Stránka 1 z 4

Comodo firewall

Napsal: 19 dub 2013 00:09
od Michi-san
Dobrý večer
Nastal mi dnes takový problém. Dnes mi můj Comodo FW hlásil novou aktualizaci, kterou jsem samozřejmě z důvodu lepší bezpečnosti nechala stáhnout. Když však hlásil, že pro stažení všech komponent je potřeba restartovat počítač a já ho následně restartovala, systém při zapínání nechtěl naskočit a objevilo se okénko, že se systém pokusí automaticky opravit chyby. Při tomto procesu mi také nabídl obnovení počítače, s čímž jsem souhlasila a po opravě mi již systém naskočil tak jak má. Po zapnutí se ale ukázalo, že mi přeinstaloval avast! antivirus na avast! Pro antivirus a můj Comodo firewall byl nepoužitelný (nebylo možné zajít do nastavení, prostě se ukazovala jen ta hlavní obrazovka). Avast i comodo jsem tedy přeinstalovala a od té chvíle avast jede zase tak jak má, jen je třeba znovu obnovit licenci. Jenže Comodo jel v pořádku asi tak hodinu, jakmile jsem ho nastavovala, chtěl znovu restartování počítače a poté se mi systém znovu nechtěl nastartovat. Znovu se obnovil, znovu naskočil (po opravě), ale Comodo mi nefunguje. Prý nějaký "system agent" nebo "security agent" či "secret agent" (to první slovo si nevybavuji, jen vím že začínalo na "s") nechce běžet a zda chci diagnostiku. S tím jsem souhlasila, ale automaticky se to prý nedokáže opravit. Teď ho nemůžu ani odinstalovat (v odinstalování programů není, ani ikona v nabídce Start ani na ploše) a Comodo složka nejde smazat, prý je používaná. Nevím, zda Vám v tom log z RSIT pomůže, ale přikládám ho sem:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Oliczech at 2013-04-19 00:40:21
Microsoft Windows 7 Starter Service Pack 1
System drive C: has 38 GB (37%) free of 102 GB
Total RAM: 1014 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:41:36, on 19.4.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\windows\system32\igfxsrvc.exe
C:\Users\Oliczech\Downloads\RSIT.exe
C:\Program Files\trend micro\Oliczech.exe
C:\windows\system32\taskeng.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/?rlz=1W4CHBA_csCZ520
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HotkeyMon] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
O4 - HKLM\..\Run: [HotkeyService] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [CapsHook] AsusSender.exe C:\Program Files\EeePC\CapsHook\CapsHook.exe
O4 - HKLM\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe autorun
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ASUSPRP] C:\Program Files\ASUS\APRP\APRP.EXE
O4 - HKLM\..\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files\ASUS\AsusVibe\AsusVibeLauncher.exe
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - (no file)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{367D9EBA-EEC7-41D3-9CD7-90A75CC42F4C}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5787F6B-C3A0-4969-93CB-7A3E6BEE527A}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{367D9EBA-EEC7-41D3-9CD7-90A75CC42F4C}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS2\Services\Tcpip\..\{367D9EBA-EEC7-41D3-9CD7-90A75CC42F4C}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Asus Launcher Service (AsusService) - Unknown owner - C:\Windows\System32\AsusService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

--
End of file - 6429 bytes

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Oliczech\AppData\Roaming\Mozilla\Firefox\Profiles\utfa2b8w.default

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.169 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@kingsfot.com/npkws]
"Description"=npkws
"Path"=C:\Program Files\kingsoft\kingsoft antivirus\npkws.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 77576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-06 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-07 1224568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-06 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-07 1224568]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotkeyMon"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe []
"HotkeyService"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe []
"SuperHybridEngine"=AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe []
"CapsHook"=AsusSender.exe C:\Program Files\EeePC\CapsHook\CapsHook.exe []
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2010-06-10 414384]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-04-27 9177632]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-11-19 1594664]
"ASUSPRP"=C:\Program Files\ASUS\APRP\APRP.EXE [2010-12-22 2018032]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [2009-11-19 83240]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-04-20 142104]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-04-20 174360]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-04-20 150808]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-03-07 4767304]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-01-24 1430736]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files\ASUS\AsusVibe\AsusVibeLauncher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\SYSTEM32\igfxdev.dll [2011-04-11 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.siren"=sirenacm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-04-19 00:40:22 ----D---- C:\Program Files\trend micro
2013-04-19 00:40:21 ----D---- C:\rsit
2013-04-18 19:27:29 ----SD---- C:\ProgramData\Shared Space
2013-04-18 19:24:53 ----D---- C:\ProgramData\Comodo
2013-04-18 19:24:47 ----D---- C:\ProgramData\Comodo Downloader
2013-04-18 19:18:41 ----D---- C:\Program Files\COMODO
2013-04-18 19:02:59 ----SHD---- C:\Config.Msi
2013-04-18 17:44:11 ----A---- C:\windows\system32\drivers\aswVmm.sys
2013-04-18 17:44:11 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2013-04-18 17:33:47 ----A---- C:\windows\system32\drivers\aswSP.sys
2013-04-18 17:33:47 ----A---- C:\windows\system32\drivers\aswFsBlk.sys
2013-04-18 17:33:43 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2013-04-18 17:33:42 ----A---- C:\windows\system32\drivers\aswTdi.sys
2013-04-18 17:33:42 ----A---- C:\windows\system32\drivers\aswSnx.sys
2013-04-18 17:33:41 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2013-04-18 17:32:52 ----A---- C:\windows\avastSS.scr
2013-04-18 17:32:22 ----D---- C:\Program Files\AVAST Software
2013-04-11 21:44:43 ----D---- C:\Program Files\Mozilla Firefox
2013-04-10 14:27:49 ----A---- C:\windows\system32\jscript.dll
2013-04-10 14:27:45 ----A---- C:\windows\system32\jscript9.dll
2013-04-10 14:27:44 ----A---- C:\windows\system32\jsproxy.dll
2013-04-10 14:27:43 ----A---- C:\windows\system32\iesetup.dll
2013-04-10 14:27:41 ----A---- C:\windows\system32\ieui.dll
2013-04-10 14:27:39 ----A---- C:\windows\system32\msfeeds.dll
2013-04-10 14:27:38 ----A---- C:\windows\system32\iernonce.dll
2013-04-10 14:27:38 ----A---- C:\windows\system32\ie4uinit.exe
2013-04-10 14:27:37 ----A---- C:\windows\system32\RegisterIEPKEYs.exe
2013-04-10 14:27:37 ----A---- C:\windows\system32\iesysprep.dll
2013-04-10 14:27:36 ----A---- C:\windows\system32\urlmon.dll
2013-04-10 14:27:33 ----A---- C:\windows\system32\iertutil.dll
2013-04-10 14:27:26 ----A---- C:\windows\system32\wininet.dll
2013-04-10 14:27:17 ----A---- C:\windows\system32\ieframe.dll
2013-04-10 14:27:08 ----A---- C:\windows\system32\mshtml.dll
2013-04-10 14:18:32 ----A---- C:\windows\system32\win32k.sys
2013-04-10 14:18:30 ----A---- C:\windows\system32\drivers\fvevol.sys
2013-04-10 14:18:19 ----A---- C:\windows\system32\ntoskrnl.exe
2013-04-10 14:18:18 ----A---- C:\windows\system32\ntkrnlpa.exe
2013-04-10 14:18:14 ----A---- C:\windows\system32\smss.exe
2013-04-10 14:18:14 ----A---- C:\windows\system32\csrsrv.dll
2013-04-10 14:17:35 ----A---- C:\windows\system32\drivers\ntfs.sys
2013-04-08 00:14:24 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2013-04-08 00:14:24 ----A---- C:\windows\system32\msls31.dll
2013-04-08 00:14:24 ----A---- C:\windows\system32\elshyph.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\wextract.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\webcheck.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\vbscript.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\url.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\SetIEInstalledDate.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\pngfilt.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\occache.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\msrating.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshtmlmedia.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshtmler.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshtmled.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshta.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\msfeedssync.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\msfeedsbs.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\licmgr10.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\inseng.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\imgutil.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\iexpress.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\ieUnatt.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\iepeers.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\iedkcs32.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\ieapfltr.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\ieapfltr.dat
2013-04-08 00:14:23 ----A---- C:\windows\system32\IEAdvpack.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\icardie.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\dxtrans.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\dxtmsft.dll
2013-04-01 10:59:00 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-30 17:16:24 ----D---- C:\Users\Oliczech\AppData\Roaming\vlc
2013-03-30 17:11:07 ----D---- C:\Program Files\VideoLAN
2013-03-23 16:20:10 ----A---- C:\windows\system32\drivers\usb8023.sys

======List of files/folders modified in the last 1 month======

9999-12-23 10:04:57 ----D---- C:\Program Files\Internet Explorer
9999-12-23 10:04:55 ----D---- C:\Program Files\Metin2
2013-04-19 00:41:09 ----D---- C:\windows\Temp
2013-04-19 00:40:39 ----D---- C:\windows\Prefetch
2013-04-19 00:40:22 ----RD---- C:\Program Files
2013-04-19 00:32:07 ----D---- C:\windows\system32\config
2013-04-19 00:26:47 ----D---- C:\windows\system32\drivers
2013-04-19 00:26:46 ----D---- C:\windows\inf
2013-04-19 00:26:41 ----D---- C:\windows\system32\DriverStore
2013-04-19 00:26:31 ----SHD---- C:\System Volume Information
2013-04-18 19:27:29 ----HD---- C:\ProgramData
2013-04-18 19:07:13 ----D---- C:\windows\system32\Tasks
2013-04-18 17:52:41 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-04-18 17:32:22 ----D---- C:\ProgramData\AVAST Software
2013-04-18 00:21:54 ----D---- C:\temp
2013-04-12 15:45:25 ----D---- C:\windows\rescache
2013-04-10 22:33:03 ----D---- C:\windows\debug
2013-04-10 22:28:40 ----RSD---- C:\windows\assembly
2013-04-10 14:46:04 ----D---- C:\windows\winsxs
2013-04-10 14:28:24 ----D---- C:\windows\system32\catroot
2013-04-10 14:21:39 ----A---- C:\windows\system32\MRT.exe
2013-04-08 00:25:07 ----D---- C:\windows\system32\cs-CZ
2013-04-08 00:25:05 ----D---- C:\windows\system32\migration
2013-04-08 00:25:05 ----D---- C:\windows\system32\en-US
2013-04-08 00:25:05 ----D---- C:\windows\PolicyDefinitions
2013-04-08 00:23:09 ----D---- C:\windows\Logs
2013-04-01 12:28:56 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-04-01 12:27:23 ----A---- C:\windows\system32\FlashPlayerApp.exe
2013-04-01 11:01:18 ----D---- C:\Users\Oliczech\AppData\Roaming\Mozilla
2013-03-26 02:12:07 ----D---- C:\Users\Oliczech\AppData\Roaming\Media Player Classic

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2013-03-07 49248]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2010-06-08 435736]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 AsUpIO;AsUpIO; C:\windows\system32\drivers\AsUpIO.sys [2010-03-31 11520]
R1 aswRdr;aswRdr; C:\windows\System32\Drivers\aswrdr2.sys [2013-03-07 60656]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2013-03-07 765736]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2013-03-07 368176]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2013-03-07 62376]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\windows\system32\DRIVERS\cmderd.sys [2013-01-16 20072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\windows\system32\DRIVERS\cmdguard.sys [2013-01-16 576768]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\windows\System32\DRIVERS\cmdhlp.sys [2013-01-16 43728]
R1 inspect;COMODO Internet Security Firewall Driver; C:\windows\system32\DRIVERS\inspect.sys [2013-01-16 84416]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2013-03-07 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2013-03-07 66336]
R2 irda;IrDA Protocol; C:\windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2011-04-11 4815872]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHDA.sys [2010-04-27 3084256]
R3 kbfiltr;Keyboard Filter; C:\windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 13880]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x86.sys [2010-08-24 68208]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\windows\system32\DRIVERS\rtl8192se.sys [2010-07-02 1015912]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2009-11-19 230448]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2013-03-07 164736]
S3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2009-07-01 43944]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys []
S3 EagleNT;EagleNT; \??\C:\windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\windows\system32\drivers\EagleXNt.sys []
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 MosIrUsb;MosIrUsb.sys; C:\windows\system32\DRIVERS\MosIrUsb.sys [2007-10-11 22016]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TOO;TOO; \??\C:\Program Files\ASUS\LiveUpdate\genport.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2012-08-23 49664]
S3 viaagp;Filtr VIA sběrnice AGP; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AsusService;Asus Launcher Service; C:\Windows\System32\AsusService.exe [2009-08-19 219136]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-03-07 45248]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-01-24 2319504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-22 1710464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-01 256904]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-01-24 127184]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-04-11 115608]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040]

-----------------EOF-----------------



Děkuji za ochotu a případnou pomoc.

Re: Comodo firewall

Napsal: 19 dub 2013 03:21
od Márty84
Zdravim :)

Zkuste na odinstalaci comoda pouzit http://www.stahuj.centrum.cz/utility_a_ ... installer/

Jestli ho nenajde, zkuste comodo znovu nainstalovat a pak hned pres revo odinstalovat.

Jinak ho budem muset odpalit nasilim. Dejte vedet zda to slo a podle toho budem postupovat dale

Re: Comodo firewall

Napsal: 19 dub 2013 08:38
od Michi-san
Přes revo odinstalovat nejde, protože se tam nezobrazí
Zkoušela jsem druhý postup (opětovnou instalaci a odinstalaci přes revo), jenže v půlce instalace hlásil, že chce restartovat počítač a že potom bude instalace pokračovat. Restartovala jsem počítač, instalace naskočila, ale sekla se na 66% (které byly pravděpodobně i před restartem) a chtěl znovu restartovat počítač. Po dalším restartu už to vyhodilo jen okénko, kde mám odsouhlasit, aby Comodo provedl změny v počítači, instalace se už nespustí. A po dalším restartu už nevyskočilo ani to okénko s odsouhlasením změn.
Ale hlášení o security agentovi (starý) Comodo hází dále, to samé hlášení o diagnostice

Re: Comodo firewall

Napsal: 19 dub 2013 19:19
od Márty84
Takze revo uz ho zase nevidi a znovu nainstalovat uz nejde, rozumim tomu spravne? Jestli ho revo vidi, zkuste to odinstalovat jeste jednou, ale v nouzovem rezimu.


Pokud ho uz revo nevidi, tak sem hodte novy log z RSIT a odpalime ho nasilim.

Re: Comodo firewall

Napsal: 19 dub 2013 19:53
od Michi-san
Nene, revo ho vůbec neviděl/nevidí. Ani ten starý, ani ten, který jsem se snažila znovu nainstalovat a jeho instalace selhala. Navíc mi revo teď při dalším spuštění, abych situaci zkontrolovala, hodil hlášku, že "tento program je (nejspíše) špatně nainstalován" (tím "nejspíše" si nejsem jistá, proto to dávám do závorky).
Všimla jsem si ale ještě dalšího problému, i když jsem o maličkost - na FB se mi při psaní zprávy často neukazuje text v modrém poli, když ho označím. Někdy naskočí (většinou když píšu delší správu a na začátku textu mám lomítka nebo písmeno "a" tak se mi označí modře, někdy ale ne). Možná to ale nic není.
Také se mi při spuštění IE před pár dny ozvalo "cinknutí" od windowsu, které se ozývá například když zmáčknu nechtěně klávesu, která nemá přiřazen žádný příkaz (neumím to správně vysvětlit), přitom jsem se dívala pouze na možnosti, které jsou v těch panelech "stránka, zabezpečení, nástroje, nastavení" a na nic neklikala. Možná to nic není, pro jistotu jsem to ale sdělila.

Zde log z RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Oliczech at 2013-04-19 20:50:10
Microsoft Windows 7 Starter Service Pack 1
System drive C: has 37 GB (36%) free of 102 GB
Total RAM: 1014 MB (13% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:50:44, on 19.4.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\windows\system32\taskhost.exe
C:\Users\Oliczech\Downloads\RSIT.exe
C:\Program Files\trend micro\Oliczech.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/?rlz=1W4CHBA_csCZ520
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HotkeyMon] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
O4 - HKLM\..\Run: [HotkeyService] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [CapsHook] AsusSender.exe C:\Program Files\EeePC\CapsHook\CapsHook.exe
O4 - HKLM\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe autorun
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ASUSPRP] C:\Program Files\ASUS\APRP\APRP.EXE
O4 - HKLM\..\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [{1606DC18-9578-4cbd-8312-8E9868F06A1D}] \cmdinstall.exe -cmdfile
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files\ASUS\AsusVibe\AsusVibeLauncher.exe
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - (no file)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{367D9EBA-EEC7-41D3-9CD7-90A75CC42F4C}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5787F6B-C3A0-4969-93CB-7A3E6BEE527A}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{367D9EBA-EEC7-41D3-9CD7-90A75CC42F4C}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS2\Services\Tcpip\..\{367D9EBA-EEC7-41D3-9CD7-90A75CC42F4C}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Asus Launcher Service (AsusService) - Unknown owner - C:\Windows\System32\AsusService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

--
End of file - 6759 bytes

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Oliczech\AppData\Roaming\Mozilla\Firefox\Profiles\utfa2b8w.default

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.169 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@kingsfot.com/npkws]
"Description"=npkws
"Path"=C:\Program Files\kingsoft\kingsoft antivirus\npkws.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 77576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-06 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-07 1224568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-06 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-03-07 1224568]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotkeyMon"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe []
"HotkeyService"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe []
"SuperHybridEngine"=AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe []
"CapsHook"=AsusSender.exe C:\Program Files\EeePC\CapsHook\CapsHook.exe []
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2010-06-10 414384]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-04-27 9177632]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-11-19 1594664]
"ASUSPRP"=C:\Program Files\ASUS\APRP\APRP.EXE [2010-12-22 2018032]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [2009-11-19 83240]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-04-20 142104]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-04-20 174360]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-04-20 150808]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-03-07 4767304]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-01-24 1430736]
"{1606DC18-9578-4cbd-8312-8E9868F06A1D}"=\cmdinstall.exe [2013-01-25 18980560]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files\ASUS\AsusVibe\AsusVibeLauncher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\SYSTEM32\igfxdev.dll [2011-04-11 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.siren"=sirenacm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-04-19 09:26:58 ----D---- C:\translations
2013-04-19 09:26:58 ----D---- C:\themes
2013-04-19 09:26:58 ----D---- C:\cis
2013-04-19 09:26:58 ----A---- C:\7za.dll
2013-04-19 09:26:57 ----A---- C:\cmdinstall.exe
2013-04-19 09:26:57 ----A---- C:\cmdhtml.dll
2013-04-19 09:11:32 ----D---- C:\Program Files\VS Revo Group
2013-04-19 00:40:22 ----D---- C:\Program Files\trend micro
2013-04-19 00:40:21 ----D---- C:\rsit
2013-04-18 19:27:29 ----SD---- C:\ProgramData\Shared Space
2013-04-18 19:24:53 ----D---- C:\ProgramData\Comodo
2013-04-18 19:24:47 ----D---- C:\ProgramData\Comodo Downloader
2013-04-18 19:18:41 ----D---- C:\Program Files\COMODO
2013-04-18 19:02:59 ----SHD---- C:\Config.Msi
2013-04-18 17:44:11 ----A---- C:\windows\system32\drivers\aswVmm.sys
2013-04-18 17:44:11 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2013-04-18 17:33:47 ----A---- C:\windows\system32\drivers\aswSP.sys
2013-04-18 17:33:47 ----A---- C:\windows\system32\drivers\aswFsBlk.sys
2013-04-18 17:33:43 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2013-04-18 17:33:42 ----A---- C:\windows\system32\drivers\aswTdi.sys
2013-04-18 17:33:42 ----A---- C:\windows\system32\drivers\aswSnx.sys
2013-04-18 17:33:41 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2013-04-18 17:32:52 ----A---- C:\windows\avastSS.scr
2013-04-18 17:32:22 ----D---- C:\Program Files\AVAST Software
2013-04-11 21:44:43 ----D---- C:\Program Files\Mozilla Firefox
2013-04-10 14:27:49 ----A---- C:\windows\system32\jscript.dll
2013-04-10 14:27:45 ----A---- C:\windows\system32\jscript9.dll
2013-04-10 14:27:44 ----A---- C:\windows\system32\jsproxy.dll
2013-04-10 14:27:43 ----A---- C:\windows\system32\iesetup.dll
2013-04-10 14:27:41 ----A---- C:\windows\system32\ieui.dll
2013-04-10 14:27:39 ----A---- C:\windows\system32\msfeeds.dll
2013-04-10 14:27:38 ----A---- C:\windows\system32\iernonce.dll
2013-04-10 14:27:38 ----A---- C:\windows\system32\ie4uinit.exe
2013-04-10 14:27:37 ----A---- C:\windows\system32\RegisterIEPKEYs.exe
2013-04-10 14:27:37 ----A---- C:\windows\system32\iesysprep.dll
2013-04-10 14:27:36 ----A---- C:\windows\system32\urlmon.dll
2013-04-10 14:27:33 ----A---- C:\windows\system32\iertutil.dll
2013-04-10 14:27:26 ----A---- C:\windows\system32\wininet.dll
2013-04-10 14:27:17 ----A---- C:\windows\system32\ieframe.dll
2013-04-10 14:27:08 ----A---- C:\windows\system32\mshtml.dll
2013-04-10 14:18:32 ----A---- C:\windows\system32\win32k.sys
2013-04-10 14:18:30 ----A---- C:\windows\system32\drivers\fvevol.sys
2013-04-10 14:18:19 ----A---- C:\windows\system32\ntoskrnl.exe
2013-04-10 14:18:18 ----A---- C:\windows\system32\ntkrnlpa.exe
2013-04-10 14:18:14 ----A---- C:\windows\system32\smss.exe
2013-04-10 14:18:14 ----A---- C:\windows\system32\csrsrv.dll
2013-04-10 14:17:35 ----A---- C:\windows\system32\drivers\ntfs.sys
2013-04-08 00:14:24 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2013-04-08 00:14:24 ----A---- C:\windows\system32\msls31.dll
2013-04-08 00:14:24 ----A---- C:\windows\system32\elshyph.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\wextract.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\webcheck.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\vbscript.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\url.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\SetIEInstalledDate.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\pngfilt.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\occache.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\msrating.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshtmlmedia.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshtmler.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshtmled.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\mshta.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\msfeedssync.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\msfeedsbs.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\licmgr10.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\inseng.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\imgutil.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\iexpress.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\ieUnatt.exe
2013-04-08 00:14:23 ----A---- C:\windows\system32\iepeers.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\iedkcs32.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\ieapfltr.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\ieapfltr.dat
2013-04-08 00:14:23 ----A---- C:\windows\system32\IEAdvpack.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\icardie.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\dxtrans.dll
2013-04-08 00:14:23 ----A---- C:\windows\system32\dxtmsft.dll
2013-04-01 10:59:00 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-30 17:16:24 ----D---- C:\Users\Oliczech\AppData\Roaming\vlc
2013-03-30 17:11:07 ----D---- C:\Program Files\VideoLAN
2013-03-23 16:20:10 ----A---- C:\windows\system32\drivers\usb8023.sys

======List of files/folders modified in the last 1 month======

9999-12-23 10:04:57 ----D---- C:\Program Files\Internet Explorer
9999-12-23 10:04:55 ----D---- C:\Program Files\Metin2
2013-04-19 20:50:28 ----D---- C:\windows\Temp
2013-04-19 12:49:23 ----D---- C:\windows\system32\config
2013-04-19 09:26:57 ----D---- C:\windows\System32
2013-04-19 09:26:42 ----D---- C:\windows\system32\catroot2
2013-04-19 09:20:06 ----D---- C:\windows\Prefetch
2013-04-19 09:11:32 ----RD---- C:\Program Files
2013-04-19 00:26:47 ----D---- C:\windows\system32\drivers
2013-04-19 00:26:46 ----D---- C:\windows\inf
2013-04-19 00:26:41 ----D---- C:\windows\system32\DriverStore
2013-04-19 00:26:31 ----SHD---- C:\System Volume Information
2013-04-18 19:27:29 ----HD---- C:\ProgramData
2013-04-18 19:07:13 ----D---- C:\windows\system32\Tasks
2013-04-18 17:52:41 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-04-18 17:32:22 ----D---- C:\ProgramData\AVAST Software
2013-04-18 00:21:54 ----D---- C:\temp
2013-04-12 15:45:25 ----D---- C:\windows\rescache
2013-04-10 22:33:03 ----D---- C:\windows\debug
2013-04-10 22:28:40 ----RSD---- C:\windows\assembly
2013-04-10 14:46:04 ----D---- C:\windows\winsxs
2013-04-10 14:28:24 ----D---- C:\windows\system32\catroot
2013-04-10 14:21:39 ----A---- C:\windows\system32\MRT.exe
2013-04-08 00:25:07 ----D---- C:\windows\system32\cs-CZ
2013-04-08 00:25:05 ----D---- C:\windows\system32\migration
2013-04-08 00:25:05 ----D---- C:\windows\system32\en-US
2013-04-08 00:25:05 ----D---- C:\windows\PolicyDefinitions
2013-04-08 00:23:09 ----D---- C:\windows\Logs
2013-04-01 12:28:56 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-04-01 12:27:23 ----A---- C:\windows\system32\FlashPlayerApp.exe
2013-04-01 11:01:18 ----D---- C:\Users\Oliczech\AppData\Roaming\Mozilla
2013-03-26 02:12:07 ----D---- C:\Users\Oliczech\AppData\Roaming\Media Player Classic

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2013-03-07 49248]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2010-06-08 435736]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 AsUpIO;AsUpIO; C:\windows\system32\drivers\AsUpIO.sys [2010-03-31 11520]
R1 aswRdr;aswRdr; C:\windows\System32\Drivers\aswrdr2.sys [2013-03-07 60656]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2013-03-07 765736]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2013-03-07 368176]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2013-03-07 62376]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\windows\system32\DRIVERS\cmderd.sys [2013-01-16 20072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\windows\system32\DRIVERS\cmdguard.sys [2013-01-16 576768]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\windows\System32\DRIVERS\cmdhlp.sys [2013-01-16 43728]
R1 inspect;COMODO Internet Security Firewall Driver; C:\windows\system32\DRIVERS\inspect.sys [2013-01-16 84416]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2013-03-07 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2013-03-07 66336]
R2 irda;IrDA Protocol; C:\windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2011-04-11 4815872]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHDA.sys [2010-04-27 3084256]
R3 kbfiltr;Keyboard Filter; C:\windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 13880]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x86.sys [2010-08-24 68208]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\windows\system32\DRIVERS\rtl8192se.sys [2010-07-02 1015912]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2009-11-19 230448]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2013-03-07 164736]
S3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2009-07-01 43944]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys []
S3 EagleNT;EagleNT; \??\C:\windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\windows\system32\drivers\EagleXNt.sys []
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 MosIrUsb;MosIrUsb.sys; C:\windows\system32\DRIVERS\MosIrUsb.sys [2007-10-11 22016]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sisagp;Filtr SIS sběrnice AGP; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TOO;TOO; \??\C:\Program Files\ASUS\LiveUpdate\genport.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2012-08-23 49664]
S3 viaagp;Filtr VIA sběrnice AGP; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AsusService;Asus Launcher Service; C:\Windows\System32\AsusService.exe [2009-08-19 219136]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-03-07 45248]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-01-24 2319504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-22 1710464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-01 256904]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-01-24 127184]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-04-11 115608]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040]

-----------------EOF-----------------

Re: Comodo firewall

Napsal: 19 dub 2013 20:33
od Márty84
:???: Tyto soubory a slozky znate? Nebo se to objevilo az v souvislosti az s Comodem?
C:\cmdhtml.dll
C:\7za.dll
C:\cis
C:\themes
C:\translations
C:\cmdinstall.exe

:!: :!: :!: Jestli je znate a mate tam neco potrebneho, nepokracujte dale, ale napiste!!!


Jestli je neznate, spustte OTM dle navodu



:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe a ulozte nejlepe na plochu.
Restartujte pc a najedte do nouzoveho rezimu.
Kliknete na OTM pravym mysidlem a levym na Spustit jako spravce. Pokud v NR ta moznost nebude, spustte jej normalne dvojklikem.
Do leveho okna zkopirujte tento skript (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]
[CreateRestorePoint]

:services
cmderd
cmdGuard
cmdHlp
inspect
cmdAgent
AdobeFlashPlayerUpdateSvc
cmdvirth

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Program Files\COMODO
C:\ProgramData\Comodo
C:\ProgramData\Comodo Downloader
C:\cmdhtml.dll
C:\7za.dll
C:\cis
C:\themes
C:\translations
C:\cmdinstall.exe
C:\windows\system32\DRIVERS\cmderd.sys
C:\windows\system32\DRIVERS\cmdguard.sys
C:\windows\System32\DRIVERS\cmdhlp.sys
C:\windows\system32\DRIVERS\inspect.sys

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=-
"{1606DC18-9578-4cbd-8312-8E9868F06A1D}"=-
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery na vas vyskoci, nebo bude zde C:\_OTM\MovedFiles\xxxxxxxx_xxxxxx (misto tech x budou cisla, predstavujici datum a cas spusteni)

Re: Comodo firewall

Napsal: 19 dub 2013 20:39
od Michi-san
Ta složka "cis" vypadá, že má něco společného s comodo, protože i jeho instalátor se nazývá "cis" a většinou se takhle nazývají i jeho součásti, na zbytek bych se musela podívat tak, že je jednoduše otevřu, protože si je nijak nevybavuju a neznám je.
Hloupá otázka, ale - jak spustím nouzový režim? Při spuštění notebooku mi to totiž normálně nenabízí

Re: Comodo firewall

Napsal: 19 dub 2013 20:47
od Márty84
Podle logu to vsechno vzniklo, nebo bylo zmeneno, ve stejnem case, proto si myslim, ze to vsechno patri k sobe. Ale radeji se podivejte.
2013-04-19 09:26:58 ----D---- C:\translations
2013-04-19 09:26:58 ----D---- C:\themes
2013-04-19 09:26:58 ----D---- C:\cis
2013-04-19 09:26:58 ----A---- C:\7za.dll
2013-04-19 09:26:57 ----A---- C:\cmdinstall.exe
2013-04-19 09:26:57 ----A---- C:\cmdhtml.dll


:arrow: Do nouzoveho rezimu se dostanete takto:
restartujte pc, mackejte klavesu F8 - pripadne jinou, zalezi na typu stroje - a zvolte moznost nouzovy rezim, nebo kdyby to neslo, zde je jiny postup http://forum.viry.cz/viewtopic.php?f=46&t=7554

Re: Comodo firewall

Napsal: 19 dub 2013 21:03
od Michi-san
to "themes" má v sobě jediný soubor s názvem "installer" a v popisu má, že je to "soubor motivů systému windows"
"translations" má v sobě také jeden soubor s názvem "1029.lang"
"cis" je trošku takovej nekončící řetězec složek - má v sobě složku "download", ta v sobě má složku "installs", ta zase v sobě "installer_data" a ta má v sobě soubor "installer_init", jehož popis je "dokument ve formátu XML"
"7za.dll" je samostatný soubor ve složce "Místní Disk (C:)", ve stejné složce je i ten "cmdhtml" a i ten "cmdinstall" .
Zvláštní je, že se mi v "Místní Disk (C:)" také ukázala nová složky, která tam dodneška nebyla, a to složka "Intel" (což by měla být složka, soudě podle názvu, týkající se nejspíše procesoru)

Edit: Teda oprava - i "translations" a "themes" tam nebyla stejně jako složka "Intel", všechny jsou nový

Re: Comodo firewall

Napsal: 19 dub 2013 21:06
od Michi-san
Teda, omlouvám se, že tu teď tak plaším, ale složka "Intel" má staré datum vytvoření, takže je možné že jí "falešně obviňuji" :D

Re: Comodo firewall

Napsal: 19 dub 2013 21:11
od Márty84
Vrhnete se na OTM. Pro vsechny pripady jsem mu tam dal prikaz at pred mazanim udela bod obnovy, takze kdyby nastal problem, melo by to jit vratit zpet.

Re: Comodo firewall

Napsal: 19 dub 2013 21:14
od Michi-san
Takže ho mohu normálně stáhnout z odkazu, který jste mi dal o pár zpráv výše?

Re: Comodo firewall

Napsal: 19 dub 2013 21:19
od Márty84
Ano. A s tim skriptem, v nouzovem rezimu.

Re: Comodo firewall

Napsal: 19 dub 2013 22:07
od Michi-san
Vše jsem udělala jak jste mi řekl, ale nastal problém s připojením k internetu: Počítač se chová, jako by žádná internet nebyl připojený, prostě internet nenaskočí. Zkoušela jsem restart modemu, restart počítače, spuštění v nouzovém režimu, ale nic nepomohlo.
Zde log:

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57472 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Oliczech
->Temp folder emptied: 135418724 bytes
->Temporary Internet Files folder emptied: 5035 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 355923762 bytes
->Flash cache emptied: 58487 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2088563 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 64260 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 471,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Oliczech
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb

C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Error creating restore point.
========== SERVICES/DRIVERS ==========
Error: Unable to stop service cmderd!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmderd deleted successfully.
Service cmdGuard stopped successfully!
Service cmdGuard deleted successfully!
Error: Unable to stop service cmdHlp!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdHlp deleted successfully.
Service inspect stopped successfully!
Service inspect deleted successfully!
Service cmdAgent stopped successfully!
Service cmdAgent deleted successfully!
Service AdobeFlashPlayerUpdateSvc stopped successfully!
Service AdobeFlashPlayerUpdateSvc deleted successfully!
Service cmdvirth stopped successfully!
Service cmdvirth deleted successfully!
========== FILES ==========
File/Folder C:\windows\system32\*.tmp.dll not found.
File/Folder C:\windows\system32\SET*.tmp not found.
File/Folder C:\windows\*.tmp not found.
C:\Program Files\COMODO\COMODO Internet Security\vkthemes folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\vddata\vduserdata\themes folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\vddata\vduserdata\images folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\vddata\vduserdata\bin folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\vddata\vduserdata folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\vddata folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\translations folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\themes folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\sounds folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\scanners folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\database folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security folder moved successfully.
C:\Program Files\COMODO folder moved successfully.
C:\ProgramData\Comodo\Installer folder moved successfully.
C:\ProgramData\Comodo\Firewall Pro folder moved successfully.
C:\ProgramData\Comodo\CisDumps folder moved successfully.
C:\ProgramData\Comodo\Cis\WebDialogs\images folder moved successfully.
C:\ProgramData\Comodo\Cis\WebDialogs\css folder moved successfully.
C:\ProgramData\Comodo\Cis\WebDialogs folder moved successfully.
C:\ProgramData\Comodo\Cis\Quarantine\Temp\TempFiles folder moved successfully.
C:\ProgramData\Comodo\Cis\Quarantine\Temp folder moved successfully.
C:\ProgramData\Comodo\Cis\Quarantine\info folder moved successfully.
C:\ProgramData\Comodo\Cis\Quarantine\data folder moved successfully.
C:\ProgramData\Comodo\Cis\Quarantine folder moved successfully.
C:\ProgramData\Comodo\Cis\cmc2\local_trees folder moved successfully.
C:\ProgramData\Comodo\Cis\cmc2 folder moved successfully.
C:\ProgramData\Comodo\Cis folder moved successfully.
C:\ProgramData\Comodo folder moved successfully.
C:\ProgramData\Comodo Downloader\cis\download\installs\xml_binaries\geekbuddy folder moved successfully.
C:\ProgramData\Comodo Downloader\cis\download\installs\xml_binaries\dragon folder moved successfully.
C:\ProgramData\Comodo Downloader\cis\download\installs\xml_binaries\cis folder moved successfully.
C:\ProgramData\Comodo Downloader\cis\download\installs\xml_binaries folder moved successfully.
C:\ProgramData\Comodo Downloader\cis\download\installs folder moved successfully.
C:\ProgramData\Comodo Downloader\cis\download folder moved successfully.
C:\ProgramData\Comodo Downloader\cis folder moved successfully.
C:\ProgramData\Comodo Downloader folder moved successfully.
DllUnregisterServer procedure not found in C:\cmdhtml.dll
C:\cmdhtml.dll moved successfully.
DllUnregisterServer procedure not found in C:\7za.dll
C:\7za.dll moved successfully.
C:\cis\download\installs\installer_data folder moved successfully.
C:\cis\download\installs folder moved successfully.
C:\cis\download folder moved successfully.
C:\cis folder moved successfully.
C:\themes folder moved successfully.
C:\translations folder moved successfully.
C:\cmdinstall.exe moved successfully.
C:\windows\system32\DRIVERS\cmderd.sys moved successfully.
C:\windows\system32\DRIVERS\cmdguard.sys moved successfully.
C:\windows\System32\DRIVERS\cmdhlp.sys moved successfully.
C:\windows\system32\DRIVERS\inspect.sys moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\COMODO Internet Security deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\{1606DC18-9578-4cbd-8312-8E9868F06A1D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1606DC18-9578-4cbd-8312-8E9868F06A1D}\ not found.

OTM by OldTimer - Version 3.1.21.0 log created on 04192013_222706

Files moved on Reboot...
File C:\windows\temp\TMP00000001D83F35CB6F6D3900 not found!

Registry entries deleted on Reboot...

Re: Comodo firewall

Napsal: 19 dub 2013 22:13
od Márty84
Nastaveni site je v poradku? (protokol tcp/ip) Nejde wifi, nebo ani kabel?