Stránka 1 z 1

Přesměrování odkazů výsledků vyhledávání google ve FF a GC

Napsal: 05 čer 2012 17:34
od micola
Dobrý den,

v poslední době mám problémy s vyhledáváním na google. Odkazy výsledků vyhledávání jsou přesměrovány na různé reklamní nebo pochybné stránky. Při opakovaném použití odkazu se někdy správná stránka zobrazí někdy ne. Problém se projevuje ve Firefoxu a Chrome, v IE v současné době ne.

Děkuji za pomoc, přikládám log:


Logfile of random's system information tool 1.09 (written by random/random)
Run by Martin at 2012-06-05 18:29:44
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 2 GB (4%) free of 40 GB
Total RAM: 2047 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:29:54, on 5.6.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\xampp\apache\bin\httpd.exe
C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe
C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceUI.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\xampp\apache\bin\httpd.exe
C:\Program Files\Activ Software\Inspire\Inspire.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Martin\Dokumenty\Stažené soubory\RSIT(1).exe
C:\Program Files\trend micro\Martin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 8298996296
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\httpd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: eBeam Device Service - Luidia, Inc. - C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 6879 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\PMSWIDXJ.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Martin\Data aplikací\Mozilla\Firefox\Profiles\cwpfkcyo.default

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.3.1]
"Description"=
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll
npwachk.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll [2012-01-10 59272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2011-12-05 20065384]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2012-05-10 348624]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-11 61440]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"Ad-Aware Browsing Protection"=C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection\adawarebp.exe [2011-10-21 198032]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2012-01-31 17147528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2011-12-09 74752]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\xampp\apache\bin\httpd.exe"="C:\xampp\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.tscc"=tsccvid.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 1 month======

2012-06-05 17:39:48 ----D---- C:\Documents and Settings\Martin\Data aplikací\Mozilla
2012-06-05 17:39:41 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-06-04 17:50:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2718704$
2012-06-01 19:54:40 ----D---- C:\Documents and Settings\Martin\Data aplikací\inkscape
2012-05-22 20:54:33 ----D---- C:\1475a444a559642180d3148c80
2012-05-22 17:31:24 ----D---- C:\Program Files\MSXML 4.0
2012-05-21 21:21:32 ----D---- C:\Program Files\trend micro
2012-05-21 21:21:31 ----D---- C:\rsit
2012-05-21 21:01:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ad-Aware Browsing Protection
2012-05-21 21:01:01 ----A---- C:\WINDOWS\system32\drivers\sbhips.sys
2012-05-21 21:01:00 ----A---- C:\WINDOWS\system32\drivers\sbtis.sys
2012-05-21 21:00:28 ----A---- C:\WINDOWS\system32\drivers\SbFwIm.sys
2012-05-21 21:00:28 ----A---- C:\WINDOWS\system32\drivers\SbFw.sys
2012-05-10 17:45:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-05-10 17:37:17 ----D---- C:\Program Files\Spybot - Search & Destroy
2012-05-10 17:37:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-05-10 17:28:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-05-10 17:28:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2695962$
2012-05-10 17:17:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$

======List of files/folders modified in the last 1 month======

2012-06-05 18:29:54 ----D---- C:\WINDOWS\Prefetch
2012-06-05 18:29:51 ----D---- C:\WINDOWS\Temp
2012-06-05 17:39:41 ----RD---- C:\Program Files
2012-06-05 17:39:36 ----D---- C:\Program Files\Mozilla Firefox
2012-06-04 21:55:14 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-06-04 21:41:38 ----SHD---- C:\WINDOWS\Installer
2012-06-04 21:41:37 ----RD---- C:\Program Files\Skype
2012-06-04 21:03:05 ----D---- C:\WINDOWS
2012-06-04 18:15:01 ----D---- C:\Documents and Settings\Martin\Data aplikací\Media Player Classic
2012-06-04 18:01:07 ----D---- C:\WINDOWS\system32
2012-06-04 18:00:06 ----D---- C:\WINDOWS\system32\CatRoot2
2012-06-04 17:50:11 ----HD---- C:\WINDOWS\inf
2012-06-04 17:50:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-06-04 17:32:53 ----HD---- C:\WINDOWS\$hf_mig$
2012-06-02 09:00:02 ----D---- C:\WINDOWS\system32\drivers
2012-06-01 20:19:51 ----RSD---- C:\WINDOWS\Fonts
2012-05-31 15:22:06 ----A---- C:\WINDOWS\system32\crypt32.dll
2012-05-27 20:52:25 ----SD---- C:\WINDOWS\Tasks
2012-05-22 21:03:04 ----D---- C:\WINDOWS\Microsoft.NET
2012-05-22 17:31:33 ----D---- C:\WINDOWS\WinSxS
2012-05-21 21:00:24 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-05-19 16:04:28 ----D---- C:\Documents and Settings\Martin\Data aplikací\Winamp
2012-05-12 10:59:22 ----D---- C:\Documents and Settings\Martin\Data aplikací\Skype
2012-05-10 19:14:39 ----RSD---- C:\WINDOWS\assembly
2012-05-10 18:49:38 ----D---- C:\WINDOWS\Ticket
2012-05-10 18:21:04 ----D---- C:\Program Files\Microsoft Silverlight
2012-05-10 17:44:53 ----D---- C:\WINDOWS\system32\XPSViewer
2012-05-10 17:44:02 ----A---- C:\WINDOWS\system32\MRT.exe
2012-05-10 17:43:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-05-06 20:58:11 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2012-05-10 137928]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2011-09-16 36000]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SbFw;SbFw; C:\WINDOWS\system32\drivers\SbFw.sys [2011-04-05 332248]
R1 SbTis;SbTis; C:\WINDOWS\system32\drivers\sbtis.sys [2011-04-05 212568]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2012-05-10 83392]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-12-06 7067752]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2003-04-16 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2011-08-24 323816]
R3 SBFWIMCLMP;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\WINDOWS\system32\DRIVERS\SBFWIM.sys [2011-02-08 69208]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Service; C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2011-02-08 69208]
S3 sbhips;sbhips; C:\WINDOWS\system32\drivers\sbhips.sys [2011-04-05 94040]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira Realtime Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2012-05-10 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2012-05-10 86224]
R2 Apache2.2;Apache2.2; C:\xampp\apache\bin\httpd.exe [2011-09-10 18432]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 eBeam Device Service;eBeam Device Service; C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe [2010-01-27 180224]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-03-25 161664]
R2 mysql;mysql; C:\xampp\mysql\bin\mysqld.exe [2011-09-09 8158720]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-02-03 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-01-31 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-06 257696]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-02-03 136176]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-01 113120]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Přesměrování odkazů výsledků vyhledávání google ve FF a

Napsal: 05 čer 2012 19:26
od micola
Výpis programu AVZ4
virusinfo_syscheck.zip
(37.74 KiB) Staženo 32 x

Re: Přesměrování odkazů výsledků vyhledávání google ve FF a

Napsal: 05 čer 2012 19:30
od micola
Exporty z programu PowerTool
- u některých záložek nebyla možnost Export
- u některých záložek je Export prázdný
exporty_PT.zip
(23.85 KiB) Staženo 42 x

Re: Přesměrování odkazů výsledků vyhledávání google ve FF a

Napsal: 05 čer 2012 19:32
od micola
Screenshoty požadovaných záložek.
screenshots.zip
(266.67 KiB) Staženo 29 x
P.S. posílám po jednom souboru, nešly vložit všechny najednou.

