Stránka 1 z 1

Spomalena vista

Napsal: 08 dub 2010 15:01
od skip27
zdravim, vcera som robil poriadok v pc, so spyware doctorom som pomazal nejake hrozby, nasledne som ccleanerom vymazal docasne subory a udaje z prehliadacov.. spokojne som konecne dal nainstalovat service pack 2 a po restarte bol vysledok ze pc je totalne spomalene.. vopred dakujem za rady

Logfile of random's system information tool 1.06 (written by random/random)
Run by Briatka at 2010-04-08 15:59:56
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 5 GB (4%) free of 146 GB
Total RAM: 2046 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:00:01, on 8. 4. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Windows\system32\AEADISRV.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Windows\System32\TPHDEXLG.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Briatka\Downloads\RSIT.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Briatka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2269050
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
O2 - BHO: DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll
O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVDV.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [LenovoOobeOffers] c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt"
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Orezávač obrazovky a spúšťač programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: LenovoRegistration.lnk = C:\SWTOOLS\LenovoWelcome\LenovoRegistration.cmd
O8 - Extra context menu item: &Windows Live Search - res://c:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Users\Briatka\AppData\LocalLow\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O13 - Gopher Prefix:
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\Windows\system32\IPSSVC.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\System32\TPHDEXLG.exe
O23 - Service: On Screen Display (TPHKSVC) - Unknown owner - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 17771 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Check Updates for Windows Live Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pre aplikáciu Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}]
DealioBHO Class - C:\Program Files\Dealio\kb127\Dealio.dll [2008-05-26 3170144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - c:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - C:\Program Files\Search Settings\kb127\SearchSettings.dll [2008-06-12 1111904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
DVDVideoSoft Toolbar - C:\Program Files\DVDVideoSoft\tbDVDV.dll [2009-11-09 2331672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F040E541-A427-4CF7-85D8-75E3E0F476C5}]
CPwmIEBrowserHelper Object - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll [2007-08-09 795960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - c:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]
{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - Dealio - C:\Program Files\Dealio\kb127\Dealio.dll [2008-05-26 3170144]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-12-09 958200]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]
{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - DVDVideoSoft Toolbar - C:\Program Files\DVDVideoSoft\tbDVDV.dll [2009-11-09 2331672]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"TPFNF7"=C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe [2007-11-29 59168]
"PWMTRV"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor []
"BLOG"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBattLog []
"TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2007-03-09 66176]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-03-05 172032]
""= []
"TpShocks"=C:\Windows\system32\TpShocks.exe [2007-11-23 181536]
"EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe []
"LenovoOobeOffers"=c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe [2007-09-25 28672]
"TVT Scheduler Proxy"=C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2007-01-09 536576]
"DiskeeperSystray"=C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe [2006-11-16 217176]
"AwaySch"=C:\Program Files\Lenovo\AwayTask\AwaySch.EXE [2006-11-07 91688]
"LPManager"=C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe [2007-04-26 120368]
"AMSG"=C:\Program Files\ThinkVantage\AMSG\Amsg.exe [2007-02-01 419376]
"ACTray"=C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe [2007-07-06 419112]
"ACWLIcon"=C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe [2007-07-06 124200]
"cssauth"=C:\Program Files\Lenovo\Client Security Solution\cssauth.exe [2007-08-09 2630968]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe []
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-08-13 177440]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-01-15 185896]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-06-09 13543968]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-06-09 92704]
"UVS12 Preload"=C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe [2008-06-09 397456]
"H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe [2005-05-11 200069]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-06-10 1447168]
"ISTray"=C:\Program Files\Spyware Doctor\pctsTray.exe [2010-01-18 1286608]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-07-09 1282048]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2007-03-01 2321600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\au]
C:\Program Files\Dealio\DealioAU.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DU Meter]
C:\Program Files\DU Meter\DUMeter.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
C:\Program Files\Spyware Doctor\pctsTray.exe [2010-01-18 1286608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-03-20 83240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
C:\Program Files\TrojanHunter 5.0\THGuard.exe [2009-04-26 1046688]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
LenovoRegistration.lnk - C:\SWTOOLS\LenovoWelcome\LenovoRegistration.cmd

C:\Users\Briatka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Orezávač obrazovky a spúšťač programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Windows\system32\psqlpwd.dll [2007-03-15 89600]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd
ACGina

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"DisableCAD"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2dd92239-3caf-11df-9bb9-001e37d891c8}]
shell\AutoRun\command - "J:\WD SmartWare.exe" autoplay=true

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4abdc74f-f7c8-11de-bd64-001e37d891c8}]
shell\AutoRun\command - I:\SUD\SSOW\sep.exe
shell\open\command - I:\SUD\SSOW\sep.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{700b16ac-39c4-11df-b21b-001e37d891c8}]
shell\AutoRun\command - I:\AutoTransfer.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{856f093d-69a7-11dd-a5b9-001e37d891c8}]
shell\Auto\command - sal.xls.exe
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.reg - open - "regedit.exe" "%1"

