Stránka 1 z 2

Padá "TENTO POČÍTAČ"

Napsal: 02 led 2011 19:38
od Collizia
Zdravím,
Mám taký problém, že ako náhle otvorím tento PC a prehliadam dokumnety (disk "C" disk "D" alebo USB ) tak mi to padne ( nie však vždy )...zamrzne...a vypíše mi tab. "internet.exe nemôže správne fungovať je potrebné ho ukončiť".
Vopred ďakujem.

Re: Padá "TENTO POČÍTAČ"

Napsal: 02 led 2011 19:48
od Rudy
internet.exe může být šmejd. Dejte log z RSIT: http://viry.cz/forum/viewtopic.php?f=24&t=81939 .

Re: Padá "TENTO POČÍTAČ"

Napsal: 02 led 2011 21:29
od Collizia
Nech sa páči :-)



Logfile of random's system information tool 1.08 (written by random/random)
Run by Golis family at 2011-01-02 21:27:13
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 10 GB (24%) free of 40 GB
Total RAM: 1789 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:28:48, on 2. 1. 2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Bywifi\bywifi.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\AccuWeather.com Stratus\AccuWeather.com Stratus.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\IncrediMail\Bin\ImApp.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Downloads Chrome\RSIT.exe
C:\Program Files\trend micro\Golis family.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9000/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_0.dll
R3 - URLSearchHook: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBro1.dll
R3 - URLSearchHook: (no name) - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - (no file)
R3 - URLSearchHook: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: FMTLB0001 - {3873F029-A2F7-42D1-94C1-A35ED1C59096} - C:\Program Files\FaceSounds Toolbar\tbcore3.dll
O2 - BHO: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll
O2 - BHO: wit for ie - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - (no file)
O2 - BHO: BywifiBHO - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Program Files\Bywifi\bywifiie.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBro1.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_0.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_0.dll
O3 - Toolbar: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBro1.dll
O3 - Toolbar: FaceSounds Toolbar - {8B52078D-B630-4B00-A0AB-54D51CEDD9AA} - C:\Program Files\FaceSounds Toolbar\tbcore3.dll
O3 - Toolbar: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Softonic Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKCU\..\Run: [bywifi] C:\Program Files\Bywifi\bywifi.exe "-silent"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DeskSpace] C:\Program Files\DeskSpace\deskspace.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AccuWeather.lnk = C:\Program Files\AccuWeather.com Stratus\AccuWeather.com Stratus.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Bywifi: Video Stahovač - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe
O9 - Extra 'Tools' menuitem: Bywifi: Video Stahovač - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Bywifi: Video Stahovač - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (HKCU)
O9 - Extra 'Tools' menuitem: Bywifi: Video Stahovač - {09E90109-A9AA-4980-BCEF-76F8D924E902} - C:\Program Files\Bywifi\bywifici.exe (HKCU)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan ... stubie.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\wbsys.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - D:\nainstalovanehry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 14286 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GlaryInitialize.job
C:\WINDOWS\tasks\Norton Security Scan for Golis family.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3873F029-A2F7-42D1-94C1-A35ED1C59096}]
FMTLB0001 Class - C:\Program Files\FaceSounds Toolbar\tbcore3.dll [2010-06-11 2604032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSof0.dll [2010-09-15 2735200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C4743D3E-20D7-4B52-84F2-5E4E277B2D82}]
BywifiBHO Class - C:\Program Files\Bywifi\bywifiie.dll [2010-01-05 720896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Softonic Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
IncrediMail MediaBar 2 Toolbar - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll [2010-09-12 3863136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-11-24 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-11-24 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]
Brothersoft Toolbar - C:\Program Files\Brothersoft\tbBro1.dll [2010-09-15 2735200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files\BS_Player\tbBS_0.dll [2010-09-15 2735200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-10-04 1049912]
{3041d03e-fd4b-44e0-b742-2d9b88305f98}
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSof0.dll [2010-09-15 2735200]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files\BS_Player\tbBS_0.dll [2010-09-15 2735200]
{e8de9422-3b2c-4243-bf6f-235da84d8ef8} - Brothersoft Toolbar - C:\Program Files\Brothersoft\tbBro1.dll [2010-09-15 2735200]
{8B52078D-B630-4B00-A0AB-54D51CEDD9AA} - FaceSounds Toolbar - C:\Program Files\FaceSounds Toolbar\tbcore3.dll [2010-06-11 2604032]
{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - IncrediMail MediaBar 2 Toolbar - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll [2010-09-12 3863136]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Softonic Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-07-16 61440]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-08-26 16851456]
"ClocX"=C:\Program Files\ClocX\ClocX.exe [2007-07-26 270336]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-12-09 74752]
"bywifi"=C:\Program Files\Bywifi\bywifi.exe [2010-01-05 2199552]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-11-08 2219184]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ClocX"=C:\Program Files\ClocX\ClocX.exe [2007-07-26 270336]
"bywifi"=C:\Program Files\Bywifi\bywifi.exe [2010-01-05 2199552]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2010-03-19 2363392]
"IncrediMail"=C:\Program Files\IncrediMail\bin\IncMail.exe [2010-11-25 353736]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Google Update"=C:\Documents and Settings\Golis family\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-09-11 136176]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-12-03 14944136]
"DeskSpace"=C:\Program Files\DeskSpace\deskspace.exe [2008-12-04 1621232]

