
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosim o kontrolu logu - zamrzlo PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 30
- Registrován: 05 úno 2010 17:37
prosim o kontrolu logu - zamrzlo PC
Mozete prosim niekto pozriet tento log? Zamrzlo mi PC pri praci a ked som ho po chvili necinnosti resetol (po na citani tej uvodnej ciernej obrazovky po starte - neviem ako sa tomu hovori) vypisalo ze kontroluje disky C a D ci nedoslo ku chybe a po asi 3minutach vypisalo ze 100% hotovo a spustil sa windows. Zatial ide vsetko dobre zda sa, no moze tam, byt daka skryta haved... tak chcem mat istotu, vdaka
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2010-02-13 11:42:44
Microsoft Windows 7 Professional Service Pack 2
System drive C: has 64 GB (64%) free of 100 GB
Total RAM: 2047 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:46, on 13. 2. 2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\admin\Desktop\cistenie PC registre, malware,\RSIT.exe
C:\Program Files\trend micro\admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoznam.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
--
End of file - 4234 bytes
======Scheduled tasks folder======
C:\Windows\tasks\NeroLiveEpgUpdate-admin-PC_admin.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pre aplikáciu Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2008-06-11 61816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
"AdobeVersionCue"=C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe [2004-03-25 1732608]
"NWEReboot"= []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acrobat Assistant.lnk - C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-02-10 18:07:36 ----A---- C:\Windows\system32\kernel32.dll
2010-02-10 18:07:35 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\apphelp.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\quartz.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msrle32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\avifil32.dll
2010-02-10 18:07:07 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-07 14:05:51 ----D---- C:\Windows\system32\QuickTime
2010-02-07 14:05:51 ----D---- C:\ProgramData\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files\Macromedia
2010-02-07 14:05:11 ----D---- C:\Windows\Downloaded Installations
2010-02-07 13:36:06 ----D---- C:\Users\admin\AppData\Roaming\Malwarebytes
2010-02-07 13:36:01 ----D---- C:\ProgramData\Malwarebytes
2010-02-07 13:36:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-07 13:24:11 ----D---- C:\Program Files\CCleaner
2010-02-06 11:36:41 ----D---- C:\Windows\system32\appmgmt
2010-02-06 11:05:49 ----D---- C:\Program Files\TrendMicro
2010-02-06 10:36:32 ----D---- C:\Program Files\trend micro
2010-02-06 10:36:31 ----D---- C:\rsit
2010-01-31 08:24:19 ----D---- C:\Users\admin\AppData\Roaming\Google
2010-01-30 18:25:44 ----D---- C:\Users\admin\AppData\Roaming\skypePM
2010-01-30 18:20:16 ----D---- C:\Program Files\Google
2010-01-30 18:19:05 ----D---- C:\ProgramData\Skype
2010-01-27 17:21:06 ----A---- C:\Windows\system32\winlogon.exe
2010-01-27 17:21:06 ----A---- C:\Windows\explorer.exe
2010-01-24 15:32:29 ----D---- C:\Program Files\MSXML 4.0
2010-01-23 19:48:58 ----D---- C:\Users\admin\AppData\Roaming\Nero
2010-01-23 19:34:44 ----A---- C:\Windows\Irremote.ini
2010-01-23 19:26:01 ----D---- C:\ProgramData\Nero
2010-01-23 19:26:00 ----D---- C:\Program Files\Common Files\Nero
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-01-23 17:59:36 ----A---- C:\Users\admin\AppData\Roaming\inst.exe
2010-01-23 17:59:35 ----D---- C:\Users\admin\AppData\Roaming\Vso
2010-01-23 17:59:19 ----A---- C:\Windows\system32\wvc1dmod.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\vp7vfw.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\sipr3260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\Pncrt.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv43260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv33260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv23260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\cook3260.dll
2010-01-23 17:59:16 ----D---- C:\Program Files\VSO
2010-01-23 17:35:37 ----D---- C:\Users\admin\AppData\Roaming\Ahead
2010-01-23 17:13:58 ----D---- C:\Program Files\Nero
2010-01-23 17:13:58 ----D---- C:\Program Files\Common Files\Ahead
2010-01-23 13:15:11 ----D---- C:\ProgramData\Adobe
2010-01-23 13:13:30 ----D---- C:\Windows\system32\Adobe
2010-01-23 13:13:30 ----A---- C:\Windows\system32\FileOps.exe
2010-01-23 13:07:05 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-23 13:05:37 ----HD---- C:\Program Files\Installshield Installation Information
2010-01-23 12:59:14 ----D---- C:\Program Files\YouTube Downloader
2010-01-23 12:54:42 ----D---- C:\Program Files\CamStudio
2010-01-23 12:43:01 ----D---- C:\Program Files\Adobe
2010-01-23 11:45:12 ----D---- C:\Program Files\7-Zip
2010-01-23 11:41:00 ----D---- C:\Program Files\Microsoft Works
2010-01-23 11:40:50 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-23 11:40:50 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-23 11:40:38 ----D---- C:\Windows\PCHEALTH
2010-01-23 11:40:38 ----D---- C:\Program Files\Microsoft.NET
2010-01-23 11:39:01 ----D---- C:\ProgramData\Microsoft Help
2010-01-23 11:39:01 ----D---- C:\Program Files\Microsoft Office
2010-01-23 11:34:35 ----D---- C:\Users\admin\AppData\Roaming\WinRAR
2010-01-23 11:34:02 ----D---- C:\Program Files\WinRAR
2010-01-23 10:48:19 ----D---- C:\Program Files\Common Files\Adobe
2010-01-22 20:32:23 ----D---- C:\NOD32 antivirus 4
2010-01-22 20:26:00 ----D---- C:\ProgramData\ESET