Re: Přesměrování odkazů výsledků vyhledávání google ve FF a

Napsal: 07 čer 2012 17:57
od micola
Combofix neproveden, po začátku skenování (zpráva o době trvání) vždy po několika minutách počítač zatuhne (nutný tvrdý reset) - disk přestane přestavovat hlavy; ponecháno v klidu přes 1 hodinu, combofix aktualizován, antivir odstraněn.

Výpis z RK:
RogueKiller V7.5.4 [06/07/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Martin [Práva správce]
Mód: Kontrola -- Datum: 06/07/2012 18:51:45

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 4 ¤¤¤
[] HKLM\[...]\Windows : () -> ACCESS DENIED
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[] HKLM\[...]\Windows : () -> ACCESS DENIED

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD800BB-00CAA1 +++++
--- User ---
[MBR] eb9770f9acf9e81a53328658155d6e54
[BSP] cdcc2b749e8c7abb07712853e5c0dde8 : Linux MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 39997 Mo
1 - [XXXXXX] EXTEN (0x05) [VISIBLE] Offset (sectors): 81915902 | Size: 36321 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt


Výpis z Kaspersky:
18:48:13.0126 3028 TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
18:48:13.0220 3028 ============================================================
18:48:13.0220 3028 Current date / time: 2012/06/07 18:48:13.0220
18:48:13.0220 3028 SystemInfo:
18:48:13.0220 3028
18:48:13.0220 3028 OS Version: 5.1.2600 ServicePack: 3.0
18:48:13.0220 3028 Product type: Workstation
18:48:13.0220 3028 ComputerName: DOMA1
18:48:13.0220 3028 UserName: Martin
18:48:13.0220 3028 Windows directory: C:\WINDOWS
18:48:13.0220 3028 System windows directory: C:\WINDOWS
18:48:13.0220 3028 Processor architecture: Intel x86
18:48:13.0220 3028 Number of processors: 1
18:48:13.0220 3028 Page size: 0x1000
18:48:13.0220 3028 Boot type: Normal boot
18:48:13.0220 3028 ============================================================
18:48:15.0376 3028 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
18:48:15.0376 3028 ============================================================
18:48:15.0376 3028 \Device\Harddisk0\DR0:
18:48:15.0376 3028 MBR partitions:
18:48:15.0376 3028 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4E1EDEC
18:48:15.0423 3028 ============================================================
18:48:15.0454 3028 C: <-> \Device\Harddisk0\DR0\Partition0
18:48:15.0454 3028 ============================================================
18:48:15.0454 3028 Initialize success
18:48:15.0454 3028 ============================================================
18:48:50.0580 2976 ============================================================
18:48:50.0580 2976 Scan started
18:48:50.0580 2976 Mode: Manual; SigCheck; TDLFS;
18:48:50.0580 2976 ============================================================
18:48:51.0080 2976 Abiosdsk - ok
18:48:51.0095 2976 abp480n5 - ok
18:48:51.0158 2976 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:48:53.0580 2976 ACPI - ok
18:48:53.0642 2976 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\drivers\ACPIEC.sys
18:48:53.0876 2976 ACPIEC - ok
18:48:54.0017 2976 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:48:54.0064 2976 AdobeFlashPlayerUpdateSvc - ok
18:48:54.0064 2976 adpu160m - ok
18:48:54.0111 2976 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
18:48:54.0298 2976 aec - ok
18:48:54.0345 2976 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
18:48:54.0423 2976 AFD - ok
18:48:54.0439 2976 Aha154x - ok
18:48:54.0455 2976 aic78u2 - ok
18:48:54.0455 2976 aic78xx - ok
18:48:54.0501 2976 Alerter (e0a6fa244b8624d78fe5ff6f56a33bae) C:\WINDOWS\system32\alrsvc.dll
18:48:54.0658 2976 Alerter - ok
18:48:54.0689 2976 ALG (88842de939a827577bf24243699ac80a) C:\WINDOWS\System32\alg.exe
18:48:54.0861 2976 ALG - ok
18:48:54.0861 2976 AliIde - ok
18:48:55.0080 2976 Ambfilt (267fc636801edc5ab28e14036349e3be) C:\WINDOWS\system32\drivers\Ambfilt.sys
18:48:55.0267 2976 Ambfilt - ok
18:48:55.0361 2976 amsint - ok
18:48:55.0470 2976 Apache2.2 (f41e453a90ef19217cee1675f5256ee7) C:\xampp\apache\bin\httpd.exe
18:48:55.0486 2976 Apache2.2 ( UnsignedFile.Multi.Generic ) - warning
18:48:55.0486 2976 Apache2.2 - detected UnsignedFile.Multi.Generic (1)
18:48:55.0501 2976 AppMgmt - ok
18:48:55.0517 2976 asc - ok
18:48:55.0517 2976 asc3350p - ok
18:48:55.0533 2976 asc3550 - ok
18:48:55.0642 2976 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
18:48:55.0673 2976 aspnet_state - ok
18:48:55.0705 2976 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:48:55.0876 2976 AsyncMac - ok
18:48:55.0923 2976 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
18:48:56.0111 2976 atapi - ok
18:48:56.0126 2976 Atdisk - ok
18:48:56.0345 2976 Ati HotKey Poller (471087b5e1e01cc82604e81ea14781d8) C:\WINDOWS\system32\Ati2evxx.exe
18:48:56.0392 2976 Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - warning
18:48:56.0392 2976 Ati HotKey Poller - detected UnsignedFile.Multi.Generic (1)
18:48:56.0470 2976 ATI Smart (b979ba0120b6db757196a8e2e873fe3c) C:\WINDOWS\system32\ati2sgag.exe
18:48:56.0517 2976 ATI Smart ( UnsignedFile.Multi.Generic ) - warning
18:48:56.0517 2976 ATI Smart - detected UnsignedFile.Multi.Generic (1)
18:48:56.0798 2976 ati2mtag (c0b86ecb324e50f6bbd529f9d5c6b24b) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
18:48:56.0939 2976 ati2mtag ( UnsignedFile.Multi.Generic ) - warning
18:48:56.0939 2976 ati2mtag - detected UnsignedFile.Multi.Generic (1)
18:48:57.0080 2976 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:48:57.0251 2976 Atmarpc - ok
18:48:57.0283 2976 AudioSrv (de31b88962a8645dba5a37b993e7b0f1) C:\WINDOWS\System32\audiosrv.dll
18:48:57.0486 2976 AudioSrv - ok
18:48:57.0517 2976 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
18:48:57.0673 2976 audstub - ok
18:48:57.0720 2976 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
18:48:57.0876 2976 Beep - ok
18:48:57.0939 2976 BITS (19395d092fd85ddc2d9c7729cf5a2ac8) C:\WINDOWS\System32\qmgr.dll
18:48:58.0142 2976 BITS - ok
18:48:58.0189 2976 Browser (249276d3ef1e74b992299cb96099e4d7) C:\WINDOWS\System32\browser.dll
18:48:58.0377 2976 Browser - ok
18:48:58.0439 2976 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
18:48:58.0611 2976 cbidf2k - ok
18:48:58.0627 2976 cd20xrnt - ok
18:48:58.0689 2976 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
18:48:58.0877 2976 Cdaudio - ok
18:48:58.0939 2976 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
18:48:59.0127 2976 Cdfs - ok
18:48:59.0158 2976 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:48:59.0345 2976 Cdrom - ok
