Stránka 1 z 1

Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 15:45
od Torres69
Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-03-29 15:20:03
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (18%) free of 30 GB
Total RAM: 511 MB (13% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:21:38, on 29.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - *{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: (no name) - *{b552069b-7b85-492f-8b98-ccf409c93a39} - (no file)
O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: OddsMaker Toolbar - {b552069b-7b85-492f-8b98-ccf409c93a39} - C:\Program Files\OddsMaker\tbOdd1.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: OddsMaker Toolbar - {b552069b-7b85-492f-8b98-ccf409c93a39} - C:\Program Files\OddsMaker\tbOdd1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Startup: syspck32.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Program Files\Betway\Poker\MPPoker.exe
O9 - Extra button: Gnuf Casino - {8FE9B27A-BDCD-4d27-A430-4DC0B58D01B0} - C:\Program Files\Gnuf\Casino\casinogame.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exe
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exe
O9 - Extra button: Gnuf Poker - {A99C8F70-4D5B-482c-8854-05BC0BB8B182} - C:\Program Files\Gnuf\Poker\MPPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Tell Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\TellPokerMPP\MPPoker.exe (HKCU)
O9 - Extra button: UB - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\UB\UB.lnk (HKCU)
O9 - Extra 'Tools' menuitem: UB - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\UB\UB.lnk (HKCU)
O9 - Extra button: 365 Bonitas - {2afed132-dab8-4c91-8f14-5e98a6b50ddb} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\365 Bonitas\365 Bonitas.lnk (HKCU)
O9 - Extra button: Spin32 - {3497d1fd-bd47-4046-b167-4e4382228237} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\Spin32\Spin32.lnk (HKCU)
O9 - Extra button: ReeferPoker - {60a501e4-a078-4cb2-8728-3fab4264f3c1} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\ReeferPoker\ReeferPoker.lnk (HKCU)
O9 - Extra button: InterCasino $$$ - {909AAEB6-C2CB-4AB5-A7BB-C33B72AB4BFB} - C:\Documents and Settings\Administrator\Plocha\InterCasino $$$.lnk (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: InterCasino $$$ - {909AAEB6-C2CB-4AB5-A7BB-C33B72AB4BFB} - C:\Documents and Settings\Administrator\Plocha\InterCasino $$$.lnk (file missing) (HKCU)
O9 - Extra button: PokerNordica - {caf8603b-35e9-4f0f-819d-a509543a1e09} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\PokerNordica\PokerNordica.lnk (HKCU)
O9 - Extra button: CarbonPoker - {e4e8c758-34b4-44bb-8ef9-1f0786e81d2d} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\CarbonPoker\CarbonPoker.lnk (HKCU)
O9 - Extra button: Bluff Room - {edd4b28a-e68d-43d4-bfad-689dcd0e7a22} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\Bluff Room\Bluff Room.lnk (HKCU)
O9 - Extra button: FeltStars - {fbd780d2-c26b-46dd-9002-fdf30465c9d2} - C:\Documents and Settings\Administrator\Nabídka Start\Programy\FeltStars\FeltStars.lnk (HKCU)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 14757 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1238525580.job
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1239198963.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1500820517-1177238915-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1500820517-1177238915-500UA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
MediaBar - C:\Program Files\BearShareTb\BearShareDx.dll [2009-08-10 91576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-04-30 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
UrlHelper Class - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll [2009-05-04 398776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-06-02 1004800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-07-23 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-07-23 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b552069b-7b85-492f-8b98-ccf409c93a39}]
OddsMaker Toolbar - C:\Program Files\OddsMaker\tbOdd1.dll [2010-03-07 2349080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-07-23 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-06-01 962808]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-06-02 1004800]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-07-23 256112]
{0974BA1E-64EC-11DE-B2A5-E43756D89593} - MediaBar - C:\Program Files\BearShareTb\BearShareDx.dll [2009-08-10 91576]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
{b552069b-7b85-492f-8b98-ccf409c93a39} - OddsMaker Toolbar - C:\Program Files\OddsMaker\tbOdd1.dll [2010-03-07 2349080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-12-04 8523776]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-12-04 81920]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-06-11 1948440]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-02-26 2140880]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-26 39408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-08-27 133104]
"EA Core"=C:\Program Files\Electronic Arts\EADM\Core.exe [2009-09-03 3342336]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
syspck32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-04-30 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2009-03-01 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\AVG\AVG8\avgam.exe"="C:\Program Files\AVG\AVG8\avgam.exe:*:Enabled:avgam.exe"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{47f3b4d6-1c38-11de-9664-000c76e58681}]
shell\AutoRun\command - cv22.cmd
shell\open\command - cv22.cmd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc8adf8c-f468-11de-ad2c-000c76e58681}]
shell\AutoRun\command - G:\Launcher.exe


======List of files/folders created in the last 1 months======

2010-03-29 15:20:13 ----D---- C:\Program Files\trend micro
2010-03-29 15:20:03 ----D---- C:\rsit
2010-03-29 10:57:22 ----D---- C:\Program Files\ESET
2010-03-29 10:57:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-03-28 02:25:27 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-28 02:21:05 ----D---- C:\WINDOWS\pss
2010-03-26 00:11:47 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Luvin Poker
2010-03-22 16:28:14 ----A---- C:\WINDOWS\system32\UnCasino5.exe
2010-03-22 16:27:30 ----D---- C:\Program Files\InterCasino $$$
2010-03-22 16:26:46 ----D---- C:\Program Files\InterPoker
2010-03-16 03:52:53 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Raineman Poker
2010-03-15 01:57:32 ----D---- C:\Program Files\RedStarPoker
2010-03-14 18:39:23 ----D---- C:\Program Files\VeniceLobby
2010-03-13 15:20:35 ----D---- C:\bwinPoker
2010-03-12 00:40:04 ----D---- C:\Program Files\Spin32
2010-03-11 23:06:08 ----D---- C:\Program Files\FlandersPoker
2010-03-11 09:04:10 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-11 04:03:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-03-07 02:13:56 ----D---- C:\Program Files\Conduit
2010-03-07 02:13:27 ----D---- C:\Program Files\OddsMaker
2010-03-06 18:37:44 ----D---- C:\Program Files\Gnuf
2010-03-06 02:32:41 ----D---- C:\Program Files\BrucePoker.com
2010-03-03 02:13:40 ----D---- C:\Bet24
2010-03-03 01:05:23 ----D---- C:\Documents and Settings\Administrator\Data aplikací\GoHardPoker
2010-03-02 23:45:47 ----D---- C:\Program Files\POKER
2010-03-01 01:05:54 ----D---- C:\Program Files\Cake Poker

