Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu (miniaplikace)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Prosím o kontrolu logu (miniaplikace)

#1 Příspěvek od darkane »

Prosím o kontrolu logu. Včera mi eset nahlásil vir a uložil do karantény.
Dnes nejdou miniaplikace. Jinak se PC chová standartně. Už se zde takový problém řešil, ale .....
Proto moc prosím o kontrolu.


Logfile of random's system information tool 1.08 (written by random/random)
Run by darkane at 2011-02-17 19:02:38
Microsoft Windows 7 Professional
System drive C: has 67 GB (59%) free of 114 GB
Total RAM: 2048 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:03:03, on 17.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\darkane\Desktop\viry\RSIT.exe
C:\Program Files\trend micro\darkane.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooofullsearch.com/bar
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooofullsearch.com/bar
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://roonic.com/results.html?q=%s&sa= ... 0&ie=UTF-8
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbhelper.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: TBSB07458 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Free software Gooofull toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\flashget.exe /min
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" /S
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [CE8SIIFGSU] C:\Users\darkane\AppData\Local\Temp\Jgg.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Free software Gooofull toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll
O9 - Extra 'Tools' menuitem: Free software Gooofull toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\Windows\system32\dgdersvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 7994 bytes

======Scheduled tasks folder======

C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-14 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
TBSB07458 Class - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll [2010-06-18 2604032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]
{C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - Free software Gooofull toolbar - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll [2010-06-18 2604032]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-04-07 2145000]
"Flashget"=C:\Program Files\FlashGet\flashget.exe [2007-09-20 1994800]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"RivaTunerStartupDaemon"=C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe [2009-08-22 24576]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-04 336384]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2009-10-03 38768]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2009-10-02 640376]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"AtiTrayTools"=C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe [2010-12-09 928256]
"CE8SIIFGSU"=C:\Users\darkane\AppData\Local\Temp\Jgg.exe [2011-02-16 135680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2009-10-02 640376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2009-10-03 38768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\flashget.exe [2007-09-20 1994800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2010-10-27 3365176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\Windows\SOUNDMAN.EXE [2009-04-14 604704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-04 336384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TNOD UP]
C:\Program Files\TNod User & Password Finder\TNODUP.exe [2010-04-01 1811968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2010-12-08 74752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Hyalo-RAM_v3_by adni18.lnk]
E:\PROG\MINIAP~1\HYALO-~1.COM\HYALO-~1.EXE [2006-10-28 808960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registrace FIFA 11.lnk]
C:\PROGRA~1\EASPOR~1\FIFA11~1\Support\EAREGI~1.EXE [2010-09-23 4407808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-02-17 19:02:38 ----D---- C:\rsit
2011-02-17 19:02:38 ----D---- C:\Program Files\trend micro
2011-02-17 16:00:16 ----A---- C:\Windows\Jxikyb.exe
2011-02-16 23:18:16 ----A---- C:\Windows\Jxikya.exe
2011-02-15 08:04:13 ----D---- C:\Users\darkane\AppData\Roaming\PropMgrAsync
2011-02-15 08:04:13 ----D---- C:\Users\darkane\AppData\Roaming\PlayerPlug
2011-02-15 08:02:53 ----D---- C:\Program Files\CATraxx 9.02
2011-02-15 07:44:14 ----D---- C:\Program Files\CATraxx
2011-02-10 18:43:06 ----RA---- C:\Windows\system32\AdobePDFUI.dll
2011-02-10 18:43:06 ----RA---- C:\Windows\system32\AdobePDF.dll
2011-02-09 23:17:29 ----D---- C:\ProgramData\ATI
2011-02-09 23:13:26 ----D---- C:\Program Files\ATI Technologies
2011-02-09 23:13:19 ----D---- C:\Program Files\ATI
2011-02-09 16:33:03 ----D---- C:\ProgramData\Protexis
2011-02-09 16:32:49 ----D---- C:\Users\darkane\AppData\Roaming\Corel
2011-02-09 16:18:27 ----D---- C:\Program Files\Microsoft SDKs
2011-02-09 16:18:22 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2011-02-09 16:18:20 ----D---- C:\ProgramData\Microsoft Help
2011-02-09 16:15:13 ----D---- C:\Program Files\Common Files\Corel
2011-02-09 16:13:28 ----D---- C:\Program Files\Common Files\Protexis
2011-02-09 16:13:27 ----D---- C:\ProgramData\Corel
2011-02-09 16:05:59 ----D---- C:\Program Files\Corel
2011-02-09 15:08:29 ----D---- C:\Users\darkane\AppData\Roaming\atitray
2011-02-09 15:07:48 ----D---- C:\Program Files\Ray Adams
2011-02-09 10:46:36 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 10:46:31 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 10:46:27 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 10:46:25 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 10:46:19 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 10:45:44 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 10:45:40 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 10:45:40 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 10:45:38 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 10:45:37 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 10:45:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 10:45:37 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 10:45:36 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 10:45:36 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 10:45:27 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 10:45:27 ----A---- C:\Windows\system32\atmfd.dll
2011-02-09 10:45:19 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 10:45:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 10:45:11 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-02-09 10:44:59 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 10:44:51 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 10:44:49 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 10:44:48 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 10:44:45 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 10:44:39 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 10:44:37 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 10:44:37 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 10:44:36 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 10:44:36 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 10:44:36 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 10:44:35 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 10:44:30 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-04 12:30:06 ----D---- C:\Program Files\Rar Repair Tool
2011-01-31 18:11:17 ----D---- C:\Windows\system32\a moje icony
2011-01-26 07:09:56 ----D---- C:\Users\darkane\AppData\Roaming\foobar2000
2011-01-26 07:04:25 ----D---- C:\Program Files\foobar2000
2011-01-25 07:14:30 ----A---- C:\test.txt
2011-01-23 10:07:33 ----D---- C:\Users\darkane\AppData\Roaming\PgcEdit
2011-01-23 10:04:10 ----D---- C:\ProgramData\DVD Shrink
2011-01-23 10:04:09 ----D---- C:\Program Files\DVD Shrink
2011-01-22 22:42:44 ----N---- C:\Windows\Algouinstall.exe
2011-01-22 22:42:43 ----D---- C:\Program Files\Algorithmix
2011-01-22 14:28:32 ----D---- C:\Program Files\Zrychleni Pocitace
2011-01-22 14:28:21 ----D---- C:\Users\darkane\AppData\Roaming\OpenCandy
2011-01-22 14:28:19 ----D---- C:\Program Files\MediaInfo
2011-01-21 20:32:39 ----D---- C:\Convert

