Logfile of random's system information tool 1.08 (written by random/random)
Run by Rado at 2011-01-09 18:26:47
Microsoft Windows 7 Ultimate
System drive C: has 14 GB (47%) free of 31 GB
Total RAM: 2047 MB (65% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\Norton Security Scan for Rado.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-09-11 2054360]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-11-09 7862816]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2009-06-17 55824]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2009-11-26 5129128]
"Služba Acronis Scheduler2"=C:\Program Files\Common Files\Acronis\Plán2\schedhlp.exe [2009-11-26 361976]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"HDD Regenerator"=C:\Program Files\HDD Regenerator\HDD Regenerator.exe []
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-08-11 81920]
"MSWUpdate"=C:\Users\Rado\AppData\Roaming\lsass.exe [2011-01-09 368641]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
""= []
"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2005-08-11 249856]
"MSWUpdate"=C:\Users\Rado\AppData\Roaming\lsass.exe [2011-01-09 368641]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Users\Rado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Logitech . Registrácia výrobku.lnk - C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe
Orezávač obrazovky a spúšťač programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-07-20 72208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-01-09 18:26:47 ----D---- C:\rsit
2011-01-09 18:26:47 ----D---- C:\Program Files\trend micro
2011-01-09 16:38:35 ----A---- C:\Windows\ntbtlog.txt
2011-01-09 14:44:34 ----RSH---- C:\Users\Rado\AppData\Roaming\lsass.exe
2011-01-08 13:15:48 ----A---- C:\Windows\system32\CNMVS23.DLL
2011-01-08 13:15:45 ----A---- C:\Windows\system32\CNMCP23.EXE
2011-01-08 13:15:44 ----HD---- C:\BJPrinter
2011-01-08 13:05:26 ----A---- C:\Windows\system32\CNMLM23.DLL
2011-01-08 13:05:05 ----D---- C:\temp
2011-01-06 11:01:00 ----D---- C:\Users\Rado\AppData\Roaming\Corel
2011-01-06 11:00:22 ----D---- C:\ProgramData\InstallShield
2011-01-06 10:59:07 ----D---- C:\Program Files\Corel
2011-01-06 10:59:07 ----D---- C:\Program Files\Common Files\Corel
2011-01-03 19:38:39 ----A---- C:\Windows\WDIRECT.INI
2011-01-03 19:35:07 ----A---- C:\Windows\IsUninst.exe
2011-01-03 14:09:50 ----D---- C:\Program Files\EDDICA
2011-01-02 17:32:17 ----D---- C:\ProgramData\Symantec
2011-01-02 17:32:13 ----D---- C:\Windows\system32\drivers\NSS
2011-01-02 17:32:12 ----D---- C:\ProgramData\Norton
2011-01-02 17:32:11 ----D---- C:\ProgramData\NortonInstaller
2011-01-02 16:59:05 ----D---- C:\Windows\system32\Adobe
2010-12-30 10:59:20 ----D---- C:\ProgramData\Nokia
2010-12-30 10:42:30 ----D---- C:\Users\Rado\AppData\Roaming\Nokia Ovi Suite
2010-12-28 10:51:56 ----D---- C:\Users\Rado\AppData\Roaming\EleFun Games
2010-12-26 09:11:02 ----D---- C:\Users\Rado\AppData\Roaming\Nokia
2010-12-26 09:10:51 ----D---- C:\ProgramData\PC Suite
2010-12-26 09:09:53 ----D---- C:\Users\Rado\AppData\Roaming\PC Suite
2010-12-26 09:09:01 ----D---- C:\Program Files\Common Files\Nokia
2010-12-26 09:08:44 ----D---- C:\Program Files\DIFX
2010-12-26 09:08:44 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2010-12-26 09:08:42 ----DC---- C:\Windows\system32\DRVSTORE
2010-12-26 09:08:39 ----D---- C:\Program Files\PC Connectivity Solution
2010-12-26 09:08:22 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-12-26 09:07:11 ----D---- C:\ProgramData\NokiaInstallerCache
2010-12-26 09:07:11 ----D---- C:\Program Files\Nokia
2010-12-25 12:32:21 ----D---- C:\Windows\system32\appmgmt
2010-12-25 12:22:41 ----D---- C:\ProgramData\TEMP
2010-12-25 12:22:34 ----D---- C:\Program Files\HDD Regenerator
2010-12-25 09:36:15 ----D---- C:\Users\Rado\AppData\Roaming\XnView
2010-12-25 09:35:55 ----D---- C:\Program Files\XnView
2010-12-25 09:28:12 ----D---- C:\Program Files\IrfanView
2010-12-25 09:11:00 ----D---- C:\Users\Rado\AppData\Roaming\IrfanView
2010-12-25 09:03:23 ----D---- C:\Program Files\The KMPlayer
2010-12-24 09:44:54 ----RASH---- C:\MSDOS.SYS
2010-12-24 09:44:54 ----RASH---- C:\IO.SYS
2010-12-23 19:26:18 ----D---- C:\Users\Rado\AppData\Roaming\DeepVoyage
2010-12-23 19:16:54 ----D---- C:\Users\Rado\AppData\Roaming\Nero
2010-12-23 19:15:45 ----RA---- C:\Windows\system32\imagxpr7.dll
2010-12-23 19:15:45 ----A---- C:\Windows\system32\twnlib4.dll
2010-12-23 19:15:45 ----A---- C:\Windows\system32\imagxra7.dll
2010-12-23 19:15:45 ----A---- C:\Windows\system32\imagxr7.dll
2010-12-23 19:15:45 ----A---- C:\Windows\system32\imagx7.dll
2010-12-23 19:15:36 ----D---- C:\Program Files\Nero
2010-12-23 19:15:36 ----D---- C:\Program Files\Common Files\Nero
2010-12-23 18:50:07 ----A---- C:\Windows\avisplitter.ini
2010-12-23 18:50:05 ----A---- C:\Windows\system32\yv12vfw.dll
2010-12-23 18:50:05 ----A---- C:\Windows\system32\xvidvfw.dll
2010-12-23 18:50:05 ----A---- C:\Windows\system32\xvidcore.dll
2010-12-23 18:50:05 ----A---- C:\Windows\system32\ff_vfw.dll.manifest
