Problém so "systémom"
Napsal: 28 lis 2010 08:34
Už viackrát mi pri spúšťaní PC zobrazilo tú správu, že mám chýbajúci alebo poškodený súbor v cieľovom adresári c:/windows/system...Podarilo sa mi komp viackrát zapnúť aspoň cez Safe Mode, teraz napodiv normálne, avšak je strašne zavírený a bojím sa, že ho nabudúce nezapnem už vôbec
...
Vopred ďakujem za pomoc.
DDS (Ver_10-11-27.01) - NTFSx86
Run by Jakub at 8:31:34,09 on ne 28.11.2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.511.88 [GMT 1:00]
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\CmUCReye.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
svchost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Documents and Settings\Jakub\My Documents\Preberanie\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://googleure.com
uURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe
mWinlogon: Taskman=c:\documents and settings\jakub\application data\juzjf.exe
uWinlogon: Shell=c:\recycler\s-1-5-21-4349727068-6333880499-498343625-6351\nvapbar.exe,c:\recycler\s-1-5-21-3492822507-1643205622-369944611-5105\yv8g67.exe,explorer.exe,c:\documents and settings\jakub\application data\juzjf.exe
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\GrabPro.dll
TB: {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
TB: {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {35065594-9169-4A34-B167-FC4865038E53} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NVIDIA driver monitor] c:\windows\nvsvc32.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RaidTool] c:\program files\via\raid\raid_tool.exe
mRun: [SkyTel] SkyTel.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [JMB36X Configure] c:\windows\system32\JMRaidTool.exe boot
mRun: [CmUCRRun] c:\windows\system32\CmUCReye.exe
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [UpdatePDRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles
mRun: [NokiaMusic FastStart] "c:\program files\nokia\nokia music\NokiaMusic.exe" /command:faststart
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [NVIDIA driver monitor] c:\windows\nvsvc32.exe
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [wuaucldt] c:\windows\system32\wuaucldt.exe
mRun: [Regedit32] c:\windows\system32\regedit.exe
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\0ggbssn.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\0kplbbx.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\0tpkk6w.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\1ieezqq.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\6ss6ee6.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\c3eezqqlccx.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\e3ggbssneez.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\eezk6ww6ii.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\f0lhcc6oo.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\fbww6ii6.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\s70tpkq70.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\wwriiduupg.exe
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\jakub\application data\dvdvideosoftiehelpers\youtubedownload.htm
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} - hxxps://asp.photoprintit.de/microsite/5854/defaults/activex/ips/IPSUploader4.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {B96DF464-F62A-46C6-B2E4-E9F050499A76} = 217.119.117.28,217.119.113.244
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\
FF - plugin: c:\documents and settings\jakub\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\jakub\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Extension: Facicons: {DDABDBA1-2377-4A30-A027-25697B99E254} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{DDABDBA1-2377-4A30-A027-25697B99E254}
FF - Extension: U Flv: {5647f4b2-2f19-15dd-2d2b-7212613c2b46} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{5647f4b2-2f19-15dd-2d2b-7212613c2b46}
FF - Extension: {5647f4b2-2f19-15dd-2d2b-7212613c2b46}: {5647f4b2-2f19-15dd-2d2b-7212613c2b46} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{5647f4b2-2f19-15dd-2d2b-7212613c2b46}
============= SERVICES / DRIVERS ===============
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-7-1 34312]
R2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2008-7-1 468224]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 CMISTOR;CMIUCR.SYS CM220 Card Reader Driver;c:\windows\system32\drivers\cmiucr.SYS [2009-7-9 72320]
R3 PSched;QoS Packet Scheduler;c:\windows\system32\drivers\psched.sys [2004-8-3 69120]
S2 ea26a79qboa;Asset Management Daemon;c:\windows\system32\venelyzu.exe --> c:\windows\system32\venelyzu.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-14 136176]
S3 jkzycxdn;jkzycxdn;\??\c:\windows\system32\drivers\jkzycxdn.sys --> c:\windows\system32\drivers\jkzycxdn.sys [?]
S3 rwaofnwl;rwaofnwl;\??\c:\windows\system32\drivers\rwaofnwl.sys --> c:\windows\system32\drivers\rwaofnwl.sys [?]
