 520192]
{66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - ZoneAlarm Toolbar - C:\Program Files\ZoneAlarm\tbZone.dll [2010-05-09 2517088]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2010-05-18 591336]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C6501Sound"=RunDll32 c6501.cpl,CMICtrlWnd []
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"nTrayFw"=C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe [2005-12-21 270336]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-09-05 417792]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2010-05-20 1043968]
"ISW"=C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [2010-05-18 730600]
"nwiz"=nwiz.exe /installquiet []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-07-08 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-07-08 13762560]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\James\Nabídka Start\Programy\Po spuštění
GIGABYTE Gamer HUD.lnk - C:\Program Files\GIGABYTE\Gamer HUD\HUD.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="wbsys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll [2010-06-07 214320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispAppearancePage"=0
"NoColorChoice"=0
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0
"NoVisualStyleChoice"=0
"NoSizeChoice"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SynchronousMachineGroupPolicy"=0
"SynchronousUserGroupPolicy"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSMBalloonTip"=1
"NoDriveTypeAutoRun"=145
"MemCheckBoxInRunDlg"=0
"NoClose"=0
"NoAutoTrayNotify"=0
"NoResolveTrack"=0
"NoResolveSearch"=1
"NoWelcomeScreen"=1
"NoRecentDocsNetHood"=1
"NoDesktopCleanupWizard"=1
"NoSharedDocuments"=1
"NoThemesTab"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoStrCmpLogical"=1
"NoClose"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"D:\hry\Painkiller Overdose\Bin\Overdose.exe"="D:\hry\Painkiller Overdose\Bin\Overdose.exe:*:Enabled:Painkiller Overdose"
"D:\hry\Painkiller Overdose\Bin\OverdoseEditor.exe"="D:\hry\Painkiller Overdose\Bin\OverdoseEditor.exe:*:Enabled:Painkiller Overdose Editor"
"D:\hry\Painkiller Overdose\Bin\OverdoseServer.exe"="D:\hry\Painkiller Overdose\Bin\OverdoseServer.exe:*:Enabled:Painkiller Overdose Console Server"
"D:\hry\Heroes of Might and Magic V\bin\H5_Game.exe"="D:\hry\Heroes of Might and Magic V\bin\H5_Game.exe:*:Enabled:Heroes of Might and Magic V"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\hry\Prince of Persia\Prince of Persia.exe"="D:\hry\Prince of Persia\Prince of Persia.exe:*:Enabled:Prince of Persia Dx"
"D:\hry\Prince of Persia\PrinceOfPersia_Launcher.exe"="D:\hry\Prince of Persia\PrinceOfPersia_Launcher.exe:*:Enabled:Prince of Persia Update"
"D:\hry\racedriver GRID\GRID.exe"="D:\hry\racedriver GRID\GRID.exe:*:Enabled:GRID"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\hry\Warcraft 3\Warcraft III\Warcraft III.exe"="D:\hry\Warcraft 3\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"D:\hry\hellgate\Launcher.exe"="D:\hry\hellgate\Launcher.exe:*:Enabled:Hellgate: London"
"D:\hry\hawx\H.A.W.X\HAWX.exe"="D:\hry\hawx\H.A.W.X\HAWX.exe:*:Disabled:HAWX"
"D:\hry\left4dead\left4dead.exe"="D:\hry\left4dead\left4dead.exe:*:Enabled:left4dead"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"D:\hry\Dragon Age\bin_ship\daorigins.exe"="D:\hry\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game"
"D:\hry\Dragon Age\DAOriginsLauncher.exe"="D:\hry\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\hry\COD4\iw3mp.exe"="D:\hry\COD4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"D:\hry\Sins of a Solar Empire\Sins of a Solar Empire.exe"="D:\hry\Sins of a Solar Empire\Sins of a Solar Empire.exe:*:Enabled:Sins of a Solar Empire"
"D:\hry\dirt2\dirt2_game.exe"="D:\hry\dirt2\dirt2_game.exe:*:Enabled:DiRT2"
"D:\hry\avatar\bin\Avatar.exe"="D:\hry\avatar\bin\Avatar.exe:*:Enabled:James Cameron's AVATAR(tm): THE GAME"
"D:\hry\avatar\bin\AvatarLauncher.exe"="D:\hry\avatar\bin\AvatarLauncher.exe:*:Enabled:Updater"
"D:\hry\Dragon Age\bin_ship\daupdatersvc.service.exe"="D:\hry\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater"
"D:\hry\assassins creed\AssassinsCreed_Dx9.exe"="D:\hry\assassins creed\AssassinsCreed_Dx9.exe:*:Enabled:Assassin's Creed Dx9"
"D:\hry\assassins creed\AssassinsCreed_Dx10.exe"="D:\hry\assassins creed\AssassinsCreed_Dx10.exe:*:Enabled:Assassin's Creed Dx10"
"D:\hry\assassins creed\AssassinsCreed_Launcher.exe"="D:\hry\assassins creed\AssassinsCreed_Launcher.exe:*:Enabled:Assassin's Creed Update"
"D:\hry\bf bc2\BFBC2Updater.exe"="D:\hry\bf bc2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"D:\hry\gta4\Rockstar Games Social Club\RGSCLauncher.exe"="D:\hry\gta4\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"D:\hry\gta4\Grand Theft Auto IV\LaunchGTAIV.exe"="D:\hry\gta4\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"D:\hry\Mass Effect 2\Binaries\MassEffect2.exe"="D:\hry\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Hra"
"D:\hry\Mass Effect 2\MassEffect2Launcher.exe"="D:\hry\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Spustit"
"D:\hry\Alpha protocol\Binaries\APGame.exe"="D:\hry\Alpha protocol\Binaries\APGame.exe:*:Enabled:Alpha Protocol"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
"D:\hry\singularity\Binaries\Singularity.exe"="D:\hry\singularity\Binaries\Singularity.exe:*:Enabled:Singularity"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-10-01 13:31:55 ----D---- C:\Program Files\trend micro
2010-10-01 13:31:54 ----D---- C:\rsit
2010-09-29 08:32:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$
2010-09-26 20:15:54 ----A---- C:\WINDOWS\system32\wbsys.dll
2010-09-23 18:53:26 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{9A4E21A0-83F7-4E3F-8A2D-BA379A5A8EBB}
2010-09-19 10:34:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-09-19 00:21:36 ----D---- C:\Program Files\NexusFont
2010-09-17 10:45:12 ----D---- C:\WINDOWS\B83FC356B7C0441F8A4DD71E088E7974.TMP
2010-09-17 07:47:48 ----A---- C:\WINDOWS\system32\MRT.exe
2010-09-16 15:58:58 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-09-16 15:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-09-16 15:58:13 ----A---- C:\WINDOWS\imsins.BAK
2010-09-16 15:58:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-09-15 22:57:12 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-09-15 22:57:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-09-15 22:56:59 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-09-15 22:56:52 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-09-15 22:56:46 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-09-15 22:56:34 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-09-15 22:56:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-09-15 22:56:23 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-09-15 22:56:16 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-09-15 22:56:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-09-15 22:56:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-09-15 22:55:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-09-15 22:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-09-15 22:55:44 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-09-15 22:55:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-09-15 22:55:31 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-09-15 22:55:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-09-15 22:55:18 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-09-15 22:55:13 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-09-15 22:55:06 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-09-15 22:54:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-09-15 22:54:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-09-15 22:54:45 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-09-15 22:54:37 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-09-15 22:54:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-09-15 22:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-09-15 22:54:17 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-09-15 22:54:10 ----HDC---- C:\WINDOWS\$NtUninstallKB982802$
2010-09-15 22:54:03 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-09-15 22:51:34 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-09-15 22:51:27 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-09-15 22:51:21 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-09-15 22:51:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-09-15 22:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-09-15 22:50:58 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-09-15 22:50:53 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-09-15 22:50:48 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-09-15 22:50:42 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-09-15 22:50:37 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-09-15 22:50:31 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-09-15 22:50:25 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-09-15 22:50:12 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-09-15 22:49:58 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-09-15 22:49:51 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-09-15 22:49:42 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-09-15 22:49:36 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-09-15 22:49:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-09-15 22:49:22 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-09-15 22:49:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-09-15 22:49:11 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-09-15 22:49:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-09-15 22:49:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-09-15 22:48:55 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-09-15 22:48:49 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-09-15 22:48:38 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-09-15 22:37:32 ----D---- C:\Documents and Settings\James\Data aplikací\CheckPoint
2010-09-15 22:36:54 ----D---- C:\Program Files\ZoneAlarm
2010-09-15 22:36:54 ----D---- C:\Program Files\Conduit
2010-09-15 22:35:38 ----D---- C:\Program Files\CheckPoint
2010-09-15 22:35:36 ----A---- C:\WINDOWS\system32\vsregexp.dll
2010-09-15 22:35:35 ----A---- C:\WINDOWS\system32\zlcommdb.dll
2010-09-15 22:35:35 ----A---- C:\WINDOWS\system32\zlcomm.dll
2010-09-15 22:35:33 ----A---- C:\WINDOWS\system32\vswmi.dll
2010-09-15 22:35:32 ----A---- C:\WINDOWS\system32\zpeng25.dll
2010-09-15 22:35:32 ----A---- C:\WINDOWS\system32\vsmonapi.dll
2010-09-15 22:35:31 ----A---- C:\WINDOWS\system32\vsdatant.sys
2010-09-15 22:35:12 ----A---- C:\WINDOWS\system32\vsutil.dll
2010-09-15 22:35:12 ----A---- C:\WINDOWS\system32\vsinit.dll
2010-09-15 21:08:07 ----D---- C:\WINDOWS\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2010-09-15 19:51:07 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-09-13 21:44:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-09-13 21:44:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-09-13 21:44:33 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-09-13 21:44:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-09-13 21:44:04 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-09-13 21:43:59 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-09-13 21:43:55 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-09-13 21:43:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-09-13 21:43:38 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-09-13 21:41:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-09-13 21:41:25 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-09-13 21:41:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-09-13 21:41:14 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-09-13 21:41:08 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-09-13 21:41:03 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-09-13 21:40:59 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2010-09-13 21:40:43 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-09-13 21:40:38 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-09-13 21:40:29 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-09-13 19:57:21 ----D---- C:\Documents and Settings\James\Data aplikací\CBS Interactive
2010-09-13 19:33:55 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-09-13 18:21:57 ----D---- C:\Program Files\ImageShack Uploader
2010-09-13 17:03:38 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-09-13 17:03:30 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-09-13 17:03:23 ----D---- C:\WINDOWS\ie8updates
2010-09-13 17:03:17 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-09-13 17:00:55 ----D---- C:\Program Files\MSXML 4.0
2010-09-13 17:00:37 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2010-09-13 17:00:24 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-09-13 16:47:41 ----D---- C:\Program Files\NOS
2010-09-13 16:47:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\NOS
2010-09-13 16:34:49 ----D---- C:\WINDOWS\system32\NtmsData
2010-09-13 16:34:14 ----D---- C:\Documents and Settings\James\Data aplikací\Avira
2010-09-13 16:32:31 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2010-09-13 16:32:30 ----D---- C:\Program Files\Avira
2010-09-13 16:32:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-09-13 16:32:30 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2010-09-13 16:32:30 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2010-09-13 16:32:30 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2010-09-13 16:32:30 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2010-09-13 16:19:40 ----D---- C:\WINDOWS\system32\PreInstall
2010-09-13 16:19:38 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-09-13 16:19:38 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-13 16:19:36 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-09-13 16:16:42 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-09-13 16:16:42 ----A---- C:\WINDOWS\system32\wups2.dll
2010-09-13 16:16:42 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-09-13 16:16:42 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-09-13 16:16:42 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-09-13 15:35:38 ----D---- C:\Documents and Settings\James\Data aplikací\Mozilla
2010-09-13 15:33:56 ----D---- C:\Program Files\Mozilla Firefox
2010-09-13 14:07:15 ----D---- C:\Documents and Settings\James\Data aplikací\Motive
2010-09-13 14:06:54 ----D---- C:\Program Files\Common Files\Motive
2010-09-13 14:06:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Motive
2010-09-04 12:01:28 ----D---- C:\Program Files\directx

