
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
nejde pristupovat na stranky vyzadujuce https
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 31
- Registrován: 19 úno 2009 20:51
nejde pristupovat na stranky vyzadujuce https
zdravim, vyskusal som uz vsetko mozne, v ziadnom prehlidaci nejde pristupovat na secured stranky, log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Užívateľ at 2010-12-23 14:24:16
Microsoft Windows 7 Home Premium
System drive C: has 65 GB (65%) free of 100 GB
Total RAM: 3959 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:24:21, on 23. 12. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\boostspeed.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Užívateľ.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SmileyCentral Service (SmileyCentral_1vService) - SmileyCentral - C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6322 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Essentials\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\boostspeed.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/ --channel=3552.0100D180.467715951 /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Google\Chrome\Application\8.0.552.224\gcswf32.dll" --lang=en-US --plugin-data-dir="C:\Users\Užívateľ\AppData\Local\Google\Chrome\User Data\Default" --channel=3552.08E91E4C.1159073603 /prefetch:4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel=3552.0528A72C.393861171 /prefetch:12
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/ --channel=3552.06D41780.344942855 /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/ --channel=3552.04BF2A80.1319128591 /prefetch:3
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
"C:\Users\Užívateľ\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-03-26 10135584]
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-09-15 1448568]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
C:\Users\Užívateľ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2010-09-01 250368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-12-23 13:15:32 ----D---- C:\Program Files\CCleaner
2010-12-23 13:09:07 ----D---- C:\Users\Užívateľ\AppData\Roaming\Auslogics
2010-12-23 13:08:32 ----AD---- C:\ProgramData\TEMP
2010-12-23 13:08:17 ----D---- C:\Program Files (x86)\Auslogics
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\mshta.exe
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\jscript.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\inseng.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\mshta.exe
2010-12-23 12:31:38 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\jscript9.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\jscript.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\inseng.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\imgutil.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\iexpress.exe
2010-12-23 12:31:38 ----A---- C:\Windows\system32\ieUnatt.exe
2010-12-23 12:31:38 ----A---- C:\Windows\system32\ieui.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\iesysprep.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2010-12-23 12:31:37 ----A---- C:\Windows\system32\mshtml.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-23 12:31:37 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ieakui.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ieaksie.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ieakeng.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\IEAdvpack.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ie4uinit.exe
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\icardie.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\admparse.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iesetup.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iertutil.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iernonce.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iepeers.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\ieframe.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\ieapfltr.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\icardie.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\dxtrans.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\dxtmsft.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\admparse.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\wextract.exe
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\url.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\occache.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\msls31.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\wininet.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\wextract.exe
2010-12-23 12:31:35 ----A---- C:\Windows\system32\webcheck.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\vbscript.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\urlmon.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\url.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2010-12-23 12:31:35 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2010-12-23 12:31:35 ----A---- C:\Windows\system32\pngfilt.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\occache.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\msrating.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\msls31.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\mshtmler.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-23 12:29:30 ----A---- C:\Windows\system32\mfreadwrite.dll
2010-12-23 12:29:30 ----A---- C:\Windows\system32\mfps.dll
2010-12-23 12:29:29 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2010-12-23 12:29:28 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2010-12-23 12:29:28 ----A---- C:\Windows\system32\WMVDECOD.DLL
2010-12-23 12:29:28 ----A---- C:\Windows\system32\mf.dll
2010-12-23 12:29:27 ----A---- C:\Windows\SYSWOW64\mf.dll
2010-12-23 12:29:09 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2010-12-23 12:29:09 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2010-12-23 12:29:09 ----A---- C:\Windows\system32\d2d1.dll
2010-12-23 12:29:08 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2010-12-23 12:29:08 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\FntCache.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\DWrite.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\d3d10warp.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-12-23 12:28:50 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2010-12-23 12:28:50 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2010-12-23 12:28:50 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-12-23 12:28:50 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-12-23 12:28:17 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2010-12-23 12:28:17 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-12-23 12:27:21 ----D---- C:\Program Files (x86)\Feedback Tool
2010-12-23 12:03:59 ----D---- C:\rsit
2010-12-23 12:03:59 ----D---- C:\Program Files\trend micro
2010-12-23 11:55:44 ----SHD---- C:\$RECYCLE.BIN
2010-12-23 11:47:54 ----D---- C:\Windows\temp
2010-12-23 11:47:52 ----A---- C:\ComboFix.txt
2010-12-23 11:42:10 ----A---- C:\Windows\zip.exe
2010-12-23 11:42:10 ----A---- C:\Windows\SWSC.exe
2010-12-23 11:42:10 ----A---- C:\Windows\SWREG.exe
2010-12-23 11:42:10 ----A---- C:\Windows\sed.exe
2010-12-23 11:42:10 ----A---- C:\Windows\PEV.exe
2010-12-23 11:42:10 ----A---- C:\Windows\NIRCMD.exe
2010-12-23 11:42:10 ----A---- C:\Windows\MBR.exe
2010-12-23 11:42:10 ----A---- C:\Windows\grep.exe
2010-12-23 11:41:25 ----A---- C:\Windows\SWXCACLS.exe
2010-12-23 11:41:23 ----D---- C:\32788R22FWJFW
2010-12-23 11:20:48 ----D---- C:\Windows\ERDNT
2010-12-23 11:17:29 ----D---- C:\Qoobox
2010-12-16 06:22:53 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-16 06:22:53 ----A---- C:\Windows\system32\tzres.dll
2010-12-16 06:22:51 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2010-12-16 06:22:51 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2010-12-16 06:22:51 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\taskschd.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\taskeng.exe
2010-12-16 06:22:51 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\schtasks.exe
2010-12-16 06:22:51 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-16 06:22:50 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2010-12-16 06:22:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2010-12-16 06:22:47 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2010-12-16 06:22:47 ----A---- C:\Windows\system32\atmlib.dll
2010-12-16 06:22:47 ----A---- C:\Windows\system32\atmfd.dll
2010-12-16 06:22:46 ----A---- C:\Windows\SYSWOW64\webio.dll
2010-12-16 06:22:46 ----A---- C:\Windows\system32\win32k.sys
2010-12-16 06:22:46 ----A---- C:\Windows\system32\webio.dll
2010-12-16 06:22:45 ----A---- C:\Windows\system32\consent.exe
2010-12-02 20:04:52 ----D---- C:\Program Files (x86)\SmileyCentral_1v
2010-12-02 20:04:39 ----D---- C:\Program Files (x86)\SmileyCentral_1vEI
2010-11-26 21:25:17 ----D---- C:\Program Files (x86)\Ask.com
2010-11-26 21:25:03 ----D---- C:\Program Files (x86)\The KMPlayer
2010-11-24 18:18:05 ----A---- C:\Windows\NeroDigital.ini
======List of files/folders modified in the last 1 months======
2010-12-23 14:15:51 ----D---- C:\Windows\Prefetch
2010-12-23 14:15:44 ----RD---- C:\Users
2010-12-23 13:42:41 ----D---- C:\Windows\System32
2010-12-23 13:33:15 ----D---- C:\Windows\system32\drivers\etc
2010-12-23 13:15:49 ----D---- C:\Windows\debug
2010-12-23 13:15:49 ----D---- C:\Windows
2010-12-23 13:15:32 ----RD---- C:\Program Files
2010-12-23 13:12:44 ----SHD---- C:\System Volume Information