======List of files/folders modified in the last 1 months======

2011-02-17 19:03:03 ----D---- C:\Windows\Temp
2011-02-17 19:02:49 ----D---- C:\Windows\Prefetch
2011-02-17 19:02:38 ----RD---- C:\Program Files
2011-02-17 19:01:40 ----D---- C:\Windows\system32\config
2011-02-17 18:32:26 ----D---- C:\Windows\system32\Tasks
2011-02-17 18:32:19 ----D---- C:\Windows\Tasks
2011-02-17 16:00:16 ----D---- C:\Windows
2011-02-15 21:58:15 ----D---- C:\F2K
2011-02-15 19:22:33 ----AD---- C:\ProgramData\TEMP
2011-02-15 15:35:31 ----SD---- C:\Users\darkane\AppData\Roaming\Microsoft
2011-02-15 07:46:57 ----D---- C:\Windows\System32
2011-02-15 07:28:44 ----SHD---- C:\System Volume Information
2011-02-11 17:06:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-11 17:06:09 ----D---- C:\Windows\inf
2011-02-10 21:20:08 ----HD---- C:\ProgramData
2011-02-10 20:26:41 ----A---- C:\Windows\system32\everest_cpl.ini
2011-02-10 18:43:38 ----SHD---- C:\Windows\Installer
2011-02-10 18:43:24 ----D---- C:\Windows\system32\DriverStore
2011-02-10 18:39:45 ----D---- C:\Program Files\Common Files\Adobe
2011-02-10 07:47:16 ----D---- C:\Windows\system32\catroot2
2011-02-09 23:59:18 ----D---- C:\Program Files\SpeedFan
2011-02-09 23:15:10 ----D---- C:\Windows\system32\catroot
2011-02-09 23:15:02 ----D---- C:\Windows\system32\drivers
2011-02-09 23:08:19 ----D---- C:\Program Files\Common Files
2011-02-09 19:36:20 ----D---- C:\Windows\Microsoft.NET
2011-02-09 19:36:18 ----RSD---- C:\Windows\assembly
2011-02-09 18:49:55 ----D---- C:\Windows\winsxs
2011-02-09 18:48:17 ----D---- C:\Program Files\Internet Explorer
2011-02-09 16:41:44 ----A---- C:\Windows\system32\MRT.exe
2011-02-09 16:25:32 ----SD---- C:\ProgramData\Microsoft
2011-02-09 16:19:48 ----D---- C:\Program Files\Common Files\microsoft shared
2011-02-09 16:14:28 ----RSD---- C:\Windows\Fonts
2011-02-01 12:03:36 ----D---- C:\Windows\system32\NDF
2011-01-22 23:16:16 ----D---- C:\Downloads
2011-01-22 14:01:48 ----D---- C:\Program Files\Winamp
2011-01-22 14:01:27 ----D---- C:\Program Files\Winamp Detect

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-23 691696]
R1 atitray;atitray; \??\C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys [2010-10-30 19360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2010-10-09 142592]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-04-07 134488]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-04-07 41312]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-01-05 6789120]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-01-05 235520]
R3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [2010-10-25 18120]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-04-07 32584]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2010-07-26 36640]
R3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys [2009-08-22 9088]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-13 43008]
S3 a3id3oje;a3id3oje; C:\Windows\system32\drivers\a3id3oje.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-01-05 6789120]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\Windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\Windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\Windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM); C:\Windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-01-05 176128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 dgdersvc;Device Error Recovery Service; C:\Windows\system32\dgdersvc.exe [2010-10-25 95568]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-04-07 810120]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2010-05-28 233472]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-10-09 488960]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-08-21 72704]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-04-07 33560]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-26 651720]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-21 1343400]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]

-----------------EOF-----------------
Děkuji

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu (miniaplikace)

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

Vzhledem k tomu, ze pouzivate nelegalni SW Obrázek se nedivim, ze jste navstevnikem naseho fora :?:
Dle pravidel fora (viz zde a a zde bod c.3 ) se vsak nelegalnim SW nezabyvame, jelikoz nelegalni programy jsou vetsinou zdrojem haveti. Navic tim porusujete i autorska prava Obrázek, pachate trestny cin a ten jako takovy nebude nasim forem podporovan. Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora :!:
Obstarejte si proto legalni ochranu Vaseho PC (antivir), pote sem vlozte novy log z RSITu a CKScanneru - viz nize.

Osobne Vam doporucuji Avast nebo MSE. Prehled antiviru mate ZDE.

:arrow: Log z RSITu - viz muj podpis
:arrow: Stahnete na plochu CKScanner
  • Spustte a kliknete na Search for files
  • Po dokonceni skenu kliknete na Save List to File a nasledne OK
  • Na plose se Vam vytvori log s nazvem ckfiles.txt, jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu (miniaplikace)

#3 Příspěvek od darkane »

Dobrý večer
Předem se hlavně moc omlovám jak za formu mého příspěvku tak za porušení pravidel fóra.
Snažil jsem se o nápravu a polepšení. Přijměte ještě jednou moji omluvu.
Pokud to bude možné prosím o kontrolu.

Logfile of random's system information tool 1.08 (written by random/random)
Run by darkane at 2011-02-17 20:49:18
Microsoft Windows 7 Professional
System drive C: has 71 GB (62%) free of 114 GB
Total RAM: 2048 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:49:31, on 17.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Jxikyb.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\darkane\AppData\Local\Temp\Jgg.exe
C:\Users\darkane\Desktop\viry\RSIT.exe
C:\Program Files\trend micro\darkane.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooofullsearch.com/bar
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooofullsearch.com/bar
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://roonic.com/results.html?q=%s&sa= ... 0&ie=UTF-8
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbhelper.dll (file missing)
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: TBSB07458 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Free software Gooofull toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll (file missing)
O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\flashget.exe /min
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" /S
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [CE8SIIFGSU] C:\Users\darkane\AppData\Local\Temp\Jgg.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Stáhnout FlashGetem - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Free software Gooofull toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll (file missing)
O9 - Extra 'Tools' menuitem: Free software Gooofull toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\Windows\system32\dgdersvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 8061 bytes

