
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o pomoc s Win32/Heur
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o pomoc s Win32/Heur
Zdravím, prosím o pomoc, po naběhnutí NB mi AVG nnajde spoustu virů viz screen.
Je to vážné? Jak mám tu havěť zrušit.
Díky
http://yfrog.com/3zvirrrrrrrrrrj
Tady je log RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Tomas at 2010-03-17 14:53:59
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 226 GB (76%) free of 297 GB
Total RAM: 3002 MB (65% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\PCConfidential.job
C:\Windows\tasks\RegPowerClean.job
C:\Windows\tasks\RPCReminder.job
C:\Windows\tasks\User_Feed_Synchronization-{8418694D-8FB5-4C47-93FD-625F68D20685}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-07-17 279944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-03-11 1598744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-01 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-01 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - C:\Program Files\Search Settings\SearchSettings.dll [2009-12-16 1109504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-10-19 1345336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2008-03-27 501056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\1002011624\ICQToolBar.dll [2010-01-03 1019128]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-07-17 279944]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-10-19 1345336]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-01 279664]
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-10-28 150040]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-10-28 178712]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-10-28 154136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-12-04 1410344]
"UpdateLBPShortCut"=C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePSTShortCut"=C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-12-24 210216]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-10-10 206128]
"UpdateP2GoShortCut"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-10-30 210216]
"UpdatePDIRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-12-08 432432]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2008-03-13 106496]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-06-03 475136]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-03-11 2059544]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-10-20 111928]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2009-09-08 468264]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-08-20 2387968]
"Software Informer"=C:\Program Files\Software Informer\softinfo.exe [2009-11-25 2035712]
"fsm"= []
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]
"ICQ"=~C:\Program Files\ICQ7.0\ICQ.exe silent loginmode=4 []
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-23 39408]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Remote Control.lnk - C:\Program Files\MSI\DigiVox Duo Utilities\AFRCtl.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-10-28 221184]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Windows\system32\winlogon.exe"="C:\Windows\system32\winlogon.exe:*:enabled:@shell32.dll,-1"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - %SystemRoot%\System32\CScript.exe "%1" %*
.vbs - open - %SystemRoot%\System32\CScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-17 14:53:59 ----D---- C:\rsit
2010-03-17 14:53:59 ----D---- C:\Program Files\trend micro
2010-03-17 07:09:55 ----RSHD---- C:\RECYCLER
2010-03-11 18:01:03 ----A---- C:\Windows\system32\avgrsstx.dll
2010-03-08 16:17:04 ----D---- C:\Program Files\DVDFab 6
2010-03-06 01:15:40 ----D---- C:\Program Files\Daisy
2010-02-24 08:53:15 ----D---- C:\Program Files\Nero
2010-02-24 08:47:24 ----A---- C:\Windows\system32\jscript.dll
2010-02-24 08:47:20 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 08:47:06 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 08:47:05 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 08:47:01 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 08:47:00 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 08:47:00 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 08:46:58 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 08:46:57 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 08:46:57 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-02-23 20:25:03 ----D---- C:\ProgramData\HP Product Assistant