======List of files/folders modified in the last 1 months======

2010-03-29 15:21:45 ----D---- C:\WINDOWS\Temp
2010-03-29 15:20:13 ----RD---- C:\Program Files
2010-03-29 11:21:58 ----D---- C:\WINDOWS\system32
2010-03-29 11:21:55 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-29 11:19:33 ----D---- C:\WINDOWS
2010-03-29 11:16:46 ----D---- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2010-03-29 11:05:08 ----SHD---- C:\WINDOWS\Installer
2010-03-29 11:03:49 ----D---- C:\WINDOWS\system32\drivers
2010-03-29 11:03:48 ----HD---- C:\WINDOWS\inf
2010-03-29 11:03:15 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-29 11:03:06 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-29 10:20:37 ----D---- C:\WINDOWS\system32\config
2010-03-29 10:20:15 ----D---- C:\WINDOWS\system32\wbem
2010-03-29 10:20:15 ----D---- C:\WINDOWS\Registration
2010-03-29 10:19:54 ----D---- C:\Program Files\DoylesRoom
2010-03-29 10:19:45 ----D---- C:\Program Files\Everest Poker
2010-03-29 10:19:37 ----D---- C:\Program Files\Absolute Poker
2010-03-29 10:19:28 ----D---- C:\Program Files\UB
2010-03-29 10:18:52 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-29 09:46:47 ----D---- C:\WINDOWS\Debug
2010-03-29 09:28:03 ----A---- C:\WINDOWS\win.ini
2010-03-29 09:28:03 ----A---- C:\WINDOWS\system.ini
2010-03-28 19:46:28 ----D---- C:\Program Files\PokerStars
2010-03-28 02:41:29 ----D---- C:\WINDOWS\twain_32
2010-03-28 02:21:15 ----D---- C:\WINDOWS\Prefetch
2010-03-28 02:08:19 ----D---- C:\Program Files\FeltStars
2010-03-28 01:48:40 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-03-27 00:52:48 ----D---- C:\Program Files\BluffRoom
2010-03-27 00:38:28 ----D---- C:\Program Files\Mozilla Firefox
2010-03-26 00:07:24 ----D---- C:\Program Files\Full Tilt Poker
2010-03-24 14:51:21 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Microgaming
2010-03-24 00:46:40 ----D---- C:\Program Files\ReeferPoker
2010-03-22 03:07:40 ----D---- C:\Documents and Settings\Administrator\Data aplikací\dvdcss
2010-03-21 17:11:23 ----D---- C:\Program Files\CarbonPoker
2010-03-21 16:51:52 ----D---- C:\Program Files\A-Winning-Hand
2010-03-21 16:45:33 ----D---- C:\Program Files\PowerPoker
2010-03-21 15:07:24 ----D---- C:\Program Files\BetClick Poker
2010-03-21 14:38:49 ----D---- C:\Program Files\ParadisePoker
2010-03-18 19:54:33 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-17 01:55:20 ----D---- C:\Program Files\liipoker
2010-03-17 00:35:26 ----D---- C:\Program Files\OnlyPoker
2010-03-16 18:28:46 ----D---- C:\Poker
2010-03-16 16:46:11 ----D---- C:\Documents and Settings\Administrator\Data aplikací\AnoPoker
2010-03-16 16:18:01 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Pokerface52
2010-03-16 13:49:38 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Kong Gaming.com
2010-03-16 13:49:10 ----D---- C:\Program Files\Kong Gaming
2010-03-16 03:21:36 ----D---- C:\Program Files\PokerNordica
2010-03-16 00:07:34 ----D---- C:\Program Files\365Bonitas
2010-03-14 18:37:49 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-03-13 16:23:15 ----D---- C:\Program Files\Poker Heaven
2010-03-13 15:20:15 ----D---- C:\Program Files\bwin
2010-03-12 04:32:24 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Timeless Poker
2010-03-11 04:03:33 ----D---- C:\WINDOWS\system32\dllcache
2010-03-11 04:03:33 ----D---- C:\Program Files\Movie Maker
2010-03-11 04:03:20 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-10 15:08:13 ----D---- C:\Program Files\High Pulse
2010-03-07 18:12:19 ----D---- C:\Program Files\PayNoRake
2010-03-07 02:06:10 ----D---- C:\Program Files\Goal Win
2010-03-06 01:51:42 ----D---- C:\Program Files\Winamax
2010-03-06 00:47:22 ----D---- C:\Program Files\Betsson
2010-03-04 21:20:01 ----D---- C:\Program Files\PokerLoco
2010-03-04 21:18:33 ----D---- C:\Program Files\Betsafe
2010-03-04 20:58:38 ----D---- C:\Program Files\RedKings
2010-03-04 18:27:11 ----D---- C:\Europoker
2010-03-04 03:10:18 ----D---- C:\Program Files\B2BPOKER
2010-03-03 02:30:23 ----D---- C:\Program Files\Action Poker
2010-03-02 07:30:12 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2009-03-31 82380]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-06-11 327688]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-06-17 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-04-30 108552]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-02-26 114984]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-02-26 95872]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\Drivers\StarOpen.sys [2008-11-28 5504]
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-02-26 139192]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-01-24 4127488]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-04-30 29208]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2009-03-01 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-12-04 7435392]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 aipdb8jy;aipdb8jy; C:\WINDOWS\system32\drivers\aipdb8jy.sys []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-04-30 29208]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-04-07 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-04-07 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-04-07 21456]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-03-01 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-03-01 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2008-09-29 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-02-26 810120]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2009-06-01 222968]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-09 152984]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-12-05 935208]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-12-04 155716]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-06-17 906520]
S2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-04-30 298776]
S2 avgfws8;AVG8 Firewall; C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2009-06-11 1368952]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-02-26 33560]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-11-03 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-03 182768]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2003-04-07 65795]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 15:53
od Caroprd111
Zdravím :)

Na logu se pracuje, prosím o strpení.

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 15:56
od Torres69
Dakujem .... prosim surne strasne lebo mi za chvilku asi vybuchne komp:D

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 15:56
od Caroprd111
Obrázek Napište, které z těchto toolbarů (lišt) můžeme odstranit.

O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: OddsMaker Toolbar - {b552069b-7b85-492f-8b98-ccf409c93a39} - C:\Program Files\OddsMaker\tbOdd1.dll



Obrázek Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary
  • Vložte do PC všechny flash disky, které používáte.
  • Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrazí stránka s licenčními podmínkami, pokračujte stisknutím tlačítka "Ano"
  • Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:
  • Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.
  • Během skenování může být počítač restartován.


Obrázek Doporučuji odinstalovat:
C:\Program Files\uTorrent\uTorrent.exe

P2P sítě a jejich klienti jsou potenciálním bezpečnostním rizikem, prakticky neustále jsou zdrojem virů, zbytečně se vystavujete riziku.

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 15:58
od Torres69
Ved to je iba toolbar a mozem aj vsetky odstranit

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 16:00
od Caroprd111
OK, počkám na log z CF. V dalším kroku je společně s havětí smažu. :)

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 19:56
od Torres69
ComboFix 10-03-28.03 - Administrator 29.03.2010 20:43:10.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.250 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-28 do 2010-03-29 )))))))))))))))))))))))))))))))
.