======List of files/folders modified in the last 1 months======

2010-10-01 14:55:45 ----D---- C:\WINDOWS\Prefetch
2010-10-01 14:55:31 ----D---- C:\WINDOWS\Internet Logs
2010-10-01 14:53:06 ----D---- C:\WINDOWS\Temp
2010-10-01 14:52:15 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-01 13:31:55 ----RD---- C:\Program Files
2010-10-01 12:22:50 ----D---- C:\WINDOWS\Registration
2010-09-30 21:15:32 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-30 19:41:30 ----AD---- C:\WINDOWS
2010-09-29 20:17:47 ----D---- C:\pracovní
2010-09-29 18:39:11 ----AC---- C:\WINDOWS\NeroDigital.ini
2010-09-29 08:32:36 ----HD---- C:\WINDOWS\inf
2010-09-29 08:32:28 ----D---- C:\WINDOWS\system32
2010-09-28 18:05:04 ----AC---- C:\WINDOWS\win.ini
2010-09-26 21:26:19 ----D---- C:\Program Files\Apophysis 7x
2010-09-26 20:15:53 ----D---- C:\Program Files\Stardock
2010-09-23 18:53:26 ----SHD---- C:\WINDOWS\Installer
2010-09-23 18:53:26 ----SHD---- C:\Config.Msi
2010-09-19 21:35:47 ----RSD---- C:\WINDOWS\assembly
2010-09-19 21:35:47 ----D---- C:\WINDOWS\Microsoft.NET
2010-09-19 20:55:15 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-09-19 20:52:33 ----D---- C:\WINDOWS\WinSxS
2010-09-19 20:51:56 ----D---- C:\WINDOWS\system32\en-us
2010-09-19 20:51:53 ----D---- C:\Program Files\Microsoft.NET
2010-09-18 00:15:30 ----D---- C:\Documents and Settings\James\Data aplikací\Bioshock2
2010-09-17 10:46:07 ----D---- C:\WINDOWS\Help
2010-09-17 10:45:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-17 10:45:23 ----D---- C:\WINDOWS\system32\drivers
2010-09-17 10:45:10 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-09-17 10:44:57 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-09-17 10:44:01 ----D---- C:\NVIDIA
2010-09-17 09:15:57 ----D---- C:\Program Files\NVIDIA Corporation
2010-09-17 07:47:51 ----D---- C:\WINDOWS\Debug
2010-09-15 22:51:49 ----D---- C:\Program Files\Internet Explorer
2010-09-15 22:49:37 ----D---- C:\Program Files\Outlook Express
2010-09-15 22:37:32 ----D---- C:\WINDOWS\system32\ZoneLabs
2010-09-15 21:14:50 ----D---- C:\WINDOWS\system32\DirectX
2010-09-15 21:07:22 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-14 19:45:40 ----SD---- C:\WINDOWS\Tasks
2010-09-14 19:36:34 ----D---- C:\WINDOWS\system32\wbem
2010-09-14 19:36:34 ----D---- C:\WINDOWS\AppPatch
2010-09-13 21:44:13 ----D---- C:\WINDOWS\system32\CatRoot
2010-09-13 21:40:40 ----D---- C:\Program Files\Movie Maker
2010-09-13 19:37:20 ----D---- C:\WINDOWS\Network Diagnostic
2010-09-13 16:47:43 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-09-13 16:34:49 ----D---- C:\WINDOWS\repair
2010-09-13 16:16:46 ----D---- C:\WINDOWS\SoftwareDistribution
2010-09-13 15:15:07 ----SD---- C:\Documents and Settings\James\Data aplikací\Microsoft
2010-09-13 14:06:54 ----D---- C:\Program Files\Common Files
2010-09-12 20:43:30 ----D---- C:\Documents and Settings\James\Data aplikací\vlc
2010-09-02 16:07:19 ----D---- C:\Documents and Settings\James\Data aplikací\dvdcss