2010-02-22 14:13:40 ----D---- C:\PI3LP1W1
2010-02-20 14:54:23 ----D---- C:\Program Files\Haali
2010-02-20 14:54:10 ----A---- C:\Windows\system32\pncrt.dll
2010-02-20 13:27:19 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2010-02-19 14:35:46 ----A---- C:\Windows\system32\ff_vfw.dll
2010-02-19 14:35:45 ----A---- C:\Windows\system32\pthreadGC2.dll
2010-02-19 14:35:44 ----D---- C:\Program Files\ffdshow
2010-02-19 14:35:17 ----D---- C:\Program Files\AviSynth 2.5
2010-02-19 14:34:51 ----D---- C:\Program Files\Avi2Dvd
2010-02-19 14:11:28 ----D---- C:\Program Files\Steel RunAs
2010-02-19 13:00:11 ----D---- C:\Users\Tomas\AppData\Roaming\STOIK
2010-02-18 14:17:38 ----D---- C:\Users\Tomas\AppData\Roaming\AnvSoft
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomwave.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomtran.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomqtde.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscommpgenc.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscommpgdec.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomframe.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomflvdec.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomaudioencoder.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomaudiodata.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\writelib.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\videotrans.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\videoformat.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\videocore.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\imgscaler.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\img_utils.dll
2010-02-18 14:06:36 ----D---- C:\Program Files\Zealot Software
2010-02-18 14:06:36 ----A---- C:\Windows\system32\xvid.dll
2010-02-18 14:06:36 ----A---- C:\Windows\system32\dvdlib.dll
2010-02-18 13:53:17 ----A---- C:\Windows\system32\msvcp70.dll
2010-02-18 13:53:17 ----A---- C:\Windows\system32\divx.dll
2010-02-18 13:53:16 ----D---- C:\Program Files\Acala DivX DVD Player Assist
2010-02-18 13:28:35 ----D---- C:\Users\Tomas\AppData\Roaming\Search Settings
======List of files/folders modified in the last 1 months======
2010-03-17 14:53:59 ----RD---- C:\Program Files
2010-03-17 14:53:59 ----D---- C:\Windows\Prefetch
2010-03-17 14:53:57 ----D---- C:\Windows\Temp
2010-03-17 14:53:46 ----A---- C:\ProgramData\HPWALog.txt
2010-03-17 14:41:39 ----D---- C:\Windows
2010-03-17 14:32:55 ----D---- C:\Users\Tomas\AppData\Roaming\Software Informer
2010-03-17 14:30:27 ----HD---- C:\ProgramData
2010-03-17 14:30:06 ----A---- C:\ProgramData\hpqp.ini
2010-03-17 13:32:02 ----D---- C:\Program Files\Common Files\LightScribe
2010-03-17 13:31:09 ----D---- C:\Program Files\QuickTime
2010-03-17 13:25:12 ----D---- C:\Program Files\Windows Media Player
2010-03-17 13:25:11 ----D---- C:\Program Files\Windows Mail
2010-03-17 13:24:59 ----D---- C:\Program Files\Movie Maker
2010-03-17 13:24:28 ----D---- C:\Program Files\MediaCoder
2010-03-17 13:24:20 ----D---- C:\Program Files\Internet Explorer
2010-03-17 13:14:44 ----D---- C:\Program Files\Search Settings
2010-03-17 13:03:15 ----D---- C:\Windows\System32
2010-03-17 13:03:09 ----D---- C:\Windows\system32\wbem
2010-03-17 07:30:53 ----D---- C:\Windows\system32\drivers
2010-03-17 07:24:29 ----D---- C:\Program Files\Recepty doma
2010-03-17 07:24:24 ----D---- C:\Program Files\ProgDVB
2010-03-16 23:02:57 ----SHD---- C:\System Volume Information
2010-03-15 17:53:39 ----A---- C:\ProgramData\hpqp.txt
2010-03-15 05:46:18 ----D---- C:\Windows\Debug
2010-03-14 16:50:32 ----D---- C:\Windows\inf
2010-03-14 16:50:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-14 16:48:14 ----D---- C:\Windows\system32\catroot
2010-03-14 11:34:42 ----D---- C:\Windows\system32\catroot2
2010-03-12 06:07:11 ----D---- C:\Windows\winsxs
2010-03-12 06:03:06 ----SHD---- C:\Windows\Installer
2010-03-12 06:03:01 ----HD---- C:\Config.Msi
2010-03-12 06:03:00 ----D---- C:\ProgramData\Microsoft Help
2010-03-11 17:51:55 ----D---- C:\Program Files\ICQ7.0
2010-03-06 00:09:08 ----D---- C:\Users\Tomas\AppData\Roaming\Skype
2010-03-06 00:00:51 ----D---- C:\Users\Tomas\AppData\Roaming\skypePM
2010-03-03 16:05:07 ----A---- C:\Windows\system32\ezsvc7x.dll
2010-03-02 06:30:12 ----A---- C:\Windows\system32\mrt.exe
2010-02-28 16:53:45 ----D---- C:\Users\Tomas\AppData\Roaming\HP
2010-02-28 16:53:45 ----D---- C:\ProgramData\CyberLink
2010-02-28 16:53:44 ----D---- C:\ProgramData\HP
