Stránka 1 z 1

Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 05:55
od mino14051965
Zdravim Vas.
Prosim zkontrolujte muj log.Notebook se mi spomaluje a pri urcitych aplikacich napr.ANY VIDEO CONVERTER se mi pri zacatku konverze
vypne jako by nic.I kdyz jsem program znovu preinstaloval,tak mi nedela strih atd.V programu bych rekl,ze to neni,dlouho se odhlasuje a dela to i ConvertXto DVD.Predtim mi programy bezeli normalne.
Prosim o radu co s tim.

Muj log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by MINO at 2010-02-07 05:38:23
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 58 GB (40%) free of 146 GB
Total RAM: 894 MB (14% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:38:56, on 7.2.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ASScrPro.exe
C:\Program Files\P4P\P4P.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\TweakNow PowerPack 2009\CDAuto.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Opera\opera.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\totalcmd\TOTALCMD.EXE
C:\STAHOVANIE\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\MINO.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: MyPlayCity Toolbar - {4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} - C:\Program Files\MyPlayCity\tbMyPl.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: wellgames Toolbar - {8e41e543-e069-4197-8608-e8b4c2f75747} - C:\Program Files\wellgames\tbwell.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: wellgames Toolbar - {8e41e543-e069-4197-8608-e8b4c2f75747} - C:\Program Files\wellgames\tbwell.dll
O3 - Toolbar: MyPlayCity Toolbar - {4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} - C:\Program Files\MyPlayCity\tbMyPl.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CD Autorun] C:\Program Files\TweakNow PowerPack 2009\CDAuto.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\SideBar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [Opera Internet Browser] C:\Program Files\Opera\Opera.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video Free Download Managerem - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 10797 bytes

======Scheduled tasks folder======

C:\Windows\tasks\1-Click Maintenance.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\User_Feed_Synchronization-{E0E06C9F-87D6-4BF8-BA57-5F8136AE85E5}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\ctbr.dll [2008-02-29 1142784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
MyPlayCity Toolbar - C:\Program Files\MyPlayCity\tbMyPl.dll [2008-03-04 1470488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e41e543-e069-4197-8608-e8b4c2f75747}]
wellgames Toolbar - C:\Program Files\wellgames\tbwell.dll [2008-06-24 1569304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-11-17 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-12 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{8e41e543-e069-4197-8608-e8b4c2f75747} - wellgames Toolbar - C:\Program Files\wellgames\tbwell.dll [2008-06-24 1569304]
{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} - MyPlayCity Toolbar - C:\Program Files\MyPlayCity\tbMyPl.dll [2008-03-04 1470488]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\ctbr.dll [2008-02-29 1142784]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2009-05-05 1466368]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [2006-11-02 61440]
"JMB36X IDE Setup"=C:\Windows\JM\JMInsIDE.exe [2006-10-30 36864]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-03-01 857648]
"ASUS Camera ScreenSaver"=C:\Windows\ASScrProlog.exe [2008-09-21 37232]
"ASUS Screen Saver Protector"=C:\Windows\ASScrPro.exe [2008-09-21 33136]
"PowerForPhone"=C:\Program Files\P4P\P4P.exe [2007-07-19 778240]
"Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-14 644696]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-04-03 1603152]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
"CD Autorun"=C:\Program Files\TweakNow PowerPack 2009\CDAuto.exe [2009-11-13 429312]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"Sidebar"=C:\Program Files\Windows Sidebar\SideBar.exe [2009-04-11 1233920]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"Opera Internet Browser"=C:\Program Files\Opera\Opera.exe [2009-11-20 832296]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\system32\wpdshserviceobj.dll [2009-10-01 87552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4ed7003-d0df-11de-abd4-001d60c6616c}]
shell\AutoRun\command - E:\cj3k.exe
shell\open\command - E:\cj3k.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.reg - open - NOTEPAD.EXE %1
.scr - open - NOTEPAD.EXE %1
.vbs - open - NOTEPAD.EXE %1

======List of files/folders created in the last 1 months======

2010-01-24 11:46:17 ----A---- C:\Windows\ODBCINST.INI
2010-01-24 05:46:05 ----D---- C:\Users\MINO\AppData\Roaming\DivX
2010-01-24 05:39:01 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-01-24 05:37:23 ----D---- C:\Program Files\Common Files\DivX Shared
2010-01-22 01:53:50 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 01:53:46 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 01:53:44 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 01:53:44 ----A---- C:\Windows\system32\iertutil.dll
2010-01-22 01:53:43 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 01:53:43 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-22 01:53:42 ----A---- C:\Windows\system32\occache.dll
2010-01-22 01:53:42 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 01:53:40 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-22 01:53:40 ----A---- C:\Windows\system32\ieui.dll
2010-01-22 01:53:40 ----A---- C:\Windows\system32\iepeers.dll
2010-01-22 01:53:39 ----A---- C:\Windows\system32\msfeedssync.exe
2010-01-22 01:53:39 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 01:53:39 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-22 01:53:39 ----A---- C:\Windows\system32\iesysprep.dll
2010-01-22 01:53:39 ----A---- C:\Windows\system32\iesetup.dll
2010-01-22 01:53:39 ----A---- C:\Windows\system32\ie4uinit.exe
2010-01-22 01:53:38 ----A---- C:\Windows\system32\iernonce.dll
2010-01-20 17:27:01 ----HD---- C:\Autorun.inf
2010-01-20 16:38:13 ----D---- C:\Program Files\Yamicsoft
2010-01-17 16:07:51 ----A---- C:\Windows\NeroDigital.ini
2010-01-16 14:43:30 ----A---- C:\Windows\MegaManager.INI
2010-01-15 05:38:35 ----D---- C:\Users\MINO\AppData\Roaming\TweakNow RegCleaner
2010-01-15 05:38:35 ----D---- C:\Program Files\TweakNow RegCleaner
2010-01-13 16:44:05 ----D---- C:\VirtualDub 1.9.7
2010-01-13 04:22:03 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 04:22:02 ----A---- C:\Windows\system32\fontsub.dll
2010-01-12 12:47:51 ----D---- C:\HODINY
2010-01-08 17:06:06 ----D---- C:\Users\MINO\AppData\Roaming\TweakNow PowerPack 2009
2010-01-08 17:06:06 ----D---- C:\Program Files\TweakNow PowerPack 2009
2010-01-08 16:09:21 ----D---- C:\CENNIK LIEKOV 1.1.2010