C:\Documents and Settings\Golis family\Nabídka Start\Programy\Po spuštění
AccuWeather.lnk - C:\Program Files\AccuWeather.com Stratus\AccuWeather.com Stratus.exe
Stardock ObjectDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
Y'z ToolBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\WINDOWS\system32\wbsys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-08-01 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll [2001-12-20 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bywifi\bywifi.exe"="C:\Program Files\Bywifi\bywifi.exe:*:Enabled:Bywifi: Video Streaming Accelerator"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\IncrediMail\Bin\IncMail.exe"="C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\Bin\ImApp.exe"="C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\Bin\ImpCnt.exe"="C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\nainstalovanehry\BF2\BF2.exe"="D:\nainstalovanehry\BF2\BF2.exe:*:Enabled:Battlefield 2"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\nainstalovanehry\WOTLK\World of Warcraft\Launcher.exe"="D:\nainstalovanehry\WOTLK\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\nainstalovanehry\Dragon Age\bin_ship\daorigins.exe"="D:\nainstalovanehry\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Origins Game"
"D:\nainstalovanehry\Dragon Age\DAOriginsLauncher.exe"="D:\nainstalovanehry\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Origins Launcher"
"D:\nainstalovanehry\Dragon Age\bin_ship\daupdatersvc.service.exe"="D:\nainstalovanehry\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Updater"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-12-31 20:28:04 ----A---- C:\WINDOWS\IE4 Error Log.txt
2010-12-30 01:10:12 ----D---- C:\Program Files\Müllabfuhr-Simulator 2011
2010-12-29 16:01:56 ----D---- C:\Documents and Settings\Golis family\Data aplikací\OtakuSoftware
2010-12-29 16:01:48 ----D---- C:\Program Files\DeskSpace
2010-12-29 01:11:38 ----A---- C:\WINDOWS\system32\kbdkor.dll
2010-12-29 01:11:38 ----A---- C:\WINDOWS\system32\kbdjpn.dll
2010-12-29 01:11:38 ----A---- C:\WINDOWS\system32\kbd106.dll
2010-12-29 01:11:38 ----A---- C:\WINDOWS\system32\kbd103.dll
2010-12-29 01:11:38 ----A---- C:\WINDOWS\system32\kbd101c.dll
2010-12-29 01:11:37 ----A---- C:\WINDOWS\system32\kbd101b.dll
2010-12-26 02:45:06 ----D---- C:\Program Files\Bagger-Simulator 2011
2010-12-23 22:01:16 ----D---- C:\Program Files\Common Files\Adobe
2010-12-18 13:11:12 ----D---- C:\Program Files\Winamp Detect
2010-12-18 13:11:03 ----D---- C:\Documents and Settings\Golis family\Data aplikací\Winamp
2010-12-18 11:24:11 ----D---- C:\Program Files\Common Files\Skype
2010-12-18 11:24:08 ----RD---- C:\Program Files\Skype
2010-12-18 11:21:50 ----D---- C:\WINDOWS\system32\appmgmt
2010-12-13 22:36:19 ----D---- C:\Documents and Settings\Golis family\Data aplikací\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2010-12-13 20:05:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\BioWare
2010-12-13 17:14:42 ----D---- C:\WINDOWS\1C4551A64743409391E41477CD655043.TMP
2010-12-13 16:56:42 ----D---- C:\Program Files\Common Files\BioWare
2010-12-13 16:52:44 ----D---- C:\Documents and Settings\Golis family\Data aplikací\PriceGong
2010-12-13 13:33:22 ----D---- C:\totalcmd
2010-12-13 13:33:22 ----A---- C:\WINDOWS\wincmd.ini
2010-12-13 13:33:22 ----A---- C:\WINDOWS\UC.PIF
2010-12-13 13:33:22 ----A---- C:\WINDOWS\RAR.PIF
2010-12-13 13:33:22 ----A---- C:\WINDOWS\PKZIP.PIF
2010-12-13 13:33:22 ----A---- C:\WINDOWS\PKUNZIP.PIF
2010-12-13 13:33:22 ----A---- C:\WINDOWS\NOCLOSE.PIF
2010-12-13 13:33:22 ----A---- C:\WINDOWS\LHA.PIF
2010-12-13 13:33:22 ----A---- C:\WINDOWS\ARJ.PIF
2010-12-06 20:15:01 ----D---- C:\Program Files\Ask.com

======List of files/folders modified in the last 1 months======

2011-01-02 21:28:46 ----D---- C:\Program Files\trend micro
2011-01-02 21:28:39 ----D---- C:\WINDOWS\temp
2011-01-02 21:27:25 ----D---- C:\WINDOWS\Prefetch
2011-01-02 21:23:15 ----D---- C:\Documents and Settings\Golis family\Data aplikací\Skype
2011-01-02 20:27:06 ----A---- C:\WINDOWS\NeroDigital.ini
2011-01-02 18:03:41 ----D---- C:\Documents and Settings\Golis family\Data aplikací\skypePM
2011-01-01 23:54:04 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-01-01 21:17:07 ----D---- C:\WINDOWS
2011-01-01 17:32:33 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-01-01 09:48:47 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-30 01:12:00 ----D---- C:\WINDOWS\system32\config
2010-12-30 01:10:12 ----D---- C:\Program Files
2010-12-29 01:11:45 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-29 01:11:38 ----AD---- C:\WINDOWS\system32
2010-12-28 23:27:07 ----SHD---- C:\WINDOWS\Installer
2010-12-28 20:38:24 ----D---- C:\Documents and Settings\Golis family\Data aplikací\vlc
2010-12-25 17:41:19 ----HD---- C:\WINDOWS\inf
2010-12-23 22:01:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-12-23 22:01:16 ----D---- C:\Program Files\Common Files
2010-12-23 22:01:16 ----D---- C:\Program Files\Adobe
2010-12-22 09:37:14 ----D---- C:\Program Files\Java
2010-12-21 22:00:01 ----D---- C:\WINDOWS\system32\drivers
2010-12-21 17:54:05 ----D---- C:\Program Files\ESET
2010-12-20 20:05:42 ----D---- C:\Program Files\Mozilla Firefox
2010-12-20 11:06:29 ----D---- C:\Program Files\WinRAR
2010-12-18 17:16:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-12-18 13:11:19 ----D---- C:\Program Files\Winamp
2010-12-17 23:38:48 ----D---- C:\WINDOWS\Minidump
2010-12-16 20:50:26 ----D---- C:\Program Files\Opera
2010-12-14 20:10:12 ----D---- C:\Documents and Settings\Golis family\Data aplikací\BSplayer
2010-12-13 17:14:40 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-12-13 15:01:09 ----SD---- C:\WINDOWS\Tasks
2010-12-13 12:32:45 ----D---- C:\Documents and Settings\Golis family\Data aplikací\DivX
2010-12-11 09:44:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ahcix86;ahcix86; C:\WINDOWS\system32\drivers\ahcix86.sys [2008-05-27 174600]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 pavboot;pavboot; C:\WINDOWS\system32\drivers\pavboot.sys [2009-06-30 28552]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-07-12 45648]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-04-29 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-08-03 95896]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-08-01 3266560]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-08-06 25280]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-08-27 4754432]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 RTHDMIAzAudService;Service for HDMI; C:\WINDOWS\system32\drivers\RtHDMI.sys [2008-08-26 3684352]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-08-07 111360]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 a3pnf0sq;a3pnf0sq; C:\WINDOWS\system32\drivers\a3pnf0sq.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2004-08-03 25600]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-08-01 573440]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-11-08 810144]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-12 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-03-19 73728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater; D:\nainstalovanehry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-11-08 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-06-14 615936]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Padá "TENTO POČÍTAČ"

