Kontola Logu
Napsal: 06 bře 2014 09:32
Poprosím Vás o kontrolu Logu z programu HiJack:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:13:44, on 6. 3. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Eset\ESET Endpoint Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe
C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Opera\opera.exe
C:\Windows\explorer.exe
C:\Program Files\HiJack This\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {32b29df0-2237-4370-9a29-37cebb730e9b} - (no file)
R3 - URLSearchHook: (no name) - {88ac3cb6-596b-4217-964c-b6757ef9602d} - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Users\Georgo\AppData\Roaming\Microsoft\microsoftwindowsupdate.exe
O2 - BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (file missing)
O2 - BHO: Slick Savings - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Georgo\AppData\Roaming\Slick Savings\Coupons.dll
O2 - BHO: FaceCons - {B2A44031-7EAD-434C-AC9E-7F1DA176BA8C} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MicrosoftWindowsUpdate] C:\Users\Georgo\AppData\Roaming\Microsoft\microsoftwindowsupdate.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Slick Savings] "C:\Users\Georgo\AppData\Roaming\Slick Savings\CouponsHelper.exe"
O4 - HKCU\..\Run: [zhuhghdt] regsvr32.exe "C:\ProgramData\zhuhghdt.dat"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
O8 - Extra context menu item: Free YouTube Download - C:\Users\Georgo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {5672DADB-EFBC-4927-B991-55678B70D679} (WebCamX Control) - http://213.160.160.82/WebCamX.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{294FC601-668D-4AC5-9367-F3E01C315FD8}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2DD43EE-464B-4D08-8B63-0EA9C6B0B2B4}: NameServer = 195.146.132.58,195.146.128.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{294FC601-668D-4AC5-9367-F3E01C315FD8}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{294FC601-668D-4AC5-9367-F3E01C315FD8}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O22 - SharedTaskScheduler: ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files\Stardock\ObjectDockFree\ODMenu.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\ekrn.exe
O23 - Service: ESET SHA Service (ESHASRV) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
--
End of file - 7868 bytes
A kontrolu logu z programu Gmer:
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-03-05 11:42:50
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK2035GSS rev.DK020M 186,31GB
Running: 77g9m6de.exe; Driver: C:\Users\Georgo\AppData\Local\Temp\kwliapob.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwCreateThread [0x8A7767F0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwLoadDriver [0x8A7768B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSystemInformation [0x8A776870]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSystemDebugControl [0x8A776830]
---- Kernel code sections - GMER 2.1 ----
.text ntoskrnl.exe!ZwRollbackEnlistment + 1409 838789A5 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 83898512 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 14CB 8389FAC0 4 Bytes [F0, 67, 77, 8A] {JA 0xffffff8e}
.text ntoskrnl.exe!KeRemoveQueueEx + 15DB 8389FBD0 4 Bytes [B0, 68, 77, 8A] {MOV AL, 0x68; JA 0xffffff8e}
.text ntoskrnl.exe!KeRemoveQueueEx + 18E7 8389FEDC 4 Bytes [70, 68, 77, 8A] {JO 0x6a; JA 0xffffff8e}
.text ntoskrnl.exe!KeRemoveQueueEx + 192F 8389FF24 4 Bytes [30, 68, 77, 8A]
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x92021340, 0x3EE217, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\ESET\ESET Endpoint Antivirus\ekrn.exe[1924] kernel32.dll!SetUnhandledExceptionFilter 75C4F4EB 4 Bytes [C2, 04, 00, 00]
.text C:\Windows\System32\rundll32.exe[3360] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 00698138
.text C:\Windows\System32\rundll32.exe[3360] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 00698191
.text C:\Windows\System32\rundll32.exe[3360] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 006981EA
.text C:\Windows\System32\rundll32.exe[3360] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Windows\System32\rundll32.exe[3360] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 00698246
.text C:\Windows\Explorer.EXE[3384] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 05258138
.text C:\Windows\Explorer.EXE[3384] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 05258191
.text C:\Windows\Explorer.EXE[3384] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 052581EA
.text C:\Windows\Explorer.EXE[3384] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Windows\Explorer.EXE[3384] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 05258246
.text C:\Windows\System32\rundll32.exe[3624] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 00758138
.text C:\Windows\System32\rundll32.exe[3624] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 00758191
.text C:\Windows\System32\rundll32.exe[3624] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 007581EA
.text C:\Windows\System32\rundll32.exe[3624] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Windows\System32\rundll32.exe[3624] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 00758246
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 017C8138
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 017C8191
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 017C81EA
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 017C8246
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 02BD8138
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 02BD8191
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 02BD81EA
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 02BD8246
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 01308138
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 01308191
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 013081EA
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 01308246
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 01B78138
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 01B78191
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 01B781EA
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 01B78246
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 08028138
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 08028191
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 080281EA
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 08028246
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 04C38138
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 04C38191
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 04C381EA
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 04C38246
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 01308138
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 01308191
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 013081EA
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 01308246
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 08CB8138
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 08CB8191
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] kernel32.dll!SetUnhandledExceptionFilter 75C4F4EB 5 Bytes JMP 5AC25629 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 08CB81EA
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 08CB8246
.text C:\Program Files\Opera\opera.exe[8132] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 00588138
.text C:\Program Files\Opera\opera.exe[8132] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 00588191
.text C:\Program Files\Opera\opera.exe[8132] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 005881EA
.text C:\Program Files\Opera\opera.exe[8132] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Opera\opera.exe[8132] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 00588246
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73EA24CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73E8562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73E856EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73EA2546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73E985AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73E94D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73E95105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73E951DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73E96707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73E98301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73E98850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73E990B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73E9E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73E94C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
---- Devices - GMER 2.1 ----
Device Ntfs.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Intel(R) PRO/Wireless 3945ABG \x2013 síťové připojení 1?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00037ad7c67b
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Intel(R) PRO/Wireless 3945ABG \x2013 síťové připojení 1?
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00037ad7c67b (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Dveře\Door Hasp Catching.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Gag\Bone Crush.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Temné burácení\Alligator Hiss.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Různé\Bike Sliding in Sand.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Hrající si děti\Bat Crack .wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Vesmírná loď\Electronic Motor2.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Cestování\Camera Shutter.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Zimní radovánky\Baby Cough2.wav 1
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0xAA 0x52 0xC6 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@L:\Zaloha 16.4.2008-Externeho HDD\NET\Convertory\I\xb4M To AVI\ImTOO AVI MPEG Converter 2_1_16_1213b (MPEG,VOB,AVI,DV,MOV,animated GIF,swf,MPEG4,RM,WMV,ASF,WAV,WMA,MP3,3GP,m4a,mp4,h264,MP2,OGG,m4v etc to MPEGeAVI).exe 1
---- EOF - GMER 2.1 ----
Ďakujem Veľmi pekne
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:13:44, on 6. 3. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Eset\ESET Endpoint Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe
C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Opera\opera.exe
C:\Windows\explorer.exe
C:\Program Files\HiJack This\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {32b29df0-2237-4370-9a29-37cebb730e9b} - (no file)
R3 - URLSearchHook: (no name) - {88ac3cb6-596b-4217-964c-b6757ef9602d} - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Users\Georgo\AppData\Roaming\Microsoft\microsoftwindowsupdate.exe
O2 - BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (file missing)
O2 - BHO: Slick Savings - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Georgo\AppData\Roaming\Slick Savings\Coupons.dll
O2 - BHO: FaceCons - {B2A44031-7EAD-434C-AC9E-7F1DA176BA8C} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MicrosoftWindowsUpdate] C:\Users\Georgo\AppData\Roaming\Microsoft\microsoftwindowsupdate.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Slick Savings] "C:\Users\Georgo\AppData\Roaming\Slick Savings\CouponsHelper.exe"
O4 - HKCU\..\Run: [zhuhghdt] regsvr32.exe "C:\ProgramData\zhuhghdt.dat"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
O8 - Extra context menu item: Free YouTube Download - C:\Users\Georgo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {5672DADB-EFBC-4927-B991-55678B70D679} (WebCamX Control) - http://213.160.160.82/WebCamX.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{294FC601-668D-4AC5-9367-F3E01C315FD8}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2DD43EE-464B-4D08-8B63-0EA9C6B0B2B4}: NameServer = 195.146.132.58,195.146.128.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{294FC601-668D-4AC5-9367-F3E01C315FD8}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{294FC601-668D-4AC5-9367-F3E01C315FD8}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O22 - SharedTaskScheduler: ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files\Stardock\ObjectDockFree\ODMenu.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\ekrn.exe
O23 - Service: ESET SHA Service (ESHASRV) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
--
End of file - 7868 bytes
A kontrolu logu z programu Gmer:
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-03-05 11:42:50
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK2035GSS rev.DK020M 186,31GB
Running: 77g9m6de.exe; Driver: C:\Users\Georgo\AppData\Local\Temp\kwliapob.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwCreateThread [0x8A7767F0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwLoadDriver [0x8A7768B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSetSystemInformation [0x8A776870]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys ZwSystemDebugControl [0x8A776830]
---- Kernel code sections - GMER 2.1 ----
.text ntoskrnl.exe!ZwRollbackEnlistment + 1409 838789A5 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 83898512 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 14CB 8389FAC0 4 Bytes [F0, 67, 77, 8A] {JA 0xffffff8e}
.text ntoskrnl.exe!KeRemoveQueueEx + 15DB 8389FBD0 4 Bytes [B0, 68, 77, 8A] {MOV AL, 0x68; JA 0xffffff8e}
.text ntoskrnl.exe!KeRemoveQueueEx + 18E7 8389FEDC 4 Bytes [70, 68, 77, 8A] {JO 0x6a; JA 0xffffff8e}
.text ntoskrnl.exe!KeRemoveQueueEx + 192F 8389FF24 4 Bytes [30, 68, 77, 8A]
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x92021340, 0x3EE217, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\ESET\ESET Endpoint Antivirus\ekrn.exe[1924] kernel32.dll!SetUnhandledExceptionFilter 75C4F4EB 4 Bytes [C2, 04, 00, 00]
.text C:\Windows\System32\rundll32.exe[3360] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 00698138
.text C:\Windows\System32\rundll32.exe[3360] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 00698191
.text C:\Windows\System32\rundll32.exe[3360] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 006981EA
.text C:\Windows\System32\rundll32.exe[3360] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Windows\System32\rundll32.exe[3360] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 00698246
.text C:\Windows\Explorer.EXE[3384] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 05258138
.text C:\Windows\Explorer.EXE[3384] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 05258191
.text C:\Windows\Explorer.EXE[3384] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 052581EA
.text C:\Windows\Explorer.EXE[3384] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Windows\Explorer.EXE[3384] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 05258246
.text C:\Windows\System32\rundll32.exe[3624] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 00758138
.text C:\Windows\System32\rundll32.exe[3624] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 00758191
.text C:\Windows\System32\rundll32.exe[3624] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 007581EA
.text C:\Windows\System32\rundll32.exe[3624] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Windows\System32\rundll32.exe[3624] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 00758246
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 017C8138
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 017C8191
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 017C81EA
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3660] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 017C8246
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 02BD8138
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 02BD8191
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 02BD81EA
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3684] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 02BD8246
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 01308138
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 01308191
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 013081EA
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[3704] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 01308246
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 01B78138
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 01B78191
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 01B781EA
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe[3744] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 01B78246
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 08028138
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 08028191
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 080281EA
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3824] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 08028246
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 04C38138
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 04C38191
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 04C381EA
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe[4080] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 04C38246
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 01308138
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 01308191
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 013081EA
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[4600] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 01308246
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 08CB8138
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 08CB8191
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] kernel32.dll!SetUnhandledExceptionFilter 75C4F4EB 5 Bytes JMP 5AC25629 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 08CB81EA
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[6124] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 08CB8246
.text C:\Program Files\Opera\opera.exe[8132] kernel32.dll!CreateProcessW 75C0204D 5 Bytes JMP 00588138
.text C:\Program Files\Opera\opera.exe[8132] kernel32.dll!CreateProcessA 75C02082 5 Bytes JMP 00588191
.text C:\Program Files\Opera\opera.exe[8132] ADVAPI32.dll!CreateProcessAsUserW 75ACC532 5 Bytes JMP 005881EA
.text C:\Program Files\Opera\opera.exe[8132] ADVAPI32.dll!CreateProcessAsUserA 75B02642 1 Byte [E9]
.text C:\Program Files\Opera\opera.exe[8132] ADVAPI32.dll!CreateProcessAsUserA 75B02642 5 Bytes JMP 00588246
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73EA24CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73E8562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73E856EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73EA2546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73E985AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73E94D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73E95105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73E951DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [73E96707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73E98301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73E98850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73E990B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73E9E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3384] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73E94C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\gdiplus.dll
---- Devices - GMER 2.1 ----
Device Ntfs.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Intel(R) PRO/Wireless 3945ABG \x2013 síťové připojení 1?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00037ad7c67b
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Intel(R) PRO/Wireless 3945ABG \x2013 síťové připojení 1?
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00037ad7c67b (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Dveře\Door Hasp Catching.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Gag\Bone Crush.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Temné burácení\Alligator Hiss.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Různé\Bike Sliding in Sand.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Hrající si děti\Bat Crack .wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Vesmírná loď\Electronic Motor2.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Cestování\Camera Shutter.wav 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs@C:\Users\Public\Documents\Pinnacle\Content\Sound Effects\UFX \x2013 Zimní radovánky\Baby Cough2.wav 1
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0xAA 0x52 0xC6 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@L:\Zaloha 16.4.2008-Externeho HDD\NET\Convertory\I\xb4M To AVI\ImTOO AVI MPEG Converter 2_1_16_1213b (MPEG,VOB,AVI,DV,MOV,animated GIF,swf,MPEG4,RM,WMV,ASF,WAV,WMA,MP3,3GP,m4a,mp4,h264,MP2,OGG,m4v etc to MPEGeAVI).exe 1
---- EOF - GMER 2.1 ----
Ďakujem Veľmi pekne