======List of files/folders modified in the last 1 months======

2010-02-07 05:38:36 ----D---- C:\Windows\Prefetch
2010-02-07 05:38:29 ----D---- C:\Windows\Temp
2010-02-07 05:30:40 ----D---- C:\Windows
2010-02-07 04:50:28 ----D---- C:\Windows\Tasks
2010-02-07 04:47:53 ----D---- C:\Windows\system32\drivers
2010-02-07 04:47:22 ----A---- C:\Windows\system32\acovcnt.exe
2010-02-06 15:20:28 ----SHD---- C:\System Volume Information
2010-02-06 11:40:25 ----D---- C:\Windows\Minidump
2010-02-06 11:32:23 ----D---- C:\Windows\system32\catroot2
2010-02-06 10:53:04 ----D---- C:\STAHOVANIE
2010-02-06 09:43:26 ----D---- C:\ProgramData\Google Updater
2010-02-06 01:03:06 ----D---- C:\Program Files\Crawler
2010-02-03 12:01:18 ----D---- C:\Users\MINO\AppData\Roaming\Adobe
2010-02-03 12:01:18 ----D---- C:\ProgramData\Adobe
2010-02-03 11:49:28 ----D---- C:\Windows\System32
2010-02-03 11:49:28 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-02-03 11:49:27 ----D---- C:\Windows\inf
2010-02-03 09:04:51 ----D---- C:\DOKUMENTY-MINO
2010-02-02 17:11:27 ----D---- C:\ProgramData\CanonIJPLM
2010-02-02 15:28:24 ----D---- C:\Windows\system32\config
2010-02-01 01:17:07 ----D---- C:\Users\MINO\AppData\Roaming\Vso
2010-01-31 12:24:42 ----SHD---- C:\Boot
2010-01-27 04:27:05 ----D---- C:\Windows\winsxs
2010-01-27 04:27:04 ----D---- C:\Program Files\Internet Explorer
2010-01-27 04:21:04 ----D---- C:\Windows\system32\catroot
2010-01-25 04:56:15 ----D---- C:\Program Files\Google
2010-01-25 04:56:13 ----SHD---- C:\Windows\Installer
2010-01-25 04:06:59 ----RD---- C:\Program Files
2010-01-24 05:51:11 ----D---- C:\Windows\system32\Tasks
2010-01-24 05:39:01 ----D---- C:\Program Files\Common Files
2010-01-22 01:58:58 ----D---- C:\Windows\system32\migration
2010-01-20 17:24:08 ----D---- C:\Windows\system32\LogFiles
2010-01-20 16:58:18 ----D---- C:\Program Files\WinRAR
2010-01-20 16:58:18 ----D---- C:\Program Files\TuneUp Utilities 2008
2010-01-20 16:38:32 ----SD---- C:\Users\MINO\AppData\Roaming\Microsoft
2010-01-19 06:45:46 ----D---- C:\Users\MINO\AppData\Roaming\gtk-2.0
2010-01-19 06:44:32 ----D---- C:\AviDEMUX 2.5.1
2010-01-17 16:04:10 ----D---- C:\Users\MINO\AppData\Roaming\Any Video Converter Professional
2010-01-17 15:57:53 ----D---- C:\Program Files\Any Video Converter Professional
2010-01-16 14:44:39 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-16 14:11:02 ----D---- C:\Users\MINO\AppData\Roaming\Free Download Manager
2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-13 12:49:37 ----D---- C:\Windows\Debug
2010-01-13 04:26:36 ----D---- C:\Program Files\Windows Mail

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-11-25 23120]
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-09-08 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-09-08 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-05-10 108552]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2009-09-11 142592]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-11-25 53328]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2006-12-28 18688]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-19 95744]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-24 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-03-22 37376]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-01-13 954368]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-04 2771456]
R3 BthAvrcp;Bluetooth AVRCP Profile; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2008-09-21 12800]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-02-14 1740904]
R3 irsir;Microsoft Serial Infrared Driver; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-19 20992]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2006-11-24 45568]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-19 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2009-09-11 47360]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-11-16 216576]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-05-05 1095808]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam; C:\Windows\System32\Drivers\StkCMini.sys [2007-02-13 1245056]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-03-01 182456]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\Windows\system32\DRIVERS\MSIRCOMM.sys [2008-01-19 24064]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945BG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2006-10-14 4422560]
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2006-11-02 41064]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2007-05-18 73728]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-02-06 94208]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-07-04 606208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-06-11 94208]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-09-12 554352]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 IJPLMSVC;PIXMA Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 101528]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2006-12-29 123248]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service; C:\Windows\System32\StkCSrv.exe [2007-02-07 24576]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-10 183280]
S2 LiveUpdate Notice Ex;LiveUpdate Notice Service Ex; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe []
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-09-12 2999664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2009-12-10 355584]

-----------------EOF-----------------

Predem dekuji!!!!! :(

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 07:05
od meteorolog
Dobrý den :)

odinstalujte wellgames Toolbar a MyPlayCity Toolbar

zapojte do PC všechny přenosné usb disky (klíčenky) a pošlete ještě log z Combofix:

Stáhneme na plochu, ukončíme všechna aktivní okna a spustíme ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Po spuštění potvrdíme podmínky užití
- Dále postupujeme dle pokynů, během aplikování ComboFixu neklikejte do zobrazujících se oken
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt
- ComboFix je třeba spustit pod účtem s právy administrátora

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 09:19
od mino14051965
Dekuji pekne za navod a program.
Nevim sice k cemu slouzi,jestli to bude myt nejaky efekt.Slo by mi to nejak priblizit???(jakou ma funkci atd.)
Cekam na dalsi rady.......Děkuji!!!!