2010-12-23 18:50:05 ----A---- C:\Windows\system32\ff_vfw.dll
2010-12-23 18:47:07 ----D---- C:\Program Files\Common Files\Adobe
2010-12-23 18:47:07 ----D---- C:\Program Files\Adobe
2010-12-23 18:37:52 ----D---- C:\ProgramData\NVIDIA Corporation
2010-12-23 18:37:45 ----D---- C:\Program Files\NVIDIA Corporation
2010-12-23 18:37:05 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-12-23 18:37:05 ----A---- C:\Windows\system32\PresentationHost.exe
2010-12-23 18:37:05 ----A---- C:\Windows\system32\netfxperf.dll
2010-12-23 18:37:05 ----A---- C:\Windows\system32\mscoree.dll
2010-12-23 18:37:05 ----A---- C:\Windows\system32\dfshim.dll
2010-12-23 18:33:46 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2010-12-23 18:33:43 ----A---- C:\Windows\system32\drivers\ks.sys
2010-12-23 18:26:19 ----A---- C:\Windows\system32\tzres.dll
2010-12-23 18:26:16 ----A---- C:\Windows\system32\rtutils.dll
2010-12-23 18:26:16 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-12-23 18:26:10 ----A---- C:\Windows\system32\lsasrv.dll
2010-12-23 18:26:10 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2010-12-23 18:26:08 ----A---- C:\Windows\system32\mshtml.dll
2010-12-23 18:26:08 ----A---- C:\Windows\system32\iertutil.dll
2010-12-23 18:26:06 ----A---- C:\Windows\system32\ieframe.dll
2010-12-23 18:26:05 ----A---- C:\Windows\system32\mstime.dll
2010-12-23 18:26:05 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\wininet.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\urlmon.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\ieui.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\iepeers.dll
2010-12-23 18:26:04 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-23 18:26:03 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-23 18:26:03 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-23 18:25:59 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-12-23 18:25:59 ----A---- C:\Windows\system32\drivers\srv.sys
2010-12-23 18:25:58 ----A---- C:\Windows\system32\srvsvc.dll
2010-12-23 18:25:58 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-12-23 18:25:56 ----A---- C:\Windows\system32\shell32.dll
2010-12-23 18:25:55 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-12-23 18:25:54 ----A---- C:\Windows\system32\mfc40u.dll
2010-12-23 18:25:54 ----A---- C:\Windows\system32\mfc40.dll
2010-12-23 18:25:45 ----A---- C:\Windows\system32\spoolsv.exe
2010-12-23 18:25:42 ----A---- C:\Windows\system32\wmp.dll
2010-12-23 18:25:41 ----A---- C:\Windows\system32\wmploc.DLL
2010-12-23 18:25:40 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-23 18:25:40 ----A---- C:\Windows\system32\taskschd.dll
2010-12-23 18:25:40 ----A---- C:\Windows\system32\taskeng.exe
2010-12-23 18:25:40 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-23 18:25:40 ----A---- C:\Windows\system32\schtasks.exe
2010-12-23 18:25:40 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-23 18:25:39 ----A---- C:\Windows\system32\ir32_32.dll
2010-12-23 18:25:39 ----A---- C:\Windows\system32\iccvid.dll
2010-12-23 18:25:39 ----A---- C:\Windows\system32\atmlib.dll
2010-12-23 18:25:39 ----A---- C:\Windows\system32\atmfd.dll
2010-12-23 18:25:38 ----A---- C:\Windows\system32\inetcomm.dll
2010-12-23 18:25:37 ----A---- C:\Windows\system32\comctl32.dll
2010-12-23 18:25:37 ----A---- C:\Windows\system32\cabview.dll
2010-12-23 18:25:36 ----A---- C:\Windows\system32\t2embed.dll
2010-12-23 18:25:35 ----A---- C:\Windows\system32\msxml3.dll
2010-12-23 18:25:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-12-23 18:25:33 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-12-23 18:25:32 ----A---- C:\Windows\system32\kernel32.dll
2010-12-23 18:25:32 ----A---- C:\Windows\system32\apphelp.dll
2010-12-23 18:25:31 ----A---- C:\Windows\system32\wintrust.dll
2010-12-23 18:25:30 ----A---- C:\Windows\system32\vbscript.dll
2010-12-23 18:25:28 ----A---- C:\Windows\system32\ole32.dll
2010-12-23 18:25:27 ----A---- C:\Windows\system32\consent.exe
2010-12-23 18:25:26 ----A---- C:\Windows\system32\webio.dll
2010-12-23 18:25:25 ----A---- C:\Windows\system32\wmpmde.dll
2010-12-23 18:25:25 ----A---- C:\Windows\system32\ntdll.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\tsbyuv.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\quartz.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\msyuv.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\msvidc32.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\msrle32.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\mciavi32.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\iyuv_32.dll
2010-12-23 18:25:24 ----A---- C:\Windows\system32\avifil32.dll
2010-12-23 18:25:23 ----A---- C:\Windows\system32\schannel.dll
2010-12-23 18:25:21 ----A---- C:\Windows\system32\StructuredQuery.dll
2010-12-23 18:25:21 ----A---- C:\Windows\system32\asycfilt.dll
2010-12-23 18:25:20 ----A---- C:\Windows\system32\oleaut32.dll