S3 yvhsauqu;yvhsauqu;\??\c:\windows\system32\drivers\yvhsauqu.sys --> c:\windows\system32\drivers\yvhsauqu.sys [?]
=============== Created Last 30 ================
2010-11-28 06:28:06 315392 ----a-w- c:\windows\system32\pyly.exe
2010-11-27 16:54:30 -------- d-----w- c:\program files\VirtualDJ
2010-11-27 10:28:50 30560 ----a-w- c:\windows\system32\drivers\wcscd.sys
2010-11-22 15:42:37 -------- d-----w- c:\docume~1\jakub\locals~1\applic~1\Electronic Arts
2010-11-21 21:26:31 256 ----a-w- C:\HDTV.exe
2010-11-20 14:31:17 85504 --sh--r- c:\docume~1\jakub\applic~1\juzjf.exe
2010-11-20 14:31:07 85504 ----a-w- C:\wifi32.exe
2010-11-15 19:30:41 90978 ----a-w- C:\winnt7.exe
2010-11-15 14:40:38 72192 --sh--r- c:\windows\nvsvc32.exe
2010-11-09 14:25:42 -------- d-----w- c:\docume~1\jakub\locals~1\applic~1\Unity
2010-11-08 06:25:54 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Norton
2010-11-08 06:25:53 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Symantec
2010-11-08 06:25:45 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\NortonInstaller
2010-11-06 10:37:34 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2010-11-06 10:37:34 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2010-11-03 17:09:47 -------- d-----w- C:\divx
2010-11-03 09:07:23 -------- d-----w- c:\program files\AllToAVI
==================== Find3M ====================
2010-11-28 06:18:23 98304 ----a-w- c:\windows\DUMP6b3d.tmp
2010-11-28 06:16:50 98304 ----a-w- c:\windows\DUMP6a14.tmp
2010-11-27 14:33:40 98304 ----a-w- c:\windows\DUMP70f9.tmp
2010-09-08 07:09:46 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-09-08 07:07:36 50688 ----a-w- c:\windows\system32\ff_acm.acm
2010-09-01 13:57:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
============= FINISH: 8:32:47,06 ===============

Vopred ďakujem za pomoc.
DDS (Ver_10-11-27.01) - NTFSx86
Run by Jakub at 8:31:34,09 on ne 28.11.2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.511.88 [GMT 1:00]
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\CmUCReye.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
svchost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Documents and Settings\Jakub\My Documents\Preberanie\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://googleure.com
uURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe
mWinlogon: Taskman=c:\documents and settings\jakub\application data\juzjf.exe
uWinlogon: Shell=c:\recycler\s-1-5-21-4349727068-6333880499-498343625-6351\nvapbar.exe,c:\recycler\s-1-5-21-3492822507-1643205622-369944611-5105\yv8g67.exe,explorer.exe,c:\documents and settings\jakub\application data\juzjf.exe
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\GrabPro.dll
TB: {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
TB: {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {35065594-9169-4A34-B167-FC4865038E53} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NVIDIA driver monitor] c:\windows\nvsvc32.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RaidTool] c:\program files\via\raid\raid_tool.exe
mRun: [SkyTel] SkyTel.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [JMB36X Configure] c:\windows\system32\JMRaidTool.exe boot
mRun: [CmUCRRun] c:\windows\system32\CmUCReye.exe
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [UpdatePDRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles
mRun: [NokiaMusic FastStart] "c:\program files\nokia\nokia music\NokiaMusic.exe" /command:faststart
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [NVIDIA driver monitor] c:\windows\nvsvc32.exe
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [wuaucldt] c:\windows\system32\wuaucldt.exe
mRun: [Regedit32] c:\windows\system32\regedit.exe
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\0ggbssn.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\0kplbbx.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\0tpkk6w.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\1ieezqq.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\6ss6ee6.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\c3eezqqlccx.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\e3ggbssneez.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\eezk6ww6ii.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\f0lhcc6oo.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\fbww6ii6.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\s70tpkq70.exe
StartupFolder: c:\documents and settings\jakub\start menu\programs\startup\wwriiduupg.exe
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\jakub\application data\dvdvideosoftiehelpers\youtubedownload.htm
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} - hxxps://asp.photoprintit.de/microsite/5854/defaults/activex/ips/IPSUploader4.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {B96DF464-F62A-46C6-B2E4-E9F050499A76} = 217.119.117.28,217.119.113.244
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\
FF - plugin: c:\documents and settings\jakub\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\jakub\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Extension: Facicons: {DDABDBA1-2377-4A30-A027-25697B99E254} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{DDABDBA1-2377-4A30-A027-25697B99E254}
FF - Extension: U Flv: {5647f4b2-2f19-15dd-2d2b-7212613c2b46} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{5647f4b2-2f19-15dd-2d2b-7212613c2b46}
FF - Extension: {5647f4b2-2f19-15dd-2d2b-7212613c2b46}: {5647f4b2-2f19-15dd-2d2b-7212613c2b46} - c:\docume~1\jakub\applic~1\mozilla\firefox\profiles\p7177uah.default\extensions\{5647f4b2-2f19-15dd-2d2b-7212613c2b46}
============= SERVICES / DRIVERS ===============
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-7-1 34312]
R2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2008-7-1 468224]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 CMISTOR;CMIUCR.SYS CM220 Card Reader Driver;c:\windows\system32\drivers\cmiucr.SYS [2009-7-9 72320]
R3 PSched;QoS Packet Scheduler;c:\windows\system32\drivers\psched.sys [2004-8-3 69120]
S2 ea26a79qboa;Asset Management Daemon;c:\windows\system32\venelyzu.exe --> c:\windows\system32\venelyzu.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-14 136176]
S3 jkzycxdn;jkzycxdn;\??\c:\windows\system32\drivers\jkzycxdn.sys --> c:\windows\system32\drivers\jkzycxdn.sys [?]
S3 rwaofnwl;rwaofnwl;\??\c:\windows\system32\drivers\rwaofnwl.sys --> c:\windows\system32\drivers\rwaofnwl.sys [?]
S3 yvhsauqu;yvhsauqu;\??\c:\windows\system32\drivers\yvhsauqu.sys --> c:\windows\system32\drivers\yvhsauqu.sys [?]
=============== Created Last 30 ================
2010-11-28 06:28:06 315392 ----a-w- c:\windows\system32\pyly.exe
2010-11-27 16:54:30 -------- d-----w- c:\program files\VirtualDJ
2010-11-27 10:28:50 30560 ----a-w- c:\windows\system32\drivers\wcscd.sys
2010-11-22 15:42:37 -------- d-----w- c:\docume~1\jakub\locals~1\applic~1\Electronic Arts
2010-11-21 21:26:31 256 ----a-w- C:\HDTV.exe
2010-11-20 14:31:17 85504 --sh--r- c:\docume~1\jakub\applic~1\juzjf.exe
2010-11-20 14:31:07 85504 ----a-w- C:\wifi32.exe
2010-11-15 19:30:41 90978 ----a-w- C:\winnt7.exe
2010-11-15 14:40:38 72192 --sh--r- c:\windows\nvsvc32.exe
2010-11-09 14:25:42 -------- d-----w- c:\docume~1\jakub\locals~1\applic~1\Unity
2010-11-08 06:25:54 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Norton
2010-11-08 06:25:53 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Symantec
2010-11-08 06:25:45 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\NortonInstaller
2010-11-06 10:37:34 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2010-11-06 10:37:34 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2010-11-03 17:09:47 -------- d-----w- C:\divx
2010-11-03 09:07:23 -------- d-----w- c:\program files\AllToAVI
==================== Find3M ====================
2010-11-28 06:18:23 98304 ----a-w- c:\windows\DUMP6b3d.tmp
2010-11-28 06:16:50 98304 ----a-w- c:\windows\DUMP6a14.tmp
2010-11-27 14:33:40 98304 ----a-w- c:\windows\DUMP70f9.tmp
2010-09-08 07:09:46 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-09-08 07:07:36 50688 ----a-w- c:\windows\system32\ff_acm.acm
2010-09-01 13:57:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
============= FINISH: 8:32:47,06 ===============