Hijackthis - nelze odstranit!
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: Hijackthis - nelze odstranit!
Psal ComboFix neco o tom ze pripravuje log
Pripadne je ulozen v c:\combodix.txt
Pokud ne, tam mi zabalte celou slozku c:\qoobox a uploadnete mi ji sem http://vyosek.ic.cz/havet/uploader.php
-
VitHerrmann
- Návštěvník

- Příspěvky: 20
- Registrován: 07 Ún 2011 20:19
Re: Hijackthis - nelze odstranit!
do dupy ,ta složka mi neje zabalit!!!
mě s toho picne!
combofix nepsal nic
mě s toho picne!
combofix nepsal nic
Re: Hijackthis - nelze odstranit!
-
VitHerrmann
- Návštěvník

- Příspěvky: 20
- Registrován: 07 Ún 2011 20:19
Re: Hijackthis - nelze odstranit!
2011-02-08 04:36:40 . 2011-02-08 04:36:40 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440}.reg.dat
2011-02-08 04:33:26 . 2011-02-08 04:33:26 5,891 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-02-08 04:27:51 . 2011-02-08 04:27:51 51 ----a-w- C:\Qoobox\Quarantine\catchme.log
2011-02-08 04:33:26 . 2011-02-08 04:33:26 5,891 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-02-08 04:27:51 . 2011-02-08 04:27:51 51 ----a-w- C:\Qoobox\Quarantine\catchme.log
Re: Hijackthis - nelze odstranit!
Zkuste ComboFix aplikovat jeste jednou v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)
-
VitHerrmann
- Návštěvník

- Příspěvky: 20
- Registrován: 07 Ún 2011 20:19
Re: Hijackthis - nelze odstranit!
Zkusil jsem vytvořit nový text combofixu, tady je obsah!
ComboFix 11-02-07.02 - Vít 08.02.2011 14:09:30.2.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.4091.1114 [GMT 1:00]
Spuštěný z: c:\users\Vít\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-08 do 2011-02-08 )))))))))))))))))))))))))))))))
.
2011-02-08 13:16 . 2011-02-08 13:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-08 11:28 . 2011-01-13 08:37 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-08 11:28 . 2011-01-13 08:41 273488 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-08 11:28 . 2011-01-13 08:37 29264 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-08 11:28 . 2011-01-13 08:40 51792 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-08 11:28 . 2011-01-13 08:47 237168 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-08 11:28 . 2011-01-13 08:37 62032 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-08 11:28 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-08 11:28 . 2011-01-13 08:47 188216 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-02-08 11:28 . 2011-02-08 11:28 -------- d-----w- c:\programdata\Alwil Software
2011-02-08 11:28 . 2011-02-08 11:28 -------- d-----w- c:\program files\Alwil Software
2011-02-07 19:09 . 2011-02-08 10:36 -------- d-----w- c:\program files\trend micro
2011-02-07 19:09 . 2011-02-07 19:09 -------- d-----w- C:\rsit
2011-02-06 06:04 . 2011-02-06 11:29 -------- d-----w- c:\program files (x86)\DAEMON Tools Toolbar
2011-02-04 05:50 . 2011-01-13 10:20 7844688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{46DEC575-5947-4470-BB16-9E168ECB8EF7}\mpengine.dll
2011-01-28 14:01 . 2011-01-28 14:03 -------- d-----w- c:\users\Vít\AppData\Roaming\GHISLER
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKZIP.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2011-01-27 14:17 . 2011-01-27 14:18 -------- d-----w- c:\program files (x86)\Common Files\Ahead
2011-01-27 14:17 . 2011-01-27 14:17 -------- d-----w- c:\program files (x86)\Nero
2011-01-26 20:00 . 2011-01-26 20:00 -------- d-----w- c:\users\Vít\AppData\Local\Nero_AG
2011-01-26 15:25 . 2011-01-26 15:25 -------- d-----w- c:\users\Vít\AppData\Roaming\Nero
2011-01-26 15:17 . 2011-01-27 14:17 -------- d-----w- c:\programdata\Nero
2011-01-26 15:13 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
2011-01-26 15:13 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2011-01-26 15:12 . 2008-10-15 05:22 4379984 ----a-w- c:\windows\SysWow64\D3DX9_40.dll
2011-01-26 15:12 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\SysWow64\d3dx9_35.dll
2011-01-26 15:12 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\SysWow64\d3dx9_34.dll
