
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola logu, pomaly start, po startu chybi soubor dll
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Kontrola logu, pomaly start, po startu chybi soubor dll
Dobrý den,
prosím o kontrolu logu, moc děkuji.
¨Logfile of random's system information tool 1.08 (written by random/random)
Run by Radek at 2010-12-30 07:28:33
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 7 GB (18%) free of 41 GB
Total RAM: 2037 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:29:11, on 30.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Radek\Desktop\RSIT.exe
C:\Program Files\trend micro\Radek.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
--
End of file - 8173 bytes
======Scheduled tasks folder======
C:\Windows\tasks\User_Feed_Synchronization-{3BC4EEBA-98AB-4468-94DE-986FFF7A9E20}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2008-09-12 153008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-11-03 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2010-10-30 321312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-10-30 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-11-03 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-09-07 2838912]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2010-09-02 1043968]
"PAC7302_Monitor"=C:\Windows\PixArt\PAC7302\Monitor.exe [2007-12-10 323584]
"USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2007-08-01 222592]
"Metropolis"=C:\Windows\system32\sshnas21.dll,GetHandle []
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-18 202240]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-18 125952]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-03-20 1312256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - "C:\Windows\system32\notepad.exe" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2010-12-30 07:28:53 ----D---- C:\Program Files\trend micro
2010-12-30 07:28:33 ----D---- C:\rsit
2010-12-29 21:16:11 ----D---- C:\ProgramData\FLEXnet
2010-12-29 21:13:18 ----D---- C:\Windows\Sun
2010-12-29 20:58:38 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-12-29 20:54:43 ----D---- C:\Windows\fonts\Fonts
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxinsi64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxinsa64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxcpyi64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxcpya64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\drivers\PxHelp20.sys
2010-12-29 20:52:27 ----N---- C:\Windows\system32\vxblock.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxwave.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxsfs.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxmas.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxhpinst.exe
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxdrv.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxafs.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\px.dll
2010-12-29 20:42:07 ----A---- C:\Windows\system32\spr32d35.dll
2010-12-26 16:02:13 ----D---- C:\Users\Radek\AppData\Roaming\Autodesk
2010-12-26 16:01:30 ----D---- C:\ProgramData\Autodesk
2010-12-26 16:01:04 ----D---- C:\Program Files\Common Files\InstallShield
2010-12-26 16:00:16 ----D---- C:\Program Files\Common Files\Autodesk Shared
2010-12-24 13:15:53 ----D---- C:\Users\Radek\AppData\Roaming\dvdcss
2010-12-16 17:59:12 ----A---- C:\Windows\system32\win32k.sys
2010-12-16 17:59:07 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-16 17:59:06 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-16 17:59:06 ----A---- C:\Windows\system32\taskschd.dll
2010-12-16 17:59:06 ----A---- C:\Windows\system32\taskeng.exe
2010-12-16 17:59:06 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-16 17:59:02 ----A---- C:\Windows\system32\consent.exe
2010-12-16 17:59:01 ----A---- C:\Windows\system32\fontsub.dll
2010-12-16 17:59:01 ----A---- C:\Windows\system32\atmlib.dll
2010-12-16 17:59:01 ----A---- C:\Windows\system32\atmfd.dll
2010-12-16 17:58:54 ----A---- C:\Windows\system32\iertutil.dll
2010-12-16 17:58:53 ----A---- C:\Windows\system32\mstime.dll
2010-12-16 17:58:53 ----A---- C:\Windows\system32\mshtml.dll
2010-12-16 17:58:53 ----A---- C:\Windows\system32\ieframe.dll
2010-12-16 17:58:47 ----A---- C:\Windows\system32\ie4uinit.exe
2010-12-16 17:58:46 ----A---- C:\Windows\system32\wininet.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\urlmon.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\occache.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-16 17:58:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\ieUnatt.exe
2010-12-16 17:58:46 ----A---- C:\Windows\system32\ieui.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iesysprep.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iesetup.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iepeers.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-16 17:58:45 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-16 17:58:45 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-16 17:58:45 ----A---- C:\Windows\system32\iernonce.dll
2010-12-16 17:58:32 ----A---- C:\Windows\system32\tzres.dll
2010-12-16 17:58:16 ----A---- C:\Windows\system32\msshsq.dll
2010-12-11 17:26:49 ----D---- C:\Program Files\Common Files\PCSuite
2010-12-11 17:26:44 ----D---- C:\Program Files\Common Files\Nokia
2010-12-11 17:25:32 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2010-12-11 17:24:50 ----DC---- C:\Windows\system32\DRVSTORE
2010-12-11 17:24:32 ----D---- C:\Program Files\PC Connectivity Solution
2010-12-11 16:29:47 ----D---- C:\ProgramData\PC Suite
2010-12-11 16:28:01 ----D---- C:\Users\Radek\AppData\Roaming\Nokia
2010-12-11 16:27:59 ----D---- C:\Program Files\DIFX
2010-12-11 16:25:44 ----D---- C:\Users\Radek\AppData\Roaming\PC Suite
2010-12-11 16:23:24 ----D---- C:\Program Files\Nokia
2010-12-11 16:23:24 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-12-11 16:22:59 ----D---- C:\ProgramData\Installations
2010-12-08 18:27:39 ----A---- C:\Windows\system32\pncrt.dll
2010-12-08 18:27:00 ----D---- C:\Program Files\FreeTime
2010-12-07 17:54:28 ----D---- C:\Program Files\CDex
======List of files/folders modified in the last 1 months======
2010-12-30 07:29:07 ----D---- C:\Windows\Prefetch
2010-12-30 07:29:06 ----D---- C:\Windows\Temp
2010-12-30 07:29:02 ----D---- C:\Windows\Internet Logs
2010-12-30 07:28:53 ----RD---- C:\Program Files
2010-12-30 07:23:18 ----D---- C:\Program Files\Mozilla Firefox
2010-12-29 22:37:19 ----D---- C:\Users\Radek\AppData\Roaming\Adobe
2010-12-29 22:15:38 ----D---- C:\Windows\System32
2010-12-29 22:15:38 ----D---- C:\Windows\inf
2010-12-29 22:15:38 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-29 22:07:00 ----D---- C:\Users\Radek\AppData\Roaming\vlc
2010-12-29 21:16:11 ----HD---- C:\ProgramData
2010-12-29 21:13:18 ----D---- C:\Windows
2010-12-29 20:59:28 ----SHD---- C:\Windows\Installer
2010-12-29 20:58:59 ----D---- C:\ProgramData\Adobe
2010-12-29 20:58:58 ----D---- C:\Program Files\Common Files\Adobe
2010-12-29 20:58:38 ----D---- C:\Program Files\Common Files
2010-12-29 20:54:43 ----RSD---- C:\Windows\Fonts
2010-12-29 20:52:37 ----D---- C:\Program Files\Adobe
2010-12-29 20:52:28 ----D---- C:\Windows\system32\drivers
2010-12-29 20:51:21 ----SHD---- C:\System Volume Information
2010-12-28 14:42:27 ----D---- C:\Program Files\JDownloader
2010-12-28 14:08:38 ----A---- C:\Windows\win.ini
2010-12-28 13:43:09 ----SD---- C:\ProgramData\Microsoft
2010-12-28 13:23:30 ----D---- C:\Windows\system32\NDF
2010-12-26 16:12:54 ----RSD---- C:\Windows\assembly
2010-12-26 16:12:53 ----D---- C:\Windows\winsxs
2010-12-26 16:12:49 ----D---- C:\Windows\Microsoft.NET
2010-12-26 16:05:44 ----SD---- C:\Windows\Downloaded Program Files
2010-12-26 16:03:30 ----D---- C:\Windows\Help
2010-12-26 15:59:19 ----D---- C:\Program Files\Common Files\DESIGNER
2010-12-26 15:59:16 ----D---- C:\Program Files\Microsoft Office
2010-12-26 15:59:16 ----D---- C:\Program Files\Common Files\microsoft shared
2010-12-25 08:25:25 ----D---- C:\Windows\system32\catroot2
2010-12-18 14:03:27 ----D---- C:\Windows\rescache
2010-12-18 13:49:05 ----D---- C:\Windows\system32\catroot
2010-12-17 17:21:19 ----D---- C:\Program Files\Windows Mail
2010-12-17 17:21:18 ----D---- C:\Windows\system32\migration
2010-12-17 17:21:18 ----D---- C:\Windows\system32\cs-CZ