Zasilam Log z CombFixu

ComboFix 10-02-06.02 - MINO 07.02.2010 7:57.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.894.171 [GMT 1:00]
Spuštěný z: c:\users\MINO\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spyware Terminator *enabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1876766861-4099627362-3959107545-500
C:\LOG.TXT
c:\users\MINO\AppData\Roaming\inst.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-07 do 2010-02-07 )))))))))))))))))))))))))))))))
.

2010-02-07 07:18 . 2010-02-07 07:18 -------- d-----w- c:\users\MINO\AppData\Local\temp
2010-02-07 07:18 . 2010-02-07 07:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-24 04:46 . 2010-01-26 05:49 -------- d-----w- c:\users\MINO\AppData\Roaming\DivX
2010-01-24 04:39 . 2010-01-25 03:05 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-01-24 04:37 . 2010-01-24 04:38 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-20 15:38 . 2010-01-20 15:38 -------- d-----w- c:\program files\Yamicsoft
2010-01-15 04:38 . 2010-01-15 04:38 -------- d-----w- c:\program files\TweakNow RegCleaner
2010-01-15 04:38 . 2010-01-15 04:38 -------- d-----w- c:\users\MINO\AppData\Roaming\TweakNow RegCleaner
2010-01-13 15:44 . 2010-01-18 06:14 -------- d-----w- C:\VirtualDub 1.9.7
2010-01-13 03:22 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 03:22 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-12 11:47 . 2010-01-12 11:48 -------- d-----w- C:\HODINY
2010-01-08 16:06 . 2010-01-09 11:36 -------- d-----w- c:\program files\TweakNow PowerPack 2009
2010-01-08 16:06 . 2010-01-08 16:06 -------- d-----w- c:\users\MINO\AppData\Roaming\TweakNow PowerPack 2009
2010-01-08 15:09 . 2010-01-08 15:45 -------- d-----w- C:\CENNIK LIEKOV 1.1.2010

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 05:57 . 2008-09-21 03:10 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-02-07 05:52 . 2007-04-21 10:36 18562 ----a-w- c:\windows\bthservsdp.dat
2010-02-06 08:43 . 2009-05-10 09:06 -------- d-----w- c:\programdata\Google Updater
2010-02-06 00:03 . 2009-12-25 08:34 -------- d-----w- c:\program files\Crawler
2010-02-03 10:49 . 2007-04-21 11:18 598838 ----a-w- c:\windows\system32\perfh005.dat
2010-02-03 10:49 . 2007-04-21 11:18 115014 ----a-w- c:\windows\system32\perfc005.dat
2010-02-02 16:11 . 2008-10-10 09:27 -------- d-----w- c:\programdata\CanonIJPLM
2010-02-01 00:17 . 2009-12-04 04:59 -------- d-----w- c:\users\MINO\AppData\Roaming\Vso
2010-01-25 03:56 . 2009-05-10 09:06 -------- d-----w- c:\program files\Google
2010-01-20 15:58 . 2009-12-10 11:26 -------- d-----w- c:\program files\TuneUp Utilities 2008
2010-01-19 05:45 . 2009-11-20 08:33 -------- d-----w- c:\users\MINO\AppData\Roaming\gtk-2.0
2010-01-17 15:04 . 2009-12-10 05:03 -------- d-----w- c:\users\MINO\AppData\Roaming\Any Video Converter Professional
2010-01-17 14:57 . 2009-12-10 05:02 -------- d-----w- c:\program files\Any Video Converter Professional
2010-01-16 13:44 . 2008-09-21 02:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-16 13:11 . 2009-11-03 13:31 -------- d-----w- c:\users\MINO\AppData\Roaming\Free Download Manager
2010-01-14 10:12 . 2009-10-06 08:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 03:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-02 06:38 . 2010-01-22 00:53 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 00:53 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 00:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 00:53 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-28 16:03 . 2009-12-05 12:19 -------- d-----w- c:\programdata\DVD Shrink
2009-12-19 06:44 . 2009-06-24 14:20 -------- d-----w- c:\program files\GameTop.com
2009-12-18 17:52 . 2009-12-18 06:26 -------- d-----w- c:\users\MINO\AppData\Roaming\Ahead
2009-12-18 06:25 . 2009-12-18 06:23 -------- d-----w- c:\program files\Common Files\Ahead
2009-12-18 06:23 . 2008-09-25 13:15 -------- d-----w- c:\programdata\Nero
2009-12-18 06:23 . 2009-12-18 06:23 -------- d-----w- c:\program files\Nero
2009-12-18 06:01 . 2008-09-25 13:15 -------- d-----w- c:\program files\Common Files\Nero
2009-12-12 11:53 . 2008-09-23 09:21 -------- d-----w- c:\program files\Trend Micro
2009-12-10 13:36 . 2009-12-10 13:36 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-12-10 11:27 . 2009-12-08 15:50 -------- d-----w- c:\users\MINO\AppData\Roaming\TuneUp Software
2009-12-10 11:26 . 2009-12-08 15:48 -------- d-----w- c:\programdata\TuneUp Software
2009-12-10 11:24 . 2009-12-10 11:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-10 05:44 . 2009-12-10 05:44 -------- d-----w- c:\users\MINO\AppData\Roaming\AnvSoft
2009-12-10 05:44 . 2009-12-10 05:44 -------- d-----w- c:\program files\AnvSoft
2009-12-10 01:27 . 2009-09-11 13:47 47360 ----a-w- c:\users\MINO\AppData\Roaming\pcouffin.sys
2009-12-10 01:27 . 2009-09-11 13:47 47360 ----a-w- c:\users\MINO\AppData\Roaming\pcouffin.sys
2009-11-24 23:54 . 2009-12-02 18:13 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2009-12-02 18:14 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-12-02 18:14 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-12-02 18:13 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2009-12-02 18:14 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-12-02 18:14 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-12-02 18:14 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-16 02:13 . 2009-11-16 02:13 216576 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-11-14 00:49 . 2009-02-23 09:33 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-11-14 00:49 . 2009-02-21 20:16 129784 ------w- c:\windows\system32\pxafs.dll
2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-12 06:24 . 2009-11-12 06:24 94208 ----a-w- c:\windows\system32\RTNUninst32.dll
2009-11-09 12:31 . 2009-12-10 00:30 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-10 00:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-10 00:30 411648 ----a-w- c:\windows\system32\drivers\http.sys
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\Windows Sidebar\SideBar.exe" [2009-04-11 1233920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"Opera Internet Browser"="c:\program files\Opera\Opera.exe" [2009-11-20 832296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2008-09-21 37232]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2008-09-21 33136]
"PowerForPhone"="c:\program files\P4P\P4P.exe" [2007-07-19 778240]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"CD Autorun"="c:\program files\TweakNow PowerPack 2009\CDAuto.exe" [2009-11-13 429312]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-9-1 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /r \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\c:\0autocheck autochk /p \??\C:\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b6,a8,bb,1a,0e,47,ca,01