2011-01-18 14:33 . 2011-01-18 14:33 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-01-12 07:30 . 2010-11-02 04:35 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-01-11 07:58 . 2009-04-02 17:12 1354240 ----a-w- c:\windows\system32\CNQ2413C.DLL
2011-01-11 07:58 . 2009-04-02 17:12 92672 ----a-w- c:\windows\system32\CNQ2413I.DLL
2011-01-11 07:58 . 2008-05-02 08:14 677888 ----a-w- c:\windows\system32\CNQ2413L.DLL
2011-01-11 07:58 . 2007-03-15 13:13 229888 ----a-w- c:\windows\system32\CNQ2413O.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-05 20:51 . 2011-01-05 20:51 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-01-05 20:51 . 2011-01-05 20:51 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-12-12 19:04 . 2010-12-12 19:04 99384 ----a-w- c:\users\Vít\AppData\Roaming\inst.exe
2010-12-12 19:04 . 2010-12-12 19:04 99384 ----a-w- c:\users\Vít\AppData\Roaming\inst.exe
2010-12-12 19:04 . 2010-12-12 19:04 82816 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-12-12 19:04 . 2010-12-12 19:04 82816 ----a-w- c:\users\Vít\AppData\Roaming\pcouffin.sys
2010-12-12 19:04 . 2010-12-12 19:04 82816 ----a-w- c:\users\Vít\AppData\Roaming\pcouffin.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-02-08_04.35.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2011-02-08 12:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-02-06 07:40 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-02-08 12:41 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-02-06 07:40 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-02-06 07:40 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-02-08 12:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-12 15:25 . 2011-02-08 12:42 27674 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-02-08 12:42 36304 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2011-01-11 07:59 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-02-08 11:25 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-12 15:16 . 2011-02-08 12:42 7078 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-230198825-3932402014-1349866741-1001_UserData.bin
- 2011-02-08 04:19 . 2011-02-08 04:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-02-08 12:40 . 2011-02-08 12:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-02-08 04:19 . 2011-02-08 04:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-02-08 12:40 . 2011-02-08 12:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2011-02-08 04:23 616008 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-02-08 12:45 616008 c:\windows\system32\perfh009.dat
- 2009-07-14 15:18 . 2011-02-08 04:23 631292 c:\windows\system32\perfh005.dat
+ 2009-07-14 15:18 . 2011-02-08 12:45 631292 c:\windows\system32\perfh005.dat
- 2009-07-14 02:36 . 2011-02-08 04:23 106388 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-02-08 12:45 106388 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2011-02-08 12:45 121914 c:\windows\system32\perfc005.dat
- 2009-07-14 15:18 . 2011-02-08 04:23 121914 c:\windows\system32\perfc005.dat
- 2009-07-14 05:30 . 2011-01-11 07:59 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-02-08 11:25 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-01-11 07:58 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2011-02-08 11:25 143360 c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:01 . 2011-02-07 19:33 387144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-02-08 12:39 387144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:34 . 2011-02-08 04:30 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-02-08 12:54 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Easy-PrintToolBox"="c:\program files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 136176]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-12 1255736]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSP;aswSP; [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 203264]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2mdx64.sys [2008-04-15 62040]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
.
Obsah adresáře 'Naplánované úlohy'
2011-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 04:39]
2011-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 04:39]
.