2010-03-29 13:20 . 2010-03-29 13:21 -------- d-----w- c:\program files\trend micro
2010-03-29 13:20 . 2010-03-29 13:22 -------- d-----w- C:\rsit
2010-03-29 08:20 . 2010-03-29 08:20 -------- d-----w- c:\windows\system32\wbem\Repository
2010-03-22 14:28 . 2009-09-29 15:38 108032 ----a-w- c:\windows\system32\UnCasino5.exe
2010-03-22 14:27 . 2010-03-22 14:28 -------- d-----w- c:\program files\InterCasino $$$
2010-03-22 14:26 . 2010-03-22 14:28 -------- d-----w- c:\program files\InterPoker
2010-03-14 23:57 . 2010-03-16 21:07 -------- d-----w- c:\program files\RedStarPoker
2010-03-14 16:39 . 2010-03-14 16:39 -------- d-----w- c:\program files\VeniceLobby
2010-03-13 13:20 . 2010-03-13 13:21 -------- d-----w- C:\bwinPoker
2010-03-11 22:40 . 2010-03-17 01:57 -------- d-----w- c:\program files\Spin32
2010-03-11 21:06 . 2010-03-11 21:06 -------- d-----w- c:\program files\FlandersPoker
2010-03-11 07:04 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-10 21:46 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-07 00:13 . 2010-03-07 00:13 -------- d-----w- c:\program files\Conduit
2010-03-07 00:13 . 2010-03-07 19:16 -------- d-----w- c:\program files\OddsMaker
2010-03-06 16:37 . 2010-03-06 16:38 -------- d-----w- c:\program files\Gnuf
2010-03-06 00:32 . 2010-03-11 23:32 -------- d-----w- c:\program files\BrucePoker.com
2010-03-03 00:13 . 2010-03-04 15:26 -------- d-----w- C:\Bet24
2010-03-02 21:45 . 2010-03-04 19:17 -------- d-----w- c:\program files\POKER
2010-02-28 23:05 . 2010-03-17 00:22 -------- d-----w- c:\program files\Cake Poker
2010-02-28 15:34 . 2010-02-28 15:34 -------- d-----w- c:\program files\Common Files\Radik Software
2010-02-28 15:34 . 2010-02-28 15:34 -------- d-----w- c:\program files\Radik Software
2010-02-28 11:45 . 2010-02-28 12:23 -------- d-----w- c:\program files\Mafia

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-29 09:21 . 2001-10-25 15:00 78030 ----a-w- c:\windows\system32\perfc005.dat
2010-03-29 09:21 . 2001-10-25 15:00 429018 ----a-w- c:\windows\system32\perfh005.dat
2010-03-29 08:19 . 2010-02-22 01:18 -------- d-----w- c:\program files\DoylesRoom
2010-03-29 08:19 . 2009-08-15 23:29 -------- d-----w- c:\program files\Everest Poker
2010-03-29 08:19 . 2010-02-18 01:11 -------- d-----w- c:\program files\Absolute Poker
2010-03-29 08:19 . 2010-02-18 23:50 -------- d-----w- c:\program files\UB
2010-03-28 17:46 . 2009-07-15 18:26 -------- d-----w- c:\program files\PokerStars
2010-03-28 00:08 . 2010-02-19 02:19 -------- d-----w- c:\program files\FeltStars
2010-03-26 22:52 . 2010-02-17 09:22 -------- d-----w- c:\program files\BluffRoom
2010-03-25 22:07 . 2009-05-06 00:15 -------- d-----w- c:\program files\Full Tilt Poker
2010-03-23 22:46 . 2009-11-25 12:38 -------- d-----w- c:\program files\ReeferPoker
2010-03-21 15:11 . 2010-02-21 00:08 -------- d-----w- c:\program files\CarbonPoker
2010-03-21 14:51 . 2010-02-03 17:17 -------- d-----w- c:\program files\A-Winning-Hand
2010-03-21 14:45 . 2010-02-17 19:43 -------- d-----w- c:\program files\PowerPoker
2010-03-21 13:07 . 2010-02-21 18:53 -------- d-----w- c:\program files\BetClick Poker
2010-03-21 12:38 . 2009-07-09 15:30 -------- d-----w- c:\program files\ParadisePoker
2010-03-16 23:55 . 2010-02-21 00:30 -------- d-----w- c:\program files\liipoker
2010-03-16 22:35 . 2010-02-18 00:57 -------- d-----w- c:\program files\OnlyPoker
2010-03-16 11:49 . 2010-02-23 00:44 -------- d-----w- c:\program files\Kong Gaming
2010-03-16 01:21 . 2010-02-07 17:42 -------- d-----w- c:\program files\PokerNordica
2010-03-15 22:07 . 2010-02-16 12:18 -------- d-----w- c:\program files\365Bonitas
2010-03-14 16:37 . 2009-03-26 19:19 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-13 14:23 . 2009-07-22 17:04 -------- d-----w- c:\program files\Poker Heaven
2010-03-13 13:20 . 2009-05-25 19:53 -------- d-----w- c:\program files\bwin
2010-03-10 13:08 . 2010-02-17 15:06 -------- d-----w- c:\program files\High Pulse
2010-03-07 16:12 . 2010-02-23 02:32 -------- d-----w- c:\program files\PayNoRake
2010-03-07 00:06 . 2009-08-04 07:41 -------- d-----w- c:\program files\Goal Win
2010-03-05 23:51 . 2010-02-22 18:19 -------- d-----w- c:\program files\Winamax
2010-03-05 22:47 . 2009-08-11 18:11 -------- d-----w- c:\program files\Betsson
2010-03-04 19:20 . 2009-12-22 15:35 -------- d-----w- c:\program files\PokerLoco
2010-03-04 19:18 . 2010-02-18 10:53 -------- d-----w- c:\program files\Betsafe
2010-03-04 18:58 . 2010-02-16 17:37 -------- d-----w- c:\program files\RedKings
2010-03-04 01:10 . 2009-07-19 22:33 -------- d-----w- c:\program files\B2BPOKER
2010-03-03 00:30 . 2010-02-17 11:44 -------- d-----w- c:\program files\Action Poker
2010-02-27 06:01 . 2010-01-05 00:23 -------- d-----w- c:\program files\Ask.com
2010-02-26 01:21 . 2009-12-08 00:02 -------- d-----w- c:\program files\Betway
2010-02-19 16:31 . 2009-06-16 09:42 -------- d-----w- c:\program files\jtm
2010-02-18 23:50 . 2010-02-18 01:10 -------- d-----w- c:\program files\_uninstallation_info
2010-02-17 15:03 . 2009-07-28 20:47 -------- d-----w- c:\program files\PartyGaming
2010-02-16 21:55 . 2009-06-20 13:07 -------- d-----w- c:\program files\bet-at-home.com Poker
2010-02-13 19:07 . 2009-07-19 22:15 -------- d-----w- c:\program files\Bodog Poker
2010-01-05 09:58 . 2008-12-20 22:03 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 09:57 . 2009-03-01 07:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 09:57 . 2009-03-01 07:41 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-01 07:58 . 2009-03-01 07:46 353792 ----a-w- c:\windows\system32\drivers\srv.sys
.