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2.12.2009 19:14 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [21.9.2008 11:24 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [31.1.2009 8:36 108552]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [11.9.2009 12:20 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2.12.2009 19:14 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2.12.2009 19:13 53328]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\System32\StkCSrv.exe [21.9.2008 4:07 24576]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\System32\drivers\BthAvrcp.sys [21.9.2008 3:53 12800]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [21.9.2008 3:56 45568]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\System32\drivers\StkCMini.sys [21.9.2008 4:07 1245056]
S3 FontCache;Mezipaměť písem Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [8.7.2009 13:13 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-02-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 08:09]

2010-02-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-10 09:06]

2010-02-07 c:\windows\Tasks\User_Feed_Synchronization-{E0E06C9F-87D6-4BF8-BA57-5F8136AE85E5}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
BHO-{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} - c:\program files\MyPlayCity\tbMyPl.dll
BHO-{8e41e543-e069-4197-8608-e8b4c2f75747} - c:\program files\wellgames\tbwell.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{8E41E543-E069-4197-8608-E8B4C2F75747} - c:\program files\wellgames\tbwell.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC} - c:\program files\MyPlayCity\tbMyPl.dll
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-07 08:18
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CD Autorun = c:\program files\TweakNow PowerPack 2009\CDAuto.exe???????3?c:\program files\Microsoft Office\Office12

skenování skrytých souborů ...


C:\ADSM_PData_0150

sken byl úspešně dokončen
skryté soubory: 1

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-02-07 08:30:03
ComboFix-quarantined-files.txt 2010-02-07 07:29

Před spuštěním: Volných bajtů: 61 014 032 384
Po spuštění: Volných bajtů: 60 951 932 928

- - End Of File - - 6167EBCD8BE87CE599F2BC5AF5BCBEB8

Napiste co treba vymazat,co je nepotrebne atd.Díky :wink:
PO RESTARTE MI ZASE NENASKOCIL WINDOWS,AZ ZA 5MIN.
Jeste sem chtel dodat,ze AVG ani Spyware Terminator jiz sem davno odinstaloval,tak nevim proc tam figurujou.
Jsou tady i starsi nepouzivane veci,ale mozno jsou v registrech a ja nevim jak se jich zbavit.
poradte,prosim!!!

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 10:16
od meteorolog
otevřte poznámkový blok (Notepad) a zkopírujte do něj následující text:
KillAll::
Driver::
AvgLdx86
AvgTdiX
sp_rsdrv2

File::
c:\windows\System32\drivers\avgldx86.sys
c:\windows\System32\drivers\avgtdix.sys
c:\windows\System32\drivers\sp_rsdrv2.sys

Folder::
c:\program files\Crawler

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]

DDS::
IE: Crawler Search - tbr:iemenu
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
Soubor uložte na plochu jako CFScript.txt a podle obrázku přetáhněte nad ComboFix

Obrázek

spustí se ComboFix a vykoná příkaz ze skriptu - potom pošlete nový log

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 15:44
od mino14051965
Tak se opet po delsi odmlce vracim do fora.
Provedl jsem operaci,kterou jste mi poradil,ovsem ikony(programy atd.), co mam na plose nejdou spustit klasickym dvouklikem,pise nasledujici: " Pokus pouzit neplatnou operaci na klic registru,ktery je oznacen pro odstraneni ".WAS IST DAS????
Dokonce se nemuzu dostat klasicky do ovladacich panelu.
Co dal??? Na NET me to pustilo jen jako s povolenim SPRAVCE,co jsem zkousel,tak pise to co jsem uvedl nahore.
Jsou v mem notebooku jeste veci,ktere by meli byt vymazany????Je to nejak poznat nebo videt z logu,co je treba jeste za vasi pomoci vymazat????
A jeste jedna vec.Nainstaloval jsem program pro Vistu......VISTA MANAGER-trial,ale nevim,jak ji odinstalovat,abych neco nepotentockoval.