2010-01-22 20:26:00 ----D---- C:\Program Files\ESET
2010-01-22 20:23:18 ----SHD---- C:\Windows\Installer
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Macromedia
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Adobe
2010-01-22 20:07:51 ----D---- C:\Windows\system32\Macromed
2010-01-22 19:36:10 ----A---- C:\Windows\system32\msv1_0.dll
2010-01-22 19:35:46 ----HD---- C:\ProgramData\CanonBJ
2010-01-22 19:34:51 ----A---- C:\Windows\system32\MRT.exe
2010-01-22 19:34:12 ----A---- C:\Windows\system32\tzres.dll
2010-01-22 19:33:58 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-22 19:33:42 ----A---- C:\Windows\system32\wmp.dll
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winresume.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winload.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\CertEnroll.dll
2010-01-22 19:33:40 ----A---- C:\Windows\system32\wmploc.DLL
2010-01-22 19:33:39 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 19:33:39 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\t2embed.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\fontsub.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\atmfd.dll
2010-01-22 19:33:28 ----A---- C:\Windows\system32\msasn1.dll
2010-01-22 19:32:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-22 19:30:34 ----D---- C:\Users\admin\AppData\Roaming\Identities
2010-01-22 19:30:24 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2010-01-22 19:30:24 ----D---- C:\Users\admin\AppData\Roaming\Media Center Programs
2010-01-22 19:20:46 ----D---- C:\Windows\SoftwareDistribution
2010-01-22 19:18:04 ----D---- C:\Windows\Prefetch
2010-01-22 19:16:50 ----D---- C:\Windows\Panther
2010-01-22 19:11:33 ----D---- C:\Windows.old
======List of files/folders modified in the last 1 months======
2010-02-13 11:42:46 ----D---- C:\Windows\Temp
2010-02-13 11:40:45 ----D---- C:\Windows\System32
2010-02-13 11:40:44 ----D---- C:\Windows\inf
2010-02-13 10:22:25 ----D---- C:\Windows\system32\config
2010-02-12 18:56:50 ----RD---- C:\Program Files
2010-02-12 18:56:19 ----SHD---- C:\System Volume Information
2010-02-10 18:11:44 ----D---- C:\Windows\winsxs
2010-02-10 18:10:48 ----D---- C:\Windows\system32\catroot2
2010-02-10 18:10:41 ----D---- C:\Windows\system32\drivers
2010-02-10 18:07:01 ----D---- C:\Windows\system32\catroot
2010-02-09 18:23:41 ----RSD---- C:\Windows\Fonts
2010-02-07 14:05:51 ----HD---- C:\ProgramData
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files
2010-02-07 14:05:11 ----D---- C:\Windows
2010-02-06 11:37:33 ----D---- C:\Windows\system32\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\system32\wfp
2010-02-05 19:09:22 ----D---- C:\Windows\system32\DriverStore
2010-02-05 19:09:22 ----D---- C:\Windows\rescache
2010-02-05 19:09:22 ----D---- C:\Program Files\Internet Explorer
2010-02-05 19:09:20 ----D---- C:\Windows\system32\wbem
2010-02-05 19:09:20 ----D---- C:\Windows\system32\CodeIntegrity
2010-02-05 19:09:18 ----D---- C:\Windows\AppCompat
2010-02-05 19:09:09 ----D---- C:\Windows\registration
2010-02-05 19:06:49 ----D---- C:\Windows\system32\LogFiles
2010-02-04 18:53:19 ----D---- C:\Windows\system32\NDF
2010-01-31 09:27:11 ----D---- C:\Windows\system32\wdi
2010-01-30 18:15:41 ----D---- C:\Windows\Logs
2010-01-24 10:41:25 ----SD---- C:\ProgramData\Microsoft
2010-01-23 19:25:42 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-23 17:52:05 ----RSD---- C:\Windows\assembly
2010-01-23 16:40:37 ----D---- C:\Program Files\Common Files\System
2010-01-23 16:40:37 ----A---- C:\Windows\win.ini
2010-01-23 11:39:35 ----D---- C:\Windows\ShellNew
2010-01-22 20:07:52 ----D---- C:\Windows\Downloaded Program Files
2010-01-22 19:48:41 ----D---- C:\Windows\Microsoft.NET
2010-01-22 19:36:40 ----D---- C:\Windows\system32\Boot
2010-01-22 19:36:40 ----D---- C:\Windows\ehome
2010-01-22 19:36:40 ----D---- C:\Windows\AppPatch
2010-01-22 19:36:40 ----D---- C:\Program Files\Windows Media Player
2010-01-22 19:34:52 ----D---- C:\Windows\debug
2010-01-22 19:34:19 ----D---- C:\Windows\system32\sk-SK
2010-01-22 19:31:11 ----D---- C:\Windows\system32\restore
2010-01-22 19:30:32 ----SHD---- C:\$Recycle.Bin
2010-01-22 19:30:21 ----RD---- C:\Users
2010-01-22 19:30:11 ----SHD---- C:\Recovery
2010-01-22 19:30:11 ----D---- C:\Windows\system32\Recovery
2010-01-22 19:21:22 ----D---- C:\Windows\system32\sysprep
2010-01-22 19:18:37 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 CompositeBus;Composite Bus Enumerator Driver; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-01-23 47360]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 drmkaud;Microsoft Trusted Audio Drivers; C:\Windows\system32\drivers\drmkaud.sys [2009-07-14 5120]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2009-07-14 8320]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2009-07-14 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2009-07-14 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 AdobeVersionCue;AdobeVersionCue; C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe [2004-03-25 61440]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2010-02-13 11:42:44
Microsoft Windows 7 Professional Service Pack 2
System drive C: has 64 GB (64%) free of 100 GB
Total RAM: 2047 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:46, on 13. 2. 2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\admin\Desktop\cistenie PC registre, malware,\RSIT.exe
C:\Program Files\trend micro\admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoznam.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
--
End of file - 4234 bytes
======Scheduled tasks folder======