2010-12-23 18:23:55 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2010-12-23 18:23:55 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2010-12-23 18:23:55 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2010-12-23 18:22:45 ----A---- C:\Windows\system32\win32k.sys
2010-12-23 17:25:02 ----A---- C:\Windows\system32\drivers\netr61.sys
======List of files/folders modified in the last 1 months======
2011-01-09 18:26:48 ----D---- C:\Windows\Prefetch
2011-01-09 18:26:47 ----D---- C:\Program Files
2011-01-09 18:25:34 ----D---- C:\Windows\Temp
2011-01-09 18:10:24 ----D---- C:\Windows\System32
2011-01-09 18:10:24 ----D---- C:\Windows\inf
2011-01-09 18:10:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-09 16:43:29 ----D---- C:\Windows\system32\config
2011-01-09 16:38:35 ----D---- C:\Windows
2011-01-09 15:13:15 ----SHD---- C:\System Volume Information
2011-01-09 14:44:33 ----D---- C:\Program Files\Mozilla Firefox
2011-01-09 14:27:48 ----SHD---- C:\Windows\Installer
2011-01-09 14:27:47 ----D---- C:\Windows\system32\Tasks
2011-01-08 18:16:14 ----SD---- C:\Users\Rado\AppData\Roaming\Microsoft
2011-01-08 13:15:52 ----D---- C:\Windows\system32\DriverStore
2011-01-08 13:05:29 ----D---- C:\Windows\system32\catroot
2011-01-06 11:00:22 ----HD---- C:\ProgramData
2011-01-06 11:00:20 ----D---- C:\Windows\Downloaded Program Files
2011-01-06 11:00:20 ----D---- C:\Program Files\Common Files\InstallShield
2011-01-06 11:00:10 ----D---- C:\Program Files\Common Files\microsoft shared
2011-01-06 11:00:10 ----D---- C:\Program Files\Common Files\DESIGNER
2011-01-06 10:59:37 ----D---- C:\Windows\winsxs
2011-01-06 10:59:29 ----RSD---- C:\Windows\Fonts
2011-01-06 10:59:07 ----D---- C:\Program Files\Common Files
2011-01-05 18:10:51 ----D---- C:\Windows\system32\drivers
2011-01-02 17:32:18 ----D---- C:\Windows\Tasks
2011-01-02 13:41:11 ----D---- C:\Users\Rado\AppData\Roaming\Skype
2011-01-02 13:40:28 ----D---- C:\Users\Rado\AppData\Roaming\skypePM
2010-12-30 20:53:00 ----D---- C:\Windows\system32\NDF
2010-12-30 15:41:28 ----SD---- C:\ProgramData\Microsoft
2010-12-30 15:27:23 ----D---- C:\Windows\system32\catroot2
2010-12-30 10:36:44 ----D---- C:\Windows\system32\drivers\UMDF
2010-12-26 10:35:31 ----D---- C:\Windows\rescache
2010-12-26 10:34:18 ----D---- C:\Windows\Logs
2010-12-25 09:53:20 ----SHD---- C:\$Recycle.Bin
2010-12-25 09:53:16 ----RD---- C:\Users
2010-12-25 09:51:58 ----HD---- C:\Windows\system32\GroupPolicyUsers
2010-12-25 09:51:57 ----HD---- C:\Windows\system32\GroupPolicy
2010-12-24 07:52:36 ----D---- C:\Windows\system32\wdi
2010-12-23 19:09:12 ----D---- C:\Windows\Microsoft.NET
2010-12-23 19:09:03 ----RSD---- C:\Windows\assembly
2010-12-23 18:50:13 ----D---- C:\Program Files\K-Lite Codec Pack
2010-12-23 18:47:47 ----D---- C:\ProgramData\Adobe
2010-12-23 18:42:05 ----D---- C:\ProgramData\NVIDIA
2010-12-23 18:39:53 ----D---- C:\Windows\system32\sk-SK
2010-12-23 18:39:53 ----D---- C:\Windows\system32\migration
2010-12-23 18:39:53 ----D---- C:\Program Files\Windows Mail
2010-12-23 18:39:53 ----D---- C:\Program Files\Internet Explorer
2010-12-23 18:39:52 ----D---- C:\Windows\AppPatch
2010-12-23 18:39:52 ----D---- C:\Program Files\Windows Media Player
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2010-02-08 158272]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-02-07 691696]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258); C:\Windows\system32\DRIVERS\tdrpm258.sys [2010-02-08 911680]
R0 timounter;Acronis Backup Archive Explorer; C:\Windows\system32\DRIVERS\timntr.sys [2010-02-08 581984]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-09-11 116008]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2009-09-11 135048]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys [2010-02-08 160288]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2009-06-19 33096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-11-09 2785568]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2009-06-17 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2009-06-17 37392]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2009-06-17 28560]
S3 aels6s7w;aels6s7w; C:\Windows\system32\drivers\aels6s7w.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista; C:\Windows\system32\DRIVERS\netr61.sys [2008-12-23 286208]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-07-14 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files\Common Files\Acronis\Plán2\schedul2.exe [2009-11-26 661008]
R2 afcdpsrv;Acronis Nonstop Backup service; C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-02-08 2480048]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-09-11 20680]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
ComboFix 11-01-08.05 - Rado . 01. 2011 19:13:40.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.2047.1419 [GMT 1:00]
Running from: d:\soft\Utility a ostatne\Systemove nastroje\AKO NA VIRY\ComboFix.exe
AV: ESET Smart Security 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Rado\AppData\Roaming\lsass.exe
.
((((((((((((((((((((((((( Files Created from 2010-12-09 to 2011-01-09 )))))))))))))))))))))))))))))))
.