======List of files/folders created in the last 1 months======

2010-04-08 15:00:54 ----D---- C:\rsit
2010-04-08 15:00:54 ----D---- C:\Program Files\trend micro
2010-04-07 19:54:16 ----D---- C:\Windows\system32\eu-ES
2010-04-07 19:54:16 ----D---- C:\Windows\system32\ca-ES
2010-04-07 19:54:14 ----D---- C:\Windows\system32\vi-VN
2010-04-07 19:17:49 ----D---- C:\Windows\system32\EventProviders
2010-04-07 15:49:13 ----A---- C:\Windows\SGDetectionTool.dll
2010-04-07 15:49:13 ----A---- C:\Windows\PCTBDRes.dll
2010-04-07 15:49:13 ----A---- C:\Windows\PCTBDCore.dll
2010-04-07 15:49:13 ----A---- C:\Windows\BDTSupport.dll
2010-04-07 15:48:54 ----D---- C:\Users\Briatka\AppData\Roaming\PC Tools
2010-04-07 15:48:54 ----D---- C:\ProgramData\PC Tools
2010-04-07 15:48:54 ----D---- C:\Program Files\Spyware Doctor
2010-04-07 15:48:54 ----D---- C:\Program Files\Common Files\PC Tools
2010-04-07 15:48:30 ----A---- C:\Users\Briatka\AppData\Roaming\sdasetup.exe
2010-04-07 15:10:16 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-04-07 15:10:16 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-04-06 11:50:18 ----D---- C:\Users\Briatka\AppData\Roaming\Blue Cat Audio
2010-04-06 11:49:05 ----D---- C:\Program Files\Common Files\VST3
2010-04-06 11:49:03 ----D---- C:\Program Files\iZotope
2010-04-03 20:03:22 ----D---- C:\ProgramData\Sun
2010-04-03 09:06:35 ----D---- C:\folder ni
2010-04-03 09:05:20 ----A---- C:\Windows\system32\NI_IRC_1_2.dll
2010-04-03 09:04:14 ----A---- C:\Windows\system32\NI_DFD_1_5.dll
2010-04-03 09:04:14 ----A---- C:\Windows\system32\bconvert.dll
2010-04-03 00:57:05 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2010-04-02 19:47:15 ----HDC---- C:\ProgramData\{BF329843-149E-4A5A-82A1-0250286442D0}
2010-04-02 19:45:02 ----HDC---- C:\ProgramData\{4275E5EA-6E30-48EB-A209-F964539CBE1C}
2010-04-01 14:19:34 ----D---- C:\Program Files\CCleaner
2010-03-31 13:08:04 ----D---- C:\ProgramData\Western Digital
2010-03-31 12:33:05 ----A---- C:\Windows\system32\mshtml.dll
2010-03-31 12:33:01 ----A---- C:\Windows\system32\ieframe.dll
2010-03-31 12:33:00 ----A---- C:\Windows\system32\iertutil.dll
2010-03-31 12:32:59 ----A---- C:\Windows\system32\urlmon.dll
2010-03-31 12:32:58 ----A---- C:\Windows\system32\wininet.dll
2010-03-31 12:32:58 ----A---- C:\Windows\system32\occache.dll
2010-03-31 12:32:58 ----A---- C:\Windows\system32\msfeeds.dll
2010-03-31 12:32:57 ----A---- C:\Windows\system32\mstime.dll
2010-03-31 12:32:57 ----A---- C:\Windows\system32\iedkcs32.dll
2010-03-31 12:32:55 ----A---- C:\Windows\system32\ieui.dll
2010-03-31 12:32:54 ----A---- C:\Windows\system32\iepeers.dll
2010-03-31 12:32:53 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-03-31 12:32:53 ----A---- C:\Windows\system32\ieUnatt.exe
2010-03-31 12:32:53 ----A---- C:\Windows\system32\iesysprep.dll
2010-03-31 12:32:52 ----A---- C:\Windows\system32\jsproxy.dll
2010-03-31 12:32:52 ----A---- C:\Windows\system32\ie4uinit.exe
2010-03-31 12:32:51 ----A---- C:\Windows\system32\msfeedssync.exe
2010-03-31 12:32:51 ----A---- C:\Windows\system32\iesetup.dll
2010-03-31 12:32:51 ----A---- C:\Windows\system32\iernonce.dll
2010-03-29 03:01:15 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-27 19:12:27 ----D---- C:\A
2010-03-11 04:02:25 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-11 04:02:21 ----A---- C:\Windows\system32\httpapi.dll