2010-02-28 16:52:59 ----D---- C:\Windows\system32\Tasks
2010-02-28 16:52:58 ----RSD---- C:\Windows\Fonts
2010-02-28 16:52:23 ----D---- C:\Program Files\HP
2010-02-28 16:52:16 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-27 23:47:32 ----D---- C:\Program Files\Google
2010-02-26 10:23:11 ----D---- C:\Users\Tomas\AppData\Roaming\Mozilla
2010-02-25 19:47:27 ----D---- C:\Users\Tomas\AppData\Roaming\ICQ
2010-02-25 12:44:25 ----D---- C:\Windows\rescache
2010-02-25 12:22:03 ----D---- C:\Windows\system32\sk-SK
2010-02-25 12:22:03 ----D---- C:\Windows\system32\cs-CZ
2010-02-25 12:21:59 ----D---- C:\Windows\AppPatch
2010-02-24 08:52:55 ----D---- C:\ProgramData\Nero
2010-02-24 08:52:55 ----D---- C:\Program Files\Common Files\Nero
2010-02-20 14:58:21 ----D---- C:\Program Files\Common Files
2010-02-20 13:27:30 ----RSD---- C:\Windows\assembly
2010-02-19 14:26:14 ----D---- C:\Users\Tomas\AppData\Roaming\Vso
2010-02-19 14:26:14 ----A---- C:\Users\Tomas\AppData\Roaming\inst.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-03-11 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-03-11 29512]
R1 AvgTdiX;AVG Free Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-03-11 242696]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};Power Control [2010/02/28 16:53:02]; \??\C:\Program Files\HP\QuickPlay\000.fcl [2009-09-08 87536]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2006-11-10 18688]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-12-19 1093120]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-10-28 2476544]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-09-22 112128]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-12-23 138240]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt.sys [2009-06-03 407040]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-12-04 204976]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 AF15BDA;AF9015 BDA Filter; C:\Windows\system32\DRIVERS\AF15BDA.sys [2010-01-12 327296]
S3 avngq42x;avngq42x; C:\Windows\system32\drivers\avngq42x.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
S3 Pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\Pcouffin.sys [2010-02-17 47360]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-12-29 60416]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-03-11 916760]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-03-11 308064]
R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-10-09 94208]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 Recovery Service for Windows;Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [2008-12-23 365952]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-11-26 247152]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\STacSV.exe [2009-06-03 217170]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-12-04 222512]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-10-23 223232]
S2 gupdate1ca71231b6578a4;Služba Google Update (gupdate1ca71231b6578a4); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-11-29 133104]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-23 182768]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
-----------------EOF-----------------
Je to vážné? Jak mám tu havěť zrušit.
Díky
http://yfrog.com/3zvirrrrrrrrrrj
Tady je log RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Tomas at 2010-03-17 14:53:59
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 226 GB (76%) free of 297 GB
Total RAM: 3002 MB (65% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\PCConfidential.job
C:\Windows\tasks\RegPowerClean.job
C:\Windows\tasks\RPCReminder.job
C:\Windows\tasks\User_Feed_Synchronization-{8418694D-8FB5-4C47-93FD-625F68D20685}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-07-17 279944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-03-11 1598744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-01 279664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-01 812528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - C:\Program Files\Search Settings\SearchSettings.dll [2009-12-16 1109504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-10-19 1345336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2008-03-27 501056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\1002011624\ICQToolBar.dll [2010-01-03 1019128]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-07-17 279944]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-10-19 1345336]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-01 279664]