Napsal: 02 led 2011 22:19
od Rudy
Pár šmejdů tam vidím. Udělejte sken ComboFix a dejte log:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Padá "TENTO POČÍTAČ"

Napsal: 02 led 2011 22:42
od Collizia
log:



ComboFix 11-01-02.02 - Golis family . 01. 2011 22:32:53.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1789.1219 [GMT 1:00]
Spuštěný z: d:\downloads chrome\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Golis family\Data aplikací\PriceGong
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\1.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\a.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\b.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\c.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\d.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\e.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\f.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\g.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\h.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\i.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\J.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\k.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\l.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\m.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\mru.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\n.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\o.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\p.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\q.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\r.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\s.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\t.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\u.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\v.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\w.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\x.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\y.xml
c:\documents and settings\Golis family\Data aplikací\PriceGong\Data\z.xml

c:\windows\regedit.exe . . . je infikován!!

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-02 do 2011-01-02 )))))))))))))))))))))))))))))))
.

2010-12-30 00:10 . 2010-12-30 00:10 -------- d-----w- c:\program files\Müllabfuhr-Simulator 2011
2010-12-29 15:01 . 2010-12-29 15:01 -------- d-----w- c:\documents and settings\Golis family\Data aplikací\OtakuSoftware
2010-12-29 15:01 . 2010-12-29 15:01 -------- d-----w- c:\program files\DeskSpace
2010-12-29 00:11 . 2001-08-18 05:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-12-29 00:11 . 2001-08-18 05:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-12-29 00:11 . 2001-08-18 05:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-12-29 00:11 . 2001-08-18 05:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd106.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-12-29 00:11 . 2001-08-17 21:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-12-29 00:11 . 2001-08-17 21:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2010-12-26 01:45 . 2010-12-26 01:46 -------- d-----w- c:\program files\Bagger-Simulator 2011
2010-12-23 21:01 . 2010-12-23 21:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-12-18 12:11 . 2010-12-18 12:11 -------- d-----w- c:\program files\Winamp Detect
2010-12-18 12:11 . 2010-12-18 18:38 -------- d-----w- c:\documents and settings\Golis family\Data aplikací\Winamp
2010-12-18 10:24 . 2010-12-18 10:24 -------- d-----w- c:\program files\Common Files\Skype
2010-12-18 10:24 . 2010-12-18 10:24 -------- d-----r- c:\program files\Skype
2010-12-13 21:36 . 2010-12-13 21:36 -------- d-----w- c:\documents and settings\Golis family\Data aplikací\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2010-12-13 19:05 . 2010-12-13 19:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BioWare
2010-12-13 16:14 . 2010-12-13 16:14 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
2010-12-13 15:56 . 2010-12-13 16:14 -------- d-----w- c:\program files\Common Files\BioWare
2010-12-13 15:52 . 2010-12-31 19:27 -------- d-----w- c:\documents and settings\Golis family\Local Settings\Data aplikací\AskToolbar
2010-12-13 12:33 . 2010-12-13 12:33 -------- d-----w- C:\totalcmd
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\UC.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\RAR.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\PKZIP.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\LHA.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\ARJ.PIF
2010-12-09 10:47 . 2010-12-09 10:47 12800 ----a-w- c:\program files\Mozilla Firefox\plugins\npwachk.dll
2010-12-06 19:15 . 2010-12-13 14:01 -------- d-----w- c:\program files\Ask.com

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 17:53 . 2010-04-15 16:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2010-04-15 16:52 73728 ----a-w- c:\windows\system32\javacpl.cpl
.

------- Sigcheck -------

[-] 2008-04-14 . 27AFD587C462E280EE046B8CCA3C2CD1 . 1034240 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[-] 2004-08-17 . 3CA180B1D5BD5CC22374B2FB77491EE8 . 1881088 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[-] 2004-08-17 . 3CA180B1D5BD5CC22374B2FB77491EE8 . 1881088 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\explorer.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-09-15 2735200]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_0.dll" [2010-09-15 2735200]
"{e8de9422-3b2c-4243-bf6f-235da84d8ef8}"= "c:\program files\Brothersoft\tbBro1.dll" [2010-09-15 2735200]
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files\IncrediMail_MediaBar_2\tbIncr.dll" [2010-09-12 3863136]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-09-12 14:02 3863136 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3873F029-A2F7-42D1-94C1-A35ED1C59096}]
2010-06-11 15:44 2604032 ------w- c:\program files\FaceSounds Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2010-09-15 13:36 2735200 ----a-w- c:\program files\Softonic-Eng7\tbSof0.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
2010-09-12 14:02 3863136 ----a-w- c:\program files\IncrediMail_MediaBar_2\tbIncr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]
2010-09-15 13:36 2735200 ----a-w- c:\program files\Brothersoft\tbBro1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-09-15 13:36 2735200 ----a-w- c:\program files\BS_Player\tbBS_0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-09-15 2735200]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_0.dll" [2010-09-15 2735200]
"{e8de9422-3b2c-4243-bf6f-235da84d8ef8}"= "c:\program files\Brothersoft\tbBro1.dll" [2010-09-15 2735200]
"{8B52078D-B630-4B00-A0AB-54D51CEDD9AA}"= "c:\program files\FaceSounds Toolbar\tbcore3.dll" [2010-06-11 2604032]
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files\IncrediMail_MediaBar_2\tbIncr.dll" [2010-09-12 3863136]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-09-12 3863136]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]