2010-12-23 13:09:20 ----D---- C:\Windows\Downloaded Program Files
2010-12-23 13:08:32 ----D---- C:\ProgramData
2010-12-23 13:08:17 ----RD---- C:\Program Files (x86)
2010-12-23 13:03:24 ----D---- C:\Windows\system32\config
2010-12-23 12:54:45 ----D---- C:\Windows\system32\NDF
2010-12-23 12:39:27 ----D---- C:\Windows\inf
2010-12-23 12:39:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-23 12:35:44 ----D---- C:\Windows\system32\Tasks
2010-12-23 12:35:37 ----D---- C:\Windows\winsxs
2010-12-23 12:35:19 ----D---- C:\ProgramData\NVIDIA
2010-12-23 12:35:16 ----A---- C:\Windows\SYSWOW64\log.txt
2010-12-23 12:34:12 ----D---- C:\Windows\SYSWOW64\sk-SK
2010-12-23 12:34:12 ----D---- C:\Windows\SYSWOW64\migration
2010-12-23 12:34:12 ----D---- C:\Windows\SYSWOW64\en-US
2010-12-23 12:34:12 ----D---- C:\Program Files\Internet Explorer
2010-12-23 12:34:11 ----D---- C:\Windows\SysWOW64
2010-12-23 12:34:11 ----D---- C:\Windows\system32\sk-SK
2010-12-23 12:34:11 ----D---- C:\Windows\system32\migration
2010-12-23 12:34:11 ----D---- C:\Windows\system32\en-US
2010-12-23 12:34:11 ----D---- C:\Windows\PolicyDefinitions
2010-12-23 12:34:10 ----D---- C:\Program Files (x86)\Internet Explorer
2010-12-23 12:31:57 ----D---- C:\Windows\system32\catroot2
2010-12-23 12:31:57 ----D---- C:\Windows\system32\catroot
2010-12-23 12:28:01 ----D---- C:\Windows\SoftwareDistribution
2010-12-23 12:27:28 ----SHD---- C:\Windows\Installer
2010-12-23 12:27:23 ----SD---- C:\Users\Užívateľ\AppData\Roaming\Microsoft
2010-12-23 12:27:10 ----D---- C:\Windows\Logs
2010-12-23 12:24:57 ----D---- C:\Windows\tracing
2010-12-23 11:47:54 ----D---- C:\Windows\system32\drivers
2010-12-23 11:46:07 ----A---- C:\Windows\system.ini
2010-12-23 11:43:51 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-23 11:43:51 ----D---- C:\Windows\AppPatch
2010-12-23 11:43:51 ----D---- C:\Program Files\Common Files
2010-12-23 11:43:51 ----D---- C:\Program Files (x86)\Common Files
2010-12-23 11:36:20 ----D---- C:\Windows\Tasks
2010-12-23 11:36:20 ----D---- C:\Windows\system32\wfp
2010-12-23 11:36:19 ----D---- C:\Windows\system32\wbem
2010-12-23 11:35:37 ----D---- C:\Windows\system32\DriverStore
2010-12-23 11:35:28 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-12-23 11:35:28 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2010-12-23 11:35:26 ----D---- C:\Program Files (x86)\IrfanView
2010-12-23 11:35:21 ----D---- C:\Windows\registration
2010-12-23 11:35:09 ----SD---- C:\ProgramData\Microsoft
2010-12-23 11:34:53 ----D---- C:\Program Files (x86)\Google
2010-12-16 11:45:34 ----D---- C:\Windows\rescache
2010-12-16 11:18:08 ----D---- C:\Program Files\Windows Mail
2010-12-16 11:18:08 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-16 06:48:53 ----A---- C:\Windows\system32\MRT.exe
2010-12-15 08:20:01 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2010-12-09 19:08:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-11-24 18:23:29 ----D---- C:\Windows\system32\LogFiles
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 173984]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-03-26 2307616]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 40832]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-09-07 155752]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2010-11-19 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2010-11-19 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2010-11-19 30528]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-09-30 268824]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17424]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
R2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe [2010-12-02 28766]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-19 1255736]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Užívateľ at 2010-12-23 14:24:16
Microsoft Windows 7 Home Premium
System drive C: has 65 GB (65%) free of 100 GB
Total RAM: 3959 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:24:21, on 23. 12. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\boostspeed.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Užívateľ.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SmileyCentral Service (SmileyCentral_1vService) - SmileyCentral - C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6322 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Essentials\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\boostspeed.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/ --channel=3552.0100D180.467715951 /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Google\Chrome\Application\8.0.552.224\gcswf32.dll" --lang=en-US --plugin-data-dir="C:\Users\Užívateľ\AppData\Local\Google\Chrome\User Data\Default" --channel=3552.08E91E4C.1159073603 /prefetch:4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel=3552.0528A72C.393861171 /prefetch:12
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/ --channel=3552.06D41780.344942855 /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyImpact/npn_with_spdy/ --channel=3552.04BF2A80.1319128591 /prefetch:3
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
"C:\Users\Užívateľ\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-03-26 10135584]
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-09-15 1448568]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
C:\Users\Užívateľ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2010-09-01 250368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-12-23 13:15:32 ----D---- C:\Program Files\CCleaner
2010-12-23 13:09:07 ----D---- C:\Users\Užívateľ\AppData\Roaming\Auslogics
2010-12-23 13:08:32 ----AD---- C:\ProgramData\TEMP
2010-12-23 13:08:17 ----D---- C:\Program Files (x86)\Auslogics
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\mshta.exe
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\jscript.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\inseng.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-12-23 12:31:38 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\mshta.exe
2010-12-23 12:31:38 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\jscript9.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\jscript.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\inseng.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\imgutil.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\iexpress.exe
2010-12-23 12:31:38 ----A---- C:\Windows\system32\ieUnatt.exe
2010-12-23 12:31:38 ----A---- C:\Windows\system32\ieui.dll
2010-12-23 12:31:38 ----A---- C:\Windows\system32\iesysprep.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2010-12-23 12:31:37 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2010-12-23 12:31:37 ----A---- C:\Windows\system32\mshtml.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-23 12:31:37 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ieakui.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ieaksie.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ieakeng.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\IEAdvpack.dll
2010-12-23 12:31:37 ----A---- C:\Windows\system32\ie4uinit.exe
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\icardie.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2010-12-23 12:31:36 ----A---- C:\Windows\SYSWOW64\admparse.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iesetup.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iertutil.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iernonce.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iepeers.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\ieframe.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\ieapfltr.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\icardie.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\dxtrans.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\dxtmsft.dll
2010-12-23 12:31:36 ----A---- C:\Windows\system32\admparse.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\wextract.exe
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\url.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\occache.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\msls31.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2010-12-23 12:31:35 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\wininet.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\wextract.exe
2010-12-23 12:31:35 ----A---- C:\Windows\system32\webcheck.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\vbscript.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\urlmon.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\url.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2010-12-23 12:31:35 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2010-12-23 12:31:35 ----A---- C:\Windows\system32\pngfilt.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\occache.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\msrating.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\msls31.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\mshtmler.dll
2010-12-23 12:31:35 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-23 12:29:30 ----A---- C:\Windows\system32\mfreadwrite.dll
2010-12-23 12:29:30 ----A---- C:\Windows\system32\mfps.dll
2010-12-23 12:29:29 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2010-12-23 12:29:28 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2010-12-23 12:29:28 ----A---- C:\Windows\system32\WMVDECOD.DLL
2010-12-23 12:29:28 ----A---- C:\Windows\system32\mf.dll
2010-12-23 12:29:27 ----A---- C:\Windows\SYSWOW64\mf.dll