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-10-28 150040]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-10-28 178712]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-10-28 154136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-12-04 1410344]
"UpdateLBPShortCut"=C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePSTShortCut"=C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-12-24 210216]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-10-10 206128]
"UpdateP2GoShortCut"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-10-30 210216]
"UpdatePDIRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-12-08 432432]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2008-03-13 106496]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-06-03 475136]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-03-11 2059544]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-10-20 111928]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2009-09-08 468264]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-08-20 2387968]
"Software Informer"=C:\Program Files\Software Informer\softinfo.exe [2009-11-25 2035712]
"fsm"= []
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]
"ICQ"=~C:\Program Files\ICQ7.0\ICQ.exe silent loginmode=4 []
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-23 39408]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Remote Control.lnk - C:\Program Files\MSI\DigiVox Duo Utilities\AFRCtl.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-10-28 221184]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Windows\system32\winlogon.exe"="C:\Windows\system32\winlogon.exe:*:enabled:@shell32.dll,-1"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - %SystemRoot%\System32\CScript.exe "%1" %*
.vbs - open - %SystemRoot%\System32\CScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-17 14:53:59 ----D---- C:\rsit
2010-03-17 14:53:59 ----D---- C:\Program Files\trend micro
2010-03-17 07:09:55 ----RSHD---- C:\RECYCLER
2010-03-11 18:01:03 ----A---- C:\Windows\system32\avgrsstx.dll
2010-03-08 16:17:04 ----D---- C:\Program Files\DVDFab 6
2010-03-06 01:15:40 ----D---- C:\Program Files\Daisy
2010-02-24 08:53:15 ----D---- C:\Program Files\Nero
2010-02-24 08:47:24 ----A---- C:\Windows\system32\jscript.dll
2010-02-24 08:47:20 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 08:47:06 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 08:47:05 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 08:47:01 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 08:47:00 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 08:47:00 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 08:47:00 ----A---- C:\Windows\system32\msdrm.dll
2010-02-24 08:46:58 ----A---- C:\Windows\system32\gameux.dll
2010-02-24 08:46:57 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-02-24 08:46:57 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-02-23 20:25:03 ----D---- C:\ProgramData\HP Product Assistant
2010-02-22 14:13:40 ----D---- C:\PI3LP1W1
2010-02-20 14:54:23 ----D---- C:\Program Files\Haali
2010-02-20 14:54:10 ----A---- C:\Windows\system32\pncrt.dll
2010-02-20 13:27:19 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2010-02-19 14:35:46 ----A---- C:\Windows\system32\ff_vfw.dll
2010-02-19 14:35:45 ----A---- C:\Windows\system32\pthreadGC2.dll
2010-02-19 14:35:44 ----D---- C:\Program Files\ffdshow
2010-02-19 14:35:17 ----D---- C:\Program Files\AviSynth 2.5
2010-02-19 14:34:51 ----D---- C:\Program Files\Avi2Dvd
2010-02-19 14:11:28 ----D---- C:\Program Files\Steel RunAs
2010-02-19 13:00:11 ----D---- C:\Users\Tomas\AppData\Roaming\STOIK
2010-02-18 14:17:38 ----D---- C:\Users\Tomas\AppData\Roaming\AnvSoft
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomwave.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomtran.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomqtde.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscommpgenc.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscommpgdec.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomframe.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomflvdec.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomaudioencoder.dll
2010-02-18 14:06:38 ----A---- C:\Windows\system32\viscomaudiodata.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\writelib.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\videotrans.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\videoformat.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\videocore.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\imgscaler.dll