======Scheduled tasks folder======

C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-09-14 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
TBSB07458 Class - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]
{C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - Free software Gooofull toolbar - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Flashget"=C:\Program Files\FlashGet\flashget.exe [2007-09-20 1994800]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"RivaTunerStartupDaemon"=C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe [2009-08-22 24576]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-04 336384]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2009-10-03 38768]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2009-10-02 640376]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
""= []
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"AtiTrayTools"=C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe [2010-12-09 928256]
"CE8SIIFGSU"=C:\Users\darkane\AppData\Local\Temp\Jgg.exe [2011-02-16 135680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2009-10-02 640376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2009-10-03 38768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\flashget.exe [2007-09-20 1994800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2010-10-27 3365176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\Windows\SOUNDMAN.EXE [2009-04-14 604704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-04 336384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TNOD UP]
C:\Program Files\TNod User & Password Finder\TNODUP.exe /i []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2010-12-08 74752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Hyalo-RAM_v3_by adni18.lnk]
E:\PROG\MINIAP~1\HYALO-~1.COM\HYALO-~1.EXE [2006-10-28 808960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registrace FIFA 11.lnk]
C:\PROGRA~1\EASPOR~1\FIFA11~1\Support\EAREGI~1.EXE [2010-09-23 4407808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-02-17 20:00:02 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-02-17 20:00:02 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-02-17 19:59:59 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-02-17 19:59:58 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-02-17 19:59:57 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-02-17 19:59:40 ----A---- C:\Windows\system32\aswBoot.exe
2011-02-17 19:59:36 ----D---- C:\ProgramData\Alwil Software
2011-02-17 19:59:36 ----D---- C:\Program Files\Alwil Software
2011-02-17 19:02:38 ----D---- C:\rsit
2011-02-17 19:02:38 ----D---- C:\Program Files\trend micro
2011-02-17 16:00:16 ----A---- C:\Windows\Jxikyb.exe
2011-02-16 23:18:16 ----A---- C:\Windows\Jxikya.exe
2011-02-15 08:04:13 ----D---- C:\Users\darkane\AppData\Roaming\PropMgrAsync
2011-02-15 08:04:13 ----D---- C:\Users\darkane\AppData\Roaming\PlayerPlug
2011-02-10 18:43:06 ----RA---- C:\Windows\system32\AdobePDFUI.dll
2011-02-10 18:43:06 ----RA---- C:\Windows\system32\AdobePDF.dll
2011-02-09 23:17:29 ----D---- C:\ProgramData\ATI
2011-02-09 23:13:26 ----D---- C:\Program Files\ATI Technologies
2011-02-09 23:13:19 ----D---- C:\Program Files\ATI
2011-02-09 16:33:03 ----D---- C:\ProgramData\Protexis
2011-02-09 16:32:49 ----D---- C:\Users\darkane\AppData\Roaming\Corel
2011-02-09 16:18:27 ----D---- C:\Program Files\Microsoft SDKs
2011-02-09 16:18:22 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2011-02-09 16:18:20 ----D---- C:\ProgramData\Microsoft Help
2011-02-09 16:13:28 ----D---- C:\Program Files\Common Files\Protexis
2011-02-09 16:13:27 ----D---- C:\ProgramData\Corel
2011-02-09 15:08:29 ----D---- C:\Users\darkane\AppData\Roaming\atitray
2011-02-09 15:07:48 ----D---- C:\Program Files\Ray Adams
2011-02-09 10:46:36 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 10:46:31 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 10:46:27 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 10:46:25 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 10:46:19 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 10:45:44 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 10:45:40 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 10:45:40 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 10:45:38 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 10:45:37 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 10:45:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 10:45:37 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 10:45:36 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 10:45:36 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 10:45:27 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 10:45:27 ----A---- C:\Windows\system32\atmfd.dll
2011-02-09 10:45:19 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 10:45:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 10:45:11 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-02-09 10:44:59 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 10:44:51 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 10:44:49 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 10:44:48 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 10:44:45 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 10:44:39 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 10:44:37 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 10:44:37 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 10:44:36 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 10:44:36 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 10:44:36 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 10:44:35 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 10:44:30 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-04 12:30:06 ----D---- C:\Program Files\Rar Repair Tool
2011-01-31 18:11:17 ----D---- C:\Windows\system32\a moje icony
2011-01-26 07:09:56 ----D---- C:\Users\darkane\AppData\Roaming\foobar2000
2011-01-26 07:04:25 ----D---- C:\Program Files\foobar2000
2011-01-25 07:14:30 ----A---- C:\test.txt
2011-01-23 10:07:33 ----D---- C:\Users\darkane\AppData\Roaming\PgcEdit
2011-01-23 10:04:10 ----D---- C:\ProgramData\DVD Shrink
2011-01-23 10:04:09 ----D---- C:\Program Files\DVD Shrink
2011-01-22 22:42:44 ----N---- C:\Windows\Algouinstall.exe
2011-01-22 22:42:43 ----D---- C:\Program Files\Algorithmix
2011-01-22 14:28:21 ----D---- C:\Users\darkane\AppData\Roaming\OpenCandy
2011-01-22 14:28:19 ----D---- C:\Program Files\MediaInfo
2011-01-21 20:32:39 ----D---- C:\Convert