======List of files/folders modified in the last 1 months======

2010-04-08 15:59:59 ----D---- C:\Windows\Temp
2010-04-08 15:00:54 ----D---- C:\Program Files
2010-04-08 14:36:33 ----D---- C:\Windows\System32
2010-04-08 14:36:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-04-08 14:36:31 ----D---- C:\Windows\inf
2010-04-08 14:35:32 ----SHD---- C:\System Volume Information
2010-04-08 14:33:21 ----AD---- C:\ProgramData\TEMP
2010-04-08 14:30:38 ----A---- C:\Windows\system32\PROCDB.INI
2010-04-08 14:29:53 ----A---- C:\Windows\system32\IPSCtrl.INI
2010-04-08 09:52:40 ----D---- C:\Windows\system32\catroot
2010-04-08 09:52:38 ----D---- C:\Windows\winsxs
2010-04-07 21:02:09 ----D---- C:\Windows\rescache
2010-04-07 20:38:51 ----D---- C:\Windows\Microsoft.NET
2010-04-07 20:38:41 ----RSD---- C:\Windows\assembly
2010-04-07 20:08:18 ----D---- C:\Windows
2010-04-07 20:07:49 ----SHD---- C:\Boot
2010-04-07 19:55:48 ----D---- C:\Program Files\Windows Calendar
2010-04-07 19:55:48 ----D---- C:\Program Files\Movie Maker
2010-04-07 19:55:46 ----D---- C:\Program Files\Windows Sidebar
2010-04-07 19:55:46 ----D---- C:\Program Files\Windows Media Player
2010-04-07 19:55:46 ----D---- C:\Program Files\Windows Mail
2010-04-07 19:55:46 ----D---- C:\Program Files\Internet Explorer
2010-04-07 19:55:45 ----D---- C:\Program Files\Windows Journal
2010-04-07 19:55:45 ----D---- C:\Program Files\Windows Collaboration
2010-04-07 19:55:44 ----D---- C:\Program Files\Windows Photo Gallery
2010-04-07 19:55:44 ----D---- C:\Program Files\Common Files\System
2010-04-07 19:55:42 ----D---- C:\Program Files\Windows Defender
2010-04-07 19:55:41 ----D---- C:\Windows\servicing
2010-04-07 19:55:30 ----D---- C:\Windows\PolicyDefinitions
2010-04-07 19:55:30 ----D---- C:\Windows\IME
2010-04-07 19:55:29 ----D---- C:\Windows\system32\XPSViewer
2010-04-07 19:55:29 ----D---- C:\Windows\system32\lv-LV
2010-04-07 19:55:29 ----D---- C:\Windows\system32\hr-HR
2010-04-07 19:55:29 ----D---- C:\Windows\system32\et-EE
2010-04-07 19:55:29 ----D---- C:\Windows\system32\da-DK
2010-04-07 19:55:28 ----D---- C:\Windows\system32\sk-SK
2010-04-07 19:55:26 ----D---- C:\Windows\system32\ko-KR
2010-04-07 19:55:26 ----D---- C:\Windows\system32\en-US
2010-04-07 19:55:24 ----D---- C:\Windows\system32\oobe
2010-04-07 19:55:24 ----D---- C:\Windows\system32\migration
2010-04-07 19:55:24 ----D---- C:\Windows\system32\it-IT
2010-04-07 19:55:24 ----D---- C:\Windows\system32\el-GR
2010-04-07 19:55:24 ----D---- C:\Windows\system32\de-DE
2010-04-07 19:55:20 ----D---- C:\Windows\system32\sv-SE
2010-04-07 19:55:20 ----D---- C:\Windows\system32\setup
2010-04-07 19:55:20 ----D---- C:\Windows\system32\ru-RU
2010-04-07 19:55:20 ----D---- C:\Windows\system32\hu-HU
2010-04-07 19:55:20 ----D---- C:\Windows\system32\he-IL
2010-04-07 19:55:20 ----D---- C:\Windows\system32\fr-FR
2010-04-07 19:55:20 ----D---- C:\Windows\system32\fi-FI
2010-04-07 19:55:20 ----D---- C:\Windows\system32\cs-CZ
2010-04-07 19:55:20 ----D---- C:\Windows\system32\AdvancedInstallers
2010-04-07 19:55:19 ----D---- C:\Windows\system32\SLUI
2010-04-07 19:55:19 ----D---- C:\Windows\system32\pt-PT
2010-04-07 19:55:18 ----D---- C:\Windows\system32\zh-CN
2010-04-07 19:55:18 ----D---- C:\Windows\system32\sr-Latn-CS
2010-04-07 19:55:18 ----D---- C:\Windows\system32\manifeststore
2010-04-07 19:55:18 ----D---- C:\Windows\system32\en
2010-04-07 19:55:17 ----D---- C:\Windows\system32\zh-TW
2010-04-07 19:55:17 ----D---- C:\Windows\system32\uk-UA
2010-04-07 19:55:17 ----D---- C:\Windows\system32\th-TH
2010-04-07 19:55:17 ----D---- C:\Windows\system32\sl-SI
2010-04-07 19:55:17 ----D---- C:\Windows\system32\ro-RO
2010-04-07 19:55:17 ----D---- C:\Windows\system32\pl-PL
2010-04-07 19:55:17 ----D---- C:\Windows\system32\ja-JP
2010-04-07 19:55:17 ----D---- C:\Windows\system32\es-ES
2010-04-07 19:55:17 ----D---- C:\Windows\system32\drivers
2010-04-07 19:55:17 ----D---- C:\Windows\system32\bg-BG
2010-04-07 19:55:14 ----D---- C:\Windows\system32\tr-TR
2010-04-07 19:55:13 ----D---- C:\Windows\system32\wbem
2010-04-07 19:55:12 ----D---- C:\Windows\system32\nl-NL
2010-04-07 19:55:12 ----D---- C:\Windows\system32\nb-NO
2010-04-07 19:55:12 ----D---- C:\Windows\system32\lt-LT
2010-04-07 19:55:12 ----D---- C:\Windows\system32\ar-SA
2010-04-07 19:55:11 ----D---- C:\Windows\system32\pt-BR
2010-04-07 19:55:11 ----D---- C:\Windows\system32\migwiz
2010-04-07 19:54:23 ----RSD---- C:\Windows\Fonts
2010-04-07 19:54:23 ----D---- C:\Windows\AppPatch
2010-04-07 19:54:14 ----D---- C:\Windows\system32\Boot
2010-04-07 19:17:27 ----D---- C:\Windows\system32\catroot2
2010-04-07 18:49:20 ----D---- C:\Users\Briatka\AppData\Roaming\uTorrent
2010-04-07 18:19:42 ----D---- C:\Program Files\TrojanHunter 5.0
2010-04-07 15:49:01 ----SHD---- C:\Windows\Installer
2010-04-07 15:49:01 ----SHD---- C:\Config.Msi
2010-04-07 15:48:54 ----HD---- C:\ProgramData
2010-04-07 15:48:54 ----D---- C:\Program Files\Common Files
2010-04-07 15:09:33 ----D---- C:\Windows\Prefetch
2010-04-07 14:55:57 ----D---- C:\Windows\Minidump
2010-04-06 23:27:44 ----D---- C:\Windows\system32\Tasks
2010-04-03 20:03:19 ----D---- C:\Program Files\Common Files\Java
2010-04-03 20:01:22 ----D---- C:\Program Files\Mozilla Firefox
2010-04-03 09:07:14 ----D---- C:\Sample
2010-04-03 09:04:05 ----D---- C:\Program Files\Native Instruments