[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{8b52078d-b630-4b00-a0ab-54d51cedd9aa}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001]

[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-09-15 2735200]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_0.dll" [2010-09-15 2735200]
"{E8DE9422-3B2C-4243-BF6F-235DA84D8EF8}"= "c:\program files\Brothersoft\tbBro1.dll" [2010-09-15 2735200]
"{8B52078D-B630-4B00-A0AB-54D51CEDD9AA}"= "c:\program files\FaceSounds Toolbar\tbcore3.dll" [2010-06-11 2604032]
"{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}"= "c:\program files\IncrediMail_MediaBar_2\tbIncr.dll" [2010-09-12 3863136]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]

[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{8b52078d-b630-4b00-a0ab-54d51cedd9aa}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001]

[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"bywifi"="c:\program files\Bywifi\bywifi.exe" [2010-01-05 2199552]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-03-19 2363392]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2010-11-25 353736]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Google Update"="c:\documents and settings\Golis family\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-09-11 136176]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"DeskSpace"="c:\program files\DeskSpace\deskspace.exe" [2008-12-04 1621232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-07-16 61440]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-26 16851456]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-09 74752]
"bywifi"="c:\program files\Bywifi\bywifi.exe" [2010-01-05 2199552]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-11-08 2219184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\Golis family\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AccuWeather.lnk - c:\program files\AccuWeather.com Stratus\AccuWeather.com Stratus.exe [2010-9-28 95232]
Stardock ObjectDock.lnk - c:\windows\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-2-21 1826885]
Y'z ToolBar.lnk - c:\windows\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-9-29 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 21:34 24576 ----a-w- c:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bywifi\\bywifi.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\nainstalovanehry\\BF2\\BF2.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"d:\\nainstalovanehry\\Dragon Age\\bin_ship\\daorigins.exe"=
"d:\\nainstalovanehry\\Dragon Age\\DAOriginsLauncher.exe"=
"d:\\nainstalovanehry\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [22. 3. 2009 11:25 174600]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [28. 6. 2010 10:36 28552]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14. 4. 2010 12:44 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29. 7. 2010 12:31 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [3. 8. 2010 12:28 95896]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [8. 11. 2010 9:50 810144]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [13. 4. 2010 22:33 246520]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\nainstalovanehry\Dragon Age\bin_ship\daupdatersvc.service.exe [13. 12. 2010 17:08 25832]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [12. 10. 2010 20:34 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [12. 10. 2010 20:34 8320]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-03-19 09:15 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2011-01-02 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-04-14 15:58]

2011-01-01 c:\windows\Tasks\Norton Security Scan for Golis family.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-11-28 08:48]

2011-01-02 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 21:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://mystart.incredimail.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{09E90109-A9AA-4980-BCEF-76F8D924E902} - c:\program files\Bywifi\bywifici.exe
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
FF - ProfilePath - c:\documents and settings\Golis family\Data aplikací\Mozilla\Firefox\Profiles\dmrp1idn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.2&q=
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: LoudMo Contextual Ad Assistant: {b959bf0c-acd8-67e8-ac75-c33ca9f4779b} - c:\program files\Mozilla Firefox\extensions\{b959bf0c-acd8-67e8-ac75-c33ca9f4779b}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
FF - Ext: Facemoods: ffxtlbr@Facemoods.com - %profile%\extensions\ffxtlbr@Facemoods.com
FF - Ext: OnAir_FM: onair_FM@marek.chrenko.net - %profile%\extensions\onair_FM@marek.chrenko.net
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: FaceSounds Toolbar: {8B52078D-B630-4B00-A0AB-54D51CEDD9AA} - %profile%\extensions\{8B52078D-B630-4B00-A0AB-54D51CEDD9AA}
FF - Ext: IncrediMail MediaBar 2 Toolbar: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - %profile%\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
FF - Ext: Softonic Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see hxxp://www.mozilla.org/unix/customizing.html#prefs
*/
FF - user.js: network.proxy.type - 2
FF - user.js: network.proxy.autoconfig_url - hxxp://localhost:9000/proxy.pac
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-02 22:35
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{750C27DA-3E50-01F2-4522-B614058EB036}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abmcdpoppablbkmiahdckpneijcpfakcbb"=hex:6b,61,69,68,6f,67,68,61,69,6f,70,61,
6b,68,67,66,64,70,61,6a,6d,63,00,00
"pagcjmhgaemnanjapnkkambmopomfbco"=hex:69,61,69,68,62,68,6c,63,62,70,68,6f,65,
63,65,6d,6d,6f,00,00
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(856)
c:\windows\system32\Ati2evxx.dll
c:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
.
Celkový čas: 2011-01-02 22:36:39
ComboFix-quarantined-files.txt 2011-01-02 21:36
ComboFix2.txt 2010-10-20 18:47

Před spuštěním: Volných bajtů: 10 136 571 904
Po spuštění: Volných bajtů: 11 257 622 528

- - End Of File - - BD275D1BE4A6FFBC8C1128C2B7BB4C32

Re: Padá "TENTO POČÍTAČ"

Napsal: 02 led 2011 23:05
od Rudy
Ještě dočistíme. Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files\Ask.com

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
[-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-

Regnull::
[HKEY_USERS\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{750C27DA-3E50-01F2-4522-B614058EB036}*]
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Padá "TENTO POČÍTAČ"

Napsal: 03 led 2011 00:07
od Collizia
COMBO :



ComboFix 11-01-02.02 - Golis family . 01. 2011 0:01.5.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1789.1159 [GMT 1:00]
Spuštěný z: c:\documents and settings\Golis family\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Golis family\Plocha\CFScript.txt.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_27bd.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe

c:\windows\regedit.exe . . . je infikován!!