------- Sigcheck -------

[-] 2009-03-01 . 1F39C7BDBA4C5F3F01C4EABF7EDBF4B3 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[-] 2009-03-01 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

[-] 2009-03-01 07:38 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
2009-08-10 14:06 91576 ----a-w- c:\program files\BearShareTb\BearShareDx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2009-05-04 10:56 398776 ----a-w- c:\program files\BearShare Applications\BearShare\BearShareIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b552069b-7b85-492f-8b98-ccf409c93a39}]
2010-03-07 19:16 2349080 ----a-w- c:\program files\OddsMaker\tbOdd1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 15:50 1197448 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0974BA1E-64EC-11DE-B2A5-E43756D89593}"= "c:\program files\BearShareTb\BearShareDx.dll" [2009-08-10 91576]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
"{b552069b-7b85-492f-8b98-ccf409c93a39}"= "c:\program files\OddsMaker\tbOdd1.dll" [2010-03-07 2349080]

[HKEY_CLASSES_ROOT\clsid\{0974ba1e-64ec-11de-b2a5-e43756d89593}]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{b552069b-7b85-492f-8b98-ccf409c93a39}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
"{B552069B-7B85-492F-8B98-CCF409C93A39}"= "c:\program files\OddsMaker\tbOdd1.dll" [2010-03-07 2349080]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{b552069b-7b85-492f-8b98-ccf409c93a39}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-26 39408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-08-27 133104]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"nwiz"="nwiz.exe" [2007-12-04 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-04 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]

c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
syspck32.exe [2008-4-14 30720]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-30 08:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [29.4.2009 1:45 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [29.4.2009 1:45 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [29.4.2009 1:45 108552]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [26.3.2009 18:17 222968]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [29.4.2009 1:44 29208]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.6.2009 21:28 721904]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe --> c:\progra~1\AVG\AVG8\avgfws8.exe [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [29.4.2009 1:44 29208]
.
Obsah adresáře 'Naplánované úlohy'

2009-07-01 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1100 series5E771253C1676EBED677BF361FDFC537825E15B8238525580.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]

2010-03-29 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1100 series5E771253C1676EBED677BF361FDFC537825E15B8239198963.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]

2010-03-29 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 15:50]

2010-03-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-01 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.bearshare.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: {{4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - c:\program files\Betway\Poker\MPPoker.exe
IE: {{8FE9B27A-BDCD-4d27-A430-4DC0B58D01B0} - c:\program files\Gnuf\Casino\casinogame.exe
IE: {{A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - c:\poker\CDPoker\casino.exe
IE: {{A99C8F70-4D5B-482c-8854-05BC0BB8B182} - c:\program files\Gnuf\Poker\MPPoker.exe
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\cc2ble11.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?o=15187&l=dis
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
URLSearchHooks-*{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
URLSearchHooks-*{b552069b-7b85-492f-8b98-ccf409c93a39} - (no file)
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
AddRemove-AVG8Uninstall - c:\program files\AVG\AVG8\setup.exe
AddRemove-Club Dice Poker - c:\poker\CDPoker\_SetupPoker.exe
AddRemove-PC Translator - c:\docume~1\ADMINI~1\LOCALS~1\Temp\UN32.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-29 20:51
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
Celkový čas: 2010-03-29 20:54:26
ComboFix-quarantined-files.txt 2010-03-29 18:54

Před spuštěním: 5 722 116 096
Po spuštění: 5 871 665 152

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - CB1E104DF5173E3198E947D54224607E

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 19:58
od Torres69
Len som este odvtedy ako som spravil ten combofix nevypol este pocitac a som zvedavy (kedze teraz mam uz normalne CPU uz ide komp ako hodinky) ze ci ked ho restartnem tak pojde zase tak ako teraz:) ale super diki moc... :) :) :)

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 20:13
od Caroprd111
Obrázek Pokud nemáte, přesuňte Combofix na plochu
  • Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.

Kód: Vybrat vše

File::
c:\documents and settings\Administrator\Nabídka Start\Programy\Po spuštění\syspck32.exe
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
c:\windows\Tasks\WGASetup.job

Driver::
ICQ Service

Folder::
C:\Program Files\BearShareTb
C:\Program Files\Google\Google Toolbar
C:\Program Files\Google\GoogleToolbarNotifier
C:\Program Files\Ask.com
C:\Program Files\ICQ6Toolbar
C:\Program Files\DAEMON Tools Toolbar

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
"{32099AAC-C132-4136-9E9A-4E364A424E17}"=-
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-
"{0974BA1E-64EC-11DE-B2A5-E43756D89593}"=-
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{0974ba1e-64ec-11de-b2a5-e43756d89593}]
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[-HKEY_CLASSES_ROOT\clsid\{b552069b-7b85-492f-8b98-ccf409c93a39}]

DDS::
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?o=15187&l=dis
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?cl ... e=en_US&q=
  • Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
  • Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:

    Obrázek
  • Po aplikaci na Vás vypadne další log,vložte ho sem
Může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci




Obrázek Tohle otestujte na http://www.virustotal.com/cs/
c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\sfcfiles.dll
c:\windows\system32\mspmsnsv.dll

(Soubor nehledejte, jenom vložíte tučně označenou cestu, v případě hlášky "Soubor již byl testován" dejte otestovat znovu. Výsledek analýzy sem v podobě odkazu vložte.)

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 20:30
od Torres69
co to pomoze? uz som spravil inak

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 20:40
od Caroprd111
Smažeme tím další svinstvo. :)

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 20:42
od Torres69
paradicka.. comp slape ako ma... dakujem velmo pekneeeeeeee

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 20:49
od Caroprd111
Potřeboval bych ten log. :)

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 29 bře 2010 21:07
od Torres69
ComboFix 10-03-28.03 - Administrator 29.03.2010 21:47:12.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.193 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}

