vypadky internetu a zvuku
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
vypadky internetu a zvuku
Dobry den, stale mi vypadava internet a zvuk pri koukani na online stream videa, pomaha bud restart nebo preinstalovani ovladaci, prikladam log a dekuji za radu.
Logfile of random's system information tool 1.08 (written by random/random)
Run by UserXP at 2011-05-24 11:01:02
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 803 MB (8%) free of 10 GB
Total RAM: 2301 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:01:08, on 24. 5. 2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\wdm\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\AESTFltr.exe
D:\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
D:\utorent\uTorrent.exe
D:\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\UserXP\Data aplikací\QipGuard\QipGuard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\QipGuard\QipGuard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe
D:\QIP 2010\qip.exe
D:\CCleaner\CCleaner.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Plocha\RSIT.exe
C:\Program Files\trend micro\UserXP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivX Download Manager] "C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe" start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "D:\utorent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Documents and Settings\UserXP\Data aplikací\QipGuard\QipGuard.exe /p
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: QipGuard - QIP.ru - C:\Program Files\QipGuard\QipGuard.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\wdm\STacSV.exe
--
End of file - 9710 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1957994488-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1957994488-725345543-1003UA.job
C:\WINDOWS\tasks\SDMsgUpdate (TE).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\MICROS~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2011-05-10 141184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-09 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files\BS_Player\tbBS_P.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files\BS_Player\tbBS_P.dll [2010-11-29 3908192]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-04-02 61440]
"AESTFltr"=C:\WINDOWS\system32\AESTFltr.exe [2009-02-18 737280]
"GrooveMonitor"=D:\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe Reader Speed Launcher"=D:\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"DivX Download Manager"=C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe [2010-12-08 63360]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2219184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-01-09 136176]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"uTorrent"=D:\utorent\uTorrent.exe [2011-04-14 399736]
"DAEMON Tools Lite"=D:\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-04-18 15146376]
"QIP Internet Guardian"=C:\Documents and Settings\UserXP\Data aplikací\QipGuard\QipGuard.exe [2011-05-10 187776]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-04-01 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\MICROS~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=181
"NoDriveAutoRun"=0xE0FFFF03
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Microsoft Office\Office12\OUTLOOK.EXE"="D:\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Microsoft Office\Office12\GROOVE.EXE"="D:\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"D:\Microsoft Office\Office12\ONENOTE.EXE"="D:\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\utorent\uTorrent.exe"="D:\utorent\uTorrent.exe:*:Enabled:µTorrent"
"F:\civil\Civilization4.exe"="F:\civil\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"F:\civil\Warlords\Civ4Warlords.exe"="F:\civil\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4 Warlords"
"F:\civil\Warlords\Civ4Warlords_PitBoss.exe"="F:\civil\Warlords\Civ4Warlords_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Pitboss"
"F:\civil\Beyond the Sword\Civ4BeyondSword.exe"="F:\civil\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword"
"F:\civil\Beyond the Sword\Civ4BeyondSword_PitBoss.exe"="F:\civil\Beyond the Sword\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\UserXP\Data aplikací\57.tmp"="C:\Documents and Settings\UserXP\Data aplikací\57.tmp:*:C:\WINDOWS\aadrive32.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2011-05-24 11:01:03 ----D---- C:\Program Files\trend micro
2011-05-24 11:01:02 ----D---- C:\rsit
2011-05-23 22:51:03 ----D---- C:\Program Files\IDT
2011-05-21 15:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB894391$
2011-05-21 15:02:53 ----HD---- C:\WINDOWS\$hf_mig$
2011-05-21 14:46:49 ----D---- C:\Program Files\ESET
2011-05-21 14:46:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-05-18 19:11:06 ----D---- C:\Program Files\QipGuard
2011-05-18 19:11:06 ----D---- C:\Documents and Settings\UserXP\Data aplikací\QipGuard
2011-05-18 15:06:41 ----D---- C:\WINDOWS\system32\appmgmt
2011-05-18 09:58:05 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2011-05-18 09:57:01 ----D---- C:\Program Files\Microsoft SDKs
2011-05-18 09:55:42 ----D---- C:\WINDOWS\system32\XPSViewer
2011-05-18 09:55:35 ----D---- C:\Program Files\Reference Assemblies
2011-05-18 09:55:15 ----N---- C:\WINDOWS\system32\spmsg2.dll
2011-05-18 09:52:15 ----D---- C:\Program Files\MSXML 6.0
2011-05-17 16:27:48 ----A---- C:\Documents and Settings\UserXP\Data aplikací\31.tmp
2011-05-17 15:25:10 ----A---- C:\Documents and Settings\UserXP\Data aplikací\5D.tmp
2011-05-16 23:39:05 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-05-16 23:03:15 ----A---- C:\Documents and Settings\UserXP\Data aplikací\30.tmp
2011-05-16 23:03:13 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2C.tmp
2011-05-16 21:11:48 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2F.tmp
2011-05-16 19:44:25 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2E.tmp
2011-05-16 18:37:44 ----A---- C:\Documents and Settings\UserXP\Data aplikací\E7.tmp
2011-05-16 18:26:00 ----A---- C:\Documents and Settings\UserXP\Data aplikací\28.tmp
2011-05-16 18:21:56 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2D.tmp
2011-05-11 15:06:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype Extras
2011-05-11 15:06:17 ----D---- C:\Program Files\Common Files\Skype
======List of files/folders modified in the last 1 months======
2011-05-24 11:01:03 ----RD---- C:\Program Files
2011-05-24 11:00:06 ----D---- C:\WINDOWS
2011-05-24 10:59:43 ----D---- C:\WINDOWS\Temp
2011-05-24 10:59:08 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-05-24 10:55:37 ----D---- C:\Documents and Settings\UserXP\Data aplikací\Skype
2011-05-24 10:55:18 ----D---- C:\Documents and Settings\UserXP\Data aplikací\skypePM
2011-05-24 10:55:04 ----D---- C:\Documents and Settings\UserXP\Data aplikací\uTorrent
2011-05-23 22:51:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-05-23 22:51:26 ----D---- C:\WINDOWS\system32\drivers
2011-05-23 22:51:26 ----D---- C:\WINDOWS\system32
2011-05-23 22:51:20 ----D---- C:\WINDOWS\system32\CatRoot2
2011-05-23 22:49:49 ----D---- C:\WINDOWS\Prefetch
2011-05-23 13:32:39 ----HD---- C:\WINDOWS\inf
2011-05-23 13:32:39 ----D---- C:\WINDOWS\system32\CatRoot
2011-05-23 10:07:01 ----D---- C:\WINDOWS\system32\config
2011-05-21 14:51:47 ----SD---- C:\Documents and Settings\UserXP\Data aplikací\Microsoft
2011-05-21 14:47:29 ----SHD---- C:\WINDOWS\Installer
2011-05-19 06:15:44 ----D---- C:\WINDOWS\Minidump
2011-05-19 06:15:44 ----D---- C:\WINDOWS\Debug
2011-05-18 19:03:03 ----D---- C:\Program Files\DivX
2011-05-18 19:03:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2011-05-18 15:11:20 ----D---- C:\WINDOWS\Microsoft.NET