======List of files/folders modified in the last 1 months======

2011-02-17 20:49:21 ----D---- C:\Windows\Temp
2011-02-17 20:47:05 ----D---- C:\Windows\Prefetch
2011-02-17 20:45:09 ----RD---- C:\Program Files
2011-02-17 20:41:03 ----D---- C:\Windows\system32\Tasks
2011-02-17 20:41:02 ----D---- C:\Windows\Tasks
2011-02-17 20:37:14 ----SHD---- C:\Windows\Installer
2011-02-17 20:37:13 ----D---- C:\Program Files\Common Files
2011-02-17 20:37:01 ----SHD---- C:\System Volume Information
2011-02-17 20:00:02 ----D---- C:\Windows\system32\drivers
2011-02-17 19:59:40 ----D---- C:\Windows\System32
2011-02-17 19:59:40 ----D---- C:\Windows
2011-02-17 19:59:36 ----HD---- C:\ProgramData
2011-02-17 19:55:50 ----D---- C:\Windows\system32\config
2011-02-17 19:55:26 ----D---- C:\Windows\system32\DriverStore
2011-02-17 19:55:26 ----D---- C:\Windows\system32\catroot
2011-02-17 19:55:26 ----D---- C:\Windows\inf
2011-02-15 21:58:15 ----D---- C:\F2K
2011-02-15 19:22:33 ----AD---- C:\ProgramData\TEMP
2011-02-15 15:35:31 ----SD---- C:\Users\darkane\AppData\Roaming\Microsoft
2011-02-11 17:06:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-02-10 20:26:41 ----A---- C:\Windows\system32\everest_cpl.ini
2011-02-10 18:39:45 ----D---- C:\Program Files\Common Files\Adobe
2011-02-10 07:47:16 ----D---- C:\Windows\system32\catroot2
2011-02-09 23:59:18 ----D---- C:\Program Files\SpeedFan
2011-02-09 19:36:20 ----D---- C:\Windows\Microsoft.NET
2011-02-09 19:36:18 ----RSD---- C:\Windows\assembly
2011-02-09 18:49:55 ----D---- C:\Windows\winsxs
2011-02-09 18:48:17 ----D---- C:\Program Files\Internet Explorer
2011-02-09 16:41:44 ----A---- C:\Windows\system32\MRT.exe
2011-02-09 16:25:32 ----SD---- C:\ProgramData\Microsoft
2011-02-09 16:19:48 ----D---- C:\Program Files\Common Files\microsoft shared
2011-02-09 16:14:28 ----RSD---- C:\Windows\Fonts
2011-02-01 12:03:36 ----D---- C:\Windows\system32\NDF
2011-01-22 23:16:16 ----D---- C:\Downloads
2011-01-22 14:01:48 ----D---- C:\Program Files\Winamp
2011-01-22 14:01:27 ----D---- C:\Program Files\Winamp Detect

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-23 691696]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-01-13 23632]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-01-13 294608]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-01-13 47440]
R1 atitray;atitray; \??\C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys [2010-10-30 19360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2010-10-09 142592]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-01-13 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-18 4172832]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-01-05 6789120]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-01-05 235520]
R3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [2010-10-25 18120]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2010-07-26 36640]
R3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys [2009-08-22 9088]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-13 43008]
S2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
S3 a8723ffj;a8723ffj; C:\Windows\system32\drivers\a8723ffj.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-01-05 6789120]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\Windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\Windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\Windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM); C:\Windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-01-05 176128]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 dgdersvc;Device Error Recovery Service; C:\Windows\system32\dgdersvc.exe [2010-10-25 95568]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2010-05-28 233472]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-10-09 488960]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-08-21 72704]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-26 651720]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-21 1343400]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]

-----------------EOF-----------------


CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----


Děkuji

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu (miniaplikace)

#4 Příspěvek od vyosek »

:arrow: Me se omlouvat nemusite, me Ceska ProtiPiratska unie spolu s PCR pripadne klepat na dvere nebude :?:

:arrow: Spustte HJT a provedeme fixnuti polozek
  • HJT najdete zde C:\Program Files\trend micro\darkane.exe
  • Otevre se Vam okno, kliknete na Do a system scan only
  • V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
  • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... p=aus&qkw=%s&tbid=60347
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooofullsearch.com/bar
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://gooofullsearch.com/bar
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://roonic.com/results.html?q=%s&sa= ... 0&ie=UTF-8
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\CATraxx 9.02\mybarnsaD80E.tmp\tbhelper.dll
  • Kliknete na Fix checked (vlevo dole)
  • HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo Obrázek
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu (miniaplikace)

#5 Příspěvek od darkane »

Fix v HJT jsem provedl
přikládám log Combofix

ComboFix 11-02-17.01 - darkane 17.02.2011 21:16:22.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2048.1357 [GMT 1:00]
Spuštěný z: c:\users\darkane\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\Desktop
C:\test.txt
c:\windows\system32\muzapp.exe
c:\windows\system32\system32
c:\windows\system32\system32\cis-2.4.dll
c:\windows\system32\system32\issacapi_bs-2.3.dll
c:\windows\system32\system32\issacapi_pe-2.3.dll
c:\windows\system32\system32\issacapi_se-2.3.dll
c:\windows\system32\system32\MACXMLProto.dll
c:\windows\system32\system32\MaDRM.dll
c:\windows\system32\system32\MaJGUILib.dll
c:\windows\system32\system32\MaJUtilLib.dll
c:\windows\system32\system32\MAMACExtract.dll
c:\windows\system32\system32\MASetupCaller.dll
c:\windows\system32\system32\MASetupCleaner.exe
c:\windows\system32\system32\MaXMLProto.dll
c:\windows\system32\system32\MetaStore2.dll
c:\windows\system32\system32\Microsoft.Synchronization.dll
c:\windows\system32\system32\MK_Lyric.dll
c:\windows\system32\system32\MSCLib.dll
c:\windows\system32\system32\MSFLib.dll
c:\windows\system32\system32\MSLUR71.dll
c:\windows\system32\system32\msvcp60.dll
c:\windows\system32\system32\MTTELECHIP.dll
c:\windows\system32\system32\MTXSYNCICON.dll
c:\windows\system32\system32\muzaf1.dll
c:\windows\system32\system32\muzapp.dll
c:\windows\system32\system32\muzapp.exe
c:\windows\system32\system32\muzdecode.ax
c:\windows\system32\system32\muzeffect.ax
c:\windows\system32\system32\muzmp4sp.ax
c:\windows\system32\system32\muzmpgsp.ax
c:\windows\system32\system32\muzoggsp.ax
c:\windows\system32\system32\muzwmts.dll
c:\windows\system32\system32\psapi.dll
c:\windows\system32\system32\Synchronization2.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-17 do 2011-02-17 )))))))))))))))))))))))))))))))
.