FILE ::
"c:\documents and settings\Administrator\Nabídka Start\Programy\Po spuštění\syspck32.exe"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
"c:\windows\Tasks\WGASetup.job"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Nabídka Start\Programy\Po spuštění\syspck32.exe
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\BearShareTb
c:\program files\BearShareTb\BearShareDx.dll
c:\program files\BearShareTb\bearsharetb.dll
c:\program files\BearShareTb\chrome.manifest
c:\program files\BearShareTb\chrome\components\windowmediator.js
c:\program files\BearShareTb\chrome\content\about.xml
c:\program files\BearShareTb\chrome\content\allocine.xml
c:\program files\BearShareTb\chrome\content\bearshare.js
c:\program files\BearShareTb\chrome\content\bliptv.xml
c:\program files\BearShareTb\chrome\content\calories.xml
c:\program files\BearShareTb\chrome\content\Casino.xml
c:\program files\BearShareTb\chrome\content\data\search\engines.xml
c:\program files\BearShareTb\chrome\content\data\search\search.xsl
c:\program files\BearShareTb\chrome\content\desktop.ini
c:\program files\BearShareTb\chrome\content\Documents.lnk
c:\program files\BearShareTb\chrome\content\Google.xml
c:\program files\BearShareTb\chrome\content\LabPixies.xml
c:\program files\BearShareTb\chrome\content\lib\dtxpanelwin.xul
c:\program files\BearShareTb\chrome\content\lib\dtxprefwin.xul
c:\program files\BearShareTb\chrome\content\lib\dtxwin.xul
c:\program files\BearShareTb\chrome\content\lib\emailnotifierproviders.xml
c:\program files\BearShareTb\chrome\content\lib\external.js
c:\program files\BearShareTb\chrome\content\preferences.xml
c:\program files\BearShareTb\chrome\content\Sudoku.xml
c:\program files\BearShareTb\chrome\content\todo.xml
c:\program files\BearShareTb\chrome\content\toolbar.htm
c:\program files\BearShareTb\chrome\content\toolbar.xul
c:\program files\BearShareTb\chrome\content\trio.xml
c:\program files\BearShareTb\chrome\content\Unit Converter.xml
c:\program files\BearShareTb\chrome\content\uwa.js
c:\program files\BearShareTb\chrome\content\youtube.xml
c:\program files\BearShareTb\chrome\content\youtube_.xml
c:\program files\BearShareTb\chrome\skin\bearshare.css
c:\program files\BearShareTb\chrome\skin\bluelite.gif
c:\program files\BearShareTb\chrome\skin\bluesky.gif
c:\program files\BearShareTb\chrome\skin\btn-search-over.png
c:\program files\BearShareTb\chrome\skin\btn-search.png
c:\program files\BearShareTb\chrome\skin\btn-settings-over.png
c:\program files\BearShareTb\chrome\skin\btn-settings.png
c:\program files\BearShareTb\chrome\skin\btn-widgets-over.png
c:\program files\BearShareTb\chrome\skin\btn-widgets.png
c:\program files\BearShareTb\chrome\skin\btn_settings.png
c:\program files\BearShareTb\chrome\skin\button-down-back-ff.png
c:\program files\BearShareTb\chrome\skin\button-down-back.png
c:\program files\BearShareTb\chrome\skin\button-down-left.png
c:\program files\BearShareTb\chrome\skin\button-down-right.png
c:\program files\BearShareTb\chrome\skin\button-down-splitter.png
c:\program files\BearShareTb\chrome\skin\button-drop-back.png
c:\program files\BearShareTb\chrome\skin\button-drop-left.png
c:\program files\BearShareTb\chrome\skin\button-drop-right.png
c:\program files\BearShareTb\chrome\skin\button-drop-splitter.png
c:\program files\BearShareTb\chrome\skin\button-hover-back-ff.png
c:\program files\BearShareTb\chrome\skin\button-hover-back.png
c:\program files\BearShareTb\chrome\skin\button-hover-left.png
c:\program files\BearShareTb\chrome\skin\button-hover-right.png
c:\program files\BearShareTb\chrome\skin\button-hover-splitter.png
c:\program files\BearShareTb\chrome\skin\ca.png
c:\program files\BearShareTb\chrome\skin\dictionary.png
c:\program files\BearShareTb\chrome\skin\divider.png
c:\program files\BearShareTb\chrome\skin\downloadcom.png
c:\program files\BearShareTb\chrome\skin\dtxlogo.png
c:\program files\BearShareTb\chrome\skin\email.png
c:\program files\BearShareTb\chrome\skin\email_on.png
c:\program files\BearShareTb\chrome\skin\games.png
c:\program files\BearShareTb\chrome\skin\graphred0.png
c:\program files\BearShareTb\chrome\skin\graphred0_5.png
c:\program files\BearShareTb\chrome\skin\grey.gif
c:\program files\BearShareTb\chrome\skin\headsup.png
c:\program files\BearShareTb\chrome\skin\ico-shield.png
c:\program files\BearShareTb\chrome\skin\images.png
c:\program files\BearShareTb\chrome\skin\lib\add.png
c:\program files\BearShareTb\chrome\skin\lib\aol.png
c:\program files\BearShareTb\chrome\skin\lib\arrow-dn.gif
c:\program files\BearShareTb\chrome\skin\lib\arrow-right.gif
c:\program files\BearShareTb\chrome\skin\lib\arrow-up.gif
c:\program files\BearShareTb\chrome\skin\lib\bg-btn-end.png
c:\program files\BearShareTb\chrome\skin\lib\bg-btn-mdl.png
c:\program files\BearShareTb\chrome\skin\lib\bg-btn-start.png
c:\program files\BearShareTb\chrome\skin\lib\bg-btnover-end.png
c:\program files\BearShareTb\chrome\skin\lib\bg-btnover-mdl.png
c:\program files\BearShareTb\chrome\skin\lib\bg-btnover-mdl_ff.png
c:\program files\BearShareTb\chrome\skin\lib\bg-btnover-start.png
c:\program files\BearShareTb\chrome\skin\lib\blank.gif
c:\program files\BearShareTb\chrome\skin\lib\btnback-down-vista.png
c:\program files\BearShareTb\chrome\skin\lib\btnback-vista.png
c:\program files\BearShareTb\chrome\skin\lib\btnleft-down-vista.png
c:\program files\BearShareTb\chrome\skin\lib\btnleft-vista.png
c:\program files\BearShareTb\chrome\skin\lib\btnright-down-vista.png
c:\program files\BearShareTb\chrome\skin\lib\btnright-vista.png
c:\program files\BearShareTb\chrome\skin\lib\button-splitter-down-vista.png
c:\program files\BearShareTb\chrome\skin\lib\button-splitter-vista.png
c:\program files\BearShareTb\chrome\skin\lib\collapse.png
c:\program files\BearShareTb\chrome\skin\lib\comcast.png
c:\program files\BearShareTb\chrome\skin\lib\dtx.css
c:\program files\BearShareTb\chrome\skin\lib\edit-back-hot.png
c:\program files\BearShareTb\chrome\skin\lib\edit-back.png
c:\program files\BearShareTb\chrome\skin\lib\expand.png
c:\program files\BearShareTb\chrome\skin\lib\found.png
c:\program files\BearShareTb\chrome\skin\lib\gmail.png
c:\program files\BearShareTb\chrome\skin\lib\highlight.png
c:\program files\BearShareTb\chrome\skin\lib\highlight_blue.png
c:\program files\BearShareTb\chrome\skin\lib\highlight_cyan.png
c:\program files\BearShareTb\chrome\skin\lib\highlight_lime.png
c:\program files\BearShareTb\chrome\skin\lib\highlight_magenta.png
c:\program files\BearShareTb\chrome\skin\lib\highlight_yellow.png
c:\program files\BearShareTb\chrome\skin\lib\hotmail.png
c:\program files\BearShareTb\chrome\skin\lib\checkmark.png
c:\program files\BearShareTb\chrome\skin\lib\chevron.png
c:\program files\BearShareTb\chrome\skin\lib\imap.png
c:\program files\BearShareTb\chrome\skin\lib\lastsearch-thumb-back.gif
c:\program files\BearShareTb\chrome\skin\lib\loadingMid.gif
c:\program files\BearShareTb\chrome\skin\lib\lock.png
c:\program files\BearShareTb\chrome\skin\lib\mailcom.png
c:\program files\BearShareTb\chrome\skin\lib\menu_bg-basic.png
c:\program files\BearShareTb\chrome\skin\lib\menu_separator_bar.png
c:\program files\BearShareTb\chrome\skin\lib\menu_separator_white.png
c:\program files\BearShareTb\chrome\skin\lib\menuitem-splitter.png
c:\program files\BearShareTb\chrome\skin\lib\menuitemback-down-vista.png
c:\program files\BearShareTb\chrome\skin\lib\menuitemback-vista.png
c:\program files\BearShareTb\chrome\skin\lib\menuitemleft-down-vista.png
c:\program files\BearShareTb\chrome\skin\lib\menuitemleft-vista.png
c:\program files\BearShareTb\chrome\skin\lib\menuitemright-down-vista.png
c:\program files\BearShareTb\chrome\skin\lib\menuitemright-vista.png
c:\program files\BearShareTb\chrome\skin\lib\modify.png
c:\program files\BearShareTb\chrome\skin\lib\move.gif
c:\program files\BearShareTb\chrome\skin\lib\movetarget.png
c:\program files\BearShareTb\chrome\skin\lib\pop.png
c:\program files\BearShareTb\chrome\skin\lib\radio.png
c:\program files\BearShareTb\chrome\skin\lib\reload.png
c:\program files\BearShareTb\chrome\skin\lib\remove.png
c:\program files\BearShareTb\chrome\skin\lib\rename.gif
c:\program files\BearShareTb\chrome\skin\lib\resize-box.gif
c:\program files\BearShareTb\chrome\skin\lib\rss.png
c:\program files\BearShareTb\chrome\skin\lib\rsschannelback.png
c:\program files\BearShareTb\chrome\skin\lib\RSSLogo.png
c:\program files\BearShareTb\chrome\skin\lib\rsstabdivider.gif
c:\program files\BearShareTb\chrome\skin\lib\scroll-left.png
c:\program files\BearShareTb\chrome\skin\lib\scroll-right.png
c:\program files\BearShareTb\chrome\skin\lib\search-go.png
c:\program files\BearShareTb\chrome\skin\lib\search.png
c:\program files\BearShareTb\chrome\skin\lib\text-ellipsis.xml
c:\program files\BearShareTb\chrome\skin\lib\toolbarsplitter.gif
c:\program files\BearShareTb\chrome\skin\lib\transparent_1px.gif
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_02.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_03.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_04.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_06.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_07.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_08.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_09.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_10.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_11.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_12.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_13.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_14.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_15.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_16.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_18.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_19.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_20.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\border_21.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\btn-close-grey.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\btn-close-greyover.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\close-hot.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\close-normal.png
c:\program files\BearShareTb\chrome\skin\lib\uwa\loadingMid.gif
c:\program files\BearShareTb\chrome\skin\lib\uwa\proxy.html
c:\program files\BearShareTb\chrome\skin\lib\uwa\template.html
c:\program files\BearShareTb\chrome\skin\lib\uwa\template.xml
c:\program files\BearShareTb\chrome\skin\lib\uwa\templateFF.html
c:\program files\BearShareTb\chrome\skin\lib\uwa\throbber.gif
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\add.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\box-check.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\popupWeather.css
c:\program files\BearShareTb\chrome\skin\lib\weatherbutton\panels\popupWeather.html
c:\program files\BearShareTb\chrome\skin\lib\yahoo.png
c:\program files\BearShareTb\chrome\skin\lichen.gif
c:\program files\BearShareTb\chrome\skin\logo-about.jpg
c:\program files\BearShareTb\chrome\skin\logo-over.png
c:\program files\BearShareTb\chrome\skin\logo.png
c:\program files\BearShareTb\chrome\skin\logo_old.png
c:\program files\BearShareTb\chrome\skin\maps.bmp
c:\program files\BearShareTb\chrome\skin\menuseparatorback.gif
c:\program files\BearShareTb\chrome\skin\modify-save.png
c:\program files\BearShareTb\chrome\skin\modify.png
c:\program files\BearShareTb\chrome\skin\modifyhot.png
c:\program files\BearShareTb\chrome\skin\music.png
c:\program files\BearShareTb\chrome\skin\news.png