18:48:59.0361 2976 Changer - ok
18:49:00.0392 2976 CiSvc (e390dc1d7c461d7d56ec53402f329928) C:\WINDOWS\system32\cisvc.exe
18:49:00.0595 2976 CiSvc - ok
18:49:00.0658 2976 ClipSrv (064507a8dfa8c5c7e2ffddd3e6f424fa) C:\WINDOWS\system32\clipsrv.exe
18:49:00.0877 2976 ClipSrv - ok
18:49:00.0986 2976 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:49:01.0002 2976 clr_optimization_v2.0.50727_32 - ok
18:49:01.0048 2976 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:49:01.0064 2976 clr_optimization_v4.0.30319_32 - ok
18:49:01.0080 2976 CmdIde - ok
18:49:01.0095 2976 COMSysApp - ok
18:49:01.0111 2976 Cpqarray - ok
18:49:01.0158 2976 CryptSvc (f3ab0933cbd166d271992f411c27ccaf) C:\WINDOWS\System32\cryptsvc.dll
18:49:01.0330 2976 CryptSvc - ok
18:49:01.0330 2976 dac2w2k - ok
18:49:01.0345 2976 dac960nt - ok
18:49:01.0408 2976 DcomLaunch (be27674d1cbc3214aec84b4336a38bbf) C:\WINDOWS\system32\rpcss.dll
18:49:01.0486 2976 DcomLaunch - ok
18:49:01.0533 2976 Dhcp (8c9a53e285ac5e6704844d0459ec85be) C:\WINDOWS\System32\dhcpcsvc.dll
18:49:01.0720 2976 Dhcp - ok
18:49:01.0752 2976 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
18:49:01.0939 2976 Disk - ok
18:49:01.0939 2976 dmadmin - ok
18:49:02.0017 2976 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
18:49:02.0252 2976 dmboot - ok
18:49:02.0314 2976 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
18:49:02.0502 2976 dmio - ok
18:49:02.0548 2976 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
18:49:02.0720 2976 dmload - ok
18:49:02.0783 2976 dmserver (2bfefe9e865655a76982f050450b9591) C:\WINDOWS\System32\dmserver.dll
18:49:02.0970 2976 dmserver - ok
18:49:03.0033 2976 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
18:49:03.0220 2976 DMusic - ok
18:49:03.0267 2976 Dnscache (dfaa406bf19f4ee806a6f8d4342137f7) C:\WINDOWS\System32\dnsrslvr.dll
18:49:03.0377 2976 Dnscache - ok
18:49:03.0455 2976 Dot3svc (4a3e2bd20157a0946751229e92eb8621) C:\WINDOWS\System32\dot3svc.dll
18:49:03.0658 2976 Dot3svc - ok
18:49:03.0658 2976 dpti2o - ok
18:49:03.0705 2976 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
18:49:03.0877 2976 drmkaud - ok
18:49:03.0908 2976 EapHost (0887d9c2be8d940778cad1e3b85f2a41) C:\WINDOWS\System32\eapsvc.dll
18:49:04.0095 2976 EapHost - ok
18:49:04.0173 2976 eBeam Device Service (4e791c305abbdc61282d24da3fb46a55) C:\Program Files\Luidia\eBeam Device Service\eBeamDeviceServiceMain.exe
18:49:04.0189 2976 eBeam Device Service ( UnsignedFile.Multi.Generic ) - warning
18:49:04.0189 2976 eBeam Device Service - detected UnsignedFile.Multi.Generic (1)
18:49:04.0220 2976 ERSvc (a2a4912798f2be706abadd3d30800d16) C:\WINDOWS\System32\ersvc.dll
18:49:04.0392 2976 ERSvc - ok
18:49:04.0439 2976 Eventlog (9ef697af07bb8dd82c3b02ca953a95b7) C:\WINDOWS\system32\services.exe
18:49:04.0470 2976 Eventlog - ok
18:49:04.0533 2976 EventSystem (a371f11ef07653591c8de26afb13ce7f) C:\WINDOWS\System32\es.dll
18:49:04.0580 2976 EventSystem - ok
18:49:04.0627 2976 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
18:49:04.0814 2976 Fastfat - ok
18:49:04.0861 2976 FastUserSwitchingCompatibility (ee9a2b9ea968a792a053c9d1a86bf870) C:\WINDOWS\System32\shsvcs.dll
18:49:04.0908 2976 FastUserSwitchingCompatibility - ok
18:49:04.0923 2976 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
18:49:05.0111 2976 Fdc - ok
18:49:05.0142 2976 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
18:49:05.0314 2976 Fips - ok
18:49:05.0330 2976 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
18:49:05.0502 2976 Flpydisk - ok
18:49:05.0548 2976 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
18:49:05.0720 2976 FltMgr - ok
18:49:05.0830 2976 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
18:49:05.0845 2976 FontCache3.0.0.0 - ok
18:49:05.0892 2976 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:49:06.0080 2976 Fs_Rec - ok
18:49:06.0111 2976 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:49:06.0283 2976 Ftdisk - ok
18:49:06.0314 2976 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:49:06.0502 2976 Gpc - ok
18:49:06.0580 2976 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
18:49:06.0595 2976 gupdate - ok
18:49:06.0595 2976 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
18:49:06.0627 2976 gupdatem - ok
18:49:06.0658 2976 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
18:49:06.0673 2976 gusvc - ok
18:49:06.0705 2976 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:49:06.0877 2976 HDAudBus - ok
18:49:06.0939 2976 helpsvc (fcfe31fb75f8a6295b6b0af87a626282) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
18:49:07.0111 2976 helpsvc - ok
18:49:07.0111 2976 HidServ - ok
18:49:07.0127 2976 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:49:07.0298 2976 hidusb - ok
18:49:07.0330 2976 hkmsvc (7a6b320928f86bc851530d63c82965d9) C:\WINDOWS\System32\kmsvc.dll
18:49:07.0502 2976 hkmsvc - ok
18:49:07.0502 2976 hpn - ok
18:49:07.0564 2976 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
18:49:07.0627 2976 HTTP - ok
18:49:07.0673 2976 HTTPFilter (58fe2f2da3bc5573f4a35b3760d3125f) C:\WINDOWS\System32\w3ssl.dll
18:49:07.0861 2976 HTTPFilter - ok
18:49:07.0861 2976 i2omgmt - ok
18:49:07.0877 2976 i2omp - ok
18:49:07.0924 2976 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:49:08.0080 2976 i8042prt - ok
18:49:08.0580 2976 ialm (0f68e2ec713f132ffb19e45415b09679) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
18:49:09.0236 2976 ialm - ok
18:49:09.0470 2976 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:49:09.0533 2976 idsvc - ok
18:49:09.0642 2976 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
18:49:09.0814 2976 Imapi - ok
18:49:09.0861 2976 ImapiService (f7b93aafad33b2320954c17e26c8d361) C:\WINDOWS\system32\imapi.exe
18:49:10.0049 2976 ImapiService - ok
18:49:10.0064 2976 ini910u - ok
18:49:10.0720 2976 IntcAzAudAddService (bbe8a7474a7f09821594f3e5c2c638fb) C:\WINDOWS\system32\drivers\RtkHDAud.sys
18:49:11.0002 2976 IntcAzAudAddService - ok
18:49:11.0111 2976 IntelIde - ok
18:49:11.0142 2976 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:49:11.0314 2976 intelppm - ok
18:49:11.0330 2976 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
18:49:11.0502 2976 ip6fw - ok
18:49:11.0549 2976 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:49:11.0720 2976 IpFilterDriver - ok
18:49:11.0783 2976 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:49:11.0939 2976 IpInIp - ok