--------- x86-64 -----------
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint - Náhled - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint - Přidat na seznam k tisku - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint - Tisk - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Easy-WebPrint - Vysokorychlostní tisk - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
FF - ProfilePath - c:\users\Vít\AppData\Roaming\Mozilla\Firefox\Profiles\7yvz5r5x.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-02-08 14:23:27
ComboFix-quarantined-files.txt 2011-02-08 13:23
Před spuštěním: Volných bajtů: 37 011 783 680
Po spuštění: Volných bajtů: 36 830 244 864
- - End Of File - - E243103B8FDFD31B169AE314E8D98895
ComboFix 11-02-07.02 - Vít 08.02.2011 14:09:30.2.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.4091.1114 [GMT 1:00]
Spuštěný z: c:\users\Vít\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-08 do 2011-02-08 )))))))))))))))))))))))))))))))
.
2011-02-08 13:16 . 2011-02-08 13:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-08 11:28 . 2011-01-13 08:37 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-08 11:28 . 2011-01-13 08:41 273488 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-08 11:28 . 2011-01-13 08:37 29264 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-08 11:28 . 2011-01-13 08:40 51792 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-08 11:28 . 2011-01-13 08:47 237168 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-08 11:28 . 2011-01-13 08:37 62032 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-08 11:28 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-08 11:28 . 2011-01-13 08:47 188216 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-02-08 11:28 . 2011-02-08 11:28 -------- d-----w- c:\programdata\Alwil Software
2011-02-08 11:28 . 2011-02-08 11:28 -------- d-----w- c:\program files\Alwil Software
2011-02-07 19:09 . 2011-02-08 10:36 -------- d-----w- c:\program files\trend micro
2011-02-07 19:09 . 2011-02-07 19:09 -------- d-----w- C:\rsit
2011-02-06 06:04 . 2011-02-06 11:29 -------- d-----w- c:\program files (x86)\DAEMON Tools Toolbar
2011-02-04 05:50 . 2011-01-13 10:20 7844688 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{46DEC575-5947-4470-BB16-9E168ECB8EF7}\mpengine.dll
2011-01-28 14:01 . 2011-01-28 14:03 -------- d-----w- c:\users\Vít\AppData\Roaming\GHISLER
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKZIP.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2011-01-28 14:01 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2011-01-27 14:17 . 2011-01-27 14:18 -------- d-----w- c:\program files (x86)\Common Files\Ahead
2011-01-27 14:17 . 2011-01-27 14:17 -------- d-----w- c:\program files (x86)\Nero
2011-01-26 20:00 . 2011-01-26 20:00 -------- d-----w- c:\users\Vít\AppData\Local\Nero_AG
2011-01-26 15:25 . 2011-01-26 15:25 -------- d-----w- c:\users\Vít\AppData\Roaming\Nero
2011-01-26 15:17 . 2011-01-27 14:17 -------- d-----w- c:\programdata\Nero
2011-01-26 15:13 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\SysWow64\D3DCompiler_42.dll
2011-01-26 15:13 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll
2011-01-26 15:12 . 2008-10-15 05:22 4379984 ----a-w- c:\windows\SysWow64\D3DX9_40.dll
2011-01-26 15:12 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\SysWow64\d3dx9_35.dll
2011-01-26 15:12 . 2007-05-16 15:45 3497832 ----a-w- c:\windows\SysWow64\d3dx9_34.dll
2011-01-18 14:33 . 2011-01-18 14:33 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-01-12 07:30 . 2010-11-02 04:35 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-01-11 07:58 . 2009-04-02 17:12 1354240 ----a-w- c:\windows\system32\CNQ2413C.DLL
2011-01-11 07:58 . 2009-04-02 17:12 92672 ----a-w- c:\windows\system32\CNQ2413I.DLL
2011-01-11 07:58 . 2008-05-02 08:14 677888 ----a-w- c:\windows\system32\CNQ2413L.DLL
2011-01-11 07:58 . 2007-03-15 13:13 229888 ----a-w- c:\windows\system32\CNQ2413O.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-05 20:51 . 2011-01-05 20:51 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-01-05 20:51 . 2011-01-05 20:51 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-12-12 19:04 . 2010-12-12 19:04 99384 ----a-w- c:\users\Vít\AppData\Roaming\inst.exe
2010-12-12 19:04 . 2010-12-12 19:04 99384 ----a-w- c:\users\Vít\AppData\Roaming\inst.exe
2010-12-12 19:04 . 2010-12-12 19:04 82816 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-12-12 19:04 . 2010-12-12 19:04 82816 ----a-w- c:\users\Vít\AppData\Roaming\pcouffin.sys