C:\Windows\tasks\NeroLiveEpgUpdate-admin-PC_admin.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pre aplikáciu Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2008-06-11 61816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
"AdobeVersionCue"=C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe [2004-03-25 1732608]
"NWEReboot"= []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acrobat Assistant.lnk - C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-02-10 18:07:36 ----A---- C:\Windows\system32\kernel32.dll
2010-02-10 18:07:35 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\apphelp.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\quartz.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msrle32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\avifil32.dll
2010-02-10 18:07:07 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-07 14:05:51 ----D---- C:\Windows\system32\QuickTime
2010-02-07 14:05:51 ----D---- C:\ProgramData\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files\Macromedia
2010-02-07 14:05:11 ----D---- C:\Windows\Downloaded Installations
2010-02-07 13:36:06 ----D---- C:\Users\admin\AppData\Roaming\Malwarebytes
2010-02-07 13:36:01 ----D---- C:\ProgramData\Malwarebytes
2010-02-07 13:36:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-07 13:24:11 ----D---- C:\Program Files\CCleaner
2010-02-06 11:36:41 ----D---- C:\Windows\system32\appmgmt
2010-02-06 11:05:49 ----D---- C:\Program Files\TrendMicro
2010-02-06 10:36:32 ----D---- C:\Program Files\trend micro
2010-02-06 10:36:31 ----D---- C:\rsit
2010-01-31 08:24:19 ----D---- C:\Users\admin\AppData\Roaming\Google
2010-01-30 18:25:44 ----D---- C:\Users\admin\AppData\Roaming\skypePM
2010-01-30 18:20:16 ----D---- C:\Program Files\Google
2010-01-30 18:19:05 ----D---- C:\ProgramData\Skype
2010-01-27 17:21:06 ----A---- C:\Windows\system32\winlogon.exe
2010-01-27 17:21:06 ----A---- C:\Windows\explorer.exe
2010-01-24 15:32:29 ----D---- C:\Program Files\MSXML 4.0
2010-01-23 19:48:58 ----D---- C:\Users\admin\AppData\Roaming\Nero
2010-01-23 19:34:44 ----A---- C:\Windows\Irremote.ini
2010-01-23 19:26:01 ----D---- C:\ProgramData\Nero
2010-01-23 19:26:00 ----D---- C:\Program Files\Common Files\Nero
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-01-23 17:59:36 ----A---- C:\Users\admin\AppData\Roaming\inst.exe
2010-01-23 17:59:35 ----D---- C:\Users\admin\AppData\Roaming\Vso
2010-01-23 17:59:19 ----A---- C:\Windows\system32\wvc1dmod.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\vp7vfw.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\sipr3260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\Pncrt.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv43260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv33260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv23260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\cook3260.dll
2010-01-23 17:59:16 ----D---- C:\Program Files\VSO
2010-01-23 17:35:37 ----D---- C:\Users\admin\AppData\Roaming\Ahead
2010-01-23 17:13:58 ----D---- C:\Program Files\Nero
2010-01-23 17:13:58 ----D---- C:\Program Files\Common Files\Ahead
2010-01-23 13:15:11 ----D---- C:\ProgramData\Adobe
2010-01-23 13:13:30 ----D---- C:\Windows\system32\Adobe
2010-01-23 13:13:30 ----A---- C:\Windows\system32\FileOps.exe
2010-01-23 13:07:05 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-23 13:05:37 ----HD---- C:\Program Files\Installshield Installation Information
2010-01-23 12:59:14 ----D---- C:\Program Files\YouTube Downloader
2010-01-23 12:54:42 ----D---- C:\Program Files\CamStudio
2010-01-23 12:43:01 ----D---- C:\Program Files\Adobe
2010-01-23 11:45:12 ----D---- C:\Program Files\7-Zip
2010-01-23 11:41:00 ----D---- C:\Program Files\Microsoft Works
2010-01-23 11:40:50 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-23 11:40:50 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-23 11:40:38 ----D---- C:\Windows\PCHEALTH
2010-01-23 11:40:38 ----D---- C:\Program Files\Microsoft.NET
2010-01-23 11:39:01 ----D---- C:\ProgramData\Microsoft Help
2010-01-23 11:39:01 ----D---- C:\Program Files\Microsoft Office
2010-01-23 11:34:35 ----D---- C:\Users\admin\AppData\Roaming\WinRAR
2010-01-23 11:34:02 ----D---- C:\Program Files\WinRAR
2010-01-23 10:48:19 ----D---- C:\Program Files\Common Files\Adobe
2010-01-22 20:32:23 ----D---- C:\NOD32 antivirus 4
2010-01-22 20:26:00 ----D---- C:\ProgramData\ESET
2010-01-22 20:26:00 ----D---- C:\Program Files\ESET
2010-01-22 20:23:18 ----SHD---- C:\Windows\Installer
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Macromedia
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Adobe
2010-01-22 20:07:51 ----D---- C:\Windows\system32\Macromed
2010-01-22 19:36:10 ----A---- C:\Windows\system32\msv1_0.dll
2010-01-22 19:35:46 ----HD---- C:\ProgramData\CanonBJ
2010-01-22 19:34:51 ----A---- C:\Windows\system32\MRT.exe
2010-01-22 19:34:12 ----A---- C:\Windows\system32\tzres.dll
2010-01-22 19:33:58 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-22 19:33:42 ----A---- C:\Windows\system32\wmp.dll
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winresume.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winload.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\CertEnroll.dll
2010-01-22 19:33:40 ----A---- C:\Windows\system32\wmploc.DLL
2010-01-22 19:33:39 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 19:33:39 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\t2embed.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\fontsub.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\atmfd.dll
2010-01-22 19:33:28 ----A---- C:\Windows\system32\msasn1.dll
