Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

preventivny log

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
hinatahyuuga
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 30 kvě 2008 13:37

preventivny log

#1 Příspěvek od hinatahyuuga »

Zdravim prosim o kontrolu logu :)


Logfile of random's system information tool 1.08 (written by random/random)

Run by Artemisko at 2010-10-21 06:23:44
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (7%) free of 151 GB
Total RAM: 1022 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:24:03 AM, on 10/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tunngle\TnglCtrl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\ARTEMI~1\LOCALS~1\Temp\Isd.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Artemisko\Desktop\RSIT.exe
C:\Program Files\trend micro\Artemisko.exe

O1 - Hosts: 188.40.106.218 L2authd.Lineage2.com
O1 - Hosts: 188.40.139.3 testauthd.lineage2.com
O1 - Hosts: 216.107.250.194 update.nProtect.com
O1 - Hosts: 216.107.250.194 update.nProtect.net
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IJKUK66HMN] C:\DOCUME~1\ARTEMI~1\LOCALS~1\Temp\Isd.exe
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 5625 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-03-08 761947]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2005-12-19 1347584]
"NVHotkey"=nvHotkey.dll,Start []
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-01-30 13594624]
"nwiz"=nwiz.exe /installquiet []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-01-30 86016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"IJKUK66HMN"=C:\DOCUME~1\ARTEMI~1\LOCALS~1\Temp\Isd.exe [2010-10-21 241664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-04-13 1135912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
C:\Program Files\Dell\MediaDirect\PCMService.exe [2006-10-13 184320]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Dell\MediaDirect\PCMService.exe"="C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\Heroes of Newerth - Servers-eXtreme\hon.exe"="C:\Program Files\Heroes of Newerth - Servers-eXtreme\hon.exe:*:Enabled:Heroes of Newerth"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Documents and Settings\Artemisko\Desktop\MTGOIII_Helper.exe"="C:\Documents and Settings\Artemisko\Desktop\MTGOIII_Helper.exe:*:Enabled:Magic: The Gathering Online III"
"C:\Games\magictg\ManaLink.exe"="C:\Games\magictg\ManaLink.exe:*:Enabled:ManaLink"
"C:\Games\Red Alert 2 Retail\game.exe"="C:\Games\Red Alert 2 Retail\game.exe:*:Enabled:Main executable for Red Alert 2"
"C:\Games\Quake3\quake3.exe"="C:\Games\Quake3\quake3.exe:*:Enabled:quake3"
"D:\Kópia (2) – Kópia – Kópia – Counter-Strike 1.6\hl.exe"="D:\Kópia (2) – Kópia – Kópia – Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Savage 2 - A Tortured Soul\savage2.exe"="C:\Program Files\Savage 2 - A Tortured Soul\savage2.exe:*:Enabled:savage2"
"C:\Games\Kópia (2) – Kópia – Kópia – Counter-Strike 1.6\hl.exe"="C:\Games\Kópia (2) – Kópia – Kópia – Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Documents and Settings\Artemisko\Desktop\LieroX v0.56 Pack 1.9\LieroX.exe"="C:\Documents and Settings\Artemisko\Desktop\LieroX v0.56 Pack 1.9\LieroX.exe:*:Enabled:LieroX"
"C:\Games\Red Alert 2 Retail\gamemd.exe"="C:\Games\Red Alert 2 Retail\gamemd.exe:*:Enabled:Main executable for Yuri's Revenge"
"C:\Games\Thq\Titan Quest.exe"="C:\Games\Thq\Titan Quest.exe:*:Enabled:Titan Quest"
"C:\Games\lotr\Conquest.exe"="C:\Games\lotr\Conquest.exe:*:Enabled:Game"
"C:\Program Files\VentSrv\ventrilo_srv.exe"="C:\Program Files\VentSrv\ventrilo_srv.exe:*:Enabled:ventrilo_srv"
"C:\Games\nhl\nhl2009.exe"="C:\Games\nhl\nhl2009.exe:*:Enabled:nhl2009"
"C:\Documents and Settings\Artemisko\Desktop\L4D\Left 4 Dead 1.0.1.5 garena\left4dead.exe"="C:\Documents and Settings\Artemisko\Desktop\L4D\Left 4 Dead 1.0.1.5 garena\left4dead.exe:*:Enabled:left4dead"
"C:\Program Files\Fox\Aliens versus Predator 2 - Primal Hunt\lithtech.exe"="C:\Program Files\Fox\Aliens versus Predator 2 - Primal Hunt\lithtech.exe:*:Enabled:Client"
"C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe"="C:\Program Files\Fox\Aliens vs. Predator 2\lithtech.exe:*:Enabled:Client"
"C:\Program Files\Fox\Aliens vs. Predator 2\AVP2Serv.exe"="C:\Program Files\Fox\Aliens vs. Predator 2\AVP2Serv.exe:*:Enabled:AVP2 Stand-Alone Server"
"C:\Games\Heroes of Newerth\hon.exe"="C:\Games\Heroes of Newerth\hon.exe:*:Enabled:Heroes of Newerth"
"C:\Program Files\Brain Seal\Masters of Belial\MastersOfBelial.exe"="C:\Program Files\Brain Seal\Masters of Belial\MastersOfBelial.exe:*:Enabled:Masters of Belial"
"C:\Program Files\Metin2_CZ\metin2client.bin"="C:\Program Files\Metin2_CZ\metin2client.bin:*:Enabled:metin2client"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe"="C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe:*:Enabled:ijjiOptimizer.exe"
"C:\Program Files\Heroes of Newerth - Extreme\hon.exe"="C:\Program Files\Heroes of Newerth - Extreme\hon.exe:*:Enabled:Heroes of Newerth"
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Games\League of Legends\air\LolClient.exe"="C:\Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Games\League of Legends\game\League of Legends.exe"="C:\Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Documents and Settings\Artemisko\Desktop\QIP Infium bz™Pack\inf.exe"="C:\Documents and Settings\Artemisko\Desktop\QIP Infium bz™Pack\inf.exe:*:Enabled:QIP Infium"
"C:\Documents and Settings\Artemisko\My Documents\Downloads\Tony hawk 3\Skate3.exe"="C:\Documents and Settings\Artemisko\My Documents\Downloads\Tony hawk 3\Skate3.exe:*:Enabled:THPS3PC"
"C:\Games\Postal2STP\System\Postal2MP.exe"="C:\Games\Postal2STP\System\Postal2MP.exe:*:Enabled:Postal2MP"
"C:\Documents and Settings\All Users\Documents\Rune - Co-op 3\Rune - Co-op\RUNE\SYSTEM\RUNE.EXE"="C:\Documents and Settings\All Users\Documents\Rune - Co-op 3\Rune - Co-op\RUNE\SYSTEM\RUNE.EXE:*:Enabled:RUNE"
"C:\Documents and Settings\Artemisko\My Documents\Downloads\Warcraft III\Warcraft III.exe"="C:\Documents and Settings\Artemisko\My Documents\Downloads\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"C:\Documents and Settings\Artemisko\My Documents\Downloads\Left 4 Dead 2 - V2.0.0.8 (Patched For Online Gameplay) NoN-Steam .Full-Rip. [blaze69]\Left 4 Dead 2\left4dead2.exe"="C:\Documents and Settings\Artemisko\My Documents\Downloads\Left 4 Dead 2 - V2.0.0.8 (Patched For Online Gameplay) NoN-Steam .Full-Rip. [blaze69]\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"C:\Games\nfs\NFSHP2.exe"="C:\Games\nfs\NFSHP2.exe:*:Enabled:NFSHP2"
"C:\Rune\System\Rune.exe"="C:\Rune\System\Rune.exe:*:Enabled:Rune"
"C:\Games\rune\System\Rune.exe"="C:\Games\rune\System\Rune.exe:*:Enabled:Rune"
"C:\Documents and Settings\Artemisko\Desktop\Left 4 Dead 2\left4dead2.exe"="C:\Documents and Settings\Artemisko\Desktop\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"C:\Documents and Settings\Artemisko\Local Settings\Application Data\Kamuse\KCSTrayDownloader\KCSTrayDownloaderEngine.exe"="C:\Documents and Settings\Artemisko\Local Settings\Application Data\Kamuse\KCSTrayDownloader\KCSTrayDownloaderEngine.exe:*:Enabled:KCSTrayDownloaderEngine"
"C:\Games\battleforge\Bootstrapper.exe"="C:\Games\battleforge\Bootstrapper.exe:*:Enabled:BattleForge™ Launcher"
"C:\Games\battleforge\BattleForge.exe"="C:\Games\battleforge\BattleForge.exe:*:Enabled:BattleForge™"
"C:\Program Files\Tunngle\TnglCtrl.exe"="C:\Program Files\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service"
"C:\Program Files\Tunngle\Tunngle.exe"="C:\Program Files\Tunngle\Tunngle.exe:*:Enabled:Tunngle Client"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Documents and Settings\Artemisko\Local Settings\Temp\FJ_Downloader.exe"="C:\Documents and Settings\Artemisko\Local Settings\Temp\FJ_Downloader.exe:*:Enabled:FreeJack_Downloader"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

