Stránka 1 z 2

Kontrola logu RogueKiller

Napsal: 04 črc 2013 09:30
od marketa20
Dobrý den, včera nám na PC naběhla obrazovka s nadpisem Policie ČR, požadující 2000 Kč za stahování nelegálního obsahu.
Nejprve jsem stáhla AdwCleaner.exe a potom RogueKiller. Prosím o kontrolu logu a případnou další radu co s tím :)


RogueKiller V8.6.2 [Jul 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : hxxp://www.adlice.com/forum/
Webové stránky : hxxp://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows Vista (6.0.6000 ) 32 bits version
Spuštěno v : Nouzový režim
Uživatel : Market [Práva správce]
Mód : Odebrat -- Datum : 07/04/2013 10:20:53
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : ctfmon.exe (C:\PROGRA~2\rundll32.exe C:\PROGRA~2\vzdif.dat,FG00 [7][-]) -> VYMAZÁNO
[RUN][SUSP PATH] HKUS\S-1-5-21-1026731070-3286125721-3540810417-1000\[...]\Run : ctfmon.exe (C:\PROGRA~2\rundll32.exe C:\PROGRA~2\vzdif.dat,FG00 [7][-]) -> [0x2] Systém nemůže nalézt uvedený soubor.
[HJ POL] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ SECU] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0xc000035f] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

Re: Kontrola logu RogueKiller

Napsal: 04 črc 2013 09:33
od vyosek

Re: Kontrola logu RogueKiller

Napsal: 04 črc 2013 10:39
od marketa20
Tady je FRST log :)


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-07-2013
Ran by Market (administrator) on 04-07-2013 10:45:03
Running from H:\
Microsoft® Windows Vista™ Ultimate (X86) OS Language: Czech
Internet Explorer Version 7
Boot Mode: Safe Mode (minimal)

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Windows\system32\cmd.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1004136 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe [36864 2006-10-30] ()
HKLM\...\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r [180224 2007-02-28] (Creative Technology Ltd)
HKLM\...\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry [x]
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13535776 2008-05-16] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2008-05-16] (NVIDIA Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM\...\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon [644696 2007-05-15] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [1603152 2007-04-04] (CANON INC.)
HKLM\...\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [505368 2007-05-17] (Logitech Inc.)
HKLM\...\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide [780312 2007-05-17] ()
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "D:\Itunes\iTunesHelper.exe" [x]
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [253672 2011-01-07] (Sun Microsystems, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [3080264 2011-09-22] (ESET)
HKLM\...\Run: [SMART Board Service] "D:\SMART Technologies\Education Software\SMARTBoardService.exe" -d [x]
HKLM\...\Run: [SMART Board Tools] "D:\SMART Technologies\Education Software\SMARTBoardTools.exe" [x]
HKLM\...\Run: [SMART Ink] "D:\SMART Technologies\Education Software\SMARTInk.exe" [x]
HKLM\...\Runonce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.894 [x]
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1196032 2006-11-02] (Microsoft Corporation)
HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKCU\...\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s [278528 2006-03-08] (Creative Technology Ltd)
HKCU\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [201728 2006-11-02] (Microsoft Corporation)
HKCU\...\RunOnce: [Report] C:\AdwCleaner[S1].txt [2522 2013-07-04] ()
MountPoints2: {4054ff75-6a20-11dd-9acd-806e6f6e6963} - F:\Run.exe
MountPoints2: {8f8fa8f9-ed02-11e1-8954-001a4d5672bd} - I:\iLinker.exe
MountPoints2: {e2203041-6a21-11dd-93ac-001a4d5672bd} - I:\LaunchU3.exe -a

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={ ... rer:source?}
SearchScopes: HKCU - {6524606B-C677-4600-AE11-7CCF0C09857B} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: SMART Notebook Download Utility - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - D:\SMART Technologies\Education Software\Win32\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Winsock: Catalog5 04 %SystemRoot%\system32\napinsp.dll [50176] (Spoleènost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Market\AppData\Roaming\Mozilla\Firefox\Profiles\jgmkr19k.default
FF SelectedSearchEngine: Seznam
FF Homepage: hxxp://www.google.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\Itunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.2 - D:\VLC\npvlc.dll (VideoLAN)
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

========================== Services (Whitelisted) =================

S2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [974944 2011-09-22] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2012-08-31] (Flexera Software, Inc.)
S2 LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [187168 2007-05-11] (Logitech Inc.)
S2 LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [142112 2007-05-11] (Logitech Inc.)
S2 SMARTHelperService; D:\SMART Technologies\Education Software\SMARTHelperService.exe [580976 2012-03-21] (SMART Technologies)

