nemocnej explorer
Napsal: 24 bře 2013 18:41
zdravim -po zapnutí exploreru trvá naběhnutí asi 30 vteřin.každé další okno to samé.prosim o kontrol logu -díky
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16521 BrowserJavaVersion: 10.17.2
Run by jemin at 18:33:35 on 2013-03-23
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3070.1738 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\FsUsbExService.Exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\PnkBstrB.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
D:\Fraps\fraps.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\IncrediMail\Bin\IncMail.exe
C:\Program Files\Skype\Phone\Skype.exe
F:\Kies\Kies.exe
C:\Program Files\NoC:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\IncrediMail\Bin\ImApp.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.seznam.cz/
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: WebTransBHO Class: {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - c:\programdata\langsoft\WebIE.dll
BHO: Groove GFS Browser Helper: {4DB74D06-491C-440D-305E-012400990F3E} - c:\windows\system32\cii.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - f:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [Svátky a výročí] c:\program files\oksoftware\svátky a výročí\Vyroci.exe
uRun: [IncrediMail] c:\program files\incredimail\bin\IncMail.exe /c
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [] f:\kies\external\firmwareupdate\KiesPDLR.exe
uRun: [KiesAirMessage] f:\kies\KiesAirMessage.exe -startup
uRun: [KiesPreload] f:\kies\Kies.exe /preload
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [GrooveMonitor] "f:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SpywareTerminatorShield] c:\program files\spyware terminator\SpywareTerminatorShield.exe
mRun: [SpywareTerminatorUpdater] c:\program files\spyware terminator\SpywareTerminatorUpdate.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\jemin\appdata\roaming\micros~1\windows\startm~1\programs\startup\vesmrn~1.lnk - c:\program files\noční obloha\vesmir.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\kasper~1.lnk - c:\program files\kaspersky security scan\KSS.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - f:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: Stáhnout odkaz s použitím BitCometu - f:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: Stáhnout všechna videa s použitím BitCometu - f:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - f:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\program files\microsoft office\office12\ONBttnIE.dll
IE: {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\langsoft\WebIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\langsoft\WebIE.dll
IE: {CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\langsoft\WebIE.dll
IE: {CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\langsoft\WebIE.dll
IE: {CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\langsoft\WebIE.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{F5F9714F-8253-4118-93DC-41DFCB3E7387} : DHCPNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - f:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
STS: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - c:\windows\system32\DreamScene.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - f:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 validation.sls.microsoft.com
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]
R1 atitray;atitray;c:\program files\ray adams\ati tray tools\atitray.sys [2010-10-30 19360]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-3-14 218688]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-11-25 32768]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2012-11-16 291840]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2013-3-20 233472]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 100328]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\spyware terminator\st_rsser.exe [2011-11-25 587472]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-3-14 383264]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2011-2-13 37944]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2013-3-20 37344]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\microsoft security client\NisSrv.exe [2013-1-27 295232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-1-8 161536]
S3 AODDriver4.0;AODDriver4.0;c:\program files\ati technologies\ati.ace\fuel\i386\aoddriver2.sys [2012-3-5 45184]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2012-5-14 86656]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-2-6 83864]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-8-2 18432]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-2-23 15872]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-2-6 181784]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-2-23 52224]
S3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\wat\WatAdminSvc.exe [2011-2-14 1343400]
.
=============== Created Last 30 ================
.
2013-03-23 17:31:20 60872 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{31d5bdbd-d79d-46f7-bd98-778cd1fb3c96}\offreg.dll
2013-03-23 08:38:55 7108640 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{31d5bdbd-d79d-46f7-bd98-778cd1fb3c96}\mpengine.dll
2013-03-21 10:20:31 740840 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f596c12f-278b-426a-ac33-37785819496d}\gapaengine.dll
2013-03-21 10:20:15 7108640 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2013-03-20 15:22:35 37344 ----a-w- c:\windows\system32\FsUsbExDisk.Sys
2013-03-20 15:22:35 233472 ----a-w- c:\windows\system32\FsUsbExService.Exe
2013-03-20 15:22:35 110592 ----a-w- c:\windows\system32\FsUsbExDevice.Dll
2013-03-18 19:35:21 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-03-18 19:32:21 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-18 15:01:45 8952608 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-03-18 15:01:45 892704 ----a-w- c:\windows\system32\nvdispgenco3231421.dll
2013-03-18 15:01:45 7959000 ----a-w- c:\windows\system32\nvcuda.dll
2013-03-18 15:01:45 6271872 ----a-w- c:\windows\system32\nvopencl.dll
2013-03-18 15:01:45 481056 ----a-w- c:\windows\system32\nvEncodeAPI.dll
2013-03-18 15:01:45 2728736 ----a-w- c:\windows\system32\nvcuvid.dll
2013-03-18 15:01:45 205184 ----a-w- c:\windows\system32\nvinit.dll
2013-03-18 15:01:45 1995552 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-03-18 15:01:45 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2013-03-18 15:01:45 1012512 ----a-w- c:\windows\system32\nvdispco3231421.dll
2013-03-18 15:01:44 20542752 ----a-w- c:\windows\system32\nvoglv32.dll
2013-03-17 15:56:31 -------- d-----w- C:\CFLog
2013-03-15 22:10:13 -------- d-----w- c:\users\jemin\.objectdb
2013-03-15 16:55:34 28600 ----a-w- c:\windows\system32\nvhdap32.dll
2013-03-15 16:55:34 154040 ----a-w- c:\windows\system32\drivers\nvhda32v.sys
2013-03-15 16:55:30 892704 ----a-w- c:\windows\system32\nvdispgenco3220162.dll
2013-03-15 16:55:30 1012512 ----a-w- c:\windows\system32\nvdispco3220294.dll
2013-03-15 09:18:48 -------- d-----w- c:\users\jemin\appdata\roaming\NVIDIA
2013-03-15 08:39:10 634144 ----a-w- c:\windows\system32\nvvsvc.exe
2013-03-15 08:39:10 62752 ----a-w- c:\windows\system32\nvshext.dll
2013-03-15 08:39:10 3065455 ----a-w- c:\windows\system32\nvcoproc.bin
2013-03-15 08:39:10 3014432 ----a-w- c:\windows\system32\nvsvc.dll
2013-03-15 08:39:10 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2013-03-15 08:39:09 4119328 ----a-w- c:\windows\system32\nvcpl.dll
2013-03-15 08:39:09 223008 ----a-w- c:\windows\system32\nvmctray.dll
2013-03-15 08:38:41 -------- d-----w- c:\programdata\NVIDIA Corporation
2013-03-15 08:38:28 1009512 ----a-w- c:\windows\system32\nvdispco32.dll
2013-03-15 08:38:27 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll
2013-03-15 08:37:36 13001456 ----a-w- c:\windows\system32\nvwgf2um.dll
2013-03-15 08:37:28 968408 ----a-w- c:\windows\system32\nvumdshim.dll
2013-03-15 08:37:27 15042928 ----a-w- c:\windows\system32\nvd3dum.dll
2013-03-15 08:37:26 2539128 ----a-w- c:\windows\system32\nvapi.dll
2013-03-14 02:38:26 559904 ----a-w- c:\windows\system32\nvStreaming.exe
2013-03-09 05:40:19 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-04 16:53:54 -------- d-----w- c:\users\jemin\appdata\roaming\LangSoft
2013-02-26 06:55:22 65536 ----a-w- c:\windows\system32\frapsvid.dll
2013-02-23 08:37:47 -------- d-----w- c:\windows\system32\3045
2013-02-22 14:37:49 -------- d-----w- c:\users\jemin\appdata\roaming\Mikrotik
.
==================== Find3M ====================
.
2013-03-23 17:17:49 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-03-23 17:17:49 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-03-19 18:36:18 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-03-19 18:35:52 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-03-18 19:35:21 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-03-15 09:36:36 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-15 09:36:36 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-09 05:40:09 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-09 05:40:09 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-12 04:48:31 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-06 06:42:10 83864 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2013-02-06 06:42:08 181784 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2013-01-30 10:53:21 232336 ------w- c:\windows\system32\MpSigStub.exe
2013-01-20 14:59:04 195296 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 14:59:04 100328 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-01-05 05:00:15 3967848 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-05 05:00:11 3913064 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 04:50:52 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-01-04 03:00:29 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-01-03 05:05:20 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-01-03 05:04:43 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
.
============= FINISH: 18:34:58,82 ===============
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16521 BrowserJavaVersion: 10.17.2
Run by jemin at 18:33:35 on 2013-03-23
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.3070.1738 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\FsUsbExService.Exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\PnkBstrB.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
D:\Fraps\fraps.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
F:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\IncrediMail\Bin\IncMail.exe
C:\Program Files\Skype\Phone\Skype.exe
F:\Kies\Kies.exe
C:\Program Files\NoC:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\IncrediMail\Bin\ImApp.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.seznam.cz/
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: WebTransBHO Class: {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - c:\programdata\langsoft\WebIE.dll
BHO: Groove GFS Browser Helper: {4DB74D06-491C-440D-305E-012400990F3E} - c:\windows\system32\cii.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - f:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [Svátky a výročí] c:\program files\oksoftware\svátky a výročí\Vyroci.exe
uRun: [IncrediMail] c:\program files\incredimail\bin\IncMail.exe /c
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [] f:\kies\external\firmwareupdate\KiesPDLR.exe
uRun: [KiesAirMessage] f:\kies\KiesAirMessage.exe -startup
uRun: [KiesPreload] f:\kies\Kies.exe /preload
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [GrooveMonitor] "f:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SpywareTerminatorShield] c:\program files\spyware terminator\SpywareTerminatorShield.exe
mRun: [SpywareTerminatorUpdater] c:\program files\spyware terminator\SpywareTerminatorUpdate.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\jemin\appdata\roaming\micros~1\windows\startm~1\programs\startup\vesmrn~1.lnk - c:\program files\noční obloha\vesmir.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\kasper~1.lnk - c:\program files\kaspersky security scan\KSS.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - f:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: Stáhnout odkaz s použitím BitCometu - f:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: Stáhnout všechna videa s použitím BitCometu - f:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - f:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\program files\microsoft office\office12\ONBttnIE.dll
IE: {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\langsoft\WebIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\langsoft\WebIE.dll
IE: {CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\langsoft\WebIE.dll
IE: {CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\langsoft\WebIE.dll
IE: {CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\langsoft\WebIE.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{F5F9714F-8253-4118-93DC-41DFCB3E7387} : DHCPNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - f:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
STS: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - c:\windows\system32\DreamScene.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - f:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 validation.sls.microsoft.com
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]
R1 atitray;atitray;c:\program files\ray adams\ati tray tools\atitray.sys [2010-10-30 19360]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-3-14 218688]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-11-25 32768]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-11-16 217088]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2012-11-16 291840]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2013-3-20 233472]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 100328]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\spyware terminator\st_rsser.exe [2011-11-25 587472]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2013-3-14 383264]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2011-2-13 37944]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2013-3-20 37344]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\microsoft security client\NisSrv.exe [2013-1-27 295232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-1-8 161536]
S3 AODDriver4.0;AODDriver4.0;c:\program files\ati technologies\ati.ace\fuel\i386\aoddriver2.sys [2012-3-5 45184]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2012-5-14 86656]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2013-2-6 83864]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-8-2 18432]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-2-23 15872]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2013-2-6 181784]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-2-23 52224]
S3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\wat\WatAdminSvc.exe [2011-2-14 1343400]
.
=============== Created Last 30 ================
.
2013-03-23 17:31:20 60872 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{31d5bdbd-d79d-46f7-bd98-778cd1fb3c96}\offreg.dll
2013-03-23 08:38:55 7108640 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{31d5bdbd-d79d-46f7-bd98-778cd1fb3c96}\mpengine.dll
2013-03-21 10:20:31 740840 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f596c12f-278b-426a-ac33-37785819496d}\gapaengine.dll
2013-03-21 10:20:15 7108640 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2013-03-20 15:22:35 37344 ----a-w- c:\windows\system32\FsUsbExDisk.Sys
2013-03-20 15:22:35 233472 ----a-w- c:\windows\system32\FsUsbExService.Exe
2013-03-20 15:22:35 110592 ----a-w- c:\windows\system32\FsUsbExDevice.Dll
2013-03-18 19:35:21 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-03-18 19:32:21 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-18 15:01:45 8952608 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-03-18 15:01:45 892704 ----a-w- c:\windows\system32\nvdispgenco3231421.dll
2013-03-18 15:01:45 7959000 ----a-w- c:\windows\system32\nvcuda.dll
2013-03-18 15:01:45 6271872 ----a-w- c:\windows\system32\nvopencl.dll
2013-03-18 15:01:45 481056 ----a-w- c:\windows\system32\nvEncodeAPI.dll
2013-03-18 15:01:45 2728736 ----a-w- c:\windows\system32\nvcuvid.dll
2013-03-18 15:01:45 205184 ----a-w- c:\windows\system32\nvinit.dll
2013-03-18 15:01:45 1995552 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-03-18 15:01:45 17560352 ----a-w- c:\windows\system32\nvcompiler.dll
2013-03-18 15:01:45 1012512 ----a-w- c:\windows\system32\nvdispco3231421.dll
2013-03-18 15:01:44 20542752 ----a-w- c:\windows\system32\nvoglv32.dll
2013-03-17 15:56:31 -------- d-----w- C:\CFLog
2013-03-15 22:10:13 -------- d-----w- c:\users\jemin\.objectdb
2013-03-15 16:55:34 28600 ----a-w- c:\windows\system32\nvhdap32.dll
2013-03-15 16:55:34 154040 ----a-w- c:\windows\system32\drivers\nvhda32v.sys
2013-03-15 16:55:30 892704 ----a-w- c:\windows\system32\nvdispgenco3220162.dll
2013-03-15 16:55:30 1012512 ----a-w- c:\windows\system32\nvdispco3220294.dll
2013-03-15 09:18:48 -------- d-----w- c:\users\jemin\appdata\roaming\NVIDIA
2013-03-15 08:39:10 634144 ----a-w- c:\windows\system32\nvvsvc.exe
2013-03-15 08:39:10 62752 ----a-w- c:\windows\system32\nvshext.dll
2013-03-15 08:39:10 3065455 ----a-w- c:\windows\system32\nvcoproc.bin
2013-03-15 08:39:10 3014432 ----a-w- c:\windows\system32\nvsvc.dll
2013-03-15 08:39:10 2555168 ----a-w- c:\windows\system32\nvsvcr.dll
2013-03-15 08:39:09 4119328 ----a-w- c:\windows\system32\nvcpl.dll
2013-03-15 08:39:09 223008 ----a-w- c:\windows\system32\nvmctray.dll
2013-03-15 08:38:41 -------- d-----w- c:\programdata\NVIDIA Corporation
2013-03-15 08:38:28 1009512 ----a-w- c:\windows\system32\nvdispco32.dll
2013-03-15 08:38:27 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll
2013-03-15 08:37:36 13001456 ----a-w- c:\windows\system32\nvwgf2um.dll
2013-03-15 08:37:28 968408 ----a-w- c:\windows\system32\nvumdshim.dll
2013-03-15 08:37:27 15042928 ----a-w- c:\windows\system32\nvd3dum.dll
2013-03-15 08:37:26 2539128 ----a-w- c:\windows\system32\nvapi.dll
2013-03-14 02:38:26 559904 ----a-w- c:\windows\system32\nvStreaming.exe
2013-03-09 05:40:19 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-04 16:53:54 -------- d-----w- c:\users\jemin\appdata\roaming\LangSoft
2013-02-26 06:55:22 65536 ----a-w- c:\windows\system32\frapsvid.dll
2013-02-23 08:37:47 -------- d-----w- c:\windows\system32\3045
2013-02-22 14:37:49 -------- d-----w- c:\users\jemin\appdata\roaming\Mikrotik
.
==================== Find3M ====================
.
2013-03-23 17:17:49 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2013-03-23 17:17:49 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-03-19 18:36:18 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-03-19 18:35:52 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-03-18 19:35:21 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-03-15 09:36:36 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-15 09:36:36 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-09 05:40:09 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-09 05:40:09 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-12 04:48:31 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-06 06:42:10 83864 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2013-02-06 06:42:08 181784 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2013-01-30 10:53:21 232336 ------w- c:\windows\system32\MpSigStub.exe
2013-01-20 14:59:04 195296 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-20 14:59:04 100328 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2013-01-05 05:00:15 3967848 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-05 05:00:11 3913064 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-04 04:50:52 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-01-04 03:00:29 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-01-03 05:05:20 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-01-03 05:04:43 187752 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
.
============= FINISH: 18:34:58,82 ===============