Mění se datum - podezření na viry
Napsal: 18 pro 2011 16:07
Prosím o konrolu logu, mám podezření na viry. Notebook se chová nestandartně, občas zamrzává a mění se mi datum o několik let zpětně.
Dále žádám o pomoc s přístupy na viry.cz. Od posledního přihlášení jsem změnila emailovou adresu na: holeckovaz@yahoo.com a zapoměla jsem své heslo. Nyní jsem se nalogovala tak, že po zadání svého přihlašovacího jména si můj prohlížeč doplnil heslo z posledního přihlášení. Obávám se, že se to příště nemusí podařit a vzhledem ke změně emailové adresy nemám možnost zaslat znovu heslo emailem.
Prosím o změnu emailu, popřípadě mě informujte jak postupovat dál.
Zde přikládám log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Moje cesky at 2011-12-18 15:50:52
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive F: has 6 GB (16%) free of 38 GB
Total RAM: 2037 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:51:17, on 18.12.2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
F:\Windows\system32\Dwm.exe
F:\Windows\Explorer.EXE
F:\Windows\system32\taskeng.exe
F:\Windows\System32\igfxtray.exe
F:\Windows\System32\hkcmd.exe
F:\Windows\System32\igfxpers.exe
F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
F:\Windows\system32\igfxsrvc.exe
F:\Program Files\ESET\ESET Smart Security\egui.exe
F:\Program Files\TrustPort Disk Protection\Bin\TDWatch.exe
F:\Program Files\Common Files\TrustPort\bin\tptray.exe
F:\Windows\WindowsMobile\wmdc.exe
F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
F:\Program Files\HP\HP Software Update\hpwuSchd2.exe
F:\Program Files\Windows Sidebar\sidebar.exe
F:\Windows\ehome\ehtray.exe
F:\Program Files\Skype\Phone\Skype.exe
F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\Program Files\Windows Media Player\wmpnscfg.exe
F:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
F:\Windows\ehome\ehmsas.exe
F:\Windows\system32\wbem\unsecapp.exe
F:\Program Files\Skype\Plugin Manager\skypePM.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
F:\Users\Moje cesky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WAZ5JR3R\RSIT[1].exe
F:\Program Files\trend micro\Moje cesky.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - F:\Program Files\MyAshampoo\prxtbMyA0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - F:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: MyAshampoo - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - F:\Program Files\MyAshampoo\prxtbMyA0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - F:\Program Files\MyAshampoo\prxtbMyA0.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] F:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] F:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] F:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [egui] "F:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TrustPortDiskProtectionWatchDog] F:\Program Files\TrustPort Disk Protection\bin\TDWatch.exe
O4 - HKLM\..\Run: [TrustPortTray] "F:\Program Files\Common Files\TrustPort\Bin\tptray.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HP Software Update] F:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Sidebar] F:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] F:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "F:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] "F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] F:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @F:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @F:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - F:\Windows\System32\DreamScene.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - F:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - F:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - F:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - F:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - F:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - F:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - F:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
--
End of file - 7321 bytes
======Scheduled tasks folder======
F:\Windows\tasks\CHYZTBSHU.job
F:\Windows\tasks\GoogleUpdateTaskMachineCore.job
F:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - F:\Users\Moje cesky\AppData\Roaming\Mozilla\Firefox\Profiles\p2fu6rbt.default
prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT24750 ... hSource=13"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:2.5.6.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.20"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=F:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=F:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=0.9.4]
"Description"=VLC Multimedia Plugin
"Path"=F:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1]
"Description"=Yahoo! activeX Plug-in Bridge
"Path"=F:\Program Files\Yahoo!\Common\npyaxmpb.dll
F:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
F:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
F:\Program Files\Mozilla Firefox\plugins\
npnul32.dll
NPOFF12.DLL
nppdf32.dll
F:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
F:\Users\Moje cesky\AppData\Roaming\Mozilla\Firefox\Profiles\p2fu6rbt.default\extensions\