c:\program files\BearShareTb\chrome\skin\options\options-main.png
c:\program files\BearShareTb\chrome\skin\options\options-search.png
c:\program files\BearShareTb\chrome\skin\options\options-weather.gif
c:\program files\BearShareTb\chrome\skin\options\options-widgets.png
c:\program files\BearShareTb\chrome\skin\orange.gif
c:\program files\BearShareTb\chrome\skin\pixsy.png
c:\program files\BearShareTb\chrome\skin\relatedlinks.png
c:\program files\BearShareTb\chrome\skin\rss-collapse.png
c:\program files\BearShareTb\chrome\skin\rss-delete.png
c:\program files\BearShareTb\chrome\skin\rss-expand.png
c:\program files\BearShareTb\chrome\skin\rss-feed.png
c:\program files\BearShareTb\chrome\skin\rss-folder-remove.png
c:\program files\BearShareTb\chrome\skin\rss-folder-rename.png
c:\program files\BearShareTb\chrome\skin\rss-folder.png
c:\program files\BearShareTb\chrome\skin\rss-found.png
c:\program files\BearShareTb\chrome\skin\rss-reload.png
c:\program files\BearShareTb\chrome\skin\rss-subscribe.png
c:\program files\BearShareTb\chrome\skin\rss.png
c:\program files\BearShareTb\chrome\skin\rssback.gif
c:\program files\BearShareTb\chrome\skin\rsstopback.gif
c:\program files\BearShareTb\chrome\skin\search-over.png
c:\program files\BearShareTb\chrome\skin\search.png
c:\program files\BearShareTb\chrome\skin\searchbar\searchbar-background-left.png
c:\program files\BearShareTb\chrome\skin\searchbar\searchbar-background-middle.png
c:\program files\BearShareTb\chrome\skin\searchbar\searchbar-background-right.png
c:\program files\BearShareTb\chrome\skin\settings.png
c:\program files\BearShareTb\chrome\skin\shopping.png
c:\program files\BearShareTb\chrome\skin\siteinfo.png
c:\program files\BearShareTb\chrome\skin\skin-bluelite.png
c:\program files\BearShareTb\chrome\skin\skin-bluesky.png
c:\program files\BearShareTb\chrome\skin\skin-grey.png
c:\program files\BearShareTb\chrome\skin\skin-lichen.png
c:\program files\BearShareTb\chrome\skin\skin-orange.png
c:\program files\BearShareTb\chrome\skin\skin-yellow.png
c:\program files\BearShareTb\chrome\skin\technorati.png
c:\program files\BearShareTb\chrome\skin\throbber.gif
c:\program files\BearShareTb\chrome\skin\Thumbs.db
c:\program files\BearShareTb\chrome\skin\video.bmp
c:\program files\BearShareTb\chrome\skin\vmn.css
c:\program files\BearShareTb\chrome\skin\weather.png
c:\program files\BearShareTb\chrome\skin\web.png
c:\program files\BearShareTb\chrome\skin\widget_allocine.png
c:\program files\BearShareTb\chrome\skin\widget_bliptv.png
c:\program files\BearShareTb\chrome\skin\widget_calcal.png
c:\program files\BearShareTb\chrome\skin\widget_calculator.png
c:\program files\BearShareTb\chrome\skin\widget_gservices.png
c:\program files\BearShareTb\chrome\skin\widget_sudoku.png
c:\program files\BearShareTb\chrome\skin\widget_todo.jpg
c:\program files\BearShareTb\chrome\skin\widget_todo.png
c:\program files\BearShareTb\chrome\skin\widget_trio.png
c:\program files\BearShareTb\chrome\skin\widget_uconverter.png
c:\program files\BearShareTb\chrome\skin\widgets.png
c:\program files\BearShareTb\chrome\skin\wikipedia.png
c:\program files\BearShareTb\chrome\skin\yahoosearch.png
c:\program files\BearShareTb\chrome\skin\yellow.gif
c:\program files\BearShareTb\chrome\skin\youtube.png
c:\program files\BearShareTb\chrome\skin\zoom.png
c:\program files\BearShareTb\install.ico
c:\program files\BearShareTb\install.rdf
c:\program files\BearShareTb\manifest.xml
c:\program files\BearShareTb\uninstall.exe
c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.bmp
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\cond000.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond001.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond003.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond004.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond005.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond006.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond007.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond008.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond009.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond010.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond011.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond019.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond020.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond021.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond022.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond023.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond024.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond025.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond026.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond037.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond038.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond039.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond040.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond041.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond046.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond048.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond050.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond051.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond052.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond053.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond054.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond055.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond056.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond057.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond058.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond059.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond060.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond061.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond062.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond063.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond064.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond065.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond066.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond067.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond068.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond069.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond075.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond076.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond077.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond078.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond079.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond080.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond084.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond085.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond086.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond087.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond088.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond089.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond090.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond091.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond092.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond093.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond094.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond095.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond108.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond109.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond110.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond111.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond112.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond113.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond120.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond121.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond122.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond126.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond127.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond128.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond129.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond130.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond131.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond132.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond133.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond134.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond135.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond136.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond137.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond138.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond140.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond141.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond142.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond143.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond148.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond149.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond152.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond154.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond155.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond156.gif
c:\program files\DAEMON Tools Toolbar\Resources\cond157.gif
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\noW.gif
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\time.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Weather_m42.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Weather_m43.bmp
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\program files\Google\Google Toolbar
c:\program files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
c:\program files\Google\Google Toolbar\Component\GoogleCld_AE2927CDD77381B4.dll
c:\program files\Google\Google Toolbar\Component\googledict_en2es_76D5B51588E8E478.dat
c:\program files\Google\Google Toolbar\Component\GoogleToolbar.6.2.1910.1554.manifest.xml
c:\program files\Google\Google Toolbar\Component\GoogleToolbar_32_73DD003E17144CAC.dll
c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_32_D5B8545F3CFB02D4.dll
c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_9655453EC427A513.dll
c:\program files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe
c:\program files\Google\Google Toolbar\Component\GoogleToolbarUser_32_1D643E0FC0BE74CC.exe
c:\program files\Google\Google Toolbar\Component\GoogleUpdaterService_5898FABCFA121C11.exe
c:\program files\Google\Google Toolbar\Component\SearchWithGoogleUpdate_C5C67DF5D46FB314.exe
c:\program files\Google\Google Toolbar\GoogleToolbar_32.dll
c:\program files\Google\Google Toolbar\GoogleToolbarHelper_signed.msi
c:\program files\Google\Google Toolbar\GoogleToolbarHelperPatch_signed.msp
c:\program files\Google\Google Toolbar\GoogleToolbarUser_32.exe
c:\program files\Google\GoogleToolbarNotifier
c:\program files\Google\GoogleToolbarNotifier\5.2.4204.1700\gth.dll
c:\program files\Google\GoogleToolbarNotifier\5.2.4204.1700\gtn.dll
c:\program files\Google\GoogleToolbarNotifier\5.2.4204.1700\Readme.url
c:\program files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\program files\Google\GoogleToolbarNotifier\swg-5.1.1309.15642\SearchWithGoogleUpdate.exe
c:\program files\Google\GoogleToolbarNotifier\swg-5.1.1309.3572\SearchWithGoogleUpdate.exe
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
c:\windows\Tasks\WGASetup.job