Jinak zatim MOCMOC diky a cekam na dalsi rady,at je muj comp v poradku. :roll:

Posilam log od COMBFIX::::::


ComboFix 10-02-06.03 - MINO 07.02.2010 10:56:42.2.2 - x86
Spuštěný z: c:\users\MINO\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\MINO\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spyware Terminator *enabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\System32\drivers\avgldx86.sys"
"c:\windows\System32\drivers\avgtdix.sys"
"c:\windows\System32\drivers\sp_rsdrv2.sys"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\progra~1\Crawler\ctbr.dll
c:\program files\Crawler
c:\program files\Crawler\Cache\COMMON\CLEANUP_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\CLEANUP_MENU.dat
c:\program files\Crawler\Cache\COMMON\DIRLIST_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\DIRLIST_MENU.dat
c:\program files\Crawler\Cache\COMMON\ECARDS_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\ECARDS_MENU.dat
c:\program files\Crawler\Cache\COMMON\EMAIL_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\GAMES_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\GAMES_MENU.dat
c:\program files\Crawler\Cache\COMMON\SHOP_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\SPELL_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\TRAVEL_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\WAYBACK_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\WP_CHBMP.dat
c:\program files\Crawler\Cache\COMMON\YP_CHBMP.dat
c:\program files\Crawler\confirm.dat
c:\program files\Crawler\ctbcomm.dll
c:\program files\Crawler\ctbr.dll
c:\program files\Crawler\CTipsDef.dll
c:\program files\Crawler\CToolbar.exe
c:\program files\Crawler\CUpdate.exe
c:\program files\Crawler\Languages\TBR5_CS.cab
c:\program files\Crawler\Languages\TBR5_DE.cab
c:\program files\Crawler\Languages\TBR5_EN.cab
c:\program files\Crawler\Languages\TBR5_ES.cab
c:\program files\Crawler\Languages\TBR5_IT.cab
c:\program files\Crawler\Languages\TBR5_PT-BR.cab
c:\program files\Crawler\Languages\TBR5_PT.cab
c:\program files\Crawler\lookfor.dat
c:\program files\Crawler\majorse.dat
c:\program files\Crawler\rootmenu.dat
c:\program files\Crawler\services.dat
c:\program files\Crawler\TBR5LanguageAct\info.ini
c:\program files\Crawler\TBR5LanguageAct\language.ini
c:\windows\System32\drivers\avgldx86.sys
c:\windows\System32\drivers\avgtdix.sys
c:\windows\System32\drivers\sp_rsdrv2.sys

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_AVGLDX86
-------\Legacy_AVGTDIX
-------\Legacy_SP_RSDRV2
-------\Service_AvgLdx86
-------\Service_AvgTdiX
-------\Service_sp_rsdrv2


((((((((((((((((((((((((( Soubory vytvořené od 2010-01-07 do 2010-02-07 )))))))))))))))))))))))))))))))
.

2010-02-07 10:16 . 2010-02-07 13:43 -------- d-----w- c:\users\MINO\AppData\Local\temp
2010-02-07 10:16 . 2010-02-07 10:16 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-02-07 10:16 . 2010-02-07 10:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-24 04:46 . 2010-01-26 05:49 -------- d-----w- c:\users\MINO\AppData\Roaming\DivX
2010-01-24 04:39 . 2010-01-25 03:05 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-01-24 04:37 . 2010-01-24 04:38 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-20 15:38 . 2010-01-20 15:38 -------- d-----w- c:\program files\Yamicsoft
2010-01-15 04:38 . 2010-01-15 04:38 -------- d-----w- c:\program files\TweakNow RegCleaner
2010-01-15 04:38 . 2010-01-15 04:38 -------- d-----w- c:\users\MINO\AppData\Roaming\TweakNow RegCleaner
2010-01-13 15:44 . 2010-01-18 06:14 -------- d-----w- C:\VirtualDub 1.9.7
2010-01-13 03:22 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 03:22 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-12 11:47 . 2010-01-12 11:48 -------- d-----w- C:\HODINY
2010-01-08 16:06 . 2010-01-09 11:36 -------- d-----w- c:\program files\TweakNow PowerPack 2009
2010-01-08 16:06 . 2010-01-08 16:06 -------- d-----w- c:\users\MINO\AppData\Roaming\TweakNow PowerPack 2009
2010-01-08 15:09 . 2010-01-08 15:45 -------- d-----w- C:\CENNIK LIEKOV 1.1.2010