2010-01-22 19:32:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-22 19:30:34 ----D---- C:\Users\admin\AppData\Roaming\Identities
2010-01-22 19:30:24 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2010-01-22 19:30:24 ----D---- C:\Users\admin\AppData\Roaming\Media Center Programs
2010-01-22 19:20:46 ----D---- C:\Windows\SoftwareDistribution
2010-01-22 19:18:04 ----D---- C:\Windows\Prefetch
2010-01-22 19:16:50 ----D---- C:\Windows\Panther
2010-01-22 19:11:33 ----D---- C:\Windows.old
======List of files/folders modified in the last 1 months======
2010-02-13 11:42:46 ----D---- C:\Windows\Temp
2010-02-13 11:40:45 ----D---- C:\Windows\System32
2010-02-13 11:40:44 ----D---- C:\Windows\inf
2010-02-13 10:22:25 ----D---- C:\Windows\system32\config
2010-02-12 18:56:50 ----RD---- C:\Program Files
2010-02-12 18:56:19 ----SHD---- C:\System Volume Information
2010-02-10 18:11:44 ----D---- C:\Windows\winsxs
2010-02-10 18:10:48 ----D---- C:\Windows\system32\catroot2
2010-02-10 18:10:41 ----D---- C:\Windows\system32\drivers
2010-02-10 18:07:01 ----D---- C:\Windows\system32\catroot
2010-02-09 18:23:41 ----RSD---- C:\Windows\Fonts
2010-02-07 14:05:51 ----HD---- C:\ProgramData
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files
2010-02-07 14:05:11 ----D---- C:\Windows
2010-02-06 11:37:33 ----D---- C:\Windows\system32\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\system32\wfp
2010-02-05 19:09:22 ----D---- C:\Windows\system32\DriverStore
2010-02-05 19:09:22 ----D---- C:\Windows\rescache
2010-02-05 19:09:22 ----D---- C:\Program Files\Internet Explorer
2010-02-05 19:09:20 ----D---- C:\Windows\system32\wbem
2010-02-05 19:09:20 ----D---- C:\Windows\system32\CodeIntegrity
2010-02-05 19:09:18 ----D---- C:\Windows\AppCompat
2010-02-05 19:09:09 ----D---- C:\Windows\registration
2010-02-05 19:06:49 ----D---- C:\Windows\system32\LogFiles
2010-02-04 18:53:19 ----D---- C:\Windows\system32\NDF
2010-01-31 09:27:11 ----D---- C:\Windows\system32\wdi
2010-01-30 18:15:41 ----D---- C:\Windows\Logs
2010-01-24 10:41:25 ----SD---- C:\ProgramData\Microsoft
2010-01-23 19:25:42 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-23 17:52:05 ----RSD---- C:\Windows\assembly
2010-01-23 16:40:37 ----D---- C:\Program Files\Common Files\System
2010-01-23 16:40:37 ----A---- C:\Windows\win.ini
2010-01-23 11:39:35 ----D---- C:\Windows\ShellNew
2010-01-22 20:07:52 ----D---- C:\Windows\Downloaded Program Files
2010-01-22 19:48:41 ----D---- C:\Windows\Microsoft.NET
2010-01-22 19:36:40 ----D---- C:\Windows\system32\Boot
2010-01-22 19:36:40 ----D---- C:\Windows\ehome
2010-01-22 19:36:40 ----D---- C:\Windows\AppPatch
2010-01-22 19:36:40 ----D---- C:\Program Files\Windows Media Player
2010-01-22 19:34:52 ----D---- C:\Windows\debug
2010-01-22 19:34:19 ----D---- C:\Windows\system32\sk-SK
2010-01-22 19:31:11 ----D---- C:\Windows\system32\restore
2010-01-22 19:30:32 ----SHD---- C:\$Recycle.Bin
2010-01-22 19:30:21 ----RD---- C:\Users
2010-01-22 19:30:11 ----SHD---- C:\Recovery
2010-01-22 19:30:11 ----D---- C:\Windows\system32\Recovery
2010-01-22 19:21:22 ----D---- C:\Windows\system32\sysprep
2010-01-22 19:18:37 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 CompositeBus;Composite Bus Enumerator Driver; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-01-23 47360]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 drmkaud;Microsoft Trusted Audio Drivers; C:\Windows\system32\drivers\drmkaud.sys [2009-07-14 5120]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2009-07-14 8320]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2009-07-14 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2009-07-14 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 AdobeVersionCue;AdobeVersionCue; C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe [2004-03-25 61440]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: prosim o kontrolu logu - zamrzlo PC
Dobrý den, pošlete ještě log z Combofix:
Stáhneme na plochu, ukončíme všechna aktivní okna a spustíme ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Po spuštění potvrdíme podmínky užití
- Dále postupujeme dle pokynů, během aplikování ComboFixu neklikejte do zobrazujících se oken
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt
- ComboFix je třeba spustit pod účtem s právy administrátora
Stáhneme na plochu, ukončíme všechna aktivní okna a spustíme ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Po spuštění potvrdíme podmínky užití
- Dále postupujeme dle pokynů, během aplikování ComboFixu neklikejte do zobrazujících se oken
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt
- ComboFix je třeba spustit pod účtem s právy administrátora
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
-
- Návštěvník
- Příspěvky: 30
- Registrován: 05 úno 2010 17:37
Re: prosim o kontrolu logu - zamrzlo PC
ComboFix som spustil zacalo to nacitavat a po nacitani sa nic nedeje. Ani nic nevypise.... Robim nieco zle?
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: prosim o kontrolu logu - zamrzlo PC
to je 32-bit nebo 64-bit systém?
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
-
- Návštěvník
- Příspěvky: 30
- Registrován: 05 úno 2010 17:37
Re: prosim o kontrolu logu - zamrzlo PC
tu jeten log z CF- uz sa to spustilo:
ComboFix 10-02-12.01 - admin . 02. 2010 13:03:04.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1051.18.2047.1364 [GMT 1:00]
Running from: c:\users\admin\Desktop\cistenie PC registre, malware,\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\admin\AppData\Roaming\inst.exe
.
((((((((((((((((((((((((( Files Created from 2010-01-13 to 2010-02-13 )))))))))))))))))))))))))))))))
.