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ICQ_SERVICE
-------\Service_ICQ Service


((((((((((((((((((((((((( Soubory vytvořené od 2010-02-28 do 2010-03-29 )))))))))))))))))))))))))))))))
.

2010-03-29 19:59 . 2010-03-29 19:59 -------- d-----w- c:\windows\system32\wbem\snmp
2010-03-29 19:59 . 2010-03-29 19:59 -------- d-----w- c:\windows\system32\xircom
2010-03-29 19:59 . 2010-03-29 19:59 -------- d-----w- c:\program files\microsoft frontpage
2010-03-29 13:20 . 2010-03-29 13:21 -------- d-----w- c:\program files\trend micro
2010-03-29 13:20 . 2010-03-29 13:22 -------- d-----w- C:\rsit
2010-03-29 08:20 . 2010-03-29 08:20 -------- d-----w- c:\windows\system32\wbem\Repository
2010-03-22 14:28 . 2009-09-29 15:38 108032 ----a-w- c:\windows\system32\UnCasino5.exe
2010-03-22 14:27 . 2010-03-22 14:28 -------- d-----w- c:\program files\InterCasino $$$
2010-03-22 14:26 . 2010-03-22 14:28 -------- d-----w- c:\program files\InterPoker
2010-03-14 23:57 . 2010-03-16 21:07 -------- d-----w- c:\program files\RedStarPoker
2010-03-14 16:39 . 2010-03-14 16:39 -------- d-----w- c:\program files\VeniceLobby
2010-03-13 13:20 . 2010-03-13 13:21 -------- d-----w- C:\bwinPoker
2010-03-11 22:40 . 2010-03-17 01:57 -------- d-----w- c:\program files\Spin32
2010-03-11 21:06 . 2010-03-11 21:06 -------- d-----w- c:\program files\FlandersPoker
2010-03-11 07:04 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-10 21:46 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-07 00:13 . 2010-03-07 00:13 -------- d-----w- c:\program files\Conduit
2010-03-07 00:13 . 2010-03-07 19:16 -------- d-----w- c:\program files\OddsMaker
2010-03-06 16:37 . 2010-03-06 16:38 -------- d-----w- c:\program files\Gnuf
2010-03-06 00:32 . 2010-03-11 23:32 -------- d-----w- c:\program files\BrucePoker.com
2010-03-03 00:13 . 2010-03-04 15:26 -------- d-----w- C:\Bet24
2010-03-02 21:45 . 2010-03-04 19:17 -------- d-----w- c:\program files\POKER
2010-02-28 23:05 . 2010-03-17 00:22 -------- d-----w- c:\program files\Cake Poker
2010-02-28 15:34 . 2010-02-28 15:34 -------- d-----w- c:\program files\Common Files\Radik Software
2010-02-28 15:34 . 2010-02-28 15:34 -------- d-----w- c:\program files\Radik Software
2010-02-28 11:45 . 2010-02-28 12:23 -------- d-----w- c:\program files\Mafia