2010-12-17 17:21:18 ----D---- C:\Program Files\Internet Explorer
2010-12-17 15:22:36 ----D---- C:\ProgramData\Microsoft Help
2010-12-17 15:14:46 ----A---- C:\Windows\system32\mrt.exe
2010-12-13 21:22:05 ----D---- C:\Users\Radek\AppData\Roaming\uTorrent
2010-12-12 10:42:23 ----SD---- C:\Users\Radek\AppData\Roaming\Microsoft
2010-12-11 17:37:59 ----D---- C:\Windows\system32\drivers\UMDF
2010-12-09 21:04:58 ----D---- C:\Users\Radek\AppData\Roaming\Skype
2010-12-09 19:54:54 ----D---- C:\Users\Radek\AppData\Roaming\skypePM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2005-11-14 34176]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2010-12-29 43528]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-30 685816]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2010-05-15 457304]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
R2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2006-11-22 693760]
R2 NSHE;Guardant Emulator Driver; \??\C:\Windows\system32\Drivers\NSHE.SYS [2008-11-23 97792]
R3 CamSuiteVAC;CamSuite Virtual Audio; C:\Windows\system32\DRIVERS\CamSuiteVAC.sys [2008-09-20 37560]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-18 2225664]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-02 47104]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 av8aq0ev;av8aq0ev; C:\Windows\system32\drivers\av8aq0ev.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 PAC7302;iLook 310; C:\Windows\system32\DRIVERS\PAC7302.SYS [2009-04-28 461824]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-04-11 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 vsdatant7;vsdatant7; C:\Windows\System32\drivers\vsdatant.win7.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7; C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 NAUpdate;@C:\Program Files\Nero\Update\NASvc.exe,-200; C:\Program Files\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2010-09-02 2435592]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-12-26 85096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-29 651720]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
prosím o kontrolu logu, moc děkuji.
¨Logfile of random's system information tool 1.08 (written by random/random)
Run by Radek at 2010-12-30 07:28:33
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 7 GB (18%) free of 41 GB
Total RAM: 2037 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:29:11, on 30.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Radek\Desktop\RSIT.exe
C:\Program Files\trend micro\Radek.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
--
End of file - 8173 bytes
======Scheduled tasks folder======
C:\Windows\tasks\User_Feed_Synchronization-{3BC4EEBA-98AB-4468-94DE-986FFF7A9E20}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2008-09-12 153008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-11-03 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2010-10-30 321312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-10-30 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-11-03 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-09-07 2838912]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2010-09-02 1043968]
"PAC7302_Monitor"=C:\Windows\PixArt\PAC7302\Monitor.exe [2007-12-10 323584]
"USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2007-08-01 222592]
"Metropolis"=C:\Windows\system32\sshnas21.dll,GetHandle []
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-18 202240]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-18 125952]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-03-20 1312256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - "C:\Windows\system32\notepad.exe" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 months======
2010-12-30 07:28:53 ----D---- C:\Program Files\trend micro
2010-12-30 07:28:33 ----D---- C:\rsit
2010-12-29 21:16:11 ----D---- C:\ProgramData\FLEXnet
2010-12-29 21:13:18 ----D---- C:\Windows\Sun
2010-12-29 20:58:38 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-12-29 20:54:43 ----D---- C:\Windows\fonts\Fonts
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxinsi64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxinsa64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxcpyi64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\pxcpya64.exe
2010-12-29 20:52:28 ----N---- C:\Windows\system32\drivers\PxHelp20.sys
2010-12-29 20:52:27 ----N---- C:\Windows\system32\vxblock.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxwave.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxsfs.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxmas.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxhpinst.exe
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxdrv.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\pxafs.dll
2010-12-29 20:52:27 ----N---- C:\Windows\system32\px.dll
2010-12-29 20:42:07 ----A---- C:\Windows\system32\spr32d35.dll
2010-12-26 16:02:13 ----D---- C:\Users\Radek\AppData\Roaming\Autodesk
2010-12-26 16:01:30 ----D---- C:\ProgramData\Autodesk
2010-12-26 16:01:04 ----D---- C:\Program Files\Common Files\InstallShield
2010-12-26 16:00:16 ----D---- C:\Program Files\Common Files\Autodesk Shared
2010-12-24 13:15:53 ----D---- C:\Users\Radek\AppData\Roaming\dvdcss
2010-12-16 17:59:12 ----A---- C:\Windows\system32\win32k.sys
2010-12-16 17:59:07 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-16 17:59:06 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-16 17:59:06 ----A---- C:\Windows\system32\taskschd.dll
2010-12-16 17:59:06 ----A---- C:\Windows\system32\taskeng.exe
2010-12-16 17:59:06 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-16 17:59:02 ----A---- C:\Windows\system32\consent.exe
2010-12-16 17:59:01 ----A---- C:\Windows\system32\fontsub.dll
2010-12-16 17:59:01 ----A---- C:\Windows\system32\atmlib.dll
2010-12-16 17:59:01 ----A---- C:\Windows\system32\atmfd.dll
2010-12-16 17:58:54 ----A---- C:\Windows\system32\iertutil.dll
2010-12-16 17:58:53 ----A---- C:\Windows\system32\mstime.dll
2010-12-16 17:58:53 ----A---- C:\Windows\system32\mshtml.dll
2010-12-16 17:58:53 ----A---- C:\Windows\system32\ieframe.dll
2010-12-16 17:58:47 ----A---- C:\Windows\system32\ie4uinit.exe
2010-12-16 17:58:46 ----A---- C:\Windows\system32\wininet.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\urlmon.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\occache.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-16 17:58:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\ieUnatt.exe
2010-12-16 17:58:46 ----A---- C:\Windows\system32\ieui.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iesysprep.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iesetup.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iepeers.dll
2010-12-16 17:58:46 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-16 17:58:45 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-16 17:58:45 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-16 17:58:45 ----A---- C:\Windows\system32\iernonce.dll
2010-12-16 17:58:32 ----A---- C:\Windows\system32\tzres.dll
2010-12-16 17:58:16 ----A---- C:\Windows\system32\msshsq.dll
2010-12-11 17:26:49 ----D---- C:\Program Files\Common Files\PCSuite
2010-12-11 17:26:44 ----D---- C:\Program Files\Common Files\Nokia
2010-12-11 17:25:32 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2010-12-11 17:24:50 ----DC---- C:\Windows\system32\DRVSTORE
2010-12-11 17:24:32 ----D---- C:\Program Files\PC Connectivity Solution
2010-12-11 16:29:47 ----D---- C:\ProgramData\PC Suite
2010-12-11 16:28:01 ----D---- C:\Users\Radek\AppData\Roaming\Nokia
2010-12-11 16:27:59 ----D---- C:\Program Files\DIFX
2010-12-11 16:25:44 ----D---- C:\Users\Radek\AppData\Roaming\PC Suite
2010-12-11 16:23:24 ----D---- C:\Program Files\Nokia
2010-12-11 16:23:24 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-12-11 16:22:59 ----D---- C:\ProgramData\Installations
2010-12-08 18:27:39 ----A---- C:\Windows\system32\pncrt.dll
2010-12-08 18:27:00 ----D---- C:\Program Files\FreeTime
2010-12-07 17:54:28 ----D---- C:\Program Files\CDex
======List of files/folders modified in the last 1 months======
2010-12-30 07:29:07 ----D---- C:\Windows\Prefetch
2010-12-30 07:29:06 ----D---- C:\Windows\Temp
2010-12-30 07:29:02 ----D---- C:\Windows\Internet Logs
2010-12-30 07:28:53 ----RD---- C:\Program Files