2011-01-09 18:16 . 2011-01-09 18:17 -------- d-----w- c:\users\Rado\AppData\Local\temp
2011-01-09 18:16 . 2011-01-09 18:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-09 17:26 . 2011-01-09 17:26 -------- d-----w- C:\rsit
2011-01-09 17:26 . 2011-01-09 17:26 -------- d-----w- c:\program files\trend micro
2011-01-09 13:44 . 2011-01-09 13:44 368640 ----a-w- c:\program files\Mozilla Firefox\update.exe
2011-01-09 13:21 . 2011-01-09 13:21 -------- d-----w- c:\users\Rado\AppData\Local\ESET
2011-01-08 12:15 . 2001-08-28 15:00 5632 ----a-w- c:\windows\system32\CNMVS23.DLL
2011-01-08 12:15 . 2001-08-28 15:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP23.DLL
2011-01-08 12:15 . 2001-08-23 11:06 36864 ----a-w- c:\windows\system32\CNMCP23.EXE
2011-01-08 12:15 . 2011-01-08 12:15 -------- d-----w- C:\BJPrinter
2011-01-08 12:05 . 2001-08-28 15:00 94720 ----a-w- c:\windows\system32\CNMLM23.DLL
2011-01-08 12:05 . 2001-08-28 15:00 8192 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD23.DLL
2011-01-08 12:05 . 2011-01-08 12:05 -------- d-----w- C:\temp
2011-01-06 17:48 . 2011-01-06 17:48 -------- d-----w- c:\users\Rado\AppData\Local\FunnyMiners
2011-01-06 10:01 . 2011-01-06 10:01 -------- d-----w- c:\users\Rado\AppData\Roaming\Corel
2011-01-06 10:00 . 2011-01-06 10:00 -------- d-----w- c:\programdata\InstallShield
2011-01-06 10:00 . 2011-01-06 10:00 65536 ----a-r- c:\users\Rado\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
2011-01-06 09:59 . 2011-01-06 09:59 -------- d-----w- c:\program files\Corel
2011-01-06 09:59 . 2011-01-06 09:59 -------- d-----w- c:\program files\Common Files\Corel
2011-01-03 18:35 . 1998-10-29 23:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-01-03 13:09 . 2011-01-03 13:09 -------- d-----w- c:\program files\EDDICA
2011-01-02 16:32 . 2011-01-02 16:32 -------- d-----w- c:\programdata\Symantec
2011-01-02 16:32 . 2011-01-02 16:32 -------- d-----w- c:\windows\system32\drivers\NSS
2011-01-02 16:32 . 2011-01-02 16:32 -------- d-----w- c:\programdata\Norton
2011-01-02 15:59 . 2011-01-02 15:59 -------- d-----w- c:\windows\system32\Adobe
2010-12-30 09:59 . 2010-12-30 09:59 -------- d-----w- c:\programdata\Nokia
2010-12-30 09:42 . 2010-12-30 09:42 -------- d-----w- c:\users\Rado\AppData\Roaming\Nokia Ovi Suite
2010-12-28 09:51 . 2010-12-28 09:51 -------- d-----w- c:\users\Rado\AppData\Roaming\EleFun Games
2010-12-26 08:11 . 2010-12-30 09:42 -------- d-----w- c:\users\Rado\AppData\Roaming\Nokia
2010-12-26 08:10 . 2010-12-26 08:11 -------- d-----w- c:\users\Rado\AppData\Local\Nokia
2010-12-26 08:10 . 2010-12-26 08:10 -------- d-----w- c:\programdata\PC Suite
2010-12-26 08:09 . 2010-12-30 09:37 -------- d-----w- c:\users\Rado\AppData\Roaming\PC Suite
2010-12-26 08:09 . 2010-12-26 08:09 -------- d-----w- c:\program files\Common Files\Nokia
2010-12-26 08:08 . 2010-12-26 08:08 -------- d-----w- c:\program files\DIFX
2010-12-26 08:08 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-12-26 08:08 . 2010-12-26 08:08 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-26 08:08 . 2010-12-26 08:08 -------- d-----w- c:\program files\PC Connectivity Solution
2010-12-26 08:08 . 2010-02-26 13:32 92672 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-12-26 08:07 . 2010-12-26 08:08 -------- d-----w- c:\program files\Nokia
2010-12-25 11:22 . 2010-12-25 11:32 -------- d-----w- c:\program files\HDD Regenerator
2010-12-25 11:21 . 2010-12-25 11:21 -------- d-----w- c:\users\Rado\AppData\Local\Downloaded Installations
2010-12-25 08:53 . 2010-12-25 08:53 -------- d-----w- c:\users\Anulka
2010-12-25 08:36 . 2011-01-09 10:54 -------- d-----w- c:\users\Rado\AppData\Roaming\XnView
2010-12-25 08:35 . 2010-12-25 08:36 -------- d-----w- c:\program files\XnView
2010-12-25 08:28 . 2010-12-25 08:29 -------- d-----w- c:\program files\IrfanView
2010-12-25 08:11 . 2010-12-25 08:28 -------- d-----w- c:\users\Rado\AppData\Roaming\IrfanView
2010-12-25 08:03 . 2011-01-09 13:29 -------- d-----w- c:\program files\The KMPlayer
2010-12-23 18:26 . 2010-12-23 18:26 -------- d-----w- c:\users\Rado\AppData\Roaming\DeepVoyage
2010-12-23 18:16 . 2010-12-23 18:16 -------- d-----w- c:\users\Rado\AppData\Roaming\Nero
2010-12-23 18:15 . 2009-09-14 18:05 808240 ----a-w- c:\windows\system32\imagxra7.dll
2010-12-23 18:15 . 2009-09-14 18:05 374064 ----a-w- c:\windows\system32\twnlib4.dll
2010-12-23 18:15 . 2009-09-14 18:05 263472 ----a-w- c:\windows\system32\imagxr7.dll
2010-12-23 18:15 . 2009-09-14 18:05 1762608 ----a-w- c:\windows\system32\imagx7.dll
2010-12-23 18:15 . 2009-09-14 18:04 497296 ----a-r- c:\windows\system32\imagxpr7.dll
2010-12-23 18:15 . 2010-04-26 19:18 -------- d-----w- c:\program files\Nero
2010-12-23 18:15 . 2010-04-26 19:17 -------- d-----w- c:\program files\Common Files\Nero
2010-12-23 17:50 . 2010-01-17 16:18 151552 ----a-w- c:\windows\system32\ac3acm.acm
2010-12-23 17:50 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm
2010-12-23 17:50 . 2010-12-11 08:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-23 17:50 . 2010-12-07 18:40 183808 ----a-w- c:\windows\system32\xvidvfw.dll
2010-12-23 17:50 . 2010-12-07 18:22 810496 ----a-w- c:\windows\system32\xvidcore.dll
2010-12-23 17:50 . 2010-11-03 19:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2010-12-23 17:47 . 2010-12-23 17:47 -------- d-----w- c:\program files\Common Files\Adobe
2010-12-23 17:44 . 2010-12-23 17:44 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-12-23 17:44 . 2010-12-23 17:44 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-12-23 17:37 . 2010-12-23 17:37 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-12-23 17:37 . 2010-12-23 17:38 -------- d-----w- c:\program files\NVIDIA Corporation
2010-12-23 17:37 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-12-23 17:37 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-12-23 17:37 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-12-23 17:37 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-12-23 17:37 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-12-23 17:34 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21F76BB3-2983-424A-8677-9DEEFCC488B1}\mpengine.dll
2010-12-23 17:33 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-12-23 17:33 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-12-23 17:25 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-12-23 17:23 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-12-23 17:23 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-12-23 17:23 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-12-23 17:22 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-12-23 16:25 . 2008-12-23 17:49 286208 ----a-w- c:\windows\system32\drivers\netr61.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-02 04:39 . 2010-12-23 17:25 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34 . 2010-12-23 17:25 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-22 11:43 . 2010-10-22 11:43 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-22 11:43 . 2010-10-22 11:43 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-10-19 09:41 . 2010-02-07 09:48 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-09-11 2054360]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-11-09 7862816]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-11-26 5129128]
"Služba Acronis Scheduler2"="c:\program files\Common Files\Acronis\Plán2\schedhlp.exe" [2009-11-26 361976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
c:\users\Rado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registr cia věrobku.lnk - c:\program files\Common Files\Logishrd\eReg\SetPoint\eReg.exe [2008-11-7 517384]
Orez vaź obrazovky a spŁçśaź programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-7 813584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
R3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr61.sys [2008-12-23 286208]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-07 691696]
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [2010-02-08 911680]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-02-08 2480048]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-02-08 160288]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bleskovky.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Rado\AppData\Roaming\Mozilla\Firefox\Profiles\cxmelhp8.default\
FF - prefs.js: browser.startup.homepage - www.bleskovky.sk
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-MSWUpdate - c:\users\Rado\AppData\Roaming\lsass.exe
HKLM-Run-HDD Regenerator - c:\program files\HDD Regenerator\HDD Regenerator.exe
HKLM-Run-MSWUpdate - c:\users\Rado\AppData\Roaming\lsass.exe
AddRemove-NSS - c:\program files\Norton Security Scan\Engine\3.0.0.103\InstWrap.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-01-09 19:18:23
ComboFix-quarantined-files.txt 2011-01-09 18:18
Pre-Run: 15 018 172 416 bytes free
Post-Run: 15 308 914 688 bytes free
- - End Of File - - B5E03705E6ED2E0B7074AF65A32AF8D8

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o preventivku logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosim o preventivku logu
Zdravím, ComboFix není hračka kterou si můžeš spustit kdy chceš.