2010-12-23 12:29:09 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2010-12-23 12:29:09 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2010-12-23 12:29:09 ----A---- C:\Windows\system32\d2d1.dll
2010-12-23 12:29:08 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2010-12-23 12:29:08 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\FntCache.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\DWrite.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\d3d10warp.dll
2010-12-23 12:29:08 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-12-23 12:28:50 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2010-12-23 12:28:50 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2010-12-23 12:28:50 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-12-23 12:28:50 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-12-23 12:28:17 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2010-12-23 12:28:17 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-12-23 12:27:21 ----D---- C:\Program Files (x86)\Feedback Tool
2010-12-23 12:03:59 ----D---- C:\rsit
2010-12-23 12:03:59 ----D---- C:\Program Files\trend micro
2010-12-23 11:55:44 ----SHD---- C:\$RECYCLE.BIN
2010-12-23 11:47:54 ----D---- C:\Windows\temp
2010-12-23 11:47:52 ----A---- C:\ComboFix.txt
2010-12-23 11:42:10 ----A---- C:\Windows\zip.exe
2010-12-23 11:42:10 ----A---- C:\Windows\SWSC.exe
2010-12-23 11:42:10 ----A---- C:\Windows\SWREG.exe
2010-12-23 11:42:10 ----A---- C:\Windows\sed.exe
2010-12-23 11:42:10 ----A---- C:\Windows\PEV.exe
2010-12-23 11:42:10 ----A---- C:\Windows\NIRCMD.exe
2010-12-23 11:42:10 ----A---- C:\Windows\MBR.exe
2010-12-23 11:42:10 ----A---- C:\Windows\grep.exe
2010-12-23 11:41:25 ----A---- C:\Windows\SWXCACLS.exe
2010-12-23 11:41:23 ----D---- C:\32788R22FWJFW
2010-12-23 11:20:48 ----D---- C:\Windows\ERDNT
2010-12-23 11:17:29 ----D---- C:\Qoobox
2010-12-16 06:22:53 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-16 06:22:53 ----A---- C:\Windows\system32\tzres.dll
2010-12-16 06:22:51 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2010-12-16 06:22:51 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2010-12-16 06:22:51 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\taskschd.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\taskeng.exe
2010-12-16 06:22:51 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-16 06:22:51 ----A---- C:\Windows\system32\schtasks.exe
2010-12-16 06:22:51 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-16 06:22:50 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2010-12-16 06:22:47 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2010-12-16 06:22:47 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2010-12-16 06:22:47 ----A---- C:\Windows\system32\atmlib.dll
2010-12-16 06:22:47 ----A---- C:\Windows\system32\atmfd.dll
2010-12-16 06:22:46 ----A---- C:\Windows\SYSWOW64\webio.dll
2010-12-16 06:22:46 ----A---- C:\Windows\system32\win32k.sys
2010-12-16 06:22:46 ----A---- C:\Windows\system32\webio.dll
2010-12-16 06:22:45 ----A---- C:\Windows\system32\consent.exe
2010-12-02 20:04:52 ----D---- C:\Program Files (x86)\SmileyCentral_1v
2010-12-02 20:04:39 ----D---- C:\Program Files (x86)\SmileyCentral_1vEI
2010-11-26 21:25:17 ----D---- C:\Program Files (x86)\Ask.com
2010-11-26 21:25:03 ----D---- C:\Program Files (x86)\The KMPlayer
2010-11-24 18:18:05 ----A---- C:\Windows\NeroDigital.ini
======List of files/folders modified in the last 1 months======
2010-12-23 14:15:51 ----D---- C:\Windows\Prefetch
2010-12-23 14:15:44 ----RD---- C:\Users
2010-12-23 13:42:41 ----D---- C:\Windows\System32
2010-12-23 13:33:15 ----D---- C:\Windows\system32\drivers\etc
2010-12-23 13:15:49 ----D---- C:\Windows\debug
2010-12-23 13:15:49 ----D---- C:\Windows
2010-12-23 13:15:32 ----RD---- C:\Program Files
2010-12-23 13:12:44 ----SHD---- C:\System Volume Information
2010-12-23 13:09:20 ----D---- C:\Windows\Downloaded Program Files
2010-12-23 13:08:32 ----D---- C:\ProgramData
2010-12-23 13:08:17 ----RD---- C:\Program Files (x86)
2010-12-23 13:03:24 ----D---- C:\Windows\system32\config
2010-12-23 12:54:45 ----D---- C:\Windows\system32\NDF
2010-12-23 12:39:27 ----D---- C:\Windows\inf
2010-12-23 12:39:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-23 12:35:44 ----D---- C:\Windows\system32\Tasks
2010-12-23 12:35:37 ----D---- C:\Windows\winsxs
2010-12-23 12:35:19 ----D---- C:\ProgramData\NVIDIA
2010-12-23 12:35:16 ----A---- C:\Windows\SYSWOW64\log.txt
2010-12-23 12:34:12 ----D---- C:\Windows\SYSWOW64\sk-SK
2010-12-23 12:34:12 ----D---- C:\Windows\SYSWOW64\migration
2010-12-23 12:34:12 ----D---- C:\Windows\SYSWOW64\en-US
2010-12-23 12:34:12 ----D---- C:\Program Files\Internet Explorer
2010-12-23 12:34:11 ----D---- C:\Windows\SysWOW64
2010-12-23 12:34:11 ----D---- C:\Windows\system32\sk-SK
2010-12-23 12:34:11 ----D---- C:\Windows\system32\migration
2010-12-23 12:34:11 ----D---- C:\Windows\system32\en-US
2010-12-23 12:34:11 ----D---- C:\Windows\PolicyDefinitions
2010-12-23 12:34:10 ----D---- C:\Program Files (x86)\Internet Explorer
2010-12-23 12:31:57 ----D---- C:\Windows\system32\catroot2
2010-12-23 12:31:57 ----D---- C:\Windows\system32\catroot
2010-12-23 12:28:01 ----D---- C:\Windows\SoftwareDistribution
2010-12-23 12:27:28 ----SHD---- C:\Windows\Installer
2010-12-23 12:27:23 ----SD---- C:\Users\Užívateľ\AppData\Roaming\Microsoft
2010-12-23 12:27:10 ----D---- C:\Windows\Logs
2010-12-23 12:24:57 ----D---- C:\Windows\tracing
2010-12-23 11:47:54 ----D---- C:\Windows\system32\drivers
2010-12-23 11:46:07 ----A---- C:\Windows\system.ini
2010-12-23 11:43:51 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-23 11:43:51 ----D---- C:\Windows\AppPatch
2010-12-23 11:43:51 ----D---- C:\Program Files\Common Files
2010-12-23 11:43:51 ----D---- C:\Program Files (x86)\Common Files
2010-12-23 11:36:20 ----D---- C:\Windows\Tasks
2010-12-23 11:36:20 ----D---- C:\Windows\system32\wfp
2010-12-23 11:36:19 ----D---- C:\Windows\system32\wbem
2010-12-23 11:35:37 ----D---- C:\Windows\system32\DriverStore
2010-12-23 11:35:28 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-12-23 11:35:28 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2010-12-23 11:35:26 ----D---- C:\Program Files (x86)\IrfanView
2010-12-23 11:35:21 ----D---- C:\Windows\registration
2010-12-23 11:35:09 ----SD---- C:\ProgramData\Microsoft
2010-12-23 11:34:53 ----D---- C:\Program Files (x86)\Google
2010-12-16 11:45:34 ----D---- C:\Windows\rescache
2010-12-16 11:18:08 ----D---- C:\Program Files\Windows Mail
2010-12-16 11:18:08 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-16 06:48:53 ----A---- C:\Windows\system32\MRT.exe
2010-12-15 08:20:01 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2010-12-09 19:08:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-11-24 18:23:29 ----D---- C:\Windows\system32\LogFiles
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 173984]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-03-26 2307616]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 40832]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-09-07 155752]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2010-11-19 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2010-11-19 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2010-11-19 30528]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-09-30 268824]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17424]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
R2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~2\SMILEY~2\bar\1.bin\1vbarsvc.exe [2010-12-02 28766]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-19 1255736]
-----------------EOF-----------------
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: nejde pristupovat na stranky vyzadujuce https
Zdravím,
podle mých zkušeností potřebuješ pro přístup na zabezpečené stránky (https) v PC nainstalovaný jejich certifikát (*.crt)
podle mých zkušeností potřebuješ pro přístup na zabezpečené stránky (https) v PC nainstalovaný jejich certifikát (*.crt)

Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
-
- Návštěvník
- Příspěvky: 31
- Registrován: 19 úno 2009 20:51
Re: nejde pristupovat na stranky vyzadujuce https
vsetko fungovalo v poriadku, pred par dnami vsak proste prestali fungovat akekolvek stranky vyuzivajuce https (gmail, pokec, facebook).... skusal som vsetky mozne navody ktore sa tykali nefunkcnosti https ktore som na nete nasiel (od tych na microsoft support az po pochybne rady co som nasiel k tomuto na forach) no nic nezabralo, preto som postol log, ci sa nejeden o nejaku haved.... je mozne ze niekto, kto ten pc vyuziva klikol na nejaku blbost napr na facebooku ("pozri si Megan Fox v sprche") alebo nieco podobne...uz fakt si neviem rady, zabil som s tym cele poobedie 

- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: nejde pristupovat na stranky vyzadujuce https
a nemůžeš použít Obnovení systému k datu kdy to fungovalo?pred par dnami vsak proste prestali fungovat akekolvek stranky vyuzivajuce https
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
-
- Návštěvník
- Příspěvky: 31
- Registrován: 19 úno 2009 20:51
Re: nejde pristupovat na stranky vyzadujuce https
aj to som skusal, na den pred tym ako sa to stalo a to tiez nepomohlo
-
- Návštěvník
- Příspěvky: 31
- Registrován: 19 úno 2009 20:51
Re: nejde pristupovat na stranky vyzadujuce https
cernohous13:
mohli by ste mi prosim teda skusit skontrolovat ten log? budem velmi vdacny ak si najdete cas
mohli by ste mi prosim teda skusit skontrolovat ten log? budem velmi vdacny ak si najdete cas

- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: nejde pristupovat na stranky vyzadujuce https
Stáhni siComboFix
a ulož ho na plochu.