2010-12-30 07:23:18 ----D---- C:\Program Files\Mozilla Firefox
2010-12-29 22:37:19 ----D---- C:\Users\Radek\AppData\Roaming\Adobe
2010-12-29 22:15:38 ----D---- C:\Windows\System32
2010-12-29 22:15:38 ----D---- C:\Windows\inf
2010-12-29 22:15:38 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-29 22:07:00 ----D---- C:\Users\Radek\AppData\Roaming\vlc
2010-12-29 21:16:11 ----HD---- C:\ProgramData
2010-12-29 21:13:18 ----D---- C:\Windows
2010-12-29 20:59:28 ----SHD---- C:\Windows\Installer
2010-12-29 20:58:59 ----D---- C:\ProgramData\Adobe
2010-12-29 20:58:58 ----D---- C:\Program Files\Common Files\Adobe
2010-12-29 20:58:38 ----D---- C:\Program Files\Common Files
2010-12-29 20:54:43 ----RSD---- C:\Windows\Fonts
2010-12-29 20:52:37 ----D---- C:\Program Files\Adobe
2010-12-29 20:52:28 ----D---- C:\Windows\system32\drivers
2010-12-29 20:51:21 ----SHD---- C:\System Volume Information
2010-12-28 14:42:27 ----D---- C:\Program Files\JDownloader
2010-12-28 14:08:38 ----A---- C:\Windows\win.ini
2010-12-28 13:43:09 ----SD---- C:\ProgramData\Microsoft
2010-12-28 13:23:30 ----D---- C:\Windows\system32\NDF
2010-12-26 16:12:54 ----RSD---- C:\Windows\assembly
2010-12-26 16:12:53 ----D---- C:\Windows\winsxs
2010-12-26 16:12:49 ----D---- C:\Windows\Microsoft.NET
2010-12-26 16:05:44 ----SD---- C:\Windows\Downloaded Program Files
2010-12-26 16:03:30 ----D---- C:\Windows\Help
2010-12-26 15:59:19 ----D---- C:\Program Files\Common Files\DESIGNER
2010-12-26 15:59:16 ----D---- C:\Program Files\Microsoft Office
2010-12-26 15:59:16 ----D---- C:\Program Files\Common Files\microsoft shared
2010-12-25 08:25:25 ----D---- C:\Windows\system32\catroot2
2010-12-18 14:03:27 ----D---- C:\Windows\rescache
2010-12-18 13:49:05 ----D---- C:\Windows\system32\catroot
2010-12-17 17:21:19 ----D---- C:\Program Files\Windows Mail
2010-12-17 17:21:18 ----D---- C:\Windows\system32\migration
2010-12-17 17:21:18 ----D---- C:\Windows\system32\cs-CZ
2010-12-17 17:21:18 ----D---- C:\Program Files\Internet Explorer
2010-12-17 15:22:36 ----D---- C:\ProgramData\Microsoft Help
2010-12-17 15:14:46 ----A---- C:\Windows\system32\mrt.exe
2010-12-13 21:22:05 ----D---- C:\Users\Radek\AppData\Roaming\uTorrent
2010-12-12 10:42:23 ----SD---- C:\Users\Radek\AppData\Roaming\Microsoft
2010-12-11 17:37:59 ----D---- C:\Windows\system32\drivers\UMDF
2010-12-09 21:04:58 ----D---- C:\Users\Radek\AppData\Roaming\Skype
2010-12-09 19:54:54 ----D---- C:\Users\Radek\AppData\Roaming\skypePM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2005-11-14 34176]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2010-12-29 43528]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-30 685816]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2010-05-15 457304]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
R2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2006-11-22 693760]
R2 NSHE;Guardant Emulator Driver; \??\C:\Windows\system32\Drivers\NSHE.SYS [2008-11-23 97792]
R3 CamSuiteVAC;CamSuite Virtual Audio; C:\Windows\system32\DRIVERS\CamSuiteVAC.sys [2008-09-20 37560]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-18 2225664]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-02 47104]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 av8aq0ev;av8aq0ev; C:\Windows\system32\drivers\av8aq0ev.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 PAC7302;iLook 310; C:\Windows\system32\DRIVERS\PAC7302.SYS [2009-04-28 461824]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-04-11 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 vsdatant7;vsdatant7; C:\Windows\System32\drivers\vsdatant.win7.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7; C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 NAUpdate;@C:\Program Files\Nero\Update\NASvc.exe,-200; C:\Program Files\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2010-09-02 2435592]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-12-26 85096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-29 651720]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Zdravim a pekny den preji
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
ComboFix 10-12-29.02 - Radek 30.12.2010 9:53.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2037.1131 [GMT 1:00]
Spuštěný z: c:\users\Radek\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\UNWISE.EXE
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 09:00 . 2010-12-30 09:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- c:\program files\trend micro
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- C:\rsit
2010-12-29 20:16 . 2010-12-29 20:16 -------- d-----w- c:\programdata\FLEXnet
2010-12-29 20:13 . 2010-12-29 20:13 -------- d-----w- c:\windows\Sun
2010-12-29 19:58 . 2010-12-29 19:58 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-29 19:42 . 2002-08-18 18:43 794624 ----a-w- c:\windows\system32\spr32d35.dll
2010-12-28 19:20 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D5139D5-D081-4F05-8E3C-C18107D1B5B9}\mpengine.dll
2010-12-26 15:02 . 2010-12-26 15:02 -------- d-----w- c:\users\Radek\AppData\Roaming\Autodesk
2010-12-26 15:01 . 2010-12-26 15:14 -------- d-----w- c:\programdata\Autodesk
2010-12-26 15:01 . 2010-12-26 15:01 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-26 15:00 . 2010-12-26 15:12 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-12-26 15:00 . 2010-12-26 15:07 -------- d-----w- c:\users\Radek\AppData\Local\Autodesk
2010-12-24 12:15 . 2010-12-24 12:15 -------- d-----w- c:\users\Radek\AppData\Roaming\dvdcss
2010-12-11 16:27 . 2010-12-11 16:27 -------- d-----w- c:\users\Radek\{01f23597-6798-432f-b0c7-8511011677b5}
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\PCSuite
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\Nokia
2010-12-11 16:25 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-12-11 16:24 . 2010-12-11 16:25 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-11 16:24 . 2010-12-11 16:24 -------- d-----w- c:\program files\PC Connectivity Solution
2010-12-11 15:29 . 2010-12-11 16:37 -------- d-----w- c:\programdata\PC Suite
2010-12-11 15:28 . 2010-12-11 16:37 -------- d-----w- c:\users\Radek\AppData\Roaming\Nokia
2010-12-11 15:27 . 2010-12-11 15:27 -------- d-----w- c:\program files\DIFX
2010-12-11 15:25 . 2010-12-11 16:59 -------- d-----w- c:\users\Radek\AppData\Roaming\PC Suite
2010-12-11 15:23 . 2010-12-11 16:26 -------- d-----w- c:\program files\Nokia
2010-12-11 15:23 . 2009-02-09 06:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-12-11 15:22 . 2010-12-11 16:20 -------- d-----w- c:\programdata\Installations
2010-12-08 17:27 . 2010-12-08 17:27 -------- d-----w- c:\program files\FreeTime
2010-12-07 16:54 . 2010-12-07 16:55 -------- d-----w- c:\program files\CDex
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-27 21:12 . 2010-11-27 21:12 157696 ----a-w- c:\windows\system\STORAGE.DLL
2010-11-27 21:12 . 2010-11-27 21:12 398416 ----a-w- c:\windows\system\VBRUN300.DLL
2010-11-13 13:06 . 2010-11-13 13:06 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-10-30 08:51 . 2006-11-02 10:32 101888 ------w- c:\windows\system32\ifxcardm.dll
2010-10-30 08:51 . 2006-11-02 10:32 82432 ------w- c:\windows\system32\axaltocm.dll
2010-10-30 07:57 . 2010-10-30 07:58 411368 ------w- c:\windows\system32\deployJava1.dll
2010-10-30 07:37 . 2010-10-30 07:37 2421760 ----a-w- c:\windows\system32\wucltux.dll
2010-10-30 07:37 . 2010-10-30 07:37 53472 ----a-w- c:\windows\system32\wuauclt.exe
2010-10-30 07:37 . 2010-10-30 07:37 44768 ----a-w- c:\windows\system32\wups2.dll
2010-10-30 07:37 . 2010-10-30 07:37 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2010-10-30 07:36 . 2010-10-30 07:36 87552 ----a-w- c:\windows\system32\wudriver.dll
2010-10-30 07:36 . 2010-10-30 07:36 575704 ----a-w- c:\windows\system32\wuapi.dll
2010-10-30 07:36 . 2010-10-30 07:36 35552 ----a-w- c:\windows\system32\wups.dll
2010-10-30 07:36 . 2010-10-30 07:36 33792 ----a-w- c:\windows\system32\wuapp.exe
2010-10-30 07:36 . 2010-10-30 07:36 171608 ----a-w- c:\windows\system32\wuwebv.dll
2010-10-30 07:01 . 2010-10-30 07:01 191488 ------w- c:\windows\system32\hlvdd.dll
2010-10-30 05:55 . 2010-10-30 05:55 685816 ------w- c:\windows\system32\drivers\sptd.sys
