Nejede Firefox, IE ani RSIT
Napsal: 22 lis 2012 16:27
Dobrý den,
máme doma 3 počítače a teď jsem si dokupoval notebook, takže jsem chtěl naší domácí síť rozšířit i o něj. Mám dva mladší brášky, kterým patří dva kompy. Jenže když jsem přišel k počítači jednoho z nich, zjistil jsem že se k němu chová... mírně řečeno hrozně. Vůbec nekoukal co se mu instalovalo spolu s hrami a všelijakým softwarem apod. Dneska jsem strávil několik hodin tím, že jsem odinstalovával různé toolbary a jiný balast. CCleaner u něj odstranil 6GB volného místa.
Jenže jsem zjistil, že mu nefunguje Firefox ani IE. Internet funguje, ten je ok (ping) ale když se otevřou okna z IE nebo Firefoxu (který jsem teď odinstaloval a nainstaloval nejnovější verzi) tak se nic nezobrazí, je se čeká. U FF je to navíc z půlky černé okno. Tak jsem si říkal, že bych se obrátil na vás, už jste mi v minulosti mockrát dobře poradili a pomohli
.
Jenže jsem zjistil, že RSIT se u něj nespustí - po kliknutí na Continue se objeví status bar s "Writing header information"
A pak error:
AutoIt Error
Line 8055 (File "C:\Users\Petr\Desktop\RSIT.exe"):
Error: Variable used withnout being declared.
Takže jsem zkusil ten DDS a ten už log vytvořil.
Asi tam toho ještě bude dost... každopádně kdybyste se na to podívali, byl bych vám moc vděčný, děkuju!
EDIT: Ještě jsem zapoměl, že firewall má, ten je ok (ZoneAlarm), ale antivir už asi nějakou dobu nebyl aktualizovaný (Avast) a teď tam není vůbec, protože jsem ho odninstaloval a chtěl nainstalovat nově, ale u toho jsem zjistil, že mu nejedou ty prohlížeče.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 1.6.0_29
Run by Petr at 16:15:21 on 2012-11-22
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.seznam.cz/
uSearch Page = hxxp://downloads.phpnuke.org/en/index.php?rvs=google&q={searchTerms}
mStart Page = hxxp://search.gboxapp.com/
mSearch Page = hxxp://downloads.phpnuke.org/en/index.php?rvs=google&q={searchTerms}
uURLSearchHooks: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - <orphaned>
uURLSearchHooks: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - <orphaned>
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
EB: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - <orphaned>
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ISW] <no file>
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{B52AD1FF-6440-4C80-BA3D-36C05C00A77F} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\petr\appdata\roaming\mozilla\firefox\profiles\icmq9n54.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.gboxapp.com/?q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.gboxapp.com/?q=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_287.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6Oyu36sSF3&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.incredibar_i.hardId - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.incredibar_i.instlDay - 15396
FF - user.js: extensions.incredibar_i.vrsn - 1.5.3.27
FF - user.js: extensions.incredibar_i.vrsni - 1.5.3.27
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.3.2712:32:16
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6Oyu36sSF3
FF - user.js: extensions.incredibar_i.upn2n - 92260966304444521
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10606
FF - user.js: extensions.incredibar_i.ppd - 20
FF - user.js: extensions.Softonic.rvrtMsg - Click Yes to keep current home page and default search settings, Click No to restore original settings
FF - user.js: extensions.Softonic.autoRvrt - false
FF - user.js: extensions.Softonic_i.hmpg - true
FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=13&cc=
FF - user.js: extensions.Softonic.hpOld - hxxp://www.seznam.cz/
FF - user.js: extensions.Softonic.hpNew - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=13&cc=
FF - user.js: extensions.Softonic.dfltSrch - true
FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic)
FF - user.js: extensions.Softonic.keyWordUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=2&cc=&q=
FF - user.js: extensions.Softonic.dspOld - Google
FF - user.js: extensions.Softonic.dspNew - Search the web (Softonic)
FF - user.js: extensions.Softonic_i.dnsErr - true
FF - user.js: extensions.Softonic_i.newTab - true
FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=15&cc=
FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=1&cc=&q=
FF - user.js: extensions.Softonic.id - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.Softonic.instlDay - 15529
FF - user.js: extensions.Softonic.vrsn - 1.5.24.3
FF - user.js: extensions.Softonic.vrsni - 1.5.24.3
FF - user.js: extensions.Softonic_i.vrsnTs - 1.5.24.319:55:44
FF - user.js: extensions.Softonic.prtnrId - softonic
FF - user.js: extensions.Softonic.prdct - Softonic
FF - user.js: extensions.Softonic.aflt - SD
FF - user.js: extensions.Softonic_i.smplGrp - none
FF - user.js: extensions.Softonic.tlbrId - base
FF - user.js: extensions.Softonic.instlRef - MON00005
FF - user.js: extensions.Softonic.dfltLng -
FF - user.js: extensions.Softonic.excTlbr - false
FF - user.js: extensions.Softonic.admin - false
.
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112060&tt=010712_6
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.BabylonToolbar_i.hardId - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15529
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:07:32
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
.
.
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-11-22 14:11:27 -------- d-----w- c:\windows\system32\appmgmt
2012-11-22 14:02:46 -------- d-----w- c:\windows\system32\wbem\mof\good
2012-11-22 14:02:46 -------- d-----w- c:\windows\system32\wbem\mof\bad
2012-11-22 13:58:07 -------- d-----w- c:\windows\system32\wbem\Logs
2012-11-22 08:04:28 -------- d-----w- c:\users\petr\appdata\local\Diagnostics
2012-11-20 17:47:02 6812136 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{665697ca-bd2a-4e03-9de2-31752028eeb2}\mpengine.dll
2012-11-14 22:50:55 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-14 22:50:55 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-14 22:50:55 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-14 22:50:13 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-14 22:50:13 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-14 22:50:13 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-14 22:50:12 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-14 22:50:11 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-14 22:50:11 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-14 22:50:10 613888 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-14 19:39:45 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-11-14 19:39:45 175104 ----a-w- c:\windows\system32\netcorehc.dll
2012-11-14 19:39:45 156672 ----a-w- c:\windows\system32\ncsi.dll
2012-11-14 19:39:45 1293680 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-11-14 19:39:44 52224 ----a-w- c:\windows\system32\nlaapi.dll
2012-11-14 19:39:44 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-11-14 19:39:44 242176 ----a-w- c:\windows\system32\nlasvc.dll
2012-11-14 19:39:44 18944 ----a-w- c:\windows\system32\netevent.dll
2012-11-14 19:39:30 78336 ----a-w- c:\windows\system32\synceng.dll
2012-11-14 19:39:27 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-11-14 19:39:14 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-11-14 19:39:14 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-10-27 17:47:31 -------- d-----w- c:\users\petr\appdata\local\SkypeFx
2012-10-27 17:47:26 -------- d-----w- c:\users\petr\appdata\local\IsolatedStorage
2012-10-27 14:52:50 96224 ----a-w- c:\program files\mozilla firefox\webapprt-stub.exe
2012-10-27 14:52:50 157272 ----a-w- c:\program files\mozilla firefox\webapp-uninstaller.exe
.
==================== Find3M ====================
.
2012-11-22 14:32:19 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-22 14:32:19 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-14 18:59:37 22328 ----a-w- c:\users\petr\appdata\roaming\PnkBstrK.sys
2012-10-14 18:30:18 111928 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-10-10 20:15:04 1867112 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-10-10 20:15:00 2574696 ----a-w- c:\windows\system32\nvcuvid.dll
2012-10-10 20:14:50 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll
2012-10-10 20:14:50 12501352 ----a-w- c:\windows\system32\nvwgf2um.dll
2012-10-10 20:14:46 17559912 ----a-w- c:\windows\system32\nvcompiler.dll
2012-10-10 20:14:44 2428776 ----a-w- c:\windows\system32\nvapi.dll
2012-10-10 20:14:42 7697768 ----a-w- c:\windows\system32\nvcuda.dll
2012-10-10 20:14:28 10837352 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-10-10 20:14:22 19906920 ----a-w- c:\windows\system32\nvoglv32.dll
2012-10-10 20:14:22 1009512 ----a-w- c:\windows\system32\nvdispco32.dll
2012-10-10 20:14:16 6127464 ----a-w- c:\windows\system32\nvopencl.dll
2012-10-10 20:14:16 15309160 ----a-w- c:\windows\system32\nvd3dum.dll
2012-10-08 07:56:24 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-10-08 07:48:03 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-10-08 07:47:44 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 07:44:05 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 07:43:21 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-10-08 07:40:56 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-10-02 19:29:42 645992 ----a-w- c:\windows\system32\nvvsvc.exe
2012-10-02 19:29:41 62312 ----a-w- c:\windows\system32\nvshext.dll
2012-10-02 19:29:41 2557288 ----a-w- c:\windows\system32\nvsvcr.dll
2012-10-02 19:29:41 108392 ----a-w- c:\windows\system32\nvmctray.dll
2012-10-02 19:29:22 2853224 ----a-w- c:\windows\system32\nvsvc.dll
2012-10-02 19:28:53 3965288 ----a-w- c:\windows\system32\nvcpl.dll
2012-10-02 12:15:52 430952 ----a-w- c:\windows\system32\nvStreaming.exe
2012-09-16 13:06:20 281768 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-14 18:28:53 2048 ----a-w- c:\windows\system32\tzres.dll
2012-08-31 17:18:09 1211760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-30 17:12:02 3968880 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-24 16:57:48 172544 ----a-w- c:\windows\system32\wintrust.dll
.
============= FINISH: 16:16:03,18 ===============
máme doma 3 počítače a teď jsem si dokupoval notebook, takže jsem chtěl naší domácí síť rozšířit i o něj. Mám dva mladší brášky, kterým patří dva kompy. Jenže když jsem přišel k počítači jednoho z nich, zjistil jsem že se k němu chová... mírně řečeno hrozně. Vůbec nekoukal co se mu instalovalo spolu s hrami a všelijakým softwarem apod. Dneska jsem strávil několik hodin tím, že jsem odinstalovával různé toolbary a jiný balast. CCleaner u něj odstranil 6GB volného místa.
Jenže jsem zjistil, že mu nefunguje Firefox ani IE. Internet funguje, ten je ok (ping) ale když se otevřou okna z IE nebo Firefoxu (který jsem teď odinstaloval a nainstaloval nejnovější verzi) tak se nic nezobrazí, je se čeká. U FF je to navíc z půlky černé okno. Tak jsem si říkal, že bych se obrátil na vás, už jste mi v minulosti mockrát dobře poradili a pomohli

Jenže jsem zjistil, že RSIT se u něj nespustí - po kliknutí na Continue se objeví status bar s "Writing header information"
A pak error:
AutoIt Error
Line 8055 (File "C:\Users\Petr\Desktop\RSIT.exe"):
Error: Variable used withnout being declared.
Takže jsem zkusil ten DDS a ten už log vytvořil.
Asi tam toho ještě bude dost... každopádně kdybyste se na to podívali, byl bych vám moc vděčný, děkuju!
EDIT: Ještě jsem zapoměl, že firewall má, ten je ok (ZoneAlarm), ale antivir už asi nějakou dobu nebyl aktualizovaný (Avast) a teď tam není vůbec, protože jsem ho odninstaloval a chtěl nainstalovat nově, ale u toho jsem zjistil, že mu nejedou ty prohlížeče.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 1.6.0_29
Run by Petr at 16:15:21 on 2012-11-22
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.seznam.cz/
uSearch Page = hxxp://downloads.phpnuke.org/en/index.php?rvs=google&q={searchTerms}
mStart Page = hxxp://search.gboxapp.com/
mSearch Page = hxxp://downloads.phpnuke.org/en/index.php?rvs=google&q={searchTerms}
uURLSearchHooks: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - <orphaned>
uURLSearchHooks: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - <orphaned>
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
EB: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - <orphaned>
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ISW] <no file>
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{B52AD1FF-6440-4C80-BA3D-36C05C00A77F} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\petr\appdata\roaming\mozilla\firefox\profiles\icmq9n54.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.gboxapp.com/?q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.gboxapp.com/?q=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_287.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6Oyu36sSF3&loc=IB_TB&i=26&search=
FF - user.js: extensions.incredibar_i.id - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.incredibar_i.hardId - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.incredibar_i.instlDay - 15396
FF - user.js: extensions.incredibar_i.vrsn - 1.5.3.27
FF - user.js: extensions.incredibar_i.vrsni - 1.5.3.27
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.3.2712:32:16
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6Oyu36sSF3
FF - user.js: extensions.incredibar_i.upn2n - 92260966304444521
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10606
FF - user.js: extensions.incredibar_i.ppd - 20
FF - user.js: extensions.Softonic.rvrtMsg - Click Yes to keep current home page and default search settings, Click No to restore original settings
FF - user.js: extensions.Softonic.autoRvrt - false
FF - user.js: extensions.Softonic_i.hmpg - true
FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=13&cc=
FF - user.js: extensions.Softonic.hpOld - hxxp://www.seznam.cz/
FF - user.js: extensions.Softonic.hpNew - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=13&cc=
FF - user.js: extensions.Softonic.dfltSrch - true
FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic)
FF - user.js: extensions.Softonic.keyWordUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=2&cc=&q=
FF - user.js: extensions.Softonic.dspOld - Google
FF - user.js: extensions.Softonic.dspNew - Search the web (Softonic)
FF - user.js: extensions.Softonic_i.dnsErr - true
FF - user.js: extensions.Softonic_i.newTab - true
FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=15&cc=
FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=1&cc=&q=
FF - user.js: extensions.Softonic.id - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.Softonic.instlDay - 15529
FF - user.js: extensions.Softonic.vrsn - 1.5.24.3
FF - user.js: extensions.Softonic.vrsni - 1.5.24.3
FF - user.js: extensions.Softonic_i.vrsnTs - 1.5.24.319:55:44
FF - user.js: extensions.Softonic.prtnrId - softonic
FF - user.js: extensions.Softonic.prdct - Softonic
FF - user.js: extensions.Softonic.aflt - SD
FF - user.js: extensions.Softonic_i.smplGrp - none
FF - user.js: extensions.Softonic.tlbrId - base
FF - user.js: extensions.Softonic.instlRef - MON00005
FF - user.js: extensions.Softonic.dfltLng -
FF - user.js: extensions.Softonic.excTlbr - false
FF - user.js: extensions.Softonic.admin - false
.
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112060&tt=010712_6
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.BabylonToolbar_i.hardId - 4c57e0ae0000000000000016e66a397c
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15529
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:07:32
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
.
.
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-11-22 14:11:27 -------- d-----w- c:\windows\system32\appmgmt
2012-11-22 14:02:46 -------- d-----w- c:\windows\system32\wbem\mof\good
2012-11-22 14:02:46 -------- d-----w- c:\windows\system32\wbem\mof\bad
2012-11-22 13:58:07 -------- d-----w- c:\windows\system32\wbem\Logs
2012-11-22 08:04:28 -------- d-----w- c:\users\petr\appdata\local\Diagnostics
2012-11-20 17:47:02 6812136 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{665697ca-bd2a-4e03-9de2-31752028eeb2}\mpengine.dll
2012-11-14 22:50:55 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-14 22:50:55 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-14 22:50:55 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-14 22:50:13 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-14 22:50:13 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-14 22:50:13 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-14 22:50:12 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-14 22:50:11 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-14 22:50:11 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-14 22:50:10 613888 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-14 19:39:45 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-11-14 19:39:45 175104 ----a-w- c:\windows\system32\netcorehc.dll
2012-11-14 19:39:45 156672 ----a-w- c:\windows\system32\ncsi.dll
2012-11-14 19:39:45 1293680 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-11-14 19:39:44 52224 ----a-w- c:\windows\system32\nlaapi.dll
2012-11-14 19:39:44 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-11-14 19:39:44 242176 ----a-w- c:\windows\system32\nlasvc.dll
2012-11-14 19:39:44 18944 ----a-w- c:\windows\system32\netevent.dll
2012-11-14 19:39:30 78336 ----a-w- c:\windows\system32\synceng.dll
2012-11-14 19:39:27 2345984 ----a-w- c:\windows\system32\win32k.sys
2012-11-14 19:39:14 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-11-14 19:39:14 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-10-27 17:47:31 -------- d-----w- c:\users\petr\appdata\local\SkypeFx
2012-10-27 17:47:26 -------- d-----w- c:\users\petr\appdata\local\IsolatedStorage
2012-10-27 14:52:50 96224 ----a-w- c:\program files\mozilla firefox\webapprt-stub.exe
2012-10-27 14:52:50 157272 ----a-w- c:\program files\mozilla firefox\webapp-uninstaller.exe
.
==================== Find3M ====================
.
2012-11-22 14:32:19 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-22 14:32:19 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-14 18:59:37 22328 ----a-w- c:\users\petr\appdata\roaming\PnkBstrK.sys
2012-10-14 18:30:18 111928 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-10-10 20:15:04 1867112 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-10-10 20:15:00 2574696 ----a-w- c:\windows\system32\nvcuvid.dll
2012-10-10 20:14:50 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll
2012-10-10 20:14:50 12501352 ----a-w- c:\windows\system32\nvwgf2um.dll
2012-10-10 20:14:46 17559912 ----a-w- c:\windows\system32\nvcompiler.dll
2012-10-10 20:14:44 2428776 ----a-w- c:\windows\system32\nvapi.dll
2012-10-10 20:14:42 7697768 ----a-w- c:\windows\system32\nvcuda.dll
2012-10-10 20:14:28 10837352 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-10-10 20:14:22 19906920 ----a-w- c:\windows\system32\nvoglv32.dll
2012-10-10 20:14:22 1009512 ----a-w- c:\windows\system32\nvdispco32.dll
2012-10-10 20:14:16 6127464 ----a-w- c:\windows\system32\nvopencl.dll
2012-10-10 20:14:16 15309160 ----a-w- c:\windows\system32\nvd3dum.dll
2012-10-08 07:56:24 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-10-08 07:48:03 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-10-08 07:47:44 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 07:44:05 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 07:43:21 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-10-08 07:40:56 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-10-02 19:29:42 645992 ----a-w- c:\windows\system32\nvvsvc.exe
2012-10-02 19:29:41 62312 ----a-w- c:\windows\system32\nvshext.dll
2012-10-02 19:29:41 2557288 ----a-w- c:\windows\system32\nvsvcr.dll
2012-10-02 19:29:41 108392 ----a-w- c:\windows\system32\nvmctray.dll
2012-10-02 19:29:22 2853224 ----a-w- c:\windows\system32\nvsvc.dll
2012-10-02 19:28:53 3965288 ----a-w- c:\windows\system32\nvcpl.dll
2012-10-02 12:15:52 430952 ----a-w- c:\windows\system32\nvStreaming.exe
2012-09-16 13:06:20 281768 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-09-14 18:28:53 2048 ----a-w- c:\windows\system32\tzres.dll
2012-08-31 17:18:09 1211760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-30 17:12:02 3968880 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-30 17:12:02 3914096 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-24 16:57:48 172544 ----a-w- c:\windows\system32\wintrust.dll
.
============= FINISH: 16:16:03,18 ===============