návod na použití: http://www.bleepingcomputer.com/combofi ... t-combofix
Ukonči všechna aktivní okna,vypni Antispy a Antivir a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna a nic nespouštěj
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Kdyby ti po použití ComboFixu systém nenaběhl - při restartu F8 a poslední známá funkční konfigurace
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
-
- Návštěvník
- Příspěvky: 31
- Registrován: 19 úno 2009 20:51
Re: nejde pristupovat na stranky vyzadujuce https
ComboFix 10-12-25.02 - Užívateľ . 12. 2010 14:29:31.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3959.2907 [GMT 1:00]
Running from: c:\users\Užívateľ\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BF5CEBDC-F2D3-7540-343C-F0CE11FD6E66}
SP: Microsoft Security Essentials *Disabled/Updated* {043D0A38-D4E9-7ACE-0E8C-CBBC6A7A24DB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-11-26 to 2010-12-26 )))))))))))))))))))))))))))))))
.
2010-12-26 13:31 . 2010-12-26 13:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-25 13:10 . 2010-11-09 20:35 8199504 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{59CD27F8-9194-46F7-B850-5597182AFC97}\mpengine.dll
2010-12-23 12:15 . 2010-12-23 12:15 -------- d-----w- c:\program files\CCleaner
2010-12-23 12:09 . 2010-12-23 12:12 -------- d-----w- c:\users\Užívateľ\AppData\Roaming\Auslogics
2010-12-23 12:08 . 2010-12-23 12:08 -------- d-----w- c:\program files (x86)\Auslogics
2010-12-23 11:29 . 2010-05-23 10:11 196608 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
2010-12-23 11:29 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2010-12-23 11:29 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2010-12-23 11:29 . 2010-08-16 06:14 737280 ----a-w- c:\windows\SysWow64\d2d1.dll
2010-12-23 11:29 . 2010-08-16 06:14 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2010-12-23 11:29 . 2010-08-16 06:14 1076224 ----a-w- c:\windows\SysWow64\DWrite.dll
2010-12-23 11:29 . 2010-08-16 06:14 1172480 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2010-12-23 11:28 . 2010-05-09 09:15 279552 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2010-12-23 11:28 . 2010-05-09 09:15 135168 ----a-w- c:\windows\SysWow64\XpsRasterService.dll
2010-12-23 11:28 . 2010-06-26 05:14 1495040 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2010-12-23 11:27 . 2010-12-23 11:27 -------- d-----w- c:\program files (x86)\Feedback Tool
2010-12-23 11:03 . 2010-12-23 13:24 -------- d-----w- c:\program files\trend micro
2010-12-23 11:03 . 2010-12-23 11:04 -------- d-----w- C:\rsit
2010-12-22 00:03 . 2010-12-22 00:03 -------- d-----w- c:\users\Užívateľ\AppData\Local\ElevatedDiagnostics
2010-12-16 05:22 . 2010-10-27 04:32 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2010-12-16 05:22 . 2010-11-02 04:40 496128 ----a-w- c:\windows\SysWow64\taskschd.dll
2010-12-16 05:22 . 2010-11-02 04:40 305152 ----a-w- c:\windows\SysWow64\taskcomp.dll
2010-12-16 05:22 . 2010-11-02 04:34 192000 ----a-w- c:\windows\SysWow64\taskeng.exe
2010-12-16 05:22 . 2010-11-02 04:34 179712 ----a-w- c:\windows\SysWow64\schtasks.exe
2010-12-16 05:22 . 2010-10-20 04:54 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2010-12-16 05:22 . 2010-10-20 02:58 294400 ----a-w- c:\windows\SysWow64\atmfd.dll
2010-12-16 05:22 . 2010-10-16 04:36 314368 ----a-w- c:\windows\SysWow64\webio.dll
2010-12-16 05:22 . 2010-10-12 05:05 35328 ----a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-16 05:22 . 2010-10-12 05:00 516096 ----a-w- c:\program files\Windows Mail\wab.exe
2010-12-16 05:22 . 2010-10-12 04:25 516096 ----a-w- c:\program files (x86)\Windows Mail\wab.exe
2010-12-02 19:04 . 2010-12-02 19:04 -------- d-----w- c:\program files (x86)\SmileyCentral_1v
2010-11-26 20:25 . 2010-11-26 20:25 -------- d-----w- c:\program files (x86)\Ask.com
2010-11-26 20:25 . 2010-11-26 20:25 -------- d-----w- c:\program files (x86)\The KMPlayer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-19 14:26 . 2010-11-19 13:43 30528 ----a-w- c:\windows\GVTDrv64.sys
2010-11-19 14:26 . 2010-11-19 13:40 25640 ----a-w- c:\windows\gdrv.sys
2010-11-19 13:56 . 2010-11-19 13:56 423656 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-11-19 13:46 . 2010-11-19 13:46 25640 ----a-w- c:\windows\etdrv.sys
2010-11-09 20:35 . 2010-11-23 08:31 8199504 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2010-11-02 04:34 . 2010-12-16 05:22 179712 ----a-w- c:\windows\SysWow64\schtasks.exe
2010-10-22 06:23 . 2010-11-19 14:33 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2010-10-22 06:23 . 2010-11-19 14:33 5473896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2010-10-22 06:23 . 2010-11-19 14:33 319080 ----a-w- c:\windows\SysWow64\nvdecodemft.dll
2010-10-22 06:23 . 2010-11-19 14:33 14899816 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2010-10-22 06:23 . 2010-11-19 14:33 4837480 ----a-w- c:\windows\SysWow64\nvcuda.dll
2010-10-22 06:23 . 2010-11-19 14:33 2912360 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2010-10-22 06:23 . 2010-11-19 14:33 2666600 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2010-10-22 06:23 . 2010-11-19 14:33 10023528 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2010-10-22 06:23 . 2010-11-19 14:33 13019752 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2010-10-22 06:23 . 2010-07-10 04:38 1719912 ----a-w- c:\windows\SysWow64\nvapi.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-23_10.46.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-23 11:31 . 2010-08-31 23:43 76800 c:\windows\SysWOW64\SetIEInstalledDate.exe
+ 2010-12-23 11:31 . 2010-08-31 23:43 74752 c:\windows\SysWOW64\RegisterIEPKEYs.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 49664 c:\windows\SysWOW64\pngfilt.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 48640 c:\windows\SysWOW64\mshtmler.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 67072 c:\windows\SysWOW64\mshtmled.dll
- 2010-12-16 05:22 . 2010-11-04 05:49 67072 c:\windows\SysWOW64\mshtmled.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 11264 c:\windows\SysWOW64\mshta.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 10240 c:\windows\SysWOW64\msfeedssync.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 44544 c:\windows\SysWOW64\msfeedsbs.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 66048 c:\windows\SysWOW64\migration\WininetPlugin.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 23552 c:\windows\SysWOW64\licmgr10.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 65024 c:\windows\SysWOW64\jsproxy.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 80384 c:\windows\SysWOW64\inseng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 33280 c:\windows\SysWOW64\imgutil.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 75264 c:\windows\SysWOW64\iesetup.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 32768 c:\windows\SysWOW64\iernonce.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 59392 c:\windows\SysWOW64\icardie.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 51200 c:\windows\SysWOW64\admparse.dll
+ 2010-12-24 09:31 . 2010-12-24 09:31 58330 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2010-11-19 14:27 . 2010-12-26 12:11 23434 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2010-12-23 10:38 25662 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2010-12-26 12:11 25662 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-13 23:58 . 2009-07-14 01:39 93184 c:\windows\system32\SetIEInstalledDate.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 93184 c:\windows\system32\SetIEInstalledDate.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 90624 c:\windows\system32\RegisterIEPKEYs.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 65024 c:\windows\system32\pngfilt.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 48640 c:\windows\system32\mshtmler.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 97792 c:\windows\system32\mshtmled.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 12288 c:\windows\system32\mshta.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 10752 c:\windows\system32\msfeedssync.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 52224 c:\windows\system32\msfeedsbs.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 86528 c:\windows\system32\migration\WininetPlugin.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 27136 c:\windows\system32\licmgr10.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 84480 c:\windows\system32\jsproxy.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 49664 c:\windows\system32\imgutil.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 85504 c:\windows\system32\iesetup.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 39424 c:\windows\system32\iernonce.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 93696 c:\windows\system32\ie4uinit.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 81920 c:\windows\system32\icardie.dll