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-02 do 2011-01-02 )))))))))))))))))))))))))))))))
.

2010-12-30 00:10 . 2010-12-30 00:10 -------- d-----w- c:\program files\Müllabfuhr-Simulator 2011
2010-12-29 15:01 . 2010-12-29 15:01 -------- d-----w- c:\documents and settings\Golis family\Data aplikací\OtakuSoftware
2010-12-29 15:01 . 2010-12-29 15:01 -------- d-----w- c:\program files\DeskSpace
2010-12-29 00:11 . 2001-08-18 05:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-12-29 00:11 . 2001-08-18 05:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-12-29 00:11 . 2001-08-18 05:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-12-29 00:11 . 2001-08-18 05:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd106.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-12-29 00:11 . 2001-08-17 21:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-12-29 00:11 . 2001-08-17 21:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-12-29 00:11 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2010-12-26 01:45 . 2010-12-26 01:46 -------- d-----w- c:\program files\Bagger-Simulator 2011
2010-12-23 21:01 . 2010-12-23 21:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-12-18 12:11 . 2010-12-18 12:11 -------- d-----w- c:\program files\Winamp Detect
2010-12-18 12:11 . 2010-12-18 18:38 -------- d-----w- c:\documents and settings\Golis family\Data aplikací\Winamp
2010-12-18 10:24 . 2010-12-18 10:24 -------- d-----w- c:\program files\Common Files\Skype
2010-12-18 10:24 . 2010-12-18 10:24 -------- d-----r- c:\program files\Skype
2010-12-13 21:36 . 2010-12-13 21:36 -------- d-----w- c:\documents and settings\Golis family\Data aplikací\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2010-12-13 19:05 . 2010-12-13 19:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BioWare
2010-12-13 16:14 . 2010-12-13 16:14 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
2010-12-13 15:56 . 2010-12-13 16:14 -------- d-----w- c:\program files\Common Files\BioWare
2010-12-13 15:52 . 2010-12-31 19:27 -------- d-----w- c:\documents and settings\Golis family\Local Settings\Data aplikací\AskToolbar
2010-12-13 12:33 . 2010-12-13 12:33 -------- d-----w- C:\totalcmd
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\UC.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\RAR.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\PKZIP.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\LHA.PIF
2010-12-13 12:33 . 2007-09-05 06:02 545 ----a-w- c:\windows\ARJ.PIF
2010-12-09 10:47 . 2010-12-09 10:47 12800 ----a-w- c:\program files\Mozilla Firefox\plugins\npwachk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 17:53 . 2010-04-15 16:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2010-04-15 16:52 73728 ----a-w- c:\windows\system32\javacpl.cpl
.

------- Sigcheck -------

[-] 2008-04-14 . 27AFD587C462E280EE046B8CCA3C2CD1 . 1034240 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[-] 2004-08-17 . 3CA180B1D5BD5CC22374B2FB77491EE8 . 1881088 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[-] 2004-08-17 . 3CA180B1D5BD5CC22374B2FB77491EE8 . 1881088 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\explorer.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-09-15 2735200]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_0.dll" [2010-09-15 2735200]
"{e8de9422-3b2c-4243-bf6f-235da84d8ef8}"= "c:\program files\Brothersoft\tbBro1.dll" [2010-09-15 2735200]
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files\IncrediMail_MediaBar_2\tbIncr.dll" [2010-09-12 3863136]

[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-09-12 14:02 3863136 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3873F029-A2F7-42D1-94C1-A35ED1C59096}]
2010-06-11 15:44 2604032 ------w- c:\program files\FaceSounds Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2010-09-15 13:36 2735200 ----a-w- c:\program files\Softonic-Eng7\tbSof0.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
2010-09-12 14:02 3863136 ----a-w- c:\program files\IncrediMail_MediaBar_2\tbIncr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]
2010-09-15 13:36 2735200 ----a-w- c:\program files\Brothersoft\tbBro1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-09-15 13:36 2735200 ----a-w- c:\program files\BS_Player\tbBS_0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-09-15 2735200]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_0.dll" [2010-09-15 2735200]
"{e8de9422-3b2c-4243-bf6f-235da84d8ef8}"= "c:\program files\Brothersoft\tbBro1.dll" [2010-09-15 2735200]
"{8B52078D-B630-4B00-A0AB-54D51CEDD9AA}"= "c:\program files\FaceSounds Toolbar\tbcore3.dll" [2010-06-11 2604032]
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files\IncrediMail_MediaBar_2\tbIncr.dll" [2010-09-12 3863136]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-09-12 3863136]

[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{8b52078d-b630-4b00-a0ab-54d51cedd9aa}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001]

[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-09-15 2735200]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_0.dll" [2010-09-15 2735200]
"{E8DE9422-3B2C-4243-BF6F-235DA84D8EF8}"= "c:\program files\Brothersoft\tbBro1.dll" [2010-09-15 2735200]
"{8B52078D-B630-4B00-A0AB-54D51CEDD9AA}"= "c:\program files\FaceSounds Toolbar\tbcore3.dll" [2010-06-11 2604032]
"{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}"= "c:\program files\IncrediMail_MediaBar_2\tbIncr.dll" [2010-09-12 3863136]

[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{8b52078d-b630-4b00-a0ab-54d51cedd9aa}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\FMTLB0001.FMTLB0001]

[HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"bywifi"="c:\program files\Bywifi\bywifi.exe" [2010-01-05 2199552]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-03-19 2363392]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2010-11-25 353736]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Google Update"="c:\documents and settings\Golis family\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-09-11 136176]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"DeskSpace"="c:\program files\DeskSpace\deskspace.exe" [2008-12-04 1621232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-07-16 61440]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-26 16851456]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-09 74752]
"bywifi"="c:\program files\Bywifi\bywifi.exe" [2010-01-05 2199552]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-11-08 2219184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\Golis family\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AccuWeather.lnk - c:\program files\AccuWeather.com Stratus\AccuWeather.com Stratus.exe [2010-9-28 95232]
Stardock ObjectDock.lnk - c:\windows\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-2-21 1826885]
Y'z ToolBar.lnk - c:\windows\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-9-29 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 21:34 24576 ----a-w- c:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bywifi\\bywifi.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\nainstalovanehry\\BF2\\BF2.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"d:\\nainstalovanehry\\Dragon Age\\bin_ship\\daorigins.exe"=
"d:\\nainstalovanehry\\Dragon Age\\DAOriginsLauncher.exe"=
"d:\\nainstalovanehry\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [22. 3. 2009 11:25 174600]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [28. 6. 2010 10:36 28552]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14. 4. 2010 12:44 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29. 7. 2010 12:31 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [3. 8. 2010 12:28 95896]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [8. 11. 2010 9:50 810144]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [13. 4. 2010 22:33 246520]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\nainstalovanehry\Dragon Age\bin_ship\daupdatersvc.service.exe [13. 12. 2010 17:08 25832]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [12. 10. 2010 20:34 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [12. 10. 2010 20:34 8320]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-03-19 09:15 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2011-01-02 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-04-14 15:58]

2011-01-01 c:\windows\Tasks\Norton Security Scan for Golis family.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-11-28 08:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://mystart.incredimail.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{09E90109-A9AA-4980-BCEF-76F8D924E902} - c:\program files\Bywifi\bywifici.exe
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
FF - ProfilePath - c:\documents and settings\Golis family\Data aplikací\Mozilla\Firefox\Profiles\dmrp1idn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.2&q=
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: LoudMo Contextual Ad Assistant: {b959bf0c-acd8-67e8-ac75-c33ca9f4779b} - c:\program files\Mozilla Firefox\extensions\{b959bf0c-acd8-67e8-ac75-c33ca9f4779b}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
FF - Ext: Facemoods: ffxtlbr@Facemoods.com - %profile%\extensions\ffxtlbr@Facemoods.com
FF - Ext: OnAir_FM: onair_FM@marek.chrenko.net - %profile%\extensions\onair_FM@marek.chrenko.net
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: FaceSounds Toolbar: {8B52078D-B630-4B00-A0AB-54D51CEDD9AA} - %profile%\extensions\{8B52078D-B630-4B00-A0AB-54D51CEDD9AA}
FF - Ext: IncrediMail MediaBar 2 Toolbar: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - %profile%\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
FF - Ext: Softonic Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see hxxp://www.mozilla.org/unix/customizing.html#prefs
*/
FF - user.js: network.proxy.type - 2
FF - user.js: network.proxy.autoconfig_url - hxxp://localhost:9000/proxy.pac
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-03 00:05
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(856)
c:\windows\system32\Ati2evxx.dll
c:\program files\Stardock\Object Desktop\ThemeManager\fastload.dll
.
Celkový čas: 2011-01-03 00:05:59
ComboFix-quarantined-files.txt 2011-01-02 23:05
ComboFix2.txt 2011-01-02 21:36
ComboFix3.txt 2010-10-20 18:47

Před spuštěním: Volných bajtů: 10 990 198 784
Po spuštění: Volných bajtů: 10 974 740 480

- - End Of File - - FB8F20A25DA4AB2AA476F2BB1D8F9B62
a ďakujem za venovanie sa mi :-)

Re: Padá "TENTO POČÍTAČ"

Napsal: 03 led 2011 13:41
od Collizia
Už to mám v poriadku ? :o

Re: Padá "TENTO POČÍTAČ"

Napsal: 03 led 2011 17:36
od Rudy
Smazáno, ještě, prosím, otestujte tento soubor: c:\windows\regedit.exe online na www.virustotal.com . Výsledek oznamte.

Re: Padá "TENTO POČÍTAČ"

Napsal: 05 led 2011 20:35
od Collizia
Nech sa páči :


File name:
regedit.exe
Submission date:
2010-12-13 17:25:03 (UTC)
Current status:
finished
Result:
0 /42 (0.0%) VT Community