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\qwavedrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\wacompen.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\SCR111.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\scmstcs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\pscr.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\grserial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\stcusb.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\gpr400.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cxbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cmbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mtag.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\serial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\rndismpx.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\pnpmem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\battc.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\acpi.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 7168 ----a-w- c:\windows\system32\drivers\cs-CZ\IPMIDrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\pcmcia.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\pacer.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\BrSerId.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\sermouse.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\msdsm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\mouclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\mouhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\i8042prt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\modem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\serscan.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\afd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 6656 ----a-w- c:\windows\system32\drivers\cs-CZ\yk60x86.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\ipnat.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\ltmdmnt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\hidbth.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 65536 ----a-w- c:\windows\system32\drivers\cs-CZ\ntfs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\e100b325.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\srv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mpad.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\ntrigdigi.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\cs-CZ\LMPRTPRC.DLL.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\viac7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\processr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\intelppm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\crusoe.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk8.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\parport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\RNDISMP.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\parvdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\umbus.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\UAGP35.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\BrParwdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 12288 ----a-w- c:\windows\system32\drivers\cs-CZ\ohci1394.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\Dot4usb.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\amdide.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\bcm4sbxp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\fltmgr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\bthpan.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\nv4_mini.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\isapnp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\scsiport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\mssmbios.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\atikmdag.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 9216 ----a-w- c:\windows\system32\drivers\cs-CZ\pci.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\VIAAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ULIAGPKX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\SISAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\NV_AGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AMDAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AGP440.sys.mui
2010-10-19 09:41 . 2010-10-30 15:23 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-09-02 1043968]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-12-10 323584]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
R3 vsdatant7;vsdatant7;c:\windows\system32\drivers\vsdatant.win7.sys [x]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2005-11-14 34176]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 685816]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2008-11-23 97792]
S3 CamSuiteVAC;CamSuite Virtual Audio;c:\windows\system32\DRIVERS\CamSuiteVAC.sys [2008-09-19 37560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
2010-12-29 c:\windows\Tasks\User_Feed_Synchronization-{3BC4EEBA-98AB-4468-94DE-986FFF7A9E20}.job
- c:\windows\system32\msfeedssync.exe [2010-12-16 04:25]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
FF - ProfilePath - c:\users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\yavt2a2c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - %profile%\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-Metropolis - c:\windows\system32\sshnas21.dll
HKU-Default-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
AddRemove-Hardlock Device Drivers - c:\windows\system32\UNWISE.EXE
AddRemove-PC Translator - c:\users\Radek\AppData\Local\Temp\UN32.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-30 10:00
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
c:\windows\TEMP\TMP0000006630359557E8F3BA84 524288 bytes
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-12-30 10:02:59
ComboFix-quarantined-files.txt 2010-12-30 09:02
Před spuštěním: 7 506 034 688
Po spuštění: Volných bajtů: 11 537 956 864
- - End Of File - - 46623E2521BF6E6B340FC2D7EF5460A4
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2037.1131 [GMT 1:00]
Spuštěný z: c:\users\Radek\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\UNWISE.EXE
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 09:00 . 2010-12-30 09:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- c:\program files\trend micro
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- C:\rsit
2010-12-29 20:16 . 2010-12-29 20:16 -------- d-----w- c:\programdata\FLEXnet
2010-12-29 20:13 . 2010-12-29 20:13 -------- d-----w- c:\windows\Sun
2010-12-29 19:58 . 2010-12-29 19:58 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-29 19:42 . 2002-08-18 18:43 794624 ----a-w- c:\windows\system32\spr32d35.dll
2010-12-28 19:20 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D5139D5-D081-4F05-8E3C-C18107D1B5B9}\mpengine.dll
2010-12-26 15:02 . 2010-12-26 15:02 -------- d-----w- c:\users\Radek\AppData\Roaming\Autodesk
2010-12-26 15:01 . 2010-12-26 15:14 -------- d-----w- c:\programdata\Autodesk
2010-12-26 15:01 . 2010-12-26 15:01 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-26 15:00 . 2010-12-26 15:12 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-12-26 15:00 . 2010-12-26 15:07 -------- d-----w- c:\users\Radek\AppData\Local\Autodesk
2010-12-24 12:15 . 2010-12-24 12:15 -------- d-----w- c:\users\Radek\AppData\Roaming\dvdcss
2010-12-11 16:27 . 2010-12-11 16:27 -------- d-----w- c:\users\Radek\{01f23597-6798-432f-b0c7-8511011677b5}
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\PCSuite
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\Nokia
2010-12-11 16:25 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-12-11 16:24 . 2010-12-11 16:25 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-11 16:24 . 2010-12-11 16:24 -------- d-----w- c:\program files\PC Connectivity Solution
2010-12-11 15:29 . 2010-12-11 16:37 -------- d-----w- c:\programdata\PC Suite
2010-12-11 15:28 . 2010-12-11 16:37 -------- d-----w- c:\users\Radek\AppData\Roaming\Nokia
2010-12-11 15:27 . 2010-12-11 15:27 -------- d-----w- c:\program files\DIFX
2010-12-11 15:25 . 2010-12-11 16:59 -------- d-----w- c:\users\Radek\AppData\Roaming\PC Suite
2010-12-11 15:23 . 2010-12-11 16:26 -------- d-----w- c:\program files\Nokia
2010-12-11 15:23 . 2009-02-09 06:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-12-11 15:22 . 2010-12-11 16:20 -------- d-----w- c:\programdata\Installations