2010-02-13 12:07 . 2010-02-13 12:07 -------- d-----w- c:\users\admin\AppData\Local\temp
2010-02-13 12:07 . 2010-02-13 12:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-07 13:08 . 2010-02-07 13:08 -------- d-----w- c:\users\admin\AppData\Local\Macromedia
2010-02-07 13:05 . 2010-02-07 13:05 45056 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{91057632-CA70-413C-B628-2D3CDBBB906B}\ARPPRODUCTICON.exe
2010-02-07 13:05 . 2010-02-07 13:05 45056 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
2010-02-07 13:05 . 2010-02-07 13:05 -------- d-----w- c:\windows\system32\QuickTime
2010-02-07 13:05 . 2010-02-07 13:07 -------- d-----w- c:\program files\Common Files\Macromedia
2010-02-07 13:05 . 2010-02-07 13:06 -------- d-----w- c:\program files\Macromedia
2010-02-07 13:05 . 2010-02-07 13:05 -------- d-----w- c:\windows\Downloaded Installations
2010-02-07 12:36 . 2010-02-07 12:36 -------- d-----w- c:\users\admin\AppData\Roaming\Malwarebytes
2010-02-07 12:36 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 12:36 . 2010-02-07 12:36 -------- d-----w- c:\programdata\Malwarebytes
2010-02-07 12:36 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-07 12:36 . 2010-02-07 12:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 12:24 . 2010-02-07 12:24 -------- d-----w- c:\program files\CCleaner
2010-02-06 10:05 . 2010-02-06 10:05 388096 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-06 10:05 . 2010-02-06 10:05 -------- d-----w- c:\program files\TrendMicro
2010-02-06 09:36 . 2010-02-13 10:42 -------- d-----w- c:\program files\trend micro
2010-02-06 09:36 . 2010-02-06 10:42 -------- d-----w- C:\rsit
2010-02-04 17:51 . 2010-02-04 17:51 -------- d-----w- c:\users\admin\AppData\Local\Diagnostics
2010-01-31 07:24 . 2010-02-06 10:38 -------- d-----w- c:\users\admin\AppData\Local\Google
2010-01-30 17:25 . 2010-02-06 09:29 -------- d-----w- c:\users\admin\AppData\Roaming\skypePM
2010-01-30 17:20 . 2010-02-07 07:52 -------- d-----w- c:\program files\Google
2010-01-30 17:19 . 2010-02-06 10:37 -------- d-----w- c:\programdata\Skype
2010-01-27 16:21 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-01-27 16:21 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-01-24 14:32 . 2010-01-24 14:32 -------- d-----w- c:\program files\MSXML 4.0
2010-01-24 10:32 . 2010-02-09 17:16 -------- d-----w- c:\users\admin\AppData\Local\Nero
2010-01-23 18:48 . 2010-02-05 18:08 -------- d-----w- c:\users\admin\AppData\Roaming\Nero
2010-01-23 18:26 . 2010-01-24 09:19 -------- d-----w- c:\programdata\Nero
2010-01-23 18:26 . 2010-01-23 18:40 -------- d-----w- c:\program files\Common Files\Nero
2010-01-23 16:59 . 2010-01-23 16:59 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-01-23 16:59 . 2010-01-23 16:59 47360 ----a-w- c:\users\admin\AppData\Roaming\pcouffin.sys
2010-01-23 16:59 . 2010-01-23 17:03 -------- d-----w- c:\users\admin\AppData\Roaming\Vso
2010-01-23 16:59 . 2009-09-02 20:58 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-01-23 16:59 . 2009-09-02 20:58 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-01-23 16:59 . 2009-09-02 20:58 217127 ----a-w- c:\windows\system32\drv43260.dll
2010-01-23 16:59 . 2009-09-02 20:58 208935 ----a-w- c:\windows\system32\drv33260.dll
2010-01-23 16:59 . 2009-09-02 20:58 176165 ----a-w- c:\windows\system32\drv23260.dll
2010-01-23 16:59 . 2009-09-02 20:58 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-01-23 16:59 . 2009-09-02 20:57 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-01-23 16:59 . 2010-01-23 16:59 -------- d-----w- c:\program files\VSO
2010-01-23 16:35 . 2010-01-24 09:20 -------- d-----w- c:\users\admin\AppData\Roaming\Ahead
2010-01-23 16:13 . 2010-01-23 18:34 -------- d-----w- c:\program files\Nero
2010-01-23 16:13 . 2010-01-23 16:14 -------- d-----w- c:\program files\Common Files\Ahead
2010-01-23 13:05 . 2010-01-23 13:05 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-01-23 12:30 . 2002-02-02 01:02 75776 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\WinRAR\patch.exe
2010-01-23 12:13 . 2010-01-23 12:13 -------- d-----w- c:\windows\system32\Adobe
2010-01-23 12:13 . 2001-10-26 22:16 16384 ----a-w- c:\windows\system32\FileOps.exe
2010-01-23 12:07 . 2010-02-07 13:05 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-23 12:05 . 2010-01-23 12:16 -------- d--h--w- c:\program files\Installshield Installation Information
2010-01-23 11:59 . 2010-01-23 11:59 -------- d-----w- c:\program files\YouTube Downloader
2010-01-23 11:54 . 2010-01-23 11:54 -------- d-----w- c:\program files\CamStudio
2010-01-23 10:45 . 2010-01-23 10:45 -------- d-----w- c:\program files\7-Zip
2010-01-23 10:41 . 2010-01-23 15:41 -------- d-----w- c:\program files\Microsoft Works
2010-01-23 10:40 . 2010-01-23 10:40 -------- d-----w- c:\windows\PCHEALTH
2010-01-23 10:40 . 2010-01-23 10:40 -------- d-----w- c:\program files\Microsoft.NET
2010-01-23 10:39 . 2010-01-23 10:39 -------- d-----w- c:\users\admin\AppData\Local\Microsoft Help
2010-01-23 10:39 . 2010-02-10 17:08 -------- d-----w- c:\programdata\Microsoft Help
2010-01-23 10:35 . 2010-01-23 10:35 -------- d-----w- c:\users\admin\AppData\Local\ESET
2010-01-23 10:26 . 2010-02-05 18:09 -------- d-----w- c:\users\admin\AppData\Local\RapidSharing.eu
2010-01-23 09:48 . 2010-02-05 18:28 -------- d-----w- c:\users\admin\AppData\Local\Adobe
2010-01-23 09:48 . 2010-02-12 17:30 65120 ----a-w- c:\users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-23 09:48 . 2010-02-05 18:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-22 19:32 . 2010-01-22 19:32 -------- d-----w- C:\NOD32 antivirus 4
2010-01-22 19:26 . 2010-01-22 19:26 -------- d-----w- c:\program files\ESET
2010-01-22 19:23 . 2010-02-12 17:56 -------- d-sh--w- c:\windows\Installer
2010-01-22 19:07 . 2010-01-22 19:07 -------- d-----w- c:\windows\system32\Macromed
2010-01-22 18:36 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-01-22 18:35 . 2010-01-22 18:35 -------- d--h--w- c:\programdata\CanonBJ
2010-01-22 18:35 . 2009-07-14 01:15 70144 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNBPP3.DLL
2010-01-22 18:34 . 2009-10-29 07:22 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-22 18:32 . 2010-02-13 10:59 -------- d-----w- c:\windows\system32\wbem\Performance
2010-01-22 18:20 . 2010-01-22 18:20 0 ----a-w- c:\windows\ativpsrm.bin
2010-01-22 18:16 . 2010-01-22 18:30 -------- d-----w- c:\windows\Panther
2010-01-22 18:11 . 2010-01-22 18:11 -------- d-----w- C:\Windows.old
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 17:38 . 2010-02-12 17:38 338 ----a-w- c:\users\admin\AppData\Roaming\settings.dat