2010-04-03 01:57:30 ----D---- C:\Program Files\Image-Line
2010-04-03 00:59:42 ----D---- C:\Users\Briatka\AppData\Roaming\Adobe
2010-04-03 00:56:51 ----D---- C:\Program Files\Common Files\Adobe
2010-04-03 00:52:24 ----D---- C:\ProgramData\Adobe
2010-04-03 00:52:24 ----D---- C:\Program Files\Adobe
2010-04-02 19:42:11 ----D---- C:\Program Files\Common Files\Native Instruments
2010-03-25 23:31:49 ----SD---- C:\Users\Briatka\AppData\Roaming\Microsoft
2010-03-19 01:40:11 ----D---- C:\Windows\Debug
2010-03-11 04:08:28 ----D---- C:\ProgramData\Microsoft Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2009-04-11 351744]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-06-10 53256]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2008-06-10 54280]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiif32.sys [2006-08-30 13744]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr32v.sys [2007-12-06 12080]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-06-10 39944]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2008-06-10 71688]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 PROCDD;IPS Helper Driver; C:\Windows\system32\DRIVERS\PROCDD.SYS [2006-11-06 12080]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-08 45568]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-03-15 11152]
R2 tvtfilter;tvtfilter; C:\Windows\system32\DRIVERS\tvtfilter.sys [2008-06-15 33536]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 8192]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2007-07-24 348160]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-10-25 153136]
R3 CLEDX;Team H2O CLEDX service; C:\Windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2007-04-26 225152]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2008-06-10 30728]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-05-18 26600]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-12-22 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2006-12-22 207360]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2007-05-31 21424]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-04-29 2219520]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-06-09 7522624]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2007-05-22 21376]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2007-03-15 40848]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2008-01-21 45624]
R3 TVTI2C;Lenovo SM bus driver; C:\Windows\system32\DRIVERS\Tvti2c.sys [2007-05-23 30336]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-12-22 659968]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 a29gfsa0;a29gfsa0; C:\Windows\system32\drivers\a29gfsa0.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-03-29 79664]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 81200]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 16432]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2008-07-10 32000]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2007-01-09 128104]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcPrfMgrSvc;Ac Profile Manager Service; C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe [2007-07-06 91432]
R2 AcSvc;Access Connections Main Service; C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe [2007-07-06 206120]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-07-09 144712]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 Diskeeper;Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2006-11-16 634988]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2008-06-10 468224]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2007-05-31 36400]
R2 IPSSVC;IPS Core Service; C:\Windows\system32\IPSSVC.EXE [2007-01-30 108080]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-06-09 196608]
R2 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-12-09 365280]
R2 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2010-01-18 1141712]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 SUService;System Update; c:\Program Files\Lenovo\System Update\SUService.exe [2007-06-08 13312]
R2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-08-09 644408]
R2 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG.exe [2007-10-17 37424]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2007-03-02 55936]
R2 TSSCoreService;TSS Core Service; C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe [2007-08-09 722232]
R2 TVT Backup Protection Service;TVT Backup Protection Service; C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-01-09 569344]
R2 TVT Backup Service;TVT Backup Service; C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe [2007-01-09 950272]
R2 TVT Scheduler;TVT Scheduler; c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe [2007-01-09 1118208]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-11-28 386560]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 ASKUpgrade;ASKUpgrade; C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-04-02 234888]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-04-03 72704]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-06-10 19200]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-21 523776]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-04 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-04-11 918528]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]