======List of files/folders created in the last 1 months======

2010-10-21 06:21:14 ----A---- C:\WINDOWS\Ilasaa.exe
2010-10-21 06:20:56 ----A---- C:\WINDOWS\system32\sshnas21.dll
2010-10-20 21:02:19 ----A---- C:\WINDOWS\system32\npptNT2.sys
2010-10-20 20:45:48 ----D---- C:\Documents and Settings\Artemisko\Application Data\InstallShield
2010-10-20 20:06:31 ----D---- C:\WINDOWS\LastGood
2010-10-20 20:05:15 ----D---- C:\Program Files\Bethesda Softworks
2010-10-19 10:50:28 ----A---- C:\WINDOWS\system32\WNASPINT.DLL
2010-10-19 10:42:08 ----D---- C:\eJay
2010-10-14 03:08:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-10-14 03:07:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-10-14 03:07:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-10-14 03:07:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-10-14 03:07:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-10-14 03:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-10-14 03:06:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2360131$
2010-10-14 03:05:58 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-10-14 03:01:36 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-10-14 03:01:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-10-13 22:28:33 ----D---- C:\Documents and Settings\Artemisko\Application Data\MSNInstaller
2010-10-12 23:18:06 ----A---- C:\WINDOWS\system32\unicows.dll
2010-10-09 15:13:44 ----D---- C:\Documents and Settings\Artemisko\Application Data\AIMP
2010-10-09 15:07:55 ----D---- C:\Program Files\AIMP2
2010-10-06 15:25:41 ----D---- C:\Program Files\Magic Workstation
2010-09-30 11:43:33 ----A---- C:\WINDOWS\system32\ptpusd.dll
2010-09-30 06:44:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$
2010-09-28 16:06:33 ----D---- C:\WINDOWS\pss
2010-09-26 01:40:35 ----D---- C:\Program Files\Wizards of the Coast LLC
2010-09-23 09:36:51 ----D---- C:\Program Files\MOHPA