2011-02-17 20:27 . 2011-02-17 20:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-17 19:00 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-17 19:00 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-17 18:59 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-17 18:59 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-17 18:59 . 2011-01-13 08:37 51280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-17 18:59 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-17 18:59 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-17 18:59 . 2011-02-17 18:59 -------- d-----w- c:\programdata\Alwil Software
2011-02-17 18:59 . 2011-02-17 18:59 -------- d-----w- c:\program files\Alwil Software
2011-02-17 18:02 . 2011-02-17 20:10 -------- d-----w- c:\program files\trend micro
2011-02-17 18:02 . 2011-02-17 18:03 -------- d-----w- C:\rsit
2011-02-17 15:00 . 2011-02-16 22:20 136704 ----a-w- c:\windows\Jxikyb.exe
2011-02-16 22:18 . 2011-02-16 22:18 136704 ----a-w- c:\windows\Jxikya.exe
2011-02-15 07:04 . 2011-02-15 07:04 -------- d-----w- c:\users\darkane\AppData\Roaming\PropMgrAsync
2011-02-15 07:04 . 2011-02-15 07:04 -------- d-----w- c:\users\darkane\AppData\Roaming\PlayerPlug
2011-02-15 06:28 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{907B0562-E159-4D32-88AA-E783170CDC1E}\mpengine.dll
2011-02-10 17:43 . 2009-08-19 22:50 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2011-02-10 17:43 . 2009-08-19 22:50 46928 ----a-r- c:\windows\system32\AdobePDF.dll
2011-02-09 22:17 . 2011-02-09 22:17 -------- d-----w- c:\programdata\ATI
2011-02-09 22:13 . 2011-02-09 22:15 -------- d-----w- c:\program files\ATI Technologies
2011-02-09 22:13 . 2011-02-09 22:13 -------- d-----w- c:\program files\ATI
2011-02-09 15:33 . 2011-02-09 15:33 -------- d-----w- c:\programdata\Protexis
2011-02-09 15:32 . 2011-02-09 15:33 -------- d-----w- c:\users\darkane\AppData\Roaming\Corel
2011-02-09 15:24 . 2011-02-09 15:24 -------- d-----w- c:\users\darkane\AppData\Local\Microsoft Help
2011-02-09 15:18 . 2011-02-09 15:18 -------- d-----w- c:\program files\Microsoft SDKs
2011-02-09 15:18 . 2011-02-09 15:19 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-02-09 15:18 . 2011-02-09 15:30 -------- d-----w- c:\programdata\Microsoft Help
2011-02-09 15:13 . 2011-02-09 15:13 -------- d-----w- c:\program files\Common Files\Protexis
2011-02-09 15:13 . 2011-02-09 15:13 -------- d-----w- c:\programdata\Corel
2011-02-09 14:08 . 2011-02-09 14:08 -------- d-----w- c:\users\darkane\AppData\Roaming\atitray
2011-02-09 14:07 . 2011-02-09 14:07 -------- d-----w- c:\program files\Ray Adams
2011-02-09 09:46 . 2011-01-05 03:37 2329088 ----a-w- c:\windows\system32\win32k.sys
2011-02-09 09:46 . 2010-12-18 05:29 541184 ----a-w- c:\windows\system32\kerberos.dll
2011-02-09 09:46 . 2011-01-05 05:37 428032 ----a-w- c:\windows\system32\vbscript.dll
2011-02-09 09:44 . 2010-12-21 05:38 204288 ----a-w- c:\windows\system32\upnp.dll
2011-02-09 09:44 . 2010-12-21 05:36 1389568 ----a-w- c:\windows\system32\msxml6.dll
2011-02-09 09:44 . 2010-12-21 05:38 981504 ----a-w- c:\windows\system32\wininet.dll
2011-02-09 09:44 . 2010-12-21 05:36 1236992 ----a-w- c:\windows\system32\msxml3.dll
2011-02-09 09:44 . 2010-12-21 05:38 204800 ----a-w- c:\windows\system32\WebClnt.dll
2011-02-09 09:44 . 2010-12-21 05:34 80384 ----a-w- c:\windows\system32\davclnt.dll
2011-02-09 09:44 . 2010-12-21 05:38 51200 ----a-w- c:\windows\system32\wscapi.dll
2011-02-09 09:44 . 2010-12-21 05:38 350720 ----a-w- c:\windows\system32\winhttp.dll
2011-02-09 09:44 . 2010-12-21 05:38 14336 ----a-w- c:\windows\system32\slwga.dll
2011-02-09 09:44 . 2010-12-21 05:38 73728 ----a-w- c:\windows\system32\wscsvc.dll
2011-02-09 09:44 . 2011-02-03 05:45 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-04 11:30 . 2011-02-04 11:30 -------- d-----w- c:\program files\Rar Repair Tool
2011-01-31 17:11 . 2011-01-31 17:11 -------- d-----w- c:\windows\system32\a moje icony
2011-01-26 06:09 . 2011-02-16 22:09 -------- d-----w- c:\users\darkane\AppData\Roaming\foobar2000
2011-01-26 06:04 . 2011-01-26 17:04 -------- d-----w- c:\program files\foobar2000
2011-01-23 09:07 . 2011-01-23 09:10 -------- d-----w- c:\users\darkane\AppData\Roaming\PgcEdit
2011-01-23 09:04 . 2011-02-04 12:03 -------- d-----w- c:\programdata\DVD Shrink
2011-01-23 09:04 . 2011-01-23 09:04 -------- d-----w- c:\program files\DVD Shrink
2011-01-22 21:42 . 2009-02-02 16:50 36864 ------w- c:\windows\Algouinstall.exe
2011-01-22 21:42 . 2011-01-22 21:42 -------- d-----w- c:\program files\Algorithmix
2011-01-22 13:28 . 2011-02-09 14:08 -------- d-----w- c:\users\darkane\AppData\Local\OpenCandy
2011-01-22 13:28 . 2011-02-09 14:07 -------- d-----w- c:\users\darkane\AppData\Roaming\OpenCandy
2011-01-22 13:28 . 2011-01-22 13:28 -------- d-----w- c:\program files\MediaInfo
2011-01-21 19:32 . 2011-01-21 19:40 -------- d-----w- C:\Convert