2010-02-06 10:35 . 2010-02-06 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-01-30 17:25 . 2010-01-30 17:25 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-01-24 09:41 . 2010-01-24 09:41 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-01-18 23:29 . 2010-02-10 17:07 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-10 17:07 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-10 17:07 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-10 17:07 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-10 17:07 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-10 17:07 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-10 17:07 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-10 17:07 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-14 10:12 . 2010-01-22 18:33 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-08 03:18 . 2010-02-10 17:07 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-10 17:07 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-19 09:02 . 2010-01-22 18:33 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-10 17:07 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-10 17:07 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-10 17:07 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-10 17:07 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-10 17:07 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-10 17:07 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-10 17:07 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-10 17:07 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-12-18 14:02 . 2009-12-18 14:02 95896 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2009-12-08 11:40 . 2010-02-10 17:07 3955288 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 11:40 . 2010-02-10 17:07 3899464 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 11:32 . 2010-02-10 17:07 292864 ----a-w- c:\windows\system32\apphelp.dll
2009-12-08 08:05 . 2010-02-10 17:07 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-08 08:05 . 2010-02-10 17:07 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-11-16 08:03 . 2009-11-16 08:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-11-16 07:56 . 2009-11-16 07:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
"AdobeVersionCue"="c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2004-03-25 1732608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe [2004-5-24 221276]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-1-23 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [16. 11. 2009 9:03 108792]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [18. 8. 2009 2:36 176128]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16. 11. 2009 9:04 735960]
R2 epfwwfpr;epfwwfpr;c:\windows\System32\drivers\epfwwfpr.sys [18. 12. 2009 15:02 95896]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [25. 6. 2009 3:15 47104]
.
Contents of the 'Scheduled Tasks' folder
2010-01-24 c:\windows\Tasks\NeroLiveEpgUpdate-admin-PC_admin.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 12:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.zoznam.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NWEReboot - (no file)
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-02-13 13:08:51
ComboFix-quarantined-files.txt 2010-02-13 12:08
Pre-Run: 66 085 421 056 bytes free
Post-Run: 66 310 692 864 bytes free
- - End Of File - - 80337B16D337E355E08968B403C064CE
ComboFix 10-02-12.01 - admin . 02. 2010 13:03:04.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1051.18.2047.1364 [GMT 1:00]
Running from: c:\users\admin\Desktop\cistenie PC registre, malware,\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\admin\AppData\Roaming\inst.exe
.
((((((((((((((((((((((((( Files Created from 2010-01-13 to 2010-02-13 )))))))))))))))))))))))))))))))
.
2010-02-13 12:07 . 2010-02-13 12:07 -------- d-----w- c:\users\admin\AppData\Local\temp
2010-02-13 12:07 . 2010-02-13 12:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-07 13:08 . 2010-02-07 13:08 -------- d-----w- c:\users\admin\AppData\Local\Macromedia
2010-02-07 13:05 . 2010-02-07 13:05 45056 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{91057632-CA70-413C-B628-2D3CDBBB906B}\ARPPRODUCTICON.exe
2010-02-07 13:05 . 2010-02-07 13:05 45056 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
2010-02-07 13:05 . 2010-02-07 13:05 -------- d-----w- c:\windows\system32\QuickTime
2010-02-07 13:05 . 2010-02-07 13:07 -------- d-----w- c:\program files\Common Files\Macromedia
2010-02-07 13:05 . 2010-02-07 13:06 -------- d-----w- c:\program files\Macromedia
2010-02-07 13:05 . 2010-02-07 13:05 -------- d-----w- c:\windows\Downloaded Installations
2010-02-07 12:36 . 2010-02-07 12:36 -------- d-----w- c:\users\admin\AppData\Roaming\Malwarebytes
2010-02-07 12:36 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 12:36 . 2010-02-07 12:36 -------- d-----w- c:\programdata\Malwarebytes
2010-02-07 12:36 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-07 12:36 . 2010-02-07 12:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 12:24 . 2010-02-07 12:24 -------- d-----w- c:\program files\CCleaner
2010-02-06 10:05 . 2010-02-06 10:05 388096 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-06 10:05 . 2010-02-06 10:05 -------- d-----w- c:\program files\TrendMicro
2010-02-06 09:36 . 2010-02-13 10:42 -------- d-----w- c:\program files\trend micro
2010-02-06 09:36 . 2010-02-06 10:42 -------- d-----w- C:\rsit
2010-02-04 17:51 . 2010-02-04 17:51 -------- d-----w- c:\users\admin\AppData\Local\Diagnostics
2010-01-31 07:24 . 2010-02-06 10:38 -------- d-----w- c:\users\admin\AppData\Local\Google
2010-01-30 17:25 . 2010-02-06 09:29 -------- d-----w- c:\users\admin\AppData\Roaming\skypePM
2010-01-30 17:20 . 2010-02-07 07:52 -------- d-----w- c:\program files\Google
2010-01-30 17:19 . 2010-02-06 10:37 -------- d-----w- c:\programdata\Skype
2010-01-27 16:21 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-01-27 16:21 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-01-24 14:32 . 2010-01-24 14:32 -------- d-----w- c:\program files\MSXML 4.0
2010-01-24 10:32 . 2010-02-09 17:16 -------- d-----w- c:\users\admin\AppData\Local\Nero
2010-01-23 18:48 . 2010-02-05 18:08 -------- d-----w- c:\users\admin\AppData\Roaming\Nero
2010-01-23 18:26 . 2010-01-24 09:19 -------- d-----w- c:\programdata\Nero
2010-01-23 18:26 . 2010-01-23 18:40 -------- d-----w- c:\program files\Common Files\Nero
2010-01-23 16:59 . 2010-01-23 16:59 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-01-23 16:59 . 2010-01-23 16:59 47360 ----a-w- c:\users\admin\AppData\Roaming\pcouffin.sys
2010-01-23 16:59 . 2010-01-23 17:03 -------- d-----w- c:\users\admin\AppData\Roaming\Vso