2010-02-18 14:06:37 ----A---- C:\Windows\system32\img_utils.dll
2010-02-18 14:06:36 ----D---- C:\Program Files\Zealot Software
2010-02-18 14:06:36 ----A---- C:\Windows\system32\xvid.dll
2010-02-18 14:06:36 ----A---- C:\Windows\system32\dvdlib.dll
2010-02-18 13:53:17 ----A---- C:\Windows\system32\msvcp70.dll
2010-02-18 13:53:17 ----A---- C:\Windows\system32\divx.dll
2010-02-18 13:53:16 ----D---- C:\Program Files\Acala DivX DVD Player Assist
2010-02-18 13:28:35 ----D---- C:\Users\Tomas\AppData\Roaming\Search Settings
======List of files/folders modified in the last 1 months======
2010-03-17 14:53:59 ----RD---- C:\Program Files
2010-03-17 14:53:59 ----D---- C:\Windows\Prefetch
2010-03-17 14:53:57 ----D---- C:\Windows\Temp
2010-03-17 14:53:46 ----A---- C:\ProgramData\HPWALog.txt
2010-03-17 14:41:39 ----D---- C:\Windows
2010-03-17 14:32:55 ----D---- C:\Users\Tomas\AppData\Roaming\Software Informer
2010-03-17 14:30:27 ----HD---- C:\ProgramData
2010-03-17 14:30:06 ----A---- C:\ProgramData\hpqp.ini
2010-03-17 13:32:02 ----D---- C:\Program Files\Common Files\LightScribe
2010-03-17 13:31:09 ----D---- C:\Program Files\QuickTime
2010-03-17 13:25:12 ----D---- C:\Program Files\Windows Media Player
2010-03-17 13:25:11 ----D---- C:\Program Files\Windows Mail
2010-03-17 13:24:59 ----D---- C:\Program Files\Movie Maker
2010-03-17 13:24:28 ----D---- C:\Program Files\MediaCoder
2010-03-17 13:24:20 ----D---- C:\Program Files\Internet Explorer
2010-03-17 13:14:44 ----D---- C:\Program Files\Search Settings
2010-03-17 13:03:15 ----D---- C:\Windows\System32
2010-03-17 13:03:09 ----D---- C:\Windows\system32\wbem
2010-03-17 07:30:53 ----D---- C:\Windows\system32\drivers
2010-03-17 07:24:29 ----D---- C:\Program Files\Recepty doma
2010-03-17 07:24:24 ----D---- C:\Program Files\ProgDVB
2010-03-16 23:02:57 ----SHD---- C:\System Volume Information
2010-03-15 17:53:39 ----A---- C:\ProgramData\hpqp.txt
2010-03-15 05:46:18 ----D---- C:\Windows\Debug
2010-03-14 16:50:32 ----D---- C:\Windows\inf
2010-03-14 16:50:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-14 16:48:14 ----D---- C:\Windows\system32\catroot
2010-03-14 11:34:42 ----D---- C:\Windows\system32\catroot2
2010-03-12 06:07:11 ----D---- C:\Windows\winsxs
2010-03-12 06:03:06 ----SHD---- C:\Windows\Installer
2010-03-12 06:03:01 ----HD---- C:\Config.Msi
2010-03-12 06:03:00 ----D---- C:\ProgramData\Microsoft Help
2010-03-11 17:51:55 ----D---- C:\Program Files\ICQ7.0
2010-03-06 00:09:08 ----D---- C:\Users\Tomas\AppData\Roaming\Skype
2010-03-06 00:00:51 ----D---- C:\Users\Tomas\AppData\Roaming\skypePM
2010-03-03 16:05:07 ----A---- C:\Windows\system32\ezsvc7x.dll
2010-03-02 06:30:12 ----A---- C:\Windows\system32\mrt.exe
2010-02-28 16:53:45 ----D---- C:\Users\Tomas\AppData\Roaming\HP
2010-02-28 16:53:45 ----D---- C:\ProgramData\CyberLink
2010-02-28 16:53:44 ----D---- C:\ProgramData\HP
2010-02-28 16:52:59 ----D---- C:\Windows\system32\Tasks
2010-02-28 16:52:58 ----RSD---- C:\Windows\Fonts
2010-02-28 16:52:23 ----D---- C:\Program Files\HP
2010-02-28 16:52:16 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-27 23:47:32 ----D---- C:\Program Files\Google
2010-02-26 10:23:11 ----D---- C:\Users\Tomas\AppData\Roaming\Mozilla
2010-02-25 19:47:27 ----D---- C:\Users\Tomas\AppData\Roaming\ICQ
2010-02-25 12:44:25 ----D---- C:\Windows\rescache
2010-02-25 12:22:03 ----D---- C:\Windows\system32\sk-SK
2010-02-25 12:22:03 ----D---- C:\Windows\system32\cs-CZ
2010-02-25 12:21:59 ----D---- C:\Windows\AppPatch
2010-02-24 08:52:55 ----D---- C:\ProgramData\Nero
2010-02-24 08:52:55 ----D---- C:\Program Files\Common Files\Nero
2010-02-20 14:58:21 ----D---- C:\Program Files\Common Files
2010-02-20 13:27:30 ----RSD---- C:\Windows\assembly
2010-02-19 14:26:14 ----D---- C:\Users\Tomas\AppData\Roaming\Vso
2010-02-19 14:26:14 ----A---- C:\Users\Tomas\AppData\Roaming\inst.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-03-11 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-03-11 29512]
R1 AvgTdiX;AVG Free Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-03-11 242696]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};Power Control [2010/02/28 16:53:02]; \??\C:\Program Files\HP\QuickPlay\000.fcl [2009-09-08 87536]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2006-11-10 18688]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-12-19 1093120]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-10-28 2476544]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-09-22 112128]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-12-23 138240]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt.sys [2009-06-03 407040]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-12-04 204976]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 AF15BDA;AF9015 BDA Filter; C:\Windows\system32\DRIVERS\AF15BDA.sys [2010-01-12 327296]
S3 avngq42x;avngq42x; C:\Windows\system32\drivers\avngq42x.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\Windows\system32\DRIVERS\k750bus.sys [2005-02-11 55216]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
S3 Pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\Pcouffin.sys [2010-02-17 47360]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-12-29 60416]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-03-11 916760]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-03-11 308064]
R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-10-09 94208]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 Recovery Service for Windows;Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [2008-12-23 365952]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-11-26 247152]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\STacSV.exe [2009-06-03 217170]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-12-04 222512]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-10-23 223232]
S2 gupdate1ca71231b6578a4;Služba Google Update (gupdate1ca71231b6578a4); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-11-29 133104]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-23 182768]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
-----------------EOF-----------------
Naposledy upravil(a) Duhen dne 17 bře 2010 15:01, celkem upraveno 1 x.
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o pomoc s Win32/Heur

- Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary
- Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrazí stránka s licenčními podmínkami, pokračujte stisknutím tlačítka "Ano"
- Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna
- Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.
- Během skenování může být počítač restartován.
Re: Prosím o pomoc s Win32/Heur
Jdu na to , za moment je to tady !
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o pomoc s Win32/Heur
No nějak se mi nedaří spustit combofix, stále mi to háže !!varování!! Není bezpečné dále pokračovat že jsou narušeny jeho části a tak .....
pak dám OK a combofix se ztratí z plochy

- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o pomoc s Win32/Heur

Re: Prosím o pomoc s Win32/Heur
Tak jsem při stažení combofix přejmenoval na cistka a spustil v nouzáku, ale háže to to samé
Obsah součástí combofixu byly narušeny
Stahněte si prosím novou kopii z:http://www.bleepingcomputer.com/com.....atd
Poznámka: Můžete být infikování parazitickým souborovým virem (typický: virut)
ooooo to snad né virut mám ten notebook zapojen v routeru snad mi nenapadne další PC !
Obsah součástí combofixu byly narušeny
Stahněte si prosím novou kopii z:http://www.bleepingcomputer.com/com.....atd
Poznámka: Můžete být infikování parazitickým souborovým virem (typický: virut)

- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o pomoc s Win32/Heur
Stáhl jste nový Combofix v nouzovém režimu
Počítač od ostatních odpojte 


Re: Prosím o pomoc s Win32/Heur
Myslíte stáhl nebo spustil. V nouzovém režimi se na net nedostanu myslím, abych ho stáhl?
V nouzáku jsem ho spustil a to samé!
V nouzáku jsem ho spustil a to samé!
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o pomoc s Win32/Heur
Jděte do nouzového systému s prací v síti a tam už při stahování přejmenujte ComboFix a spusťte.
Re: Prosím o pomoc s Win32/Heur
Jooo ták, jsem totiž v v nouzáku bez sítí..tak jo zkusím....
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o pomoc s Win32/Heur
hmm , tak stále ta tabulka přesto že jsem před uložením combofix přejmenoval na cistka.com 
něco ho nechce pustit asi nějaká ta havěť....co se s tím dá dělat?

něco ho nechce pustit asi nějaká ta havěť....co se s tím dá dělat?
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o pomoc s Win32/Heur

- Podle návodu v odkazu nainstalujte, poté dejte úplný sken.
- Nic nemažte
MBAM má občas falešné detekce a mohl by smazat např. systémové soubory.
- Log vložte sem.