{707db484-2428-402d-afb5-d85b387544c7}
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
F:\Users\Moje cesky\AppData\Roaming\Mozilla\Firefox\Profiles\p2fu6rbt.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - F:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
MyAshampoo Toolbar - F:\Program Files\MyAshampoo\prxtbMyA0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-11-30 342192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - F:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll [2011-11-11 1003576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - MyAshampoo Toolbar - F:\Program Files\MyAshampoo\prxtbMyA0.dll [2011-01-17 175912]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-11-30 342192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=F:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"HotKeysCmds"=F:\Windows\system32\hkcmd.exe [2008-02-11 166424]
"Persistence"=F:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"GrooveMonitor"=F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"egui"=F:\Program Files\ESET\ESET Smart Security\egui.exe [2009-05-14 2029640]
"TrustPortDiskProtectionWatchDog"=F:\Program Files\TrustPort Disk Protection\bin\TDWatch.exe [2009-06-12 155480]
"TrustPortTray"=F:\Program Files\Common Files\TrustPort\Bin\tptray.exe [2009-06-12 835416]
"Windows Mobile Device Center"=F:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"Adobe Reader Speed Launcher"=F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
"Adobe ARM"=F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"HP Software Update"=F:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=F:\Program Files\Windows Sidebar\sidebar.exe [2008-01-18 1233920]
"ehTray.exe"=F:\Windows\ehome\ehTray.exe [2008-01-18 125952]
"Skype"=F:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]
"swg"=F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-06-30 39408]
"WMPNSCFG"=F:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-18 202240]
F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - F:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
F:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - F:\Windows\System32\DreamScene.dll [2008-12-13 233888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"F:\Users\Moje cesky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7NU22VQU\IMAGE464-facebook.com.JPG.jpg[2].exe"="F:\Windows\infocard.exe:*:Enabled:Firewall Admin"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=F:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2023-06-27 02:16:04 ----D---- F:\ProgramData\WindowsSearch
======List of files/folders modified in the last 1 month======
2011-12-18 15:51:03 ----D---- F:\Windows\Prefetch
2011-12-18 15:50:53 ----D---- F:\Program Files\trend micro
2011-12-18 15:50:40 ----D---- F:\Windows\temp
2011-12-18 15:49:10 ----D---- F:\Users\Moje cesky\AppData\Roaming\Skype
2011-12-18 15:10:31 ----D---- F:\Users\Moje cesky\AppData\Roaming\skypePM
2011-12-08 12:23:50 ----SHD---- F:\Windows\Installer
2011-12-08 12:11:42 ----D---- F:\Program Files\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 fvevol;BitLocker Drive Encryption Filter Driver; F:\Windows\System32\DRIVERS\fvevol.sys [2008-01-18 145464]
R0 MEMLOCK;Secured Memory Driver; F:\Windows\system32\drivers\memlock.sys [2009-06-12 14136]
R1 ehdrv;ehdrv; F:\Windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R2 eamon;eamon; F:\Windows\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R2 EncDisk;EncDisk; \??\F:\Program Files\TrustPort Disk Protection\bin\EncDsk.sys [2009-06-12 55128]
R2 epfw;epfw; F:\Windows\system32\DRIVERS\epfw.sys [2009-05-14 133000]
R2 epfwwfp;epfwwfp; F:\Windows\system32\DRIVERS\epfwwfp.sys [2009-05-14 38240]
R2 rismxdp;Ricoh xD-Picture Card Driver; F:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R3 BthEnum;Služba Bluetooth Enumerator; F:\Windows\system32\DRIVERS\BthEnum.sys [2008-12-13 19456]
R3 BthPan;Zařízení Bluetooth (síť PAN); F:\Windows\system32\DRIVERS\bthpan.sys [2008-01-18 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; F:\Windows\System32\Drivers\BTHUSB.sys [2008-12-13 29184]
R3 E100B;Intel(R) PRO Adapter Driver; F:\Windows\system32\DRIVERS\e100b325.sys [2008-01-18 159744]
R3 Epfwndis;Eset Personal Firewall; F:\Windows\system32\DRIVERS\Epfwndis.sys [2009-05-14 33096]
R3 HBtnKey;HBtnKey; F:\Windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; F:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 HSF_DPV;HSF_DPV; F:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 HSFHWAZL;HSFHWAZL; F:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
R3 igfx;igfx; F:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; F:\Windows\system32\DRIVERS\NETw4v32.sys [2007-10-31 2252800]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); F:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-18 49664]
R3 rimmptsk;rimmptsk; F:\Windows\system32\DRIVERS\rimmptsk.sys [2005-11-16 28928]
R3 rimsptsk;rimsptsk; F:\Windows\system32\DRIVERS\rimsptsk.sys [2005-12-22 51840]
R3 sdbus;sdbus; F:\Windows\system32\DRIVERS\sdbus.sys [2008-01-18 88576]
R3 usbvideo;Zobrazovací zařízení USB (WDM); F:\Windows\System32\Drivers\usbvideo.sys [2008-01-18 134016]