-----------------EOF-----------------

Re: Spomalena vista

Napsal: 08 dub 2010 17:32
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Spomalena vista

Napsal: 08 dub 2010 21:21
od skip27
ked som vypinal spyware doctora mal som pocit ze rychlost rapidne stupla.. ale chcel som este ten log z combofix-u, zial veci sa teraz maju tak, ze log mam ale nemozem ho odoslat z dovodov, ze po zapnuti cohokolvek (mozila, ie, safari, skicar, pokus o odinstalovanie mozily) proste na co som klikol vyplulo mi hlasku
"vyskytol sa pokus o nepovolenu operaciu s klucom databazy registry, ktory bol oznaceny na odstranenie"

Re: Spomalena vista

Napsal: 08 dub 2010 22:07
od Rudy
Vypnul jste také ESS? Co dává tu hlášku. Systém nebo nějaká aplikace?

Re: Spomalena vista

Napsal: 08 dub 2010 22:10
od skip27
system, ess som dal docasne vypnut.. mozno sa po restarte znovu zapol

Re: Spomalena vista

Napsal: 08 dub 2010 22:22
od Rudy
Ano. Aplikace Esetu se po restartu samy zapínají. Pokud se dostanete na fórum, můžete sem obsah log souboru zkopírovat.

Re: Spomalena vista

Napsal: 08 dub 2010 23:32
od skip27
z daneho pc sa stale nedokazem dostat na internet ani otvorit dokumenty a aplikacie.. stale ta ista hlaska..
no nie som nijaky odbornik ale asi bol pocas skenu zapnuty eset... momentalne nie som schopny ani spravit iny log.. stale ta ista hlaska..