Ale co už se stalo.
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
Ale co už se stalo.
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
Kód: Vybrat vše
File::
c:\windows\system32\drivers\NSS
Folder::
c:\programdata\Norton
c:\Programdata\NortonInstaller
c:\programdata\Symantec
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
Re: Prosim o preventivku logu
Ešte objasním môj malý problém.Včera sa som mal taký problém ,že po prihlásení do win7 sa mi nezobrazila pracovná plocha,ale len čierna obrazovka s kurzorom.Cez správcu úloh som sa po zadaní príkazu "explorer"dostal do win7 a zistil som ,že z nejakého dôvodu bola vypnutá ochrana prístupu na web v EsetSS.Neviem prečo.Na vašej stránke som sa dočítal o RSIT a ComboFix-u.Tak som vyskúšal vytvoriť obidva logy.
Po vytvorení logu cez ComboFix a následného reštartu PC mi už Win7 nabehol normálne.Preto som Vás žiadal o kontrolu mojich logov,či sa mi do PC nemohli dostať nejake červy.Znepokojujú ma aj v správcovy úloh procesy,ktorých je dosť veľa celkom 49 procesov.
Teraz vám posielam Log ComboFix po prekopírovaní vašeho TXT súboru podľa návodu,ktorý ste mi poslali.Ďakujem za kontrolu.
ComboFix 11-01-08.05 - Rado . 01. 2011 22:22:06.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.2047.1333 [GMT 1:00]
Running from: c:\users\Rado\Desktop\ComboFix.exe
Command switches used :: c:\users\Rado\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
FILE ::
"c:\windows\system32\drivers\NSS"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Norton
c:\programdata\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}\LC.INI
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\isolate.ini
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Module9000.txt
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\Connections\connections.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\diMaster\eula.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\diMaster\service.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\itbLUReg\{65190544-26C3-43a4-A78A-694964901607}.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\itbLUReg\{6E3396BD-C6A6-4f0f-9254-267F9058FEC4}.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\itbLUReg\{D4F4CC32-7A41-4684-AE57-41E59E9B4503}.dat
c:\programdata\NortonInstaller
c:\programdata\NortonInstaller\Logs\2011-01-02-17h32m11s\Install.1.mft
c:\programdata\NortonInstaller\Logs\2011-01-02-17h32m11s\Install.2.mft
c:\programdata\NortonInstaller\Logs\2011-01-02-17h32m11s\NortonInstall-2011-01-02-17h32m11s.log
c:\programdata\NortonInstaller\Logs\Url.txt
c:\programdata\Symantec
.
((((((((((((((((((((((((( Files Created from 2010-12-10 to 2011-01-10 )))))))))))))))))))))))))))))))
.
