Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Prosím o kontrolu logu
ahoj,
poprosím o kontrolu logu. Na notebooku sa mi spúšťa program PC security guardian a vypisuje niekoľko vírov a zablokovalo mi to internet explorer. Spustila som Antivirák, našiel 1 vír a bol zmazaný. spustila som scan na superantispyware.
Problém stále je.
Ďakujem
Vladka
Logfile of random's system information tool 1.08 (written by random/random)
Run by okay at 2011-06-05 18:16:04
Microsoft Windows 7 Home Premium
System drive C: has 251 GB (86%) free of 291 GB
Total RAM: 3767 MB (67% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
winlogon.exe
C:\Windows\system32\WLANExt.exe 1808624
\??\C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Program Files (x86)\Eset\nod32krn.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
"C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1480
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\PLFSetI.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files (x86)\Eset\nod32kui.exe"
"C:\ProgramData\520806\PS520_2121.exe" /s /d
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ecab22a3-b321-4c36-91e5-01b24d60173a -SystemEventPortName:HostProcess-48bbd38b-7813-488a-ada2-ec86900a727b -IoCancelEventPortName:HostProcess-2cd8c6a1-9023-4c41-887b-cf10982756d6 -NonStateChangingEventPortName:HostProcess-4e62888f-7551-42f1-8275-70f8b1b7957c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e6c5abbd-c724-4798-82e9-a0291bbd9965
"C:\instal\RSITx64.exe"
"c:\program files\windows defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey BE7D1BE6-1B14-3FAE-EE5D-8637AEDF79D2 -Reinvoke
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for okay.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll [2011-05-20 341048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-20 1007160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-29 9913376]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-03-04 166424]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-03-04 391192]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-03-04 410648]
"PLFSetI"=C:\Windows\PLFSetI.exe [2010-06-15 206208]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2010-03-17 860704]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-05-16 153136]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-04-21 39408]
"PC Security Guardian"=C:\ProgramData\520806\PS520_2121.exe [2011-06-02 2361344]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-05-23 2988928]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-12-24 284696]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2010-04-08 908368]
"nod32kui"=C:\Program Files (x86)\Eset\nod32kui.exe [2010-12-25 949376]
"UpdateReminder"=C:\Program Files (x86)\Eset\UpdateReminder.exe [2010-12-25 434176]
"Microsoft WinUpdate"=C:\Windows\system32\msupdte.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-02-20 269824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-06-05 18:16:05 ----D---- C:\Program Files\trend micro
2011-06-05 18:16:04 ----D---- C:\rsit
2011-06-05 17:56:52 ----D---- C:\Program Files (x86)\SpywareBlaster
2011-06-05 15:30:29 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-06-05 15:30:29 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-06-05 15:21:36 ----D---- C:\ProgramData\Google Updater
2011-06-05 15:06:40 ----D---- C:\Program Files (x86)\Trend Micro
2011-06-05 13:07:22 ----D---- C:\Users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 13:07:22 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-06-05 13:07:18 ----D---- C:\ProgramData\!SASCORE
2011-06-05 13:07:13 ----D---- C:\Program Files\SUPERAntiSpyware
2011-05-26 09:59:04 ----SHD---- C:\Users\okay\AppData\Roaming\PC Security Guardian
2011-05-26 09:56:25 ----SHD---- C:\ProgramData\PSYMKCMVCNG
2011-05-26 09:55:49 ----SHD---- C:\ProgramData\520806
======List of files/folders modified in the last 1 months======
2011-06-05 18:16:05 ----RD---- C:\Program Files
2011-06-05 18:16:05 ----D---- C:\Windows\Temp
2011-06-05 18:15:38 ----D---- C:\instal
2011-06-05 18:06:27 ----AD---- C:\ProgramData\Temp
2011-06-05 18:03:23 ----D---- C:\Windows\system32\config
2011-06-05 17:57:17 ----D---- C:\Windows\System32
2011-06-05 17:57:17 ----D---- C:\Windows\inf
2011-06-05 17:57:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-05 17:56:57 ----D---- C:\Windows\SysWOW64
2011-06-05 17:56:52 ----RD---- C:\Program Files (x86)
2011-06-05 17:52:54 ----A---- C:\Windows\SYSWOW64\log.txt
2011-06-05 17:43:36 ----D---- C:\Windows\system32\drivers\etc
2011-06-05 15:30:29 ----HD---- C:\ProgramData
2011-06-05 15:06:42 ----SHD---- C:\Windows\Installer
2011-06-05 15:06:41 ----SD---- C:\Users\okay\AppData\Roaming\Microsoft
2011-06-05 15:06:29 ----SHD---- C:\System Volume Information
2011-06-05 15:06:25 ----D---- C:\Windows\system32\catroot2
2011-06-05 13:05:22 ----D---- C:\Windows\Prefetch
2011-06-02 17:55:54 ----D---- C:\Windows\Minidump
2011-06-02 17:55:54 ----D---- C:\Windows
2011-06-02 14:36:46 ----D---- C:\video
2011-06-02 11:48:38 ----D---- C:\Program Files (x86)\Jewel Quest 2
2011-05-31 10:16:29 ----D---- C:\Windows\system32\wdi
2011-05-31 10:07:23 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-12-17 538136]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 AMON;AMON; C:\Windows\system32\drivers\amon.sys [2010-12-25 146704]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2010-04-01 3060800]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-02-20 10300800]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-10 158720]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-29 2231584]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-02-02 271872]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2010-03-21 321064]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-05 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-12-10 301104]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-05 16896]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btwampfl;Bluetooth AMP USB Filter; C:\Windows\system32\drivers\btwampfl.sys [2010-03-05 335400]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-02-14 102440]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-13 135720]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-03-01 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-13 21544]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-01 239136]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-12-02 213280]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-03-26 920352]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-18 268824]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files (x86)\Eset\nod32krn.exe [2010-12-25 552064]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-09 250368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-29 243232]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
poprosím o kontrolu logu. Na notebooku sa mi spúšťa program PC security guardian a vypisuje niekoľko vírov a zablokovalo mi to internet explorer. Spustila som Antivirák, našiel 1 vír a bol zmazaný. spustila som scan na superantispyware.
Problém stále je.
Ďakujem
Vladka
Logfile of random's system information tool 1.08 (written by random/random)
Run by okay at 2011-06-05 18:16:04
Microsoft Windows 7 Home Premium
System drive C: has 251 GB (86%) free of 291 GB
Total RAM: 3767 MB (67% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
winlogon.exe
C:\Windows\system32\WLANExt.exe 1808624
\??\C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Program Files (x86)\Eset\nod32krn.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
"C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1480
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\PLFSetI.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files (x86)\Eset\nod32kui.exe"
"C:\ProgramData\520806\PS520_2121.exe" /s /d
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ecab22a3-b321-4c36-91e5-01b24d60173a -SystemEventPortName:HostProcess-48bbd38b-7813-488a-ada2-ec86900a727b -IoCancelEventPortName:HostProcess-2cd8c6a1-9023-4c41-887b-cf10982756d6 -NonStateChangingEventPortName:HostProcess-4e62888f-7551-42f1-8275-70f8b1b7957c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e6c5abbd-c724-4798-82e9-a0291bbd9965
"C:\instal\RSITx64.exe"
"c:\program files\windows defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey BE7D1BE6-1B14-3FAE-EE5D-8637AEDF79D2 -Reinvoke
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for okay.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll [2011-05-20 341048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-20 1007160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-29 9913376]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-03-04 166424]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-03-04 391192]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-03-04 410648]
"PLFSetI"=C:\Windows\PLFSetI.exe [2010-06-15 206208]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2010-03-17 860704]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-05-16 153136]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-04-21 39408]
"PC Security Guardian"=C:\ProgramData\520806\PS520_2121.exe [2011-06-02 2361344]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-05-23 2988928]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-12-24 284696]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2010-04-08 908368]
"nod32kui"=C:\Program Files (x86)\Eset\nod32kui.exe [2010-12-25 949376]
"UpdateReminder"=C:\Program Files (x86)\Eset\UpdateReminder.exe [2010-12-25 434176]
"Microsoft WinUpdate"=C:\Windows\system32\msupdte.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-02-20 269824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-06-05 18:16:05 ----D---- C:\Program Files\trend micro
2011-06-05 18:16:04 ----D---- C:\rsit
2011-06-05 17:56:52 ----D---- C:\Program Files (x86)\SpywareBlaster
2011-06-05 15:30:29 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-06-05 15:30:29 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-06-05 15:21:36 ----D---- C:\ProgramData\Google Updater
2011-06-05 15:06:40 ----D---- C:\Program Files (x86)\Trend Micro
2011-06-05 13:07:22 ----D---- C:\Users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 13:07:22 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-06-05 13:07:18 ----D---- C:\ProgramData\!SASCORE
2011-06-05 13:07:13 ----D---- C:\Program Files\SUPERAntiSpyware
2011-05-26 09:59:04 ----SHD---- C:\Users\okay\AppData\Roaming\PC Security Guardian
2011-05-26 09:56:25 ----SHD---- C:\ProgramData\PSYMKCMVCNG
2011-05-26 09:55:49 ----SHD---- C:\ProgramData\520806
======List of files/folders modified in the last 1 months======
2011-06-05 18:16:05 ----RD---- C:\Program Files
2011-06-05 18:16:05 ----D---- C:\Windows\Temp
2011-06-05 18:15:38 ----D---- C:\instal
2011-06-05 18:06:27 ----AD---- C:\ProgramData\Temp
2011-06-05 18:03:23 ----D---- C:\Windows\system32\config
2011-06-05 17:57:17 ----D---- C:\Windows\System32
2011-06-05 17:57:17 ----D---- C:\Windows\inf
2011-06-05 17:57:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-05 17:56:57 ----D---- C:\Windows\SysWOW64
2011-06-05 17:56:52 ----RD---- C:\Program Files (x86)
2011-06-05 17:52:54 ----A---- C:\Windows\SYSWOW64\log.txt
2011-06-05 17:43:36 ----D---- C:\Windows\system32\drivers\etc
2011-06-05 15:30:29 ----HD---- C:\ProgramData
2011-06-05 15:06:42 ----SHD---- C:\Windows\Installer
2011-06-05 15:06:41 ----SD---- C:\Users\okay\AppData\Roaming\Microsoft
2011-06-05 15:06:29 ----SHD---- C:\System Volume Information
2011-06-05 15:06:25 ----D---- C:\Windows\system32\catroot2
2011-06-05 13:05:22 ----D---- C:\Windows\Prefetch
2011-06-02 17:55:54 ----D---- C:\Windows\Minidump
2011-06-02 17:55:54 ----D---- C:\Windows
2011-06-02 14:36:46 ----D---- C:\video
2011-06-02 11:48:38 ----D---- C:\Program Files (x86)\Jewel Quest 2
2011-05-31 10:16:29 ----D---- C:\Windows\system32\wdi
2011-05-31 10:07:23 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-12-17 538136]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 AMON;AMON; C:\Windows\system32\drivers\amon.sys [2010-12-25 146704]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2010-04-01 3060800]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-02-20 10300800]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-10 158720]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-29 2231584]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-02-02 271872]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2010-03-21 321064]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-05 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-12-10 301104]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-05 16896]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btwampfl;Bluetooth AMP USB Filter; C:\Windows\system32\drivers\btwampfl.sys [2010-03-05 335400]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-02-14 102440]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-13 135720]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-03-01 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-13 21544]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-01 239136]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-12-02 213280]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-03-26 920352]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-18 268824]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files (x86)\Eset\nod32krn.exe [2010-12-25 552064]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-09 250368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-29 243232]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
Re: Prosím o kontrolu logu
Zdravim a pekny vecer preji
A co budem delat s tim nelegalnim NOD32
Po dobehnuti skenu SASem mi sem dejte jeho log
Re: Prosím o kontrolu logu
pekný večer,
to som im aj vytkla, totiž notebook je neterin a šetrí na nesprávnych miestach
ja používam ESS a nemám zatiaľ problém.. aspoň si myslím
prosím Vás kde nájdem program SAS
ďakujem
to som im aj vytkla, totiž notebook je neterin a šetrí na nesprávnych miestach
ja používam ESS a nemám zatiaľ problém.. aspoň si myslím
prosím Vás kde nájdem program SAS
ďakujem
Re: Prosím o kontrolu logu
SAS = SuperAntiSpyware
Ale pokud bude v PC nelegalni zabezpeceni, tak jej odmitam resit - dle pravidel fora (viz zde a a zde bod c.3 ) se nelegalnim SW nezabyvame, jelikoz nelegalni programy jsou vetsinou zdrojem haveti. Navic tim porusujete i autorska prava
, pachate trestny cin a ten jako takovy nebude nasim forem podporovan. Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora
Takze ten cinknuty NOD32 odinstalujte a dejte si tam free reseni (Avast, Avira ci MSE) - pak poprosim o novy log z RSIT
Ale pokud bude v PC nelegalni zabezpeceni, tak jej odmitam resit - dle pravidel fora (viz zde a a zde bod c.3 ) se nelegalnim SW nezabyvame, jelikoz nelegalni programy jsou vetsinou zdrojem haveti. Navic tim porusujete i autorska prava
, pachate trestny cin a ten jako takovy nebude nasim forem podporovan. Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora Takze ten cinknuty NOD32 odinstalujte a dejte si tam free reseni (Avast, Avira ci MSE) - pak poprosim o novy log z RSIT
Re: Prosím o kontrolu logu
log zo SAS
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/05/2011 at 01:54 PM
Application Version : 4.53.1000
Core Rules Database Version : 7202
Trace Rules Database Version: 5014
Scan type : Complete Scan
Total Scan Time : 00:42:28
Memory items scanned : 587
Memory threats detected : 1
Registry items scanned : 14035
Registry threats detected : 3
File items scanned : 28416
File threats detected : 377
Trojan.Agent/Gen-FakeAlert
C:\PROGRAMDATA\520806\PS520_2121.EXE
C:\PROGRAMDATA\520806\PS520_2121.EXE
(x86) [PC Security Guardian] C:\PROGRAMDATA\520806\PS520_2121.EXE
C:\USERS\OKAY\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\PC SECURITY GUARDIAN.LNK
C:\USERS\OKAY\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PC SECURITY GUARDIAN.LNK
C:\USERS\OKAY\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PC SECURITY GUARDIAN.LNK
C:\USERS\OKAY\DESKTOP\COMPUTER.LNK
C:\USERS\OKAY\DESKTOP\PC SECURITY GUARDIAN.LNK
C:\Windows\Prefetch\PS520_2121.EXE-271C34BA.pf
Adware.Tracking Cookie
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@ad.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@doubleclick[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@invitemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@atdmt[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@content.yieldmanager[1].txt
.doubleclick.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
statse.webtrendslive.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adx.zdravie.sk [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adverticum.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adverticum.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
s06.flagcounter.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lfstmedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.azjmp.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.toplist.sk [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.toplist.cz [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@www.googleadservices[4].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@ad.kasa[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@etargetnet[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@toplist[4].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@www.googleadservices[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@ad.yieldmanager[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@adtech[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@statcounter[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@ad2.billboard[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@adbrite[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@b2m.web2media[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@etargetnet[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@content.yieldmanager[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@doubleclick[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@doubleclick[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@komtrack[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@komtrack[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@neckermannde.122.2o7[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@sk.search.etargetnet[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@sk.search.etargetnet[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@toplist[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@toplist[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@www.googleadservices[1].txt
acer.oberon-media.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
ia.media-imdb.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
imgs.adverticum.net [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.jaludo.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.mtvnservices.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.pluska.sk [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.y8.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