not reviewed
Safety score: -

Compact
Print results Antivirus Version Last Update Result
AhnLab-V3 2010.12.13.01 2010.12.12 -
AntiVir 7.10.15.12 2010.12.13 -
Antiy-AVL 2.0.3.7 2010.12.13 -
Avast 4.8.1351.0 2010.12.13 -
Avast5 5.0.677.0 2010.12.13 -
AVG 9.0.0.851 2010.12.13 -
BitDefender 7.2 2010.12.13 -
CAT-QuickHeal 11.00 2010.12.13 -
ClamAV 0.96.4.0 2010.12.13 -
Command 5.2.11.5 2010.12.13 -
Comodo 7048 2010.12.13 -
DrWeb 5.0.2.03300 2010.12.13 -
Emsisoft 5.1.0.1 2010.12.13 -
eSafe 7.0.17.0 2010.12.09 -
eTrust-Vet 36.1.8037 2010.12.13 -
F-Prot 4.6.2.117 2010.12.13 -
F-Secure 9.0.16160.0 2010.12.13 -
Fortinet 4.2.254.0 2010.12.13 -
GData 21 2010.12.13 -
Ikarus T3.1.1.90.0 2010.12.13 -
Jiangmin 13.0.900 2010.12.13 -
K7AntiVirus 9.72.3235 2010.12.13 -
Kaspersky 7.0.0.125 2010.12.13 -
McAfee 5.400.0.1158 2010.12.13 -
McAfee-GW-Edition 2010.1C 2010.12.13 -
Microsoft 1.6402 2010.12.13 -
NOD32 5699 2010.12.13 -
Norman 6.06.12 2010.12.13 -
nProtect 2010-12-13.01 2010.12.13 -
Panda 10.0.2.7 2010.12.13 -
PCTools 7.0.3.5 2010.12.13 -
Rising 22.77.06.03 2010.12.13 -
Sophos 4.60.0 2010.12.13 -
SUPERAntiSpyware 4.40.0.1006 2010.12.13 -
Symantec 20101.3.0.103 2010.12.13 -
TheHacker 6.7.0.1.099 2010.12.13 -
TrendMicro 9.120.0.1004 2010.12.13 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.13 -
VBA32 3.12.14.2 2010.12.13 -
VIPRE 7634 2010.12.13 -
ViRobot 2010.12.13.4198 2010.12.13 -
VirusBuster 13.6.92.0 2010.12.13 -
Additional information
Show all
MD5 : 303784db4b8df72c19e5ce96fc45087b
SHA1 : d9fc8d45c30100c1aa107c041cd91ed2052192e4
SHA256: e4cab78ca122d3a03d769ff274c5f07c55c4093f1c8ecae4fe9aca54fb62f72c
ssdeep: 12288:PaMVkUet7EwBI+APu7IIX1Z15tMnMGzxMnMBTffa7:PzVkUetVI5uhF5tMnMGzxMnMty7
File size : 418304 bytes
First seen: 2010-12-13 11:13:12
Last seen : 2010-12-13 17:25:03
Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
TrID:
Win32 Executable MS Visual C++ (generic) (53.1%)
Windows Screen Saver (18.4%)
Win32 Executable Generic (12.0%)
Win32 Dynamic Link Library (generic) (10.6%)
Generic Win/DOS Executable (2.8%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. V_echna pr_va vyhrazena.
product......: Microsoft_ Windows_ Operating System
description..: Editor registru
original name: REGEDIT.EXE
internal name: REGEDIT
file version.: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEiD: -
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x168EC
timedatestamp....: 0x41107C0F (Wed Aug 04 06:02:55 2004)
machinetype......: 0x14C (Intel I386)

[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x178D2, 0x17A00, 6.36, 7e7cbed25b02b3bf92f7c446d1b85239
.data, 0x19000, 0x40DA0, 0x400, 1.2, 608604848080cee7338324c4556bee35
.rsrc, 0x5A000, 0x4DF15, 0x4E000, 4.65, c0b6da2e4f06369e2fcb22aabf46ccaa