+ 2010-11-19 13:35 . 2010-12-23 13:57 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-19 13:35 . 2010-12-16 10:18 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-11-19 13:35 . 2010-12-23 13:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-11-19 13:35 . 2010-12-16 10:18 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2010-12-23 13:57 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2010-12-16 10:18 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-23 11:31 . 2010-08-31 23:41 60416 c:\windows\system32\admparse.dll
+ 2009-07-14 04:46 . 2010-12-26 12:13 79264 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2009-07-14 04:46 . 2010-12-19 12:08 79264 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-11-19 16:25 . 2010-12-23 10:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-11-19 16:25 . 2010-12-23 11:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-19 16:25 . 2010-12-23 10:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-19 16:25 . 2010-12-23 11:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-11-19 14:14 . 2010-11-19 14:14 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-11-19 14:14 . 2010-12-24 09:33 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-11-19 13:46 . 2010-12-26 12:11 7118 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4139137649-2033661816-222925476-1000_UserData.bin
+ 2010-12-26 12:10 . 2010-12-26 12:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-23 10:45 . 2010-12-23 10:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-26 12:10 . 2010-12-26 12:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-23 11:31 . 2010-08-31 23:42 149504 c:\windows\SysWOW64\wextract.exe
+ 2010-12-23 11:31 . 2010-08-31 23:43 208384 c:\windows\SysWOW64\webcheck.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 424960 c:\windows\SysWOW64\vbscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 109568 c:\windows\SysWOW64\url.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 128000 c:\windows\SysWOW64\occache.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 166400 c:\windows\SysWOW64\msrating.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 160768 c:\windows\SysWOW64\msls31.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 596480 c:\windows\SysWOW64\msfeeds.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 719360 c:\windows\SysWOW64\jscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 150016 c:\windows\SysWOW64\iexpress.exe
+ 2010-12-23 11:31 . 2010-08-31 23:43 142848 c:\windows\SysWOW64\ieUnatt.exe
- 2010-12-16 05:22 . 2010-11-04 05:48 176640 c:\windows\SysWOW64\ieui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 176640 c:\windows\SysWOW64\ieui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 114176 c:\windows\SysWOW64\iesysprep.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 111104 c:\windows\SysWOW64\iepeers.dll
+ 2010-12-23 11:31 . 2010-08-31 23:55 460088 c:\windows\SysWOW64\iedkcs32.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 441856 c:\windows\SysWOW64\ieapfltr.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 163840 c:\windows\SysWOW64\ieakui.dll
- 2009-07-13 23:42 . 2009-07-14 01:05 163840 c:\windows\SysWOW64\ieakui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 227840 c:\windows\SysWOW64\ieaksie.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 130560 c:\windows\SysWOW64\ieakeng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 110592 c:\windows\SysWOW64\IEAdvpack.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 193024 c:\windows\SysWOW64\ie4uinit.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 223232 c:\windows\SysWOW64\dxtrans.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 353280 c:\windows\SysWOW64\dxtmsft.dll
+ 2010-12-23 11:28 . 2010-05-09 09:46 229888 c:\windows\system32\XpsRasterService.dll
- 2009-07-14 00:37 . 2009-07-14 01:41 229888 c:\windows\system32\XpsRasterService.dll
- 2009-07-14 00:37 . 2009-07-14 01:41 466432 c:\windows\system32\XpsGdiConverter.dll
+ 2010-12-23 11:28 . 2010-05-09 09:46 466432 c:\windows\system32\XpsGdiConverter.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 159232 c:\windows\system32\wextract.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 250368 c:\windows\system32\webcheck.dll
+ 2010-11-19 18:16 . 2010-12-25 15:03 207602 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2010-12-23 11:31 . 2010-08-31 23:41 601088 c:\windows\system32\vbscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 112128 c:\windows\system32\url.dll
- 2009-07-14 02:36 . 2010-12-23 10:40 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2010-12-26 12:14 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2010-12-23 10:40 106190 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2010-12-26 12:14 106190 c:\windows\system32\perfc009.dat
+ 2010-12-23 11:31 . 2010-08-31 23:42 147968 c:\windows\system32\occache.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 197120 c:\windows\system32\msrating.dll
+ 2010-12-23 11:31 . 2010-08-31 23:40 215552 c:\windows\system32\msls31.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 690176 c:\windows\system32\msfeeds.dll
+ 2010-12-23 11:29 . 2010-05-23 08:35 257024 c:\windows\system32\mfreadwrite.dll
+ 2010-12-23 11:29 . 2010-05-23 08:35 206848 c:\windows\system32\mfps.dll
- 2009-07-14 00:18 . 2009-07-14 01:41 206848 c:\windows\system32\mfps.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 819712 c:\windows\system32\jscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 102400 c:\windows\system32\inseng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 165888 c:\windows\system32\iexpress.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 173056 c:\windows\system32\ieUnatt.exe
+ 2010-12-23 11:31 . 2010-08-31 23:40 242688 c:\windows\system32\ieui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 136704 c:\windows\system32\iesysprep.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 147456 c:\windows\system32\iepeers.dll
+ 2010-12-23 11:31 . 2010-08-31 23:54 394040 c:\windows\system32\iedkcs32.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 545792 c:\windows\system32\ieapfltr.dll
- 2009-07-13 23:58 . 2009-07-14 01:27 163840 c:\windows\system32\ieakui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 163840 c:\windows\system32\ieakui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 263168 c:\windows\system32\ieaksie.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 157696 c:\windows\system32\ieakeng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 133632 c:\windows\system32\IEAdvpack.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 313344 c:\windows\system32\dxtrans.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 532480 c:\windows\system32\dxtmsft.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 320512 c:\windows\system32\d3d10_1core.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 899072 c:\windows\system32\d2d1.dll
+ 2009-07-14 05:01 . 2010-12-24 09:35 271292 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-12-23 11:31 . 2010-08-31 23:44 1122304 c:\windows\SysWOW64\wininet.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 1097728 c:\windows\SysWOW64\urlmon.dll