======List of files/folders modified in the last 1 months======

2010-10-21 06:23:49 ----D---- C:\Program Files\trend micro
2010-10-21 06:21:20 ----SD---- C:\WINDOWS\Tasks
2010-10-21 06:21:14 ----D---- C:\WINDOWS
2010-10-21 06:20:56 ----D---- C:\WINDOWS\system32
2010-10-21 06:13:29 ----D---- C:\WINDOWS\Temp
2010-10-20 20:46:41 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-20 20:46:14 ----D---- C:\Games
2010-10-20 20:44:52 ----D---- C:\WINDOWS\Prefetch
2010-10-20 20:44:17 ----D---- C:\Program Files\Lineage II
2010-10-20 20:36:17 ----D---- C:\Documents and Settings\Artemisko\Application Data\uTorrent
2010-10-20 20:06:49 ----RSD---- C:\WINDOWS\assembly
2010-10-20 20:06:24 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-20 20:05:48 ----D---- C:\WINDOWS\system32\DirectX
2010-10-20 20:05:15 ----D---- C:\Program Files
2010-10-20 19:06:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-20 18:02:13 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-10-20 17:43:05 ----A---- C:\WINDOWS\NeroDigital.ini
2010-10-20 17:42:50 ----D---- C:\Program Files\Dangerous Dave 2
2010-10-20 17:19:57 ----D---- C:\Program Files\Mozilla Firefox
2010-10-19 18:00:16 ----D---- C:\Documents and Settings\Artemisko\Application Data\Hamachi
2010-10-19 18:00:11 ----D---- C:\Documents and Settings\Artemisko\Application Data\Skype
2010-10-19 17:59:41 ----D---- C:\Documents and Settings\Artemisko\Application Data\skypePM
2010-10-19 09:47:32 ----D---- C:\Program Files\Common Files
2010-10-19 09:43:22 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-10-19 09:39:46 ----SHD---- C:\WINDOWS\Installer
2010-10-19 09:39:46 ----HD---- C:\Config.Msi
2010-10-18 19:04:18 ----D---- C:\Documents and Settings\Artemisko\Application Data\HPAppData
2010-10-18 18:07:04 ----D---- C:\Documents and Settings\Artemisko\Application Data\Tunngle
2010-10-14 17:57:26 ----D---- C:\WINDOWS\Minidump
2010-10-14 17:57:26 ----D---- C:\WINDOWS\Debug
2010-10-14 07:31:24 ----HD---- C:\WINDOWS\inf
2010-10-14 03:08:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-10-14 03:08:02 ----HD---- C:\WINDOWS\$hf_mig$
2010-10-14 03:07:52 ----D---- C:\WINDOWS\system32\drivers
2010-10-14 03:07:45 ----D---- C:\WINDOWS\WinSxS
2010-10-14 03:07:31 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-10-14 03:01:44 ----A---- C:\WINDOWS\system32\MRT.exe
2010-10-13 22:58:10 ----D---- C:\WINDOWS\system32\config
2010-10-13 22:57:43 ----D---- C:\WINDOWS\system32\wbem
2010-10-13 22:57:42 ----D---- C:\WINDOWS\Registration
2010-10-13 22:56:53 ----D---- C:\WINDOWS\system32\Restore
2010-10-13 22:28:15 ----D---- C:\Program Files\MSN
2010-10-11 15:26:54 ----D---- C:\Program Files\QIP Infium
2010-10-06 11:19:41 ----D---- C:\Program Files\Bleach X Naruto_MUGEN 3.0
2010-10-05 07:21:51 ----D---- C:\WINDOWS\Microsoft.NET
2010-10-03 16:09:41 ----D---- C:\Program Files\Windows Media Connect 2
2010-09-30 16:15:08 ----HD---- C:\WINDOWS\msdownld.tmp
2010-09-30 09:58:07 ----D---- C:\Program Files\QIP
2010-09-28 17:54:22 ----RSD---- C:\WINDOWS\Fonts
2010-09-28 16:21:51 ----SH---- C:\boot.ini
2010-09-28 16:21:51 ----A---- C:\WINDOWS\win.ini
2010-09-28 16:21:51 ----A---- C:\WINDOWS\system.ini
2010-09-28 16:05:22 ----D---- C:\Program Files\Google
2010-09-28 15:49:14 ----D---- C:\MDT
2010-09-26 12:47:00 ----D---- C:\Program Files\uTorrent