2010-12-12 19:04 . 2010-12-12 19:04 82816 ----a-w- c:\users\Vít\AppData\Roaming\pcouffin.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-02-08_04.35.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2011-02-08 12:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-02-06 07:40 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-02-08 12:41 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-02-06 07:40 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-02-06 07:40 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-02-08 12:41 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-12 15:25 . 2011-02-08 12:42 27674 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-02-08 12:42 36304 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:30 . 2011-01-11 07:59 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2009-07-14 05:30 . 2011-02-08 11:25 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-12 15:17 . 2011-02-08 12:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-12 15:17 . 2011-02-08 04:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-12 15:16 . 2011-02-08 12:42 7078 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-230198825-3932402014-1349866741-1001_UserData.bin
- 2011-02-08 04:19 . 2011-02-08 04:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-02-08 12:40 . 2011-02-08 12:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-02-08 04:19 . 2011-02-08 04:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-02-08 12:40 . 2011-02-08 12:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:36 . 2011-02-08 04:23 616008 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-02-08 12:45 616008 c:\windows\system32\perfh009.dat
- 2009-07-14 15:18 . 2011-02-08 04:23 631292 c:\windows\system32\perfh005.dat
+ 2009-07-14 15:18 . 2011-02-08 12:45 631292 c:\windows\system32\perfh005.dat
- 2009-07-14 02:36 . 2011-02-08 04:23 106388 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2011-02-08 12:45 106388 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2011-02-08 12:45 121914 c:\windows\system32\perfc005.dat
- 2009-07-14 15:18 . 2011-02-08 04:23 121914 c:\windows\system32\perfc005.dat
- 2009-07-14 05:30 . 2011-01-11 07:59 143360 c:\windows\system32\DriverStore\infstrng.dat
+ 2009-07-14 05:30 . 2011-02-08 11:25 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2011-01-11 07:58 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2011-02-08 11:25 143360 c:\windows\system32\DriverStore\infstor.dat
- 2009-07-14 05:01 . 2011-02-07 19:33 387144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-02-08 12:39 387144 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:34 . 2011-02-08 04:30 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-02-08 12:54 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Easy-PrintToolBox"="c:\program files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 136176]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-12 1255736]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSP;aswSP; [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 203264]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2mdx64.sys [2008-04-15 62040]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
.
Obsah adresáře 'Naplánované úlohy'
2011-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 04:39]
2011-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 04:39]
.
--------- x86-64 -----------
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint - Náhled - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint - Přidat na seznam k tisku - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint - Tisk - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Easy-WebPrint - Vysokorychlostní tisk - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
FF - ProfilePath - c:\users\Vít\AppData\Roaming\Mozilla\Firefox\Profiles\7yvz5r5x.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-02-08 14:23:27
ComboFix-quarantined-files.txt 2011-02-08 13:23
Před spuštěním: Volných bajtů: 37 011 783 680
Po spuštění: Volných bajtů: 36 830 244 864
- - End Of File - - E243103B8FDFD31B169AE314E8D98895
Naposledy upravil(a) VitHerrmann dne 08 Ún 2011 14:30, celkem upraveno 1 x.
Re: Hijackthis - nelze odstranit!
Odstrante to prosim z toho code, spatne se to cte a boli z toho oci...
Re: Hijackthis - nelze odstranit!
Log jiz vypada cisty, jak se chova PC 
-
VitHerrmann
- Návštěvník

- Příspěvky: 20
- Registrován: 07 Ún 2011 20:19
Re: Hijackthis - nelze odstranit!
Komp se chová stejně ,procesor je pořád na 52 proc. zatížení!!!
Re: Hijackthis - nelze odstranit!
- Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
- Napiste ComboFix /Uninstall
- Stisknete Enter
- Tohle smaze Combofix a jeho slozky
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
-
VitHerrmann
- Návštěvník

- Příspěvky: 20
- Registrován: 07 Ún 2011 20:19
Re: Hijackthis - nelze odstranit!
využití procesoru je pořád stejné!!!
Logfile of random's system information tool 1.08 (written by random/random)
Run by Vít at 2011-02-08 15:06:00
Microsoft Windows 7 Professional
System drive C: has 35 GB (60%) free of 59 GB
Total RAM: 4091 MB (16% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:06:12, on 8.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Vít.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2233703
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7468 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {739B060E-5DEE-4117-8975-FC8FC5F164E2}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3440.72edd60.191294173 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 3440 plugin \\.\pipe\gecko-crash-server-pipe.3440
"C:\Users\Vít\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-09-27 1250696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Easy-PrintToolBox"=C:\Program Files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2004-01-14 409600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-02-08 15:06:00 ----D---- C:\rsit
2011-02-08 15:00:57 ----D---- C:\Program Files (x86)\CCleaner
2011-02-08 14:18:23 ----SHD---- C:\$RECYCLE.BIN
2011-02-08 12:28:48 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-02-08 12:28:47 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-02-08 12:28:43 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-02-08 12:28:41 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-02-08 12:28:38 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-02-08 12:28:38 ----A---- C:\Windows\system32\aswBoot.exe
2011-02-08 12:28:28 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-02-08 12:28:25 ----D---- C:\ProgramData\Alwil Software
2011-02-08 12:28:25 ----D---- C:\Program Files\Alwil Software
2011-02-08 05:34:58 ----D---- C:\Windows\temp
2011-02-08 05:27:51 ----D---- C:\Windows\ERDNT
2011-02-07 20:09:11 ----D---- C:\Program Files\trend micro
2011-02-06 07:04:28 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2011-01-28 15:01:16 ----D---- C:\Users\Vít\AppData\Roaming\GHISLER
2011-01-28 15:01:16 ----A---- C:\Windows\UC.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\RAR.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\PKZIP.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\PKUNZIP.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\NOCLOSE.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\LHA.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\ARJ.PIF
2011-01-27 15:17:00 ----D---- C:\Program Files (x86)\Nero
2011-01-26 16:25:18 ----D---- C:\Users\Vít\AppData\Roaming\Nero
2011-01-26 16:17:40 ----D---- C:\ProgramData\Nero
2011-01-26 16:13:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-01-26 16:13:04 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-01-26 16:12:49 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-01-26 16:12:33 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-01-26 16:12:14 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-01-12 08:31:06 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 08:31:05 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-01-12 08:31:05 ----A---- C:\Windows\system32\d2d1.dll
2011-01-12 08:31:04 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-01-12 08:31:04 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-12 08:31:04 ----A---- C:\Windows\system32\DWrite.dll
2011-01-12 08:31:03 ----A---- C:\Windows\system32\mf.dll
2011-01-12 08:31:02 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-01-12 08:31:02 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-12 08:31:02 ----A---- C:\Windows\system32\FntCache.dll
2011-01-12 08:31:01 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-01-12 08:31:01 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-01-12 08:31:01 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-12 08:31:00 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-01-12 08:31:00 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 08:31:00 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-12 08:31:00 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 08:30:59 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-01-12 08:30:59 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-01-12 08:30:59 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-01-12 08:30:59 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-12 08:30:58 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-01-12 08:30:58 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-01-12 08:30:58 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-01-12 08:30:58 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 08:30:58 ----A---- C:\Windows\system32\mfps.dll