2010-01-23 16:59 . 2009-09-02 20:58 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2010-01-23 16:59 . 2009-09-02 20:58 65602 ----a-w- c:\windows\system32\cook3260.dll
2010-01-23 16:59 . 2009-09-02 20:58 217127 ----a-w- c:\windows\system32\drv43260.dll
2010-01-23 16:59 . 2009-09-02 20:58 208935 ----a-w- c:\windows\system32\drv33260.dll
2010-01-23 16:59 . 2009-09-02 20:58 176165 ----a-w- c:\windows\system32\drv23260.dll
2010-01-23 16:59 . 2009-09-02 20:58 102439 ----a-w- c:\windows\system32\sipr3260.dll
2010-01-23 16:59 . 2009-09-02 20:57 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2010-01-23 16:59 . 2010-01-23 16:59 -------- d-----w- c:\program files\VSO
2010-01-23 16:35 . 2010-01-24 09:20 -------- d-----w- c:\users\admin\AppData\Roaming\Ahead
2010-01-23 16:13 . 2010-01-23 18:34 -------- d-----w- c:\program files\Nero
2010-01-23 16:13 . 2010-01-23 16:14 -------- d-----w- c:\program files\Common Files\Ahead
2010-01-23 13:05 . 2010-01-23 13:05 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-01-23 12:30 . 2002-02-02 01:02 75776 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\WinRAR\patch.exe
2010-01-23 12:13 . 2010-01-23 12:13 -------- d-----w- c:\windows\system32\Adobe
2010-01-23 12:13 . 2001-10-26 22:16 16384 ----a-w- c:\windows\system32\FileOps.exe
2010-01-23 12:07 . 2010-02-07 13:05 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-23 12:05 . 2010-01-23 12:16 -------- d--h--w- c:\program files\Installshield Installation Information
2010-01-23 11:59 . 2010-01-23 11:59 -------- d-----w- c:\program files\YouTube Downloader
2010-01-23 11:54 . 2010-01-23 11:54 -------- d-----w- c:\program files\CamStudio
2010-01-23 10:45 . 2010-01-23 10:45 -------- d-----w- c:\program files\7-Zip
2010-01-23 10:41 . 2010-01-23 15:41 -------- d-----w- c:\program files\Microsoft Works
2010-01-23 10:40 . 2010-01-23 10:40 -------- d-----w- c:\windows\PCHEALTH
2010-01-23 10:40 . 2010-01-23 10:40 -------- d-----w- c:\program files\Microsoft.NET
2010-01-23 10:39 . 2010-01-23 10:39 -------- d-----w- c:\users\admin\AppData\Local\Microsoft Help
2010-01-23 10:39 . 2010-02-10 17:08 -------- d-----w- c:\programdata\Microsoft Help
2010-01-23 10:35 . 2010-01-23 10:35 -------- d-----w- c:\users\admin\AppData\Local\ESET
2010-01-23 10:26 . 2010-02-05 18:09 -------- d-----w- c:\users\admin\AppData\Local\RapidSharing.eu
2010-01-23 09:48 . 2010-02-05 18:28 -------- d-----w- c:\users\admin\AppData\Local\Adobe
2010-01-23 09:48 . 2010-02-12 17:30 65120 ----a-w- c:\users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-23 09:48 . 2010-02-05 18:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-22 19:32 . 2010-01-22 19:32 -------- d-----w- C:\NOD32 antivirus 4
2010-01-22 19:26 . 2010-01-22 19:26 -------- d-----w- c:\program files\ESET
2010-01-22 19:23 . 2010-02-12 17:56 -------- d-sh--w- c:\windows\Installer
2010-01-22 19:07 . 2010-01-22 19:07 -------- d-----w- c:\windows\system32\Macromed
2010-01-22 18:36 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-01-22 18:35 . 2010-01-22 18:35 -------- d--h--w- c:\programdata\CanonBJ
2010-01-22 18:35 . 2009-07-14 01:15 70144 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNBPP3.DLL
2010-01-22 18:34 . 2009-10-29 07:22 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-22 18:32 . 2010-02-13 10:59 -------- d-----w- c:\windows\system32\wbem\Performance
2010-01-22 18:20 . 2010-01-22 18:20 0 ----a-w- c:\windows\ativpsrm.bin
2010-01-22 18:16 . 2010-01-22 18:30 -------- d-----w- c:\windows\Panther
2010-01-22 18:11 . 2010-01-22 18:11 -------- d-----w- C:\Windows.old
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-12 17:38 . 2010-02-12 17:38 338 ----a-w- c:\users\admin\AppData\Roaming\settings.dat
2010-02-06 10:35 . 2010-02-06 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-01-30 17:25 . 2010-01-30 17:25 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-01-24 09:41 . 2010-01-24 09:41 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-01-18 23:29 . 2010-02-10 17:07 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-10 17:07 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-10 17:07 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-10 17:07 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-10 17:07 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-10 17:07 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-10 17:07 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-10 17:07 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-14 10:12 . 2010-01-22 18:33 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-08 03:18 . 2010-02-10 17:07 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-10 17:07 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-19 09:02 . 2010-01-22 18:33 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-10 17:07 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-10 17:07 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-10 17:07 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-10 17:07 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-10 17:07 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-10 17:07 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-10 17:07 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-10 17:07 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-12-18 14:02 . 2009-12-18 14:02 95896 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2009-12-08 11:40 . 2010-02-10 17:07 3955288 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 11:40 . 2010-02-10 17:07 3899464 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 11:32 . 2010-02-10 17:07 292864 ----a-w- c:\windows\system32\apphelp.dll
2009-12-08 08:05 . 2010-02-10 17:07 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-08 08:05 . 2010-02-10 17:07 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-11-16 08:03 . 2009-11-16 08:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-11-16 07:56 . 2009-11-16 07:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
"AdobeVersionCue"="c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2004-03-25 1732608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe [2004-5-24 221276]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-1-23 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [16. 11. 2009 9:03 108792]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [18. 8. 2009 2:36 176128]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16. 11. 2009 9:04 735960]
R2 epfwwfpr;epfwwfpr;c:\windows\System32\drivers\epfwwfpr.sys [18. 12. 2009 15:02 95896]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [25. 6. 2009 3:15 47104]
.
Contents of the 'Scheduled Tasks' folder
2010-01-24 c:\windows\Tasks\NeroLiveEpgUpdate-admin-PC_admin.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 12:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.zoznam.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NWEReboot - (no file)
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-02-13 13:08:51
ComboFix-quarantined-files.txt 2010-02-13 12:08
Pre-Run: 66 085 421 056 bytes free
Post-Run: 66 310 692 864 bytes free
- - End Of File - - 80337B16D337E355E08968B403C064CE
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: prosim o kontrolu logu - zamrzlo PC
vypadá to v pořádku 
ještě použijte http://sweb.cz/Marinus/T-Cleaner.exe - pro potvrzení stiskněte vždy klávesu A nebo Enter
potom CCleaner - položky Čistič a Registry - čištění opakujte do odstranění všech problémů
a nakonec ATF Cleaner - http://www.atribune.org/ccount/click.php?id=1:
po spuštění staženého souboru se objeví okno:

zatrhněte Select All, klikněte na Empty Selected a Exit
stejným způsobem vymažte případně cache Firefoxu a Opery
restartujte PC

ještě použijte http://sweb.cz/Marinus/T-Cleaner.exe - pro potvrzení stiskněte vždy klávesu A nebo Enter
potom CCleaner - položky Čistič a Registry - čištění opakujte do odstranění všech problémů
a nakonec ATF Cleaner - http://www.atribune.org/ccount/click.php?id=1:
po spuštění staženého souboru se objeví okno:

zatrhněte Select All, klikněte na Empty Selected a Exit
stejným způsobem vymažte případně cache Firefoxu a Opery

restartujte PC
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
-
- Návštěvník
- Příspěvky: 30
- Registrován: 05 úno 2010 17:37
Re: prosim o kontrolu logu - zamrzlo PC
Zda sa ze je to uz v poriadku ale jednu vec nechapem a to internet - stahovanie ide velmi pomaly malo by ist okolo 1MB/s ale ide len 314.02 kB/s vsak aj maly subor cca 3-megovy taha minutu. Mozem dakde v systeme zistit preco ide tak pomaly download? Alebo ako zistit v com je problem? Poskytovatel tvrdi ze z ich strany je vsetko v poriadku... dik
este MBAM - ten opat nic nenasiel... nechapem kde moze byt problem?
este MBAM - ten opat nic nenasiel... nechapem kde moze byt problem?
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: prosim o kontrolu logu - zamrzlo PC
zkuste aktualizovat ovladače síťové karty
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
-
- Návštěvník
- Příspěvky: 30
- Registrován: 05 úno 2010 17:37
Re: prosim o kontrolu logu - zamrzlo PC
Prosim kde to najdem? (neviem ci mam vobec sietovu kartu kedze mam iba jedno PC - v tychto technickych veciach sa velmi neorientujem) Nasiel som iba aktualizaciu v: spravca zariadeni - sietove adaptery - Atheros L1 Gigabit Ethernet 10/100/1000Base-T Controller. Mysleli ste toto? Ale ta aktualizacia aj tak nepomohla. Download je stale iba okolo 200-300kB/s. Fakt netusim v com by mohol byt problem...
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: prosim o kontrolu logu - zamrzlo PC
ano, tou kartou jsem myslel ten Atheros - zkuste ještě mrknout sem: http://www.atheros.cz/
jinak zkuste vyměnit síťový kabel a dobré by bylo vyzkoušet rychlost downloadu i na jiném PC, abychom vyloučili nebo potvrdili chybu na straně poskytovatele
jinak zkuste vyměnit síťový kabel a dobré by bylo vyzkoušet rychlost downloadu i na jiném PC, abychom vyloučili nebo potvrdili chybu na straně poskytovatele
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
-
- Návštěvník
- Příspěvky: 30
- Registrován: 05 úno 2010 17:37
Re: prosim o kontrolu logu - zamrzlo PC
Tak aj druhe PC pripojene na net ukazuje rychlost downloadu okolo 200-400kB/s. Stahovanie ale v skutocnosti ide od 1,2MB/s a postupne klesa az ku 700kB/s a kolise medzi tymito hodnotami. Vymenil som aj kabel ale nepomohlo to (teda co sa tyka merania cez speedmetre) na stranke UPC mi odporucil pouzivatel pouzivat ich speedmeter a ten ukazuje v priemere300kB/s.
Takze zhrnutie: net ide vcelku dobre aj ked nie na max., stahovanie ide tiez ale slabsie ako by malo no a speedmetre ukazuju nizku rychlost downloadu.
Takze v com moze byt este problem? dik
Takze zhrnutie: net ide vcelku dobre aj ked nie na max., stahovanie ide tiez ale slabsie ako by malo no a speedmetre ukazuju nizku rychlost downloadu.
Takze v com moze byt este problem? dik
-
- Vzorný návštěvník
- Příspěvky: 308
- Registrován: 07 led 2007 15:20
- Bydliště: Pardubice
Re: prosim o kontrolu logu - zamrzlo PC
zavolejte na technickou podporu UPC a tohle všechno jim řekněte - chyba je určitě u nich, mě to dělalo to samé a 3 dny po tom, co jsem jim zavolal, to opravili
takže se nenechte odbýt, i kdyby k vám měli poslat technika

"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)
"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)