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;ohci1394; C:\WINDOWS\system32\drivers\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-03-31 44944]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-03-11 639224]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-11-02 424320]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2006-08-17 44544]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-16 17480]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-07-22 1035008]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-07-22 201600]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-01-30 6250848]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-03-24 1156648]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-03-08 191872]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-07-22 717952]
S0 cercsr6;cercsr6; C:\WINDOWS\system32\drivers\cercsr6.sys [2004-12-13 39904]
S1 OMCI;OMCI; \??\C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS []
S3 amge43w9;amge43w9; C:\WINDOWS\system32\drivers\amge43w9.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 dump_wmimmc;dump_wmimmc; \??\C:\gamesWebzen\ArchLord\GameGuard\dump_wmimmc.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ARTEMI~1\LOCALS~1\Temp\NVG26E.tmp []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-31 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-31 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-31 21568]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 npkcrypt;npkcrypt; \??\C:\Program Files\Lineage II\system\npkcrypt.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\WINDOWS\system32\npptNT2.sys []
S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2008-04-13 11904]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2008-04-13 11008]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\drivers\UIUSys.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 vtany;vtany; \??\C:\WINDOWS\vtany.sys []
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 xhunter1;xhunter1; \??\C:\WINDOWS\xhunter1.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-01-30 168004]
R2 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2010-07-06 716024]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2005-12-19 18944]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-08-09 136176]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 SSHNAS;SSHNAS; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2010-03-27 68096]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2010-08-18 3717904]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: preventivny log

#2 Příspěvek od cernohous13 »

Zdravím, ale nepotěším tě - je tam :(
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Skener" > Provést rychlý sken > Skenovat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

hinatahyuuga
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 30 kvě 2008 13:37

Re: preventivny log

#3 Příspěvek od hinatahyuuga »

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verzia databázy: 4902

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

10/21/2010 3:53:13 PM
mbam-log-2010-10-21 (15-53-13).txt

Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 135638
Uplynulý èas: 18 min, 49 sek

Infikované služby pamäte: 1
Infikované moduly pamäte: 1
Infikované registraèné k¾úèe: 5
Infikované registraèné hodnoty: 1
Infikované položky registraèných dát: 0
Infikované prieèinky: 0
Infikované súbory: 8

Infikované služby pamäte:
C:\WINDOWS\Ilasaa.exe (Rootkit.TDSS) -> No action taken.

Infikované moduly pamäte:
c:\WINDOWS\system32\sshnas21.dll (Rootkit.TDSS) -> No action taken.

Infikované registraèné k¾úèe:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sshnas (Rootkit.TDSS) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\IJKUK66HMN (Trojan.FakeAlert) -> No action taken.

Infikované registraèné hodnoty:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ijkuk66hmn (Rootkit.TDSS) -> No action taken.

Infikované položky registraèných dát:
(Škodlivé položky neboli zistené)

Infikované prieèinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
c:\WINDOWS\system32\sshnas21.dll (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\Ilasaa.exe (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Artemisko\Local Settings\Temp\Isd.exe (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Artemisko\Local Settings\Temp\Isb.exe (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Artemisko\Local Settings\Temp\Isc.exe (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\IFinst27.exe (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: preventivny log

#4 Příspěvek od cernohous13 »

MBAM spustit znovu - dát Kompletní kontrola
:arrow: po ukončení -> Zobrazit výsledky -> zkontrolovat zda je vše označeno -> Odstranit označené
vyběhne log, ve kterém budou záznamy tohoto typu:
Infikované adresáře:
C:\Program Files\xxxxxx -> Quarantined and deleted successfully.
ten bych taky rád viděl :)
Pak restartuj a udělej nový rychlý test.
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

hinatahyuuga
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 30 kvě 2008 13:37

Re: preventivny log

#5 Příspěvek od hinatahyuuga »

Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Verzia databázy: 4902

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

10/21/2010 8:26:48 PM
mbam-log-2010-10-21 (20-26-48).txt

Typ kontroly: Úplná kontrola (C:\|)
Objektov kontrolovaných: 320776
Uplynulý èas: 3 hod, 0 min, 41 sek

Infikované služby pamäte: 2
Infikované moduly pamäte: 1
Infikované registraèné k¾úèe: 5
Infikované registraèné hodnoty: 1
Infikované položky registraèných dát: 0
Infikované prieèinky: 0
Infikované súbory: 10

Infikované služby pamäte:
C:\WINDOWS\Ilasaa.exe (Rootkit.TDSS) -> Failed to unload process.
C:\Documents and Settings\Artemisko\Local Settings\Temp\Isd.exe (Rootkit.TDSS) -> Unloaded process successfully.

Infikované moduly pamäte:
c:\WINDOWS\system32\sshnas21.dll (Rootkit.TDSS) -> Delete on reboot.

Infikované registraèné k¾úèe:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sshnas (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\IJKUK66HMN (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Infikované registraèné hodnoty:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ijkuk66hmn (Rootkit.TDSS) -> Quarantined and deleted successfully.

Infikované položky registraèných dát:
(Škodlivé položky neboli zistené)

Infikované prieèinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
c:\WINDOWS\system32\sshnas21.dll (Rootkit.TDSS) -> Delete on reboot.
C:\WINDOWS\Ilasaa.exe (Rootkit.TDSS) -> Delete on reboot.
C:\Documents and Settings\Artemisko\Local Settings\Temp\Isd.exe (Rootkit.TDSS) -> Delete on reboot.
C:\Documents and Settings\All Users\Documents\Kópia (2) – Kópia – Kópia – Counter-Strike 1.6\ECC52\ECC 5.2.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Artemisko\Desktop\Zoner photostudio 12\Zoner photostudio 12\keygen.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Artemisko\Local Settings\Temp\Isb.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Artemisko\Local Settings\Temp\Isc.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\IFinst27.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.











Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Verzia databázy: 4902

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

10/21/2010 10:55:55 PM
mbam-log-2010-10-21 (22-55-55).txt

Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 135432
Uplynulý èas: 14 min, 51 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registraèné k¾úèe: 0
Infikované registraèné hodnoty: 0
Infikované položky registraèných dát: 0
Infikované prieèinky: 0
Infikované súbory: 0

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registraèné k¾úèe:
(Škodlivé položky neboli zistené)

Infikované registraèné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registraèných dát:
(Škodlivé položky neboli zistené)

Infikované prieèinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
(Škodlivé položky neboli zistené)

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: preventivny log

#6 Příspěvek od cernohous13 »

Měl jsi tam dost těžkou infekci proto bych provedl ještě hlubší test.
Stáhni si Obrázek ComboFix
a ulož ho na plochu.
Ukonči všechna aktivní okna,vypni Antispy a Antivir a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna a nic nespouštěj
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Kdyby ti po použití ComboFixu systém nenaběhl - při restartu F8 a poslední známá funkční konfigurace
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

hinatahyuuga
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 30 kvě 2008 13:37

Re: preventivny log

#7 Příspěvek od hinatahyuuga »

ComboFix 10-10-21.07 - Artemisko 10/22/2010 14:05:47.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.712 [GMT 2:00]
Running from: C:\Documents and Settings\Artemisko\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
C:\WINDOWS\ST6UNST.000

Infected copy of C:\WINDOWS\system32\charmap.exe was found and disinfected
Restored copy from - C:\WINDOWS\system32\dllcache\charmap.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS


((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 )))))))))))))))))))))))))))))))
.