18:49:11.0970 2976 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:49:12.0158 2976 IpNat - ok
18:49:12.0174 2976 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:49:12.0330 2976 IPSec - ok
18:49:12.0361 2976 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
18:49:12.0533 2976 IRENUM - ok
18:49:12.0564 2976 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:49:12.0720 2976 isapnp - ok
18:49:12.0830 2976 JavaQuickStarterService (d9b1e929f2464d4c23fa9cb47df4a1d4) C:\Program Files\Java\jre7\bin\jqs.exe
18:49:12.0845 2976 JavaQuickStarterService - ok
18:49:12.0861 2976 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:49:13.0017 2976 Kbdclass - ok
18:49:13.0080 2976 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
18:49:13.0236 2976 kmixer - ok
18:49:13.0267 2976 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
18:49:13.0314 2976 KSecDD - ok
18:49:13.0345 2976 lanmanserver (3428e8f86f8add36b42fb23542c7b3e4) C:\WINDOWS\System32\srvsvc.dll
18:49:13.0408 2976 lanmanserver - ok
18:49:13.0455 2976 lanmanworkstation (936c1d110232d23b621cb0196e4f80f0) C:\WINDOWS\System32\wkssvc.dll
18:49:13.0486 2976 lanmanworkstation - ok
18:49:13.0502 2976 lbrtfdc - ok
18:49:13.0533 2976 LmHosts (0ab159f536e3e8f7f07113702a07cca5) C:\WINDOWS\System32\lmhsvc.dll
18:49:13.0705 2976 LmHosts - ok
18:49:13.0720 2976 Messenger (221cd1c815b8a6b79389c3f5d1018de8) C:\WINDOWS\System32\msgsvc.dll
18:49:13.0892 2976 Messenger - ok
18:49:13.0939 2976 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
18:49:14.0095 2976 mnmdd - ok
18:49:14.0142 2976 mnmsrvc (9a57d046f88f4b69751b11fd40088a61) C:\WINDOWS\System32\mnmsrvc.exe
18:49:14.0314 2976 mnmsrvc - ok
18:49:14.0330 2976 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
18:49:14.0517 2976 Modem - ok
18:49:14.0674 2976 Monfilt (c7d9f9717916b34c1b00dd4834af485c) C:\WINDOWS\system32\drivers\Monfilt.sys
18:49:14.0767 2976 Monfilt - ok
18:49:14.0799 2976 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:49:14.0970 2976 Mouclass - ok
18:49:15.0017 2976 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:49:15.0189 2976 mouhid - ok
18:49:15.0205 2976 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
18:49:15.0377 2976 MountMgr - ok
18:49:15.0439 2976 MozillaMaintenance (6380ff81dd4d78b23398752d2f46ea43) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:49:15.0455 2976 MozillaMaintenance - ok
18:49:15.0470 2976 mraid35x - ok
18:49:15.0486 2976 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:49:15.0674 2976 MRxDAV - ok
18:49:15.0736 2976 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:49:15.0845 2976 MRxSmb - ok
18:49:15.0877 2976 MSDTC (6db4d1521caba9a5ffab54ade0ae867d) C:\WINDOWS\System32\msdtc.exe
18:49:16.0049 2976 MSDTC - ok
18:49:16.0095 2976 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
18:49:16.0252 2976 Msfs - ok
18:49:16.0267 2976 MSIServer - ok
18:49:16.0314 2976 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:49:16.0486 2976 MSKSSRV - ok
18:49:16.0502 2976 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:49:16.0658 2976 MSPCLOCK - ok
18:49:16.0689 2976 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
18:49:16.0861 2976 MSPQM - ok
18:49:16.0908 2976 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:49:17.0064 2976 mssmbios - ok
18:49:17.0095 2976 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
18:49:17.0142 2976 Mup - ok
18:49:17.0220 2976 mysql - ok
18:49:17.0283 2976 napagent (6ea362e9db03d44f6b996f4d8be237e9) C:\WINDOWS\System32\qagentrt.dll
18:49:17.0455 2976 napagent - ok
18:49:17.0486 2976 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
18:49:17.0658 2976 NDIS - ok
18:49:17.0689 2976 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:49:17.0721 2976 NdisTapi - ok
18:49:17.0767 2976 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:49:17.0924 2976 Ndisuio - ok
18:49:17.0955 2976 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:49:18.0111 2976 NdisWan - ok
18:49:18.0142 2976 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
18:49:18.0189 2976 NDProxy - ok
18:49:18.0221 2976 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
18:49:18.0392 2976 NetBIOS - ok
18:49:18.0424 2976 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
18:49:18.0596 2976 NetBT - ok
18:49:18.0642 2976 NetDDE (933de774986ec85e48210c44ab431de6) C:\WINDOWS\system32\netdde.exe
18:49:18.0814 2976 NetDDE - ok
18:49:18.0814 2976 NetDDEdsdm (933de774986ec85e48210c44ab431de6) C:\WINDOWS\system32\netdde.exe
18:49:18.0971 2976 NetDDEdsdm - ok
18:49:18.0986 2976 Netlogon (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\System32\lsass.exe
18:49:19.0158 2976 Netlogon - ok
18:49:19.0189 2976 Netman (72e1e9e2977be08bdeedb6d8fd9d4d40) C:\WINDOWS\System32\netman.dll
18:49:19.0377 2976 Netman - ok
18:49:19.0486 2976 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:49:19.0502 2976 NetTcpPortSharing - ok
18:49:19.0549 2976 Nla (39ee7c3bfbc64ba87cc8cf67386e814c) C:\WINDOWS\System32\mswsock.dll
18:49:19.0596 2976 Nla - ok
18:49:19.0642 2976 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
18:49:19.0814 2976 Npfs - ok
18:49:19.0861 2976 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
18:49:20.0080 2976 Ntfs - ok
18:49:20.0080 2976 NtLmSsp (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\System32\lsass.exe
18:49:20.0252 2976 NtLmSsp - ok
18:49:20.0330 2976 NtmsSvc (023dd70573d644f3d9c8b1258a7bfd08) C:\WINDOWS\system32\ntmssvc.dll
18:49:20.0533 2976 NtmsSvc - ok
18:49:20.0564 2976 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
18:49:20.0736 2976 Null - ok
18:49:20.0783 2976 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:49:20.0971 2976 NwlnkFlt - ok
18:49:20.0986 2976 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:49:21.0174 2976 NwlnkFwd - ok
18:49:21.0221 2976 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\drivers\Parport.sys
18:49:21.0392 2976 Parport - ok
18:49:21.0424 2976 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
18:49:21.0580 2976 PartMgr - ok
18:49:21.0627 2976 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
18:49:21.0799 2976 ParVdm - ok
18:49:21.0814 2976 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
18:49:21.0986 2976 PCI - ok
18:49:21.0986 2976 PCIDump - ok
18:49:22.0017 2976 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
18:49:22.0205 2976 PCIIde - ok
18:49:22.0236 2976 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\drivers\Pcmcia.sys
18:49:22.0424 2976 Pcmcia - ok
18:49:22.0424 2976 PDCOMP - ok
18:49:22.0439 2976 PDFRAME - ok