==================== Drivers (Whitelisted) ====================

S2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [163424 2011-08-09] (ESET)
S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [118104 2011-08-04] (ESET)
S1 epfwtdir; C:\Windows\System32\DRIVERS\epfwtdir.sys [103112 2011-08-04] (ESET)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [183912 2006-11-02] (Spoleènost Microsoft)
S3 gdrv; C:\Windows\gdrv.sys [15600 2008-08-14] (Windows (R) 2000 DDK provider)
R0 JGOGO; C:\Windows\System32\DRIVERS\JGOGO.sys [6912 2006-02-07] (JMicron )
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [44928 2007-02-16] (JMicron Technology Corp.)
S3 LVcKap; C:\Windows\System32\DRIVERS\LVcKap.sys [2107808 2007-05-11] ()
S3 LVMVDrv; C:\Windows\System32\DRIVERS\LVMVDrv.sys [2142752 2007-05-11] (Logitech Inc.)
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25888 2007-05-11] ()
S3 LVUSBSta; C:\Windows\System32\drivers\LVUSBSta.sys [41888 2007-05-12] (Logitech Inc.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-04-16] (Malwarebytes Corporation)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1056360 2006-11-02] (Spoleènost Microsoft)
S3 P17; C:\Windows\System32\drivers\P17.sys [1126400 2007-04-05] (Creative Technology Ltd.)
S3 pepifilter; C:\Windows\System32\DRIVERS\lv302af.sys [14112 2007-05-10] (Logitech Inc.)
S3 PID_PEPI; C:\Windows\System32\DRIVERS\LV302V32.SYS [1276832 2007-05-10] (Logitech Inc.)
R3 SMARTMouseFilterx86; C:\Windows\System32\DRIVERS\SMARTMouseFilterx86.sys [11632 2012-03-21] (SMART Technologies ULC)
R3 SMARTVHidMini2000x86; C:\Windows\System32\DRIVERS\SMARTVHidMini2000x86.sys [14704 2012-03-21] (SMART Technologies ULC)
R3 SMARTVTabletPCx86; C:\Windows\System32\DRIVERS\SMARTVTabletPCx86.sys [21872 2012-03-21] (SMART Technologies ULC)
U3 TrueSight; C:\Windows\system32\TrueSight.sys [15616 2013-07-04] ()
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 CrystalSysInfo; \??\D:\MediaCoder\SysInfo.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

========================== Drivers MD5 =======================

C:\Windows\System32\drivers\acpi.sys 192BDBD1540645C4A2AA69F24CCE197F
C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit

Re: Kontrola logu RogueKiller

Napsal: 04 črc 2013 12:39
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [34672 2008-06-12] (Adobe Systems Incorporated)
    HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
    HKLM\...\Run: [iTunesHelper] "D:\Itunes\iTunesHelper.exe" [x]
    HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [253672 2011-01-07] (Sun Microsystems, Inc.)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06] (Adobe Systems Incorporated)
    HKLM\...\Runonce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstall ... AA5AEYATgA"&"inst=NwA3AC0ANAAxADEANwA0ADYAMQAyADAALQBLAFYAMwArADcALQBCAEEAKwAxAC0AWABMACsAMQAtAFQANQAtAEIAQQBSADkARwArADEALQBUAEIAOQArADIALQBGAEwAKwA5AC0AWABPADMANgArADEALQBGADkATQA3AEMAKwA1AC0AWABPADkAKwAxAC0ARgA5AE0AMwArADEALQBDAEkAUAArADIALQBEAEQAVAArADMAMAAwADIANwAtAEQARAA5ADAARgArADEALQBTAFQAOQAwAEYAQQBQAFAAKwAxAC0ARgA5ADAATQAxADIARABUACsAMQAtAFQAQgBOACsAMQAtAFUAOQA1ACsAMQA"&"prod=90"&"ver=9.0.894 [x]
    HKCU\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [201728 2006-11-02] (Microsoft Corporation)
    HKCU\...\RunOnce: [Report] C:\AdwCleaner[S1].txt [2522 2013-07-04] ()
    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    SearchScopes: HKCU - {6524606B-C677-4600-AE11-7CCF0C09857B} URL = http://search.yahoo.com/search?fr=chr-g ... =867034&p={searchTerms}
    C:\PROGRA~2\vzdif.dat
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny log na flashku k FRST
:arrow: Spustte znovu FRST.exe na tom poskozenem PC
  • Kliknete na Fix
  • Probehne oprava a na flash disku se vytvori log Fixlog.txt
:arrow: Pokuste se nastartovat do bezneho rezimu

Re: Kontrola logu RogueKiller

Napsal: 04 črc 2013 17:08
od marketa20
Posílám fixlog, PC se zdá být v pořádku a naběhl do normálního režimu :)


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-07-2013
Ran by Market at 2013-07-04 18:06:27 Run:1
Running from H:\
Boot Mode: Normal

==============================================

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [34672 2008-06-12 => Value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29 => Value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [253672 2011-01-07 => Value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [500208 2010-03-06 => Value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AvgUninstallURL => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [201728 2006-11-02 => Value not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Report] C:\AdwCleaner[S1].txt [2522 2013-07-04 => Value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6524606B-C677-4600-AE11-7CCF0C09857B} => Key deleted successfully.
HKCR\CLSID\{6524606B-C677-4600-AE11-7CCF0C09857B} => Key not found.
C:\PROGRA~2\vzdif.dat => Moved successfully.

==== End of Fixlog ====

Re: Kontrola logu RogueKiller

Napsal: 05 črc 2013 10:47
od vyosek

Re: Kontrola logu RogueKiller

Napsal: 06 črc 2013 12:16
od marketa20
Tady to je :)


Logfile of random's system information tool 1.09 (written by random/random)
Run by Market at 2013-07-06 13:04:20
Microsoft® Windows Vista™ Ultimate
System drive C: has 55 MB (0%) free of 20 GB
Total RAM: 2046 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:04:30, on 6.7.2013
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16386)
Boot mode: Normal

Running processes:
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\SMART Technologies\Education Software\SMARTBoardService.exe
D:\SMART Technologies\Education Software\SMARTBoardTools.exe
D:\SMART Technologies\Education Software\SMARTInk.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Creative\MediaSource5\MtdAcqu.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
H:\RSIT.exe
C:\Program Files\trend micro\Market.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SMART Notebook Download Utility - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - D:\SMART Technologies\Education Software\Win32\NotebookPlugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SMART Board Service] "D:\SMART Technologies\Education Software\SMARTBoardService.exe" -d
O4 - HKLM\..\Run: [SMART Board Tools] "D:\SMART Technologies\Education Software\SMARTBoardTools.exe"
O4 - HKLM\..\Run: [SMART Ink] "D:\SMART Technologies\Education Software\SMARTInk.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SMART Helper Service (SMARTHelperService) - SMART Technologies - D:\SMART Technologies\Education Software\SMARTHelperService.exe

--
End of file - 7246 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Market\AppData\Roaming\Mozilla\Firefox\Profiles\jgmkr19k.default

prefs.js - "browser.startup.homepage" - "http://www.google.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.224 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=D:\Itunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.2]
"Description"=VLC Multimedia Plugin
"Path"=D:\VLC\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}

C:\Program Files\Mozilla Firefox\components\
nsILegitCheckPlugin.xpt
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npLegitCheckPlugin.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67BCF957-85FC-4036-8DC4-D4D80E00A77B}]
SMART Notebook Download Utility - D:\SMART Technologies\Education Software\Win32\NotebookPlugin.dll [2012-03-28 237424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2011-06-04 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-06-04 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-02 1004136]
"JMB36X IDE Setup"=C:\Windows\JM\JMInsIDE.exe [2006-10-30 36864]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [2007-02-28 180224]
"P17RunE"=RunDll32 P17RunE.dll,RunDLLEntry []
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-05-16 13535776]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-05-16 92704]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-15 644696]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-04-04 1603152]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-05-17 505368]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam10\QuickCam10.exe [2007-05-17 780312]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-01-07 253672]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-22 3080264]
"SMART Board Service"=D:\SMART Technologies\Education Software\SMARTBoardService.exe [2012-03-21 2186096]
"SMART Board Tools"=D:\SMART Technologies\Education Software\SMARTBoardTools.exe [2012-03-09 10132336]
"SMART Ink"=D:\SMART Technologies\Education Software\SMARTInk.exe [2012-03-21 94064]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2006-11-02 1196032]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2006-11-02 125440]
"MtdAcqu"=C:\Program Files\Creative\MediaSource5\MtdAcqu.exe [2006-03-08 278528]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideSCAHealth"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.I420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.iv50"=ir50_32.dll
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.tscc"=tsccvid.dll

======List of files/folders created in the last 1 month======

2013-07-06 13:04:21 ----D---- C:\Program Files\trend micro
2013-07-06 13:04:20 ----D---- C:\rsit
2013-07-04 10:44:31 ----D---- C:\FRST
2013-07-04 10:19:35 ----A---- C:\Windows\system32\TrueSight.sys
2013-07-04 10:10:07 ----A---- C:\AdwCleaner[S1].txt
2013-07-03 18:06:21 ----A---- C:\ProgramData\fidzv.js
2013-07-03 17:59:43 ----A---- C:\ProgramData\as98213.txt
2013-07-03 17:59:19 ----A---- C:\ProgramData\rundll32.exe

======List of files/folders modified in the last 1 month======

2013-07-06 13:04:31 ----D---- C:\Windows\Prefetch
2013-07-06 13:04:21 ----RD---- C:\Program Files
2013-07-06 13:04:16 ----D---- C:\Windows\Temp
2013-07-04 18:09:43 ----D---- C:\Windows\System32
2013-07-04 18:09:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-07-04 18:06:28 ----HD---- C:\ProgramData
2013-07-04 10:44:33 ----D---- C:\Windows
2013-07-04 10:44:18 ----A---- C:\Windows\ntbtlog.txt
2013-07-04 10:20:43 ----D---- C:\Windows\system32\drivers
2013-07-04 10:07:24 ----D---- C:\Program Files\Mozilla Firefox
2013-06-28 20:37:01 ----D---- C:\Windows\system32\catroot2
2013-06-26 19:10:17 ----D---- C:\Program Files\uTorrent
2013-06-26 16:59:43 ----D---- C:\Users\Market\AppData\Roaming\uTorrent
2013-06-26 15:52:55 ----D---- C:\Users\Market\AppData\Roaming\vlc
2013-06-12 22:09:11 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-06-08 09:24:10 ----D---- C:\Windows\Minidump

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2006-11-02 121960]
R0 JGOGO;JMicron Hot-Plug Driver; C:\Windows\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2007-02-16 44928]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdir;epfwtdir; C:\Windows\system32\DRIVERS\epfwtdir.sys [2011-08-04 103112]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2007-05-11 25888]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-05-16 7465312]
R3 P17;SB Live! 24-bit; C:\Windows\system32\drivers\P17.sys [2007-04-05 1126400]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 SMARTMouseFilterx86;HID-compliant mouse; C:\Windows\system32\DRIVERS\SMARTMouseFilterx86.sys [2012-03-21 11632]
R3 SMARTVHidMini2000x86;SMART HID Device; C:\Windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [2012-03-21 14704]
R3 SMARTVTabletPCx86;SMART Virtual TabletPC; C:\Windows\system32\DRIVERS\SMARTVTabletPCx86.sys [2012-03-21 21872]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 CrystalSysInfo;CrystalSysInfo; \??\D:\MediaCoder\SysInfo.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2008-08-14 15600]
S3 LVcKap;Logitech AEC Driver; C:\Windows\system32\DRIVERS\LVcKap.sys [2007-05-11 2107808]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\Windows\system32\DRIVERS\LVMVDrv.sys [2007-05-11 2142752]
S3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-05-12 41888]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2012-04-16 40776]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2007-05-10 14112]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2007-05-10 1276832]
S3 TrueSight;TrueSight; \??\C:\Windows\system32\TrueSight.sys [2013-07-04 15616]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-12-14 41984]
S3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2006-11-02 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-09-22 974944]
R2 LVCOMSer;LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2007-05-11 187168]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-05-11 133920]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-05-16 118784]
R2 SMARTHelperService;SMART Helper Service; D:\SMART Technologies\Education Software\SMARTHelperService.exe [2012-03-21 580976]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-05-11 142112]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12 256904]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-08-31 1044816]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 820008]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-24 117144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: Kontrola logu RogueKiller

Napsal: 07 črc 2013 07:09
od vyosek
:arrow: Poprosim i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit

:arrow: Predpokladam, ze ten ESET jak ma byt = zakoupena licence :???:

Re: Kontrola logu RogueKiller

Napsal: 09 črc 2013 10:13
od marketa20
Eset máme stáhnutý nelegálně :(


info.txt logfile of random's system information tool 1.09 2013-07-06 13:04:32

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative\Sound Blaster X-Fi\Program\SETUP.EXE" /S /U /W
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7AB55EC6-1158-41EF-B87D-90555A8F5C92}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7AB55EC6-1158-41EF-B87D-90555A8F5C92}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAEF329E-F353-46C9-933D-24A571986093}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAEF329E-F353-46C9-933D-24A571986093}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C88C3C27-AECE-4137-A6CC-D7A6FFAD2F84}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C88C3C27-AECE-4137-A6CC-D7A6FFAD2F84}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3C64B-2A22-48C5-857B-E952D7BE64F5}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3C64B-2A22-48C5-857B-E952D7BE64F5}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x9 /remove
µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 11 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe -maintain activex
Adobe Flash Player 11 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_Plugin.exe -maintain plugin
Adobe Photoshop CS5-->C:\Program Files\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
ALZip-->D:\ALZip\unins000.exe
Any Video Converter 3.3.5-->"D:\Any Video Converter\unins000.exe"
Apple Application Support-->MsiExec.exe /I{EE6097DD-05F4-4178-9719-D3170BF098E8}
Apple Mobile Device Support-->MsiExec.exe /I{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Canon MP Navigator EX 1.0-->"C:\Program Files\Canon\MP Navigator EX 1.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX 1.0\uninst.ini
Canon MX310 series-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX310_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX310_series /L0x0009
Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
Canon Utilities Solution Menu-->C:\Program Files\Canon\SolutionMenu\uninst.exe uninst.ini
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Convert AVI to MP4-->"D:\Convert AVI to MP4\unins000.exe"
CoreAAC-->"C:\Program Files\CoreAAC\Uninstall.exe"
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x9 /remove
Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x9 /remove
Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
IPP Run-Time 5.3-->"C:\Program Files\IPP Runtime 5.3\Uninstall.exe"
iTunes-->MsiExec.exe /I{AAD47011-8518-4608-9656-951DA35B587B}
Java(TM) 6 Update 25-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216025FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
K-Lite Codec Pack 4.1.4 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Logitech QuickCam-->MsiExec.exe /X{EFA2BBEB-CF93-493B-904B-1B970B8DFAB6}
Logitech® Camera Driver-->"C:\Program Files\Common Files\LogiShrd\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
Malwarebytes Anti-Malware verze 1.61.0.1400-->"D:\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Mozilla Firefox 21.0 (x86 cs)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Maintenance Service-->"C:\Program Files\Mozilla Maintenance Service\uninstall.exe"
MP3 Rocket-->C:\Program Files\MP3 Rocket\Uninstall.exe
MPEG2 Codec(libmpeg2/mad)-->"C:\Program Files\GNU\MPEG2\Uninstall.exe"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
QuickTime-->MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4E02C}
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\SETUP.EXE -runfromtemp -l0x0005 -removeonly
SMART Common Files-->MsiExec.exe /X{ED2455F7-6AA6-4D3C-85E9-A72297DD7051}
SMART Czech Language Pack-->MsiExec.exe /X{D4D68022-BE82-4C7B-87D5-2460A9BDB001}
SMART Ink-->MsiExec.exe /X{4A1F2472-6164-43FA-9D2F-B35E71A8DF32}
SMART Notebook-->MsiExec.exe /X{AFE024C7-7CA7-4C8E-90EE-D877C7CD96A3}
SMART Product Drivers-->MsiExec.exe /X{E3189F44-F7BD-4F96-B756-A0AEFAF61D3A}
Sound Blaster X-Fi Xtreme Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{53E2DCBB-E6F7-4C83-B1EF-F78435B9814E}\SETUP.EXE" -l0x9 /remove
TS Diktáty (doporučená instalace)-->D:\HANKA\Uninstal.exe
VLC media player 2.0.2-->D:\VLC\uninstall.exe
Windows Media Encoder 9 Series-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Zoner Photo Studio 13-->"C:\Program Files\Zoner\Photo Studio 13\unins000.exe" /SILENT /SILENT

======Security center information======

AV: ESET NOD32 Antivirus 5.0 (outdated)
AS: ESET NOD32 Antivirus 5.0 (outdated)
AS: Windows Defender (outdated)

======System event log======

Computer Name: Market-PC
Event Code: 7036
Message: Stav služby Telefonní subsystém byl změněn na: Spuštěno
Record Number: 582774
Source Name: Service Control Manager
Time Written: 20130706110358.000000-000
Event Type: Informace
User:

Computer Name: Market-PC
Event Code: 7036
Message: Stav služby Správce vzdáleného přístupu byl změněn na: Spuštěno
Record Number: 582775
Source Name: Service Control Manager
Time Written: 20130706110358.000000-000
Event Type: Informace
User:

Computer Name: Market-PC
Event Code: 7036
Message: Stav služby Služba Windows Media Player Network Sharing byl změněn na: Spuštěno
Record Number: 582776
Source Name: Service Control Manager
Time Written: 20130706110358.000000-000
Event Type: Informace
User:

Computer Name: Market-PC
Event Code: 7036
Message: Stav služby Windows Presentation Foundation Font Cache 4.0.0.0 byl změněn na: Spuštěno
Record Number: 582777
Source Name: Service Control Manager
Time Written: 20130706110400.000000-000
Event Type: Informace
User:

Computer Name: Market-PC
Event Code: 7036
Message: Stav služby Podpora ovládacího panelu Hlášení a řešení problémů byl změněn na: Zastaveno
Record Number: 582778
Source Name: Service Control Manager
Time Written: 20130706110412.000000-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: Market-PC
Event Code: 1003
Message: Vyhledávací služba systému Windows byla spuštěna.

Record Number: 180981
Source Name: Microsoft-Windows-Search
Time Written: 20130706110345.000000-000
Event Type: Informace
User:

Computer Name: Market-PC
Event Code: 1
Message: Klient Certifikační služby byl úspěšně spuštěn.
Record Number: 180982
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20130706110346.659116-000
Event Type: Informace
User: Market-PC\Market

Computer Name: Market-PC
Event Code: 1
Message: Klient Certifikační služby byl úspěšně spuštěn.
Record Number: 180983
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20130706110346.861916-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: Market-PC
Event Code: 1
Message: U aplikace (Sun Java Scheduler od dodavatele Sun Microsystems, Inc.) došlo k následujícím potížím: Aplikace Sun Java Scheduler není kompatibilní s touto verzí systému Windows. Další informace získáte od společnosti Sun Microsystems, Inc..
Record Number: 180984
Source Name: Microsoft-Windows-ApplicationExperienceInfrastructure
Time Written: 20130706110347.895116-000
Event Type: Upozornění
User: Market-PC\Market

Computer Name: Market-PC
Event Code: 11
Message: Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou aktualizaci v <http://www.download.windowsupdate.com/m ... ootstl.cab> se nezdařila. Došlo k chybě Při ověření se systémovými hodinami nebo časovým razítkem podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.
.
Record Number: 180985
Source Name: Microsoft-Windows-CAPI2
Time Written: 20130706110401.000000-000
Event Type: Chyba
User:

=====Security event log=====

Computer Name: Market-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: MARKET-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x230
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 217918
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130202102121.608517-000
Event Type: Úspěch auditu
User:

Computer Name: Market-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 217919
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130202102121.608517-000
Event Type: Úspěch auditu
User:

Computer Name: Market-PC
Event Code: 1101
Message: Při přenosu byly vyřazeny události auditu. Soubor zálohy v reálném čase byl poškozen v důsledku nesprávného vypnutí.
Record Number: 217920
Source Name: Microsoft-Windows-Eventlog
Time Written: 20130202122800.553507-000
Event Type: Úspěch auditu
User:

Computer Name: Market-PC
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 217921
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130202122756.852092-000
Event Type: Úspěch auditu
User:

Computer Name: Market-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 217922
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130202122756.852092-000
Event Type: Úspěch auditu
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;D:\ALZip\;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"asl.log"=Destination=file

-----------------EOF---------------

Re: Kontrola logu RogueKiller

Napsal: 09 črc 2013 12:31
od vyosek
:arrow: Pred pokracovanim, vas musim pozadat o odstraneni NELEGALNIHO ESETu. Tento muj "pozadavek" vychazi z platnych pravidel fora http://forum.viry.cz/viewtopic.php?f=12&t=115512, ktere jste vy i ja povinnen dodrzovat
Pomáhat NELZE:
2) Pokud stroj uživatele prokazatelně obsahuje nelegální hostitelský čí ochranný software
(operační systém, antivir, firewall, atd.), je nutné navést uživatele k nápravě, např. skrze neplacený software,
a začít řešit, až v době kdy je PC "v pořádku". V případě že uživatel nechce na pravidla přistoupit,
je nutné jej vyzvat ať fórum opustí, a vrátí se až je splní.
:arrow: Takze pokud chcete pomoci, tak jej odinstalujte, nainstalujte free reseni (napr. Avast), napiste a budeme pokracovat

Re: Kontrola logu RogueKiller

Napsal: 18 črc 2013 18:13
od marketa20
Dobrý den, dle vašeho požadavku jsem nainstalovala free verzi avastu, ale na poškozeném PC mi přestal fungovat internet :(

Re: Kontrola logu RogueKiller

Napsal: 18 črc 2013 18:48
od vyosek
:arrow: Zkuste WinSockFix http://www.spyware.cz/go.php?p=spyware&t=aplikace&id=22
Pokud mate parametry pripojeni rucne, pak je nastavte
Eithne píše: Klepněte na Start -> Ovládací Panely -> Sítová připojení -> Připojení k místní síti a pravým tlačítkem na Vlastnosti. Vyhledejte položku Protokol sítě Internet (TCP/IP) a poklepejte na ni. Tady musíte po zaškrtnutí políček Použít následující adresu IP a Použít následující adresy serverů DNS vyplnit dva údaje, a to, IP adresu a adresu DNS serveru.
:arrow: Spustte MiniTool dle kolegy
stell píše:daj spustit tento program
http://www.bleepingcomputer.com/downloa ... box/dl/65/

Spustit>.zafajknut.
1:Report IEPROXY
2:Report FFPROXY
3:List comtent OFF HOSTS
4:List IP CONFIGURATION
5:LIST WINSOCK...
6:List Last 10 EvENTS..
7:Only problems
8:Klik GO a log nech ti da do fora.

Re: Kontrola logu RogueKiller

Napsal: 23 črc 2013 10:11
od marketa20
Hezké dopoledne :)
Tady je log z Minitoolbox, program Winsockfix mi na postiženém PC nejede, možná proto, že je na něm nainstalovaná Vista.

MiniToolBox by Farbar Version: 13-07-2013
Ran by Market (administrator) on 23-07-2013 at 11:03:20
Running from "H:\"
Microsoft® Windows Vista™ Ultimate (X86)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

========================= Hosts content: =================================

::1 localhost

127.0.0.1 localhost

========================= IP Configuration: ================================

Realtek RTL8168/8111 Family PCI-E Gigabit Ethernet NIC (NDIS 6.0) = Pøipojení k místní síti (Connected)


# ----------------------------------
# Konfigurace protokolu IPv4
# ----------------------------------
pushd interface ipv4

reset
set interface luid=loopback_0 forwarding=disabled advertise=disabled mtu=0 metric=0 metric=0 nud=disabled basereachabletime=0 retransmittime=0 routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled
set interface luid=ethernet_2 forwarding=disabled advertise=disabled mtu=0 metric=0 metric=0 nud=disabled basereachabletime=0 retransmittime=0 routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled
set interface luid=ethernet_1 forwarding=disabled advertise=disabled mtu=0 metric=0 metric=0 nud=disabled basereachabletime=0 retransmittime=0 routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled
set interface luid=ethernet_4 forwarding=disabled advertise=disabled mtu=0 metric=0 metric=0 nud=disabled basereachabletime=0 retransmittime=0 routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled


popd
# Konec konfigurace protokolu IPv4



Konfigurace protokolu IP syst‚mu Windows

N zev hostitele . . . . . . . . . : Market-PC
Prim rn¡ pý¡pona DNS. . . . . . . :
Typ uzlu . . . . . . . . . . . . : hybridn¡
Povoleno smØrov n¡ IP . . . . . . : Ne
WINS Proxy povoleno . . . . . . . : Ne

Adapt‚r s¡tØ Ethernet Pýipojen¡ k m¡stn¡ s¡ti:

Pý¡pona DNS podle pýipojen¡ . . . :
Popis . . . . . . . . . . . . . . : Realtek RTL8168/8111 Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
Fyzick  Adresa. . . . . . . . . . : 00-1A-4D-56-72-BD
Protokol DHCP povolen . . . . . . : Ano
Automatick  konfigurace povolena : Ano
Spojen¡ - m¡stn¡ adresa IPv6 . . . : fe80::8dd6:f9b:824e:81a9%8(Preferovan‚)
Adresa IPv4 . . . . . . . . . . . : 192.168.0.100(Preferovan‚)
Maska pods¡tØ . . . . . . . . . . : 255.255.255.0
Zap…jŸeno . . . . . . . . . . . . : 23. Ÿervence 2013 10:59:22
Z p…jŸka vyprç¡ . . . . . . . . . : 23. Ÿervence 2013 13:59:22
Vìchoz¡ br na . . . . . . . . . . : 192.168.0.1
Server DHCP . . . . . . . . . . . : 192.168.0.1
IAID DHCPv6 . . . . . . . . . . . : 201333325
Servery DNS . . . . . . . . . . . : 192.168.0.1
Rozhran¡ NetBios nad protokolem TCP/IP. . . . . . . . : Povoleno

Adapt‚r pro tunelov‚ pýipojen¡ Pýipojen¡ k m¡stn¡ s¡ti*:

Pý¡pona DNS podle pýipojen¡ . . . :
Popis . . . . . . . . . . . . . . : isatap.{57CD6DC5-F1C8-4D45-B907-EF723964F7A9}
Fyzick  Adresa. . . . . . . . . . : 00-00-00-00-00-00-00-E0
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano
Spojen¡ - m¡stn¡ adresa IPv6 . . . : fe80::5efe:192.168.0.100%10(Preferovan‚)
Vìchoz¡ br na . . . . . . . . . . :
Servery DNS . . . . . . . . . . . : 192.168.0.1
NetBIOS nad TCP/IP. . . . . . . . : zak z no

Adapt‚r pro tunelov‚ pýipojen¡ Pýipojen¡ k m¡stn¡ s¡ti* 6:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pý¡pona DNS podle pýipojen¡ . . . :
Popis . . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Fyzick  Adresa. . . . . . . . . . : 02-00-54-55-4E-01
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano
Server: UnKnown
Address: 192.168.0.1:53

N zev: google.com
Addresses: 173.194.70.139, 173.194.70.100, 173.194.70.101, 173.194.70.102
173.194.70.113, 173.194.70.138



Pý¡kaz PING na google.com [173.194.70.102] - 32 bajt… dat:



OdpovØÔ od 173.194.70.102: bajty=32 Ÿas=18ms TTL=48

OdpovØÔ od 173.194.70.102: bajty=32 Ÿas=18ms TTL=48



Statistika ping pro 173.194.70.102:

Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),

Pýibli§n  doba do pýijet¡ odezvy v milisekund ch:

Minimum = 18ms, Maximum = 18ms, Pr…mØr = 18ms

Server: UnKnown
Address: 192.168.0.1:53

N zev: yahoo.com
Addresses: 98.139.183.24, 206.190.36.45, 98.138.253.109



Pý¡kaz PING na yahoo.com [206.190.36.45] - 32 bajt… dat:



OdpovØÔ od 206.190.36.45: bajty=32 Ÿas=223ms TTL=45

OdpovØÔ od 206.190.36.45: bajty=32 Ÿas=204ms TTL=45



Statistika ping pro 206.190.36.45:

Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),

Pýibli§n  doba do pýijet¡ odezvy v milisekund ch:

Minimum = 204ms, Maximum = 223ms, Pr…mØr = 213ms



Pý¡kaz PING na 127.0.0.1 - 32 bajt… dat:



OdpovØÔ od 127.0.0.1: bajty=32 Ÿas < 1ms TTL=128

OdpovØÔ od 127.0.0.1: bajty=32 Ÿas < 1ms TTL=128



Statistika ping pro 127.0.0.1:

Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),

Pýibli§n  doba do pýijet¡ odezvy v milisekund ch:

Minimum = 0ms, Maximum = 0ms, Pr…mØr = 0ms

===========================================================================
Seznam rozhran¡
8 ...00 1a 4d 56 72 bd ...... Realtek RTL8168/8111 Family PCI-E Gigabit Ethernet NIC (NDIS 6.0)
1 ........................... Software Loopback Interface 1
10 ...00 00 00 00 00 00 00 e0 isatap.{57CD6DC5-F1C8-4D45-B907-EF723964F7A9}
9 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 SmØrovac¡ tabulka
===========================================================================
Aktivn¡ smØrov n¡:
C¡l v s¡ti S¡œov  maska Br na Rozhran¡ Metrika
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.100 20
127.0.0.0 255.0.0.0 Propojen‚ 127.0.0.1 306
127.0.0.1 255.255.255.255 Propojen‚ 127.0.0.1 306
127.255.255.255 255.255.255.255 Propojen‚ 127.0.0.1 306
192.168.0.0 255.255.255.0 Propojen‚ 192.168.0.100 276
192.168.0.100 255.255.255.255 Propojen‚ 192.168.0.100 276
192.168.0.255 255.255.255.255 Propojen‚ 192.168.0.100 276
224.0.0.0 240.0.0.0 Propojen‚ 127.0.0.1 306
224.0.0.0 240.0.0.0 Propojen‚ 192.168.0.100 276
255.255.255.255 255.255.255.255 Propojen‚ 127.0.0.1 306
255.255.255.255 255.255.255.255 Propojen‚ 192.168.0.100 276
===========================================================================
Trval‚ trasy:
¦ dn‚

IPv6 SmØrovac¡ tabulka
===========================================================================
Aktivn¡ smØrov n¡:
Rozhran¡ Metrika C¡l v s¡ti Br na
1 306 ::1/128 Propojen‚
8 276 fe80::/64 Propojen‚
10 281 fe80::5efe:192.168.0.100/128
Propojen‚
8 276 fe80::8dd6:f9b:824e:81a9/128
Propojen‚
1 306 ff00::/8 Propojen‚
8 276 ff00::/8 Propojen‚
===========================================================================
Trval‚ trasy:
¦ dn‚
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation)
Catalog5 02 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog5 03 C:\Windows\system32\winrnr.dll [19968] (Microsoft Corporation)
Catalog5 04 C:\Windows\system32\napinsp.dll [50176] (Spoleènost Microsoft)
Catalog5 05 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 06 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [227328] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (07/23/2013 10:59:57 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download.windowsupdate.com/m ... stl.cabPøi ovìøení se systémovými hodinami nebo èasovým razítkem podepsaného souboru bylo zjištìno, že požadovaný certifikát je mimo lhùtu platnosti.

Error: (07/23/2013 10:54:31 AM) (Source: LoadPerf) (User: )
Description: WMI Objects16

Error: (07/23/2013 10:53:05 AM) (Source: LoadPerf) (User: )
Description: WMI Objects16

Error: (07/23/2013 10:50:38 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download.windowsupdate.com/m ... stl.cabPøi ovìøení se systémovými hodinami nebo èasovým razítkem podepsaného souboru bylo zjištìno, že požadovaný certifikát je mimo lhùtu platnosti.

Error: (07/15/2013 07:35:17 PM) (Source: LoadPerf) (User: )
Description: WMI Objects16

Error: (07/15/2013 07:32:47 PM) (Source: MsiInstaller) (User: Market-PC)
Description: Produkt: ESET NOD32 Antivirus -- Chyba 1730. K odebrání této aplikace musíte mít oprávnìní uživatele Administrator. Chcete-li tuto aplikaci odebrat, pøihlaste se jako Administrator nebo se pro pomoc obrate na pracovníky odborné pomoci.

Error: (07/15/2013 07:30:52 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: http://www.download.windowsupdate.com/m ... stl.cabPøi ovìøení se systémovými hodinami nebo èasovým razítkem podepsaného souboru bylo zjištìno, že požadovaný certifikát je mimo lhùtu platnosti.

Error: (07/15/2013 07:16:32 PM) (Source: MsiInstaller) (User: Market-PC)
Description: Produkt: ESET NOD32 Antivirus -- Chyba 1730. K odebrání této aplikace musíte mít oprávnìní uživatele Administrator. Chcete-li tuto aplikaci odebrat, pøihlaste se jako Administrator nebo se pro pomoc obrate na pracovníky odborné pomoci.

Error: (07/15/2013 07:11:09 PM) (Source: Application Error) (User: )
Description: Chybující aplikace SoftwareUpdate.exe, verze 2.1.1.116, èasové razítko 0x488a4f1f, chybující modul SoftwareUpdateFiles.dll, verze 6.0.6000.16386, èasové razítko 0x4549bdc9, kód výjimky 0xc0000135, posun chyby 0x00008fc7,
ID procesu 0x1138, èas spuštìní aplikace 0xSoftwareUpdate.exe0.

Error: (07/15/2013 07:05:35 PM) (Source: LoadPerf) (User: )
Description: WMI Objects16


System errors:
=============
Error: (07/23/2013 11:00:26 AM) (Source: Service Control Manager) (User: )
Description: i8042prt
luafv

Error: (07/23/2013 10:59:29 AM) (Source: Print) (User: NT AUTHORITY)
Description: Systému Windows se nezdaøila inicializace tiskárny StarBoard Document Capture, protože tiskový procesor StarBoard Printer Processor nebyl nalezen. Vyžádejte si od výrobce novou verzi ovladaèe (pokud je k dispozici) a nainstalujte ji nebo vyberte alternativní ovladaè, který bude s touto tiskárnou pracovat.

Error: (07/23/2013 10:59:25 AM) (Source: netbt) (User: )
Description: Název MARKET-PC :20 nelze zaregistrovat v rozhraní s adresou IP 192.168.0.100. Poèítaè s adresou IP 192.168.0.101
nepovolil získání názvu tímto poèítaèem.

Error: (07/23/2013 10:59:25 AM) (Source: netbt) (User: )
Description: Název MARKET-PC :0 nelze zaregistrovat v rozhraní s adresou IP 192.168.0.100. Poèítaè s adresou IP 192.168.0.101
nepovolil získání názvu tímto poèítaèem.

Error: (07/23/2013 10:59:25 AM) (Source: Server) (User: )
Description: Server nemohl vytvoøit vazbu na pøenos \Device\NetBT_Tcpip_{57CD6DC5-F1C8-4D45-B907-EF723964F7A9}, protože jiný poèítaè v síti má stejný název. Server nelze spustit.

Error: (07/23/2013 10:51:14 AM) (Source: Service Control Manager) (User: )
Description: i8042prt
luafv

Error: (07/23/2013 10:50:56 AM) (Source: volsnap) (User: )
Description: Stínové kopie svazku C: byly pøerušeny, protože z dùvodu limitu stanoveného uživatelem se nepodaøilo zvìtšit úložištì stínové kopie.

Error: (07/23/2013 10:49:53 AM) (Source: Print) (User: NT AUTHORITY)
Description: Systému Windows se nezdaøila inicializace tiskárny StarBoard Document Capture, protože tiskový procesor StarBoard Printer Processor nebyl nalezen. Vyžádejte si od výrobce novou verzi ovladaèe (pokud je k dispozici) a nainstalujte ji nebo vyberte alternativní ovladaè, který bude s touto tiskárnou pracovat.

Error: (07/23/2013 10:49:49 AM) (Source: netbt) (User: )
Description: Název MARKET-PC :20 nelze zaregistrovat v rozhraní s adresou IP 192.168.0.100. Poèítaè s adresou IP 192.168.0.101
nepovolil získání názvu tímto poèítaèem.

Error: (07/23/2013 10:49:49 AM) (Source: netbt) (User: )
Description: Název MARKET-PC :0 nelze zaregistrovat v rozhraní s adresou IP 192.168.0.100. Poèítaè s adresou IP 192.168.0.101
nepovolil získání názvu tímto poèítaèem.


Microsoft Office Sessions:
=========================
Error: (01/22/2012 10:47:59 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 17 seconds with 0 seconds of active time. This session ended with a crash.

Error: (01/11/2011 03:19:35 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 27 seconds with 0 seconds of active time. This session ended with a crash.

Error: (03/09/2010 03:37:25 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash.

Error: (12/19/2009 10:10:10 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 102 seconds with 60 seconds of active time. This session ended with a crash.

Error: (11/23/2009 06:22:45 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6241 seconds with 3360 seconds of active time. This session ended with a crash.

Error: (05/08/2009 10:01:05 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 12 seconds with 0 seconds of active time. This session ended with a crash.

Error: (04/20/2009 08:28:52 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2674 seconds with 2460 seconds of active time. This session ended with a crash.

Error: (10/09/2008 06:26:48 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9 seconds with 0 seconds of active time. This session ended with a crash.


CodeIntegrity Errors:
===================================
Date: 2009-10-05 13:08:14.109
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.105
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.101
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.097
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.093
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.088
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.084
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.080
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.076
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.

Date: 2009-10-05 13:08:14.033
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Hitachi Software Engineering\StarBoard Software\FEPHook.dll because the set of per-page image hashes could not be found on the system.


**** End of log ****

Re: Kontrola logu RogueKiller

Napsal: 23 črc 2013 19:27
od vyosek
Internet nam stale nefunguje?

Re: Kontrola logu RogueKiller

Napsal: 28 črc 2013 10:20
od marketa20
Právě, že nefunguje :(