2011-01-10 21:26 . 2011-01-10 21:26 -------- d-----w- c:\users\Rado\AppData\Local\temp
2011-01-10 21:26 . 2011-01-10 21:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-09 17:26 . 2011-01-09 17:26 -------- d-----w- C:\rsit
2011-01-09 17:26 . 2011-01-09 17:26 -------- d-----w- c:\program files\trend micro
2011-01-09 13:44 . 2011-01-09 13:44 368640 ----a-w- c:\program files\Mozilla Firefox\update.exe
2011-01-09 13:21 . 2011-01-09 13:21 -------- d-----w- c:\users\Rado\AppData\Local\ESET
2011-01-08 12:15 . 2001-08-28 15:00 5632 ----a-w- c:\windows\system32\CNMVS23.DLL
2011-01-08 12:15 . 2001-08-28 15:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP23.DLL
2011-01-08 12:15 . 2001-08-23 11:06 36864 ----a-w- c:\windows\system32\CNMCP23.EXE
2011-01-08 12:15 . 2011-01-08 12:15 -------- d-----w- C:\BJPrinter
2011-01-08 12:05 . 2001-08-28 15:00 94720 ----a-w- c:\windows\system32\CNMLM23.DLL
2011-01-08 12:05 . 2001-08-28 15:00 8192 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD23.DLL
2011-01-08 12:05 . 2011-01-08 12:05 -------- d-----w- C:\temp
2011-01-06 17:48 . 2011-01-06 17:48 -------- d-----w- c:\users\Rado\AppData\Local\FunnyMiners
2011-01-06 10:01 . 2011-01-06 10:01 -------- d-----w- c:\users\Rado\AppData\Roaming\Corel
2011-01-06 10:00 . 2011-01-06 10:00 -------- d-----w- c:\programdata\InstallShield
2011-01-06 10:00 . 2011-01-06 10:00 65536 ----a-r- c:\users\Rado\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
2011-01-06 09:59 . 2011-01-06 09:59 -------- d-----w- c:\program files\Corel
2011-01-06 09:59 . 2011-01-06 09:59 -------- d-----w- c:\program files\Common Files\Corel
2011-01-03 18:35 . 1998-10-29 23:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-01-03 13:09 . 2011-01-03 13:09 -------- d-----w- c:\program files\EDDICA
2011-01-02 16:32 . 2011-01-02 16:32 -------- d-----w- c:\windows\system32\drivers\NSS
2011-01-02 15:59 . 2011-01-02 15:59 -------- d-----w- c:\windows\system32\Adobe
2010-12-30 09:59 . 2010-12-30 09:59 -------- d-----w- c:\programdata\Nokia
2010-12-30 09:42 . 2010-12-30 09:42 -------- d-----w- c:\users\Rado\AppData\Roaming\Nokia Ovi Suite
2010-12-28 09:51 . 2010-12-28 09:51 -------- d-----w- c:\users\Rado\AppData\Roaming\EleFun Games
2010-12-26 08:11 . 2010-12-30 09:42 -------- d-----w- c:\users\Rado\AppData\Roaming\Nokia
2010-12-26 08:10 . 2010-12-26 08:11 -------- d-----w- c:\users\Rado\AppData\Local\Nokia
2010-12-26 08:10 . 2010-12-26 08:10 -------- d-----w- c:\programdata\PC Suite
2010-12-26 08:09 . 2010-12-30 09:37 -------- d-----w- c:\users\Rado\AppData\Roaming\PC Suite
2010-12-26 08:09 . 2010-12-26 08:09 -------- d-----w- c:\program files\Common Files\Nokia
2010-12-26 08:08 . 2010-12-26 08:08 -------- d-----w- c:\program files\DIFX
2010-12-26 08:08 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-12-26 08:08 . 2010-12-26 08:08 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-26 08:08 . 2010-12-26 08:08 -------- d-----w- c:\program files\PC Connectivity Solution
2010-12-26 08:08 . 2010-02-26 13:32 92672 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-12-26 08:07 . 2010-12-26 08:08 -------- d-----w- c:\program files\Nokia
2010-12-25 11:22 . 2010-12-25 11:32 -------- d-----w- c:\program files\HDD Regenerator
2010-12-25 11:21 . 2010-12-25 11:21 -------- d-----w- c:\users\Rado\AppData\Local\Downloaded Installations
2010-12-25 08:53 . 2010-12-25 08:53 -------- d-----w- c:\users\Anulka
2010-12-25 08:36 . 2011-01-10 18:06 -------- d-----w- c:\users\Rado\AppData\Roaming\XnView
2010-12-25 08:35 . 2010-12-25 08:36 -------- d-----w- c:\program files\XnView
2010-12-25 08:28 . 2010-12-25 08:29 -------- d-----w- c:\program files\IrfanView
2010-12-25 08:11 . 2010-12-25 08:28 -------- d-----w- c:\users\Rado\AppData\Roaming\IrfanView
2010-12-25 08:03 . 2011-01-09 13:29 -------- d-----w- c:\program files\The KMPlayer
2010-12-23 18:26 . 2010-12-23 18:26 -------- d-----w- c:\users\Rado\AppData\Roaming\DeepVoyage
2010-12-23 18:16 . 2010-12-23 18:16 -------- d-----w- c:\users\Rado\AppData\Roaming\Nero
2010-12-23 18:15 . 2009-09-14 18:05 808240 ----a-w- c:\windows\system32\imagxra7.dll
2010-12-23 18:15 . 2009-09-14 18:05 374064 ----a-w- c:\windows\system32\twnlib4.dll
2010-12-23 18:15 . 2009-09-14 18:05 263472 ----a-w- c:\windows\system32\imagxr7.dll
2010-12-23 18:15 . 2009-09-14 18:05 1762608 ----a-w- c:\windows\system32\imagx7.dll
2010-12-23 18:15 . 2009-09-14 18:04 497296 ----a-r- c:\windows\system32\imagxpr7.dll
2010-12-23 18:15 . 2010-04-26 19:18 -------- d-----w- c:\program files\Nero
2010-12-23 18:15 . 2010-04-26 19:17 -------- d-----w- c:\program files\Common Files\Nero
2010-12-23 17:50 . 2010-01-17 16:18 151552 ----a-w- c:\windows\system32\ac3acm.acm
2010-12-23 17:50 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm
2010-12-23 17:50 . 2010-12-11 08:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-23 17:50 . 2010-12-07 18:40 183808 ----a-w- c:\windows\system32\xvidvfw.dll
2010-12-23 17:50 . 2010-12-07 18:22 810496 ----a-w- c:\windows\system32\xvidcore.dll
2010-12-23 17:50 . 2010-11-03 19:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2010-12-23 17:47 . 2010-12-23 17:47 -------- d-----w- c:\program files\Common Files\Adobe
2010-12-23 17:44 . 2010-12-23 17:44 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-12-23 17:44 . 2010-12-23 17:44 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-12-23 17:37 . 2010-12-23 17:37 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-12-23 17:37 . 2010-12-23 17:38 -------- d-----w- c:\program files\NVIDIA Corporation
2010-12-23 17:37 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-12-23 17:37 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-12-23 17:37 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-12-23 17:37 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-12-23 17:37 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-12-23 17:34 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21F76BB3-2983-424A-8677-9DEEFCC488B1}\mpengine.dll
2010-12-23 17:33 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-12-23 17:33 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-12-23 17:25 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-12-23 17:23 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-12-23 17:23 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-12-23 17:23 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-12-23 17:22 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-12-23 16:25 . 2008-12-23 17:49 286208 ----a-w- c:\windows\system32\drivers\netr61.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-02 04:39 . 2010-12-23 17:25 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34 . 2010-12-23 17:25 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-22 11:43 . 2010-10-22 11:43 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-22 11:43 . 2010-10-22 11:43 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-10-19 09:41 . 2010-02-07 09:48 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-09-11 2054360]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-11-09 7862816]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-11-26 5129128]
"Služba Acronis Scheduler2"="c:\program files\Common Files\Acronis\Plán2\schedhlp.exe" [2009-11-26 361976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
c:\users\Rado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registr cia věrobku.lnk - c:\program files\Common Files\Logishrd\eReg\SetPoint\eReg.exe [2008-11-7 517384]
Orez vaź obrazovky a spŁçśaź programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-7 813584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
R3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr61.sys [2008-12-23 286208]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-07 691696]
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [2010-02-08 911680]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-02-08 2480048]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-02-08 160288]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bleskovky.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Rado\AppData\Roaming\Mozilla\Firefox\Profiles\cxmelhp8.default\
FF - prefs.js: browser.startup.homepage - www.bleskovky.sk
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
.