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-04-25 100736]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-11-20 43872]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\system32\drivers\sfdrv01.sys [2006-05-10 51200]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\system32\drivers\sfhlp02.sys [2006-05-10 6656]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS\system32\drivers\sfsync04.sys [2006-05-10 52224]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-08-17 721904]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2006-10-18 12664]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 NVTCP;NVIDIA TCP/IP Protocol Driver; C:\WINDOWS\System32\DRIVERS\NVTcp.sys [2006-04-15 101888]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2010-05-13 532224]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-08-16 279712]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 ISWKL;ZoneAlarm Toolbar ISWKL; \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys []
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-08-16 25888]
R2 nxsIO32;NextSensor Kernel I/O Driver; \??\C:\WINDOWS\System32\DRIVERS\nxsIO32.sys []
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface; C:\WINDOWS\system32\drivers\c6501.sys [2007-07-10 1310720]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-07-08 7967712]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-04-15 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-04-15 13056]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 aitrzw3j;aitrzw3j; C:\WINDOWS\system32\drivers\aitrzw3j.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 ultradfg;ultradfg; C:\WINDOWS\System32\DRIVERS\ultradfg.sys [2008-11-13 24576]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2009-01-15 29184]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 astcc;AST Service; C:\WINDOWS\SYSTEM32\astsrv.exe [2008-05-07 57344]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-03-19 731840]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe [2005-12-21 139264]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2005-09-23 20543]
R2 IswSvc;ZoneAlarm Toolbar IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [2010-05-18 493032]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2005-12-21 127035]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2005-12-21 61503]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-07-08 168004]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-06-09 66872]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-10-30 1021256]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2010-05-20 2437176]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:\WINDOWS\system32\sfrem01.exe [2006-05-10 353912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater; D:\hry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-08-17 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 nosGetPlusHelper;getPlus(R) Helper 3004; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2009-11-29 435016]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosím o kontrolu

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Jaky pouzivate antivir - vidim tam Aviru a NODa :o

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

Re: prosím o kontrolu

#3 Příspěvek od out_of_space »

Zdravím,
nyní používám Aviru, nod jsem přem časem odinstaloval pomocí revouninstal, ale zřejmě něco zůstalo v registrech.

Jinak jsem použil Combofix, zde je log:


ComboFix 10-10-01.01 - James 02.10.2010 9:00.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3070.2566 [GMT 2:00]
Spuštěný z: c:\documents and settings\James\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ActiveArmor Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Vytvořen nový Bod Obnovení
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\MySearch
c:\program files\MySearch\bar\1.bin\NPMYSRCH.DLL
c:\program files\MySearch\bar\1.bin\S4BAR.DLL
c:\program files\MySearch\bar\1.bin\S4FFXTBR.JAR
c:\program files\MySearch\bar\1.bin\S4FFXTBR.MANIFEST
c:\program files\MySearch\bar\1.bin\S4NTSTBR.JAR
c:\program files\MySearch\bar\1.bin\S4NTSTBR.MANIFEST
c:\program files\MySearch\bar\Cache\files.ini
c:\program files\MySearch\bar\History\search2
D:\install.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-02 do 2010-10-02 )))))))))))))))))))))))))))))))
.

2010-10-01 11:31 . 2010-10-01 12:55 -------- d-----w- c:\program files\trend micro
2010-10-01 11:31 . 2010-10-01 11:32 -------- d-----w- C:\rsit
2010-09-26 18:15 . 2008-04-26 14:14 42672 ----a-w- c:\windows\system32\wbsys.dll
2010-09-23 16:53 . 2010-07-02 17:45 3321984 -c--a-w- c:\documents and settings\All Users\Data aplikací\{9A4E21A0-83F7-4E3F-8A2D-BA379A5A8EBB}\apophysis7x-setup.exe
2010-09-19 08:34 . 2010-08-30 12:34 1496064 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-09-19 08:34 . 2010-08-30 12:33 43008 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-09-19 08:34 . 2010-08-30 12:33 338944 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-09-19 08:34 . 2010-08-30 12:33 346112 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-09-18 22:21 . 2010-09-18 22:22 -------- d-----w- c:\program files\NexusFont
2010-09-17 08:45 . 2010-09-17 08:45 -------- d-----w- c:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP
2010-09-17 07:15 . 2010-09-17 07:16 232968 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-09-17 07:15 . 2010-09-17 07:16 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-09-17 07:15 . 2010-09-17 07:16 232968 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-09-16 09:56 . 2010-09-16 09:56 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2010-09-15 20:37 . 2010-09-01 17:56 52224 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
2010-09-15 20:37 . 2010-09-01 17:56 101376 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
2010-09-15 20:36 . 2010-09-15 20:36 -------- d-----w- c:\program files\ZoneAlarm
2010-09-15 20:36 . 2010-09-15 20:36 -------- d-----w- c:\program files\Conduit
2010-09-15 20:35 . 2010-09-15 20:35 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-09-15 20:35 . 2010-09-15 20:35 -------- d-----w- c:\program files\CheckPoint
2010-09-15 20:35 . 2010-05-20 16:10 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-09-15 20:35 . 2010-05-20 16:10 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-09-15 20:35 . 2010-05-20 16:10 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-09-15 19:08 . 2010-09-15 19:08 -------- d-----w- c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2010-09-15 18:00 . 2010-06-24 12:27 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-09-15 18:00 . 2010-06-24 12:27 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-09-15 18:00 . 2010-06-24 12:27 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-09-15 18:00 . 2010-06-24 12:27 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-09-15 18:00 . 2010-06-24 12:27 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-09-15 18:00 . 2010-06-24 12:27 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-09-15 17:51 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-09-13 17:57 . 2010-09-13 17:57 100157 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\uninst.exe
2010-09-13 17:33 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-09-13 17:33 . 2008-06-14 17:35 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-09-13 16:56 . 2010-04-28 18:15 2192128 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-09-13 16:21 . 2010-09-13 16:21 -------- d-----w- c:\program files\ImageShack Uploader
2010-09-13 15:03 . 2010-09-15 20:56 -------- d-----w- c:\windows\ie8updates
2010-09-13 15:00 . 2010-09-13 15:00 -------- d-----w- c:\program files\MSXML 4.0
2010-09-13 14:47 . 2010-09-13 14:47 -------- d-----w- c:\program files\NOS
2010-09-13 14:34 . 2010-10-01 10:43 -------- d-----w- c:\windows\system32\NtmsData
2010-09-13 14:32 . 2010-09-13 14:32 -------- d-----w- c:\program files\Avira
2010-09-13 14:32 . 2010-03-01 08:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-13 14:32 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-13 14:32 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-13 14:32 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-13 14:19 . 2010-09-16 10:15 -------- d--h--w- c:\windows\$hf_mig$
2010-09-13 14:16 . 2009-08-06 17:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-09-13 13:35 . 2010-09-13 13:35 0 ----a-w- c:\windows\nsreg.dat
2010-09-13 12:06 . 2010-09-14 17:37 -------- d-----w- c:\program files\Common Files\Motive
2010-09-04 10:01 . 2010-09-04 10:01 -------- d-----w- c:\program files\directx
2010-09-03 19:08 . 2010-09-03 19:08 2618368 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\TechTracker.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-02 06:56 . 2010-08-21 07:23 44183242 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-09-26 19:26 . 2010-07-09 12:18 -------- d-----w- c:\program files\Apophysis 7x
2010-09-26 18:15 . 2010-03-24 15:25 -------- d-----w- c:\program files\Stardock
2010-09-19 18:55 . 2001-10-25 14:00 93068 ----a-w- c:\windows\system32\perfc005.dat
2010-09-19 18:55 . 2001-10-25 14:00 479232 ----a-w- c:\windows\system32\perfh005.dat
2010-09-19 18:51 . 2009-11-10 23:58 -------- d-----w- c:\program files\Microsoft.NET
2010-09-17 08:45 . 2009-07-08 13:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-17 07:15 . 2009-07-08 12:54 -------- d-----w- c:\program files\NVIDIA Corporation
2010-09-15 20:35 . 2010-09-15 20:35 -------- d-----w- c:\program files\CheckPoint
2010-09-15 19:07 . 2009-07-08 12:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-17 13:17 . 2008-04-14 05:52 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:50 . 2009-08-17 11:24 -------- d-----w- c:\program files\CDex_150
2010-08-15 19:37 . 2009-07-16 14:03 -------- d-----w- c:\program files\PDF
2010-08-15 19:37 . 2009-07-16 14:02 -------- d-----w- c:\program files\Common Files\602PHS
2010-08-15 19:36 . 2010-05-16 20:22 -------- d-----w- c:\program files\JoWooD Productions Software AG
2010-08-08 07:31 . 2010-08-08 07:31 -------- d-----w- c:\program files\CCleaner
2010-08-03 19:48 . 2010-08-03 19:48 -------- d-----w- c:\program files\Zone Labs
2010-07-22 15:46 . 2008-04-14 05:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-15 02:08 . 2010-07-15 02:08 63827 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\zlib.dll
2010-07-15 02:07 . 2010-07-15 02:07 81920 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\xmltok.dll
2010-07-15 02:07 . 2010-07-15 02:07 61440 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\xmlparse.dll
2010-07-09 22:38 . 2010-01-31 10:38 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-07-09 22:38 . 2010-01-31 10:38 10260480 ----a-w- c:\windows\system32\nvcompiler.dll
2010-07-09 22:38 . 2009-07-08 13:04 604776 -c--a-w- c:\windows\system32\nvudisp.exe
2010-07-07 11:46 . 2009-07-08 12:51 604776 -c--a-w- c:\windows\system32\NVUNINST.EXE
2003-11-03 16:07 . 2004-04-23 16:06 499712 ----a-w- c:\program files\msvcp71.dll
2003-11-03 16:07 . 2004-04-23 16:06 348160 ----a-w- c:\program files\msvcr71.dll
2003-05-30 08:22 . 2003-09-08 08:09 344064 ----a-r- c:\program files\msvcr70.dll
2002-01-05 02:40 . 2003-09-08 08:09 487424 ----a-w- c:\program files\msvcp70.dll
.