+ 2010-12-23 11:31 . 2010-08-31 23:46 1355264 c:\windows\SysWOW64\jscript9.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 2056192 c:\windows\SysWOW64\iertutil.dll
+ 2010-12-23 11:31 . 2010-08-02 13:50 3695400 c:\windows\SysWOW64\ieapfltr.dat
+ 2010-12-23 11:29 . 2010-05-23 08:37 1888256 c:\windows\system32\WMVDECOD.DLL
+ 2010-12-23 11:31 . 2010-08-31 23:42 1360896 c:\windows\system32\wininet.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 1253888 c:\windows\system32\urlmon.dll
+ 2010-12-23 11:29 . 2010-05-23 08:35 4068864 c:\windows\system32\mf.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 1633280 c:\windows\system32\jscript9.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 2431488 c:\windows\system32\iertutil.dll
+ 2010-12-23 11:31 . 2010-08-02 16:08 3695400 c:\windows\system32\ieapfltr.dat
+ 2010-12-23 11:29 . 2010-08-16 06:50 1137664 c:\windows\system32\FntCache.dll
- 2009-07-13 23:57 . 2009-07-14 01:40 1863680 c:\windows\system32\ExplorerFrame.dll
+ 2010-12-23 11:28 . 2010-06-26 05:31 1863680 c:\windows\system32\ExplorerFrame.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 1543168 c:\windows\system32\DWrite.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 1844224 c:\windows\system32\d3d10warp.dll
- 2009-07-14 04:45 . 2010-12-16 10:20 3834178 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2010-12-23 11:37 3834178 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-12-24 09:35 . 2010-12-24 09:35 2253448 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4139137649-2033661816-222925476-1000-12288.dat
+ 2010-12-23 11:27 . 2010-12-23 11:27 1989120 c:\windows\Installer\76a4b.msi
+ 2010-12-23 11:31 . 2010-08-31 23:47 10199040 c:\windows\SysWOW64\mshtml.dll
+ 2010-12-23 11:31 . 2010-08-31 23:45 12348928 c:\windows\SysWOW64\ieframe.dll
- 2009-07-14 02:34 . 2010-12-18 23:54 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2010-12-25 19:11 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2010-12-23 11:31 . 2010-08-31 23:50 16623616 c:\windows\system32\mshtml.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 13632512 c:\windows\system32\ieframe.dll
+ 2010-12-24 09:32 . 2010-12-24 09:32 20304384 c:\windows\Installer\4b69021.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
c:\users\U§ˇvate–\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2010-11-19 25640]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2010-11-19 30528]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-11-19 1255736]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
S2 SmileyCentral_1vService;SmileyCentral Service;c:\progra~2\SMILEY~2\bar\1.bin\1vbarsvc.exe [2010-12-02 28766]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 40832]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-09-07 155752]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
.
Contents of the 'Scheduled Tasks' folder
2010-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 20:06]
2010-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 20:06]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-26 10135584]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-15 1448568]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: facebook.com\login
FF - ProfilePath - c:\users\Užívateľ\AppData\Roaming\Mozilla\Firefox\Profiles\1bcuvm6e.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=GRxdm035YYSK&ptb=IFMLZn9Bi16_SU.U_sU4sA
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNzfb010YYSK_ZNzfb014&ptb=7768275E-7A80-4359-B251-44530E7C130C&psa=&ind=2010120304&ptnrS=ZNzfb010YYSK_ZNzfb014&si=&st=kwd&n=77d00070&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: SmileyCentral: 1vffxtbr@SmileyCentral_1v.com - c:\program files (x86)\SmileyCentral_1v\bar\1.bin
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-12-26 14:32:47
ComboFix-quarantined-files.txt 2010-12-26 13:32
ComboFix2.txt 2010-12-23 10:47
ComboFix3.txt 2010-12-23 10:27
Pre-Run: 72 760 135 680 bytes free
Post-Run: 72 563 445 760 bytes free
- - End Of File - - F12CBB5938F710EC2D8FCD974E47029A
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3959.2907 [GMT 1:00]
Running from: c:\users\Užívateľ\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BF5CEBDC-F2D3-7540-343C-F0CE11FD6E66}
SP: Microsoft Security Essentials *Disabled/Updated* {043D0A38-D4E9-7ACE-0E8C-CBBC6A7A24DB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-11-26 to 2010-12-26 )))))))))))))))))))))))))))))))
.
2010-12-26 13:31 . 2010-12-26 13:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-25 13:10 . 2010-11-09 20:35 8199504 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{59CD27F8-9194-46F7-B850-5597182AFC97}\mpengine.dll
2010-12-23 12:15 . 2010-12-23 12:15 -------- d-----w- c:\program files\CCleaner
2010-12-23 12:09 . 2010-12-23 12:12 -------- d-----w- c:\users\Užívateľ\AppData\Roaming\Auslogics
2010-12-23 12:08 . 2010-12-23 12:08 -------- d-----w- c:\program files (x86)\Auslogics
2010-12-23 11:29 . 2010-05-23 10:11 196608 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
2010-12-23 11:29 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2010-12-23 11:29 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2010-12-23 11:29 . 2010-08-16 06:14 737280 ----a-w- c:\windows\SysWow64\d2d1.dll
2010-12-23 11:29 . 2010-08-16 06:14 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2010-12-23 11:29 . 2010-08-16 06:14 1076224 ----a-w- c:\windows\SysWow64\DWrite.dll
2010-12-23 11:29 . 2010-08-16 06:14 1172480 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2010-12-23 11:28 . 2010-05-09 09:15 279552 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2010-12-23 11:28 . 2010-05-09 09:15 135168 ----a-w- c:\windows\SysWow64\XpsRasterService.dll
2010-12-23 11:28 . 2010-06-26 05:14 1495040 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2010-12-23 11:27 . 2010-12-23 11:27 -------- d-----w- c:\program files (x86)\Feedback Tool
2010-12-23 11:03 . 2010-12-23 13:24 -------- d-----w- c:\program files\trend micro
2010-12-23 11:03 . 2010-12-23 11:04 -------- d-----w- C:\rsit
2010-12-22 00:03 . 2010-12-22 00:03 -------- d-----w- c:\users\Užívateľ\AppData\Local\ElevatedDiagnostics
2010-12-16 05:22 . 2010-10-27 04:32 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2010-12-16 05:22 . 2010-11-02 04:40 496128 ----a-w- c:\windows\SysWow64\taskschd.dll
2010-12-16 05:22 . 2010-11-02 04:40 305152 ----a-w- c:\windows\SysWow64\taskcomp.dll
2010-12-16 05:22 . 2010-11-02 04:34 192000 ----a-w- c:\windows\SysWow64\taskeng.exe
2010-12-16 05:22 . 2010-11-02 04:34 179712 ----a-w- c:\windows\SysWow64\schtasks.exe
2010-12-16 05:22 . 2010-10-20 04:54 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2010-12-16 05:22 . 2010-10-20 02:58 294400 ----a-w- c:\windows\SysWow64\atmfd.dll
2010-12-16 05:22 . 2010-10-16 04:36 314368 ----a-w- c:\windows\SysWow64\webio.dll
2010-12-16 05:22 . 2010-10-12 05:05 35328 ----a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-16 05:22 . 2010-10-12 05:00 516096 ----a-w- c:\program files\Windows Mail\wab.exe
2010-12-16 05:22 . 2010-10-12 04:25 516096 ----a-w- c:\program files (x86)\Windows Mail\wab.exe
2010-12-02 19:04 . 2010-12-02 19:04 -------- d-----w- c:\program files (x86)\SmileyCentral_1v
2010-11-26 20:25 . 2010-11-26 20:25 -------- d-----w- c:\program files (x86)\Ask.com
2010-11-26 20:25 . 2010-11-26 20:25 -------- d-----w- c:\program files (x86)\The KMPlayer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-19 14:26 . 2010-11-19 13:43 30528 ----a-w- c:\windows\GVTDrv64.sys
2010-11-19 14:26 . 2010-11-19 13:40 25640 ----a-w- c:\windows\gdrv.sys
2010-11-19 13:56 . 2010-11-19 13:56 423656 ----a-w- c:\windows\SysWow64\deployJava1.dll
2010-11-19 13:46 . 2010-11-19 13:46 25640 ----a-w- c:\windows\etdrv.sys
2010-11-09 20:35 . 2010-11-23 08:31 8199504 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2010-11-02 04:34 . 2010-12-16 05:22 179712 ----a-w- c:\windows\SysWow64\schtasks.exe
2010-10-22 06:23 . 2010-11-19 14:33 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2010-10-22 06:23 . 2010-11-19 14:33 5473896 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2010-10-22 06:23 . 2010-11-19 14:33 319080 ----a-w- c:\windows\SysWow64\nvdecodemft.dll
