Prekonaný vírus. Nejdu antivíry a FBook
Napsal: 02 zář 2011 18:47
Zdravím ,
Pred 5 dňami som nechal moju mladšiu sestru chvilku samú na PC. Po chvíli ma však zavolala že jej tam čosi červene nabehlo , ako náhle som došiel k pc zbadal som velké červene okno od Nodu(32) a hneď sa reštartoval PC, vraj ho tam mala už predtým asi 10 min. no zrovna keď som prišiel k pc sa reštartoval jedine co som si stihnul všimnut že to bol najdutý niaky vírus a bola tam jeho adresa z ktorej si pamätám len že to bolo v system32. Po reštarte pc nabehol nudzový režim winu (mam XP SP2) hned po zapatí sa mi pc jakosy seklo tak som dal reset zasa. Normalne nabehol win , no bol spomalený. Win trochu,no ked som šiel na internet nedalo sa pracovať , jednu stránku googlu mi načítavalo skoro minútu. Po kliknutí na jeden (hociktorý pri oboch nabehlo to iste) s antivírov (mam NOD32 a aj MC.affe) mi nabehlo mensie červene okno kde bolo napísane po anglicky niečo so zmyslom že antivír sleduje pc čaka na odozvu od virusu (EDIT: FOTO:
, no nechcelo ma to ani za svet pustit do antiviru. Tak som sa do toho snažil cosi nastudovat na nete a zaviedlo ma to ku Kaspersky Virus Removal Tool (stiahlo mi to pod nazvom AVPtool11) 100 mb subor mi to stahovalo skoro tri hodiny po spustení skenu mi po par sekundach našlo niečo s nazvom trojan.(bodka) niake slova ktore som si bohužial nezapamatal , kontorolovalo niake thready či čo a resetlo pc . Po spustení PC šlo zrazu v všetko v povodnej rýchlosti aj internet . No hovoril som si dam to pre istotu ešte raz zasa som spustil AVPtool11 a zasa po par sekundach našlo niaky trojan. Niečo zase kontrolovalo niake thready a resetlo pc . Po spusteni som to pustil ešte raz a ked mi po 10 minutach nič nenašlo vypnul som to s tým že hadam bude pokoj (celkovu dobu skenu ktoru to odhadovalo bola 23 hodín to sa mi čakať nechcelo) no po spusteni internetu mi išlo všetko okrem facebooku . Všetko co malo niečo s fb mi nešlo (zdielanie z YT napr. a tak) Potom som si všimol že mi neukazuje zapnutý nod32 na lište ako bolo zvykom. Po jeho spustení (štart>programy) mi nabehlo system win. hlada subor svchost.exe ak ho chcete vyhladat ručne dajte prehladavat , alebo zrušiť. To iste naebehlo pri spusteni niakej z jeho sucasti. Pri spusteni MC.affe (štart>programy) mi zase nabehlo System win. hlada subor SSScheduler.exe. A tak som sa dostal na toto forum a žiadam Vás o pomoc. Nechapem prečo na internete ide všetko okrem facebooku a prečo tie antivíry štrajkuju. Za každú pomoc Ďakujem.
EDIT: Facebook nejde ani na jednom z prehliadačov (mam:Gchrome,Mffox,IE,Operu) takže v prehliadači chybu asi nehladať.