------- Sigcheck -------

[-] 2009-01-31 . 959B66A9B529BA5C4B1B973F1FCD98EE . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 09:50 2517088 ----a-w- c:\program files\ZoneAlarm\tbZone.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-12-21 270336]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-04 417792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-20 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-18 730600]
"nwiz"="nwiz.exe" [2009-07-08 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-08 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-08 13762560]

c:\documents and settings\James\Nabˇdka Start\Programy\Po spuçtŘnˇ\
GIGABYTE Gamer HUD.lnk - c:\program files\GIGABYTE\Gamer HUD\HUD.exe [2008-6-26 1940992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2010-06-07 13:59 214320 ----a-w- c:\program files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"OEXPRESS"=c:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"d:\\hry\\Painkiller Overdose\\Bin\\Overdose.exe"=
"d:\\hry\\Painkiller Overdose\\Bin\\OverdoseEditor.exe"=
"d:\\hry\\Painkiller Overdose\\Bin\\OverdoseServer.exe"=
"d:\\hry\\Heroes of Might and Magic V\\bin\\H5_Game.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\hry\\Prince of Persia\\Prince of Persia.exe"=
"d:\\hry\\Prince of Persia\\PrinceOfPersia_Launcher.exe"=
"d:\\hry\\racedriver GRID\\GRID.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\hry\\Warcraft 3\\Warcraft III\\Warcraft III.exe"=
"d:\\hry\\hellgate\\Launcher.exe"=
"d:\\hry\\hawx\\H.A.W.X\\HAWX.exe"=
"d:\\hry\\left4dead\\left4dead.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\hry\\Dragon Age\\bin_ship\\daorigins.exe"=
"d:\\hry\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\hry\\COD4\\iw3mp.exe"=
"d:\\hry\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"d:\\hry\\dirt2\\dirt2_game.exe"=
"d:\\hry\\avatar\\bin\\Avatar.exe"=
"d:\\hry\\avatar\\bin\\AvatarLauncher.exe"=
"d:\\hry\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"d:\\hry\\assassins creed\\AssassinsCreed_Dx9.exe"=
"d:\\hry\\assassins creed\\AssassinsCreed_Dx10.exe"=
"d:\\hry\\assassins creed\\AssassinsCreed_Launcher.exe"=
"d:\\hry\\bf bc2\\BFBC2Updater.exe"=
"d:\\hry\\gta4\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\hry\\gta4\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\hry\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"d:\\hry\\Mass Effect 2\\MassEffect2Launcher.exe"=
"d:\\hry\\Alpha protocol\\Binaries\\APGame.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\hry\\singularity\\Binaries\\Singularity.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [13.9.2010 16:32 135336]
R2 ekrn;ESET Service;c:\program files\Eset\ESET NOD32 Antivirus\ekrn.exe [19.3.2009 11:44 731840]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [18.5.2010 16:01 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [18.5.2010 16:01 493032]
R2 nxsIO32;NextSensor Kernel I/O Driver;c:\windows\system32\drivers\nxsIO32.sys [28.7.2009 12:44 2208]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [30.10.2009 16:05 1021256]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;c:\windows\system32\drivers\c6501.sys [8.7.2009 14:58 1310720]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 8:24 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\hry\Dragon Age\bin_ship\daupdatersvc.service.exe [15.12.2009 22:07 25832]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [17.7.2009 10:51 1527900]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [14.4.2008 7:52 14336]
S3 ultradfg;ultradfg;c:\windows\system32\drivers\ultradfg.sys [13.11.2008 11:52 24576]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.7.2009 11:04 721904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-10-02 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-10-30 14:12]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
FF - ProfilePath - c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=FF_5&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\NOS\bin\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-C6501Sound - c6501.cpl



**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1659004503-861567501-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:f1,25,c1,ac,c6,e1,3b,54,1f,f6,ef,e7,b4,8d,03,97,3d,f4,57,a8,2f,85,d0,
e9,28,df,a0,58,5f,69,ac,8d,c2,31,77,72,6b,1a,28,81,5e,70,23,6f,f4,5a,52,05,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50

[HKEY_USERS\S-1-5-21-1659004503-861567501-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:81,b5,1b,eb,97,f1,bb,4d,77,c8,f6,03,ad,0b,c1,fc,72,4d,6d,c4,49,
d0,3f,fb,7f,3c,e3,81,1f,2e,00,29,0d,ca,9d,d1,8f,1e,f2,90,00,fd,a3,57,c4,46,\
"rkeysecu"=hex:8c,4d,e2,8d,7d,49,bf,be,cc,f4,34,3c,02,83,34,77