[[ 14 import(s) ]]
aclui.dll: -
advapi32.dll: RegQueryValueExA, RegOpenKeyExA, InitializeSecurityDescriptor, RegDeleteValueW, InitializeAcl, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetInheritanceSourceW, LookupAccountSidW, GetSidSubAuthorityCount, GetSidSubAuthority, GetSecurityDescriptorControl, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, SetSecurityInfo, SetNamedSecurityInfoW, GetNamedSecurityInfoW, MapGenericMask, RegSetValueExA, RegSetValueW, RegFlushKey, RegSaveKeyW, RegRestoreKeyW, RegConnectRegistryW, RegQueryValueExW, RegCloseKey, RegOpenKeyW, RegSetValueExW, RegCreateKeyW, RegEnumValueW, RegEnumKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, RegUnLoadKeyW, RegLoadKeyW, RegOpenKeyExW, RegQueryInfoKeyW, RegDeleteKeyW
authz.dll: AuthzInitializeContextFromSid, AuthzAccessCheck, AuthzFreeContext, AuthzFreeResourceManager, AuthzInitializeResourceManager
clb.dll: ClbAddData, ClbSetColumnWidths
comctl32.dll: -, -, -, -, InitCommonControlsEx, -, -, ImageList_SetBkColor, ImageList_Create, ImageList_Destroy, -, -, ImageList_ReplaceIcon, -, -, -, -, CreateStatusWindowW
comdlg32.dll: GetOpenFileNameW, GetSaveFileNameW, PrintDlgExW
gdi32.dll: GetStockObject, SetAbortProc, StartDocW, StartPage, SetViewportOrgEx, EndPage, EndDoc, AbortDoc, DeleteDC, CreateBitmap, CreatePatternBrush, PatBlt, ExcludeClipRect, SelectClipRgn, DeleteObject, SetBkColor, SetTextColor, ExtTextOutW, GetDeviceCaps, CreateFontIndirectW, SelectObject, GetTextMetricsW
kernel32.dll: ReadFile, DeleteFileW, WriteFile, WideCharToMultiByte, CreateFileW, OutputDebugStringW, GetLastError, SetFilePointer, GetFileSize, SearchPathW, GetTimeFormatW, GetDateFormatW, GetSystemDefaultLCID, FileTimeToSystemTime, FileTimeToLocalFileTime, FreeLibrary, LoadLibraryW, MulDiv, lstrcpynW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, MultiByteToWideChar, lstrcmpW, FormatMessageW, GetThreadLocale, GetModuleHandleW, ExitProcess, GetCommandLineW, GetProcessHeap, lstrcatW, LocalAlloc, GetCurrentProcess, CloseHandle, LocalFree, GetComputerNameW, lstrcmpiW, lstrlenW, lstrcpyW, LocalReAlloc, GlobalAlloc, GlobalLock, GlobalUnlock, GetProcAddress, LoadLibraryA
msvcrt.dll: __p__commode, _adjust_fdiv, __p__fmode, _initterm, __getmainargs, _acmdln, __set_app_type, _except_handler3, __setusermatherr, _controlfp, exit, _XcptFilter, _exit, _c_exit, swprintf, iswprint, wcsncpy, wcslen, wcscat, wcscpy, _purecall, iswctype, wcscmp, wcschr, wcsncmp, wcsrchr, _cexit, memmove
ntdll.dll: RtlFreeHeap, RtlAllocateHeap
ole32.dll: CoCreateInstance, CoUninitialize, CoInitializeEx, ReleaseStgMedium
shell32.dll: ShellAboutW, DragQueryFileW, DragFinish
ulib.dll: _Resize@DSTRING@@UAEEK@Z, _Initialize@ARRAY@@QAEEKK@Z, _NewBuf@DSTRING@@UAEEK@Z, __1DSTRING@@UAE@XZ, __1OBJECT@@UAE@XZ, __0OBJECT@@IAE@XZ, _Compare@OBJECT@@UBEJPBV1@@Z, __0DSTRING@@QAE@XZ, _Initialize@WSTRING@@QAEEPBV1@KK@Z, _Strcat@WSTRING@@QAEEPBV1@@Z, __0ARRAY@@QAE@XZ, _Initialize@WSTRING@@QAEEPBGK@Z
user32.dll: SendDlgItemMessageW, SetDlgItemTextW, SetWindowLongW, DefWindowProcW, ReleaseDC, GetDC, SetScrollInfo, wsprintfW, DestroyCaret, ReleaseCapture, KillTimer, SetCaretPos, ScrollWindowEx, ShowCaret, HideCaret, InvalidateRect, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, GetClipboardData, WinHelpW, EndDialog, GetWindowLongW, EndPaint, BeginPaint, CreateCaret, SetTimer, SetCapture, SetFocus, CharLowerW, GetDlgItem, DestroyMenu, TrackPopupMenuEx, IsClipboardFormatAvailable, EnableMenuItem, GetSubMenu, LoadMenuW, GetKeyState, RegisterClassW, LoadCursorW, RegisterClipboardFormatW, CheckRadioButton, SendMessageW, GetWindowTextW, GetParent, GetDlgItemTextW, IsDlgButtonChecked, GetDlgCtrlID, CallWindowProcW, GetWindowTextLengthW, GetDlgItemInt, PostQuitMessage, GetWindowPlacement, SetWindowTextW, EnableWindow, GetWindowRect, DrawMenuBar, InsertMenuItemW, DeleteMenu, SetMenuItemInfoW, GetMenu, GetMenuItemInfoW, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, IsIconic, DestroyIcon, LoadImageW, GetSysColor, SetCursor, ShowCursor, ShowWindow, SetWindowPlacement, CreateWindowExW, GetProcessDefaultLayout, GetMessageW, ScreenToClient, SetCursorPos, DispatchMessageW, ClientToScreen, GetDesktopWindow, LoadIconW, PostMessageW, SetMenuDefaultItem, InsertMenuW, GetMenuItemID, CheckMenuItem, UpdateWindow, RegisterClassExW, CharNextW, GetClientRect, DestroyWindow, CreateDialogParamW, CheckDlgButton, DrawAnimatedRects, IntersectRect, ModifyMenuW, GetMessagePos, TranslateMessage, TranslateAcceleratorW, LoadAcceleratorsW, SetForegroundWindow, GetLastActivePopup, BringWindowToTop, FindWindowW, LoadStringW, GetWindow, IsDialogMessageW, PeekMessageW, MessageBoxW, CharUpperBuffW, CharUpperW, IsCharAlphaNumericW, GetSystemMetrics, MoveWindow, MapWindowPoints, DialogBoxParamW, SetWindowPos, MessageBeep
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 96768
CompanyName: Microsoft Corporation
EntryPoint: 0x168ec
FileDescription: Editor registru
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 408 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
FileVersionNumber: 5.1.2600.2180
ImageVersion: 5.1
InitializedDataSize: 320512
InternalName: REGEDIT
LanguageCode: Czech
LegalCopyright: Microsoft Corporation. V echna pr va vyhrazena.
LinkerVersion: 7.1
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 5.1
ObjectFileType: Executable application
OriginalFilename: REGEDIT.EXE
PEType: PE32
ProductName: Microsoft Windows Operating System
ProductVersion: 5.1.2600.2180
ProductVersionNumber: 5.1.2600.2180
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2004:08:04 08:02:55+02:00
UninitializedDataSize: 0
Warning: Possibly corrupt Version resource


VT Community

This file has never been reviewed by any VT Community member. Be the first one to comment on it!

Re: Padá "TENTO POČÍTAČ"

Napsal: 06 led 2011 18:08
od Rudy
Soubor a celý log jsou čisté. Nastala nějaká změna?

Re: Padá "TENTO POČÍTAČ"

Napsal: 06 led 2011 23:40
od Collizia
Tak to je super...snáď mi to padať už nebude :) Veľmi pekne ďakujem.

Re: Padá "TENTO POČÍTAČ"

Napsal: 07 led 2011 19:03
od Rudy
Nemáte zač!

Re: Padá "TENTO POČÍTAČ"

Napsal: 09 led 2011 14:55
od Collizia
Zdravím,
Problém je opäť na s5. Tento PC padá...zakaždým čo som ho otvoril po pár sekundách, že v "internet.exe" sa vyskytla chyba...+ mrzli všetky spustené programy...takže musel byť tvrdý reset zo pár krát + nechápem, ale začal blbnúť aj internet nikde ma nehccelo pripojiť všade mi vypisovalo, že nie som pripojený, že nemôže načítať obsah web. stránky (Google chrome, mozzila, opera ) ale najzaujímavejšie na tom bolo to , že na skype som bol nalogovaný a fungoval...kedže mám doma wifi router tak som skúsil sa pripojiť aj cez Notebook a robilo to isté iba skype išiel...neviem nechápal som...vyp. som PC aj router atď. na hoďku zo zásuvky a teraz už fičí všetko oka :-)

Re: Padá "TENTO POČÍTAČ"

Napsal: 09 led 2011 15:47
od Collizia
+ doplnenie zase asi po pol hodke používania PC mi padol net a šiel iba skype...reštart a všetko ide zase ok...neviem...možno je to aj sieťovou kartou...ak by sa dalo nejako pomôcť bol by so Vám vďačný :)