.
Completion time: 2011-01-10 22:28:03
ComboFix-quarantined-files.txt 2011-01-10 21:28
ComboFix2.txt 2011-01-09 18:18
Pre-Run: 15 494 922 240 bytes free
Post-Run: 15 375 335 424 bytes free
- - End Of File - - A733A324BAB5C2EC913D401E09E0C5D1
Po vytvorení logu cez ComboFix a následného reštartu PC mi už Win7 nabehol normálne.Preto som Vás žiadal o kontrolu mojich logov,či sa mi do PC nemohli dostať nejake červy.Znepokojujú ma aj v správcovy úloh procesy,ktorých je dosť veľa celkom 49 procesov.
Teraz vám posielam Log ComboFix po prekopírovaní vašeho TXT súboru podľa návodu,ktorý ste mi poslali.Ďakujem za kontrolu.
ComboFix 11-01-08.05 - Rado . 01. 2011 22:22:06.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.2047.1333 [GMT 1:00]
Running from: c:\users\Rado\Desktop\ComboFix.exe
Command switches used :: c:\users\Rado\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
FILE ::
"c:\windows\system32\drivers\NSS"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Norton
c:\programdata\Norton\{086A63F0-6B13-4F29-9695-134E7A01E963}\LC.INI
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\isolate.ini
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Module9000.txt
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\Connections\connections.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\diMaster\eula.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\diMaster\service.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\itbLUReg\{65190544-26C3-43a4-A78A-694964901607}.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\itbLUReg\{6E3396BD-C6A6-4f0f-9254-267F9058FEC4}.dat
c:\programdata\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS_3.0.0.103\itbLUReg\{D4F4CC32-7A41-4684-AE57-41E59E9B4503}.dat
c:\programdata\NortonInstaller
c:\programdata\NortonInstaller\Logs\2011-01-02-17h32m11s\Install.1.mft
c:\programdata\NortonInstaller\Logs\2011-01-02-17h32m11s\Install.2.mft
c:\programdata\NortonInstaller\Logs\2011-01-02-17h32m11s\NortonInstall-2011-01-02-17h32m11s.log
c:\programdata\NortonInstaller\Logs\Url.txt
c:\programdata\Symantec
.
((((((((((((((((((((((((( Files Created from 2010-12-10 to 2011-01-10 )))))))))))))))))))))))))))))))
.
2011-01-10 21:26 . 2011-01-10 21:26 -------- d-----w- c:\users\Rado\AppData\Local\temp
2011-01-10 21:26 . 2011-01-10 21:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-09 17:26 . 2011-01-09 17:26 -------- d-----w- C:\rsit
2011-01-09 17:26 . 2011-01-09 17:26 -------- d-----w- c:\program files\trend micro
2011-01-09 13:44 . 2011-01-09 13:44 368640 ----a-w- c:\program files\Mozilla Firefox\update.exe
2011-01-09 13:21 . 2011-01-09 13:21 -------- d-----w- c:\users\Rado\AppData\Local\ESET
2011-01-08 12:15 . 2001-08-28 15:00 5632 ----a-w- c:\windows\system32\CNMVS23.DLL
2011-01-08 12:15 . 2001-08-28 15:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP23.DLL
2011-01-08 12:15 . 2001-08-23 11:06 36864 ----a-w- c:\windows\system32\CNMCP23.EXE
2011-01-08 12:15 . 2011-01-08 12:15 -------- d-----w- C:\BJPrinter
2011-01-08 12:05 . 2001-08-28 15:00 94720 ----a-w- c:\windows\system32\CNMLM23.DLL
2011-01-08 12:05 . 2001-08-28 15:00 8192 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD23.DLL
2011-01-08 12:05 . 2011-01-08 12:05 -------- d-----w- C:\temp
2011-01-06 17:48 . 2011-01-06 17:48 -------- d-----w- c:\users\Rado\AppData\Local\FunnyMiners
2011-01-06 10:01 . 2011-01-06 10:01 -------- d-----w- c:\users\Rado\AppData\Roaming\Corel
2011-01-06 10:00 . 2011-01-06 10:00 -------- d-----w- c:\programdata\InstallShield
2011-01-06 10:00 . 2011-01-06 10:00 65536 ----a-r- c:\users\Rado\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
2011-01-06 09:59 . 2011-01-06 09:59 -------- d-----w- c:\program files\Corel
2011-01-06 09:59 . 2011-01-06 09:59 -------- d-----w- c:\program files\Common Files\Corel
2011-01-03 18:35 . 1998-10-29 23:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-01-03 13:09 . 2011-01-03 13:09 -------- d-----w- c:\program files\EDDICA
2011-01-02 16:32 . 2011-01-02 16:32 -------- d-----w- c:\windows\system32\drivers\NSS
2011-01-02 15:59 . 2011-01-02 15:59 -------- d-----w- c:\windows\system32\Adobe
2010-12-30 09:59 . 2010-12-30 09:59 -------- d-----w- c:\programdata\Nokia
2010-12-30 09:42 . 2010-12-30 09:42 -------- d-----w- c:\users\Rado\AppData\Roaming\Nokia Ovi Suite
2010-12-28 09:51 . 2010-12-28 09:51 -------- d-----w- c:\users\Rado\AppData\Roaming\EleFun Games
2010-12-26 08:11 . 2010-12-30 09:42 -------- d-----w- c:\users\Rado\AppData\Roaming\Nokia
2010-12-26 08:10 . 2010-12-26 08:11 -------- d-----w- c:\users\Rado\AppData\Local\Nokia
2010-12-26 08:10 . 2010-12-26 08:10 -------- d-----w- c:\programdata\PC Suite
2010-12-26 08:09 . 2010-12-30 09:37 -------- d-----w- c:\users\Rado\AppData\Roaming\PC Suite
2010-12-26 08:09 . 2010-12-26 08:09 -------- d-----w- c:\program files\Common Files\Nokia
2010-12-26 08:08 . 2010-12-26 08:08 -------- d-----w- c:\program files\DIFX
2010-12-26 08:08 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-12-26 08:08 . 2010-12-26 08:08 -------- dc----w- c:\windows\system32\DRVSTORE
2010-12-26 08:08 . 2010-12-26 08:08 -------- d-----w- c:\program files\PC Connectivity Solution
2010-12-26 08:08 . 2010-02-26 13:32 92672 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-12-26 08:07 . 2010-12-26 08:08 -------- d-----w- c:\program files\Nokia
2010-12-25 11:22 . 2010-12-25 11:32 -------- d-----w- c:\program files\HDD Regenerator
2010-12-25 11:21 . 2010-12-25 11:21 -------- d-----w- c:\users\Rado\AppData\Local\Downloaded Installations
2010-12-25 08:53 . 2010-12-25 08:53 -------- d-----w- c:\users\Anulka
2010-12-25 08:36 . 2011-01-10 18:06 -------- d-----w- c:\users\Rado\AppData\Roaming\XnView