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
@DACL=
"DefaultSettings"="99:{C6DDA450-F687-55DF-CA23-1A5083308C5D}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
@DACL=
"CTE_32 Name"="2455134:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 1.1]
@DACL=
"dat"="806585365:{5D0C82CA-39DA-ED40-1AF8-1541D495F249}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
@DACL=
"DefaultSettings"="2455155:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}*\Install*Loc\xga-1\dat]
@DACL=
"default"="516231781:{003A0A97-CEB0-7714-2C08-96957FF709B9}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 3.x]
@DACL=
"dat"="1767914624:{210F4669-23D3-2C3F-D082-F9E94344ED41}"

[HKEY_LOCAL_MACHINE\software\Microsoft\WinXGA*\Providers*\{D41D8CD9-8F00-B204-E980-0998ECF8427E}\Current*Set\xga-1\ver]
@DACL=
"KnownSvcs"="923714714:{F4BEA03D-BA0E-5CA1-869B-39A0711959D3}"

[HKEY_LOCAL_MACHINE\software\XBMga*\UUIDs\{59D3E28F-07E2-A406-4061-94B4A182BBA6}\xga-1\Install*Loc]
@DACL=
"{19620715-0001-1211-574574-30001}"="234521934:{58829A3F-90C8-F4E7-5A83-E255048ED5C9}"

[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
@DACL=
"CTE_32 Name"="6:{19C42D30-D844-8A07-12A4-E783E7D228F7}"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1208)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\program files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(1312)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Celkový čas: 2010-10-02 09:08:51
ComboFix-quarantined-files.txt 2010-10-02 07:08

Před spuštěním: Volných bajtů: 20 815 339 520
Po spuštění: Volných bajtů: 21 549 518 848

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - B91E7DFFDB660FE4CA1A7A518AA1D3B1

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosím o kontrolu

#4 Příspěvek od vyosek »

:arrow: Po ESETu tam zustal i drivery atd - domazeme :wink:

:arrow: Dale tam vidim dva firewally - ActiveArmor Firewall a ZoneAlarm Firewall, jeden odinstalujte - doporucuji si ponechat ZoneAlarm

:arrow: Nasledujici soubory otestujte na VirusTotalu (viz muj podpis)
  • c:\windows\system32\sfcfiles.dll
  • Kliknete na Prochazet
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Pokud napise Soubor byl jiz testovan, dejte otestovat znovu
  • Kliknete na Otestovat soubor
  • Vysledek analyzy sem vlozte (jako odkaz)
:arrow: Stahnete SytemLook (viz muj podpis) a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :filefind
    sfcfiles.dll
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

Re: prosím o kontrolu

#5 Příspěvek od out_of_space »

Zkoušel jsem odistalovat acivearmor, ale nevím jak. V Revu ani přidat/odebrat programy jsem ho nenašel. Každopádně ho mám vypnutý a nepoužívám ho.

Virus total: http://www.virustotal.com/file-scan/rep ... 1286006064

Systemlook:
SystemLook 04.09.10 by jpshortstuff
Log created at 09:46 on 02/10/2010 by James
Administrator - Elevation successful

========== filefind ==========

Searching for "sfcfiles.dll"
C:\WINDOWS\system32\sfcfiles.dll --a--c- 1571840 bytes [15:35 31/01/2009] [15:35 31/01/2009] 959B66A9B529BA5C4B1B973F1FCD98EE

-= EOF =-

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosím o kontrolu

#6 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    SecCenter::
    {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
    AV: ESET Smart Security 4.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
    {EDC10449-64D1-46c7-A59A-EC20D662F26D}
    FW: ActiveArmor Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
    
    Driver::
    ekrn
    EhttpSrv
    
    Folder::
    C:\Program Files\ESET
    C:\Program Files\DAEMON Tools Toolbar
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"=-
    "NBKeyScan"=-
    "AdobeCS4ServiceManager"=-
    "QuickTime Task"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000000
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{32099AAC-C132-4136-9E9A-4E364A424E17}"=-
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 1.1]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}*\Install*Loc\xga-1\dat]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 3.x]
    [HKEY_LOCAL_MACHINE\software\Microsoft\WinXGA*\Providers*\{D41D8CD9-8F00-B204-E980-0998ECF8427E}\Current*Set\xga-1\ver]
    [HKEY_LOCAL_MACHINE\software\XBMga*\UUIDs\{59D3E28F-07E2-A406-4061-94B4A182BBA6}\xga-1\Install*Loc]
    [HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
    
    File::
    c:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP
    c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci


:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) (viz muj podpis)
  • Provedte aktualizaci - treti zalozka
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

Re: prosím o kontrolu

#7 Příspěvek od out_of_space »

combofix:

ComboFix 10-10-01.01 - James 02.10.2010 10:28:15.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3070.2558 [GMT 2:00]
Spuštěný z: c:\documents and settings\James\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\James\Plocha\CFScript.txt
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Rezidentní štít AV je zapnutý


FILE ::
"c:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP"
"c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP"
.


.

c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.bmp
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\cond000.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond001.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond003.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond004.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond005.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond006.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond007.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond008.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond009.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond010.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond011.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond019.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond020.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond021.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond022.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond023.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond024.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond025.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond026.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond037.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond038.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond039.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond040.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond041.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond046.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond048.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond050.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond051.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond052.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond053.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond054.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond055.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond056.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond057.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond058.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond059.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond060.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond061.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond062.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond063.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond064.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond065.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond066.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond067.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond068.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond069.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond075.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond076.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond077.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond078.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond079.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond080.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond084.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond085.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond086.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond087.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond088.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond089.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond090.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond091.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond092.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond093.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond094.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond095.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond108.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond109.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond110.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond111.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond112.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond113.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond120.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond121.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond122.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond126.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond127.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond128.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond129.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond130.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond131.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond132.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond133.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond134.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond135.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond136.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond137.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond138.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond140.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond141.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond142.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond143.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond148.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond149.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond152.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond154.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond155.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond156.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond157.gif
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\noW.gif
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\time.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Weather_m42.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Weather_m43.bmp
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrnAmon.dll
c:\program files\ESET\ESET NOD32 Antivirus\ekrnDmon.dll
c:\program files\ESET\ESET NOD32 Antivirus\ekrnEmon.dll
c:\program files\ESET\ESET NOD32 Antivirus\ekrnEpfw.dll
c:\program files\ESET\ESET NOD32 Antivirus\ekrnMailPlugins.dll
c:\program files\ESET\ESET NOD32 Antivirus\ekrnScan.dll
c:\program files\ESET\ESET NOD32 Antivirus\ekrnUpdate.dll
c:\program files\ESET\ESET NOD32 Antivirus\em001_32.dat
c:\program files\ESET\ESET NOD32 Antivirus\updater.dll
c:\program files\ESET . . . . nemohl být smazán
c:\program files\ESET\ESET NOD32 Antivirus\nod32krn.exe . . . . nemohl být smazán

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_EKRN
-------\Service_EhttpSrv
-------\Service_ekrn



.