ComboFix 10-04-07.04 - Briatka . 04. 2010 21:28:21.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.421.1051.18.2046.1074 [GMT 2:00]
Running from: c:\users\Briatka\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1373474349-213147588-539347450-500
C:\install.exe
c:\program files\Search Settings
c:\program files\Search Settings\kb127\SearchSettings.dll
c:\program files\Search Settings\kb127\SearchSettingsRes409.dll
c:\program files\Search Settings\searchsettings .exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
c:\users\Briatka\AppData\Roaming\chrtmp
c:\windows\UA000106.DLL

.
((((((((((((((((((((((((( Files Created from 2010-03-08 to 2010-04-08 )))))))))))))))))))))))))))))))
.

2010-04-08 19:44 . 2010-04-08 19:50 -------- d-----w- c:\users\Briatka\AppData\Local\temp
2010-04-08 19:44 . 2010-04-08 19:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-08 19:15 . 2010-04-08 19:19 -------- d-----w- C:\32788R22FWJFW
2010-04-08 18:56 . 2010-04-08 18:56 -------- d-----w- c:\program files\Windows Portable Devices
2010-04-08 18:36 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-04-08 18:32 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-04-08 18:32 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-04-08 18:32 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-04-08 13:00 . 2010-04-08 14:30 -------- d-----w- c:\program files\trend micro
2010-04-08 13:00 . 2010-04-08 13:01 -------- d-----w- C:\rsit
2010-04-07 17:54 . 2010-04-07 17:55 -------- d-----w- c:\windows\system32\ca-ES
2010-04-07 17:54 . 2010-04-07 17:55 -------- d-----w- c:\windows\system32\eu-ES
2010-04-07 17:54 . 2010-04-07 17:55 -------- d-----w- c:\windows\system32\vi-VN
2010-04-07 17:17 . 2010-04-07 17:17 -------- d-----w- c:\windows\system32\EventProviders
2010-04-07 13:48 . 2010-04-07 13:48 -------- d-----w- c:\users\Briatka\AppData\Roaming\PC Tools
2010-04-07 13:48 . 2010-04-07 13:48 -------- d-----w- c:\programdata\PC Tools
2010-04-07 13:10 . 2010-04-07 16:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-07 13:10 . 2010-04-07 16:34 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-06 09:50 . 2010-04-06 09:50 -------- d-----w- c:\users\Briatka\AppData\Roaming\Blue Cat Audio
2010-04-06 09:49 . 2010-04-06 09:49 -------- d-----w- c:\program files\Common Files\VST3
2010-04-06 09:49 . 2010-04-06 09:49 -------- d-----w- c:\program files\iZotope
2010-04-03 07:06 . 2010-04-06 10:43 -------- d-----w- C:\folder ni
2010-04-03 07:05 . 2006-10-04 12:13 393216 ----a-w- c:\windows\system32\NI_IRC_1_2.dll
2010-04-03 07:04 . 2006-10-04 12:13 61440 ----a-w- c:\windows\system32\NI_DFD_1_5.dll
2010-04-03 07:04 . 2006-10-04 12:13 1870336 ----a-w- c:\windows\system32\bconvert.dll
2010-04-02 22:57 . 2010-04-02 22:57 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2010-04-02 17:47 . 2010-04-02 17:47 -------- dc-h--w- c:\programdata\{BF329843-149E-4A5A-82A1-0250286442D0}
2010-04-02 17:45 . 2010-04-02 17:45 -------- dc-h--w- c:\programdata\{4275E5EA-6E30-48EB-A209-F964539CBE1C}
2010-04-01 12:19 . 2010-04-01 12:19 -------- d-----w- c:\program files\CCleaner
2010-03-31 11:08 . 2010-03-31 11:08 -------- d-----w- c:\programdata\Western Digital
2010-03-31 11:07 . 2010-03-31 11:07 -------- d-----w- c:\users\Briatka\AppData\Local\Western Digital
2010-03-29 01:01 . 2010-02-12 10:48 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-03-27 17:12 . 2010-03-27 17:12 -------- d-----w- C:\A
2010-03-11 02:02 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-03-11 02:02 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-03-11 02:02 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-08 19:53 . 2010-04-07 13:48 -------- d-----w- c:\program files\Spyware Doctor
2010-04-08 19:49 . 2009-07-22 11:26 55487 ----a-w- c:\programdata\nvModes.dat
2010-04-08 19:45 . 2008-06-15 10:50 12 ----a-w- c:\windows\bthservsdp.dat
2010-04-08 18:45 . 2010-04-08 18:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-04-08 18:42 . 2010-04-08 18:42 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-04-07 17:55 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-04-07 16:49 . 2009-07-28 15:54 -------- d-----w- c:\users\Briatka\AppData\Roaming\uTorrent
2010-04-07 16:19 . 2009-04-26 21:03 -------- d-----w- c:\program files\TrojanHunter 5.0
2010-04-07 13:49 . 2010-04-07 13:48 -------- d-----w- c:\program files\Common Files\PC Tools
2010-04-07 13:48 . 2010-04-07 13:48 34870088 ----a-w- c:\users\Briatka\AppData\Roaming\sdasetup.exe
2010-04-03 18:03 . 2008-06-15 11:30 -------- d-----w- c:\program files\Common Files\Java
2010-04-03 07:04 . 2008-08-05 22:26 -------- d-----w- c:\program files\Native Instruments
2010-04-02 23:57 . 2009-01-27 14:26 -------- d-----w- c:\program files\Image-Line
2010-04-02 22:58 . 2008-07-11 19:53 113360 ----a-w- c:\users\Briatka\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-02 22:56 . 2008-08-04 21:15 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-02 17:42 . 2009-07-29 08:34 -------- d-----w- c:\program files\Common Files\Native Instruments
2010-03-11 02:08 . 2008-06-15 11:57 -------- d-----w- c:\programdata\Microsoft Help
2010-03-06 20:20 . 2010-03-06 13:41 -------- d-----w- c:\users\Briatka\AppData\Roaming\foobar2000
2010-03-06 13:41 . 2010-03-06 13:41 -------- d-----w- c:\program files\foobar2000
2010-02-24 09:16 . 2009-10-03 08:15 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39 . 2010-03-31 10:32 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 10:32 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-31 10:32 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-31 10:32 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:33 . 2008-07-13 10:24 -------- d-----w- c:\program files\ESET
2010-02-20 23:04 . 2010-02-20 23:04 -------- d-----w- c:\programdata\Alwil Software
2010-02-20 23:04 . 2010-02-20 23:04 -------- d-----w- c:\program files\Alwil Software
2010-02-17 16:03 . 2008-07-13 21:15 -------- d-----w- c:\users\Briatka\AppData\Roaming\Apple Computer
2010-02-16 14:06 . 2010-02-16 14:06 -------- d-----w- c:\program files\HooTech
2010-02-05 07:25 . 2010-04-07 13:48 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-05 07:18 . 2010-04-07 13:49 100136 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2010-02-05 07:17 . 2010-04-07 13:49 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-25 12:00 . 2010-02-24 08:17 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-24 08:17 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-24 08:17 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-24 08:17 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-24 08:17 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-24 08:17 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-24 08:17 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-24 08:17 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-24 08:17 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-24 08:16 2048 ----a-w- c:\windows\system32\tzres.dll
2008-06-15 10:41 . 2008-06-15 10:41 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