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-05 03:36 . 2011-01-05 03:36 6789120 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-01-05 03:03 . 2011-01-05 03:03 17043968 ----a-w- c:\windows\system32\atioglxx.dll
2011-01-05 03:02 . 2011-01-05 03:02 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2011-01-05 03:02 . 2011-01-05 03:02 596480 ----a-w- c:\windows\system32\aticfx32.dll
2011-01-05 02:58 . 2011-01-05 02:58 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-01-05 02:58 . 2011-01-05 02:58 397312 ----a-w- c:\windows\system32\atieclxx.exe
2011-01-05 02:57 . 2011-01-05 02:57 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2011-01-05 02:56 . 2011-01-05 02:56 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2011-01-05 02:56 . 2011-01-05 02:56 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2011-01-05 02:55 . 2011-01-05 02:55 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2011-01-05 02:55 . 2011-01-05 02:55 15872 ----a-w- c:\windows\system32\atimuixx.dll
2011-01-05 02:55 . 2011-01-05 02:55 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-01-05 02:52 . 2011-01-05 02:52 4101632 ----a-w- c:\windows\system32\atidxx32.dll
2011-01-05 02:33 . 2011-01-05 02:33 46080 ----a-w- c:\windows\system32\aticalrt.dll
2011-01-05 02:33 . 2011-01-05 02:33 4162048 ----a-w- c:\windows\system32\atiumdag.dll
2011-01-05 02:33 . 2011-01-05 02:33 44032 ----a-w- c:\windows\system32\aticalcl.dll
2011-01-05 02:32 . 2011-01-05 02:32 1912832 ----a-w- c:\windows\system32\atiumdmv.dll
2011-01-05 02:31 . 2011-01-05 02:31 5441024 ----a-w- c:\windows\system32\aticaldd.dll
2011-01-05 02:28 . 2011-01-05 02:28 52736 ----a-w- c:\windows\system32\coinst.dll
2011-01-05 02:25 . 2011-01-05 02:25 3461120 ----a-w- c:\windows\system32\atiumdva.dll
2011-01-05 02:20 . 2011-01-05 02:20 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2011-01-05 02:19 . 2011-01-05 02:19 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-01-05 02:19 . 2011-01-05 02:19 27648 ----a-w- c:\windows\system32\atigktxx.dll
2011-01-05 02:19 . 2011-01-05 02:19 235520 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2011-01-05 02:18 . 2011-01-05 02:18 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2011-01-05 02:18 . 2011-01-05 02:18 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2011-01-05 02:17 . 2011-01-05 02:17 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-01-05 02:11 . 2011-01-05 02:11 52736 ----a-w- c:\windows\system32\atimpc32.dll
2011-01-05 02:11 . 2011-01-05 02:11 52736 ----a-w- c:\windows\system32\amdpcom32.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"AtiTrayTools"="c:\program files\Ray Adams\ATI Tray Tools\atitray.exe" [2010-12-09 928256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Flashget"="c:\program files\FlashGet\flashget.exe" [2007-09-20 1994800]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" [2009-08-22 24576]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-04 336384]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-10-03 38768]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-10-02 640376]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKLM\~\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Hyalo-RAM_v3_by adni18.lnk]
path=c:\users\darkane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hyalo-RAM_v3_by adni18.lnk
backup=c:\windows\pss\Hyalo-RAM_v3_by adni18.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registrace FIFA 11.lnk]
backup=c:\windows\pss\Registrace FIFA 11.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2009-10-02 22:32 640376 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2009-10-03 03:08 38768 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 02:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-07-22 21:10 402432 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
2007-09-20 07:21 1994800 ----a-w- c:\program files\FlashGet\flashget.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2010-10-27 10:36 3365176 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2009-04-14 05:43 604704 ----a-w- c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2011-01-04 20:47 336384 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 12:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-12-08 20:42 74752 ----a-w- c:\program files\Winamp\winampa.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-21 1343400]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-23 691696]
S1 aswSP;aswSP; [x]
S1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [2010-10-30 19360]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-10-09 142592]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-01-05 176128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2010-10-25 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-05-28 233472]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-01-05 6789120]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-01-05 235520]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 18120]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-07-26 36640]


--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - FSUSBEXDISK
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
IE: &Stáhnout &vše FlashGetem - c:\program files\FlashGet\jc_all.htm
IE: &Stáhnout FlashGetem - c:\program files\FlashGet\jc_link.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - c:\program files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll
FF - ProfilePath - c:\users\darkane\AppData\Roaming\Mozilla\Firefox\Profiles\7ujvm1ki.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.gooofullsearch.com/google?cx=partne ... 8&hl=es&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Noia 2.0 eXtreme OPT: noia2_option@kk.noia - %profile%\extensions\noia2_option@kk.noia
FF - Ext: Noia 2.0 (eXtreme): {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} - %profile%\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
FF - Ext: 20-20 3D Viewer: 2020Player@2020Technologies.com - %profile%\extensions\2020Player@2020Technologies.com
FF - Ext: Seznam lištička: {ea614400-e918-4741-9a97-7a972ff7c30b} - %profile%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF - Ext: FireGestures: firegestures@xuldev.org - %profile%\extensions\firegestures@xuldev.org
FF - Ext: Google Translator for Firefox: translator@zoli.bod - %profile%\extensions\translator@zoli.bod
FF - Ext: Flagfox: {1018e4d6-728f-4b20-ad56-37578a4de76b} - %profile%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

Toolbar-{C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - c:\program files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll
WebBrowser-{C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - c:\program files\CATraxx 9.02\mybarnsaD80E.tmp\tbcore3.dll
MSConfigStartUp-TNOD UP - c:\program files\TNod User & Password Finder\TNODUP.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-3893000050-1894367474-777983228-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-3893000050-1894367474-777983228-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8D75F4B1-9833-C512-79E8-F21985E96245}*]
"mahifmafmabigjmkeohepmdngg"=hex:6f,61,67,6b,66,6a,69,69,65,6e,6c,66,6b,6f,63,
65,65,6d,65,65,6e,69,66,6c,6f,6a,67,70,6f,67,00,00
"abgiinjmadkbfkokdkdfhhnoongmfcggdi"=hex:69,61,62,6a,65,65,67,68,62,68,68,61,
6a,68,66,6c,67,69,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-02-17 21:32:08
ComboFix-quarantined-files.txt 2011-02-17 20:32

Před spuštěním: Volných bajtů: 74 369 748 992
Po spuštění: Volných bajtů: 73 891 725 312

- - End Of File - - 47CA061289C050D7D484EB660E68631A

Děkuji

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu (miniaplikace)

#6 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    File::
    c:\windows\Jxikyb.exe
    c:\windows\Jxikya.exe
    C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
    C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    
    RegLock::
    [HKEY_USERS\S-1-5-21-3893000050-1894367474-777983228-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    [HKEY_USERS\S-1-5-21-3893000050-1894367474-777983228-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8D75F4B1-9833-C512-79E8-F21985E96245}*]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    RegLockDel::
    [HKEY_USERS\S-1-5-21-3893000050-1894367474-777983228-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8D75F4B1-9833-C512-79E8-F21985E96245}*]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-3893000050-1894367474-777983228-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8D75F4B1-9833-C512-79E8-F21985E96245}*]
    
    Firefox::
    FF - ProfilePath - c:\users\darkane\AppData\Roaming\Mozilla\Firefox\Profiles\7ujvm1ki.default\
    FF - prefs.js: keyword.URL - hxxp://www.gooofullsearch.com/google?cx ... 8&hl=es&q=
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    [-HKLM\~\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registrace FIFA 11.lnk]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Acrobat Speed Launcher"=-
    "Acrobat Assistant 8.0"=-
    "Adobe ARM"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu (miniaplikace)

#7 Příspěvek od darkane »

Přidávám další log Combofixu


ComboFix 11-02-17.01 - darkane 17.02.2011 21:58:47.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2048.1432 [GMT 1:00]
Spuštěný z: c:\users\darkane\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\darkane\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FILE ::
"c:\windows\Jxikya.exe"
"c:\windows\Jxikyb.exe"
"c:\windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job"
"c:\windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Jxikya.exe
c:\windows\Jxikyb.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-17 do 2011-02-17 )))))))))))))))))))))))))))))))
.