2010-10-22 06:23 . 2010-11-19 14:33 14899816 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2010-10-22 06:23 . 2010-11-19 14:33 4837480 ----a-w- c:\windows\SysWow64\nvcuda.dll
2010-10-22 06:23 . 2010-11-19 14:33 2912360 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2010-10-22 06:23 . 2010-11-19 14:33 2666600 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2010-10-22 06:23 . 2010-11-19 14:33 10023528 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2010-10-22 06:23 . 2010-11-19 14:33 13019752 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2010-10-22 06:23 . 2010-07-10 04:38 1719912 ----a-w- c:\windows\SysWow64\nvapi.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-23_10.46.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-23 11:31 . 2010-08-31 23:43 76800 c:\windows\SysWOW64\SetIEInstalledDate.exe
+ 2010-12-23 11:31 . 2010-08-31 23:43 74752 c:\windows\SysWOW64\RegisterIEPKEYs.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 49664 c:\windows\SysWOW64\pngfilt.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 48640 c:\windows\SysWOW64\mshtmler.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 67072 c:\windows\SysWOW64\mshtmled.dll
- 2010-12-16 05:22 . 2010-11-04 05:49 67072 c:\windows\SysWOW64\mshtmled.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 11264 c:\windows\SysWOW64\mshta.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 10240 c:\windows\SysWOW64\msfeedssync.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 44544 c:\windows\SysWOW64\msfeedsbs.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 66048 c:\windows\SysWOW64\migration\WininetPlugin.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 23552 c:\windows\SysWOW64\licmgr10.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 65024 c:\windows\SysWOW64\jsproxy.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 80384 c:\windows\SysWOW64\inseng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 33280 c:\windows\SysWOW64\imgutil.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 75264 c:\windows\SysWOW64\iesetup.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 32768 c:\windows\SysWOW64\iernonce.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 59392 c:\windows\SysWOW64\icardie.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 51200 c:\windows\SysWOW64\admparse.dll
+ 2010-12-24 09:31 . 2010-12-24 09:31 58330 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2010-11-19 14:27 . 2010-12-26 12:11 23434 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2010-12-23 10:38 25662 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2010-12-26 12:11 25662 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-13 23:58 . 2009-07-14 01:39 93184 c:\windows\system32\SetIEInstalledDate.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 93184 c:\windows\system32\SetIEInstalledDate.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 90624 c:\windows\system32\RegisterIEPKEYs.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 65024 c:\windows\system32\pngfilt.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 48640 c:\windows\system32\mshtmler.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 97792 c:\windows\system32\mshtmled.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 12288 c:\windows\system32\mshta.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 10752 c:\windows\system32\msfeedssync.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 52224 c:\windows\system32\msfeedsbs.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 86528 c:\windows\system32\migration\WininetPlugin.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 27136 c:\windows\system32\licmgr10.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 84480 c:\windows\system32\jsproxy.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 49664 c:\windows\system32\imgutil.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 85504 c:\windows\system32\iesetup.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 39424 c:\windows\system32\iernonce.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 93696 c:\windows\system32\ie4uinit.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 81920 c:\windows\system32\icardie.dll
+ 2010-11-19 13:35 . 2010-12-23 13:57 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-19 13:35 . 2010-12-16 10:18 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-11-19 13:35 . 2010-12-23 13:57 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-11-19 13:35 . 2010-12-16 10:18 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2010-12-23 13:57 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2010-12-16 10:18 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-23 11:31 . 2010-08-31 23:41 60416 c:\windows\system32\admparse.dll
+ 2009-07-14 04:46 . 2010-12-26 12:13 79264 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2009-07-14 04:46 . 2010-12-19 12:08 79264 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-11-19 16:25 . 2010-12-23 10:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-11-19 16:25 . 2010-12-23 11:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-19 16:25 . 2010-12-23 10:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-11-19 16:25 . 2010-12-23 11:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-11-19 14:14 . 2010-11-19 14:14 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-11-19 14:14 . 2010-12-24 09:33 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-11-19 13:46 . 2010-12-26 12:11 7118 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4139137649-2033661816-222925476-1000_UserData.bin
+ 2010-12-26 12:10 . 2010-12-26 12:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-12-23 10:45 . 2010-12-23 10:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-26 12:10 . 2010-12-26 12:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-12-23 11:31 . 2010-08-31 23:42 149504 c:\windows\SysWOW64\wextract.exe
+ 2010-12-23 11:31 . 2010-08-31 23:43 208384 c:\windows\SysWOW64\webcheck.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 424960 c:\windows\SysWOW64\vbscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 109568 c:\windows\SysWOW64\url.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 128000 c:\windows\SysWOW64\occache.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 166400 c:\windows\SysWOW64\msrating.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 160768 c:\windows\SysWOW64\msls31.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 596480 c:\windows\SysWOW64\msfeeds.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 719360 c:\windows\SysWOW64\jscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 150016 c:\windows\SysWOW64\iexpress.exe
+ 2010-12-23 11:31 . 2010-08-31 23:43 142848 c:\windows\SysWOW64\ieUnatt.exe
- 2010-12-16 05:22 . 2010-11-04 05:48 176640 c:\windows\SysWOW64\ieui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 176640 c:\windows\SysWOW64\ieui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 114176 c:\windows\SysWOW64\iesysprep.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 111104 c:\windows\SysWOW64\iepeers.dll
+ 2010-12-23 11:31 . 2010-08-31 23:55 460088 c:\windows\SysWOW64\iedkcs32.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 441856 c:\windows\SysWOW64\ieapfltr.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 163840 c:\windows\SysWOW64\ieakui.dll
- 2009-07-13 23:42 . 2009-07-14 01:05 163840 c:\windows\SysWOW64\ieakui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 227840 c:\windows\SysWOW64\ieaksie.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 130560 c:\windows\SysWOW64\ieakeng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 110592 c:\windows\SysWOW64\IEAdvpack.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 193024 c:\windows\SysWOW64\ie4uinit.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 223232 c:\windows\SysWOW64\dxtrans.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 353280 c:\windows\SysWOW64\dxtmsft.dll
+ 2010-12-23 11:28 . 2010-05-09 09:46 229888 c:\windows\system32\XpsRasterService.dll