2010-10-21 15:34:40 . 2010-10-21 15:35:33 -------- d-----w- C:\Program Files\Sid Meier's Civilization V
2010-10-21 13:19:21 . 2010-10-21 13:19:21 -------- d-----w- C:\Documents and Settings\Artemisko\Application Data\Malwarebytes
2010-10-21 13:19:12 . 2010-04-29 13:39:38 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-10-21 13:19:09 . 2010-10-21 13:19:15 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-10-21 13:19:09 . 2010-10-21 13:19:09 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-10-21 13:19:09 . 2010-04-29 13:39:26 20952 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2010-10-21 11:21:31 . 2010-10-21 11:21:31 -------- d-----w- C:\Documents and Settings\Artemisko\Application Data\Zoner
2010-10-21 11:21:25 . 2010-10-21 11:21:25 -------- d-----w- C:\Documents and Settings\Artemisko\Local Settings\Application Data\Zoner
2010-10-21 11:18:54 . 2010-10-21 11:18:54 -------- d-----w- C:\Program Files\Zoner
2010-10-20 19:02:19 . 2006-02-04 01:50:16 5174 ----a-w- C:\WINDOWS\system32\nppt9x.vxd
2010-10-20 19:02:19 . 2006-02-04 01:50:16 4682 ----a-w- C:\WINDOWS\system32\npptNT2.sys
2010-10-20 18:45:48 . 2010-10-20 18:45:48 -------- d-----w- C:\Documents and Settings\Artemisko\Application Data\InstallShield
2010-10-20 18:05:15 . 2010-10-20 18:05:15 -------- d-----w- C:\Program Files\Bethesda Softworks
2010-10-20 18:04:31 . 2010-10-21 17:29:11 -------- d-----w- C:\Documents and Settings\Artemisko\Local Settings\Application Data\Oblivion
2010-10-19 08:50:28 . 2002-11-02 07:53:04 57344 ----a-w- C:\WINDOWS\system32\WNASPINT.DLL
2010-10-19 08:42:08 . 2010-10-19 08:42:08 -------- d-----w- C:\eJay
2010-10-19 08:40:55 . 2004-10-22 00:18:12 749568 ----a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2010-10-19 08:40:55 . 2004-10-22 00:17:48 69715 ----a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2010-10-19 08:40:55 . 2004-10-22 00:17:04 274432 ----a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2010-10-19 08:40:55 . 2004-10-22 00:16:28 180224 ----a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2010-10-19 08:40:55 . 2004-10-22 00:16:10 5632 ----a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2010-10-19 08:40:40 . 2010-10-19 08:40:40 192644 ----a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2010-10-19 08:40:39 . 2010-10-19 08:40:39 323716 ----a-w- C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2010-10-13 20:57:42 . 2010-10-13 20:57:42 -------- d-----w- C:\WINDOWS\system32\wbem\Repository
2010-10-13 20:28:33 . 2010-10-13 20:28:34 -------- d-----w- C:\Documents and Settings\Artemisko\Application Data\MSNInstaller
2010-10-13 11:47:11 . 2010-09-18 06:53:25 953856 -c----w- C:\WINDOWS\system32\dllcache\mfc40u.dll
2010-10-13 11:47:10 . 2010-09-18 06:53:25 974848 -c----w- C:\WINDOWS\system32\dllcache\mfc42.dll
2010-10-13 11:47:01 . 2010-08-23 16:12:04 617472 -c----w- C:\WINDOWS\system32\dllcache\comctl32.dll
2010-10-12 21:18:06 . 2005-05-10 16:54:30 258352 ----a-w- C:\WINDOWS\system32\unicows.dll
2010-10-09 13:13:44 . 2010-10-10 13:30:05 -------- d-----w- C:\Documents and Settings\Artemisko\Application Data\AIMP
2010-10-09 13:07:55 . 2010-10-12 22:18:39 -------- d-----w- C:\Program Files\AIMP2
2010-10-06 13:25:41 . 2010-10-19 09:51:36 -------- d-----w- C:\Program Files\Magic Workstation
2010-10-05 17:19:05 . 2010-09-07 15:12:17 38848 ----a-w- C:\WINDOWS\avastSS.scr
2010-09-30 09:43:33 . 2008-04-14 00:12:04 159232 ----a-w- C:\WINDOWS\system32\ptpusd.dll
2010-09-28 14:36:07 . 2010-10-07 11:55:03 42661920 --sha-w- C:\WINDOWS\system32\drivers\fidbox.dat
2010-09-25 23:45:35 . 2010-09-25 23:45:35 -------- d-----w- C:\Documents and Settings\Artemisko\Local Settings\Application Data\SKIDROW
2010-09-25 23:40:35 . 2010-09-25 23:40:35 -------- d-----w- C:\Program Files\Wizards of the Coast LLC
2010-09-23 07:36:51 . 2010-09-23 08:10:04 -------- d-----w- C:\Program Files\MOHPA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23:26 . 2004-08-04 10:00:00 974848 ----a-w- C:\WINDOWS\system32\mfc42u.dll
2010-09-18 06:53:25 . 2004-08-04 10:00:00 974848 ----a-w- C:\WINDOWS\system32\mfc42.dll
2010-09-18 06:53:25 . 2004-08-04 10:00:00 954368 ----a-w- C:\WINDOWS\system32\mfc40.dll
2010-09-18 06:53:25 . 2004-08-04 10:00:00 953856 ----a-w- C:\WINDOWS\system32\mfc40u.dll
2010-09-09 14:16:31 . 2006-03-04 03:33:46 667136 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-09-09 14:16:30 . 2004-08-04 10:00:00 61952 ----a-w- C:\WINDOWS\system32\tdc.ocx
2010-09-09 14:16:29 . 2004-08-04 10:00:00 81920 ----a-w- C:\WINDOWS\system32\ieencode.dll
2010-09-08 16:49:49 . 2004-08-04 10:00:00 369664 ----a-w- C:\WINDOWS\system32\html.iec
2010-09-07 15:11:54 . 2010-03-11 14:22:48 167592 ----a-w- C:\WINDOWS\system32\aswBoot.exe
2010-09-07 14:52:25 . 2010-03-11 14:23:02 46672 ----a-w- C:\WINDOWS\system32\drivers\aswTdi.sys
2010-09-07 14:52:03 . 2010-03-11 14:23:03 165584 ----a-w- C:\WINDOWS\system32\drivers\aswSP.sys
2010-09-07 14:47:46 . 2010-03-11 14:23:02 23376 ----a-w- C:\WINDOWS\system32\drivers\aswRdr.sys
2010-09-07 14:47:19 . 2010-03-11 14:23:00 100176 ----a-w- C:\WINDOWS\system32\drivers\aswmon2.sys
2010-09-07 14:47:16 . 2010-03-11 14:23:00 94544 ----a-w- C:\WINDOWS\system32\drivers\aswmon.sys
2010-09-07 14:47:07 . 2010-03-11 14:23:03 17744 ----a-w- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010-09-07 14:46:51 . 2010-03-11 14:23:00 28880 ----a-w- C:\WINDOWS\system32\drivers\aavmker4.sys
2010-09-01 11:51:14 . 2004-08-04 10:00:00 285824 ----a-w- C:\WINDOWS\system32\atmfd.dll
2010-08-31 13:42:52 . 2004-08-04 10:00:00 1852800 ----a-w- C:\WINDOWS\system32\win32k.sys
2010-08-27 08:02:29 . 2004-08-04 10:00:00 119808 ----a-w- C:\WINDOWS\system32\t2embed.dll
2010-08-27 05:57:43 . 2004-08-04 10:00:00 99840 ----a-w- C:\WINDOWS\system32\srvsvc.dll
2010-08-26 13:39:50 . 2004-08-04 10:00:00 357248 ----a-w- C:\WINDOWS\system32\drivers\srv.sys
2010-08-26 12:52:45 . 2010-03-12 12:35:00 5120 ----a-w- C:\WINDOWS\system32\xpsp4res.dll
2010-08-23 16:12:04 . 2004-08-04 10:00:00 617472 ----a-w- C:\WINDOWS\system32\comctl32.dll
2010-08-17 23:22:00 . 2010-05-09 07:08:53 3717904 ----a-w- C:\WINDOWS\system32\GameMon.des
2010-08-17 13:17:06 . 2004-08-04 10:00:00 58880 ----a-w- C:\WINDOWS\system32\spoolsv.exe
2010-08-16 08:45:00 . 2004-08-04 10:00:00 590848 ----a-w- C:\WINDOWS\system32\rpcrt4.dll

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: preventivny log

#8 Příspěvek od cernohous13 »

:?: log není kompletní - chybí důležité pokračování.

Podívej se zde C:/Combofix.txt a zkopíruj to všechno sem
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

hinatahyuuga
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 30 kvě 2008 13:37

Re: preventivny log

#9 Příspěvek od hinatahyuuga »

praveze som to kopiroval odtial ...ono mi to nejaku chybu pocas toho vyhodilo ...asi to musim dat odznova ze ?