R3 winachsf;winachsf; F:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2006-11-02 654336]
S3 BTHPORT;Ovladač portu Bluetooth; F:\Windows\System32\Drivers\BTHport.sys [2008-12-13 220160]
S3 Dot4;Ovladač MS IEEE-1284.4; F:\Windows\system32\DRIVERS\Dot4.sys [2008-01-18 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; F:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-18 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; F:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-18 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; F:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 ialm;ialm; F:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; F:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; F:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; F:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; F:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; F:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 usb_rndisx;Adaptér USB RNDIS; F:\Windows\system32\DRIVERS\usb8023x.sys [2008-01-18 15872]
S3 usbscan;Ovladač skeneru USB; F:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328]
S3 WpdUsb;WpdUsb; F:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-18 39936]
S3 WUDFRd;WUDFRd; F:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; F:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 ekrn;ESET Service; F:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; F:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; F:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; F:\Windows\system32\svchost.exe [2008-01-18 21504]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; F:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
S2 gupdate;Služba Google Update (gupdate); F:\Program Files\Google\Update\GoogleUpdate.exe [2010-06-30 135664]
S2 Net Driver HPZ12;Net Driver HPZ12; F:\Windows\System32\svchost.exe [2008-01-18 21504]
S2 Pml Driver HPZ12;Pml Driver HPZ12; F:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 EhttpSrv;ESET HTTP Server; F:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-05-14 20680]
S3 gupdatem;Služba Google Update (gupdatem); F:\Program Files\Google\Update\GoogleUpdate.exe [2010-06-30 135664]
S3 gusvc;Google Software Updater; F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-01 182768]
S3 hpqcxs08;hpqcxs08; F:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 McComponentHostService;McAfee Security Scan Component Host Service; F:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; F:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; F:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
Dále žádám o pomoc s přístupy na viry.cz. Od posledního přihlášení jsem změnila emailovou adresu na: holeckovaz@yahoo.com a zapoměla jsem své heslo. Nyní jsem se nalogovala tak, že po zadání svého přihlašovacího jména si můj prohlížeč doplnil heslo z posledního přihlášení. Obávám se, že se to příště nemusí podařit a vzhledem ke změně emailové adresy nemám možnost zaslat znovu heslo emailem.
Prosím o změnu emailu, popřípadě mě informujte jak postupovat dál.
Zde přikládám log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Moje cesky at 2011-12-18 15:50:52
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive F: has 6 GB (16%) free of 38 GB
Total RAM: 2037 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:51:17, on 18.12.2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
F:\Windows\system32\Dwm.exe
F:\Windows\Explorer.EXE
F:\Windows\system32\taskeng.exe
F:\Windows\System32\igfxtray.exe
F:\Windows\System32\hkcmd.exe
F:\Windows\System32\igfxpers.exe
F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
F:\Windows\system32\igfxsrvc.exe
F:\Program Files\ESET\ESET Smart Security\egui.exe
F:\Program Files\TrustPort Disk Protection\Bin\TDWatch.exe
F:\Program Files\Common Files\TrustPort\bin\tptray.exe
F:\Windows\WindowsMobile\wmdc.exe
F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
F:\Program Files\HP\HP Software Update\hpwuSchd2.exe
F:\Program Files\Windows Sidebar\sidebar.exe
F:\Windows\ehome\ehtray.exe
F:\Program Files\Skype\Phone\Skype.exe
F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\Program Files\Windows Media Player\wmpnscfg.exe
F:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
F:\Windows\ehome\ehmsas.exe
F:\Windows\system32\wbem\unsecapp.exe
F:\Program Files\Skype\Plugin Manager\skypePM.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
F:\Users\Moje cesky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WAZ5JR3R\RSIT[1].exe
F:\Program Files\trend micro\Moje cesky.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - F:\Program Files\MyAshampoo\prxtbMyA0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - F:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: MyAshampoo - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - F:\Program Files\MyAshampoo\prxtbMyA0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - F:\Program Files\MyAshampoo\prxtbMyA0.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] F:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] F:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] F:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [egui] "F:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TrustPortDiskProtectionWatchDog] F:\Program Files\TrustPort Disk Protection\bin\TDWatch.exe