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 10:18 . 2007-04-21 10:36 18562 ----a-w- c:\windows\bthservsdp.dat
2010-02-07 09:44 . 2009-05-10 09:06 -------- d-----w- c:\programdata\Google Updater
2010-02-07 08:33 . 2008-09-21 03:10 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-02-03 10:49 . 2007-04-21 11:18 598838 ----a-w- c:\windows\system32\perfh005.dat
2010-02-03 10:49 . 2007-04-21 11:18 115014 ----a-w- c:\windows\system32\perfc005.dat
2010-02-02 16:11 . 2008-10-10 09:27 -------- d-----w- c:\programdata\CanonIJPLM
2010-02-01 00:17 . 2009-12-04 04:59 -------- d-----w- c:\users\MINO\AppData\Roaming\Vso
2010-01-25 03:56 . 2009-05-10 09:06 -------- d-----w- c:\program files\Google
2010-01-20 15:58 . 2009-12-10 11:26 -------- d-----w- c:\program files\TuneUp Utilities 2008
2010-01-19 05:45 . 2009-11-20 08:33 -------- d-----w- c:\users\MINO\AppData\Roaming\gtk-2.0
2010-01-17 15:04 . 2009-12-10 05:03 -------- d-----w- c:\users\MINO\AppData\Roaming\Any Video Converter Professional
2010-01-17 14:57 . 2009-12-10 05:02 -------- d-----w- c:\program files\Any Video Converter Professional
2010-01-16 13:44 . 2008-09-21 02:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-16 13:11 . 2009-11-03 13:31 -------- d-----w- c:\users\MINO\AppData\Roaming\Free Download Manager
2010-01-14 10:12 . 2009-10-06 08:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 03:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-02 06:38 . 2010-01-22 00:53 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 00:53 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 00:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 00:53 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-28 16:03 . 2009-12-05 12:19 -------- d-----w- c:\programdata\DVD Shrink
2009-12-19 06:44 . 2009-06-24 14:20 -------- d-----w- c:\program files\GameTop.com
2009-12-18 17:52 . 2009-12-18 06:26 -------- d-----w- c:\users\MINO\AppData\Roaming\Ahead
2009-12-18 06:25 . 2009-12-18 06:23 -------- d-----w- c:\program files\Common Files\Ahead
2009-12-18 06:23 . 2008-09-25 13:15 -------- d-----w- c:\programdata\Nero
2009-12-18 06:23 . 2009-12-18 06:23 -------- d-----w- c:\program files\Nero
2009-12-18 06:01 . 2008-09-25 13:15 -------- d-----w- c:\program files\Common Files\Nero
2009-12-12 11:53 . 2008-09-23 09:21 -------- d-----w- c:\program files\Trend Micro
2009-12-10 13:36 . 2009-12-10 13:36 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-12-10 11:27 . 2009-12-08 15:50 -------- d-----w- c:\users\MINO\AppData\Roaming\TuneUp Software
2009-12-10 11:26 . 2009-12-08 15:48 -------- d-----w- c:\programdata\TuneUp Software
2009-12-10 11:24 . 2009-12-10 11:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-10 05:44 . 2009-12-10 05:44 -------- d-----w- c:\users\MINO\AppData\Roaming\AnvSoft
2009-12-10 05:44 . 2009-12-10 05:44 -------- d-----w- c:\program files\AnvSoft
2009-12-10 01:27 . 2009-09-11 13:47 47360 ----a-w- c:\users\MINO\AppData\Roaming\pcouffin.sys
2009-12-10 01:27 . 2009-09-11 13:47 47360 ----a-w- c:\users\MINO\AppData\Roaming\pcouffin.sys
2009-11-24 23:54 . 2009-12-02 18:13 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2009-12-02 18:14 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-12-02 18:14 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-12-02 18:13 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2009-12-02 18:14 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-12-02 18:14 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-12-02 18:14 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-16 02:13 . 2009-11-16 02:13 216576 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-11-14 00:49 . 2009-02-23 09:33 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-11-14 00:49 . 2009-02-21 20:16 129784 ------w- c:\windows\system32\pxafs.dll
2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-12 06:24 . 2009-11-12 06:24 94208 ----a-w- c:\windows\system32\RTNUninst32.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\Windows Sidebar\SideBar.exe" [2009-04-11 1233920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"Opera Internet Browser"="c:\program files\Opera\Opera.exe" [2009-11-20 832296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2008-09-21 37232]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2008-09-21 33136]
"PowerForPhone"="c:\program files\P4P\P4P.exe" [2007-07-19 778240]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"CD Autorun"="c:\program files\TweakNow PowerPack 2009\CDAuto.exe" [2009-11-13 429312]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-9-1 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b6,a8,bb,1a,0e,47,ca,01

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2.12.2009 19:14 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2.12.2009 19:14 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2.12.2009 19:13 53328]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\System32\drivers\BthAvrcp.sys [21.9.2008 3:53 12800]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [21.9.2008 3:56 45568]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\System32\drivers\StkCMini.sys [21.9.2008 4:07 1245056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-02-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 08:09]

2010-02-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-10 09:06]

2010-02-07 c:\windows\Tasks\User_Feed_Synchronization-{E0E06C9F-87D6-4BF8-BA57-5F8136AE85E5}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Stáhnout Free Download Managerem - file://c:\program files\Free Download Manager\dllink.htm
IE: Stáhnout video Free Download Managerem - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Stáhnout vybrané Free Download Managerem - file://c:\program files\Free Download Manager\dlselected.htm
IE: Stáhnout vše Free Download Managerem - file://c:\program files\Free Download Manager\dlall.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-CToolbar_UNINSTALL - c:\progra~1\Crawler\CToolbar.exe



**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CD Autorun = c:\program files\TweakNow PowerPack 2009\CDAuto.exe???????3?c:\program files\Microsoft Office\Office12

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'Explorer.exe'(2384)
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\System32\StkCSrv.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\ATK Hotkey\Hcontrol.exe
c:\program files\ATKOSD2\ATKOSD2.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Celkový čas: 2010-02-07 14:55:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-07 13:54
ComboFix2.txt 2010-02-07 07:30

Před spuštěním: Volných bajtů: 59 957 469 184
Po spuštění: Volných bajtů: 59 618 177 024

- - End Of File - - 566C6E700F27F5F9E7BE524EF14197E0
------------------------------------------------------------------------------------------------------
2010-02-07 13:53:26 . 2010-02-07 13:53:26 938 ----a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-CToolbar_UNINSTALL.reg.dat
2010-02-07 10:13:06 . 2010-02-07 10:13:06 1,406 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_sp_rsdrv2.reg.dat
2010-02-07 10:13:05 . 2010-02-07 10:13:05 1,408 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_AvgTdiX.reg.dat
2010-02-07 10:13:05 . 2010-02-07 10:13:05 1,868 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_AvgLdx86.reg.dat
2010-02-07 10:13:04 . 2010-02-07 10:13:04 1,148 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_SP_RSDRV2.reg.dat
2010-02-07 10:13:04 . 2010-02-07 10:13:04 1,120 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_AVGTDIX.reg.dat
2010-02-07 10:13:04 . 2010-02-07 10:13:04 1,144 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_AVGLDX86.reg.dat
2010-02-07 09:56:20 . 2010-02-07 09:56:21 240,718 ----a-w- C:\Qoobox\Quarantine\[4]-Submit_2010-02-07_10.55.33.zip
2010-02-07 07:27:53 . 2010-02-07 07:27:53 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98}.reg.dat
2010-02-07 07:27:53 . 2010-02-07 07:27:53 409 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC}.reg.dat
2010-02-07 07:27:52 . 2010-02-07 07:27:52 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829}.reg.dat
2010-02-07 07:27:52 . 2010-02-07 07:27:52 408 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{8E41E543-E069-4197-8608-E8B4C2F75747}.reg.dat
2010-02-07 07:27:50 . 2010-02-07 07:27:50 132 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829}.reg.dat
2010-02-07 07:27:49 . 2010-02-07 07:27:49 390 ----a-w- C:\Qoobox\Quarantine\Registry_backups\BHO-{8e41e543-e069-4197-8608-e8b4c2f75747}.reg.dat
2010-02-07 07:27:48 . 2010-02-07 07:27:49 391 ----a-w- C:\Qoobox\Quarantine\Registry_backups\BHO-{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}.reg.dat
2010-02-07 07:27:43 . 2010-02-07 07:27:45 118 ----a-w- C:\Qoobox\Quarantine\Registry_backups\URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C}.reg.dat
2010-02-07 07:14:08 . 2010-02-07 10:12:26 7,286 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2010-02-07 06:53:52 . 2010-02-07 09:55:32 175 ----a-w- C:\Qoobox\Quarantine\catchme.log
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\CLEANUP_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 306 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\CLEANUP_MENU.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\ECARDS_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 4,124 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\ECARDS_MENU.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\SPELL_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\GAMES_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 488 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\GAMES_MENU.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\EMAIL_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\WAYBACK_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\SHOP_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\TRAVEL_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\DIRLIST_CHBMP.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 4,121 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\DIRLIST_MENU.dat.vir
2010-01-05 15:47:10 . 2010-01-05 15:47:10 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\WP_CHBMP.dat.vir
2010-01-05 15:47:09 . 2010-01-05 15:47:09 5,302 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\lookfor.dat.vir
2010-01-05 15:47:09 . 2010-01-05 15:47:09 1,743 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\majorse.dat.vir
2010-01-05 15:47:09 . 2010-01-05 15:47:09 482 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\rootmenu.dat.vir
2010-01-05 15:47:09 . 2010-01-05 15:47:09 16,051 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\services.dat.vir
2010-01-05 15:47:07 . 2010-01-05 15:47:07 1,350 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Cache\COMMON\YP_CHBMP.dat.vir
2009-12-25 08:35:14 . 2010-02-06 00:03:04 9 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\confirm.dat.vir
2009-12-25 08:34:57 . 2010-02-06 00:03:04 34,747 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Languages\TBR5_DE.cab.vir
2009-12-25 08:34:57 . 2010-02-06 00:03:04 17,498 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Languages\TBR5_PT-BR.cab.vir
2009-12-25 08:34:57 . 2009-12-25 08:34:57 18,022 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Languages\TBR5_PT.cab.vir
2009-12-25 08:34:57 . 2009-12-25 08:34:57 17,776 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Languages\TBR5_IT.cab.vir
2009-12-25 08:34:57 . 2009-12-25 08:34:57 18,349 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Languages\TBR5_ES.cab.vir
2009-12-25 08:34:57 . 2010-02-06 00:03:04 10,847 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Languages\TBR5_EN.cab.vir
2009-12-25 08:34:57 . 2009-12-25 08:34:57 17,545 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\Languages\TBR5_CS.cab.vir
2009-12-25 08:34:57 . 2008-02-29 02:41:28 160,768 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\CTipsDef.dll.vir
2009-12-25 08:34:56 . 2008-02-29 02:41:28 1,142,784 ----a-w- C:\Qoobox\Quarantine\C\PROGRA~1\Crawler\ctbr.dll.vir
2009-12-25 08:34:56 . 2008-02-29 02:41:28 891,392 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\ctbcomm.dll.vir
2009-12-25 08:34:56 . 2007-11-08 06:31:20 219,648 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\CUpdate.exe.vir
2009-12-25 08:34:55 . 2008-02-29 02:41:30 1,978,208 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\CToolbar.exe.vir
2009-09-11 13:47:10 . 2009-12-10 01:27:04 87,608 ----a-w- C:\Qoobox\Quarantine\C\Users\MINO\AppData\Roaming\inst.exe.vir
2009-09-11 11:20:36 . 2009-09-11 11:20:37 142,592 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\drivers\sp_rsdrv2.sys.vir
2009-06-20 15:36:20 . 2009-06-20 15:43:33 223,110 ----a-w- C:\Qoobox\Quarantine\C\log.txt.vir
2009-01-31 07:36:21 . 2009-05-10 06:54:35 108,552 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\drivers\avgtdix.sys.vir
2008-09-21 10:24:12 . 2009-09-08 07:29:06 335,240 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\drivers\avgldx86.sys.vir
2008-02-15 07:46:48 . 2008-02-15 07:46:48 67 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\TBR5LanguageAct\info.ini.vir
2008-02-13 13:12:54 . 2008-02-13 13:12:54 42,456 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Crawler\TBR5LanguageAct\language.ini.vir
TOHLE TEDY NEVIM CO JE!!!!!! :boxed:

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 16:05
od meteorolog
použijte http://sweb.cz/Marinus/T-Cleaner.exe - pro potvrzení stiskněte vždy klávesu A nebo Enter (utilita může být označena antivirem jako vir - po použití ji smažte)

potom CCleaner - položky Čistič a Registry - čištění opakujte do odstranění všech problémů

a nakonec ATF Cleaner - http://www.atribune.org/ccount/click.php?id=1:

po spuštění staženého souboru se objeví okno:

Obrázek

zatrhněte Select All, klikněte na Empty Selected a Exit

stejným způsobem vymažte případně cache Firefoxu a Opery :-)

restartujte PC

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 17:14
od mino14051965
meteorolog píše:použijte http://sweb.cz/Marinus/T-Cleaner.exe - pro potvrzení stiskněte vždy klávesu A nebo Enter (utilita může být označena antivirem jako vir - po použití ji smažte)

potom CCleaner - položky Čistič a Registry - čištění opakujte do odstranění všech problémů

a nakonec ATF Cleaner - http://www.atribune.org/ccount/click.php?id=1:

po spuštění staženého souboru se objeví okno:

Obrázek

zatrhněte Select All, klikněte na Empty Selected a Exit

stejným způsobem vymažte případně cache Firefoxu a Opery :-)

restartujte PC

ZDRAVIM....
Jste fakt dobrej,to myslim vazne!!!,ale asi ste si neprecetl zacatek,coj sem psal.Jsem laik,tak se nezlobte.Znovu tedy prikladam text. :Provedl jsem operaci,kterou jste mi poradil,ovsem ikony(programy atd.), co mam na plose nejdou spustit klasickym dvouklikem,pise nasledujici: " Pokus pouzit neplatnou operaci na klic registru,ktery je oznacen pro odstraneni ".WAS IST DAS????
Dokonce se nemuzu dostat klasicky do ovladacich panelu.
Co dal??? Na NET me to pustilo jen jako s povolenim SPRAVCE,co jsem zkousel,tak pise to co jsem uvedl nahore.
Jsou v mem notebooku jeste veci,ktere by meli byt vymazany????Je to nejak poznat nebo videt z logu,co je treba jeste za vasi pomoci vymazat????
A jeste jedna vec.Nainstaloval jsem program pro Vistu......VISTA MANAGER-trial,ale nevim,jak ji odinstalovat,abych neco nepotentockoval.

Jinak zatim MOCMOC diky a cekam na dalsi rady,at je muj comp v poradku. A jak vypada log od ComboFixu,je to v poradku???JSEM OTRAVNEJ,ZE???? :oops:

To co jste mi napsal nahore udelam.
CCleaner mi nasel pri REGISTRY(hledej problemy) toto:

Nepoužívaná koncovka souborů .2010 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.2010
Problém ActiveX/COM LocalServer32\C:\PROGRA~1\Crawler\CToolbar.exe HKCR\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
Problém ActiveX/COM LocalServer32\C:\PROGRA~1\Crawler\CToolbar.exe HKCR\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Problém ActiveX/COM LocalServer32\C:\PROGRA~1\Crawler\CToolbar.exe HKCR\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Problém instalačního souboru C:\Program Files\MSXML 4.0 HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders
Zastaralý klíč softwaru Wget HKCU\Software\Wget

CO S TIM?????? PORADTE

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 17:39
od meteorolog
mino14051965 píše:asi ste si neprecetl zacatek,coj sem psal
A jeste jedna vec.Nainstaloval jsem program pro Vistu......VISTA MANAGER-trial,ale nevim,jak ji odinstalovat,abych neco nepotentockoval.
CCleaner mi nasel pri REGISTRY(hledej problemy) toto:
CO S TIM?????? PORADTE
začátek jsem si přečetl

VISTA MANAGER - nemá vlastní odinstalátor? pokud ne, použijte Revo Uninstaller - http://www.studna.cz/8117/systemove-nas ... installer/ - možná může za vaše problémy s ikonami (možný konflikt s ASUS Data Security Manager)

ty problémy, co našel CCleaner nechte všechny opravit :)

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 18:29
od mino14051965
Tak jsem provedl operace,ktere jste mi poradil,system zatim bezi!!!!!!!!!!
Chtel bych MOOOOOC podekovat za ochotu,za to,ze jste se mi venoval. :worship: :P
Muzu se na Vas obratit,kdyz budou nejake problemy?????
Vyzkousim,jak mi pracuje ANY VIDEO CONVERTER,ConvertXtoDVD .....uvidime jak se budou chovat.Doufam,ze uz se nebudou
samovolne vypinat......
A jeste bych mel dotaz.Co je z techto programu nejlepe pouzivat,lepe receno,co Vy by ste nechal v pocitaci:
TweakNow PowerPack 2009
TweakNow RegCleaner
TuneUp Utielities 2008
CCleaner
Programy jsou v anglictine,potreboval bych u Tweak navod,abych se orientoval jako clovek.
Jinak TweakNow PowerPack mi nasel cca 75 invalid souboru ve slozce REGISTRY CLEANER,jsou zlute oznacene,jen nevim jak je zkopirovat,abyste se na to kouknul . :cry:
Zkuste mi poradit.

Re: Prosiiiiimm o kontrolu logu ..RSIT

Napsal: 07 úno 2010 18:45
od meteorolog
nemáte zač :-)

já používám CCleaner a TuneUp Utilities, TweakNow neznám, takže ani neporadím - doporučuji ty první 2, další podobné programy vidím jako zbytečné a pro systém zatěžující, takže je doporučuji odinstalovat :-)