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-29 19:57 . 2009-03-26 19:15 -------- d-----w- c:\program files\Google
2010-03-29 19:08 . 2010-02-17 09:22 -------- d-----w- c:\program files\BluffRoom
2010-03-29 09:21 . 2001-10-25 15:00 78030 ----a-w- c:\windows\system32\perfc005.dat
2010-03-29 09:21 . 2001-10-25 15:00 429018 ----a-w- c:\windows\system32\perfh005.dat
2010-03-29 08:19 . 2010-02-22 01:18 -------- d-----w- c:\program files\DoylesRoom
2010-03-29 08:19 . 2009-08-15 23:29 -------- d-----w- c:\program files\Everest Poker
2010-03-29 08:19 . 2010-02-18 01:11 -------- d-----w- c:\program files\Absolute Poker
2010-03-29 08:19 . 2010-02-18 23:50 -------- d-----w- c:\program files\UB
2010-03-28 17:46 . 2009-07-15 18:26 -------- d-----w- c:\program files\PokerStars
2010-03-28 00:08 . 2010-02-19 02:19 -------- d-----w- c:\program files\FeltStars
2010-03-25 22:07 . 2009-05-06 00:15 -------- d-----w- c:\program files\Full Tilt Poker
2010-03-23 22:46 . 2009-11-25 12:38 -------- d-----w- c:\program files\ReeferPoker
2010-03-21 15:11 . 2010-02-21 00:08 -------- d-----w- c:\program files\CarbonPoker
2010-03-21 14:51 . 2010-02-03 17:17 -------- d-----w- c:\program files\A-Winning-Hand
2010-03-21 14:45 . 2010-02-17 19:43 -------- d-----w- c:\program files\PowerPoker
2010-03-21 13:07 . 2010-02-21 18:53 -------- d-----w- c:\program files\BetClick Poker
2010-03-21 12:38 . 2009-07-09 15:30 -------- d-----w- c:\program files\ParadisePoker
2010-03-16 23:55 . 2010-02-21 00:30 -------- d-----w- c:\program files\liipoker
2010-03-16 22:35 . 2010-02-18 00:57 -------- d-----w- c:\program files\OnlyPoker
2010-03-16 11:49 . 2010-02-23 00:44 -------- d-----w- c:\program files\Kong Gaming
2010-03-16 01:21 . 2010-02-07 17:42 -------- d-----w- c:\program files\PokerNordica
2010-03-15 22:07 . 2010-02-16 12:18 -------- d-----w- c:\program files\365Bonitas
2010-03-14 16:37 . 2009-03-26 19:19 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-13 14:23 . 2009-07-22 17:04 -------- d-----w- c:\program files\Poker Heaven
2010-03-13 13:20 . 2009-05-25 19:53 -------- d-----w- c:\program files\bwin
2010-03-10 13:08 . 2010-02-17 15:06 -------- d-----w- c:\program files\High Pulse
2010-03-07 16:12 . 2010-02-23 02:32 -------- d-----w- c:\program files\PayNoRake
2010-03-07 00:06 . 2009-08-04 07:41 -------- d-----w- c:\program files\Goal Win
2010-03-05 23:51 . 2010-02-22 18:19 -------- d-----w- c:\program files\Winamax
2010-03-05 22:47 . 2009-08-11 18:11 -------- d-----w- c:\program files\Betsson
2010-03-04 19:20 . 2009-12-22 15:35 -------- d-----w- c:\program files\PokerLoco
2010-03-04 19:18 . 2010-02-18 10:53 -------- d-----w- c:\program files\Betsafe
2010-03-04 18:58 . 2010-02-16 17:37 -------- d-----w- c:\program files\RedKings
2010-03-04 01:10 . 2009-07-19 22:33 -------- d-----w- c:\program files\B2BPOKER
2010-03-03 00:30 . 2010-02-17 11:44 -------- d-----w- c:\program files\Action Poker
2010-02-26 01:21 . 2009-12-08 00:02 -------- d-----w- c:\program files\Betway
2010-02-19 16:31 . 2009-06-16 09:42 -------- d-----w- c:\program files\jtm
2010-02-18 23:50 . 2010-02-18 01:10 -------- d-----w- c:\program files\_uninstallation_info
2010-02-17 15:03 . 2009-07-28 20:47 -------- d-----w- c:\program files\PartyGaming
2010-02-16 21:55 . 2009-06-20 13:07 -------- d-----w- c:\program files\bet-at-home.com Poker
2010-02-13 19:07 . 2009-07-19 22:15 -------- d-----w- c:\program files\Bodog Poker
2010-01-05 09:58 . 2008-12-20 22:03 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 09:57 . 2009-03-01 07:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 09:57 . 2009-03-01 07:41 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-01 07:58 . 2009-03-01 07:46 353792 ----a-w- c:\windows\system32\drivers\srv.sys
.

------- Sigcheck -------

[-] 2009-03-01 . 1F39C7BDBA4C5F3F01C4EABF7EDBF4B3 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[-] 2009-03-01 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

[-] 2009-03-01 07:38 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-29_18.51.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-29 20:00 . 2010-03-29 20:00 16384 c:\windows\Temp\Perflib_Perfdata_4e0.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2009-05-04 10:56 398776 ----a-w- c:\program files\BearShare Applications\BearShare\BearShareIEHelper.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-08-27 133104]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"nwiz"="nwiz.exe" [2007-12-04 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-04 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-30 08:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [29.4.2009 1:45 12552]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4.6.2009 21:28 721904]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [29.4.2009 1:45 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [29.4.2009 1:45 108552]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [29.4.2009 1:44 29208]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe --> c:\progra~1\AVG\AVG8\avgfws8.exe [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [29.4.2009 1:44 29208]
.
Obsah adresáře 'Naplánované úlohy'

2009-07-01 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1100 series5E771253C1676EBED677BF361FDFC537825E15B8238525580.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]

2010-03-29 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1100 series5E771253C1676EBED677BF361FDFC537825E15B8239198963.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.bearshare.com/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: {{4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - c:\program files\Betway\Poker\MPPoker.exe
IE: {{8FE9B27A-BDCD-4d27-A430-4DC0B58D01B0} - c:\program files\Gnuf\Casino\casinogame.exe
IE: {{A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - c:\poker\CDPoker\casino.exe
IE: {{A99C8F70-4D5B-482c-8854-05BC0BB8B182} - c:\program files\Gnuf\Poker\MPPoker.exe
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\cc2ble11.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?o=15187&l=dis
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=PTV&o=15184&locale=en_US&q=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{b552069b-7b85-492f-8b98-ccf409c93a39} - (no file)
Toolbar-{b552069b-7b85-492f-8b98-ccf409c93a39} - (no file)
WebBrowser-{B552069B-7B85-492F-8B98-CCF409C93A39} - (no file)
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
AddRemove-bearsharetb - c:\program files\BearShareTb\uninstall.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
AddRemove-{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-29 22:00
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spzi.sys >>UNKNOWN [0x82392938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8579f28
\Driver\ACPI -> ACPI.sys @ 0xf83d3cb8
\Driver\atapi -> atapi.sys @ 0xf8368b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf8272bd4
PacketIndicateHandler -> NDIS.sys @ 0xf827ea21
SendHandler -> NDIS.sys @ 0xf8272d44
user & kernel MBR OK

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(3912)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-03-29 22:06:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-29 20:06
ComboFix2.txt 2010-03-29 18:54

Před spuštěním: 5 856 301 056
Po spuštění: 5 730 078 720

- - End Of File - - 1CA7B6C65CB6A2CC59C133F10C659DA3

Re: Prosim o kontrolu.. svchost.exe mi vytazuje 100 perc CPU

Napsal: 30 bře 2010 05:04
od Caroprd111
Caroprd111 píše: Obrázek Tohle otestujte na http://www.virustotal.com/cs/
c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\sfcfiles.dll
c:\windows\system32\mspmsnsv.dll

(Soubor nehledejte, jenom vložíte tučně označenou cestu, v případě hlášky "Soubor již byl testován" dejte otestovat znovu. Výsledek analýzy sem v podobě odkazu vložte.)