2011-05-18 15:01:32 ----RSD---- C:\WINDOWS\assembly
2011-05-18 10:43:11 ----D---- C:\WINDOWS\WinSxS
2011-05-18 10:41:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-05-18 10:41:51 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-05-18 10:41:51 ----D---- C:\Program Files\Common Files
2011-05-18 10:00:39 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-05-18 09:56:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-05-18 09:55:45 ----RSD---- C:\WINDOWS\Fonts
2011-05-18 09:55:18 ----D---- C:\WINDOWS\system32\spool
2011-05-18 09:53:32 ----D---- C:\Program Files\Internet Explorer
2011-05-16 21:46:17 ----D---- C:\WINDOWS\system32\DirectX
2011-05-16 14:02:47 ----SHD---- C:\RECYCLER
2011-05-11 15:06:18 ----RD---- C:\Program Files\Skype
2011-05-11 15:06:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-04-14 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-12-21 94872]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-12-21 141264]
R3 AESTAud;AE Audio Service; C:\WINDOWS\system32\drivers\AESTAud.sys [2009-02-18 113536]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-04-02 3597824]
R3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2009-01-14 534568]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2009-01-14 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2009-01-14 991656]
R3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2009-01-14 156816]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2009-01-14 47272]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 STHDA;IDT High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2009-03-30 1550891]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2009-07-17 297728]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\safedrv.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-04-01 602112]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-12-11 346720]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-01-12 810144]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 pgsql-8.3;PostgreSQL Database Server 8.3; C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe [2008-02-01 65536]
R2 QipGuard;QipGuard; C:\Program Files\QipGuard\QipGuard.exe [2011-05-10 187776]
R2 STacSV;Audio Service; c:\program files\idt\wdm\STacSV.exe [2009-03-30 254042]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by UserXP at 2011-05-24 11:01:02
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 803 MB (8%) free of 10 GB
Total RAM: 2301 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:01:08, on 24. 5. 2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\wdm\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\AESTFltr.exe
D:\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
D:\utorent\uTorrent.exe
D:\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\UserXP\Data aplikací\QipGuard\QipGuard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\QipGuard\QipGuard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe
D:\QIP 2010\qip.exe
D:\CCleaner\CCleaner.exe
C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\UserXP\Plocha\RSIT.exe
C:\Program Files\trend micro\UserXP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_P.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivX Download Manager] "C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe" start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "D:\utorent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Documents and Settings\UserXP\Data aplikací\QipGuard\QipGuard.exe /p
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: QipGuard - QIP.ru - C:\Program Files\QipGuard\QipGuard.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\wdm\STacSV.exe
--
End of file - 9710 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1957994488-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1957994488-725345543-1003UA.job
C:\WINDOWS\tasks\SDMsgUpdate (TE).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll [2010-12-08 3123072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\MICROS~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2011-05-10 141184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-09 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files\BS_Player\tbBS_P.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files\BS_Player\tbBS_P.dll [2010-11-29 3908192]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-11-29 3908192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-04-02 61440]
"AESTFltr"=C:\WINDOWS\system32\AESTFltr.exe [2009-02-18 737280]
"GrooveMonitor"=D:\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe Reader Speed Launcher"=D:\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"DivX Download Manager"=C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe [2010-12-08 63360]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2219184]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\UserXP\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-01-09 136176]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"uTorrent"=D:\utorent\uTorrent.exe [2011-04-14 399736]
"DAEMON Tools Lite"=D:\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-04-18 15146376]
"QIP Internet Guardian"=C:\Documents and Settings\UserXP\Data aplikací\QipGuard\QipGuard.exe [2011-05-10 187776]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-04-01 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\MICROS~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=181
"NoDriveAutoRun"=0xE0FFFF03
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Microsoft Office\Office12\OUTLOOK.EXE"="D:\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Microsoft Office\Office12\GROOVE.EXE"="D:\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"D:\Microsoft Office\Office12\ONENOTE.EXE"="D:\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\utorent\uTorrent.exe"="D:\utorent\uTorrent.exe:*:Enabled:µTorrent"
"F:\civil\Civilization4.exe"="F:\civil\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"F:\civil\Warlords\Civ4Warlords.exe"="F:\civil\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4 Warlords"
"F:\civil\Warlords\Civ4Warlords_PitBoss.exe"="F:\civil\Warlords\Civ4Warlords_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Pitboss"
"F:\civil\Beyond the Sword\Civ4BeyondSword.exe"="F:\civil\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword"
"F:\civil\Beyond the Sword\Civ4BeyondSword_PitBoss.exe"="F:\civil\Beyond the Sword\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\UserXP\Data aplikací\57.tmp"="C:\Documents and Settings\UserXP\Data aplikací\57.tmp:*:C:\WINDOWS\aadrive32.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2011-05-24 11:01:03 ----D---- C:\Program Files\trend micro
2011-05-24 11:01:02 ----D---- C:\rsit
2011-05-23 22:51:03 ----D---- C:\Program Files\IDT
2011-05-21 15:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB894391$
2011-05-21 15:02:53 ----HD---- C:\WINDOWS\$hf_mig$
2011-05-21 14:46:49 ----D---- C:\Program Files\ESET
2011-05-21 14:46:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-05-18 19:11:06 ----D---- C:\Program Files\QipGuard
2011-05-18 19:11:06 ----D---- C:\Documents and Settings\UserXP\Data aplikací\QipGuard
2011-05-18 15:06:41 ----D---- C:\WINDOWS\system32\appmgmt
2011-05-18 09:58:05 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2011-05-18 09:57:01 ----D---- C:\Program Files\Microsoft SDKs
2011-05-18 09:55:42 ----D---- C:\WINDOWS\system32\XPSViewer
2011-05-18 09:55:35 ----D---- C:\Program Files\Reference Assemblies
2011-05-18 09:55:15 ----N---- C:\WINDOWS\system32\spmsg2.dll
2011-05-18 09:52:15 ----D---- C:\Program Files\MSXML 6.0
2011-05-17 16:27:48 ----A---- C:\Documents and Settings\UserXP\Data aplikací\31.tmp
2011-05-17 15:25:10 ----A---- C:\Documents and Settings\UserXP\Data aplikací\5D.tmp
2011-05-16 23:39:05 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-05-16 23:03:15 ----A---- C:\Documents and Settings\UserXP\Data aplikací\30.tmp
2011-05-16 23:03:13 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2C.tmp
2011-05-16 21:11:48 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2F.tmp
2011-05-16 19:44:25 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2E.tmp
2011-05-16 18:37:44 ----A---- C:\Documents and Settings\UserXP\Data aplikací\E7.tmp
2011-05-16 18:26:00 ----A---- C:\Documents and Settings\UserXP\Data aplikací\28.tmp
2011-05-16 18:21:56 ----A---- C:\Documents and Settings\UserXP\Data aplikací\2D.tmp
2011-05-11 15:06:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype Extras
2011-05-11 15:06:17 ----D---- C:\Program Files\Common Files\Skype
======List of files/folders modified in the last 1 months======
2011-05-24 11:01:03 ----RD---- C:\Program Files
2011-05-24 11:00:06 ----D---- C:\WINDOWS
2011-05-24 10:59:43 ----D---- C:\WINDOWS\Temp
2011-05-24 10:59:08 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-05-24 10:55:37 ----D---- C:\Documents and Settings\UserXP\Data aplikací\Skype
2011-05-24 10:55:18 ----D---- C:\Documents and Settings\UserXP\Data aplikací\skypePM
2011-05-24 10:55:04 ----D---- C:\Documents and Settings\UserXP\Data aplikací\uTorrent
2011-05-23 22:51:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-05-23 22:51:26 ----D---- C:\WINDOWS\system32\drivers
2011-05-23 22:51:26 ----D---- C:\WINDOWS\system32
2011-05-23 22:51:20 ----D---- C:\WINDOWS\system32\CatRoot2
2011-05-23 22:49:49 ----D---- C:\WINDOWS\Prefetch
2011-05-23 13:32:39 ----HD---- C:\WINDOWS\inf
2011-05-23 13:32:39 ----D---- C:\WINDOWS\system32\CatRoot
2011-05-23 10:07:01 ----D---- C:\WINDOWS\system32\config
2011-05-21 14:51:47 ----SD---- C:\Documents and Settings\UserXP\Data aplikací\Microsoft
2011-05-21 14:47:29 ----SHD---- C:\WINDOWS\Installer
2011-05-19 06:15:44 ----D---- C:\WINDOWS\Minidump
2011-05-19 06:15:44 ----D---- C:\WINDOWS\Debug
2011-05-18 19:03:03 ----D---- C:\Program Files\DivX
2011-05-18 19:03:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2011-05-18 15:11:20 ----D---- C:\WINDOWS\Microsoft.NET
2011-05-18 15:01:32 ----RSD---- C:\WINDOWS\assembly
2011-05-18 10:43:11 ----D---- C:\WINDOWS\WinSxS
2011-05-18 10:41:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-05-18 10:41:51 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-05-18 10:41:51 ----D---- C:\Program Files\Common Files
2011-05-18 10:00:39 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-05-18 09:56:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-05-18 09:55:45 ----RSD---- C:\WINDOWS\Fonts
2011-05-18 09:55:18 ----D---- C:\WINDOWS\system32\spool
2011-05-18 09:53:32 ----D---- C:\Program Files\Internet Explorer
2011-05-16 21:46:17 ----D---- C:\WINDOWS\system32\DirectX
2011-05-16 14:02:47 ----SHD---- C:\RECYCLER
2011-05-11 15:06:18 ----RD---- C:\Program Files\Skype
2011-05-11 15:06:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-04-14 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-12-21 94872]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-12-21 141264]
R3 AESTAud;AE Audio Service; C:\WINDOWS\system32\drivers\AESTAud.sys [2009-02-18 113536]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-04-02 3597824]
R3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2009-01-14 534568]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2009-01-14 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2009-01-14 991656]
R3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2009-01-14 156816]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2009-01-14 47272]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 STHDA;IDT High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2009-03-30 1550891]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2009-07-17 297728]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\safedrv.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-04-01 602112]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-12-11 346720]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-01-12 810144]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 pgsql-8.3;PostgreSQL Database Server 8.3; C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe [2008-02-01 65536]
R2 QipGuard;QipGuard; C:\Program Files\QipGuard\QipGuard.exe [2011-05-10 187776]
R2 STacSV;Audio Service; c:\program files\idt\wdm\STacSV.exe [2009-03-30 254042]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]
-----------------EOF-----------------
Re: vypadky internetu a zvuku
Zdravim a pekny podvecer preji
Uvolnete volne misto na disku alespon na 3 giga, jinak se windows dusi
Poprosim i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit
Stahnete na plochu CKScanner
- Spustte a kliknete na Search for files
- Po dokonceni skenu kliknete na Save List to File a nasledne OK
- Na plose se Vam vytvori log s nazvem ckfiles.txt, jeho obsah mi sem vlozte
Re: vypadky internetu a zvuku
info.txt
info.txt logfile of random's system information tool 1.08 2011-05-24 11:01:10
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent-->"D:\utorent\\uTorrent.exe" /UNINSTALL
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe -maintain activex
Adobe Photoshop 7.0 CE-->C:\WINDOWS\ISUN0405.EXE -f"D:\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Adobe\Photoshop 7.0 CE\Uninst.dll"
Adobe Reader X (10.0.1) - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AA0000000001}
Aktualizace systému Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
BS Player Toolbar-->C:\PROGRA~1\BS_PLA~1\UNWISE.EXE /U C:\PROGRA~1\BS_PLA~1\INSTALL.LOG
BS.Player FREE-->"D:\BSplayer\uninstall.exe"
Catalyst Control Center - Branding-->MsiExec.exe /I{A3276EED-22A1-4808-9AA3-88A451482E10}
Civilizácia IV SK-->F:\civil\Odinštalovať Civilizácia-IV_SK.exe
Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
Conduit Engine-->C:\PROGRA~1\CONDUI~1\ConduitEngineUninstall.exe
DAEMON Tools Lite-->D:\DAEMON Tools Lite\uninst.exe
DivX Setup-->C:\Documents and Settings\All Users\Data aplikací\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com
Garena 2010-->C:\Program Files\Garena\uninst.exe
Heroes of Newerth-->F:\hon\uninstall.exe
HP Integrated Module with Bluetooth wireless technology-->MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
IDT Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\Setup.exe" -remove -removeonly
Java(TM) 6 Update 24-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216023FF}
Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft .NET Framework 4 Extended CSY Language Pack-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\ExtendedLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ExtendedLP
Microsoft .NET Framework 4 Extended CSY Language Pack-->MsiExec.exe /X{A2DE62D8-EF1B-36CB-B461-B1E221ED8608}
Microsoft .NET Framework 4 Extended-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework-->MsiExec.exe /X{B4C0A315-07FB-39F9-85CD-8CE20C019350}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32-->MsiExec.exe /X{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
PokerStrategy.com Elephant-->MsiExec.exe /I{28C06EBC-2310-48DB-BA6A-DBEDAFADDEB0}
PokerTracker 3 (remove only)-->"D:\PokerTracker 3\uninstall.exe"
PostgreSQL 8.3-->MsiExec.exe /I{B823632F-3B72-4514-8861-B961CE263224}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x5 -removeonly
Sid Meier's Civilization 4 - Beyond the Sword-->C:\Program Files\InstallShield Installation Information\{32E4F0D2-C135-475E-A841-1D59A0D22989}\setup.exe -runfromtemp -l0x0009 -removeonly