2011-01-12 08:30:58 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-12 08:30:58 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 08:30:57 ----A---- C:\Windows\system32\cdd.dll
2011-01-12 08:30:47 ----A---- C:\Windows\system32\odbc32.dll
2011-01-12 08:30:46 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413O.DLL
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413L.DLL
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413I.DLL
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413C.DLL
======List of files/folders modified in the last 1 months======
2011-02-08 15:04:06 ----D---- C:\Windows
2011-02-08 15:02:00 ----D---- C:\Users\Vít\AppData\Roaming\Media Player Classic
2011-02-08 15:01:53 ----D---- C:\Windows\debug
2011-02-08 15:00:57 ----RD---- C:\Program Files (x86)
2011-02-08 15:00:50 ----D---- C:\Windows\System32
2011-02-08 15:00:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-08 14:59:14 ----D---- C:\Windows\system32\config
2011-02-08 14:17:03 ----A---- C:\Windows\system.ini
2011-02-08 14:12:56 ----D---- C:\Windows\SYSWOW64\drivers
2011-02-08 14:12:56 ----D---- C:\Windows\SysWOW64
2011-02-08 14:12:56 ----D---- C:\Windows\system32\drivers
2011-02-08 14:12:56 ----D---- C:\Windows\AppPatch
2011-02-08 14:12:50 ----D---- C:\Program Files\Common Files
2011-02-08 14:12:50 ----D---- C:\Program Files (x86)\Common Files
2011-02-08 13:45:08 ----D---- C:\Windows\inf
2011-02-08 13:15:30 ----RD---- C:\Program Files
2011-02-08 13:15:04 ----SHD---- C:\Windows\Installer
2011-02-08 13:15:00 ----D---- C:\Windows\system32\Tasks
2011-02-08 13:14:33 ----SHD---- C:\System Volume Information
2011-02-08 12:53:44 ----D---- C:\Program Files (x86)\DsNET Corp
2011-02-08 12:28:25 ----D---- C:\ProgramData
2011-02-08 12:25:35 ----D---- C:\Windows\system32\DriverStore
2011-02-08 12:25:35 ----D---- C:\Windows\system32\catroot
2011-02-08 12:24:23 ----D---- C:\Program Files (x86)\EurotelSMS
2011-02-08 11:59:24 ----D---- C:\Windows\system32\catroot2
2011-02-08 11:58:44 ----D---- C:\Program Files (x86)\Foxit Software
2011-02-08 09:22:15 ----D---- C:\Users\Vít\AppData\Roaming\Vso
2011-02-07 11:21:35 ----D---- C:\Windows\Prefetch
2011-02-06 19:50:07 ----D---- C:\Users\Vít\AppData\Roaming\Skype
2011-02-06 19:40:08 ----D---- C:\Users\Vít\AppData\Roaming\skypePM
2011-02-06 12:24:05 ----D---- C:\Users\Vít\AppData\Roaming\DAEMON Tools Lite
2011-02-06 07:02:45 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-01-27 15:18:17 ----D---- C:\Windows\ehome
2011-01-26 21:08:32 ----D---- C:\Windows\winsxs
2011-01-26 16:13:44 ----RSD---- C:\Windows\assembly
2011-01-26 16:11:48 ----D---- C:\Windows\Logs
2011-01-12 10:48:52 ----A---- C:\Windows\system32\MRT.exe
2011-01-11 08:59:21 ----RSD---- C:\Windows\Media
2011-01-11 08:58:32 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2011-01-11 08:58:32 ----D---- C:\Windows\twain_32
2011-01-11 08:58:13 ----HD---- C:\Program Files\CanonBJ
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-06 513080]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-01-13 29264]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-01-13 273488]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-01-13 51792]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-01-13 20560]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 6037504]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2mdx64.sys [2008-04-15 62040]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-12-12 82816]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 109056]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 203264]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2007-12-10 353280]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-12 1255736]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Vít at 2011-02-08 15:06:00
Microsoft Windows 7 Professional
System drive C: has 35 GB (60%) free of 59 GB
Total RAM: 4091 MB (16% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:06:12, on 8.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Vít.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2233703
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7468 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {739B060E-5DEE-4117-8975-FC8FC5F164E2}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3440.72edd60.191294173 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 3440 plugin \\.\pipe\gecko-crash-server-pipe.3440
"C:\Users\Vít\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files (x86)\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-09-27 1250696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files (x86)\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Easy-PrintToolBox"=C:\Program Files (x86)\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2004-01-14 409600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 290304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-02-08 15:06:00 ----D---- C:\rsit
2011-02-08 15:00:57 ----D---- C:\Program Files (x86)\CCleaner
2011-02-08 14:18:23 ----SHD---- C:\$RECYCLE.BIN
2011-02-08 12:28:48 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-02-08 12:28:47 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-02-08 12:28:43 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-02-08 12:28:41 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-02-08 12:28:38 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-02-08 12:28:38 ----A---- C:\Windows\system32\aswBoot.exe
2011-02-08 12:28:28 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-02-08 12:28:25 ----D---- C:\ProgramData\Alwil Software
2011-02-08 12:28:25 ----D---- C:\Program Files\Alwil Software
2011-02-08 05:34:58 ----D---- C:\Windows\temp
2011-02-08 05:27:51 ----D---- C:\Windows\ERDNT
2011-02-07 20:09:11 ----D---- C:\Program Files\trend micro
2011-02-06 07:04:28 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2011-01-28 15:01:16 ----D---- C:\Users\Vít\AppData\Roaming\GHISLER
2011-01-28 15:01:16 ----A---- C:\Windows\UC.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\RAR.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\PKZIP.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\PKUNZIP.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\NOCLOSE.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\LHA.PIF
2011-01-28 15:01:16 ----A---- C:\Windows\ARJ.PIF
2011-01-27 15:17:00 ----D---- C:\Program Files (x86)\Nero
2011-01-26 16:25:18 ----D---- C:\Users\Vít\AppData\Roaming\Nero
2011-01-26 16:17:40 ----D---- C:\ProgramData\Nero
2011-01-26 16:13:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-01-26 16:13:04 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-01-26 16:12:49 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-01-26 16:12:33 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-01-26 16:12:14 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-01-12 08:31:06 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 08:31:05 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-01-12 08:31:05 ----A---- C:\Windows\system32\d2d1.dll
2011-01-12 08:31:04 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-01-12 08:31:04 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-12 08:31:04 ----A---- C:\Windows\system32\DWrite.dll
2011-01-12 08:31:03 ----A---- C:\Windows\system32\mf.dll
2011-01-12 08:31:02 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-01-12 08:31:02 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-12 08:31:02 ----A---- C:\Windows\system32\FntCache.dll
2011-01-12 08:31:01 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-01-12 08:31:01 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-01-12 08:31:01 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-12 08:31:00 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-01-12 08:31:00 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 08:31:00 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-12 08:31:00 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 08:30:59 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-01-12 08:30:59 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-01-12 08:30:59 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-01-12 08:30:59 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-12 08:30:58 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-01-12 08:30:58 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-01-12 08:30:58 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-01-12 08:30:58 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 08:30:58 ----A---- C:\Windows\system32\mfps.dll
2011-01-12 08:30:58 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-12 08:30:58 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 08:30:57 ----A---- C:\Windows\system32\cdd.dll
2011-01-12 08:30:47 ----A---- C:\Windows\system32\odbc32.dll
2011-01-12 08:30:46 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413O.DLL
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413L.DLL
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413I.DLL
2011-01-11 08:58:13 ----A---- C:\Windows\system32\CNQ2413C.DLL
======List of files/folders modified in the last 1 months======
2011-02-08 15:04:06 ----D---- C:\Windows
2011-02-08 15:02:00 ----D---- C:\Users\Vít\AppData\Roaming\Media Player Classic
2011-02-08 15:01:53 ----D---- C:\Windows\debug
2011-02-08 15:00:57 ----RD---- C:\Program Files (x86)
2011-02-08 15:00:50 ----D---- C:\Windows\System32
2011-02-08 15:00:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-08 14:59:14 ----D---- C:\Windows\system32\config
2011-02-08 14:17:03 ----A---- C:\Windows\system.ini
2011-02-08 14:12:56 ----D---- C:\Windows\SYSWOW64\drivers
2011-02-08 14:12:56 ----D---- C:\Windows\SysWOW64
2011-02-08 14:12:56 ----D---- C:\Windows\system32\drivers
2011-02-08 14:12:56 ----D---- C:\Windows\AppPatch
2011-02-08 14:12:50 ----D---- C:\Program Files\Common Files
2011-02-08 14:12:50 ----D---- C:\Program Files (x86)\Common Files
2011-02-08 13:45:08 ----D---- C:\Windows\inf
2011-02-08 13:15:30 ----RD---- C:\Program Files
2011-02-08 13:15:04 ----SHD---- C:\Windows\Installer
2011-02-08 13:15:00 ----D---- C:\Windows\system32\Tasks
2011-02-08 13:14:33 ----SHD---- C:\System Volume Information
2011-02-08 12:53:44 ----D---- C:\Program Files (x86)\DsNET Corp
2011-02-08 12:28:25 ----D---- C:\ProgramData
2011-02-08 12:25:35 ----D---- C:\Windows\system32\DriverStore
2011-02-08 12:25:35 ----D---- C:\Windows\system32\catroot
2011-02-08 12:24:23 ----D---- C:\Program Files (x86)\EurotelSMS
2011-02-08 11:59:24 ----D---- C:\Windows\system32\catroot2
2011-02-08 11:58:44 ----D---- C:\Program Files (x86)\Foxit Software
2011-02-08 09:22:15 ----D---- C:\Users\Vít\AppData\Roaming\Vso
2011-02-07 11:21:35 ----D---- C:\Windows\Prefetch
2011-02-06 19:50:07 ----D---- C:\Users\Vít\AppData\Roaming\Skype
2011-02-06 19:40:08 ----D---- C:\Users\Vít\AppData\Roaming\skypePM
2011-02-06 12:24:05 ----D---- C:\Users\Vít\AppData\Roaming\DAEMON Tools Lite
2011-02-06 07:02:45 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-01-27 15:18:17 ----D---- C:\Windows\ehome
2011-01-26 21:08:32 ----D---- C:\Windows\winsxs
2011-01-26 16:13:44 ----RSD---- C:\Windows\assembly
2011-01-26 16:11:48 ----D---- C:\Windows\Logs
2011-01-12 10:48:52 ----A---- C:\Windows\system32\MRT.exe
2011-01-11 08:59:21 ----RSD---- C:\Windows\Media
2011-01-11 08:58:32 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2011-01-11 08:58:32 ----D---- C:\Windows\twain_32
2011-01-11 08:58:13 ----HD---- C:\Program Files\CanonBJ
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-06 513080]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-01-13 29264]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-01-13 273488]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-01-13 51792]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-01-13 20560]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 6037504]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2mdx64.sys [2008-04-15 62040]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-12-12 82816]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 109056]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 203264]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-13 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2007-12-10 353280]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-12 1255736]
-----------------EOF-----------------
Re: Hijackthis - nelze odstranit!
- Provedte aktualizaci - treti zalozka
- Provedte uplny sken - nic nemazte

- MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
-
VitHerrmann
- Návštěvník

- Příspěvky: 20
- Registrován: 07 Ún 2011 20:19
Re: Hijackthis - nelze odstranit!
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verze databáze: 5711
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
8.2.2011 15:46:21
mbam-log-2011-02-08 (15-46-21).txt
Typ kontroly: Úplný test (C:\|D:\|)
Testované objekty: 240286
Uplynulý čas: 30 minut, 4 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
www.malwarebytes.org
Verze databáze: 5711
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
8.2.2011 15:46:21
mbam-log-2011-02-08 (15-46-21).txt
Typ kontroly: Úplný test (C:\|D:\|)
Testované objekty: 240286
Uplynulý čas: 30 minut, 4 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Re: Hijackthis - nelze odstranit!
Je ve spravci uloh videt ktery proces jej vytezuje nejvice 
-
VitHerrmann
- Návštěvník

- Příspěvky: 20
- Registrován: 07 Ún 2011 20:19
Re: Hijackthis - nelze odstranit!
wmpnetwk.exe Netvork Service - 50 proc
a
nečíné procesy systém! - 30 proc
a
nečíné procesy systém! - 30 proc


Přispějete na provoz fóra?