Nuž tak DDS spravil čo mal.
Tu je výpis logu:
DDS (Ver_2012-11-20.01) - FAT32_x86
Internet Explorer: 6.0.2600.0 BrowserJavaVersion: 1.6.0_29
Run by administrator at 13:49:20 on 2015-09-18
Microsoft Windows 2000 Server 5.0.2195.1.1250.421.1029.18.254.77 [GMT 2:00]
.
.
============== Running Processes ================
.
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\System32\ismserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\System32\WINDOW~1\Server\nscm.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\System32\lserver.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\dns.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\WINNT\System32\WINDOW~1\Server\nspm.exe
C:\WINNT\System32\WINDOW~1\Server\nsum.exe
C:\WINNT\Explorer.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
C:\WINNT\System32\Promon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\System32\ssms.exe
C:\WINNT\System32\internat.exe
C:\WINNT\System32\svchost.exe -k netsvcs
C:\WINNT\System32\svchost.exe -k tapisrv
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?SearchSource=10&ctid=CT1708250
uSearch Bar = hxxp://
www.searchgateway.net/search/
uSearch Page = hxxp://
www.searchgateway.net/search/
uProxyServer = 192.168.1.20:3128
uProxyOverride = <local>
uSearchURL,(Default) = hxxp://
www.searchgateway.net/search/%s
uURLSearchHooks: IncrediFindBHO Class: {5D60FF48-95BE-4956-B4C6-6BB168A70310} -
uURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\prxtbTog2.dll
uURLSearchHooks: Free Lunch Design Toolbar: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} -
BHO: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\prxtbTog2.dll
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: Free Lunch Design Toolbar: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} -
BHO: CrsHO Class: {5843A29E-1246-11D4-BA8C-0050DA707ACD} - c:\winnt\system32\crs32.dll
BHO: IncrediFindBHO Class: {5D60FF48-95BE-4956-B4C6-6BB168A70310} -
BHO: Mario Forever Toolbar Helper: {A20854FD-DDB5-4931-8F76-D11EA2364D94} -
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Mario Forever Toolbar: {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} -
TB: ToggleEN Toolbar: {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - c:\program files\toggleen\prxtbTog2.dll
TB: Free Lunch Design Toolbar: {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} -
TB: Mario Forever Toolbar: {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} -
TB: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\prxtbTog2.dll
TB: Free Lunch Design Toolbar: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} -
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - c:\winnt\system32\browseui.dll
uRun: [internat.exe] internat.exe
uRun: [Steam] d:\program files\steam\Steam.exe -silent
uRun: [cdoosoft] c:\docume~1\admini~1\locals~1\temp\herss.exe
mRun: [IMONTRAY] c:\program files\intel\intel(r) active monitor\imontray.exe
mRun: [Promon.exe] Promon.exe
mRun: [EM_EXEC] c:\progra~1\logitech\mousew~1\system\EM_EXEC.EXE
mRun: [HPLJ Config] c:\program files\hewlett-packard\hp laserjet 1150_1300\SetConfig.exe -c Direct -p DOT4_002 -pn "hp LaserJet 1300 PCL 6" -n 0 -l 1029 -sl 120000
mRun: [QuickTime Task] "e:\program files\quicktime\qttask.exe" -atboottime
mRun: [outlook] c:\program files\outlook\outlook.exe /auto
mRun: [winlog] winlog.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG7_CC] c:\progra~1\grisoft\avgfre~1\avgcc.exe /STARTUP
mRun: [Windows Update] ssms.exe
mRun: [MSStp] c:\winnt\inf\msstp.vbe
mRun: [mncvwxjgSrv] c:\winnt\system32\mncvwxjg.vbe
mRun: [msmlwkSrv] c:\winnt\inf\msmlwk.vbe
mRunServices: [winlog] winlog.exe
mRunServices: [Windows Update] ssms.exe
dRun: [internat.exe] internat.exe
dRun: [AVG7_Run] c:\progra~1\grisoft\avgfre~1\avgw.exe /RUNONCE
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\documents and settings\administrator\nabídka start\programy\po spuštìní\PowerReg Scheduler V3.exe
StartupFolder: c:\docume~1\alluse~1\nabídk~1\programy\pospuš~1\micros~1.lnk - d:\program files\microsoft office\office\OSA9.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: ShowSuperHidden = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:149
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: Interfaces\{39F3BE38-9BD1-4E40-A835-880528FBB246} : NameServer = 127.0.0.1
SecurityProviders: SecurityProviders = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, pwdssp.dll
LSA: Notification Packages = FPNWCLNT RASSFM KDCSVC scecli
Hosts: 38.113.174.32
www.google-analytics.com
Hosts: 38.113.170.200 ads1.msn.com
Hosts: 38.113.174.32 dehp.myspace.com
Hosts: 38.113.174.32 demr.myspace.com
Hosts: 38.113.174.32 desk.myspace.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
============= SERVICES / DRIVERS ===============
.
R0 a347bus;a347bus;c:\winnt\system32\drivers\a347bus.sys [2012-9-14 160640]
R0 a347scsi;a347scsi;c:\winnt\system32\drivers\a347scsi.sys [2012-9-14 5248]
R0 DfsDriver;DfsDriver;c:\winnt\system32\drivers\dfs.sys [2000-9-5 73936]
R0 idebd;idebd;c:\winnt\system32\drivers\IdeBd.sys [2001-6-6 3737]
R0 IntelATA;IntelATA;c:\winnt\system32\drivers\IntelATA.sys [2001-6-6 118480]
R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2011-12-28 726592]
R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2011-12-28 21856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2011-12-28 4288]
R1 SMBus;Intel(R) SMBus Driver;c:\winnt\system32\drivers\smbus.sys [2001-6-6 10368]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avgfre~1\avgamsvr.exe [2011-12-28 336896]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avgfre~1\avgupsvc.exe [2011-12-28 84480]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avgfre~1\avgemc.exe [2011-12-28 279040]
R2 AvgTdi;AVG Network Redirector;c:\winnt\system32\drivers\avgtdi.sys [2011-12-28 4992]
R2 DNS;Server DNS;c:\winnt\system32\dns.exe [2001-6-11 320784]
R2 IsmServ;Mezisíové zasílání zpráv;c:\winnt\system32\ismserv.exe [2000-9-5 27920]
R2 kdc;Centrum distribuce klíèù modulu Kerberos;c:\winnt\system32\lsass.exe [2000-9-5 33552]
R2 MapMem;MapMem;c:\winnt\system32\drivers\MAPMEM.SYS [2007-12-12 6816]
R2 nsprogram;Služba Windows Media Program Service;c:\winnt\system32\window~1\server\nspm.exe [2001-6-6 9632]
R2 nsstation;Služba Windows Media Station Service;c:\winnt\system32\window~1\server\nscm.exe [2001-6-6 220816]
R2 nsunicast;Služba Windows Media Unicast Service;c:\winnt\system32\window~1\server\nsum.exe [2001-6-6 441312]
R2 NtFrs;Služba File Replication Service;c:\winnt\system32\ntfrs.exe [2000-9-5 624912]
R2 NTRemap;NTRemap;c:\winnt\system32\drivers\NTREMAP.SYS [2007-12-12 6336]
R2 TermServLicensing;Správa licencí služby Terminal Services;c:\winnt\system32\lserver.exe [2001-6-6 325904]
R2 TrkSvr;Server sledování distribuovaného propojení;c:\winnt\system32\services.exe [2000-9-5 88848]
R3 spud;Ovladaè nástroje k zvláštním úèelùm;c:\winnt\system32\drivers\spud.sys [2001-6-6 12336]
S2 GenPort;GenPort; [x]
S2 nsmonitor;Služba Windows Media Monitor Service;c:\winnt\system32\window~1\server\nspmon.exe [2001-6-6 29728]
S2 ProtectorPlusAVMonitor;Protector Plus Anti-virus Monitor Service;"c:\protector plus\ppavmon.exe" --> c:\protector plus\PPAVMon.exe [?]
S2 ProtectorPlusService;Protector Plus Service (UnRegistered);"c:\protector plus\ppserv.exe" --> c:\protector plus\PPServ.exe [?]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\winnt\system32\drivers\ewusbdev.sys [2012-1-4 100736]
S3 NSLService;Vysílání prezentací online;c:\winnt\system32\windows media\nslite\NSLService.exe [2001-6-6 83312]
S3 PCIDATA;PCIDATA;\??\f:\pcidata.sys --> f:\PCIDATA.sys [?]
S3 PPDrv;Protector Plus Driver (UnRegistered);\??\c:\protector plus\ppdrv.sys --> c:\protector plus\PPDrv.sys [?]
S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\ppemscan.sys --> c:\protector plus\PPEMSCAN.sys [?]
S3 TDASYNC;TDASYNC;c:\winnt\system32\drivers\tdasync.sys [2001-6-6 12600]
S3 TDIPX;TDIPX;c:\winnt\system32\drivers\tdipx.sys [2001-6-6 19896]
S3 TDNETB;TDNETB;c:\winnt\system32\drivers\tdnetb.sys [2001-6-6 17528]
S3 TDSPX;TDSPX;c:\winnt\system32\drivers\tdspx.sys [2001-6-6 17400]
.
=============== File Associations ===============
.
FileExt: .reg: regfile="regedit.exe" "%1"
FileExt: .txt: Applications\NOTEPAD.EXE=c:\winnt\system32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .vbs: VBSFile=c:\winnt\system32\CScript.exe //nologo "%1" %*
ShellExec: AcroRd32.exe: print="c:\program files\adobe\acrobat 4.0\reader\AcroRd32.exe"
ShellExec: AcroRd32.exe: printto="c:\program files\adobe\acrobat 4.0\reader\AcroRd32.exe"
ShellExec: wordpad.exe: print="c:\program files\windows nt\pøíslušenství\WORDPAD.EXE"/p "%1"
ShellExec: wordpad.exe: printto="c:\program files\windows nt\pøíslušenství\WORDPAD.EXE"/pt "%1" "%2" "%3" "%4"
.
=============== Created Last 30 ================
.
2015-09-18 08:57:47 118784 --sh--r- C:\8xcrbho6.exe
2015-09-13 17:01:47 1409 ----a-w- c:\winnt\QTFont.for
.
==================== Find3M ====================
.
2015-09-18 11:44:40 5894 ----a-w- C:\a.bat
2013-02-03 15:30:26 167936 --sh--r- c:\winnt\system32\ssms.exe
.
============= FINISH: 13:49:52,85 ===============