2011-02-17 19:00 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-17 19:00 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-17 18:59 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-17 18:59 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-17 18:59 . 2011-01-13 08:37 51280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-17 18:59 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-02-17 18:59 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-17 18:59 . 2011-02-17 18:59 -------- d-----w- c:\programdata\Alwil Software
2011-02-17 18:59 . 2011-02-17 18:59 -------- d-----w- c:\program files\Alwil Software
2011-02-17 18:02 . 2011-02-17 20:40 -------- d-----w- c:\program files\trend micro
2011-02-17 18:02 . 2011-02-17 18:03 -------- d-----w- C:\rsit
2011-02-15 07:04 . 2011-02-15 07:04 -------- d-----w- c:\users\darkane\AppData\Roaming\PropMgrAsync
2011-02-15 07:04 . 2011-02-15 07:04 -------- d-----w- c:\users\darkane\AppData\Roaming\PlayerPlug
2011-02-15 06:28 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{907B0562-E159-4D32-88AA-E783170CDC1E}\mpengine.dll
2011-02-10 17:43 . 2009-08-19 22:50 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2011-02-10 17:43 . 2009-08-19 22:50 46928 ----a-r- c:\windows\system32\AdobePDF.dll
2011-02-09 22:17 . 2011-02-09 22:17 -------- d-----w- c:\programdata\ATI
2011-02-09 22:13 . 2011-02-09 22:15 -------- d-----w- c:\program files\ATI Technologies
2011-02-09 22:13 . 2011-02-09 22:13 -------- d-----w- c:\program files\ATI
2011-02-09 15:33 . 2011-02-09 15:33 -------- d-----w- c:\programdata\Protexis
2011-02-09 15:32 . 2011-02-09 15:33 -------- d-----w- c:\users\darkane\AppData\Roaming\Corel
2011-02-09 15:24 . 2011-02-09 15:24 -------- d-----w- c:\users\darkane\AppData\Local\Microsoft Help
2011-02-09 15:18 . 2011-02-09 15:18 -------- d-----w- c:\program files\Microsoft SDKs
2011-02-09 15:18 . 2011-02-09 15:19 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-02-09 15:18 . 2011-02-09 15:30 -------- d-----w- c:\programdata\Microsoft Help
2011-02-09 15:13 . 2011-02-09 15:13 -------- d-----w- c:\program files\Common Files\Protexis
2011-02-09 15:13 . 2011-02-09 15:13 -------- d-----w- c:\programdata\Corel
2011-02-09 14:08 . 2011-02-09 14:08 -------- d-----w- c:\users\darkane\AppData\Roaming\atitray
2011-02-09 14:07 . 2011-02-09 14:07 -------- d-----w- c:\program files\Ray Adams
2011-02-09 09:46 . 2011-01-05 03:37 2329088 ----a-w- c:\windows\system32\win32k.sys
2011-02-09 09:46 . 2010-12-18 05:29 541184 ----a-w- c:\windows\system32\kerberos.dll
2011-02-09 09:46 . 2011-01-05 05:37 428032 ----a-w- c:\windows\system32\vbscript.dll
2011-02-09 09:44 . 2010-12-21 05:38 204288 ----a-w- c:\windows\system32\upnp.dll
2011-02-09 09:44 . 2010-12-21 05:36 1389568 ----a-w- c:\windows\system32\msxml6.dll
2011-02-09 09:44 . 2010-12-21 05:38 981504 ----a-w- c:\windows\system32\wininet.dll
2011-02-09 09:44 . 2010-12-21 05:36 1236992 ----a-w- c:\windows\system32\msxml3.dll
2011-02-09 09:44 . 2010-12-21 05:38 204800 ----a-w- c:\windows\system32\WebClnt.dll
2011-02-09 09:44 . 2010-12-21 05:34 80384 ----a-w- c:\windows\system32\davclnt.dll
2011-02-09 09:44 . 2010-12-21 05:38 51200 ----a-w- c:\windows\system32\wscapi.dll
2011-02-09 09:44 . 2010-12-21 05:38 350720 ----a-w- c:\windows\system32\winhttp.dll
2011-02-09 09:44 . 2010-12-21 05:38 14336 ----a-w- c:\windows\system32\slwga.dll
2011-02-09 09:44 . 2010-12-21 05:38 73728 ----a-w- c:\windows\system32\wscsvc.dll
2011-02-09 09:44 . 2011-02-03 05:45 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-04 11:30 . 2011-02-04 11:30 -------- d-----w- c:\program files\Rar Repair Tool
2011-01-31 17:11 . 2011-01-31 17:11 -------- d-----w- c:\windows\system32\a moje icony
2011-01-26 06:09 . 2011-02-16 22:09 -------- d-----w- c:\users\darkane\AppData\Roaming\foobar2000
2011-01-26 06:04 . 2011-01-26 17:04 -------- d-----w- c:\program files\foobar2000
2011-01-23 09:07 . 2011-01-23 09:10 -------- d-----w- c:\users\darkane\AppData\Roaming\PgcEdit
2011-01-23 09:04 . 2011-02-04 12:03 -------- d-----w- c:\programdata\DVD Shrink
2011-01-23 09:04 . 2011-01-23 09:04 -------- d-----w- c:\program files\DVD Shrink
2011-01-22 21:42 . 2009-02-02 16:50 36864 ------w- c:\windows\Algouinstall.exe
2011-01-22 21:42 . 2011-01-22 21:42 -------- d-----w- c:\program files\Algorithmix
2011-01-22 13:28 . 2011-02-09 14:08 -------- d-----w- c:\users\darkane\AppData\Local\OpenCandy
2011-01-22 13:28 . 2011-02-09 14:07 -------- d-----w- c:\users\darkane\AppData\Roaming\OpenCandy
2011-01-22 13:28 . 2011-01-22 13:28 -------- d-----w- c:\program files\MediaInfo
2011-01-21 19:32 . 2011-01-21 19:40 -------- d-----w- C:\Convert

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-05 03:36 . 2011-01-05 03:36 6789120 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-01-05 03:03 . 2011-01-05 03:03 17043968 ----a-w- c:\windows\system32\atioglxx.dll
2011-01-05 03:02 . 2011-01-05 03:02 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2011-01-05 03:02 . 2011-01-05 03:02 596480 ----a-w- c:\windows\system32\aticfx32.dll
2011-01-05 02:58 . 2011-01-05 02:58 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-01-05 02:58 . 2011-01-05 02:58 397312 ----a-w- c:\windows\system32\atieclxx.exe
2011-01-05 02:57 . 2011-01-05 02:57 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2011-01-05 02:56 . 2011-01-05 02:56 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2011-01-05 02:56 . 2011-01-05 02:56 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2011-01-05 02:55 . 2011-01-05 02:55 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2011-01-05 02:55 . 2011-01-05 02:55 15872 ----a-w- c:\windows\system32\atimuixx.dll
2011-01-05 02:55 . 2011-01-05 02:55 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-01-05 02:52 . 2011-01-05 02:52 4101632 ----a-w- c:\windows\system32\atidxx32.dll
2011-01-05 02:33 . 2011-01-05 02:33 46080 ----a-w- c:\windows\system32\aticalrt.dll
2011-01-05 02:33 . 2011-01-05 02:33 4162048 ----a-w- c:\windows\system32\atiumdag.dll
2011-01-05 02:33 . 2011-01-05 02:33 44032 ----a-w- c:\windows\system32\aticalcl.dll
2011-01-05 02:32 . 2011-01-05 02:32 1912832 ----a-w- c:\windows\system32\atiumdmv.dll
2011-01-05 02:31 . 2011-01-05 02:31 5441024 ----a-w- c:\windows\system32\aticaldd.dll
2011-01-05 02:28 . 2011-01-05 02:28 52736 ----a-w- c:\windows\system32\coinst.dll
2011-01-05 02:25 . 2011-01-05 02:25 3461120 ----a-w- c:\windows\system32\atiumdva.dll
2011-01-05 02:20 . 2011-01-05 02:20 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2011-01-05 02:19 . 2011-01-05 02:19 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-01-05 02:19 . 2011-01-05 02:19 27648 ----a-w- c:\windows\system32\atigktxx.dll
2011-01-05 02:19 . 2011-01-05 02:19 235520 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2011-01-05 02:18 . 2011-01-05 02:18 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2011-01-05 02:18 . 2011-01-05 02:18 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2011-01-05 02:17 . 2011-01-05 02:17 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-01-05 02:11 . 2011-01-05 02:11 52736 ----a-w- c:\windows\system32\atimpc32.dll
2011-01-05 02:11 . 2011-01-05 02:11 52736 ----a-w- c:\windows\system32\amdpcom32.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"AtiTrayTools"="c:\program files\Ray Adams\ATI Tray Tools\atitray.exe" [2010-12-09 928256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Flashget"="c:\program files\FlashGet\flashget.exe" [2007-09-20 1994800]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTunerWrapper.exe" [2009-08-22 24576]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-04 336384]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKLM\~\startupfolder\C:^Users^darkane^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Hyalo-RAM_v3_by adni18.lnk]
path=c:\users\darkane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hyalo-RAM_v3_by adni18.lnk
backup=c:\windows\pss\Hyalo-RAM_v3_by adni18.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
2007-09-20 07:21 1994800 ----a-w- c:\program files\FlashGet\flashget.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2010-10-27 10:36 3365176 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2009-04-14 05:43 604704 ----a-w- c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2011-01-04 20:47 336384 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
R3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM);c:\windows\system32\DRIVERS\ssceserd.sys [2010-04-27 100352]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-21 1343400]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-23 691696]
S1 aswSP;aswSP; [x]
S1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [2010-10-30 19360]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-10-09 142592]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-01-05 176128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2010-10-25 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-05-28 233472]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-01-05 6789120]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-01-05 235520]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2010-10-25 18120]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-07-26 36640]

.
.
------- Doplňkový sken -------
.
IE: &Stáhnout &vše FlashGetem - c:\program files\FlashGet\jc_all.htm
IE: &Stáhnout FlashGetem - c:\program files\FlashGet\jc_link.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\users\darkane\AppData\Roaming\Mozilla\Firefox\Profiles\7ujvm1ki.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Noia 2.0 eXtreme OPT: noia2_option@kk.noia - %profile%\extensions\noia2_option@kk.noia
FF - Ext: Noia 2.0 (eXtreme): {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} - %profile%\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
FF - Ext: 20-20 3D Viewer: 2020Player@2020Technologies.com - %profile%\extensions\2020Player@2020Technologies.com
FF - Ext: Seznam lištička: {ea614400-e918-4741-9a97-7a972ff7c30b} - %profile%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF - Ext: FireGestures: firegestures@xuldev.org - %profile%\extensions\firegestures@xuldev.org
FF - Ext: Google Translator for Firefox: translator@zoli.bod - %profile%\extensions\translator@zoli.bod
FF - Ext: Flagfox: {1018e4d6-728f-4b20-ad56-37578a4de76b} - %profile%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'Explorer.exe'(2024)
c:\program files\Ray Adams\ATI Tray Tools\raphook.dll
c:\program files\FlashGet\fgmgr.dll
c:\windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2011-02-17 22:22:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-17 21:22
ComboFix2.txt 2011-02-17 20:32

Před spuštěním: Volných bajtů: 74 011 987 968
Po spuštění: Volných bajtů: 73 946 423 296

- - End Of File - - A41F9AEA1170C9D68E5FC643DFF5AB28

Děkuji

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu (miniaplikace)

#8 Příspěvek od vyosek »

Jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu (miniaplikace)

#9 Příspěvek od darkane »

Po krátkém ozkoušení, se PC chová dobře, miniaplikace fungují standartně.
Jinak jsem nespozoroval nic zvlášního. Pokud je vše OK, tak
mockrát děkuji za Vaši skvělou práci a strávený čas.
:clapping: :clapping: :clapping:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu (miniaplikace)

#10 Příspěvek od vyosek »

Jeste uklidime a dam Vam pokoj :D

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /Uninstall
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: A pokud nejsou problemy ci dotazy ze to z me strany vse
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu (miniaplikace)

#11 Příspěvek od darkane »

Pročištěno vše OK
DĚKUJI

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu (miniaplikace)

#12 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :) Zase nekdy Obrázek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět