Stránka 2 z 3

Re: odstraneni antiviru

Napsal: 25 úno 2012 16:22
od maadr
SystemLook 30.07.11 by jpshortstuff
Log created at 16:21 on 25/02/2012 by Marie
Administrator - Elevation successful

========== regfind ==========

Searching for "*avira*"
No data found.

========== folderfind ==========

Searching for "*avira*"
C:\Documents and Settings\All Users\Data aplikací\Avira d------ [12:23 07/03/2011]
C:\_OTL\MovedFiles\02252012_135749\C_Documents and Settings\Marie\Data aplikací\Avira d------ [12:57 25/02/2012]

========== filefind ==========

Searching for "*avira*"
C:\Documents and Settings\Marie\Plocha\avira_free_antivirus_en.exe --a---- 87031672 bytes [13:05 25/02/2012] [13:07 25/02/2012] 3DE237251CC3FB5F7754A912563CD7E1
C:\WINDOWS\Prefetch\AVIRA_FREE_ANTIVIRUS_EN.EXE-153B7900.pf --a---- 63866 bytes [13:07 25/02/2012] [13:07 25/02/2012] F382FA2DA71FFA23249F7527E3A0E0B2

-= EOF =-

Re: odstraneni antiviru

Napsal: 25 úno 2012 16:43
od Márty84
Znovu spustte OTL v nouzovem rezimu
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

:files
C:\Documents and Settings\All Users\Data aplikací\Avira
C:\Program Files\Avira
C:\WINDOWS\Prefetch\AVIRA_FREE_ANTIVIRUS_EN.EXE

:commands
[EMPTYTEMP]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.

Re: odstraneni antiviru

Napsal: 25 úno 2012 20:08
od maadr
All processes killed
========== FILES ==========
C:\Documents and Settings\All Users\Data aplikací\Avira\AntiVir Desktop folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Avira folder moved successfully.
File\Folder C:\Program Files\Avira not found.
File\Folder C:\WINDOWS\Prefetch\AVIRA_FREE_ANTIVIRUS_EN.EXE not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator

User: Administrator.LENOVO-IDEAPAD
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Marie
->Temp folder emptied: 845466 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 8967798 bytes
->Flash cache emptied: 445 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 138803233 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 142,00 mb


OTL by OldTimer - Version 3.2.33.2 log created on 02252012_200338

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Re: odstraneni antiviru

Napsal: 25 úno 2012 20:42
od Márty84
Dalsi veci od aviry smazany. Porad to nejde?

Zkuste jeste jednou systemlook, tentokrat tam zkopirjte toto

Kód: Vybrat vše

:regfind
avira
antivir

Re: odstraneni antiviru

Napsal: 26 úno 2012 12:32
od maadr
uz to jde. diky moc :) :thumbsup: :|

Re: odstraneni antiviru

Napsal: 26 úno 2012 12:40
od maadr
ale zase jsem stáhnul Systemlook, ukládá se mi to na Plochu a když se dívám na Plochu,tak se mi nic nestáhlo, žádná ikona Systemlook na ní není. Vidím to jen když se na Plochu proklikám přes Tento počítač v oknech. Jak je to možné??

Re: odstraneni antiviru

Napsal: 26 úno 2012 12:55
od Márty84
To jsem rad :) Nemate zac :wink:

Nevim, proc systemlook nevidite. Ale uz ho delat nemusite, kdyz to funguje. Smazte ho (oba), at se vam tam zbytecne neplete.

Jsou tedy jeste nejake potize? Nebo muzeme uklidit?

Re: odstraneni antiviru

Napsal: 26 úno 2012 14:50
od maadr
Potize s Avirou už nejsou, ale s tím nezobrazováním stažených souborů přetrvávají. Co s tím můžu udělat?

Re: odstraneni antiviru

Napsal: 26 úno 2012 15:44
od Márty84
Udelejte jeste uplnou kontrolu s MBAM

Myslel jsem, ze se to tyka jen toho systemlooku, ne vsech stazenych souboru :shock:

:?: Netusim, co by to mohlo zpusobovat. Jednou jsem se setkal s necim podobnym, ale to se nejednalo o stahovani veci. Problem byl v tom, ze jsem programu omylem nastavil, at to uklada do slozky, ovsem na jiny uzivatelsky ucet. To znamena ze ve sve slozce jsem ty soubory nevidel, ale proklikat na jiny ucet do slozky se stejnym nazvem slo. Ovsem jestli to muze byt i tento pripad, to fakt nevim.

Uvidime, jestli MBAM nenajde nejakeho previta, ktery se v logu neukazal :)

Re: odstraneni antiviru

Napsal: 26 úno 2012 21:30
od maadr
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.60.1.1000
www.malwarebytes.org

Verze databáze: v2012.02.26.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Marie :: LENOVO-IDEAPAD [administrátor]

Ochrana: Zakázána

26.2.2012 20:42:17
mbam-log-2012-02-26 (20-42-17).txt

Typ: Úplná kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 230087
Uplynulý čas: 31 minut, 25 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Re: odstraneni antiviru

Napsal: 26 úno 2012 21:40
od maadr
mbam log viz minule.
Antivir jede a nic nenasel. Ale od te doby, co jsem promazal avira,tak ikdyz mam antivir i MBAM vypnuty a najel jsem na bwin, kde se instalovala java,tak mam neuveritelne vsechno zpomalene. Markantni je to na tom bwin pri hrani. zvuk neodpovida pohybu, reakce opozdene,nez jsem najel na bwin,tak to trvalo i s instalaci javy snad 5 minut atd. Ale i samotny pocitac se mi zapina dlouho...
A s tim ukladanim na plochu.. neni to ten samy pripad jako vas,protoze me se to tam nakonec po nejake dobe samo od sebe objevi. Kdyz jedu pres okna a proklikam se na plochu,tak je to tam hned. Ale na samotne plose to vidim az za delsi dobu (hodne dlouho)

Re: odstraneni antiviru

Napsal: 26 úno 2012 22:00
od Márty84
Dejte mi sem tedy novy log z RSIT :)

Re: odstraneni antiviru

Napsal: 27 úno 2012 00:47
od maadr
Logfile of random's system information tool 1.09 (written by random/random)
Run by Marie at 2012-02-27 00:45:24
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 104 GB (70%) free of 148 GB
Total RAM: 1014 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:45:37, on 27.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\QSTART.SYS\config\DVMExportService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\A4Tech\Mouse\Amoumain.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Marie\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\PROGRA~1\Lenovo\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Marie\Plocha\RSIT.exe
C:\Program Files\trend micro\Marie.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Marie\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: PicNotify - PicNotify.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM - C:\QSTART.SYS\config\DVMExportService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 7747 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2011-08-30 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-02-25 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-02-25 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-02-25 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"EnergyUtility"=C:\Program Files\Lenovo\Energy Management\utility.exe [2009-01-04 4462464]
"Energy Management"=C:\Program Files\Lenovo\Energy Management\Energy Management.exe [2008-12-26 1277952]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-09-24 16859648]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344]
"AzMixerSel"=C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe [2006-07-17 53248]
"VeriFaceManager"=C:\Program Files\Lenovo\VeriFaceIII\PManage.exe [2011-03-03 323584]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-05-23 1146880]
"WheelMouse"=C:\Program Files\A4Tech\Mouse\Amoumain.exe [2008-03-05 188416]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-28 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-28 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-28 137752]
"TVT Scheduler Proxy"=C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2008-03-04 487424]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2012-01-13 460872]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2012-01-31 258512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Marie\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-03-07 136176]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PicNotify]
C:\WINDOWS\system32\PicNotify.dll [2011-03-03 1167360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\StepMania\Program\StepMania-SSE2.exe"="C:\Program Files\StepMania\Program\StepMania-SSE2.exe:*:Disabled:StepMania"
"C:\Program Files\StepMania\Program\StepMania.exe"="C:\Program Files\StepMania\Program\StepMania.exe:*:Enabled:StepMania"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"vidc.ffds"=ff_vfw.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm

======List of files/folders created in the last 1 month======

2012-02-26 23:38:59 ----D---- C:\Program Files\Microsoft Silverlight
2012-02-26 22:35:13 ----HD---- C:\dvmexp
2012-02-26 02:59:34 ----D---- C:\Documents and Settings\Marie\Data aplikací\Avira
2012-02-25 20:19:09 ----A---- C:\WINDOWS\system32\drivers\avkmgr.sys
2012-02-25 20:19:08 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2012-02-25 20:19:07 ----D---- C:\Program Files\Avira
2012-02-25 20:19:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2012-02-25 13:57:49 ----D---- C:\_OTL
2012-02-25 00:55:44 ----D---- C:\Program Files\PokerStars
2012-02-25 00:29:24 ----D---- C:\WINDOWS\Sun
2012-02-25 00:28:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2012-02-25 00:28:32 ----D---- C:\Program Files\Common Files\Java
2012-02-25 00:28:15 ----A---- C:\WINDOWS\system32\javaws.exe
2012-02-25 00:28:15 ----A---- C:\WINDOWS\system32\javaw.exe
2012-02-25 00:28:15 ----A---- C:\WINDOWS\system32\java.exe
2012-02-25 00:28:15 ----A---- C:\WINDOWS\system32\deployJava1.dll
2012-02-25 00:27:52 ----D---- C:\Program Files\Java
2012-02-25 00:26:55 ----D---- C:\Documents and Settings\Marie\Data aplikací\Sun
2012-02-24 20:41:36 ----D---- C:\_OTM
2012-02-24 18:16:53 ----D---- C:\Program Files\trend micro
2012-02-24 18:16:51 ----D---- C:\rsit
2012-02-18 21:00:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2660465$
2012-02-18 20:59:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2012-02-16 03:01:01 ----N---- C:\WINDOWS\system32\iacenc.dll
2012-01-28 15:28:05 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2012-01-28 15:28:05 ----A---- C:\WINDOWS\system32\xvidcore.dll
2012-01-28 15:28:03 ----A---- C:\WINDOWS\system32\unrar.dll
2012-01-28 15:28:01 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2012-01-28 15:27:55 ----D---- C:\Program Files\K-Lite Codec Pack
2012-01-28 01:38:45 ----D---- C:\Config.Msi

======List of files/folders modified in the last 1 month======

2012-02-27 00:37:29 ----HD---- C:\temp
2012-02-26 23:50:23 ----D---- C:\WINDOWS\system32\CatRoot2
2012-02-26 23:39:16 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-02-26 23:39:15 ----SHD---- C:\WINDOWS\Installer
2012-02-26 23:38:59 ----RD---- C:\Program Files
2012-02-26 23:38:11 ----D---- C:\WINDOWS\system32\drivers
2012-02-26 23:28:26 ----D---- C:\WINDOWS\Temp
2012-02-26 23:07:44 ----AD---- C:\WINDOWS
2012-02-26 21:44:01 ----N---- C:\WINDOWS\SchedLgU.Txt
2012-02-26 14:42:12 ----SHD---- C:\System Volume Information
2012-02-26 14:41:45 ----D---- C:\WINDOWS\Registration
2012-02-25 20:19:26 ----D---- C:\WINDOWS\Prefetch
2012-02-25 20:01:58 ----AD---- C:\WINDOWS\system32
2012-02-25 14:03:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-02-25 13:57:56 ----D---- C:\WINDOWS\system32\CatRoot
2012-02-25 00:46:31 ----SHD---- C:\RECYCLER
2012-02-25 00:46:21 ----D---- C:\WINDOWS\system32\drivers\etc
2012-02-25 00:46:13 ----SD---- C:\WINDOWS\Tasks
2012-02-25 00:42:08 ----D---- C:\Documents and Settings
2012-02-25 00:28:32 ----D---- C:\Program Files\Common Files
2012-02-24 11:43:59 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-02-24 11:19:55 ----D---- C:\WINDOWS\Debug
2012-02-18 21:43:13 ----RSD---- C:\WINDOWS\assembly
2012-02-18 21:36:32 ----D---- C:\WINDOWS\Microsoft.NET
2012-02-18 21:06:48 ----D---- C:\WINDOWS\WinSxS
2012-02-18 21:00:27 ----A---- C:\WINDOWS\system32\MRT.exe
2012-02-18 21:00:22 ----HD---- C:\WINDOWS\inf
2012-02-18 21:00:21 ----ASHDC---- C:\WINDOWS\system32\dllcache
2012-02-18 21:00:07 ----D---- C:\Program Files\Internet Explorer
2012-02-18 20:59:48 ----HD---- C:\WINDOWS\$hf_mig$
2012-01-28 15:13:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-01-28 15:13:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2012-01-28 15:13:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-01-28 15:13:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2639417$
2012-01-28 15:10:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-01-28 15:09:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2624667$
2012-01-28 15:03:43 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2012-01-28 15:03:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-01-28 15:03:04 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2012-01-28 15:02:43 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2012-01-28 15:02:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2633952$
2012-01-28 15:02:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2012-01-28 15:02:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2618451$
2012-01-28 15:01:55 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2012-01-28 15:01:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2012-01-28 15:01:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-01-28 15:01:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2633171$
2012-01-28 14:24:41 ----D---- C:\WINDOWS\system32\config
2012-01-28 14:24:29 ----D---- C:\WINDOWS\system32\wbem

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Amfilter;A4Tech Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\Amfilter.sys [2007-01-24 8704]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2012-01-31 137416]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2011-09-16 36000]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2012-01-31 74640]
R2 PMEM;PMEM; \??\C:\WINDOWS\system32\drivers\PMEMNT.SYS []
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\WINDOWS\system32\DRIVERS\AcpiVpc.sys [2008-01-11 9472]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-06-19 176640]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2008-09-10 1386624]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-06-23 991400]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-09-24 4818432]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 psadd;Lenovo Parties Service Access Device Driver; C:\WINDOWS\system32\DRIVERS\psadd.sys [2007-02-19 21376]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RTS5121.sys [2008-07-23 157696]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:\WINDOWS\system32\DRIVERS\Amusbprt.sys [2007-12-25 14336]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-06-11 47272]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NSCIRDA;NSC Infrared Device Driver; C:\WINDOWS\system32\DRIVERS\nscirda.sys [2008-04-14 28672]
S3 PcdrNdisuio;PCDRNDISUIO Usermode I/O Protocol; C:\WINDOWS\system32\DRIVERS\pcdrndisuio.sys [2009-12-17 13440]
S3 PCDSRVC{E9084A43-01CBFFD7-06000000}_0;PCDSRVC{E9084A43-01CBFFD7-06000000}_0 - PCDR Kernel Mode Service Helper Driver; \??\d:\pcdoctor\pcdsrvc.pkms []
S3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
S3 Rts516xIR;Realtek IR Driver; C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-05-23 225280]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\Rts5161ccid.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WimFltr;WimFltr; C:\WINDOWS\system32\DRIVERS\wimfltr.sys [2007-05-23 128104]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WSVD;WSVD; \??\C:\WINDOWS\system32\drivers\WSVD.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Filtr Compaq sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;Filtr ALI sběrnice AGP; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;Ovladač filtru AMD portu AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Realtime Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2012-01-31 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2012-01-31 86224]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe [2008-06-23 346720]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\QSTART.SYS\config\DVMExportService.exe [2008-12-01 307200]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2012-02-25 153376]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
R2 SUService;System Update; c:\program files\lenovo\system update\suservice.exe [2011-04-18 28672]
R2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-09-26 644408]
R2 TVT Scheduler;TVT Scheduler; C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [2008-03-04 1122304]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: odstraneni antiviru

Napsal: 27 úno 2012 00:55
od maadr
RSIT log viz vyse.

Ja to fakt nechapu...stahnul jsem si opet rsit klasicky, ulozilo se na plochu. Okna shodim na listu a divam se ...a na plose nic neni. ..Najedu na Plochu pres Tento pocitac a rsit je tam. Schvalne zkousim myší pretahnout vedle okna,to je na plochu na ktere jsem rsit predtim nenasel a napise se mi, ze soubor se s druhym souborem shoduje nazvem atd,takze to pretahnout nelze...zrusim to, shodim okno na listu a cumim...na Plose to nevidim. Pripadam si jako blazen. Nevim jak to vysvetlit. Mam lenovo s10e a ono ma jine rozliseni obrazovky a obcas to kvuli tomu řve v nekterych programech, at zmenim rozliseni.

Re: odstraneni antiviru

Napsal: 27 úno 2012 09:54
od Márty84
:arrow: Jeste jednou spustte OTM
Do leveho okna zkopirujte toto

Kód: Vybrat vše

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Documents and Settings\Marie\Local Settings\Data aplikací\Google\Update

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"=-
"SunJavaUpdateSched"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-

:commands
[Purity]
[EMPTYTEMP]
[EMPTYFLASH]
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery bude zde C:\_OTM\MovedFiles\


:arrow: Ten problem s tou plochou je divny :roll: Zkusim se poptat, jestli se s tim nekdo setkal :)