18:49:22.0455 2976 PDRELI - ok
18:49:22.0455 2976 PDRFRAME - ok
18:49:22.0471 2976 perc2 - ok
18:49:22.0486 2976 perc2hib - ok
18:49:22.0721 2976 PEVSystemStart (f042ee4c8d66248d9b86dcf52abae416) C:\ComboFix\pev.3XE
18:49:22.0799 2976 PEVSystemStart ( UnsignedFile.Multi.Generic ) - warning
18:49:22.0799 2976 PEVSystemStart - detected UnsignedFile.Multi.Generic (1)
18:49:22.0846 2976 PlugPlay (9ef697af07bb8dd82c3b02ca953a95b7) C:\WINDOWS\system32\services.exe
18:49:22.0877 2976 PlugPlay - ok
18:49:22.0892 2976 PolicyAgent (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
18:49:23.0049 2976 PolicyAgent - ok
18:49:23.0096 2976 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:49:23.0252 2976 PptpMiniport - ok
18:49:23.0283 2976 Processor (7eb15dce4ec3a0220bd796a15c18186e) C:\WINDOWS\system32\DRIVERS\processr.sys
18:49:23.0455 2976 Processor - ok
18:49:23.0455 2976 ProtectedStorage (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
18:49:23.0611 2976 ProtectedStorage - ok
18:49:23.0642 2976 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
18:49:23.0814 2976 PSched - ok
18:49:23.0846 2976 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:49:24.0017 2976 Ptilink - ok
18:49:24.0064 2976 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:49:24.0080 2976 PxHelp20 - ok
18:49:24.0080 2976 ql1080 - ok
18:49:24.0096 2976 Ql10wnt - ok
18:49:24.0111 2976 ql12160 - ok
18:49:24.0111 2976 ql1240 - ok
18:49:24.0127 2976 ql1280 - ok
18:49:24.0142 2976 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:49:24.0314 2976 RasAcd - ok
18:49:24.0361 2976 RasAuto (2b5e44ea009f2f374b980e1e9a70635d) C:\WINDOWS\System32\rasauto.dll
18:49:24.0533 2976 RasAuto - ok
18:49:24.0564 2976 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:49:24.0736 2976 Rasl2tp - ok
18:49:24.0783 2976 RasMan (d57554c664b64604bd1ee13ea2c07e77) C:\WINDOWS\System32\rasmans.dll
18:49:24.0986 2976 RasMan - ok
18:49:25.0002 2976 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:49:25.0158 2976 RasPppoe - ok
18:49:25.0189 2976 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
18:49:25.0361 2976 Raspti - ok
18:49:25.0377 2976 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:49:25.0549 2976 Rdbss - ok
18:49:25.0564 2976 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:49:25.0736 2976 RDPCDD - ok
18:49:25.0799 2976 RDPWD (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
18:49:25.0861 2976 RDPWD - ok
18:49:25.0908 2976 RDSessMgr (c0d9d9711cb74ee9bc66353d8cbdab0e) C:\WINDOWS\system32\sessmgr.exe
18:49:26.0080 2976 RDSessMgr - ok
18:49:26.0111 2976 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
18:49:26.0283 2976 redbook - ok
18:49:26.0314 2976 RemoteAccess (127c26b5371651043450e52542099aba) C:\WINDOWS\System32\mprdim.dll
18:49:26.0486 2976 RemoteAccess - ok
18:49:26.0533 2976 RpcLocator (718b3bdc0bc3c2f7d065a53d26202af9) C:\WINDOWS\System32\locator.exe
18:49:26.0705 2976 RpcLocator - ok
18:49:26.0752 2976 RpcSs (be27674d1cbc3214aec84b4336a38bbf) C:\WINDOWS\system32\rpcss.dll
18:49:26.0783 2976 RpcSs - ok
18:49:26.0814 2976 RSVP (09ab2e71e58b078038e3bfdba7ffc984) C:\WINDOWS\System32\rsvp.exe
18:49:27.0002 2976 RSVP - ok
18:49:27.0049 2976 RTLE8023xp (d3578c3806ed545e5c36b2a20f5c0b5a) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
18:49:27.0080 2976 RTLE8023xp - ok
18:49:27.0111 2976 SamSs (ed0a176354487ceed65b80a7148ab739) C:\WINDOWS\system32\lsass.exe
18:49:27.0252 2976 SamSs - ok
18:49:27.0299 2976 SbFw (eb4a2b5faa3decd33ed682a5569e287f) C:\WINDOWS\system32\drivers\SbFw.sys
18:49:27.0330 2976 SbFw - ok
18:49:27.0377 2976 SBFWIMCL (f27b38d70b7621378161d6f48be04d2c) C:\WINDOWS\system32\DRIVERS\sbfwim.sys
18:49:27.0377 2976 SBFWIMCL - ok
18:49:27.0393 2976 SBFWIMCLMP (f27b38d70b7621378161d6f48be04d2c) C:\WINDOWS\system32\DRIVERS\SBFWIM.sys
18:49:27.0408 2976 SBFWIMCLMP - ok
18:49:27.0439 2976 sbhips (53e5e7dc26bb920b97f258bbd52abfdc) C:\WINDOWS\system32\drivers\sbhips.sys
18:49:27.0455 2976 sbhips - ok
18:49:27.0471 2976 SBRE - ok
18:49:27.0502 2976 SbTis (44062a740434b7c3946096d615aaa91c) C:\WINDOWS\system32\drivers\sbtis.sys
18:49:27.0533 2976 SbTis - ok
18:49:27.0564 2976 SCardSvr (410046e401eb11e1e6749e9deea41d4a) C:\WINDOWS\System32\SCardSvr.exe
18:49:27.0736 2976 SCardSvr - ok
18:49:27.0783 2976 Schedule (3ff232a7731621b8902d81d42418c93c) C:\WINDOWS\system32\schedsvc.dll
18:49:27.0971 2976 Schedule - ok
18:49:28.0018 2976 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:49:28.0205 2976 Secdrv - ok
18:49:28.0236 2976 seclogon (477e2c3cc5e4a0d635bcb0ea8dcac3c6) C:\WINDOWS\System32\seclogon.dll
18:49:28.0408 2976 seclogon - ok
18:49:28.0424 2976 SENS (a530b75c10c23c9ab28fdb6ce719e21f) C:\WINDOWS\system32\sens.dll
18:49:28.0596 2976 SENS - ok
18:49:28.0611 2976 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
18:49:28.0768 2976 serenum - ok
18:49:28.0799 2976 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\DRIVERS\serial.sys
18:49:28.0955 2976 Serial - ok
18:49:29.0002 2976 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
18:49:29.0158 2976 Sfloppy - ok
18:49:29.0236 2976 SharedAccess (f58faca9621d2db01bd0927d9a0a208e) C:\WINDOWS\System32\ipnathlp.dll
18:49:29.0455 2976 SharedAccess - ok
18:49:29.0486 2976 ShellHWDetection (ee9a2b9ea968a792a053c9d1a86bf870) C:\WINDOWS\System32\shsvcs.dll
18:49:29.0518 2976 ShellHWDetection - ok
18:49:29.0518 2976 Simbad - ok
18:49:29.0596 2976 SkypeUpdate (17eab7852ff9f15fbaab4e95efc0b812) C:\Program Files\Skype\Updater\Updater.exe
18:49:29.0611 2976 SkypeUpdate - ok
18:49:29.0643 2976 Sparrow - ok
18:49:29.0674 2976 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
18:49:29.0846 2976 splitter - ok
18:49:29.0877 2976 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
18:49:29.0908 2976 Spooler - ok
18:49:29.0924 2976 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
18:49:30.0111 2976 sr - ok
18:49:30.0143 2976 srservice (35b91147124f64ac8081a2edb9ea4dee) C:\WINDOWS\system32\srsvc.dll
18:49:30.0346 2976 srservice - ok
18:49:30.0393 2976 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
18:49:30.0471 2976 Srv - ok
18:49:30.0518 2976 SSDPSRV (becd5271dc4e3b7c3d035f790fcbc1e5) C:\WINDOWS\System32\ssdpsrv.dll
18:49:30.0674 2976 SSDPSRV - ok
18:49:30.0736 2976 stisvc (c1cdd9275f6a115bb0ae1d55d8d27ba6) C:\WINDOWS\system32\wiaservc.dll
18:49:30.0955 2976 stisvc - ok
18:49:30.0986 2976 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
18:49:31.0143 2976 swenum - ok
18:49:31.0189 2976 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
18:49:31.0346 2976 swmidi - ok
18:49:31.0346 2976 SwPrv - ok
18:49:31.0361 2976 symc810 - ok
18:49:31.0377 2976 symc8xx - ok
18:49:31.0393 2976 sym_hi - ok
18:49:31.0408 2976 sym_u3 - ok
18:49:31.0424 2976 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
18:49:31.0596 2976 sysaudio - ok
18:49:31.0627 2976 SysmonLog (ce06f01b88ace199a1bf460cac29c110) C:\WINDOWS\system32\smlogsvc.exe
18:49:31.0799 2976 SysmonLog - ok
18:49:31.0861 2976 TapiSrv (c2546cd7a398476f9df5614b2ae160e8) C:\WINDOWS\System32\tapisrv.dll
18:49:32.0033 2976 TapiSrv - ok
18:49:32.0096 2976 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:49:32.0127 2976 Tcpip - ok
18:49:32.0158 2976 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
18:49:32.0330 2976 TDPIPE - ok
18:49:32.0346 2976 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
18:49:32.0518 2976 TDTCP - ok
18:49:32.0533 2976 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
18:49:32.0705 2976 TermDD - ok
18:49:32.0752 2976 TermService (a75dd6fc3dbee4fff5ebc9f2c28bb66e) C:\WINDOWS\System32\termsrv.dll
18:49:32.0939 2976 TermService - ok
18:49:32.0971 2976 Themes (ee9a2b9ea968a792a053c9d1a86bf870) C:\WINDOWS\System32\shsvcs.dll
18:49:33.0002 2976 Themes - ok
18:49:33.0002 2976 TosIde - ok
18:49:33.0018 2976 TrkWks (38853304ccb938d30e0c4cde8d2c2a8a) C:\WINDOWS\system32\trkwks.dll
18:49:33.0189 2976 TrkWks - ok
18:49:33.0221 2976 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
18:49:33.0393 2976 Udfs - ok
18:49:33.0408 2976 ultra - ok
18:49:33.0471 2976 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
18:49:33.0658 2976 Update - ok
18:49:33.0689 2976 upnphost (651bd90dcee5b7bdc74a2eb7c9266f9e) C:\WINDOWS\System32\upnphost.dll
18:49:33.0877 2976 upnphost - ok
18:49:33.0908 2976 UPS (20a0f6a11959e92908717d09e87d670d) C:\WINDOWS\System32\ups.exe
18:49:34.0049 2976 UPS - ok
18:49:34.0080 2976 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:49:34.0252 2976 usbccgp - ok
18:49:34.0299 2976 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:49:34.0455 2976 usbehci - ok
18:49:34.0471 2976 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:49:34.0627 2976 usbhub - ok
18:49:34.0658 2976 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
18:49:34.0830 2976 usbprint - ok
18:49:34.0877 2976 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:49:35.0049 2976 USBSTOR - ok
18:49:35.0080 2976 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:49:35.0252 2976 usbuhci - ok
18:49:35.0283 2976 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
18:49:35.0455 2976 VgaSave - ok
18:49:35.0455 2976 ViaIde - ok
18:49:35.0502 2976 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
18:49:35.0658 2976 VolSnap - ok
18:49:35.0705 2976 VSS (d6ba1a63d9e00933f1cd2a885573afb2) C:\WINDOWS\System32\vssvc.exe
18:49:35.0893 2976 VSS - ok
18:49:35.0924 2976 W32Time (fa4e1cdba256787f2149f4aad07bc91f) C:\WINDOWS\system32\w32time.dll
18:49:36.0111 2976 W32Time - ok
18:49:36.0158 2976 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:49:36.0330 2976 Wanarp - ok
18:49:36.0330 2976 WDICA - ok
18:49:36.0377 2976 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
18:49:36.0533 2976 wdmaud - ok
18:49:36.0596 2976 WebClient (47ae51048a82dfa1cd6b51d369f7e169) C:\WINDOWS\System32\webclnt.dll
18:49:36.0752 2976 WebClient - ok
18:49:36.0830 2976 winmgmt (e488332126e3b1182d2b8a0c35408ec6) C:\WINDOWS\system32\wbem\WMIsvc.dll
18:49:36.0986 2976 winmgmt - ok
18:49:37.0018 2976 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
18:49:37.0111 2976 WmdmPmSN - ok
18:49:37.0143 2976 WmiApSrv (23f6f03272f7e5679f1f050aed5acee6) C:\WINDOWS\System32\wbem\wmiapsrv.exe
18:49:37.0315 2976 WmiApSrv - ok
18:49:37.0455 2976 WMPNetworkSvc (3739866d20abd42f26a7b85f9e2560af) C:\Program Files\Windows Media Player\WMPNetwk.exe
18:49:37.0533 2976 WMPNetworkSvc - ok
18:49:37.0690 2976 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:49:37.0752 2976 WPFFontCache_v0400 - ok
18:49:37.0846 2976 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:49:38.0018 2976 WS2IFSL - ok
18:49:38.0065 2976 wscsvc (4c86d5faf78194995af9cc1075f65dd3) C:\WINDOWS\system32\wscsvc.dll
18:49:38.0221 2976 wscsvc - ok
18:49:38.0236 2976 WSearch - ok
18:49:38.0268 2976 wuauserv (c1364564800ee9784192145324a23308) C:\WINDOWS\system32\wuauserv.dll
18:49:38.0455 2976 wuauserv - ok
18:49:38.0486 2976 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:49:38.0533 2976 WudfPf - ok
18:49:38.0565 2976 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:49:38.0580 2976 WudfRd - ok
18:49:38.0611 2976 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
18:49:38.0643 2976 WudfSvc - ok
18:49:38.0721 2976 WZCSVC (a27d4ba7264c0bf52f32d10405bea1d4) C:\WINDOWS\System32\wzcsvc.dll
18:49:38.0924 2976 WZCSVC - ok
18:49:38.0971 2976 xmlprov (eaa4bb9edb3fb10cf8979fe65e63658f) C:\WINDOWS\System32\xmlprov.dll
18:49:39.0158 2976 xmlprov - ok
18:49:39.0190 2976 MBR (0x1B8) (10ae9eb13951b8e206480773f877a330) \Device\Harddisk0\DR0
18:49:39.0268 2976 \Device\Harddisk0\DR0 - ok
18:49:39.0283 2976 Boot (0x1200) (acc5197f3423c695c97ae4b5507f1eed) \Device\Harddisk0\DR0\Partition0
18:49:39.0283 2976 \Device\Harddisk0\DR0\Partition0 - ok
18:49:39.0283 2976 ============================================================
18:49:39.0283 2976 Scan finished
18:49:39.0283 2976 ============================================================
18:49:39.0408 0936 Detected object count: 6
18:49:39.0408 0936 Actual detected object count: 6
18:49:55.0174 0936 Apache2.2 ( UnsignedFile.Multi.Generic ) - skipped by user
18:49:55.0174 0936 Apache2.2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:49:55.0174 0936 Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - skipped by user
18:49:55.0174 0936 Ati HotKey Poller ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:49:55.0174 0936 ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user
18:49:55.0174 0936 ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:49:55.0174 0936 ati2mtag ( UnsignedFile.Multi.Generic ) - skipped by user
18:49:55.0174 0936 ati2mtag ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:49:55.0174 0936 eBeam Device Service ( UnsignedFile.Multi.Generic ) - skipped by user
18:49:55.0174 0936 eBeam Device Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:49:55.0190 0936 PEVSystemStart ( UnsignedFile.Multi.Generic ) - skipped by user
18:49:55.0190 0936 PEVSystemStart ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:50:20.0940 1376 Deinitialize success


Děkuji za pomoc

Re: Přesměrování odkazů výsledků vyhledávání google ve FF a

Napsal: 09 čer 2012 11:45
od micola
Výpis z OTL:

OTL Extras logfile created on: 9.6.2012 10:38:43 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Documents and Settings\Martin\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,60 Gb Available Physical Memory | 79,81% Memory free
3,85 Gb Paging File | 3,25 Gb Available in Paging File | 84,50% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39,06 Gb Total Space | 2,76 Gb Free Space | 7,06% Space Free | Partition Type: NTFS
Drive E: | 1,89 Gb Total Space | 0,87 Gb Free Space | 46,11% Space Free | Partition Type: FAT

Computer Name: DOMA1 | User Name: Martin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-1645522239-1214440339-839522115-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\xampp\apache\bin\httpd.exe" = C:\xampp\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server -- (Apache Software Foundation)
"C:\totalcmd\TOTALCMD.EXE" = C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit -- (Ghisler Software GmbH)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03ADC8AB-C130-0C3D-1FF9-2C385DF25689}" = CCC Help Czech
"{04022AA7-40C7-4ABD-8733-745DC751E12D}" = ActivInspire Help (CZE) v1
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07021185-008D-ABF9-7716-475AC035F8B3}" = CCC Help Spanish
"{0F8D0406-7755-AC37-6529-73AD649DBE32}" = Catalyst Control Center Graphics Previews Common
"{1111706F-666A-4037-7777-203328764D10}" = JavaFX 2.0.3
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4300" = Canon iP4300
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22072CC8-7230-96F8-52F4-05EAF3F906B6}" = CCC Help Polish
"{2368ADBD-6FDF-4B9F-FE41-E20B4D78E79E}" = CCC Help Chinese Standard
"{25EF0DC4-B072-2E04-4581-A13C91423CE6}" = CCC Help Portuguese
"{26A24AE4-039D-4CA4-87B4-2F83217003FF}" = Java(TM) 7 Update 3
"{26F7855C-443B-00A6-F7B8-A97A5403F617}" = CCC Help Danish
"{2CB4A925-48A7-DA65-DCEE-D4DE224B7D84}" = CCC Help English
"{306D75B9-7FFF-FF65-0C76-57F2FE4FE1D6}" = Catalyst Control Center Core Implementation
"{32B12FE4-5A51-751A-1FB6-A14E97EBDD5C}" = CCC Help German
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{351512E5-01BD-E878-6F57-AA3E517D9ECE}" = Skins
"{354A387E-0374-21A3-6832-335674A6D7D1}" = CCC Help French
"{3C00BEE9-26D0-D9E0-A2D1-62F70D412A12}" = CCC Help Turkish
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4346F7AA-3D56-0941-424C-4454E04D37F6}" = CCC Help Italian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CAE2F2C-75CD-A0DE-7520-449BCBBCC833}" = CCC Help Korean
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{57F7F0A5-8F22-8E63-E819-803B5C9CA3A5}" = CCC Help Dutch
"{5EA437D2-7A57-B60E-E8F2-76BFAC0895A5}" = CCC Help Chinese Traditional
"{61AF4E75-050E-0304-3417-8BC16417FEB1}" = CCC Help Greek
"{632005DA-C291-5275-284C-5EE96B05C714}" = Catalyst Control Center HydraVision Full
"{6332D268-FCEE-47A0-8AD6-6948E25AA786}" = ActivInspire v1
"{6C72BE0C-3E25-CACD-0070-2FD9C02ABA14}" = ccc-core-preinstall
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{880BB617-914E-17E8-D877-A96BAC5794D2}" = Catalyst Control Center Graphics Full New
"{8897CF22-DB6C-8248-895C-12BFA2677F51}" = CCC Help Hungarian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{9B42F233-1FC2-41C4-86F5-868DFFC038E2}" = LibreOffice 3.5 Help Pack (Czech)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Czech
"{AF710FDE-2815-8C8D-5281-8004C2654AA6}" = CCC Help Russian
"{AFF2D965-C6F2-A210-FBF7-532612AA1D23}" = CCC Help Swedish
"{B21336EE-4AEF-9940-4AC7-EDB89854B8D3}" = CCC Help Thai
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BB21B808-F784-4883-A4D4-B1473384C1C6}" = LibreOffice 3.5
"{BBA69346-61A1-BD34-E75A-4D81232DB1FE}" = Catalyst Control Center Localization All
"{BFD5ED08-F066-92D5-BE67-3B9AE5DCFF0C}" = CCC Help Japanese
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4609F15-FB3C-D97E-BAA1-4F10815039C2}" = Catalyst Control Center Graphics Full Existing
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CCBE1D74-B35F-4B61-AAE2-9B1A17BB8E6D}" = Kodu Game Lab
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D01FAC3D-86B4-3A19-9D10-9156A0EB3EBE}" = CCC Help Finnish
"{D73722C8-3F65-C75B-A631-5D36894DAB92}" = ccc-core-static
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DDAD33B6-8C00-428D-087B-A7088355B9BE}" = Catalyst Control Center Graphics Light
"{E333F074-FC7F-596D-3D61-44F0EC28E8C0}" = ccc-utility
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA38F9E4-BED7-E021-B660-8FDFF7EC6E1A}" = CCC Help Norwegian
"7-Zip" = 7-Zip 9.21beta
"Ad-Aware Browsing Protection" = Ad-Aware Browsing Protection
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE v.6.80
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"eBeamDeviceService_is1" = eBeam Device Service 2.3
"eBeamInteract_is1" = eBeam Interact 2.3
"Filzip 3.0.0.0_is1" = Filzip 3.0
"Flight Simulator 8.0" = Microsoft Flight Simulator 2002
"Galerie obrázků_is1" = Galerie obrázků verze 2.3.2
"GEONExT_is1" = GEONExT 1.74
"Google Chrome" = Google Chrome
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"hotpot_is1" = HotPotatoes v 6.3.0.4
"ie8" = Windows Internet Explorer 8
"Inkscape" = Inkscape 0.48.2
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 8.2.0
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Mozilla Firefox 13.0 (x86 cs)" = Mozilla Firefox 13.0 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Picasa 3" = Picasa 3
"SGP Baltík_is1" = SGP Baltík 3
"Speccy" = Speccy
"Totalcmd" = Total Commander (Remove or Repair)
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1645522239-1214440339-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5.6.2012 13:30:02 | Computer Name = DOMA1 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace avz.exe, verze 4.39.0.16, zablokovaný modul hungapp,
verze 0.0.0.0, adresa bloku 0x00000000.

[ System Events ]
Error - 5.6.2012 11:25:18 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SBRE

Error - 7.6.2012 11:04:16 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SBRE

Error - 7.6.2012 11:20:27 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7024
Description = Služba Apache2.2 ukončena s chybou 1 (0x1), specifickou pro službu.

Error - 7.6.2012 11:23:09 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SBRE

Error - 7.6.2012 11:33:40 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SBRE

Error - 7.6.2012 12:47:26 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SBRE

Error - 7.6.2012 16:10:40 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7024
Description = Služba Apache2.2 ukončena s chybou 1 (0x1), specifickou pro službu.

Error - 8.6.2012 11:07:33 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SBRE

Error - 8.6.2012 15:56:49 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7024
Description = Služba Apache2.2 ukončena s chybou 1 (0x1), specifickou pro službu.

Error - 9.6.2012 4:16:25 | Computer Name = DOMA1 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SBRE


< End of report >



Výpisy z MBA:

---------------------------------------
Malwarebyte's Anti Rootkit utility v00.15.00.00

(c) Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.267000 GHz
Memory total: 2146746368, free: 1617190912

------------ Kernel report ------------
06/09/2012 11:12:05
------------ Loaded modules -----------
\WINDOWS\system32\ntoskrnl.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\System32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
pciide.sys
\WINDOWS\System32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\System32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
PxHelp20.sys
KSecDD.sys
Ntfs.sys
NDIS.sys
Mup.sys
\SystemRoot\System32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\System32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rtenicxp.sys
\SystemRoot\System32\DRIVERS\usbuhci.sys
\SystemRoot\System32\DRIVERS\USBPORT.SYS
\SystemRoot\System32\DRIVERS\usbehci.sys
\SystemRoot\System32\DRIVERS\serial.sys
\SystemRoot\System32\DRIVERS\serenum.sys
\SystemRoot\System32\DRIVERS\i8042prt.sys
\SystemRoot\System32\DRIVERS\kbdclass.sys
\SystemRoot\System32\DRIVERS\imapi.sys
\SystemRoot\System32\DRIVERS\cdrom.sys
\SystemRoot\System32\DRIVERS\redbook.sys
\SystemRoot\System32\DRIVERS\ks.sys
\SystemRoot\System32\DRIVERS\audstub.sys
\SystemRoot\System32\DRIVERS\rasl2tp.sys
\SystemRoot\System32\DRIVERS\ndistapi.sys
\SystemRoot\System32\DRIVERS\ndiswan.sys
\SystemRoot\System32\DRIVERS\raspppoe.sys
\SystemRoot\System32\DRIVERS\raspptp.sys
\SystemRoot\System32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\psched.sys
\SystemRoot\System32\DRIVERS\msgpc.sys
\SystemRoot\System32\DRIVERS\ptilink.sys
\SystemRoot\System32\DRIVERS\raspti.sys
\SystemRoot\System32\DRIVERS\termdd.sys
\SystemRoot\System32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\SBFWIM.sys
\SystemRoot\System32\DRIVERS\swenum.sys
\SystemRoot\System32\DRIVERS\update.sys
\SystemRoot\System32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\RtkHDAud.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\System32\DRIVERS\usbhub.sys
\SystemRoot\System32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\System32\DRIVERS\tcpip.sys
\SystemRoot\system32\drivers\SbFw.sys
\SystemRoot\system32\drivers\sbtis.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbios.sys
\SystemRoot\System32\DRIVERS\rdbss.sys
\SystemRoot\System32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\System32\DRIVERS\ipnat.sys
\SystemRoot\System32\DRIVERS\wanarp.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\DRIVERS\usbccgp.sys
\SystemRoot\System32\DRIVERS\hidusb.sys
\SystemRoot\System32\DRIVERS\HIDCLASS.SYS
\SystemRoot\System32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\atiok3x2.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\System32\DRIVERS\ndisuio.sys
\SystemRoot\System32\DRIVERS\mrxdav.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\System32\Drivers\Fastfat.SYS
\SystemRoot\system32\drivers\kmixer.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys
\WINDOWS\system32\ntdll.dll
----------- End -----------
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff89b9aab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-4\
Lower Device Object: 0xffffffff89b9bd98
Lower Device Driver Name: \Driver\atapi\
Driver name found: atapi
DriverEntry returned 0x0
Function returned 0x0
Scanning drivers directory
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff89b9aab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff89b99900, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff89b9aab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff89c0a370, DeviceName: \Device\0000005d\, DriverName: \Driver\ACPI\
DevicePointer: 0xffffffff89b9bd98, DeviceName: \Device\Ide\IdeDeviceP0T0L0-4\, DriverName: \Driver\atapi\
------------ End ----------
Upper DeviceData: 0xffffffffe1a84230, 0xffffffff89b9aab8, 0xffffffff88200ab8
Lower DeviceData: 0xffffffffe392c368, 0xffffffff89b9bd98, 0xffffffff887f6c60
Partition type: MBR
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Drive 0
Scanning MBR on drive 0...

Inspecting partition table:

MBR Signature: 55AA
Disk Signature: 6C526C52
Partition information:

Partition 0 is Type 0x7
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 81915372
Partition is bootable

Partition 1 is Type 0x5
Partition is NOT ACTIVE.
Partition starts at LBA: 81915902 Numsec = 74385410

Partition 2 is Empty.
Partition starts at LBA: 0 Numsec = 0

Partition 3 is Empty.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 80026361856 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0...
MBAM Scan
Infected: Object C:\Documents and Settings\Martin\Plocha\DownloadSetup.exe --> [Affiliate.Downloader]
Partition type: MBR
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Removal scheduling successful. System shutdown needed.


Malwarebytes Anti-Rootkit Utility 0.15.0.0
www.malwarebytes.org

Database version: v2012.06.09.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
:: DOMA1 [administrator]

9.6.2012 11:22:45
mbamantirootkit-log-2012-06-09 (11-22-45).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: PUP | PUM | P2P
Objects scanned: 26161
Time elapsed: 10 minute(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Documents and Settings\Martin\Plocha\DownloadSetup.exe (Affiliate.Downloader) -> Delete on reboot. [302dc42cc09cfd397f077c0c817f1ce4]

(end)


Ten DownloadSetup.exe jsem si omylem stáhl ze sendspace, když jsem v nepozornosti klepl na jiný odkaz.

Díky za pomoc, ale problém stále přetrvává, nejčasteji mě z odkaz vyhledávání google přesměruje na rocketnews.com; někdy i prohlížeč zobrazí upozornění na přesměrování na útočnou stránku. Vážně uvažuji o přeinstalaci systému.

Re: Přesměrování odkazů výsledků vyhledávání google ve FF a

Napsal: 09 čer 2012 13:14
od micola
výpis otl.txt:
OTL.zip
(105.97 KiB) Staženo 21 x

Re: Přesměrování odkazů výsledků vyhledávání google ve FF a

Napsal: 10 čer 2012 12:54
od micola
Problém se objevil i v IE, ale v menší míře, po odinstalování FF a GC a instalaci Opery se zdálo, že v ní je to OK, ale dnes po instalaci FF je problém zpět a to jak ve FF tak v O.