Kód: Vybrat vše

<pre>
c:\program files\Dealio\dealioau .exe
c:\program files\ThinkPad\Utilities\ezejmnap .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]

[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 10:47 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2009-11-09 17:38 2331672 ----a-w- c:\program files\DVDVideoSoft\tbDVDV.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-11-29 59168]
"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2007-12-06 324896]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2007-12-06 214576]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2007-03-09 66176]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-03-05 172032]
"TpShocks"="TpShocks.exe" [2007-11-22 181536]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [N/A]
"LenovoOobeOffers"="c:\swtools\LenovoWelcome\LenovoOobeOffers.exe" [2007-09-25 28672]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-01-09 536576]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-11-15 217176]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2007-04-26 120368]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 419376]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-07-05 419112]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-07-05 124200]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2007-08-09 2630968]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [N/A]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-15 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-09 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-09 92704]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2008-06-09 397456]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-05-11 200069]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-10 1447168]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-01-18 1286608]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-07-09 1282048]

c:\users\Briatka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Orez vaź obrazovky a spŁçśaź programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-6-15 50688]
LenovoRegistration.lnk - c:\swtools\LenovoWelcome\LenovoRegistration.cmd [2007-10-4 166]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-03-15 05:17 89600 ----a-w- c:\windows\System32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\au]
c:\program files\Dealio\DealioAU.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DU Meter]
c:\program files\DU Meter\DUMeter.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
c:\program files\ESET\ESET NOD32 Antivirus\egui.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2010-01-18 12:14 1286608 ----a-w- c:\program files\Spyware Doctor\pctsTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
2007-12-14 10:36 50472 ------w- c:\program files\CyberLink\PowerDVD8\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
2008-03-20 19:23 83240 ------w- c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
2009-04-26 21:06 1046688 ----a-w- c:\program files\TrojanHunter 5.0\THGuard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):90,b4,a3,61,7c,d6,ca,01

R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-04-02 234888]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-09-23 207280]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-06-12 721904]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2007-10-17 19504]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2006-08-30 13744]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2008-06-10 468224]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-12-09 365280]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-03-15 11152]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2007-03-02 55936]
S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-01-09 569344]
S3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2007-05-22 30336]


--- Other Services/Drivers In Memory ---

*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-04-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 13:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Compare Prices with &Dealio - c:\users\Briatka\AppData\LocalLow\Dealio\kb127\res\DealioSearch.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Briatka\AppData\Roaming\Mozilla\Firefox\Profiles\uiicnagu.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Briatka\Program Files\DNA\plugins\npbtdna.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-08 21:49
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys acpi.sys hal.dll iaStor.sys spsg.sys >>UNKNOWN [0x853D8938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x889c2d24
\Driver\ACPI -> acpi.sys @ 0x805bfd68
\Driver\atapi -> 0x854211f8
\Driver\iaStor -> iaStor.sys @ 0x82b31d30
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(764)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll

- - - - - - - > 'Explorer.exe'(5216)
c:\program files\Spyware Doctor\pctgmhk.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\ThinkVantage Fingerprint Software\upeksvr.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\windows\system32\AEADISRV.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\System32\TPHDEXLG.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Completion time: 2010-04-08 22:01:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-08 20:01

Pre-Run: 3 994 701 824 bytes free
Post-Run: 5 355 642 880 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - C598BEB71F1B66865C200407A55647DF

Re: Spomalena vista

Napsal: 09 dub 2010 00:25
od skip27
uz som zacinal mat strach ked som cital ako neodborne manipulovanie s combofixom moze poskodit pc... avsak nateraz mozem opat manipulovat so subormi (po obycajnom restarte)