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: preventivny log

#10 Příspěvek od cernohous13 »

Ano, bude nejlepší opakovat :(
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

hinatahyuuga
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 30 kvě 2008 13:37

Re: preventivny log

#11 Příspěvek od hinatahyuuga »

ComboFix 10-10-21.07 - Artemisko 10/26/2010 9:42.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.719 [GMT 2:00]
Running from: c:\documents and settings\Artemisko\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\install.exe
c:\windows\ST6UNST.000

-- Previous Run --

Infected copy of c:\windows\system32\charmap.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\charmap.exe

--------

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS


((((((((((((((((((((((((( Files Created from 2010-09-26 to 2010-10-26 )))))))))))))))))))))))))))))))
.

2010-10-22 15:51 . 2010-10-22 15:51 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-10-22 15:50 . 2010-10-22 15:51 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-10-22 15:50 . 2010-10-23 14:56 -------- d-----w- c:\documents and settings\Artemisko\Application Data\DAEMON Tools Lite
2010-10-22 15:50 . 2010-10-22 15:50 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-10-21 15:34 . 2010-10-21 15:35 -------- d-----w- c:\program files\Sid Meier's Civilization V
2010-10-21 13:19 . 2010-10-21 13:19 -------- d-----w- c:\documents and settings\Artemisko\Application Data\Malwarebytes
2010-10-21 13:19 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-21 13:19 . 2010-10-21 13:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-21 13:19 . 2010-10-21 13:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-21 13:19 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-21 11:21 . 2010-10-21 11:21 -------- d-----w- c:\documents and settings\Artemisko\Application Data\Zoner
2010-10-21 11:21 . 2010-10-21 11:21 -------- d-----w- c:\documents and settings\Artemisko\Local Settings\Application Data\Zoner
2010-10-21 11:18 . 2010-10-21 11:18 -------- d-----w- c:\program files\Zoner
2010-10-20 19:02 . 2006-02-04 01:50 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2010-10-20 19:02 . 2006-02-04 01:50 4682 ----a-w- c:\windows\system32\npptNT2.sys
2010-10-20 18:45 . 2010-10-20 18:45 -------- d-----w- c:\documents and settings\Artemisko\Application Data\InstallShield
2010-10-20 18:05 . 2010-10-20 18:05 -------- d-----w- c:\program files\Bethesda Softworks
2010-10-20 18:04 . 2010-10-22 16:51 -------- d-----w- c:\documents and settings\Artemisko\Local Settings\Application Data\Oblivion
2010-10-19 08:50 . 2002-11-02 07:53 57344 ----a-w- c:\windows\system32\WNASPINT.DLL
2010-10-19 08:42 . 2010-10-19 08:42 -------- d-----w- C:\eJay
2010-10-19 08:40 . 2004-10-22 00:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2010-10-19 08:40 . 2004-10-22 00:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2010-10-19 08:40 . 2004-10-22 00:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2010-10-19 08:40 . 2004-10-22 00:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2010-10-19 08:40 . 2004-10-22 00:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2010-10-19 08:40 . 2010-10-19 08:40 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2010-10-19 08:40 . 2010-10-19 08:40 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2010-10-13 20:57 . 2010-10-13 20:57 -------- d-----w- c:\windows\system32\wbem\Repository
2010-10-13 20:28 . 2010-10-13 20:28 -------- d-----w- c:\documents and settings\Artemisko\Application Data\MSNInstaller
2010-10-13 11:47 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 11:47 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 11:47 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 21:18 . 2005-05-10 16:54 258352 ----a-w- c:\windows\system32\unicows.dll
2010-10-09 13:13 . 2010-10-10 13:30 -------- d-----w- c:\documents and settings\Artemisko\Application Data\AIMP
2010-10-09 13:07 . 2010-10-12 22:18 -------- d-----w- c:\program files\AIMP2
2010-10-06 13:25 . 2010-10-19 09:51 -------- d-----w- c:\program files\Magic Workstation
2010-10-05 17:19 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-09-30 09:43 . 2008-04-14 00:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-09-28 14:36 . 2010-10-07 11:55 42661920 --sha-w- c:\windows\system32\drivers\fidbox.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-22 15:50 . 2010-03-11 15:34 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-18 10:23 . 2004-08-04 10:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-04 10:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-04 10:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-04 10:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-09 14:16 . 2006-03-04 03:33 667136 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 14:16 . 2004-08-04 10:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-09-09 14:16 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-09-08 16:49 . 2004-08-04 10:00 369664 ----a-w- c:\windows\system32\html.iec
2010-09-07 15:11 . 2010-03-11 14:22 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-07 14:52 . 2010-03-11 14:23 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 14:52 . 2010-03-11 14:23 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 14:47 . 2010-03-11 14:23 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 14:47 . 2010-03-11 14:23 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-07 14:47 . 2010-03-11 14:23 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-07 14:47 . 2010-03-11 14:23 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-07 14:46 . 2010-03-11 14:23 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-01 11:51 . 2004-08-04 10:00 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2004-08-04 10:00 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-08-04 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2004-08-04 10:00 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2004-08-04 10:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2010-03-12 12:35 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2004-08-04 10:00 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 23:22 . 2010-05-09 07:08 3717904 ----a-w- c:\windows\system32\GameMon.des
2010-08-17 13:17 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2004-08-04 10:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
.

------- Sigcheck -------

[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748_0$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"NVHotkey"="nvHotkey.dll" [2009-01-30 90112]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"nwiz"="nwiz.exe" [2009-01-30 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2006-11-12 10:48 157592 ----a-w- c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-04-12 22:46 1135912 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2007-08-22 15:31 80896 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2006-10-13 10:31 184320 ------w- c:\program files\Dell\MediaDirect\PCMService.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\ijjiOptimizer.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Games\\rune\\System\\Rune.exe"=
"c:\\Documents and Settings\\Artemisko\\Local Settings\\Application Data\\Kamuse\\KCSTrayDownloader\\KCSTrayDownloaderEngine.exe"=
"c:\\Games\\battleforge\\Bootstrapper.exe"=
"c:\\Games\\battleforge\\BattleForge.exe"=
"c:\\Program Files\\Tunngle\\TnglCtrl.exe"=
"c:\\Program Files\\Tunngle\\Tunngle.exe"=
"c:\\Program Files\\QIP Infium\\infium.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Games\\HoN Lan UB Edition1,5\\hon.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57196:TCP"= 57196:TCP:Pando Media Booster
"57196:UDP"= 57196:UDP:Pando Media Booster
"8377:TCP"= 8377:TCP:League of Legends Launcher
"8377:UDP"= 8377:UDP:League of Legends Launcher
"8378:TCP"= 8378:TCP:League of Legends Launcher
"8378:UDP"= 8378:UDP:League of Legends Launcher
"6909:TCP"= 6909:TCP:League of Legends Launcher
"6909:UDP"= 6909:UDP:League of Legends Launcher
"6934:TCP"= 6934:TCP:League of Legends Launcher
"6934:UDP"= 6934:UDP:League of Legends Launcher
"6881:TCP"= 6881:TCP:League of Legends Launcher
"6881:UDP"= 6881:UDP:League of Legends Launcher
"6948:TCP"= 6948:TCP:League of Legends Launcher
"6948:UDP"= 6948:UDP:League of Legends Launcher
"6913:TCP"= 6913:TCP:League of Legends Launcher
"6913:UDP"= 6913:UDP:League of Legends Launcher
"6956:TCP"= 6956:TCP:League of Legends Launcher
"6956:UDP"= 6956:UDP:League of Legends Launcher
"6932:TCP"= 6932:TCP:League of Legends Launcher
"6932:UDP"= 6932:UDP:League of Legends Launcher
"1226:TCP"= 1226:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/11/2010 4:23 PM 165584]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [5/2/2010 9:24 PM 93360]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/11/2010 4:23 PM 17744]
R2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [9/5/2010 1:41 PM 716024]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [9/5/2010 1:41 PM 27136]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/9/2010 9:56 AM 136176]
S3 dump_wmimmc;dump_wmimmc;\??\c:\gameswebzen\ArchLord\GameGuard\dump_wmimmc.sys --> c:\gameswebzen\ArchLord\GameGuard\dump_wmimmc.sys [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ARTEMI~1\LOCALS~1\Temp\NVG26E.tmp --> c:\docume~1\ARTEMI~1\LOCALS~1\Temp\NVG26E.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 vtany;vtany;\??\c:\windows\vtany.sys --> c:\windows\vtany.sys [?]
S3 xhunter1;xhunter1;\??\c:\windows\xhunter1.sys --> c:\windows\xhunter1.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/11/2010 5:34 PM 691696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-09 07:56]

2010-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-09 07:56]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Artemisko\Application Data\Mozilla\Firefox\Profiles\b4mv35hj.default\
FF - component: c:\documents and settings\Artemisko\Application Data\Mozilla\Firefox\Profiles\b4mv35hj.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\documents and settings\Artemisko\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Elmoreden Updater 1.00 - c:\games\Lineage II Interlude\Lineage II\Uninstall.exe



[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ARTEMI~1\LOCALS~1\Temp\NVG26E.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-507921405-1757981266-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:1c,fd,c3,2b,dd,5f,09,6a,84,cf,0c,41,d3,74,b6,fa,e6,61,dc,1d,37,
bb,84,b9,90,0a,0e,e4,13,ec,3a,d8,f2,24,30,1a,ff,7f,a4,18,7d,ee,dd,4e,66,9a,\
"rkeysecu"=hex:15,28,2b,60,35,cc,72,32,0a,aa,fe,57,84,c2,65,5b
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1008)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-10-26 10:02:15
ComboFix-quarantined-files.txt 2010-10-26 08:02

Pre-Run: 14,214,098,944 bytes free
Post-Run: 14,177,730,560 bytes free

- - End Of File - - 8B9788BD9D5300D381622E7E9A477922

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: preventivny log

#12 Příspěvek od cernohous13 »

:arrow: zdá se, že máš čisto
a jestli už nenacházíš nic podivného, tak po sobě uklidím :wink:

:arrow: ComboFix odinstalujeme
jdi Start -> Spustit... a zkopíruj ComboFix /Uninstall (pozor, za x je mezera) -> OK

:arrow: Stáhni TempFolderCleaner http://oldtimer.geekstogo.com/TFC.exe
Zavři všechny programy a spusť. Po ukončení akce bude PC restartován.
Pokud ne, restartuj sám.
(čistí Temp složky , nečistí URL, historii, prefetch ani cookies)

:arrow: stáhni program OTC tady: http://oldtimer.geekstogo.com/OTC.exe - spusť ho -> "CleanUp" (smaže dříve použité čističe)

:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar"

zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.
spustit "Nástroje" > "Obnova systému" - 1.řádek zachovej, ostatní "Odstranit"

Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:arrow: Po vyčištění by se hodila defragmentace
doporučuji http://www.slunecnice.cz/sw/defraggler/ + čeština

:arrow: Nakonec mi dej současný RSIT log
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Odpovědět