memecounter.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.ringier[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[11].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@casalemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adtech[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.pubmatic[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.techbox[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adform[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adnetsk.adocean[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.globalrevgen[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@neckermannde.122.2o7[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@weborama[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@server.iad.liveperson[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@eas.apm.emediate[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.topshopping[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.gamesbannernet[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.caradvice.com[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@serving-sys[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.gamesbannernet[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertures.directtrack[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.centrum[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@vinvest.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.reklamport[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adserver.adtechus[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@azjmp[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.globalrevgen[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@media6degrees[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.clicmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@liveperson[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@harrenmedianetwork[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@invitemedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@linksynergy[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.o2[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@track4u.m4u[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adecn[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@viacom.adbureau[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.carocean.co[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.lupomedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@s.imedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@travidia.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@edsa.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tyredating.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.atlas[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adx.zdravie[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lfstmedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tacoda.at.atwola[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.gameforge[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@invitemedia[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@server.cpmstar[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.new.autovia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.ad4game[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@popularscreensavers[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@chitika[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lagardere2.solution.weborama[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www8.addfreestats[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www3.smartadserver[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediabrandsww[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@sk.static.etargetnet[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tripod[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advert.istanbul[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertising[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@genertelsk.solution.weborama[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.sexigirl[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adecn[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@teensgirlsgames[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@collective-media[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@revsci[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.pricemania[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adverticum[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking1.aleadpay[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@doubleclick[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.gamersmedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.monogram[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.profimedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.atlas[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@paypal.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@media6degrees[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.epi[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@yieldmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@nextag[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@yadro[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lgelectronics.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adtech[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@in.getclicky[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.superdeal[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.1001hry[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediaplex[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.webme[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@overture[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mywebsearch[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mmotraffic[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adfarm1.adition[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adnetsk.adocean[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.horyzon-media[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.joj[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[10].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@sk.static.etargetnet[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.3sfmedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.joj[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.onlinepocasie[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statse.webtrendslive[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adnetsk.adocean[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@at.atwola[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@apmebf[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adserver.xf8[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mmotraffic[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.gigaserver[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@snowboard-zezula[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mm.chitika[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@server.cpmstar[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.advertsystem[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.forma[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@2o7[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@2o7[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@acer.oberon-media[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.new.autovia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.reklamport[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.wz[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.zanox[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.zanox[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.zenskyweb[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[11].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adecn[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.ad4game[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.pubmatic[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.glispa[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.glispa[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.intergi[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.inviziads[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.mojasvadba[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.petpop[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertures.directtrack[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.vip[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads2.itnews[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adserver.adtechus[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adtech[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertising[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@apmebf[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@audit.median[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@azjmp[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@azjmp[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@casalemedia[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@chitika[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.umstudio[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counters.gigya[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@cz5.clickzs[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@doubleclick[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@edsa.122.2o7[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@hearstmagazines.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@interland.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@imrworldwide[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@imrworldwide[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@interclick[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@invitemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lfstmedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@media6degrees[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediabrandsww[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediaplex[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@neckermannde.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@nissaneurope.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@pianomedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@popularscreensavers[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@revsci[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ru4[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@sk.static.etargetnet[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@specificclick[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@stat.mystat[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statse.webtrendslive[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.gameforge[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[11].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@track.adform[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@track4u.m4u[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@usenext[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@user.lucidmedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@viaviralvideo.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@viewablemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@webmasterplan[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@weborama[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.burstnet[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.etracker[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.etracker[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.mediahouse[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.usenext[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www6.addfreestats[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@xiti[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@xiti[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@zedo[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@www.windowsmedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@content.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@www.windowsmedia[1].txt
Browser Hijacker.Internet Explorer Settings Hijack
(x86) HKU\S-1-5-21-3463257822-2106436174-1310032169-1000_Classes\Software\Microsoft\Internet Explorer\SearchScopes#URL [ http://findgala.com/?&uid=2121&q={searchTerms} ]
Trojan.Unclassified/MSUPDTE-Fake
(x86) HKLM\Software\Microsoft\Windows\CurrentVersion\Run#Microsoft WinUpdate [ C:\Windows\system32\msupdte.exe ]
Nový log RSIT
Logfile of random's system information tool 1.08 (written by random/random)
Run by okay at 2011-06-05 19:08:38
Microsoft Windows 7 Home Premium
System drive C: has 250 GB (86%) free of 291 GB
Total RAM: 3767 MB (68% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 3860224
\??\C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
"C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\PLFSetI.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1004
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\ProgramData\520806\PS520_2121.exe" /s /d
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
C:\Windows\system32\igfxext.exe -Embedding
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d2873a12-906b-47a9-9557-74f8dc15631a -SystemEventPortName:HostProcess-a2ca6e20-e400-4b55-a743-9d9422a89dc5 -IoCancelEventPortName:HostProcess-3aac4e12-baed-44b2-ab78-6cb8d99a107d -NonStateChangingEventPortName:HostProcess-ec8f1c7b-7067-450e-a5fb-512afcbd714e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f49c4517-e00b-4c44-a4a5-39fc7819f50f
"taskhost.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000ed0
\??\C:\Windows\system32\conhost.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min /NOSPLASH /SETUPSTART