Sid Meier's Civilization 4 - Warlords-->C:\Program Files\InstallShield Installation Information\{3E4B349F-10B5-4586-9D99-489A90A8B228}\setup.exe -runfromtemp -l0x0009 -removeonly
Sid Meier's Civilization 4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}\setup.exe" -l0x9 -removeonly
SimCity 4 Deluxe-->F:\torent\Sim City 4 Deluxe\EAUninstall.exe
Skype Toolbars-->MsiExec.exe /I{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Skype™ 5.3-->MsiExec.exe /X{5335DADB-34BA-4AE8-A519-648D78498846}
SmartDraw VP-->D:\SMARTD~1\UNWISE.EXE D:\SMARTD~1\INSTALL.LOG
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->D:\winrarq\uninstall.exe
======Security center information======
AV: ESET NOD32 Antivirus 4.2
======System event log======
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _RIB_register_interface@16 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3586
Source Name: Application Popup
Time Written: 20110416145245.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _RIB_unregister_interface@16 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3585
Source Name: Application Popup
Time Written: 20110416145245.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _MSSDisableThreadLibraryCalls@4 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3584
Source Name: Application Popup
Time Written: 20110416145244.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _RIB_unregister_interface@16 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3583
Source Name: Application Popup
Time Written: 20110416145244.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _MSSDisableThreadLibraryCalls@4 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3582
Source Name: Application Popup
Time Written: 20110416145243.000000+120
Event Type: Informace
User:
=====Application event log=====
Computer Name: PRIVE-D1697D5B2
Event Code: 0
Message: 2011-03-04 17:04:44 CET LOG: loaded library "$libdir/plugins/plugin_debugger.dll"
Record Number: 1178
Source Name: PostgreSQL
Time Written: 20110304170444.000000+060
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 1800
Message: Služba Centrum zabezpečení systému Windows byla spuštěna.
Record Number: 1177
Source Name: SecurityCenter
Time Written: 20110304170444.000000+060
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 0
Message: Waiting for server startup...
Record Number: 1176
Source Name: PostgreSQL
Time Written: 20110304170443.000000+060
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 2004
Message: Nelze otevřít službu serveru. Data o výkonu serveru nejsou
k dispozici. Vrácený chybový kód je v datech DWORD 0.
Record Number: 1175
Source Name: PerfNet
Time Written: 20110304170440.000000+060
Event Type: Chyba
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 1002
Message: Prostředí bylo neočekávaně zastaveno a Explorer.exe byl restartován.
Record Number: 1174
Source Name: Winlogon
Time Written: 20110304163739.000000+060
Event Type: Informace
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=17
"PROCESSOR_IDENTIFIER"=x86 Family 17 Model 3 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=0301
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
CKS:
CKScanner - Additional Security Risks - These are not necessarily bad
c:\program files\garena\plugins\ui\avoidcrackplugin.dll
scanner sequence 3.AP.11
----- EOF -----
info.txt logfile of random's system information tool 1.08 2011-05-24 11:01:10
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent-->"D:\utorent\\uTorrent.exe" /UNINSTALL
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe -maintain activex
Adobe Photoshop 7.0 CE-->C:\WINDOWS\ISUN0405.EXE -f"D:\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Adobe\Photoshop 7.0 CE\Uninst.dll"
Adobe Reader X (10.0.1) - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AA0000000001}
Aktualizace systému Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
BS Player Toolbar-->C:\PROGRA~1\BS_PLA~1\UNWISE.EXE /U C:\PROGRA~1\BS_PLA~1\INSTALL.LOG
BS.Player FREE-->"D:\BSplayer\uninstall.exe"
Catalyst Control Center - Branding-->MsiExec.exe /I{A3276EED-22A1-4808-9AA3-88A451482E10}
Civilizácia IV SK-->F:\civil\Odinštalovať Civilizácia-IV_SK.exe
Codec Pack - All In 1 6.0.3.0-->C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
Conduit Engine-->C:\PROGRA~1\CONDUI~1\ConduitEngineUninstall.exe
DAEMON Tools Lite-->D:\DAEMON Tools Lite\uninst.exe
DivX Setup-->C:\Documents and Settings\All Users\Data aplikací\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com
Garena 2010-->C:\Program Files\Garena\uninst.exe
Heroes of Newerth-->F:\hon\uninstall.exe
HP Integrated Module with Bluetooth wireless technology-->MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
IDT Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\Setup.exe" -remove -removeonly
Java(TM) 6 Update 24-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216023FF}
Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft .NET Framework 4 Extended CSY Language Pack-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\ExtendedLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ExtendedLP
Microsoft .NET Framework 4 Extended CSY Language Pack-->MsiExec.exe /X{A2DE62D8-EF1B-36CB-B461-B1E221ED8608}
Microsoft .NET Framework 4 Extended-->C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework-->MsiExec.exe /X{B4C0A315-07FB-39F9-85CD-8CE20C019350}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32-->MsiExec.exe /X{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
PokerStrategy.com Elephant-->MsiExec.exe /I{28C06EBC-2310-48DB-BA6A-DBEDAFADDEB0}
PokerTracker 3 (remove only)-->"D:\PokerTracker 3\uninstall.exe"
PostgreSQL 8.3-->MsiExec.exe /I{B823632F-3B72-4514-8861-B961CE263224}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x5 -removeonly
Sid Meier's Civilization 4 - Beyond the Sword-->C:\Program Files\InstallShield Installation Information\{32E4F0D2-C135-475E-A841-1D59A0D22989}\setup.exe -runfromtemp -l0x0009 -removeonly
Sid Meier's Civilization 4 - Warlords-->C:\Program Files\InstallShield Installation Information\{3E4B349F-10B5-4586-9D99-489A90A8B228}\setup.exe -runfromtemp -l0x0009 -removeonly
Sid Meier's Civilization 4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}\setup.exe" -l0x9 -removeonly
SimCity 4 Deluxe-->F:\torent\Sim City 4 Deluxe\EAUninstall.exe
Skype Toolbars-->MsiExec.exe /I{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Skype™ 5.3-->MsiExec.exe /X{5335DADB-34BA-4AE8-A519-648D78498846}
SmartDraw VP-->D:\SMARTD~1\UNWISE.EXE D:\SMARTD~1\INSTALL.LOG
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->D:\winrarq\uninstall.exe
======Security center information======
AV: ESET NOD32 Antivirus 4.2
======System event log======
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _RIB_register_interface@16 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3586
Source Name: Application Popup
Time Written: 20110416145245.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _RIB_unregister_interface@16 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3585
Source Name: Application Popup
Time Written: 20110416145245.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _MSSDisableThreadLibraryCalls@4 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3584
Source Name: Application Popup
Time Written: 20110416145244.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _RIB_unregister_interface@16 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3583
Source Name: Application Popup
Time Written: 20110416145244.000000+120
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 26
Message: Místní nabídka aplikace: Civ IV: Beyond The Sword: Civ4BeyondSword.exe - Vstupní bod nebyl nalezen : Vstupní bod procedury _MSSDisableThreadLibraryCalls@4 se nepodařilo v dynamicky propojované knihovně mss32.dll nalézt.
Record Number: 3582
Source Name: Application Popup
Time Written: 20110416145243.000000+120
Event Type: Informace
User:
=====Application event log=====
Computer Name: PRIVE-D1697D5B2
Event Code: 0
Message: 2011-03-04 17:04:44 CET LOG: loaded library "$libdir/plugins/plugin_debugger.dll"
Record Number: 1178
Source Name: PostgreSQL
Time Written: 20110304170444.000000+060
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 1800
Message: Služba Centrum zabezpečení systému Windows byla spuštěna.
Record Number: 1177
Source Name: SecurityCenter
Time Written: 20110304170444.000000+060
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 0
Message: Waiting for server startup...
Record Number: 1176
Source Name: PostgreSQL
Time Written: 20110304170443.000000+060
Event Type: Informace
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 2004
Message: Nelze otevřít službu serveru. Data o výkonu serveru nejsou
k dispozici. Vrácený chybový kód je v datech DWORD 0.
Record Number: 1175
Source Name: PerfNet
Time Written: 20110304170440.000000+060
Event Type: Chyba
User:
Computer Name: PRIVE-D1697D5B2
Event Code: 1002
Message: Prostředí bylo neočekávaně zastaveno a Explorer.exe byl restartován.
Record Number: 1174
Source Name: Winlogon
Time Written: 20110304163739.000000+060
Event Type: Informace
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=17
"PROCESSOR_IDENTIFIER"=x86 Family 17 Model 3 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=0301
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
CKS:
CKScanner - Additional Security Risks - These are not necessarily bad
c:\program files\garena\plugins\ui\avoidcrackplugin.dll
scanner sequence 3.AP.11
----- EOF -----
Re: vypadky internetu a zvuku
- HJT najdete zde C:\Program Files\trend micro\UserXP.exe
- Otevre se Vam okno, kliknete na Do a system scan only
- V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie - Kliknete na Fix checked (vlevo dole)
- HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo

- Pokud ho havet blokuje, pouzijte jeden z nasledujicich
motji napsal: Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr
Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne temer okamzite a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Ted nerestartujte PC - prisli byste o ucinek RKillu
- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: vypadky internetu a zvuku
vkladam log z combofixu:
ComboFix 11-05-24.01 - Administrator . 05. 2011 23:05:40.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.2301.1633 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\UserXP\Data aplikací\2D.tmp
c:\documents and settings\UserXP\Data aplikací\Local
c:\documents and settings\UserXP\System
c:\documents and settings\UserXP\System\win_qs8.jqx
D:\install.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-24 do 2011-05-24 )))))))))))))))))))))))))))))))
.
.
2011-05-24 20:57 . 2011-05-24 20:57 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-05-24 20:56 . 2004-08-17 14:49 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-05-24 20:55 . 2011-05-24 20:56 -------- d-----w- c:\documents and settings\Administrator
2011-05-24 09:20 . 2011-05-24 16:13 -------- d-----w- c:\program files\IDT
2011-05-24 09:01 . 2011-05-24 18:58 -------- d-----w- c:\program files\trend micro
2011-05-24 09:01 . 2011-05-24 09:01 -------- d-----w- C:\rsit
2011-05-21 13:02 . 2011-05-21 13:02 -------- d--h--w- c:\windows\$hf_mig$
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\program files\ESET
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\program files\QipGuard
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\documents and settings\UserXP\Data aplikací\QipGuard
2011-05-18 17:10 . 2011-05-10 15:14 141184 ----a-w- c:\documents and settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-05-18 08:01 . 2011-05-18 08:01 112640 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-05-18 08:00 . 2011-05-18 08:00 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-05-18 07:58 . 2011-05-18 08:41 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-05-18 07:57 . 2011-05-18 07:57 -------- d-----w- c:\program files\Microsoft SDKs
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\windows\system32\XPSViewer
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\program files\Reference Assemblies
2011-05-18 07:55 . 2007-03-22 18:24 28160 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-05-18 07:55 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-05-18 07:52 . 2011-05-18 07:52 -------- d-----w- c:\program files\MSXML 6.0
2011-05-17 14:27 . 2011-05-17 14:27 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\31.tmp
2011-05-17 13:25 . 2011-05-17 13:25 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\5D.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\30.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2C.tmp
2011-05-16 19:11 . 2011-05-16 19:11 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2F.tmp
2011-05-16 17:44 . 2011-05-16 17:44 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\2E.tmp
2011-05-16 16:37 . 2011-05-16 16:37 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\E7.tmp
2011-05-16 16:26 . 2011-05-16 16:26 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\28.tmp
2011-05-16 12:06 . 2011-05-16 12:06 -------- d-----w- c:\documents and settings\UserXP\Local Settings\Data aplikací\ESET
2011-05-16 10:25 . 2011-05-16 10:25 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-05-11 13:06 . 2011-05-22 22:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-05-11 13:06 . 2011-05-11 13:06 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 20:13 . 2011-01-09 12:00 163644 ----a-w- c:\windows\system32\drivers\secdrv.sys
2011-04-14 15:17 . 2011-04-14 15:17 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-03-15 16:27 . 2011-03-15 16:25 139264 ----a-w- c:\windows\War3Unin.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2011-01-17 14:54 175912 ----a-w- c:\program files\BS_Player\prxtbBS_0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\prxtbBS_0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-01 61440]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-02-18 737280]
"GrooveMonitor"="d:\microsoft office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe Reader Speed Launcher"="d:\adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-1-11 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"d:\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\utorent\\uTorrent.exe"=
"f:\\civil\\Civilization4.exe"=
"f:\\civil\\Warlords\\Civ4Warlords.exe"=
"f:\\civil\\Warlords\\Civ4Warlords_PitBoss.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [14. 4. 2011 17:17 218688]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21. 12. 2010 15:04 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21. 12. 2010 13:47 94872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12. 1. 2011 16:41 810144]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [1. 2. 2008 5:02 65536]
R2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [18. 5. 2011 19:11 187776]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [9. 1. 2011 14:03 113536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 14:16 130384]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 14:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-24 c:\windows\Tasks\SDMsgUpdate (TE).job
- d:\smartd~1\Messages\SDNotify.exe [2011-01-10 17:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - d:\micros~1\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-24 23:09
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-05-24 23:10:26
ComboFix-quarantined-files.txt 2011-05-24 21:10
.
Před spuštěním: 610 320 384
Po spuštění: 949 223 424
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[Boot Loader]
timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="USB Repair NOT to Start Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 2DF35E484C9D10886D46A217271D35BE
ComboFix 11-05-24.01 - Administrator . 05. 2011 23:05:40.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.2301.1633 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\UserXP\Data aplikací\2D.tmp
c:\documents and settings\UserXP\Data aplikací\Local
c:\documents and settings\UserXP\System
c:\documents and settings\UserXP\System\win_qs8.jqx
D:\install.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-24 do 2011-05-24 )))))))))))))))))))))))))))))))
.
.
2011-05-24 20:57 . 2011-05-24 20:57 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-05-24 20:56 . 2004-08-17 14:49 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-05-24 20:55 . 2011-05-24 20:56 -------- d-----w- c:\documents and settings\Administrator
2011-05-24 09:20 . 2011-05-24 16:13 -------- d-----w- c:\program files\IDT
2011-05-24 09:01 . 2011-05-24 18:58 -------- d-----w- c:\program files\trend micro
2011-05-24 09:01 . 2011-05-24 09:01 -------- d-----w- C:\rsit
2011-05-21 13:02 . 2011-05-21 13:02 -------- d--h--w- c:\windows\$hf_mig$
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\program files\ESET
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\program files\QipGuard
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\documents and settings\UserXP\Data aplikací\QipGuard
2011-05-18 17:10 . 2011-05-10 15:14 141184 ----a-w- c:\documents and settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-05-18 08:01 . 2011-05-18 08:01 112640 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-05-18 08:00 . 2011-05-18 08:00 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-05-18 07:58 . 2011-05-18 08:41 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-05-18 07:57 . 2011-05-18 07:57 -------- d-----w- c:\program files\Microsoft SDKs
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\windows\system32\XPSViewer
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\program files\Reference Assemblies
2011-05-18 07:55 . 2007-03-22 18:24 28160 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-05-18 07:55 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-05-18 07:52 . 2011-05-18 07:52 -------- d-----w- c:\program files\MSXML 6.0
2011-05-17 14:27 . 2011-05-17 14:27 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\31.tmp
2011-05-17 13:25 . 2011-05-17 13:25 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\5D.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\30.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2C.tmp
2011-05-16 19:11 . 2011-05-16 19:11 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2F.tmp
2011-05-16 17:44 . 2011-05-16 17:44 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\2E.tmp
2011-05-16 16:37 . 2011-05-16 16:37 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\E7.tmp
2011-05-16 16:26 . 2011-05-16 16:26 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\28.tmp
2011-05-16 12:06 . 2011-05-16 12:06 -------- d-----w- c:\documents and settings\UserXP\Local Settings\Data aplikací\ESET
2011-05-16 10:25 . 2011-05-16 10:25 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-05-11 13:06 . 2011-05-22 22:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-05-11 13:06 . 2011-05-11 13:06 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 20:13 . 2011-01-09 12:00 163644 ----a-w- c:\windows\system32\drivers\secdrv.sys
2011-04-14 15:17 . 2011-04-14 15:17 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-03-15 16:27 . 2011-03-15 16:25 139264 ----a-w- c:\windows\War3Unin.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2011-01-17 14:54 175912 ----a-w- c:\program files\BS_Player\prxtbBS_0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\prxtbBS_0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-01 61440]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-02-18 737280]
"GrooveMonitor"="d:\microsoft office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe Reader Speed Launcher"="d:\adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-1-11 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"d:\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\utorent\\uTorrent.exe"=
"f:\\civil\\Civilization4.exe"=
"f:\\civil\\Warlords\\Civ4Warlords.exe"=
"f:\\civil\\Warlords\\Civ4Warlords_PitBoss.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [14. 4. 2011 17:17 218688]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21. 12. 2010 15:04 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21. 12. 2010 13:47 94872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12. 1. 2011 16:41 810144]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [1. 2. 2008 5:02 65536]
R2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [18. 5. 2011 19:11 187776]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [9. 1. 2011 14:03 113536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 14:16 130384]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 14:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-24 c:\windows\Tasks\SDMsgUpdate (TE).job
- d:\smartd~1\Messages\SDNotify.exe [2011-01-10 17:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - d:\micros~1\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-24 23:09
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-05-24 23:10:26
ComboFix-quarantined-files.txt 2011-05-24 21:10
.
Před spuštěním: 610 320 384
Po spuštění: 949 223 424
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[Boot Loader]
timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="USB Repair NOT to Start Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 2DF35E484C9D10886D46A217271D35BE
Re: vypadky internetu a zvuku
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: File:: c:\documents and settings\UserXP\Data aplikací\31.tmp c:\documents and settings\UserXP\Data aplikací\5D.tmp c:\documents and settings\UserXP\Data aplikací\30.tmp c:\documents and settings\UserXP\Data aplikací\2C.tmp c:\documents and settings\UserXP\Data aplikací\2F.tmp c:\documents and settings\UserXP\Data aplikací\2E.tmp c:\documents and settings\UserXP\Data aplikací\E7.tmp c:\documents and settings\UserXP\Data aplikací\28.tmp c:\program files\BS_Player\prxtbBS_0.dll c:\Documents and Settings\UserXP\Data aplikací\57.tmp C:\WINDOWS\aadrive32.exe Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"=- [-HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"=- "Adobe ARM"=- "DivX Download Manager"=- "SunJavaUpdateSched"=- "DivXUpdate"=- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Documents and Settings\UserXP\Data aplikací\57.tmp"=- RegLock:: [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] Reboot::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: vypadky internetu a zvuku
ComboFix 11-05-24.02 - Administrator . 05. 2011 7:27.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.2301.1824 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
FILE ::
"c:\documents and settings\UserXP\Data aplikací\28.tmp"
"c:\documents and settings\UserXP\Data aplikací\2C.tmp"
"c:\documents and settings\UserXP\Data aplikací\2E.tmp"
"c:\documents and settings\UserXP\Data aplikací\2F.tmp"
"c:\documents and settings\UserXP\Data aplikací\30.tmp"
"c:\documents and settings\UserXP\Data aplikací\31.tmp"
"c:\documents and settings\UserXP\Data aplikací\57.tmp"
"c:\documents and settings\UserXP\Data aplikací\5D.tmp"
"c:\documents and settings\UserXP\Data aplikací\E7.tmp"
"c:\program files\BS_Player\prxtbBS_0.dll"
"c:\windows\aadrive32.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\BS_Player\prxtbBS_0.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-25 do 2011-05-25 )))))))))))))))))))))))))))))))
.
.
2011-05-24 20:57 . 2011-05-24 20:57 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-05-24 20:56 . 2004-08-17 14:49 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-05-24 20:55 . 2011-05-24 20:56 -------- d-----w- c:\documents and settings\Administrator
2011-05-24 09:20 . 2011-05-24 16:13 -------- d-----w- c:\program files\IDT
2011-05-24 09:01 . 2011-05-24 18:58 -------- d-----w- c:\program files\trend micro
2011-05-24 09:01 . 2011-05-24 09:01 -------- d-----w- C:\rsit
2011-05-21 13:02 . 2011-05-21 13:02 -------- d--h--w- c:\windows\$hf_mig$
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\program files\ESET
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\program files\QipGuard
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\documents and settings\UserXP\Data aplikací\QipGuard
2011-05-18 17:10 . 2011-05-10 15:14 141184 ----a-w- c:\documents and settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-05-18 08:01 . 2011-05-18 08:01 112640 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-05-18 08:00 . 2011-05-18 08:00 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-05-18 07:58 . 2011-05-18 08:41 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-05-18 07:57 . 2011-05-18 07:57 -------- d-----w- c:\program files\Microsoft SDKs
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\windows\system32\XPSViewer
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\program files\Reference Assemblies
2011-05-18 07:55 . 2007-03-22 18:24 28160 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-05-18 07:55 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-05-18 07:52 . 2011-05-18 07:52 -------- d-----w- c:\program files\MSXML 6.0
2011-05-17 14:27 . 2011-05-17 14:27 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\31.tmp
2011-05-17 13:25 . 2011-05-17 13:25 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\5D.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\30.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2C.tmp
2011-05-16 19:11 . 2011-05-16 19:11 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2F.tmp
2011-05-16 17:44 . 2011-05-16 17:44 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\2E.tmp
2011-05-16 16:37 . 2011-05-16 16:37 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\E7.tmp
2011-05-16 16:26 . 2011-05-16 16:26 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\28.tmp
2011-05-16 12:06 . 2011-05-16 12:06 -------- d-----w- c:\documents and settings\UserXP\Local Settings\Data aplikací\ESET
2011-05-16 10:25 . 2011-05-16 10:25 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-05-11 13:06 . 2011-05-22 22:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-05-11 13:06 . 2011-05-11 13:06 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 20:13 . 2011-01-09 12:00 163644 ----a-w- c:\windows\system32\drivers\secdrv.sys
2011-04-14 15:17 . 2011-04-14 15:17 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-03-15 16:27 . 2011-03-15 16:25 139264 ----a-w- c:\windows\War3Unin.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-24_21.09.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-25 05:33 . 2011-05-25 05:33 16384 c:\windows\temp\Perflib_Perfdata_768.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-01 61440]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-02-18 737280]
"GrooveMonitor"="d:\microsoft office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-1-11 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"d:\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\utorent\\uTorrent.exe"=
"f:\\civil\\Civilization4.exe"=
"f:\\civil\\Warlords\\Civ4Warlords.exe"=
"f:\\civil\\Warlords\\Civ4Warlords_PitBoss.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [14. 4. 2011 17:17 218688]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21. 12. 2010 15:04 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21. 12. 2010 13:47 94872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12. 1. 2011 16:41 810144]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [1. 2. 2008 5:02 65536]
R2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [18. 5. 2011 19:11 187776]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [9. 1. 2011 14:03 113536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 14:16 130384]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 14:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-25 c:\windows\Tasks\SDMsgUpdate (TE).job
- d:\smartd~1\Messages\SDNotify.exe [2011-01-10 17:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - d:\micros~1\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-25 07:33
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(952)
c:\windows\system32\btmmhook.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\idt\wdm\STacSV.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2011-05-25 07:35:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-25 05:35
ComboFix2.txt 2011-05-24 21:10
.
Před spuštěním: 919 277 568
Po spuštění: 900 902 912
.
- - End Of File - - 4D20725AE11523DEEFABD8655034C8CC
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.2301.1824 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
FILE ::
"c:\documents and settings\UserXP\Data aplikací\28.tmp"
"c:\documents and settings\UserXP\Data aplikací\2C.tmp"
"c:\documents and settings\UserXP\Data aplikací\2E.tmp"
"c:\documents and settings\UserXP\Data aplikací\2F.tmp"
"c:\documents and settings\UserXP\Data aplikací\30.tmp"
"c:\documents and settings\UserXP\Data aplikací\31.tmp"
"c:\documents and settings\UserXP\Data aplikací\57.tmp"
"c:\documents and settings\UserXP\Data aplikací\5D.tmp"
"c:\documents and settings\UserXP\Data aplikací\E7.tmp"
"c:\program files\BS_Player\prxtbBS_0.dll"
"c:\windows\aadrive32.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\BS_Player\prxtbBS_0.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-25 do 2011-05-25 )))))))))))))))))))))))))))))))
.
.
2011-05-24 20:57 . 2011-05-24 20:57 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-05-24 20:56 . 2004-08-17 14:49 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-05-24 20:55 . 2011-05-24 20:56 -------- d-----w- c:\documents and settings\Administrator
2011-05-24 09:20 . 2011-05-24 16:13 -------- d-----w- c:\program files\IDT
2011-05-24 09:01 . 2011-05-24 18:58 -------- d-----w- c:\program files\trend micro
2011-05-24 09:01 . 2011-05-24 09:01 -------- d-----w- C:\rsit
2011-05-21 13:02 . 2011-05-21 13:02 -------- d--h--w- c:\windows\$hf_mig$
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\program files\ESET
2011-05-21 12:46 . 2011-05-21 12:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\program files\QipGuard
2011-05-18 17:11 . 2011-05-18 17:11 -------- d-----w- c:\documents and settings\UserXP\Data aplikací\QipGuard
2011-05-18 17:10 . 2011-05-10 15:14 141184 ----a-w- c:\documents and settings\UserXP\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-05-18 08:01 . 2011-05-18 08:01 112640 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VCExpress\9.0\1033\ResourceCache.dll
2011-05-18 08:00 . 2011-05-18 08:00 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-05-18 07:58 . 2011-05-18 08:41 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-05-18 07:57 . 2011-05-18 07:57 -------- d-----w- c:\program files\Microsoft SDKs
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\windows\system32\XPSViewer
2011-05-18 07:55 . 2011-05-18 07:55 -------- d-----w- c:\program files\Reference Assemblies
2011-05-18 07:55 . 2007-03-22 18:24 28160 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-05-18 07:55 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-05-18 07:52 . 2011-05-18 07:52 -------- d-----w- c:\program files\MSXML 6.0
2011-05-17 14:27 . 2011-05-17 14:27 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\31.tmp
2011-05-17 13:25 . 2011-05-17 13:25 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\5D.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\30.tmp
2011-05-16 21:03 . 2011-05-16 21:03 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2C.tmp
2011-05-16 19:11 . 2011-05-16 19:11 2334 ----a-w- c:\documents and settings\UserXP\Data aplikací\2F.tmp
2011-05-16 17:44 . 2011-05-16 17:44 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\2E.tmp
2011-05-16 16:37 . 2011-05-16 16:37 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\E7.tmp
2011-05-16 16:26 . 2011-05-16 16:26 2332 ----a-w- c:\documents and settings\UserXP\Data aplikací\28.tmp
2011-05-16 12:06 . 2011-05-16 12:06 -------- d-----w- c:\documents and settings\UserXP\Local Settings\Data aplikací\ESET
2011-05-16 10:25 . 2011-05-16 10:25 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-05-11 13:06 . 2011-05-22 22:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype Extras
2011-05-11 13:06 . 2011-05-11 13:06 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 20:13 . 2011-01-09 12:00 163644 ----a-w- c:\windows\system32\drivers\secdrv.sys
2011-04-14 15:17 . 2011-04-14 15:17 218688 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-03-15 16:27 . 2011-03-15 16:25 139264 ----a-w- c:\windows\War3Unin.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-24_21.09.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-25 05:33 . 2011-05-25 05:33 16384 c:\windows\temp\Perflib_Perfdata_768.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-01 61440]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-02-18 737280]
"GrooveMonitor"="d:\microsoft office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-1-11 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"d:\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\utorent\\uTorrent.exe"=
"f:\\civil\\Civilization4.exe"=
"f:\\civil\\Warlords\\Civ4Warlords.exe"=
"f:\\civil\\Warlords\\Civ4Warlords_PitBoss.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword.exe"=
"f:\\civil\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [14. 4. 2011 17:17 218688]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21. 12. 2010 15:04 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21. 12. 2010 13:47 94872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12. 1. 2011 16:41 810144]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [1. 2. 2008 5:02 65536]
R2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [18. 5. 2011 19:11 187776]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [9. 1. 2011 14:03 113536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 14:16 130384]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 14:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-05-25 c:\windows\Tasks\SDMsgUpdate (TE).job
- d:\smartd~1\Messages\SDNotify.exe [2011-01-10 17:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Excel - d:\micros~1\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-25 07:33
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(952)
c:\windows\system32\btmmhook.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\idt\wdm\STacSV.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2011-05-25 07:35:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-05-25 05:35
ComboFix2.txt 2011-05-24 21:10
.
Před spuštěním: 919 277 568
Po spuštění: 900 902 912
.
- - End Of File - - 4D20725AE11523DEEFABD8655034C8CC
Re: vypadky internetu a zvuku
- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:files c:\documents and settings\UserXP\Data aplikací\*.tmp %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
Re: vypadky internetu a zvuku
All processes killed
========== FILES ==========
c:\documents and settings\UserXP\Data aplikací\28.tmp moved successfully.
c:\documents and settings\UserXP\Data aplikací\2C.tmp moved successfully.
c:\documents and settings\UserXP\Data aplikací\2E.tmp moved successfully.
c:\documents and settings\UserXP\Data aplikací\2F.tmp moved successfully.
c:\documents and settings\UserXP\Data aplikací\30.tmp moved successfully.
c:\documents and settings\UserXP\Data aplikací\31.tmp moved successfully.
c:\documents and settings\UserXP\Data aplikací\5D.tmp moved successfully.
c:\documents and settings\UserXP\Data aplikací\E7.tmp moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 796421 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: elephant
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: UserXP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 15287547 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 118250883 bytes
->Flash cache emptied: 7703 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 128,00 mb
OTM by OldTimer - Version 3.1.18.0 log created on 05252011_080132
Files moved on Reboot...
Registry entries deleted on Reboot...
Re: vypadky internetu a zvuku
zaskocim jednorazovo:
ak si uvolnil miesto na disku, tak doinstaluj SP3
ak si uvolnil miesto na disku, tak doinstaluj SP3
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: vypadky internetu a zvuku
je to nezbytne?
Re: vypadky internetu a zvuku
mozes si pockat na kolegu, ale vo vacsine pripadov mozu za uvedenu hlasku chybajuce aktualizacie 
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: vypadky internetu a zvuku
trochu jsem googlil. a nasel jsem ze na to staci sosnout nejaky hotfix http://www.microsoft.com/downloads/deta ... laylang=cs 
Re: vypadky internetu a zvuku
ano aj to je jedna z nich, ale v priebehu rokov ich bolo viac - ak nechces SP3 budes musiet hladat a skusat, ktora zaberie ,,,
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: vypadky internetu a zvuku
co jsem koukal na na MS download centeru je jen jedna verze na XP...




Přispějete na provoz fóra?