2010-12-08 17:27 . 2010-12-08 17:27 -------- d-----w- c:\program files\FreeTime
2010-12-07 16:54 . 2010-12-07 16:55 -------- d-----w- c:\program files\CDex
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-27 21:12 . 2010-11-27 21:12 157696 ----a-w- c:\windows\system\STORAGE.DLL
2010-11-27 21:12 . 2010-11-27 21:12 398416 ----a-w- c:\windows\system\VBRUN300.DLL
2010-11-13 13:06 . 2010-11-13 13:06 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-10-30 08:51 . 2006-11-02 10:32 101888 ------w- c:\windows\system32\ifxcardm.dll
2010-10-30 08:51 . 2006-11-02 10:32 82432 ------w- c:\windows\system32\axaltocm.dll
2010-10-30 07:57 . 2010-10-30 07:58 411368 ------w- c:\windows\system32\deployJava1.dll
2010-10-30 07:37 . 2010-10-30 07:37 2421760 ----a-w- c:\windows\system32\wucltux.dll
2010-10-30 07:37 . 2010-10-30 07:37 53472 ----a-w- c:\windows\system32\wuauclt.exe
2010-10-30 07:37 . 2010-10-30 07:37 44768 ----a-w- c:\windows\system32\wups2.dll
2010-10-30 07:37 . 2010-10-30 07:37 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2010-10-30 07:36 . 2010-10-30 07:36 87552 ----a-w- c:\windows\system32\wudriver.dll
2010-10-30 07:36 . 2010-10-30 07:36 575704 ----a-w- c:\windows\system32\wuapi.dll
2010-10-30 07:36 . 2010-10-30 07:36 35552 ----a-w- c:\windows\system32\wups.dll
2010-10-30 07:36 . 2010-10-30 07:36 33792 ----a-w- c:\windows\system32\wuapp.exe
2010-10-30 07:36 . 2010-10-30 07:36 171608 ----a-w- c:\windows\system32\wuwebv.dll
2010-10-30 07:01 . 2010-10-30 07:01 191488 ------w- c:\windows\system32\hlvdd.dll
2010-10-30 05:55 . 2010-10-30 05:55 685816 ------w- c:\windows\system32\drivers\sptd.sys
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\qwavedrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\wacompen.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\SCR111.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\scmstcs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\pscr.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\grserial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\stcusb.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\gpr400.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cxbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cmbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mtag.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\serial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\rndismpx.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\pnpmem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\battc.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\acpi.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 7168 ----a-w- c:\windows\system32\drivers\cs-CZ\IPMIDrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\pcmcia.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\pacer.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\BrSerId.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\sermouse.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\msdsm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\mouclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\mouhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\i8042prt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\modem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\serscan.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\afd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 6656 ----a-w- c:\windows\system32\drivers\cs-CZ\yk60x86.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\ipnat.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\ltmdmnt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\hidbth.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 65536 ----a-w- c:\windows\system32\drivers\cs-CZ\ntfs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\e100b325.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\srv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mpad.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\ntrigdigi.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\cs-CZ\LMPRTPRC.DLL.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\viac7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\processr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\intelppm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\crusoe.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk8.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\parport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\RNDISMP.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\parvdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\umbus.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\UAGP35.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\BrParwdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 12288 ----a-w- c:\windows\system32\drivers\cs-CZ\ohci1394.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\Dot4usb.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\amdide.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\bcm4sbxp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\fltmgr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\bthpan.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\nv4_mini.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\isapnp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\scsiport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\mssmbios.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\atikmdag.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 9216 ----a-w- c:\windows\system32\drivers\cs-CZ\pci.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\VIAAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ULIAGPKX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\SISAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\NV_AGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AMDAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AGP440.sys.mui
2010-10-19 09:41 . 2010-10-30 15:23 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-09-02 1043968]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-12-10 323584]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
R3 vsdatant7;vsdatant7;c:\windows\system32\drivers\vsdatant.win7.sys [x]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2005-11-14 34176]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 685816]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2008-11-23 97792]
S3 CamSuiteVAC;CamSuite Virtual Audio;c:\windows\system32\DRIVERS\CamSuiteVAC.sys [2008-09-19 37560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
2010-12-29 c:\windows\Tasks\User_Feed_Synchronization-{3BC4EEBA-98AB-4468-94DE-986FFF7A9E20}.job
- c:\windows\system32\msfeedssync.exe [2010-12-16 04:25]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
FF - ProfilePath - c:\users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\yavt2a2c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - %profile%\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-Metropolis - c:\windows\system32\sshnas21.dll
HKU-Default-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
AddRemove-Hardlock Device Drivers - c:\windows\system32\UNWISE.EXE
AddRemove-PC Translator - c:\users\Radek\AppData\Local\Temp\UN32.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-30 10:00
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
c:\windows\TEMP\TMP0000006630359557E8F3BA84 524288 bytes
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-12-30 10:02:59
ComboFix-quarantined-files.txt 2010-12-30 09:02
Před spuštěním: 7 506 034 688
Po spuštění: Volných bajtů: 11 537 956 864
- - End Of File - - 46623E2521BF6E6B340FC2D7EF5460A4
Re: Kontrola logu, pomaly start, po startu chybi soubor dll

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AlcoholAutomount"=- "WMPNSCFG"=- "PC Suite Tray"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=- "Adobe Reader Speed Launcher"=- "Adobe ARM"=- Driver:: vsdatant7 Firefox:: FF - ProfilePath - c:\users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\yavt2a2c.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms} FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 2645238&q= Collect:: c:\windows\TEMP\TMP0000006630359557E8F3BA84 RegLock:: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte

-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Tady je log, děkuji.