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\instal\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for okay.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll [2011-05-20 341048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-20 1007160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-29 9913376]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-03-04 166424]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-03-04 391192]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-03-04 410648]
"PLFSetI"=C:\Windows\PLFSetI.exe [2010-06-15 206208]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2010-03-17 860704]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-05-16 153136]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-04-21 39408]
"PC Security Guardian"=C:\ProgramData\520806\PS520_2121.exe [2011-06-02 2361344]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-05-23 2988928]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-12-24 284696]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2010-04-08 908368]
"Microsoft WinUpdate"=C:\Windows\system32\msupdte.exe []
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2011-03-28 281768]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-02-20 269824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-06-05 19:05:43 ----D---- C:\ProgramData\Avira
2011-06-05 19:05:43 ----D---- C:\Program Files (x86)\Avira
2011-06-05 19:05:43 ----A---- C:\Windows\system32\drivers\avipbb.sys
2011-06-05 19:05:43 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2011-06-05 18:49:50 ----SHD---- C:\Config.Msi
2011-06-05 18:16:05 ----D---- C:\Program Files\trend micro
2011-06-05 18:16:04 ----D---- C:\rsit
2011-06-05 15:30:29 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-06-05 15:30:29 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-06-05 15:21:36 ----D---- C:\ProgramData\Google Updater
2011-06-05 15:06:40 ----D---- C:\Program Files (x86)\Trend Micro
2011-06-05 13:07:22 ----D---- C:\Users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 13:07:22 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-06-05 13:07:18 ----D---- C:\ProgramData\!SASCORE
2011-06-05 13:07:13 ----D---- C:\Program Files\SUPERAntiSpyware
2011-05-26 09:59:04 ----SHD---- C:\Users\okay\AppData\Roaming\PC Security Guardian
2011-05-26 09:56:25 ----SHD---- C:\ProgramData\PSYMKCMVCNG
2011-05-26 09:55:49 ----SHD---- C:\ProgramData\520806
======List of files/folders modified in the last 1 months======
2011-06-05 19:08:39 ----D---- C:\Windows\Temp
2011-06-05 19:05:47 ----D---- C:\Windows\system32\catroot
2011-06-05 19:05:43 ----RD---- C:\Program Files (x86)
2011-06-05 19:05:43 ----HD---- C:\ProgramData
2011-06-05 19:05:43 ----D---- C:\Windows\system32\drivers
2011-06-05 19:04:17 ----D---- C:\Windows\System32
2011-06-05 19:04:17 ----D---- C:\Windows\inf
2011-06-05 19:04:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-05 19:03:18 ----D---- C:\instal
2011-06-05 18:51:19 ----D---- C:\Windows\system32\config
2011-06-05 18:51:00 ----A---- C:\Windows\SYSWOW64\log.txt
2011-06-05 18:50:38 ----D---- C:\Windows\SysWOW64
2011-06-05 18:50:38 ----D---- C:\Program Files (x86)\ESET
2011-06-05 18:49:51 ----SHD---- C:\Windows\Installer
2011-06-05 18:49:51 ----SD---- C:\Users\okay\AppData\Roaming\Microsoft
2011-06-05 18:49:32 ----SHD---- C:\System Volume Information
2011-06-05 18:16:05 ----RD---- C:\Program Files
2011-06-05 18:06:27 ----AD---- C:\ProgramData\Temp
2011-06-05 17:43:36 ----D---- C:\Windows\system32\drivers\etc
2011-06-05 15:06:25 ----D---- C:\Windows\system32\catroot2
2011-06-05 13:05:22 ----D---- C:\Windows\Prefetch
2011-06-02 17:55:54 ----D---- C:\Windows\Minidump
2011-06-02 17:55:54 ----D---- C:\Windows
2011-06-02 14:36:46 ----D---- C:\video
2011-06-02 11:48:38 ----D---- C:\Program Files (x86)\Jewel Quest 2
2011-05-31 10:16:29 ----D---- C:\Windows\system32\wdi
2011-05-31 10:07:23 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-12-17 538136]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-04-01 116568]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-04-01 83120]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2010-04-01 3060800]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-02-20 10300800]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-10 158720]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-29 2231584]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-02-02 271872]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2010-03-21 321064]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-05 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-12-10 301104]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-05 16896]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btwampfl;Bluetooth AMP USB Filter; C:\Windows\system32\drivers\btwampfl.sys [2010-03-05 335400]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-02-14 102440]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-13 135720]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-03-01 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-13 21544]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-01 239136]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-12-02 213280]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-03-28 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-03-26 920352]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-18 268824]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-09 250368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-29 243232]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/05/2011 at 01:54 PM
Application Version : 4.53.1000
Core Rules Database Version : 7202
Trace Rules Database Version: 5014
Scan type : Complete Scan
Total Scan Time : 00:42:28
Memory items scanned : 587
Memory threats detected : 1
Registry items scanned : 14035
Registry threats detected : 3
File items scanned : 28416
File threats detected : 377
Trojan.Agent/Gen-FakeAlert
C:\PROGRAMDATA\520806\PS520_2121.EXE
C:\PROGRAMDATA\520806\PS520_2121.EXE
(x86) [PC Security Guardian] C:\PROGRAMDATA\520806\PS520_2121.EXE
C:\USERS\OKAY\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\PC SECURITY GUARDIAN.LNK
C:\USERS\OKAY\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PC SECURITY GUARDIAN.LNK
C:\USERS\OKAY\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PC SECURITY GUARDIAN.LNK
C:\USERS\OKAY\DESKTOP\COMPUTER.LNK
C:\USERS\OKAY\DESKTOP\PC SECURITY GUARDIAN.LNK
C:\Windows\Prefetch\PS520_2121.EXE-271C34BA.pf
Adware.Tracking Cookie
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@ad.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@doubleclick[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@invitemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@atdmt[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@content.yieldmanager[1].txt
.doubleclick.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
statse.webtrendslive.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adx.zdravie.sk [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adverticum.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adverticum.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
s06.flagcounter.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lfstmedia.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.azjmp.com [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.toplist.sk [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.toplist.cz [ C:\Users\okay\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@www.googleadservices[4].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@ad.kasa[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@etargetnet[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@toplist[4].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@www.googleadservices[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@ad.yieldmanager[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@adtech[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@statcounter[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@ad2.billboard[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@adbrite[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@b2m.web2media[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@etargetnet[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@content.yieldmanager[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@doubleclick[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@doubleclick[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@komtrack[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@komtrack[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@neckermannde.122.2o7[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@sk.search.etargetnet[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@sk.search.etargetnet[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@toplist[1].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@toplist[2].txt
C:\Users\okay\AppData\Local\Temp\Low\Cookies\okay@www.googleadservices[1].txt
acer.oberon-media.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
ia.media-imdb.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
imgs.adverticum.net [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.jaludo.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.mtvnservices.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.pluska.sk [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
media.y8.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
memecounter.com [ C:\Users\okay\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\Z843572H ]
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.ringier[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[11].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@casalemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adtech[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.pubmatic[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.techbox[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adform[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adnetsk.adocean[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.globalrevgen[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@neckermannde.122.2o7[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@weborama[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@server.iad.liveperson[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@eas.apm.emediate[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.topshopping[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.gamesbannernet[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.caradvice.com[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@serving-sys[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.gamesbannernet[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertures.directtrack[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.centrum[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@vinvest.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.reklamport[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adserver.adtechus[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@azjmp[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.globalrevgen[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@media6degrees[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.clicmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@liveperson[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@harrenmedianetwork[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@invitemedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@linksynergy[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.o2[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@track4u.m4u[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adecn[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@viacom.adbureau[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.carocean.co[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.lupomedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@s.imedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@travidia.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@edsa.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tyredating.