O4 - HKLM\..\Run: [TrustPortTray] "F:\Program Files\Common Files\TrustPort\Bin\tptray.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HP Software Update] F:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Sidebar] F:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] F:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "F:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] "F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] F:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @F:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @F:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - F:\Windows\System32\DreamScene.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - F:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - F:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - F:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - F:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - F:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - F:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - F:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
--
End of file - 7321 bytes
======Scheduled tasks folder======
F:\Windows\tasks\CHYZTBSHU.job
F:\Windows\tasks\GoogleUpdateTaskMachineCore.job
F:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - F:\Users\Moje cesky\AppData\Roaming\Mozilla\Firefox\Profiles\p2fu6rbt.default
prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT24750 ... hSource=13"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:2.5.6.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.20"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=F:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=F:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=0.9.4]
"Description"=VLC Multimedia Plugin
"Path"=F:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1]
"Description"=Yahoo! activeX Plug-in Bridge
"Path"=F:\Program Files\Yahoo!\Common\npyaxmpb.dll
F:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
F:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
F:\Program Files\Mozilla Firefox\plugins\
npnul32.dll
NPOFF12.DLL
nppdf32.dll
F:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
F:\Users\Moje cesky\AppData\Roaming\Mozilla\Firefox\Profiles\p2fu6rbt.default\extensions\
{707db484-2428-402d-afb5-d85b387544c7}
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
F:\Users\Moje cesky\AppData\Roaming\Mozilla\Firefox\Profiles\p2fu6rbt.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - F:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
MyAshampoo Toolbar - F:\Program Files\MyAshampoo\prxtbMyA0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-11-30 342192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - F:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll [2011-11-11 1003576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - MyAshampoo Toolbar - F:\Program Files\MyAshampoo\prxtbMyA0.dll [2011-01-17 175912]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-11-30 342192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=F:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"HotKeysCmds"=F:\Windows\system32\hkcmd.exe [2008-02-11 166424]
"Persistence"=F:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"GrooveMonitor"=F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"egui"=F:\Program Files\ESET\ESET Smart Security\egui.exe [2009-05-14 2029640]
"TrustPortDiskProtectionWatchDog"=F:\Program Files\TrustPort Disk Protection\bin\TDWatch.exe [2009-06-12 155480]
"TrustPortTray"=F:\Program Files\Common Files\TrustPort\Bin\tptray.exe [2009-06-12 835416]
"Windows Mobile Device Center"=F:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"Adobe Reader Speed Launcher"=F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
"Adobe ARM"=F:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"HP Software Update"=F:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=F:\Program Files\Windows Sidebar\sidebar.exe [2008-01-18 1233920]
"ehTray.exe"=F:\Windows\ehome\ehTray.exe [2008-01-18 125952]
"Skype"=F:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]
"swg"=F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-06-30 39408]
"WMPNSCFG"=F:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-18 202240]
F:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - F:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
F:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - F:\Windows\System32\DreamScene.dll [2008-12-13 233888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"F:\Users\Moje cesky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7NU22VQU\IMAGE464-facebook.com.JPG.jpg[2].exe"="F:\Windows\infocard.exe:*:Enabled:Firewall Admin"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=F:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2023-06-27 02:16:04 ----D---- F:\ProgramData\WindowsSearch
======List of files/folders modified in the last 1 month======
2011-12-18 15:51:03 ----D---- F:\Windows\Prefetch