- 2009-07-14 00:37 . 2009-07-14 01:41 229888 c:\windows\system32\XpsRasterService.dll
- 2009-07-14 00:37 . 2009-07-14 01:41 466432 c:\windows\system32\XpsGdiConverter.dll
+ 2010-12-23 11:28 . 2010-05-09 09:46 466432 c:\windows\system32\XpsGdiConverter.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 159232 c:\windows\system32\wextract.exe
+ 2010-12-23 11:31 . 2010-08-31 23:42 250368 c:\windows\system32\webcheck.dll
+ 2010-11-19 18:16 . 2010-12-25 15:03 207602 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2010-12-23 11:31 . 2010-08-31 23:41 601088 c:\windows\system32\vbscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 112128 c:\windows\system32\url.dll
- 2009-07-14 02:36 . 2010-12-23 10:40 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2010-12-26 12:14 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2010-12-23 10:40 106190 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2010-12-26 12:14 106190 c:\windows\system32\perfc009.dat
+ 2010-12-23 11:31 . 2010-08-31 23:42 147968 c:\windows\system32\occache.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 197120 c:\windows\system32\msrating.dll
+ 2010-12-23 11:31 . 2010-08-31 23:40 215552 c:\windows\system32\msls31.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 690176 c:\windows\system32\msfeeds.dll
+ 2010-12-23 11:29 . 2010-05-23 08:35 257024 c:\windows\system32\mfreadwrite.dll
+ 2010-12-23 11:29 . 2010-05-23 08:35 206848 c:\windows\system32\mfps.dll
- 2009-07-14 00:18 . 2009-07-14 01:41 206848 c:\windows\system32\mfps.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 819712 c:\windows\system32\jscript.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 102400 c:\windows\system32\inseng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 165888 c:\windows\system32\iexpress.exe
+ 2010-12-23 11:31 . 2010-08-31 23:41 173056 c:\windows\system32\ieUnatt.exe
+ 2010-12-23 11:31 . 2010-08-31 23:40 242688 c:\windows\system32\ieui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 136704 c:\windows\system32\iesysprep.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 147456 c:\windows\system32\iepeers.dll
+ 2010-12-23 11:31 . 2010-08-31 23:54 394040 c:\windows\system32\iedkcs32.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 545792 c:\windows\system32\ieapfltr.dll
- 2009-07-13 23:58 . 2009-07-14 01:27 163840 c:\windows\system32\ieakui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 163840 c:\windows\system32\ieakui.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 263168 c:\windows\system32\ieaksie.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 157696 c:\windows\system32\ieakeng.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 133632 c:\windows\system32\IEAdvpack.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 313344 c:\windows\system32\dxtrans.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 532480 c:\windows\system32\dxtmsft.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 320512 c:\windows\system32\d3d10_1core.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 899072 c:\windows\system32\d2d1.dll
+ 2009-07-14 05:01 . 2010-12-24 09:35 271292 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-12-23 11:31 . 2010-08-31 23:44 1122304 c:\windows\SysWOW64\wininet.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 1097728 c:\windows\SysWOW64\urlmon.dll
+ 2010-12-23 11:31 . 2010-08-31 23:46 1355264 c:\windows\SysWOW64\jscript9.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 2056192 c:\windows\SysWOW64\iertutil.dll
+ 2010-12-23 11:31 . 2010-08-02 13:50 3695400 c:\windows\SysWOW64\ieapfltr.dat
+ 2010-12-23 11:29 . 2010-05-23 08:37 1888256 c:\windows\system32\WMVDECOD.DLL
+ 2010-12-23 11:31 . 2010-08-31 23:42 1360896 c:\windows\system32\wininet.dll
+ 2010-12-23 11:31 . 2010-08-31 23:43 1253888 c:\windows\system32\urlmon.dll
+ 2010-12-23 11:29 . 2010-05-23 08:35 4068864 c:\windows\system32\mf.dll
+ 2010-12-23 11:31 . 2010-08-31 23:42 1633280 c:\windows\system32\jscript9.dll
+ 2010-12-23 11:31 . 2010-08-31 23:41 2431488 c:\windows\system32\iertutil.dll
+ 2010-12-23 11:31 . 2010-08-02 16:08 3695400 c:\windows\system32\ieapfltr.dat
+ 2010-12-23 11:29 . 2010-08-16 06:50 1137664 c:\windows\system32\FntCache.dll
- 2009-07-13 23:57 . 2009-07-14 01:40 1863680 c:\windows\system32\ExplorerFrame.dll
+ 2010-12-23 11:28 . 2010-06-26 05:31 1863680 c:\windows\system32\ExplorerFrame.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 1543168 c:\windows\system32\DWrite.dll
+ 2010-12-23 11:29 . 2010-08-16 06:50 1844224 c:\windows\system32\d3d10warp.dll
- 2009-07-14 04:45 . 2010-12-16 10:20 3834178 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2010-12-23 11:37 3834178 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-12-24 09:35 . 2010-12-24 09:35 2253448 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4139137649-2033661816-222925476-1000-12288.dat
+ 2010-12-23 11:27 . 2010-12-23 11:27 1989120 c:\windows\Installer\76a4b.msi
+ 2010-12-23 11:31 . 2010-08-31 23:47 10199040 c:\windows\SysWOW64\mshtml.dll
+ 2010-12-23 11:31 . 2010-08-31 23:45 12348928 c:\windows\SysWOW64\ieframe.dll
- 2009-07-14 02:34 . 2010-12-18 23:54 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2010-12-25 19:11 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2010-12-23 11:31 . 2010-08-31 23:50 16623616 c:\windows\system32\mshtml.dll
+ 2010-12-23 11:31 . 2010-08-31 23:44 13632512 c:\windows\system32\ieframe.dll
+ 2010-12-24 09:32 . 2010-12-24 09:32 20304384 c:\windows\Installer\4b69021.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
c:\users\U§ˇvate–\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2010-11-19 25640]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2010-11-19 30528]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-11-19 1255736]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
S2 SmileyCentral_1vService;SmileyCentral Service;c:\progra~2\SMILEY~2\bar\1.bin\1vbarsvc.exe [2010-12-02 28766]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-09-30 2320920]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 40832]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-09-07 155752]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
.
Contents of the 'Scheduled Tasks' folder
2010-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 20:06]
2010-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-22 20:06]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-26 10135584]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-15 1448568]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: facebook.com\login
FF - ProfilePath - c:\users\Užívateľ\AppData\Roaming\Mozilla\Firefox\Profiles\1bcuvm6e.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=GRxdm035YYSK&ptb=IFMLZn9Bi16_SU.U_sU4sA
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNzfb010YYSK_ZNzfb014&ptb=7768275E-7A80-4359-B251-44530E7C130C&psa=&ind=2010120304&ptnrS=ZNzfb010YYSK_ZNzfb014&si=&st=kwd&n=77d00070&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: SmileyCentral: 1vffxtbr@SmileyCentral_1v.com - c:\program files (x86)\SmileyCentral_1v\bar\1.bin
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-12-26 14:32:47
ComboFix-quarantined-files.txt 2010-12-26 13:32
ComboFix2.txt 2010-12-23 10:47
ComboFix3.txt 2010-12-23 10:27
Pre-Run: 72 760 135 680 bytes free
Post-Run: 72 563 445 760 bytes free
- - End Of File - - F12CBB5938F710EC2D8FCD974E47029A
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: nejde pristupovat na stranky vyzadujuce https
ComboFix nemazal - naznačil možný spyware
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Kontrolor" -> Rychlá kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
-
- Návštěvník
- Příspěvky: 31
- Registrován: 19 úno 2009 20:51
Re: nejde pristupovat na stranky vyzadujuce https
dakujem za pomoc, mbam som tam nestihol spustit, majitel zobral PC do nejakej opravovne, https stranky neslo nacitat ani po reinstalacii (rezim inovacia) win 7, prajem vsetko dobre do noveho roku 

- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: nejde pristupovat na stranky vyzadujuce https
Aj tebe a tvojim bízkym prajem úspešný rok 2011 v plnom zdraví 