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.atlas[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adx.zdravie[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lfstmedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tacoda.at.atwola[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.gameforge[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@invitemedia[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@server.cpmstar[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.new.autovia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.ad4game[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@popularscreensavers[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@chitika[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lagardere2.solution.weborama[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www8.addfreestats[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www3.smartadserver[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediabrandsww[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@sk.static.etargetnet[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tripod[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advert.istanbul[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertising[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@genertelsk.solution.weborama[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.sexigirl[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adecn[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@teensgirlsgames[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@collective-media[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@revsci[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.pricemania[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adverticum[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking1.aleadpay[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@doubleclick[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.gamersmedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.monogram[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.profimedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.atlas[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@paypal.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@media6degrees[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.epi[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@yieldmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@nextag[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@yadro[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lgelectronics.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adtech[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@in.getclicky[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.superdeal[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.1001hry[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediaplex[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.webme[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@overture[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mywebsearch[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mmotraffic[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adfarm1.adition[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adnetsk.adocean[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.horyzon-media[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.joj[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[10].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@sk.static.etargetnet[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.3sfmedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.joj[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.onlinepocasie[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statse.webtrendslive[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adnetsk.adocean[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@at.atwola[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tribalfusion[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@apmebf[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adserver.xf8[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mmotraffic[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.yieldmanager[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.gigaserver[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@snowboard-zezula[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mm.chitika[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@server.cpmstar[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.advertsystem[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.forma[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@2o7[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@2o7[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@acer.oberon-media[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.new.autovia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.reklamport[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad1.proklik[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.sitelement[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.wz[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.zanox[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.zanox[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad.zenskyweb[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[11].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ad2.billboard[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adbrite[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adecn[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.ad4game[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.pubmatic[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.glispa[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.glispa[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.intergi[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.inviziads[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.mojasvadba[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.petpop[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertures.directtrack[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads.vip[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ads2.itnews[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adserver.adtechus[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@adtech[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@advertising[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@apmebf[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@atdmt[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@audit.median[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@azjmp[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@azjmp[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@b2m.web2media[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@casalemedia[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@chitika[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@content.yieldmanager[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.cnw[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counter.umstudio[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@counters.gigya[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@cz5.clickzs[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@doubleclick[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@edsa.122.2o7[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[7].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@etargetnet[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@fastclick[6].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@hearstmagazines.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@interland.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@imrworldwide[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@imrworldwide[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@interclick[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@invitemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@komtrack[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@lfstmedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@media6degrees[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediabrandsww[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@mediaplex[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@neckermannde.122.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@nissaneurope.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@pianomedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@popularscreensavers[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@revsci[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@ru4[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@sk.static.etargetnet[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@smartadserver[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@specificclick[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@stat.mystat[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statcounter[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@statse.webtrendslive[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tracking.gameforge[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[11].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[5].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@toplist[9].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@track.adform[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@track4u.m4u[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@tradedoubler[4].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@usenext[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@user.lucidmedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@viaviralvideo.112.2o7[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@viewablemedia[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@webmasterplan[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@weborama[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.burstnet[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.etracker[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.etracker[3].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.googleadservices[8].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.mediahouse[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www.usenext[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@www6.addfreestats[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@xiti[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@xiti[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\Low\okay@zedo[1].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@www.windowsmedia[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@content.yieldmanager[2].txt
C:\Users\okay\AppData\Roaming\Microsoft\Windows\Cookies\okay@www.windowsmedia[1].txt
Browser Hijacker.Internet Explorer Settings Hijack
(x86) HKU\S-1-5-21-3463257822-2106436174-1310032169-1000_Classes\Software\Microsoft\Internet Explorer\SearchScopes#URL [ http://findgala.com/?&uid=2121&q={searchTerms} ]
Trojan.Unclassified/MSUPDTE-Fake
(x86) HKLM\Software\Microsoft\Windows\CurrentVersion\Run#Microsoft WinUpdate [ C:\Windows\system32\msupdte.exe ]
Nový log RSIT
Logfile of random's system information tool 1.08 (written by random/random)
Run by okay at 2011-06-05 19:08:38
Microsoft Windows 7 Home Premium
System drive C: has 250 GB (86%) free of 291 GB
Total RAM: 3767 MB (68% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 3860224
\??\C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
"C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Windows\PLFSetI.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1004
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\ProgramData\520806\PS520_2121.exe" /s /d
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
C:\Windows\system32\igfxext.exe -Embedding
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Launch Manager\LMworker.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\RunDll32.exe "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d2873a12-906b-47a9-9557-74f8dc15631a -SystemEventPortName:HostProcess-a2ca6e20-e400-4b55-a743-9d9422a89dc5 -IoCancelEventPortName:HostProcess-3aac4e12-baed-44b2-ab78-6cb8d99a107d -NonStateChangingEventPortName:HostProcess-ec8f1c7b-7067-450e-a5fb-512afcbd714e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f49c4517-e00b-4c44-a4a5-39fc7819f50f
"taskhost.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000ed0
\??\C:\Windows\system32\conhost.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min /NOSPLASH /SETUPSTART
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\instal\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for okay.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll [2011-05-20 341048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-20 1007160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-05-20 409776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-05-20 305328]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-29 9913376]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-03-04 166424]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-03-04 391192]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-03-04 410648]
"PLFSetI"=C:\Windows\PLFSetI.exe [2010-06-15 206208]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2010-03-17 860704]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-05-16 153136]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-04-21 39408]
"PC Security Guardian"=C:\ProgramData\520806\PS520_2121.exe [2011-06-02 2361344]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-05-23 2988928]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-12-24 284696]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2010-04-08 908368]
"Microsoft WinUpdate"=C:\Windows\system32\msupdte.exe []
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2011-03-28 281768]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-02-20 269824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-06-05 19:05:43 ----D---- C:\ProgramData\Avira
2011-06-05 19:05:43 ----D---- C:\Program Files (x86)\Avira
2011-06-05 19:05:43 ----A---- C:\Windows\system32\drivers\avipbb.sys
2011-06-05 19:05:43 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2011-06-05 18:49:50 ----SHD---- C:\Config.Msi
2011-06-05 18:16:05 ----D---- C:\Program Files\trend micro
2011-06-05 18:16:04 ----D---- C:\rsit
2011-06-05 15:30:29 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-06-05 15:30:29 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-06-05 15:21:36 ----D---- C:\ProgramData\Google Updater
2011-06-05 15:06:40 ----D---- C:\Program Files (x86)\Trend Micro
2011-06-05 13:07:22 ----D---- C:\Users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 13:07:22 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-06-05 13:07:18 ----D---- C:\ProgramData\!SASCORE
2011-06-05 13:07:13 ----D---- C:\Program Files\SUPERAntiSpyware
2011-05-26 09:59:04 ----SHD---- C:\Users\okay\AppData\Roaming\PC Security Guardian
2011-05-26 09:56:25 ----SHD---- C:\ProgramData\PSYMKCMVCNG
2011-05-26 09:55:49 ----SHD---- C:\ProgramData\520806
======List of files/folders modified in the last 1 months======
2011-06-05 19:08:39 ----D---- C:\Windows\Temp
2011-06-05 19:05:47 ----D---- C:\Windows\system32\catroot
2011-06-05 19:05:43 ----RD---- C:\Program Files (x86)
2011-06-05 19:05:43 ----HD---- C:\ProgramData
2011-06-05 19:05:43 ----D---- C:\Windows\system32\drivers
2011-06-05 19:04:17 ----D---- C:\Windows\System32
2011-06-05 19:04:17 ----D---- C:\Windows\inf
2011-06-05 19:04:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-05 19:03:18 ----D---- C:\instal
2011-06-05 18:51:19 ----D---- C:\Windows\system32\config
2011-06-05 18:51:00 ----A---- C:\Windows\SYSWOW64\log.txt
2011-06-05 18:50:38 ----D---- C:\Windows\SysWOW64
2011-06-05 18:50:38 ----D---- C:\Program Files (x86)\ESET
2011-06-05 18:49:51 ----SHD---- C:\Windows\Installer
2011-06-05 18:49:51 ----SD---- C:\Users\okay\AppData\Roaming\Microsoft
2011-06-05 18:49:32 ----SHD---- C:\System Volume Information
2011-06-05 18:16:05 ----RD---- C:\Program Files
2011-06-05 18:06:27 ----AD---- C:\ProgramData\Temp
2011-06-05 17:43:36 ----D---- C:\Windows\system32\drivers\etc
2011-06-05 15:06:25 ----D---- C:\Windows\system32\catroot2
2011-06-05 13:05:22 ----D---- C:\Windows\Prefetch
2011-06-02 17:55:54 ----D---- C:\Windows\Minidump
2011-06-02 17:55:54 ----D---- C:\Windows
2011-06-02 14:36:46 ----D---- C:\video
2011-06-02 11:48:38 ----D---- C:\Program Files (x86)\Jewel Quest 2
2011-05-31 10:16:29 ----D---- C:\Windows\system32\wdi
2011-05-31 10:07:23 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-12-17 538136]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-04-01 116568]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60464]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-04-01 83120]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2010-04-01 3060800]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-02-20 10300800]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-10 158720]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-29 2231584]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-02-02 271872]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2010-03-21 321064]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-05 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-12-10 301104]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-05 16896]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btwampfl;Bluetooth AMP USB Filter; C:\Windows\system32\drivers\btwampfl.sys [2010-03-05 335400]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-02-14 102440]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-13 135720]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-03-01 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-13 21544]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-03-01 239136]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-12-02 213280]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-03-28 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2010-03-26 920352]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-18 268824]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-09 250368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-29 243232]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
S3 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
Re: Prosím o kontrolu logu
- Pokud ho havet blokuje, pouzijte jeden z nasledujicich
motji napsal: Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr
Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne temer okamzite a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Ted nerestartujte PC - prisli byste o ucinek RKillu
- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Prosím o kontrolu logu
ComboFix 11-06-05.02 - okay . 06. 2011 19:38:50.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2595 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\users\okay\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PC Security Guardian.lnk
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cb.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cb.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cid.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cid.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ddv.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ddv.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ddv.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fix.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fix.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FS.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FW.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FW.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FW.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\grid.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\grid.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\grid.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ppal.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ppal.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\runddl.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SM.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SM.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\snl2w.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\snl2w.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\std.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\std.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Start Menu\PC Security Guardian.lnk
c:\users\okay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Security Guardian.lnk
c:\users\okay\AppData\Roaming\PC Security Guardian
c:\users\okay\AppData\Roaming\PC Security Guardian\Instructions.ini
c:\users\okay\Desktop\PC Security Guardian.lnk
c:\windows\SysWow64\msupdte.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-05 17:42 . 2011-06-05 17:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 17:37 . 2011-06-05 17:37 -------- d-----w- C:\32788R22FWJFW
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-05 13:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-05 13:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
2011-05-26 07:56 . 2011-05-26 07:56 -------- d-sh--w- c:\programdata\PSYMKCMVCNG
2011-05-26 07:55 . 2011-06-05 16:51 -------- d-sh--w- c:\programdata\520806
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-21 39408]
"PC Security Guardian"="c:\programdata\520806\PS520_2121.exe" [2011-06-02 2361344]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" -d
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe"
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
.
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 20:44]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 20:44]
.
2011-06-01 c:\windows\Tasks\Norton Security Scan for okay.job
- c:\progra~2\NORTON~2\Engine\300~1.103\Nss.exe [2011-03-15 19:15]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=041b&m=aspire_5741z&r=27361210f505l0404z185t46k2q26s
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-Microsoft WinUpdate - c:\windows\system32\msupdte.exe
Toolbar-Locked - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~2\UNWISE.EXE
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-06-05 19:45:01
ComboFix-quarantined-files.txt 2011-06-05 17:45
.
Pre-Run: 262 334 754 816 bytes free
Post-Run: 262 164 291 584 bytes free
.
- - End Of File - - 6A7EBE78F193A587BD3A0A6A126AAFBC
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2595 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\users\okay\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PC Security Guardian.lnk
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cb.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cb.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cid.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\cid.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ddv.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ddv.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ddv.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\delfile.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\dudl.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\eb.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\energy.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fan.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fix.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\fix.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FS.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FW.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FW.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\FW.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\gid.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\grid.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\grid.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\grid.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\kernel32.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\pal.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ppal.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\ppal.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\runddl.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\sld.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SM.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\SM.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\snl2w.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\snl2w.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\std.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\std.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tempdoc.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.dll
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.exe
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
c:\users\okay\AppData\Roaming\Microsoft\Windows\Recent\tjd.tmp
c:\users\okay\AppData\Roaming\Microsoft\Windows\Start Menu\PC Security Guardian.lnk
c:\users\okay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Security Guardian.lnk
c:\users\okay\AppData\Roaming\PC Security Guardian
c:\users\okay\AppData\Roaming\PC Security Guardian\Instructions.ini
c:\users\okay\Desktop\PC Security Guardian.lnk
c:\windows\SysWow64\msupdte.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-05 17:42 . 2011-06-05 17:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 17:37 . 2011-06-05 17:37 -------- d-----w- C:\32788R22FWJFW
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-05 13:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-05 13:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
2011-05-26 07:56 . 2011-05-26 07:56 -------- d-sh--w- c:\programdata\PSYMKCMVCNG
2011-05-26 07:55 . 2011-06-05 16:51 -------- d-sh--w- c:\programdata\520806
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-21 39408]
"PC Security Guardian"="c:\programdata\520806\PS520_2121.exe" [2011-06-02 2361344]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" -d
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe"
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
.
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 135664]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 20:44]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-12-26 20:44]
.
2011-06-01 c:\windows\Tasks\Norton Security Scan for okay.job
- c:\progra~2\NORTON~2\Engine\300~1.103\Nss.exe [2011-03-15 19:15]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=041b&m=aspire_5741z&r=27361210f505l0404z185t46k2q26s
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-Microsoft WinUpdate - c:\windows\system32\msupdte.exe
Toolbar-Locked - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~2\UNWISE.EXE
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-06-05 19:45:01
ComboFix-quarantined-files.txt 2011-06-05 17:45
.
Pre-Run: 262 334 754 816 bytes free
Post-Run: 262 164 291 584 bytes free
.
- - End Of File - - 6A7EBE78F193A587BD3A0A6A126AAFBC
Re: Prosím o kontrolu logu
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: File:: C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\Norton Security Scan for okay.job Folder:: C:\Program Files (x86)\Eset Collect:: c:\programdata\520806\PS520_2121.exe Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=- "swg"=- "PC Security Guardian"=- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"=- "BackupManagerTray"=- "EgisUpdate"=- "EgisTecPMMUpdate"=- "SuiteTray"=- Driver:: gupdate gupdatem DDS:: mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... 5t46k2q26s RegLock:: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] Reboot::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: Prosím o kontrolu logu
ComboFix 11-06-05.02 - okay . 06. 2011 21:42:25.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2433 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
Command switches used :: c:\users\okay\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\Norton Security Scan for okay.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Eset
c:\program files (x86)\Eset\Install\advheur.nup
c:\program files (x86)\Eset\Install\archs.nup
c:\program files (x86)\Eset\Install\engine.nup
c:\program files (x86)\Eset\Install\charon.nup
c:\program files (x86)\Eset\Install\main.dll
c:\program files (x86)\Eset\Install\mainlang.dll
c:\program files (x86)\Eset\Install\mfc42.dll
c:\program files (x86)\Eset\Install\mfc42u.dll
c:\program files (x86)\Eset\Install\msvcrt.dll
c:\program files (x86)\Eset\Install\ntbasesk.nup
c:\program files (x86)\Eset\Install\ntinetsk.nup
c:\program files (x86)\Eset\Install\ntstdsk.nup
c:\program files (x86)\Eset\Install\pwscan.nup
c:\program files (x86)\Eset\Install\readme.txt
c:\program files (x86)\Eset\Install\setup.exe
c:\program files (x86)\Eset\Install\setup.xml
c:\program files (x86)\Eset\Install\utilmod.nup
c:\program files (x86)\Eset\nod32.007
c:\programdata\520806\PS520_2121.exe
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\tasks\Norton Security Scan for okay.job
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-05 19:45 . 2011-06-05 19:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-05 13:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-05 13:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
2011-05-26 07:56 . 2011-05-26 07:56 -------- d-sh--w- c:\programdata\PSYMKCMVCNG
2011-05-26 07:55 . 2011-06-05 19:45 -------- d-sh--w- c:\programdata\520806
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-05_17.42.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-15 06:13 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-05 19:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-05 19:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-06-05 19:46 . 2011-06-05 19:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-06-05 19:46 . 2011-06-05 19:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:34 . 2011-06-05 19:04 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:34 . 2011-06-05 17:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF20632.cfxxe" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files (x86)\Launch Manager\LMworker.exe
c:\windows\SysWOW64\RunDll32.exe
.
**************************************************************************
.
Completion time: 2011-06-05 21:52:45 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-05 19:52
ComboFix2.txt 2011-06-05 17:45
.
Pre-Run: 261 769 224 192 bytes free
Post-Run: 261 269 909 504 bytes free
.
- - End Of File - - DF73DE4F9EE73DC57214D0E1509E287E
Upload was successful
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2433 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
Command switches used :: c:\users\okay\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\Norton Security Scan for okay.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Eset
c:\program files (x86)\Eset\Install\advheur.nup
c:\program files (x86)\Eset\Install\archs.nup
c:\program files (x86)\Eset\Install\engine.nup
c:\program files (x86)\Eset\Install\charon.nup
c:\program files (x86)\Eset\Install\main.dll
c:\program files (x86)\Eset\Install\mainlang.dll
c:\program files (x86)\Eset\Install\mfc42.dll
c:\program files (x86)\Eset\Install\mfc42u.dll
c:\program files (x86)\Eset\Install\msvcrt.dll
c:\program files (x86)\Eset\Install\ntbasesk.nup
c:\program files (x86)\Eset\Install\ntinetsk.nup
c:\program files (x86)\Eset\Install\ntstdsk.nup
c:\program files (x86)\Eset\Install\pwscan.nup
c:\program files (x86)\Eset\Install\readme.txt
c:\program files (x86)\Eset\Install\setup.exe
c:\program files (x86)\Eset\Install\setup.xml
c:\program files (x86)\Eset\Install\utilmod.nup
c:\program files (x86)\Eset\nod32.007
c:\programdata\520806\PS520_2121.exe
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\tasks\Norton Security Scan for okay.job
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-05 19:45 . 2011-06-05 19:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-05 13:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-05 13:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
2011-05-26 07:56 . 2011-05-26 07:56 -------- d-sh--w- c:\programdata\PSYMKCMVCNG
2011-05-26 07:55 . 2011-06-05 19:45 -------- d-sh--w- c:\programdata\520806
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-05_17.42.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-15 06:13 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-05 19:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-05 19:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-06-05 19:46 . 2011-06-05 19:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-06-05 19:46 . 2011-06-05 19:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:34 . 2011-06-05 19:04 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:34 . 2011-06-05 17:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF20632.cfxxe" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files (x86)\Launch Manager\LMworker.exe
c:\windows\SysWOW64\RunDll32.exe
.
**************************************************************************
.
Completion time: 2011-06-05 21:52:45 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-05 19:52
ComboFix2.txt 2011-06-05 17:45
.
Pre-Run: 261 769 224 192 bytes free
Post-Run: 261 269 909 504 bytes free
.
- - End Of File - - DF73DE4F9EE73DC57214D0E1509E287E
Upload was successful
Re: Prosím o kontrolu logu
Jeste jeden skrip, postup je stejny
Kód: Vybrat vše
KillAll::
Folder::
c:\programdata\520806
Reboot::Re: Prosím o kontrolu logu
ComboFix 11-06-05.02 - okay . 06. 2011 18:27:27.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2392 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
Command switches used :: c:\users\okay\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\520806
c:\programdata\520806\422742.reg
c:\programdata\520806\BackUp\Bluetooth.lnk
c:\programdata\520806\mcp.ico
c:\programdata\520806\PSG.ico
.
.
((((((((((((((((((((((((( Files Created from 2011-05-06 to 2011-06-06 )))))))))))))))))))))))))))))))
.
.
2011-06-06 16:31 . 2011-06-06 16:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 19:59 . 2011-06-05 19:59 -------- d-----w- c:\users\okay\AppData\Roaming\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-05 13:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-05 13:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
2011-05-26 07:56 . 2011-05-26 07:56 -------- d-sh--w- c:\programdata\PSYMKCMVCNG
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-05_17.42.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-21 10:29 . 2011-06-06 16:20 38146 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-06-06 16:20 37148 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-06-15 06:13 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-06 16:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-06 16:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:05 . 2011-06-06 16:20 7222 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3463257822-2106436174-1310032169-1000_UserData.bin
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-06-06 16:31 . 2011-06-06 16:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-06-06 16:31 . 2011-06-06 16:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:34 . 2011-06-05 17:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-06-06 16:29 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\RunDll32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
.
**************************************************************************
.
Completion time: 2011-06-06 18:37:38 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-06 16:37
ComboFix2.txt 2011-06-05 19:55
ComboFix3.txt 2011-06-05 17:45
.
Pre-Run: 261 319 954 432 bytes free
Post-Run: 261 063 606 272 bytes free
.
- - End Of File - - 527F44C41AFE195B7F8ADD0FE39A6C79
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2392 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
Command switches used :: c:\users\okay\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\520806
c:\programdata\520806\422742.reg
c:\programdata\520806\BackUp\Bluetooth.lnk
c:\programdata\520806\mcp.ico
c:\programdata\520806\PSG.ico
.
.
((((((((((((((((((((((((( Files Created from 2011-05-06 to 2011-06-06 )))))))))))))))))))))))))))))))
.
.
2011-06-06 16:31 . 2011-06-06 16:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 19:59 . 2011-06-05 19:59 -------- d-----w- c:\users\okay\AppData\Roaming\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-05 13:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-05 13:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
2011-05-26 07:56 . 2011-05-26 07:56 -------- d-sh--w- c:\programdata\PSYMKCMVCNG
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-05_17.42.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-21 10:29 . 2011-06-06 16:20 38146 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-06-06 16:20 37148 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-06-15 06:13 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-06 16:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-06 16:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:05 . 2011-06-06 16:20 7222 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3463257822-2106436174-1310032169-1000_UserData.bin
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-06-06 16:31 . 2011-06-06 16:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-06-06 16:31 . 2011-06-06 16:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:34 . 2011-06-05 17:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-06-06 16:29 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\RunDll32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
.
**************************************************************************
.
Completion time: 2011-06-06 18:37:38 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-06 16:37
ComboFix2.txt 2011-06-05 19:55
ComboFix3.txt 2011-06-05 17:45
.
Pre-Run: 261 319 954 432 bytes free
Post-Run: 261 063 606 272 bytes free
.
- - End Of File - - 527F44C41AFE195B7F8ADD0FE39A6C79
Re: Prosím o kontrolu logu
Kód: Vybrat vše
KillAll::
Folder::
c:\programdata\PSYMKCMVCNG
Reboot::Re: Prosím o kontrolu logu
avira je aktualizovana, spyboot je preč
ComboFix 11-06-05.02 - okay . 06. 2011 21:15:18.4.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2497 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
Command switches used :: c:\users\okay\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\PSYMKCMVCNG
c:\programdata\PSYMKCMVCNG\PSLLEXNILJG.cfg
.
.
((((((((((((((((((((((((( Files Created from 2011-05-06 to 2011-06-06 )))))))))))))))))))))))))))))))
.
.
2011-06-06 19:18 . 2011-06-06 19:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 19:59 . 2011-06-05 19:59 -------- d-----w- c:\users\okay\AppData\Roaming\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-06 19:11 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-06 19:11 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-05_17.42.47 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-06-05 17:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-06-06 19:09 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-06-05 17:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-06 19:09 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-06 19:09 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-06-05 17:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-04-21 10:29 . 2011-06-06 16:33 38704 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-06-06 18:52 37180 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-06-15 06:13 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-19 22:12 . 2011-06-06 19:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-06 19:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:05 . 2011-06-06 18:52 7474 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3463257822-2106436174-1310032169-1000_UserData.bin
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-06-06 19:19 . 2011-06-06 19:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-06-06 19:19 . 2011-06-06 19:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:34 . 2011-06-05 17:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-06-06 19:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\RunDll32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
.
**************************************************************************
.
Completion time: 2011-06-06 21:25:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-06 19:25
ComboFix2.txt 2011-06-06 16:37
ComboFix3.txt 2011-06-05 19:55
ComboFix4.txt 2011-06-05 17:45
.
Pre-Run: 260 942 635 008 bytes free
Post-Run: 260 861 751 296 bytes free
.
- - End Of File - - 87E1C3F09639E3356BDECEC60F663CD1
ComboFix 11-06-05.02 - okay . 06. 2011 21:15:18.4.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3767.2497 [GMT 2:00]
Running from: c:\users\okay\Desktop\ComboFix.exe
Command switches used :: c:\users\okay\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\PSYMKCMVCNG
c:\programdata\PSYMKCMVCNG\PSLLEXNILJG.cfg
.
.
((((((((((((((((((((((((( Files Created from 2011-05-06 to 2011-06-06 )))))))))))))))))))))))))))))))
.
.
2011-06-06 19:18 . 2011-06-06 19:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-05 19:59 . 2011-06-05 19:59 -------- d-----w- c:\users\okay\AppData\Roaming\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\programdata\Avira
2011-06-05 17:05 . 2011-06-05 17:05 -------- d-----w- c:\program files (x86)\Avira
2011-06-05 17:05 . 2011-04-01 15:07 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-05 17:05 . 2011-04-01 15:07 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- c:\program files\trend micro
2011-06-05 16:16 . 2011-06-05 16:16 -------- d-----w- C:\rsit
2011-06-05 13:30 . 2011-06-06 19:11 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-05 13:30 . 2011-06-06 19:11 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2011-06-05 13:21 . 2011-06-05 13:22 -------- d-----w- c:\programdata\Google Updater
2011-06-05 13:06 . 2011-06-05 13:06 -------- d-----w- c:\program files (x86)\Trend Micro
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\users\okay\AppData\Roaming\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\programdata\!SASCORE
2011-06-05 11:07 . 2011-06-05 11:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-02 13:40 . 2011-05-09 22:00 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6041B77C-B39B-42A8-80AA-444CA9C5B7FB}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-05_17.42.47 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-06-05 17:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-06-06 19:09 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-06-05 17:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-06 19:09 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-06 19:09 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-06-05 17:06 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-04-21 10:29 . 2011-06-06 16:33 38704 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-06-06 18:52 37180 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-06-15 06:13 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-15 06:13 . 2011-06-05 18:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-06-15 06:13 . 2011-05-17 05:56 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-05-17 05:56 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-06-05 18:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-19 22:12 . 2011-06-06 19:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-19 22:12 . 2011-06-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:12 . 2011-06-06 19:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-19 22:05 . 2011-06-06 18:52 7474 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3463257822-2106436174-1310032169-1000_UserData.bin
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-06-06 19:19 . 2011-06-06 19:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-06-05 16:50 . 2011-06-05 16:50 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-06-06 19:19 . 2011-06-06 19:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 02:34 . 2011-06-05 17:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2011-06-06 19:01 9961472 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:55 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-04-08 908368]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-3-26 1125152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-04-17 305520]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-06 50432]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-03-28 136360]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-04-08 312400]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-03-17 866336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-24 13336]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-03-08 250368]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-06 144640]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-12-14 2019648]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-04-17 05:58 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-29 9913376]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-04 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-04 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-04 410648]
"PLFSetI"="c:\windows\PLFSetI.exe" [2010-06-15 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-03-17 860704]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\RunDll32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
.
**************************************************************************
.
Completion time: 2011-06-06 21:25:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-06 19:25
ComboFix2.txt 2011-06-06 16:37
ComboFix3.txt 2011-06-05 19:55
ComboFix4.txt 2011-06-05 17:45
.
Pre-Run: 260 942 635 008 bytes free
Post-Run: 260 861 751 296 bytes free
.
- - End Of File - - 87E1C3F09639E3356BDECEC60F663CD1
Re: Prosím o kontrolu logu
Jak se chova PC 
Re: Prosím o kontrolu logu
vyzerá to ok, problém už nie je. Aj odkaz z plochy na problémový program zmizol



Přispějete na provoz fóra?