2010-10-01 11:31 . 2010-10-01 12:55 -------- d-----w- c:\program files\trend micro
2010-10-01 11:31 . 2010-10-01 11:32 -------- d-----w- C:\rsit
2010-09-26 18:15 . 2008-04-26 14:14 42672 ----a-w- c:\windows\system32\wbsys.dll
2010-09-23 16:53 . 2010-07-02 17:45 3321984 -c--a-w- c:\documents and settings\All Users\Data aplikací\{9A4E21A0-83F7-4E3F-8A2D-BA379A5A8EBB}\apophysis7x-setup.exe
2010-09-19 08:34 . 2010-08-30 12:34 1496064 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-09-19 08:34 . 2010-08-30 12:33 43008 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-09-19 08:34 . 2010-08-30 12:33 338944 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-09-19 08:34 . 2010-08-30 12:33 346112 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-09-18 22:21 . 2010-09-18 22:22 -------- d-----w- c:\program files\NexusFont
2010-09-17 08:45 . 2010-09-17 08:45 -------- d-----w- c:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP
2010-09-17 07:15 . 2010-09-17 07:16 232968 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-09-17 07:15 . 2010-09-17 07:16 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-09-17 07:15 . 2010-09-17 07:16 232968 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-09-16 09:56 . 2010-09-16 09:56 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2010-09-15 20:37 . 2010-09-01 17:56 52224 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
2010-09-15 20:37 . 2010-09-01 17:56 101376 ----a-w- c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
2010-09-15 20:36 . 2010-09-15 20:36 -------- d-----w- c:\program files\ZoneAlarm
2010-09-15 20:36 . 2010-09-15 20:36 -------- d-----w- c:\program files\Conduit
2010-09-15 20:35 . 2010-09-15 20:35 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-09-15 20:35 . 2010-09-15 20:35 -------- d-----w- c:\program files\CheckPoint
2010-09-15 20:35 . 2010-05-20 16:10 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-09-15 20:35 . 2010-05-20 16:10 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-09-15 20:35 . 2010-05-20 16:10 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-09-15 19:08 . 2010-09-15 19:08 -------- d-----w- c:\windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2010-09-15 18:00 . 2010-06-24 12:27 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-09-15 18:00 . 2010-06-24 12:27 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-09-15 18:00 . 2010-06-24 12:27 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-09-15 18:00 . 2010-06-24 12:27 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-09-15 18:00 . 2010-06-24 12:27 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-09-15 18:00 . 2010-06-24 12:27 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-09-15 17:51 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-09-13 17:57 . 2010-09-13 17:57 100157 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\uninst.exe
2010-09-13 17:33 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-09-13 17:33 . 2008-06-14 17:35 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-09-13 16:56 . 2010-04-28 18:15 2192128 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-09-13 16:21 . 2010-09-13 16:21 -------- d-----w- c:\program files\ImageShack Uploader
2010-09-13 15:03 . 2010-09-15 20:56 -------- d-----w- c:\windows\ie8updates
2010-09-13 15:00 . 2010-09-13 15:00 -------- d-----w- c:\program files\MSXML 4.0
2010-09-13 14:47 . 2010-09-13 14:47 -------- d-----w- c:\program files\NOS
2010-09-13 14:34 . 2010-10-01 10:43 -------- d-----w- c:\windows\system32\NtmsData
2010-09-13 14:32 . 2010-09-13 14:32 -------- d-----w- c:\program files\Avira
2010-09-13 14:32 . 2010-03-01 08:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-13 14:32 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-13 14:32 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-13 14:32 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-13 14:19 . 2010-09-16 10:15 -------- d--h--w- c:\windows\$hf_mig$
2010-09-13 14:16 . 2009-08-06 17:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-09-13 13:35 . 2010-09-13 13:35 0 ----a-w- c:\windows\nsreg.dat
2010-09-13 12:06 . 2010-09-14 17:37 -------- d-----w- c:\program files\Common Files\Motive
2010-09-04 10:01 . 2010-09-04 10:01 -------- d-----w- c:\program files\directx
2010-09-03 19:08 . 2010-09-03 19:08 2618368 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\TechTracker.exe

.

.
2010-10-02 08:37 . 2010-08-21 07:23 48134200 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-09-26 19:26 . 2010-07-09 12:18 -------- d-----w- c:\program files\Apophysis 7x
2010-09-26 18:15 . 2010-03-24 15:25 -------- d-----w- c:\program files\Stardock
2010-09-19 18:55 . 2001-10-25 14:00 93068 ----a-w- c:\windows\system32\perfc005.dat
2010-09-19 18:55 . 2001-10-25 14:00 479232 ----a-w- c:\windows\system32\perfh005.dat
2010-09-19 18:51 . 2009-11-10 23:58 -------- d-----w- c:\program files\Microsoft.NET
2010-09-17 08:45 . 2009-07-08 13:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-17 07:15 . 2009-07-08 12:54 -------- d-----w- c:\program files\NVIDIA Corporation
2010-09-15 20:35 . 2010-09-15 20:35 -------- d-----w- c:\program files\CheckPoint
2010-09-15 19:07 . 2009-07-08 12:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-17 13:17 . 2008-04-14 05:52 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:50 . 2009-08-17 11:24 -------- d-----w- c:\program files\CDex_150
2010-08-15 19:37 . 2009-07-16 14:03 -------- d-----w- c:\program files\PDF
2010-08-15 19:37 . 2009-07-16 14:02 -------- d-----w- c:\program files\Common Files\602PHS
2010-08-15 19:36 . 2010-05-16 20:22 -------- d-----w- c:\program files\JoWooD Productions Software AG
2010-08-08 07:31 . 2010-08-08 07:31 -------- d-----w- c:\program files\CCleaner
2010-08-03 19:48 . 2010-08-03 19:48 -------- d-----w- c:\program files\Zone Labs
2010-07-22 15:46 . 2008-04-14 05:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-15 02:08 . 2010-07-15 02:08 63827 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\zlib.dll
2010-07-15 02:07 . 2010-07-15 02:07 81920 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\xmltok.dll
2010-07-15 02:07 . 2010-07-15 02:07 61440 ----a-w- c:\documents and settings\James\Data aplikací\CBS Interactive\CNET TechTracker\xmlparse.dll
2010-07-09 22:38 . 2010-01-31 10:38 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-07-09 22:38 . 2010-01-31 10:38 10260480 ----a-w- c:\windows\system32\nvcompiler.dll
2010-07-09 22:38 . 2009-07-08 13:04 604776 -c--a-w- c:\windows\system32\nvudisp.exe
2010-07-07 11:46 . 2009-07-08 12:51 604776 -c--a-w- c:\windows\system32\NVUNINST.EXE
2003-11-03 16:07 . 2004-04-23 16:06 499712 ----a-w- c:\program files\msvcp71.dll
2003-11-03 16:07 . 2004-04-23 16:06 348160 ----a-w- c:\program files\msvcr71.dll
2003-05-30 08:22 . 2003-09-08 08:09 344064 ----a-r- c:\program files\msvcr70.dll
2002-01-05 02:40 . 2003-09-08 08:09 487424 ----a-w- c:\program files\msvcp70.dll
.

------- Sigcheck -------

[-] 2009-01-31 . 959B66A9B529BA5C4B1B973F1FCD98EE . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-10-02_07.06.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 16:21 . 2010-10-02 08:00 2472448 c:\windows\Installer\728a3c.msi
- 2009-07-12 16:21 . 2010-09-23 17:35 2472448 c:\windows\Installer\728a3c.msi
.

.
.