2011-12-18 15:50:53 ----D---- F:\Program Files\trend micro
2011-12-18 15:50:40 ----D---- F:\Windows\temp
2011-12-18 15:49:10 ----D---- F:\Users\Moje cesky\AppData\Roaming\Skype
2011-12-18 15:10:31 ----D---- F:\Users\Moje cesky\AppData\Roaming\skypePM
2011-12-08 12:23:50 ----SHD---- F:\Windows\Installer
2011-12-08 12:11:42 ----D---- F:\Program Files\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 fvevol;BitLocker Drive Encryption Filter Driver; F:\Windows\System32\DRIVERS\fvevol.sys [2008-01-18 145464]
R0 MEMLOCK;Secured Memory Driver; F:\Windows\system32\drivers\memlock.sys [2009-06-12 14136]
R1 ehdrv;ehdrv; F:\Windows\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R2 eamon;eamon; F:\Windows\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R2 EncDisk;EncDisk; \??\F:\Program Files\TrustPort Disk Protection\bin\EncDsk.sys [2009-06-12 55128]
R2 epfw;epfw; F:\Windows\system32\DRIVERS\epfw.sys [2009-05-14 133000]
R2 epfwwfp;epfwwfp; F:\Windows\system32\DRIVERS\epfwwfp.sys [2009-05-14 38240]
R2 rismxdp;Ricoh xD-Picture Card Driver; F:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-14 37376]
R3 BthEnum;Služba Bluetooth Enumerator; F:\Windows\system32\DRIVERS\BthEnum.sys [2008-12-13 19456]
R3 BthPan;Zařízení Bluetooth (síť PAN); F:\Windows\system32\DRIVERS\bthpan.sys [2008-01-18 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; F:\Windows\System32\Drivers\BTHUSB.sys [2008-12-13 29184]
R3 E100B;Intel(R) PRO Adapter Driver; F:\Windows\system32\DRIVERS\e100b325.sys [2008-01-18 159744]
R3 Epfwndis;Eset Personal Firewall; F:\Windows\system32\DRIVERS\Epfwndis.sys [2009-05-14 33096]
R3 HBtnKey;HBtnKey; F:\Windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; F:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 HSF_DPV;HSF_DPV; F:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 HSFHWAZL;HSFHWAZL; F:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
R3 igfx;igfx; F:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; F:\Windows\system32\DRIVERS\NETw4v32.sys [2007-10-31 2252800]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); F:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-18 49664]
R3 rimmptsk;rimmptsk; F:\Windows\system32\DRIVERS\rimmptsk.sys [2005-11-16 28928]
R3 rimsptsk;rimsptsk; F:\Windows\system32\DRIVERS\rimsptsk.sys [2005-12-22 51840]
R3 sdbus;sdbus; F:\Windows\system32\DRIVERS\sdbus.sys [2008-01-18 88576]
R3 usbvideo;Zobrazovací zařízení USB (WDM); F:\Windows\System32\Drivers\usbvideo.sys [2008-01-18 134016]
R3 winachsf;winachsf; F:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2006-11-02 654336]
S3 BTHPORT;Ovladač portu Bluetooth; F:\Windows\System32\Drivers\BTHport.sys [2008-12-13 220160]
S3 Dot4;Ovladač MS IEEE-1284.4; F:\Windows\system32\DRIVERS\Dot4.sys [2008-01-18 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; F:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-18 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; F:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-18 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; F:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 ialm;ialm; F:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; F:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; F:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; F:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; F:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; F:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 usb_rndisx;Adaptér USB RNDIS; F:\Windows\system32\DRIVERS\usb8023x.sys [2008-01-18 15872]
S3 usbscan;Ovladač skeneru USB; F:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328]
S3 WpdUsb;WpdUsb; F:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-18 39936]
S3 WUDFRd;WUDFRd; F:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; F:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 ekrn;ESET Service; F:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; F:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; F:\Windows\system32\svchost.exe [2008-01-18 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; F:\Windows\system32\svchost.exe [2008-01-18 21504]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; F:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
S2 gupdate;Služba Google Update (gupdate); F:\Program Files\Google\Update\GoogleUpdate.exe [2010-06-30 135664]
S2 Net Driver HPZ12;Net Driver HPZ12; F:\Windows\System32\svchost.exe [2008-01-18 21504]
S2 Pml Driver HPZ12;Pml Driver HPZ12; F:\Windows\System32\svchost.exe [2008-01-18 21504]
S3 EhttpSrv;ESET HTTP Server; F:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-05-14 20680]
S3 gupdatem;Služba Google Update (gupdatem); F:\Program Files\Google\Update\GoogleUpdate.exe [2010-06-30 135664]
S3 gusvc;Google Software Updater; F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-01 182768]
S3 hpqcxs08;hpqcxs08; F:\Windows\system32\svchost.exe [2008-01-18 21504]
S3 McComponentHostService;McAfee Security Scan Component Host Service; F:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; F:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; F:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------