ComboFix 10-12-29.02 - Radek 30.12.2010 10:20:16.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2037.1113 [GMT 1:00]
Spuštěný z: c:\users\Radek\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Radek\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_vsdatant7
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- c:\program files\trend micro
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- C:\rsit
2010-12-29 20:16 . 2010-12-29 20:16 -------- d-----w- c:\programdata\FLEXnet
2010-12-29 20:13 . 2010-12-29 20:13 -------- d-----w- c:\windows\Sun
2010-12-29 19:58 . 2010-12-29 19:58 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-29 19:42 . 2002-08-18 18:43 794624 ----a-w- c:\windows\system32\spr32d35.dll
2010-12-28 19:20 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D5139D5-D081-4F05-8E3C-C18107D1B5B9}\mpengine.dll
2010-12-26 15:02 . 2010-12-26 15:02 -------- d-----w- c:\users\Radek\AppData\Roaming\Autodesk
2010-12-26 15:01 . 2010-12-26 15:14 -------- d-----w- c:\programdata\Autodesk
2010-12-26 15:01 . 2010-12-26 15:01 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-26 15:00 . 2010-12-26 15:12 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-12-26 15:00 . 2010-12-26 15:07 -------- d-----w- c:\users\Radek\AppData\Local\Autodesk
2010-12-24 12:15 . 2010-12-24 12:15 -------- d-----w- c:\users\Radek\AppData\Roaming\dvdcss
2010-12-11 16:27 . 2010-12-11 16:27 -------- d-----w- c:\users\Radek\{01f23597-6798-432f-b0c7-8511011677b5}
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\PCSuite
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\Nokia
2010-12-11 16:25 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-12-11 16:24 . 2010-12-11 16:25 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-11 16:24 . 2010-12-11 16:24 -------- d-----w- c:\program files\PC Connectivity Solution
2010-12-11 15:29 . 2010-12-11 16:37 -------- d-----w- c:\programdata\PC Suite
2010-12-11 15:28 . 2010-12-11 16:37 -------- d-----w- c:\users\Radek\AppData\Roaming\Nokia
2010-12-11 15:27 . 2010-12-11 15:27 -------- d-----w- c:\program files\DIFX
2010-12-11 15:25 . 2010-12-11 16:59 -------- d-----w- c:\users\Radek\AppData\Roaming\PC Suite
2010-12-11 15:23 . 2010-12-11 16:26 -------- d-----w- c:\program files\Nokia
2010-12-11 15:23 . 2009-02-09 06:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-12-11 15:22 . 2010-12-11 16:20 -------- d-----w- c:\programdata\Installations
2010-12-08 17:27 . 2010-12-08 17:27 -------- d-----w- c:\program files\FreeTime
2010-12-07 16:54 . 2010-12-07 16:55 -------- d-----w- c:\program files\CDex
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-27 21:12 . 2010-11-27 21:12 157696 ----a-w- c:\windows\system\STORAGE.DLL
2010-11-27 21:12 . 2010-11-27 21:12 398416 ----a-w- c:\windows\system\VBRUN300.DLL
2010-11-13 13:06 . 2010-11-13 13:06 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-10-30 08:51 . 2006-11-02 10:32 101888 ------w- c:\windows\system32\ifxcardm.dll
2010-10-30 08:51 . 2006-11-02 10:32 82432 ------w- c:\windows\system32\axaltocm.dll
2010-10-30 07:57 . 2010-10-30 07:58 411368 ------w- c:\windows\system32\deployJava1.dll
2010-10-30 07:37 . 2010-10-30 07:37 2421760 ----a-w- c:\windows\system32\wucltux.dll
2010-10-30 07:37 . 2010-10-30 07:37 53472 ----a-w- c:\windows\system32\wuauclt.exe
2010-10-30 07:37 . 2010-10-30 07:37 44768 ----a-w- c:\windows\system32\wups2.dll
2010-10-30 07:37 . 2010-10-30 07:37 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2010-10-30 07:36 . 2010-10-30 07:36 87552 ----a-w- c:\windows\system32\wudriver.dll
2010-10-30 07:36 . 2010-10-30 07:36 575704 ----a-w- c:\windows\system32\wuapi.dll
2010-10-30 07:36 . 2010-10-30 07:36 35552 ----a-w- c:\windows\system32\wups.dll
2010-10-30 07:36 . 2010-10-30 07:36 33792 ----a-w- c:\windows\system32\wuapp.exe
2010-10-30 07:36 . 2010-10-30 07:36 171608 ----a-w- c:\windows\system32\wuwebv.dll
2010-10-30 07:01 . 2010-10-30 07:01 191488 ------w- c:\windows\system32\hlvdd.dll
2010-10-30 05:55 . 2010-10-30 05:55 685816 ------w- c:\windows\system32\drivers\sptd.sys
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\qwavedrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\wacompen.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\SCR111.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\scmstcs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\pscr.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\grserial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\stcusb.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\gpr400.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cxbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cmbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mtag.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\serial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\rndismpx.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\pnpmem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\battc.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\acpi.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 7168 ----a-w- c:\windows\system32\drivers\cs-CZ\IPMIDrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\pcmcia.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\pacer.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\BrSerId.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\sermouse.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\msdsm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\mouclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\mouhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\i8042prt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\modem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\serscan.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\afd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 6656 ----a-w- c:\windows\system32\drivers\cs-CZ\yk60x86.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\ipnat.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\ltmdmnt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\hidbth.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 65536 ----a-w- c:\windows\system32\drivers\cs-CZ\ntfs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\e100b325.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\srv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mpad.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\ntrigdigi.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\cs-CZ\LMPRTPRC.DLL.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\viac7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\processr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\intelppm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\crusoe.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk8.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\parport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\RNDISMP.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\parvdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\umbus.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\UAGP35.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\BrParwdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 12288 ----a-w- c:\windows\system32\drivers\cs-CZ\ohci1394.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\Dot4usb.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\amdide.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\bcm4sbxp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\fltmgr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\bthpan.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\nv4_mini.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\isapnp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\scsiport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\mssmbios.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\atikmdag.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 9216 ----a-w- c:\windows\system32\drivers\cs-CZ\pci.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\VIAAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ULIAGPKX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\SISAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\NV_AGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AMDAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AGP440.sys.mui
2010-10-19 09:41 . 2010-10-30 15:23 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-09-02 1043968]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-12-10 323584]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2005-11-14 34176]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 685816]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2008-11-23 97792]
S3 CamSuiteVAC;CamSuite Virtual Audio;c:\windows\system32\DRIVERS\CamSuiteVAC.sys [2008-09-19 37560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
2010-12-29 c:\windows\Tasks\User_Feed_Synchronization-{3BC4EEBA-98AB-4468-94DE-986FFF7A9E20}.job
- c:\windows\system32\msfeedssync.exe [2010-12-16 04:25]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
FF - ProfilePath - c:\users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\yavt2a2c.default\
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - %profile%\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-30 10:33
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(1876)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\conime.exe
c:\program files\Alwil Software\Avast5\AvastUI.exe
c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-12-30 10:35:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-12-30 09:35
ComboFix2.txt 2010-12-30 09:02
Před spuštěním: Volných bajtů: 11 301 838 848
Po spuštění: Volných bajtů: 11 303 833 600
- - End Of File - - 00B4DBFDC19F36B8B54606F892665EE0
ComboFix 10-12-29.02 - Radek 30.12.2010 10:20:16.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2037.1113 [GMT 1:00]
Spuštěný z: c:\users\Radek\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Radek\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_vsdatant7
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-28 do 2010-12-30 )))))))))))))))))))))))))))))))
.
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- c:\program files\trend micro
2010-12-30 06:28 . 2010-12-30 06:29 -------- d-----w- C:\rsit
2010-12-29 20:16 . 2010-12-29 20:16 -------- d-----w- c:\programdata\FLEXnet
2010-12-29 20:13 . 2010-12-29 20:13 -------- d-----w- c:\windows\Sun
2010-12-29 19:58 . 2010-12-29 19:58 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-29 19:42 . 2002-08-18 18:43 794624 ----a-w- c:\windows\system32\spr32d35.dll
2010-12-28 19:20 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D5139D5-D081-4F05-8E3C-C18107D1B5B9}\mpengine.dll
2010-12-26 15:02 . 2010-12-26 15:02 -------- d-----w- c:\users\Radek\AppData\Roaming\Autodesk
2010-12-26 15:01 . 2010-12-26 15:14 -------- d-----w- c:\programdata\Autodesk
2010-12-26 15:01 . 2010-12-26 15:01 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-26 15:00 . 2010-12-26 15:12 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-12-26 15:00 . 2010-12-26 15:07 -------- d-----w- c:\users\Radek\AppData\Local\Autodesk
2010-12-24 12:15 . 2010-12-24 12:15 -------- d-----w- c:\users\Radek\AppData\Roaming\dvdcss
2010-12-11 16:27 . 2010-12-11 16:27 -------- d-----w- c:\users\Radek\{01f23597-6798-432f-b0c7-8511011677b5}
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\PCSuite
2010-12-11 16:26 . 2010-12-11 16:26 -------- d-----w- c:\program files\Common Files\Nokia
2010-12-11 16:25 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-12-11 16:24 . 2010-12-11 16:25 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-11 16:24 . 2010-12-11 16:24 -------- d-----w- c:\program files\PC Connectivity Solution
2010-12-11 15:29 . 2010-12-11 16:37 -------- d-----w- c:\programdata\PC Suite
2010-12-11 15:28 . 2010-12-11 16:37 -------- d-----w- c:\users\Radek\AppData\Roaming\Nokia
2010-12-11 15:27 . 2010-12-11 15:27 -------- d-----w- c:\program files\DIFX
2010-12-11 15:25 . 2010-12-11 16:59 -------- d-----w- c:\users\Radek\AppData\Roaming\PC Suite
2010-12-11 15:23 . 2010-12-11 16:26 -------- d-----w- c:\program files\Nokia
2010-12-11 15:23 . 2009-02-09 06:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-12-11 15:22 . 2010-12-11 16:20 -------- d-----w- c:\programdata\Installations
2010-12-08 17:27 . 2010-12-08 17:27 -------- d-----w- c:\program files\FreeTime
2010-12-07 16:54 . 2010-12-07 16:55 -------- d-----w- c:\program files\CDex
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-27 21:12 . 2010-11-27 21:12 157696 ----a-w- c:\windows\system\STORAGE.DLL
2010-11-27 21:12 . 2010-11-27 21:12 398416 ----a-w- c:\windows\system\VBRUN300.DLL
2010-11-13 13:06 . 2010-11-13 13:06 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-10-30 08:51 . 2006-11-02 10:32 101888 ------w- c:\windows\system32\ifxcardm.dll
2010-10-30 08:51 . 2006-11-02 10:32 82432 ------w- c:\windows\system32\axaltocm.dll
2010-10-30 07:57 . 2010-10-30 07:58 411368 ------w- c:\windows\system32\deployJava1.dll
2010-10-30 07:37 . 2010-10-30 07:37 2421760 ----a-w- c:\windows\system32\wucltux.dll
2010-10-30 07:37 . 2010-10-30 07:37 53472 ----a-w- c:\windows\system32\wuauclt.exe
2010-10-30 07:37 . 2010-10-30 07:37 44768 ----a-w- c:\windows\system32\wups2.dll
2010-10-30 07:37 . 2010-10-30 07:37 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2010-10-30 07:36 . 2010-10-30 07:36 87552 ----a-w- c:\windows\system32\wudriver.dll
2010-10-30 07:36 . 2010-10-30 07:36 575704 ----a-w- c:\windows\system32\wuapi.dll
2010-10-30 07:36 . 2010-10-30 07:36 35552 ----a-w- c:\windows\system32\wups.dll
2010-10-30 07:36 . 2010-10-30 07:36 33792 ----a-w- c:\windows\system32\wuapp.exe
2010-10-30 07:36 . 2010-10-30 07:36 171608 ----a-w- c:\windows\system32\wuwebv.dll
2010-10-30 07:01 . 2010-10-30 07:01 191488 ------w- c:\windows\system32\hlvdd.dll
2010-10-30 05:55 . 2010-10-30 05:55 685816 ------w- c:\windows\system32\drivers\sptd.sys
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\qwavedrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\wacompen.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\SCR111.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\scmstcs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\pscr.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\grserial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\stcusb.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\gpr400.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cxbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\cmbp0wdm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mtag.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\serial.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\rndismpx.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\pnpmem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\wd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\battc.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\acpi.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 7168 ----a-w- c:\windows\system32\drivers\cs-CZ\IPMIDrv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\pcmcia.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\pacer.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\BrSerId.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\sermouse.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\msdsm.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\mouclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\mouhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 10240 ----a-w- c:\windows\system32\drivers\cs-CZ\i8042prt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\modem.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\serscan.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\afd.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 6656 ----a-w- c:\windows\system32\drivers\cs-CZ\yk60x86.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\ipnat.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 9728 ----a-w- c:\windows\system32\drivers\cs-CZ\ltmdmnt.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\hidbth.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdhid.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 65536 ----a-w- c:\windows\system32\drivers\cs-CZ\ntfs.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\e100b325.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\kbdclass.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\srv.sys.mui
2010-10-29 23:16 . 2010-10-29 23:16 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ati2mpad.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4608 ----a-w- c:\windows\system32\drivers\cs-CZ\ntrigdigi.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\cs-CZ\LMPRTPRC.DLL.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\viac7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\processr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\intelppm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\crusoe.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk8.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 21504 ----a-w- c:\windows\system32\drivers\cs-CZ\amdk7.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\parport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\RNDISMP.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\parvdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\umbus.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\UAGP35.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\GAGP30KX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\BrParwdm.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 12288 ----a-w- c:\windows\system32\drivers\cs-CZ\ohci1394.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\Dot4usb.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 2560 ----a-w- c:\windows\system32\drivers\cs-CZ\amdide.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5632 ----a-w- c:\windows\system32\drivers\cs-CZ\bcm4sbxp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\fltmgr.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\bthpan.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 5120 ----a-w- c:\windows\system32\drivers\cs-CZ\nv4_mini.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 4096 ----a-w- c:\windows\system32\drivers\cs-CZ\isapnp.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\scsiport.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3584 ----a-w- c:\windows\system32\drivers\cs-CZ\mssmbios.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\atikmdag.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 9216 ----a-w- c:\windows\system32\drivers\cs-CZ\pci.sys.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\VIAAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\ULIAGPKX.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\SISAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\NV_AGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AMDAGP.SYS.mui
2010-10-29 23:15 . 2010-10-29 23:15 3072 ----a-w- c:\windows\system32\drivers\cs-CZ\AGP440.sys.mui
2010-10-19 09:41 . 2010-10-30 15:23 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-09-02 1043968]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-12-10 323584]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2005-11-14 34176]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 685816]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NSHE;Guardant Emulator Driver;c:\windows\system32\Drivers\NSHE.SYS [2008-11-23 97792]
S3 CamSuiteVAC;CamSuite Virtual Audio;c:\windows\system32\DRIVERS\CamSuiteVAC.sys [2008-09-19 37560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
2010-12-29 c:\windows\Tasks\User_Feed_Synchronization-{3BC4EEBA-98AB-4468-94DE-986FFF7A9E20}.job
- c:\windows\system32\msfeedssync.exe [2010-12-16 04:25]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
FF - ProfilePath - c:\users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\yavt2a2c.default\
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - %profile%\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-30 10:33
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(1876)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\conime.exe
c:\program files\Alwil Software\Avast5\AvastUI.exe
c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-12-30 10:35:32 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-12-30 09:35
ComboFix2.txt 2010-12-30 09:02
Před spuštěním: Volných bajtů: 11 301 838 848
Po spuštění: Volných bajtů: 11 303 833 600
- - End Of File - - 00B4DBFDC19F36B8B54606F892665EE0
Re: Kontrola logu, pomaly start, po startu chybi soubor dll

- Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
- Napiste ComboFix /Uninstall
- Stisknete Enter
- Tohle smaze Combofix a jeho slozky

- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy

-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Diky za rady, vse jsem udelal a vypada ok.
Jen jedna vec, co mi stale vadi je, ze pri startu se objevi Vitejte, do te doby dobre, ale pak to zmizi, naskoci cerna obrazovka
a ja musim cekat cca 90s (mereno stopkama) nez se objevi plocha...
Muze to byt haveti? Děkuji pěkně.
Jen jedna vec, co mi stale vadi je, ze pri startu se objevi Vitejte, do te doby dobre, ale pak to zmizi, naskoci cerna obrazovka
a ja musim cekat cca 90s (mereno stopkama) nez se objevi plocha...
Muze to byt haveti? Děkuji pěkně.
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Nemate na plose nejake velke soubory - nemam na mysli zstupce,ale treba nejake filmy, mp3 soubory, fotky apod. 

-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Bohuzel, na to jsem poradny, na plose nic nechci, ani na C, vse je na D. Plocha ma 24MB...
Re: Kontrola logu, pomaly start, po startu chybi soubor dll



- Rozbalte nejlepe na plochu a spustte
- Kliknete pravym mysidlem do okna a klik na Vybrat vše - text bude na bilem pozadi a pak stisknout Enter - text bude na cernem pozadi (pokud po enteru pozadi nezcerna, tak stisknete Ctrl+C)
- Stisknete libovolnou klavesu pro ukoceni utility
- Sem pak vlozte log pomoci tradicni zkratky Ctrl+V
-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Ne, bootloader nepouzivam.
Tady je vypis programu:
Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com
Program version: 1.2.0.0
OS Version: Microsoft Windows Vista Home Premium Edition Service Pack 2 (build 6
002), 32-bit
System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`c9024000
Boot sector MD5 is: 0ec6b2481fc707d1e901dc2a875f2826
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)
Done;
Press any key to quit...
Tady je vypis programu:
Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com
Program version: 1.2.0.0
OS Version: Microsoft Windows Vista Home Premium Edition Service Pack 2 (build 6
002), 32-bit
System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`c9024000
Boot sector MD5 is: 0ec6b2481fc707d1e901dc2a875f2826
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)
Done;
Press any key to quit...
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Tohle je v poradku
Minuta a pul je docela hodne, ovsem zalezi i na vykonu procesoru jak rychle stiha nacitat profil... Zkuste jeste defragmentovat disk
Defragmentace disku

Minuta a pul je docela hodne, ovsem zalezi i na vykonu procesoru jak rychle stiha nacitat profil... Zkuste jeste defragmentovat disk

- Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
- Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
- prepnete se do zalozky Nastroje
- Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
- Toto provedte se vsemi disky
- Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
- Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
- Kliknete na Analyzovat
- Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
- Postup provedte se vsemi disky
- Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
- Vyhodou programku je, ze se neinstaluje
- Staci tedy jen stahnout dle verze vaseho OS a rozbalit
- Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
- Probehne analyza disku a nasledne i defragmentace
-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Tak jsem se konecne vratil k pc a defragmentuju, az bude vysledek, dam vedet. Ale asi to bude az pristi rok
Děkuji a vse nejlepsi v novem roce!

Děkuji a vse nejlepsi v novem roce!
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Ok, uzijte si silvestrovske oslavy a at maji co nejmensi dopad na jatra
Vse nej i Vam

Vse nej i Vam

-
- Návštěvník
- Příspěvky: 114
- Registrován: 14 led 2006 16:33
Re: Kontrola logu, pomaly start, po startu chybi soubor dll
Tak preci jeste letos
. C zdefragmentováno, ale ze 14% je ted 7%. Kolikrat to delat? Delam to Defraggler.
Dekuji

Dekuji