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 09:50 2517088 ----a-w- c:\program files\ZoneAlarm\tbZone.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-12-21 270336]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-20 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-18 730600]
"nwiz"="nwiz.exe" [2009-07-08 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-08 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-08 13762560]

c:\documents and settings\James\Nabˇdka Start\Programy\Po spuçtŘnˇ\
GIGABYTE Gamer HUD.lnk - c:\program files\GIGABYTE\Gamer HUD\HUD.exe [2008-6-26 1940992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2010-06-07 13:59 214320 ----a-w- c:\program files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"OEXPRESS"=c:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"d:\\hry\\Painkiller Overdose\\Bin\\Overdose.exe"=
"d:\\hry\\Painkiller Overdose\\Bin\\OverdoseEditor.exe"=
"d:\\hry\\Painkiller Overdose\\Bin\\OverdoseServer.exe"=
"d:\\hry\\Heroes of Might and Magic V\\bin\\H5_Game.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\hry\\Prince of Persia\\Prince of Persia.exe"=
"d:\\hry\\Prince of Persia\\PrinceOfPersia_Launcher.exe"=
"d:\\hry\\racedriver GRID\\GRID.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\hry\\Warcraft 3\\Warcraft III\\Warcraft III.exe"=
"d:\\hry\\hellgate\\Launcher.exe"=
"d:\\hry\\hawx\\H.A.W.X\\HAWX.exe"=
"d:\\hry\\left4dead\\left4dead.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\hry\\Dragon Age\\bin_ship\\daorigins.exe"=
"d:\\hry\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\hry\\COD4\\iw3mp.exe"=
"d:\\hry\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"d:\\hry\\dirt2\\dirt2_game.exe"=
"d:\\hry\\avatar\\bin\\Avatar.exe"=
"d:\\hry\\avatar\\bin\\AvatarLauncher.exe"=
"d:\\hry\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"d:\\hry\\assassins creed\\AssassinsCreed_Dx9.exe"=
"d:\\hry\\assassins creed\\AssassinsCreed_Dx10.exe"=
"d:\\hry\\assassins creed\\AssassinsCreed_Launcher.exe"=
"d:\\hry\\bf bc2\\BFBC2Updater.exe"=
"d:\\hry\\gta4\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\hry\\gta4\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\hry\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"d:\\hry\\Mass Effect 2\\MassEffect2Launcher.exe"=
"d:\\hry\\Alpha protocol\\Binaries\\APGame.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\hry\\singularity\\Binaries\\Singularity.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [13.9.2010 16:32 135336]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [18.5.2010 16:01 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [18.5.2010 16:01 493032]
R2 nxsIO32;NextSensor Kernel I/O Driver;c:\windows\system32\drivers\nxsIO32.sys [28.7.2009 12:44 2208]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [30.10.2009 16:05 1021256]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;c:\windows\system32\drivers\c6501.sys [8.7.2009 14:58 1310720]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 8:24 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\hry\Dragon Age\bin_ship\daupdatersvc.service.exe [15.12.2009 22:07 25832]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [17.7.2009 10:51 1527900]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [14.4.2008 7:52 14336]
S3 ultradfg;ultradfg;c:\windows\system32\drivers\ultradfg.sys [13.11.2008 11:52 24576]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.7.2009 11:04 721904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.


2010-10-02 c:\windows\Tasks\Automatic troubleshooting.job
- c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-10-30 14:12]
.
.
------- -------
.
uStart Page = hxxp://seznam.cz/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
FF - ProfilePath - c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=FF_5&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\James\Data aplikací\Mozilla\Firefox\Profiles\1yf12iki.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\NOS\bin\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - - - - -

AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-02 10:38
Windows 5.1.2600 Service Pack 3 NTFS








: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A475180]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb810cf28
\Driver\ACPI -> ACPI.sys @ 0xb7f7fcb8
\Driver\atapi -> atapi.sys @ 0xb7eff852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
user & kernel MBR OK

**************************************************************************
.
--------------------- ---------------------

[HKEY_USERS\S-1-5-21-1659004503-861567501-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:f1,25,c1,ac,c6,e1,3b,54,1f,f6,ef,e7,b4,8d,03,97,3d,f4,57,a8,2f,85,d0,
e9,28,df,a0,58,5f,69,ac,8d,c2,31,77,72,6b,1a,28,81,5e,70,23,6f,f4,5a,52,05,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50

[HKEY_USERS\S-1-5-21-1659004503-861567501-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:81,b5,1b,eb,97,f1,bb,4d,77,c8,f6,03,ad,0b,c1,fc,72,4d,6d,c4,49,
d0,3f,fb,7f,3c,e3,81,1f,2e,00,29,0d,ca,9d,d1,8f,1e,f2,90,00,fd,a3,57,c4,46,\
"rkeysecu"=hex:8c,4d,e2,8d,7d,49,bf,be,cc,f4,34,3c,02,83,34,77

[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
@DACL=
"DefaultSettings"="99:{C6DDA450-F687-55DF-CA23-1A5083308C5D}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
@DACL=
"CTE_32 Name"="2455134:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 1.1]
@DACL=
"dat"="806585365:{5D0C82CA-39DA-ED40-1AF8-1541D495F249}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
@DACL=
"DefaultSettings"="2455155:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}*\Install*Loc\xga-1\dat]
@DACL=
"default"="516231781:{003A0A97-CEB0-7714-2C08-96957FF709B9}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 3.x]
@DACL=
"dat"="1767914624:{210F4669-23D3-2C3F-D082-F9E94344ED41}"

[HKEY_LOCAL_MACHINE\software\Microsoft\WinXGA*\Providers*\{D41D8CD9-8F00-B204-E980-0998ECF8427E}\Current*Set\xga-1\ver]
@DACL=
"KnownSvcs"="923714714:{F4BEA03D-BA0E-5CA1-869B-39A0711959D3}"

[HKEY_LOCAL_MACHINE\software\XBMga*\UUIDs\{59D3E28F-07E2-A406-4061-94B4A182BBA6}\xga-1\Install*Loc]
@DACL=
"{19620715-0001-1211-574574-30001}"="234521934:{58829A3F-90C8-F4E7-5A83-E255048ED5C9}"

[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
@DACL=
"CTE_32 Name"="6:{19C42D30-D844-8A07-12A4-E783E7D228F7}"
.
--------------------- ---------------------

- - - - - - - > 'winlogon.exe'(1176)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\program files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(1268)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'explorer.exe'(3280)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ImgUtil.dll
c:\windows\system32\pngfilt.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\program files\Stardock\Object Desktop\WindowBlinds\tray.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\SYSTEM32\astsrv.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\WgaTray.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\windows\system32\RUNDLL32.EXE
.
**************************************************************************
.
: 2010-10-02 10:41:40 -
ComboFix-quarantined-files.txt 2010-10-02 08:41
ComboFix2.txt 2010-10-02 07:08

Před spuštěním: Volných bajtů: 21 482 856 448
: Volných bajtů: 21 361 315 840

- - End Of File - - 338701D6F0548C25057098C88703EDC7

out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

Re: prosím o kontrolu

#8 Příspěvek od out_of_space »

MBan:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4733

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2.10.2010 12:47:49
mbam-log-2010-10-02 (12-47-49).txt

Typ skenu: Úplný sken (C:\|D:\|)
Skenované objekty: 486095
Uplynulý čas: 1 hodina(y), 55 minuta(y), 27 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 12
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 2

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mysearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{014da6ca-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{014da6cc-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{014da6cb-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{014da6cb-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Search Uninstall (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MySearch (Adware.MyWebSearch) -> No action taken.

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\Plug-ins\Fnordware PowerPicker 1.01\keygen.exe (Malware.Packer.Gen) -> No action taken.
C:\Program Files\DVDFab 6\dbghelp.dll (Trojan.FakeMS) -> No action taken.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosím o kontrolu

#9 Příspěvek od vyosek »

:arrow: Nasledujici soubory otestujte na VirusTotalu (viz muj podpis)
  • C:\Program Files\DVDFab 6\dbghelp.dll
  • Kliknete na Prochazet
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Pokud napise Soubor byl jiz testovan, dejte otestovat znovu
  • Kliknete na Otestovat soubor
  • Vysledek analyzy sem vlozte (jako odkaz)
:arrow: Jinak ostatni nalezy MBAMu smazat

:arrow: Odinstalujte vsechny emulatory virtualnich jednotek (Deamon Tools, Alcohol 120%, PowerISO apod)

:arrow: Stahnete SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte z uvedene stranky verzi dle sveho operacniho systemu (32(x86)bit ci 64(x64)bit)
  • Ulozte na plochu a spustte
  • Zvolte moznost Uninstall a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete Defogger http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Ulozte na plochu a spustte
  • Kliknete na Disable a restartujte PC - pokud nepujde kliknout (tlacitko bude sede), krok preskocte
:arrow: Stahnete MBR na plochu http://www2.gmer.net/mbr/mbr.exe

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    "%userprofile%\plocha\mbr" -t
  • Kliknete na OK
  • Na plose se Vam vytvori log s nazvem mbr.txt, jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

Re: prosím o kontrolu

#10 Příspěvek od out_of_space »

Virustotal: http://www.virustotal.com/file-scan/rep ... 1286088188

Daemon mi odinstalovat nešel. V půlce odinstalátor přestal reagovat. Mimochodem daemon nejde ani spustit, vyskočí tato tabulka: Obrázek


Jinak vše provedeno podle vašich pokynů.

MBR:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A45EB68]<<
kernel: MBR read successfully
user & kernel MBR OK

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosím o kontrolu

#11 Příspěvek od vyosek »

:arrow: O hlasku deamona se postarame pozdeji, je zpusobena vypnutim sptd - jeho ovladace - bohuzel musi byt vypnut aby nezasahoval do cinnsoti mbr (coz asi udelal) a gmeru

:arrow: Podivejte se jestli nemate Deamona v Pridat nebo odebrat programy, pripadne zkuste Revo Uninstaller http://www.stahuj.centrum.cz/utility_a_ ... installer/

:arrow: Log z mbr je volaaky cudny, pujdeme v testech dale...

:arrow: Dejte logy z Gmeru - viz muj podpis
  • Pokud by se gmer sekal, tak jej aplikujte v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

Re: prosím o kontrolu

#12 Příspěvek od out_of_space »

V přidat/odebrat programy ani v revu jsem Daemon nenašel, jedině v nabídce start byla ikonka odinstalace.

Gmer:

První:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-10-03 17:45:54
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\James\LOCALS~1\Temp\awpdypoc.sys


---- Devices - GMER 1.0.15 ----

Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip NVTcp.sys (NVIDIA Networking Protocol Driver./NVIDIA Corporation)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp NVTcp.sys (NVIDIA Networking Protocol Driver./NVIDIA Corporation)

Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

---- EOF - GMER 1.0.15 ----




Scan
:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-10-03 18:41:25
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\awpdypoc.sys


---- Kernel code sections - GMER 1.0.15 ----

.xreloc C:\WINDOWS\system32\drivers\sfsync04.sys unknown last section [0xF74F6000, 0xC0A, 0x40000040]

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF3 0xCF 0x1D 0x8A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x0B 0x98 0xC0 0xBB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0x4B 0x1F 0x1A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x24 0xF6 0x1F 0x85 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x4B 0x40 0x19 0xD4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x27 0xFC 0x8C 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0xE9 0xC2 0x90 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x4C 0xB6 0x17 0x4D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x4B 0x40 0x19 0xD4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x27 0xFC 0x8C 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0xE9 0xC2 0x90 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x4C 0xB6 0x17 0x4D ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF3 0xCF 0x1D 0x8A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x0B 0x98 0xC0 0xBB ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0x4B 0x1F 0x1A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x24 0xF6 0x1F 0x85 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x4B 0x40 0x19 0xD4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x27 0xFC 0x8C 0x24 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0xE9 0xC2 0x90 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x4C 0xB6 0x17 0x4D ...
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs@CTE_32 Name 2455134:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\VideoFilesContentSniffer@RelPattern *.asf?*.avi?*.divx?*.mov?*.mpeg?*.mpg?*.ogm?*.qt?*.rm?*.wmv?*.mkv?*.vob?*.m1v?*.m2v?*.swf?*.fli?*.flc?*.flic?*.dat?*.mp4?*.mpe?*.3gp?*.3g2?*.ts?*.tp?*.trp?*.k3g?*.flv?*.mpg?VIDEO\*.mpg?*.mpe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 1.1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 1.1@dat 806585365:{5D0C82CA-39DA-ED40-1AF8-1541D495F249}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install\xga-1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install\xga-1\dat
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install\xga-1\dat@default 516231781:{003A0A97-CEB0-7714-2C08-96957FF709B9}
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 3.x
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 3.x@dat 1767914624:{210F4669-23D3-2C3F-D082-F9E94344ED41}

---- EOF - GMER 1.0.15 ----

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosím o kontrolu

#13 Příspěvek od vyosek »

V PC by mel byt jeste StarForce, odinstalujte jej prosim a pak provedte znovu krok s MBR...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

out_of_space
Návštěvník
Návštěvník
Příspěvky: 110
Registrován: 01 srp 2010 19:45

Re: prosím o kontrolu

#14 Příspěvek od out_of_space »

Po odinstalaci Starforce:

první:GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-10-03 19:25:23
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\James\LOCALS~1\Temp\awpdypoc.sys


---- Devices - GMER 1.0.15 ----

Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip NVTcp.sys (NVIDIA Networking Protocol Driver./NVIDIA Corporation)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp NVTcp.sys (NVIDIA Networking Protocol Driver./NVIDIA Corporation)

Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

---- EOF - GMER 1.0.15 ----







scan:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-10-03 19:46:26
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\James\LOCALS~1\Temp\awpdypoc.sys


---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF3 0xCF 0x1D 0x8A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x0B 0x98 0xC0 0xBB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0x4B 0x1F 0x1A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x24 0xF6 0x1F 0x85 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x4B 0x40 0x19 0xD4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x27 0xFC 0x8C 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0xE9 0xC2 0x90 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x4C 0xB6 0x17 0x4D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x4B 0x40 0x19 0xD4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x27 0xFC 0x8C 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0xE9 0xC2 0x90 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x4C 0xB6 0x17 0x4D ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF3 0xCF 0x1D 0x8A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x0B 0x98 0xC0 0xBB ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0x4B 0x1F 0x1A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x24 0xF6 0x1F 0x85 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x4B 0x40 0x19 0xD4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x27 0xFC 0x8C 0x24 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0xE9 0xC2 0x90 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x4C 0xB6 0x17 0x4D ...
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs@CTE_32 Name 2455134:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\VideoFilesContentSniffer@RelPattern *.asf?*.avi?*.divx?*.mov?*.mpeg?*.mpg?*.ogm?*.qt?*.rm?*.wmv?*.mkv?*.vob?*.m1v?*.m2v?*.swf?*.fli?*.flc?*.flic?*.dat?*.mp4?*.mpe?*.3gp?*.3g2?*.ts?*.tp?*.trp?*.k3g?*.flv?*.mpg?VIDEO\*.mpg?*.mpe
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 1.1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 1.1@dat 806585365:{5D0C82CA-39DA-ED40-1AF8-1541D495F249}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install\xga-1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install\xga-1\dat
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\{5198D051-CBB9-A256-8D90-B3E36470E6A1}\Install\xga-1\dat@default 516231781:{003A0A97-CEB0-7714-2C08-96957FF709B9}
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 3.x
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{3546CF9C-99FB-3BC7-042C-92F4702B59B8}\Version 3.x@dat 1767914624:{210F4669-23D3-2C3F-D082-F9E94344ED41}

---- EOF - GMER 1.0.15 ----

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosím o kontrolu

#15 Příspěvek od vyosek »

Jeste ten mbr

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    "%userprofile%\plocha\mbr" -t
  • Kliknete na OK
  • Na plose se Vam vytvori log s nazvem mbr.txt, jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět