Problém s Explorer
Napsal: 03 srp 2010 01:26
Ahoj, mám takový problém. Používám windows vista home premium 32-bit OEM CZ SP2. Můj problém je, že když otevřu složku a chci praovat se soubory ( ať už jakýkoliv ) vždy se sekne průzkumník windows a neodpovídá, musím ho restartovat. Po všech návodech co jsem četl, sem si stáhl eScan Anti Virus a Spyware Toolkit Ulitily. Našel mi chyby v systému. Odstranění téhle havěti se to přestane sekat ( doufám ). Bohužel tam u některých souborů není napsaná cesta, a tak Vás prosím, zda byste mi neřekli, jak to dát pryč a popřípadě zablokovat automatické spuštění. Už jsem z toho zoufalý, ten průzkumník se sekne na 100% což je blbé. Na Windows 7, ani XP mi to nedělalo, ale používám vistu protože mám origoš klíč na ní. Doufám, že se najde řešení a tahle havěť mi už nebude ukončovat explorer.exe. Prosím o dobrou radu, zatím mějte se a děkuji za návody. Dávám LOG z toho programu
03 VIII 2010 01:08:32 - **********************************************************
03 VIII 2010 01:08:32 - eScan Anti Virus & Spyware Toolkit Utility.
03 VIII 2010 01:08:32 - Copyright © MicroWorld Technologies
03 VIII 2010 01:08:32 - **********************************************************
03 VIII 2010 01:08:32 - Source: E:\GOOGLE~1\mwav.exe
03 VIII 2010 01:08:32 - Version 11.0.86 (C:\USERS\HYDRON\APPDATA\LOCAL\TEMP\MEXE.COM)
03 VIII 2010 01:08:32 - Log File: C:\Users\Hydron\AppData\Local\Temp\MWAV.LOG
03 VIII 2010 01:08:32 - MWAV Registered: FALSE
03 VIII 2010 01:08:32 - User Account: Hydron (Administrator Mode)
03 VIII 2010 01:08:32 - OS Type: Windows Workstation
03 VIII 2010 01:08:32 - OS: Windows Vista [OS Install Date: 02 Aug 2010 12:56:53]
03 VIII 2010 01:08:32 - Ver: Personal Service Pack 2 (Build 6002)
03 VIII 2010 01:08:32 - System Up Time: 39 Minutes, 19 Seconds
03 VIII 2010 01:08:32 - Parent Process Name : E:\Google Chrome\mwav.exe
03 VIII 2010 01:08:32 - Windows Root Folder: C:\Windows
03 VIII 2010 01:08:32 - Windows Sys32 Folder: C:\Windows\system32
03 VIII 2010 01:08:32 - DHCP NameServer: 93.91.144.100 212.80.67.98
03 VIII 2010 01:08:32 - Interface0 DHCPNameServer: 93.91.144.100 212.80.67.98
03 VIII 2010 01:08:32 - Local Fixed Drives: c:\,d:\,e:\
03 VIII 2010 01:08:32 - MWAV Mode: Only Scan files
03 VIII 2010 01:08:32 - [CREATED ZIP FILE: C:\Users\Hydron\AppData\Local\Temp\pinfect.zip]
03 VIII 2010 01:08:32 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
03 VIII 2010 01:08:32 - C:\Windows\atl80.dll (96256), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:32 - C:\Windows\gdiplus.dll (1645320), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:32 - C:\Windows\ijl15.dll (372736), 02-Aug-2010, Intel Corporation, Intel® JPEG Library
03 VIII 2010 01:08:33 - C:\Windows\mfc70.dll (974848), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio .NET
03 VIII 2010 01:08:33 - C:\Windows\mfc80.dll (1101824), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\mfc80u.dll (1093120), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\mfcm80.dll (69632), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\mfcm80u.dll (57856), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\msvbvm60.dll (1392671), 02-Aug-2010, Microsoft Corporation, Visual Basic
03 VIII 2010 01:08:33 - C:\Windows\msvcm80.dll (479232), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:34 - C:\Windows\msvcp70.dll (487424), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio .NET
03 VIII 2010 01:08:34 - C:\Windows\msvcr70.dll (344064), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio .NET
03 VIII 2010 01:08:34 - C:\Windows\system32\ATIDEMGX.dll (446464), 02-Aug-2010, Advanced Micro Devices, Inc., Catalyst® Control Centre
03 VIII 2010 01:08:34 - C:\Windows\system32\cabview.dll (98304), 02-Aug-2010, Microsoft Corporation, Operační systém Microsoft® Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\d3dx9_24.dll (2222800), 02-Aug-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\d3dx9_25.dll (2337488), 02-Aug-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\d3dx9_26.dll (2297552), 02-Aug-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\DIFxAPI.dll (319456), 02-Aug-2010, Microsoft Corporation, Driver Install Frameworks API (DIFxAPI)
03 VIII 2010 01:08:34 - C:\Windows\system32\DynamicInterpolation.ax (69632), 02-Aug-2010, Microsoft Corporation, DirectX 9.0 Sample
03 VIII 2010 01:08:34 - C:\Windows\system32\ETCoInst.dll (73728), 02-Aug-2010 [Added C:\Windows\system32\ETCoInst.dll to ZIP FILE]
03 VIII 2010 01:08:34 - C:\Windows\system32\Etprop.ax (131072), 02-Aug-2010, EtProp ???????
03 VIII 2010 01:08:34 - C:\Windows\system32\hpzids01.dll (258048), 02-Aug-2010, Hewlett-Packard, HP Installer
03 VIII 2010 01:08:35 - C:\Windows\system32\hpzll4v2.dll (117760), 02-Aug-2010, Hewlett-Packard Company, Language Monitor
03 VIII 2010 01:08:35 - C:\Windows\system32\Machnm32.sys (2304), 02-Aug-2010 [Added C:\Windows\system32\Machnm32.sys to ZIP FILE]
03 VIII 2010 01:08:35 - C:\Windows\system32\MpSigStub.exe (221568), 02-Aug-2010, Microsoft Corporation, Microsoft Malware Protection
03 VIII 2010 01:08:35 - C:\Windows\system32\RemoveET.exe (110592), 02-Aug-2010 [Added C:\Windows\system32\RemoveET.exe to ZIP FILE]
03 VIII 2010 01:08:35 - C:\Windows\system32\wintrust.dll (172032), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuapi.dll (575704), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuapp.exe (33792), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuauclt.exe (53472), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuaueng.dll (1929952), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wucltux.dll (2421760), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wudriver.dll (87552), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wups.dll (35552), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wups2.dll (44768), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuwebv.dll (171608), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\drivers\ETdrv.sys (153344), 02-Aug-2010, Etron, Etron Camera Driver
03 VIII 2010 01:08:35 - C:\Windows\system32\drivers\PdiPorts.sys (17064), 02-Aug-2010, Portrait Displays, Inc., PDI Kernel Ports Driver
03 VIII 2010 01:08:35 - C:\Windows\system32\drivers\sptd.sys (691696), 02-Aug-2010 [Unable to Add C:\Windows\system32\drivers\sptd.sys to ZIP FILE! ResultCode: 512]
03 VIII 2010 01:08:35 - C:\Windows\Debug, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\Fonts, 02-Nov-2006 [SR] [Folder]
03 VIII 2010 01:08:35 - C:\Windows\Media, 02-Nov-2006 [SR] [Folder]
03 VIII 2010 01:08:35 - C:\Windows\Panther, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\SoftwareDistribution, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\system32\Macromed, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\system32\Microsoft, 02-Nov-2006 [S] [Folder]
03 VIII 2010 01:08:35 - C:\Boot, 02-Aug-2010 [HS] [Folder]
03 VIII 2010 01:08:35 - C:\Documents and Settings, 02-Nov-2006 [HS] [Folder]
03 VIII 2010 01:08:35 - C:\ProgramData, 02-Nov-2006 [H] [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Acer Display, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\ATI, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\ATI Technologies, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\ETRON, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\HP, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\K-Lite Mega Codec Pack, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Microsoft Security Essentials, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Portrait Displays, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\WinPcap, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\ATI Technologies, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\HP, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\InstallShield, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\Portrait Displays, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\Microsoft Shared\VC, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - *********************************************************************************************
03 VIII 2010 01:08:44 - ** Deleted Value of "DisableCAD" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon". Its value was DWORD:1.
03 VIII 2010 01:08:44 - ** Changed Value of "HKEY_CLASSES_ROOT\.htm" from "ChromeHTML" to "htmlfile"
03 VIII 2010 01:08:44 - ** Changed Value of "HKEY_CLASSES_ROOT\.html" from "ChromeHTML" to "htmlfile"
03 VIII 2010 01:08:44 - Loading/Creating FileScan Database C:\ProgramData\MicroWorld\MWAV\MWAVDBX.MDB [Log: C:\Users\Hydron\AppData\Local\Temp\MWAVDB.LOG]
03 VIII 2010 01:08:45 - Loaded/Created FileScan Database...
03 VIII 2010 01:08:45 - Loading AV Library [DB]...
03 VIII 2010 01:08:59 - AV Library Loaded [DB-DIRECT].
03 VIII 2010 01:08:59 - MWAV doing self scanning...
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\avxdisk.dll
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\scan.dll
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\bdcore.dll
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\bdupdateservice.dll
03 VIII 2010 01:09:00 - MWAV files are clean.
03 VIII 2010 01:09:09 - Datum vydání databáze: 06 Nov 2009
03 VIII 2010 01:09:09 - Verze virové databáze: 4481875
03 VIII 2010 01:09:12 - Stahování Antivirus a Antispyware databází...
03 VIII 2010 01:13:10 - Stahování dokončeno...
03 VIII 2010 01:13:14 - Indexed Spyware Databases Successfully Created...
03 VIII 2010 01:13:14 - Not Reloading the Antivirus Database, as Signatures are Same...
03 VIII 2010 01:13:36 - ReCreated FileScan Database...
03 VIII 2010 01:13:38 - **********************************************************
03 VIII 2010 01:13:38 - eScan Anti Virus & Spyware Toolkit Utility.
03 VIII 2010 01:13:38 - Copyright © 2003-2006, MicroWorld Technologies Inc.
03 VIII 2010 01:13:38 -
03 VIII 2010 01:13:38 - Podpora [EN]: support@mwti.net
03 VIII 2010 01:13:38 - Web: http://www.mwti.net
03 VIII 2010 01:13:38 - **********************************************************
03 VIII 2010 01:13:38 - Verze 11.0.86[DB] (C:\USERS\HYDRON\APPDATA\LOCAL\TEMP\MEXE.COM)
03 VIII 2010 01:13:38 - Log soubor: C:\Users\Hydron\AppData\Local\Temp\MWAV.LOG
03 VIII 2010 01:13:38 - User Account: Hydron
03 VIII 2010 01:13:38 - Parent Process Name : E:\Google Chrome\mwav.exe
03 VIII 2010 01:13:38 - Windows Root Folder: C:\Windows
03 VIII 2010 01:13:38 - Windows Sys32 Folder: C:\Windows\system32
03 VIII 2010 01:13:38 - OS: Windows Vista [OS Install Date: 02 Aug 2010 12:56:53]
03 VIII 2010 01:13:38 - Ver: Personal Service Pack 2 (Build 6002)
03 VIII 2010 01:13:38 - Nastavení vybraná uživatelem:
03 VIII 2010 01:13:38 - Kontrola paměti: Zapnuto
03 VIII 2010 01:13:38 - Kontorla registrů: Zapnuto
03 VIII 2010 01:13:38 - Kontrola souborů po spuštění: Zapnuto
03 VIII 2010 01:13:38 - Kontrola systémových složek: Zapnuto
03 VIII 2010 01:13:38 - Kontrola služeb: Zapnuto
03 VIII 2010 01:13:38 - Otestovat Spyware: Zapnuto
03 VIII 2010 01:13:38 - Kotrola disku: Vypnuto
03 VIII 2010 01:13:38 - Kontrola všech disků:Zapnuto
03 VIII 2010 01:13:38 - Kontrola složek: Zapnuto
03 VIII 2010 01:13:38 - Vybrané složky = C:\Windows
03 VIII 2010 01:13:38 - SCAN: All_Files
A NAŠLO MI TO TYHLE HROZBY, JAK NA NĚ ?
** Scanning may fail! File Locked [SUSPICIOUS]: C:\Windows\system32\Drivers\sptd.sys (????)
Objekt "CoreGuardAntivirus2009 Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "YahooSpyMon Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "YahooSpyMon Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "YahooSpyMon Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Your Protection Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Orifice2K.plugin Trojan" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".07". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".3". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".CZ". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".mdf". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".r40". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".Twilight-RELOADED". Provedené akce: Ponecháno, neodstraněno!.

03 VIII 2010 01:08:32 - **********************************************************
03 VIII 2010 01:08:32 - eScan Anti Virus & Spyware Toolkit Utility.
03 VIII 2010 01:08:32 - Copyright © MicroWorld Technologies
03 VIII 2010 01:08:32 - **********************************************************
03 VIII 2010 01:08:32 - Source: E:\GOOGLE~1\mwav.exe
03 VIII 2010 01:08:32 - Version 11.0.86 (C:\USERS\HYDRON\APPDATA\LOCAL\TEMP\MEXE.COM)
03 VIII 2010 01:08:32 - Log File: C:\Users\Hydron\AppData\Local\Temp\MWAV.LOG
03 VIII 2010 01:08:32 - MWAV Registered: FALSE
03 VIII 2010 01:08:32 - User Account: Hydron (Administrator Mode)
03 VIII 2010 01:08:32 - OS Type: Windows Workstation
03 VIII 2010 01:08:32 - OS: Windows Vista [OS Install Date: 02 Aug 2010 12:56:53]
03 VIII 2010 01:08:32 - Ver: Personal Service Pack 2 (Build 6002)
03 VIII 2010 01:08:32 - System Up Time: 39 Minutes, 19 Seconds
03 VIII 2010 01:08:32 - Parent Process Name : E:\Google Chrome\mwav.exe
03 VIII 2010 01:08:32 - Windows Root Folder: C:\Windows
03 VIII 2010 01:08:32 - Windows Sys32 Folder: C:\Windows\system32
03 VIII 2010 01:08:32 - DHCP NameServer: 93.91.144.100 212.80.67.98
03 VIII 2010 01:08:32 - Interface0 DHCPNameServer: 93.91.144.100 212.80.67.98
03 VIII 2010 01:08:32 - Local Fixed Drives: c:\,d:\,e:\
03 VIII 2010 01:08:32 - MWAV Mode: Only Scan files
03 VIII 2010 01:08:32 - [CREATED ZIP FILE: C:\Users\Hydron\AppData\Local\Temp\pinfect.zip]
03 VIII 2010 01:08:32 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
03 VIII 2010 01:08:32 - C:\Windows\atl80.dll (96256), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:32 - C:\Windows\gdiplus.dll (1645320), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:32 - C:\Windows\ijl15.dll (372736), 02-Aug-2010, Intel Corporation, Intel® JPEG Library
03 VIII 2010 01:08:33 - C:\Windows\mfc70.dll (974848), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio .NET
03 VIII 2010 01:08:33 - C:\Windows\mfc80.dll (1101824), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\mfc80u.dll (1093120), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\mfcm80.dll (69632), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\mfcm80u.dll (57856), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:33 - C:\Windows\msvbvm60.dll (1392671), 02-Aug-2010, Microsoft Corporation, Visual Basic
03 VIII 2010 01:08:33 - C:\Windows\msvcm80.dll (479232), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio® 2005
03 VIII 2010 01:08:34 - C:\Windows\msvcp70.dll (487424), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio .NET
03 VIII 2010 01:08:34 - C:\Windows\msvcr70.dll (344064), 02-Aug-2010, Microsoft Corporation, Microsoft® Visual Studio .NET
03 VIII 2010 01:08:34 - C:\Windows\system32\ATIDEMGX.dll (446464), 02-Aug-2010, Advanced Micro Devices, Inc., Catalyst® Control Centre
03 VIII 2010 01:08:34 - C:\Windows\system32\cabview.dll (98304), 02-Aug-2010, Microsoft Corporation, Operační systém Microsoft® Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\d3dx9_24.dll (2222800), 02-Aug-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\d3dx9_25.dll (2337488), 02-Aug-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\d3dx9_26.dll (2297552), 02-Aug-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
03 VIII 2010 01:08:34 - C:\Windows\system32\DIFxAPI.dll (319456), 02-Aug-2010, Microsoft Corporation, Driver Install Frameworks API (DIFxAPI)
03 VIII 2010 01:08:34 - C:\Windows\system32\DynamicInterpolation.ax (69632), 02-Aug-2010, Microsoft Corporation, DirectX 9.0 Sample
03 VIII 2010 01:08:34 - C:\Windows\system32\ETCoInst.dll (73728), 02-Aug-2010 [Added C:\Windows\system32\ETCoInst.dll to ZIP FILE]
03 VIII 2010 01:08:34 - C:\Windows\system32\Etprop.ax (131072), 02-Aug-2010, EtProp ???????
03 VIII 2010 01:08:34 - C:\Windows\system32\hpzids01.dll (258048), 02-Aug-2010, Hewlett-Packard, HP Installer
03 VIII 2010 01:08:35 - C:\Windows\system32\hpzll4v2.dll (117760), 02-Aug-2010, Hewlett-Packard Company, Language Monitor
03 VIII 2010 01:08:35 - C:\Windows\system32\Machnm32.sys (2304), 02-Aug-2010 [Added C:\Windows\system32\Machnm32.sys to ZIP FILE]
03 VIII 2010 01:08:35 - C:\Windows\system32\MpSigStub.exe (221568), 02-Aug-2010, Microsoft Corporation, Microsoft Malware Protection
03 VIII 2010 01:08:35 - C:\Windows\system32\RemoveET.exe (110592), 02-Aug-2010 [Added C:\Windows\system32\RemoveET.exe to ZIP FILE]
03 VIII 2010 01:08:35 - C:\Windows\system32\wintrust.dll (172032), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuapi.dll (575704), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuapp.exe (33792), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuauclt.exe (53472), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuaueng.dll (1929952), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wucltux.dll (2421760), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wudriver.dll (87552), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wups.dll (35552), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wups2.dll (44768), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\wuwebv.dll (171608), 02-Aug-2010, Microsoft Corporation, Microsoft® Windows® Operating System
03 VIII 2010 01:08:35 - C:\Windows\system32\drivers\ETdrv.sys (153344), 02-Aug-2010, Etron, Etron Camera Driver
03 VIII 2010 01:08:35 - C:\Windows\system32\drivers\PdiPorts.sys (17064), 02-Aug-2010, Portrait Displays, Inc., PDI Kernel Ports Driver
03 VIII 2010 01:08:35 - C:\Windows\system32\drivers\sptd.sys (691696), 02-Aug-2010 [Unable to Add C:\Windows\system32\drivers\sptd.sys to ZIP FILE! ResultCode: 512]
03 VIII 2010 01:08:35 - C:\Windows\Debug, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\Fonts, 02-Nov-2006 [SR] [Folder]
03 VIII 2010 01:08:35 - C:\Windows\Media, 02-Nov-2006 [SR] [Folder]
03 VIII 2010 01:08:35 - C:\Windows\Panther, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\SoftwareDistribution, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\system32\Macromed, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Windows\system32\Microsoft, 02-Nov-2006 [S] [Folder]
03 VIII 2010 01:08:35 - C:\Boot, 02-Aug-2010 [HS] [Folder]
03 VIII 2010 01:08:35 - C:\Documents and Settings, 02-Nov-2006 [HS] [Folder]
03 VIII 2010 01:08:35 - C:\ProgramData, 02-Nov-2006 [H] [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Acer Display, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\ATI, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\ATI Technologies, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\ETRON, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\HP, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\K-Lite Mega Codec Pack, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Microsoft Security Essentials, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Portrait Displays, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\WinPcap, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\ATI Technologies, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\HP, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\InstallShield, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\Portrait Displays, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - C:\Program Files\Common Files\Microsoft Shared\VC, 02-Aug-2010 [Folder]
03 VIII 2010 01:08:35 - *********************************************************************************************
03 VIII 2010 01:08:44 - ** Deleted Value of "DisableCAD" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon". Its value was DWORD:1.
03 VIII 2010 01:08:44 - ** Changed Value of "HKEY_CLASSES_ROOT\.htm" from "ChromeHTML" to "htmlfile"
03 VIII 2010 01:08:44 - ** Changed Value of "HKEY_CLASSES_ROOT\.html" from "ChromeHTML" to "htmlfile"
03 VIII 2010 01:08:44 - Loading/Creating FileScan Database C:\ProgramData\MicroWorld\MWAV\MWAVDBX.MDB [Log: C:\Users\Hydron\AppData\Local\Temp\MWAVDB.LOG]
03 VIII 2010 01:08:45 - Loaded/Created FileScan Database...
03 VIII 2010 01:08:45 - Loading AV Library [DB]...
03 VIII 2010 01:08:59 - AV Library Loaded [DB-DIRECT].
03 VIII 2010 01:08:59 - MWAV doing self scanning...
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\avxdisk.dll
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\scan.dll
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\bdcore.dll
03 VIII 2010 01:09:00 - Scanning File C:\Users\Hydron\AppData\Local\Temp\bdupdateservice.dll
03 VIII 2010 01:09:00 - MWAV files are clean.
03 VIII 2010 01:09:09 - Datum vydání databáze: 06 Nov 2009
03 VIII 2010 01:09:09 - Verze virové databáze: 4481875
03 VIII 2010 01:09:12 - Stahování Antivirus a Antispyware databází...
03 VIII 2010 01:13:10 - Stahování dokončeno...
03 VIII 2010 01:13:14 - Indexed Spyware Databases Successfully Created...
03 VIII 2010 01:13:14 - Not Reloading the Antivirus Database, as Signatures are Same...
03 VIII 2010 01:13:36 - ReCreated FileScan Database...
03 VIII 2010 01:13:38 - **********************************************************
03 VIII 2010 01:13:38 - eScan Anti Virus & Spyware Toolkit Utility.
03 VIII 2010 01:13:38 - Copyright © 2003-2006, MicroWorld Technologies Inc.
03 VIII 2010 01:13:38 -
03 VIII 2010 01:13:38 - Podpora [EN]: support@mwti.net
03 VIII 2010 01:13:38 - Web: http://www.mwti.net
03 VIII 2010 01:13:38 - **********************************************************
03 VIII 2010 01:13:38 - Verze 11.0.86[DB] (C:\USERS\HYDRON\APPDATA\LOCAL\TEMP\MEXE.COM)
03 VIII 2010 01:13:38 - Log soubor: C:\Users\Hydron\AppData\Local\Temp\MWAV.LOG
03 VIII 2010 01:13:38 - User Account: Hydron
03 VIII 2010 01:13:38 - Parent Process Name : E:\Google Chrome\mwav.exe
03 VIII 2010 01:13:38 - Windows Root Folder: C:\Windows
03 VIII 2010 01:13:38 - Windows Sys32 Folder: C:\Windows\system32
03 VIII 2010 01:13:38 - OS: Windows Vista [OS Install Date: 02 Aug 2010 12:56:53]
03 VIII 2010 01:13:38 - Ver: Personal Service Pack 2 (Build 6002)
03 VIII 2010 01:13:38 - Nastavení vybraná uživatelem:
03 VIII 2010 01:13:38 - Kontrola paměti: Zapnuto
03 VIII 2010 01:13:38 - Kontorla registrů: Zapnuto
03 VIII 2010 01:13:38 - Kontrola souborů po spuštění: Zapnuto
03 VIII 2010 01:13:38 - Kontrola systémových složek: Zapnuto
03 VIII 2010 01:13:38 - Kontrola služeb: Zapnuto
03 VIII 2010 01:13:38 - Otestovat Spyware: Zapnuto
03 VIII 2010 01:13:38 - Kotrola disku: Vypnuto
03 VIII 2010 01:13:38 - Kontrola všech disků:Zapnuto
03 VIII 2010 01:13:38 - Kontrola složek: Zapnuto
03 VIII 2010 01:13:38 - Vybrané složky = C:\Windows
03 VIII 2010 01:13:38 - SCAN: All_Files
A NAŠLO MI TO TYHLE HROZBY, JAK NA NĚ ?
** Scanning may fail! File Locked [SUSPICIOUS]: C:\Windows\system32\Drivers\sptd.sys (????)
Objekt "CoreGuardAntivirus2009 Corrupted Adware/Spyware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "YahooSpyMon Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "YahooSpyMon Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "YahooSpyMon Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "User Account Control (Fake) Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Your Protection Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Orifice2K.plugin Trojan" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".07". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".3". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".CZ". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".mdf". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".r40". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" odkazuje na neplatný objekt ".Twilight-RELOADED". Provedené akce: Ponecháno, neodstraněno!.