2010-12-25 08:35 . 2010-12-25 08:36 -------- d-----w- c:\program files\XnView
2010-12-25 08:28 . 2010-12-25 08:29 -------- d-----w- c:\program files\IrfanView
2010-12-25 08:11 . 2010-12-25 08:28 -------- d-----w- c:\users\Rado\AppData\Roaming\IrfanView
2010-12-25 08:03 . 2011-01-09 13:29 -------- d-----w- c:\program files\The KMPlayer
2010-12-23 18:26 . 2010-12-23 18:26 -------- d-----w- c:\users\Rado\AppData\Roaming\DeepVoyage
2010-12-23 18:16 . 2010-12-23 18:16 -------- d-----w- c:\users\Rado\AppData\Roaming\Nero
2010-12-23 18:15 . 2009-09-14 18:05 808240 ----a-w- c:\windows\system32\imagxra7.dll
2010-12-23 18:15 . 2009-09-14 18:05 374064 ----a-w- c:\windows\system32\twnlib4.dll
2010-12-23 18:15 . 2009-09-14 18:05 263472 ----a-w- c:\windows\system32\imagxr7.dll
2010-12-23 18:15 . 2009-09-14 18:05 1762608 ----a-w- c:\windows\system32\imagx7.dll
2010-12-23 18:15 . 2009-09-14 18:04 497296 ----a-r- c:\windows\system32\imagxpr7.dll
2010-12-23 18:15 . 2010-04-26 19:18 -------- d-----w- c:\program files\Nero
2010-12-23 18:15 . 2010-04-26 19:17 -------- d-----w- c:\program files\Common Files\Nero
2010-12-23 17:50 . 2010-01-17 16:18 151552 ----a-w- c:\windows\system32\ac3acm.acm
2010-12-23 17:50 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm
2010-12-23 17:50 . 2010-12-11 08:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-23 17:50 . 2010-12-07 18:40 183808 ----a-w- c:\windows\system32\xvidvfw.dll
2010-12-23 17:50 . 2010-12-07 18:22 810496 ----a-w- c:\windows\system32\xvidcore.dll
2010-12-23 17:50 . 2010-11-03 19:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2010-12-23 17:47 . 2010-12-23 17:47 -------- d-----w- c:\program files\Common Files\Adobe
2010-12-23 17:44 . 2010-12-23 17:44 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-12-23 17:44 . 2010-12-23 17:44 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-12-23 17:37 . 2010-12-23 17:37 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-12-23 17:37 . 2010-12-23 17:38 -------- d-----w- c:\program files\NVIDIA Corporation
2010-12-23 17:37 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-12-23 17:37 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-12-23 17:37 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-12-23 17:37 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-12-23 17:37 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-12-23 17:34 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{21F76BB3-2983-424A-8677-9DEEFCC488B1}\mpengine.dll
2010-12-23 17:33 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-12-23 17:33 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-12-23 17:25 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-12-23 17:23 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-12-23 17:23 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-12-23 17:23 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-12-23 17:22 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-12-23 16:25 . 2008-12-23 17:49 286208 ----a-w- c:\windows\system32\drivers\netr61.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-02 04:39 . 2010-12-23 17:25 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34 . 2010-12-23 17:25 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-10-22 11:43 . 2010-10-22 11:43 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-22 11:43 . 2010-10-22 11:43 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-10-19 09:41 . 2010-02-07 09:48 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-09-11 2054360]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-11-09 7862816]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-11-26 5129128]
"Služba Acronis Scheduler2"="c:\program files\Common Files\Acronis\Plán2\schedhlp.exe" [2009-11-26 361976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
c:\users\Rado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Registr cia věrobku.lnk - c:\program files\Common Files\Logishrd\eReg\SetPoint\eReg.exe [2008-11-7 517384]
Orez vaź obrazovky a spŁçśaź programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-7 813584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
R3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr61.sys [2008-12-23 286208]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-07 691696]
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [2010-02-08 911680]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-09-11 108792]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-02-08 2480048]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-09-11 735960]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-09-11 38240]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-02-08 160288]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bleskovky.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Rado\AppData\Roaming\Mozilla\Firefox\Profiles\cxmelhp8.default\
FF - prefs.js: browser.startup.homepage - www.bleskovky.sk
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
.
.
Completion time: 2011-01-10 22:28:03
ComboFix-quarantined-files.txt 2011-01-10 21:28
ComboFix2.txt 2011-01-09 18:18
Pre-Run: 15 494 922 240 bytes free
Post-Run: 15 375 335 424 bytes free
- - End Of File - - A733A324BAB5C2EC913D401E09E0C5D1
Re: Prosim o preventivku logu
Dát sem log z Rsit je v pořádku ale ComboFix používat na vlastní pěst už tak v pohodě není.
Ani tu nikde nepíšeme že bys ho měl napoprvé použít sám.
Ale to je jedno už to řešit nebudeme.
Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Pak dej vědět jestli je s PC ještě problém.
Ani tu nikde nepíšeme že bys ho měl napoprvé použít sám.
Ale to je jedno už to řešit nebudeme.
Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Pak dej vědět jestli je s PC ještě problém.