Tu je moj log z RSIT:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:57:12, on 2.9.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\GIGABYTE\GHOST(6980)\ghostopen.exe
C:\Program Files\GIGABYTE\GHOST(6980)\Tilt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Steam\Steam.exe
c:\program files\steam\steamapps\27shadow076\counter-strike\hl.exe
C:\Program Files\Steam\GameOverlayUI.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\My Documents\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Tibor.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.sk/keyword/%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.telecom.sk:3128
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BrowserPlugin - {1C749E08-6B62-11E0-B6DA-075F4824019B} - (no file)
O2 - BHO: IEStript.com - {3FFC332D-3286-420D-A930-C8CE3F339CC2} - C:\PROGRA~1\FASTYO~1\IEStript.dll
O2 - BHO: BrowserPlugin - {BB54C912-5131-5114-A979-F4D5402448F1} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ghost] C:\Program Files\GIGABYTE\GHOST(6980)\ghostopen.exe
O4 - HKLM\..\Run: [Tilt] C:\Program Files\GIGABYTE\GHOST(6980)\Tilt.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [8232112.exe] "C:\Temp\8232112.exe"
O4 - HKLM\..\Run: [1695691.exe] "C:\Temp\1695691.exe"
O4 - HKLM\..\Run: [8812240.exe] "C:\Temp\8812240.exe"
O4 - HKLM\..\Run: [8562959.exe] "C:\Temp\8562959.exe"
O4 - HKLM\..\Run: [6283146.exe] "C:\Temp\6283146.exe"
O4 - HKLM\..\Run: [30058766-loader2.exe] "C:\Temp\30058766-loader2.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http:\\www.stonline.sk
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1394306640
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://85.248.4.35:8088/plugin/h263ctrl.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FQPO - Unknown owner - C:\Temp\FQPO.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 8533 bytes
Pred 5 dňami som nechal moju mladšiu sestru chvilku samú na PC. Po chvíli ma však zavolala že jej tam čosi červene nabehlo , ako náhle som došiel k pc zbadal som velké červene okno od Nodu(32) a hneď sa reštartoval PC, vraj ho tam mala už predtým asi 10 min. no zrovna keď som prišiel k pc sa reštartoval jedine co som si stihnul všimnut že to bol najdutý niaky vírus a bola tam jeho adresa z ktorej si pamätám len že to bolo v system32. Po reštarte pc nabehol nudzový režim winu (mam XP SP2) hned po zapatí sa mi pc jakosy seklo tak som dal reset zasa. Normalne nabehol win , no bol spomalený. Win trochu,no ked som šiel na internet nedalo sa pracovať , jednu stránku googlu mi načítavalo skoro minútu. Po kliknutí na jeden (hociktorý pri oboch nabehlo to iste) s antivírov (mam NOD32 a aj MC.affe) mi nabehlo mensie červene okno kde bolo napísane po anglicky niečo so zmyslom že antivír sleduje pc čaka na odozvu od virusu (EDIT: FOTO:

EDIT: Facebook nejde ani na jednom z prehliadačov (mam:Gchrome,Mffox,IE,Operu) takže v prehliadači chybu asi nehladať.
Tu je moj log z RSIT:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:57:12, on 2.9.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\GIGABYTE\GHOST(6980)\ghostopen.exe
C:\Program Files\GIGABYTE\GHOST(6980)\Tilt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Steam\Steam.exe
c:\program files\steam\steamapps\27shadow076\counter-strike\hl.exe
C:\Program Files\Steam\GameOverlayUI.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tibor\My Documents\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Tibor.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.sk/keyword/%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.telecom.sk:3128
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BrowserPlugin - {1C749E08-6B62-11E0-B6DA-075F4824019B} - (no file)
O2 - BHO: IEStript.com - {3FFC332D-3286-420D-A930-C8CE3F339CC2} - C:\PROGRA~1\FASTYO~1\IEStript.dll
O2 - BHO: BrowserPlugin - {BB54C912-5131-5114-A979-F4D5402448F1} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ghost] C:\Program Files\GIGABYTE\GHOST(6980)\ghostopen.exe
O4 - HKLM\..\Run: [Tilt] C:\Program Files\GIGABYTE\GHOST(6980)\Tilt.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [8232112.exe] "C:\Temp\8232112.exe"
O4 - HKLM\..\Run: [1695691.exe] "C:\Temp\1695691.exe"
O4 - HKLM\..\Run: [8812240.exe] "C:\Temp\8812240.exe"
O4 - HKLM\..\Run: [8562959.exe] "C:\Temp\8562959.exe"
O4 - HKLM\..\Run: [6283146.exe] "C:\Temp\6283146.exe"
O4 - HKLM\..\Run: [30058766-loader2.exe] "C:\Temp\30058766-loader2.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http:\\www.stonline.sk
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1394306640
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://85.248.4.35:8088/plugin/h263ctrl.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FQPO - Unknown owner - C:\Temp\FQPO.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 8533 bytes