Re: Spomalena vista

Napsal: 09 dub 2010 17:07
od Rudy
No, nedoporučuje se, aby laici sami používali utilitu ComboFix. Může se při tom stát, že si poškodí systém. Ale k věci: Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files\Dealio
c:\program files\AskBarDis

Driver::
ASKUpgrade

Registry::
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
[-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"=-
[-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SearchSettings"=-

RenV::
c:\program files\ThinkPad\Utilities\ezejmnap .exe
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Spomalena vista

Napsal: 09 dub 2010 23:42
od skip27
vykonane + aktualny log na kontrolu

ComboFix 10-04-07.04 - Briatka . 04. 2010 21:53:17.2.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1250.421.1051.18.2046.1173 [GMT 2:00]
Running from: c:\users\Briatka\Desktop\ComboFix.exe
Command switches used :: c:\users\Briatka\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\AskSplash.exe
c:\program files\AskBarDis\bar\bin\AskTBApp.exe
c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Settings\AskLogo.ico
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\program files\Dealio
c:\program files\Dealio\dealioau .exe
c:\program files\Dealio\kb127\Dealio Deskbar.exe
c:\program files\Dealio\kb127\Dealio.dll
c:\program files\Dealio\kb127\DealioRes409.dll
c:\program files\Dealio\kb127\res\alerts.gif
c:\program files\Dealio\kb127\res\alerts_over.gif
c:\program files\Dealio\kb127\res\alerts_rec.gif
c:\program files\Dealio\kb127\res\alerts_rec_over.gif
c:\program files\Dealio\kb127\res\deal_report.jpg
c:\program files\Dealio\kb127\res\DealioSearch.html
c:\program files\Dealio\kb127\res\deals-leftcap.gif
c:\program files\Dealio\kb127\res\ebay_login.jpg
c:\program files\Dealio\kb127\res\err_mainwindow.html
c:\program files\Dealio\kb127\res\err_toolbar.html
c:\program files\Dealio\kb127\res\global_scripts.js
c:\program files\Dealio\kb127\res\headerbgthin.jpg
c:\program files\Dealio\kb127\res\highlight-bg.png
c:\program files\Dealio\kb127\res\chevron-small.gif
c:\program files\Dealio\kb127\res\logo.gif
c:\program files\Dealio\kb127\res\logo_over.gif
c:\program files\Dealio\kb127\res\man_toolbar.css
c:\program files\Dealio\kb127\res\man_toolbar.html
c:\program files\Dealio\kb127\res\man_toolbar.js
c:\program files\Dealio\kb127\res\man_toolbarl.js
c:\program files\Dealio\kb127\res\post-this-deal.gif
c:\program files\Dealio\kb127\res\post-this-deal_over.gif
c:\program files\Dealio\kb127\res\scripts.js
c:\program files\Dealio\kb127\res\scroller.js
c:\program files\Dealio\kb127\res\search-chevron.gif
c:\program files\Dealio\kb127\res\search-chevron_over.gif
c:\program files\Dealio\kb127\res\search_bg_blink.gif
c:\program files\Dealio\kb127\res\separator.gif
c:\program files\Dealio\kb127\res\settings.gif
c:\program files\Dealio\kb127\res\settings_over.gif
c:\program files\Dealio\kb127\res\yahoo-search.png
c:\program files\Dealio\kb127\resDN\bottom.gif
c:\program files\Dealio\kb127\resDN\close.gif
c:\program files\Dealio\kb127\resDN\deskbar.css
c:\program files\Dealio\kb127\resDN\deskbar.js
c:\program files\Dealio\kb127\resDN\dispatch_helper.js
c:\program files\Dealio\kb127\resDN\ebay_compatible.jpg
c:\program files\Dealio\kb127\resDN\chevron_down.gif
c:\program files\Dealio\kb127\resDN\chevron_up.gif
c:\program files\Dealio\kb127\resDN\logo.gif
c:\program files\Dealio\kb127\resDN\logo_chevron_bkg.gif
c:\program files\Dealio\kb127\resDN\losing.gif
c:\program files\Dealio\kb127\resDN\lost.gif
c:\program files\Dealio\kb127\resDN\man_deskbar.html
c:\program files\Dealio\kb127\resDN\menu_arrow.gif
c:\program files\Dealio\kb127\resDN\menu_check.gif
c:\program files\Dealio\kb127\resDN\no_image.gif
c:\program files\Dealio\kb127\resDN\prod_img.gif
c:\program files\Dealio\kb127\resDN\search_chevron.gif
c:\program files\Dealio\kb127\resDN\spacer.gif
c:\program files\Dealio\kb127\resDN\textfield_bkg.gif
c:\program files\Dealio\kb127\resDN\top.gif
c:\program files\Dealio\kb127\resDN\unknown.gif
c:\program files\Dealio\kb127\resDN\winning.gif
c:\program files\Dealio\kb127\resDN\won.gif
c:\program files\Dealio\kb127\rules\index.76.35
c:\program files\Dealio\kb127\rules\rules.1.10.76
c:\program files\Dealio\kb127\rules\rules.1.109.43
c:\program files\Dealio\kb127\rules\rules.1.110.43
c:\program files\Dealio\kb127\rules\rules.1.12.52
c:\program files\Dealio\kb127\rules\rules.1.13.58
c:\program files\Dealio\kb127\rules\rules.1.130.58
c:\program files\Dealio\kb127\rules\rules.1.135.50
c:\program files\Dealio\kb127\rules\rules.1.153.44
c:\program files\Dealio\kb127\rules\rules.1.155.43
c:\program files\Dealio\kb127\rules\rules.1.156.49
c:\program files\Dealio\kb127\rules\rules.1.16.60
c:\program files\Dealio\kb127\rules\rules.1.161.52
c:\program files\Dealio\kb127\rules\rules.1.178.66
c:\program files\Dealio\kb127\rules\rules.1.184.55
c:\program files\Dealio\kb127\rules\rules.1.188.52
c:\program files\Dealio\kb127\rules\rules.1.189.45
c:\program files\Dealio\kb127\rules\rules.1.196.43
c:\program files\Dealio\kb127\rules\rules.1.198.56
c:\program files\Dealio\kb127\rules\rules.1.199.43
c:\program files\Dealio\kb127\rules\rules.1.200.53
c:\program files\Dealio\kb127\rules\rules.1.201.43
c:\program files\Dealio\kb127\rules\rules.1.202.43
c:\program files\Dealio\kb127\rules\rules.1.203.71
c:\program files\Dealio\kb127\rules\rules.1.205.62
c:\program files\Dealio\kb127\rules\rules.1.213.71
c:\program files\Dealio\kb127\rules\rules.1.214.49
c:\program files\Dealio\kb127\rules\rules.1.215.43
c:\program files\Dealio\kb127\rules\rules.1.216.67
c:\program files\Dealio\kb127\rules\rules.1.217.67
c:\program files\Dealio\kb127\rules\rules.1.218.52
c:\program files\Dealio\kb127\rules\rules.1.219.43
c:\program files\Dealio\kb127\rules\rules.1.220.43
c:\program files\Dealio\kb127\rules\rules.1.221.57
c:\program files\Dealio\kb127\rules\rules.1.222.43
c:\program files\Dealio\kb127\rules\rules.1.223.68
c:\program files\Dealio\kb127\rules\rules.1.226.68
c:\program files\Dealio\kb127\rules\rules.1.227.43
c:\program files\Dealio\kb127\rules\rules.1.228.62
c:\program files\Dealio\kb127\rules\rules.1.229.76
c:\program files\Dealio\kb127\rules\rules.1.23.63
c:\program files\Dealio\kb127\rules\rules.1.239.43
c:\program files\Dealio\kb127\rules\rules.1.24.43
c:\program files\Dealio\kb127\rules\rules.1.240.43
c:\program files\Dealio\kb127\rules\rules.1.241.43
c:\program files\Dealio\kb127\rules\rules.1.242.43
c:\program files\Dealio\kb127\rules\rules.1.243.43
c:\program files\Dealio\kb127\rules\rules.1.244.63
c:\program files\Dealio\kb127\rules\rules.1.245.43
c:\program files\Dealio\kb127\rules\rules.1.247.43
c:\program files\Dealio\kb127\rules\rules.1.248.43
c:\program files\Dealio\kb127\rules\rules.1.249.43
c:\program files\Dealio\kb127\rules\rules.1.250.43
c:\program files\Dealio\kb127\rules\rules.1.251.43
c:\program files\Dealio\kb127\rules\rules.1.252.43
c:\program files\Dealio\kb127\rules\rules.1.253.43
c:\program files\Dealio\kb127\rules\rules.1.254.43
c:\program files\Dealio\kb127\rules\rules.1.255.43
c:\program files\Dealio\kb127\rules\rules.1.256.43
c:\program files\Dealio\kb127\rules\rules.1.257.43
c:\program files\Dealio\kb127\rules\rules.1.279.43
c:\program files\Dealio\kb127\rules\rules.1.28.58
c:\program files\Dealio\kb127\rules\rules.1.282.75
c:\program files\Dealio\kb127\rules\rules.1.283.43
c:\program files\Dealio\kb127\rules\rules.1.284.43
c:\program files\Dealio\kb127\rules\rules.1.289.67
c:\program files\Dealio\kb127\rules\rules.1.290.62
c:\program files\Dealio\kb127\rules\rules.1.291.61
c:\program files\Dealio\kb127\rules\rules.1.296.43
c:\program files\Dealio\kb127\rules\rules.1.297.43
c:\program files\Dealio\kb127\rules\rules.1.304.43
c:\program files\Dealio\kb127\rules\rules.1.307.43
c:\program files\Dealio\kb127\rules\rules.1.308.75
c:\program files\Dealio\kb127\rules\rules.1.31.47
c:\program files\Dealio\kb127\rules\rules.1.310.46
c:\program files\Dealio\kb127\rules\rules.1.311.43
c:\program files\Dealio\kb127\rules\rules.1.315.43
c:\program files\Dealio\kb127\rules\rules.1.316.43
c:\program files\Dealio\kb127\rules\rules.1.317.43
c:\program files\Dealio\kb127\rules\rules.1.318.43
c:\program files\Dealio\kb127\rules\rules.1.319.49
c:\program files\Dealio\kb127\rules\rules.1.32.48
c:\program files\Dealio\kb127\rules\rules.1.334.44
c:\program files\Dealio\kb127\rules\rules.1.335.60
c:\program files\Dealio\kb127\rules\rules.1.336.44
c:\program files\Dealio\kb127\rules\rules.1.337.44
c:\program files\Dealio\kb127\rules\rules.1.338.75
c:\program files\Dealio\kb127\rules\rules.1.339.47
c:\program files\Dealio\kb127\rules\rules.1.34.43
c:\program files\Dealio\kb127\rules\rules.1.340.47
c:\program files\Dealio\kb127\rules\rules.1.341.47
c:\program files\Dealio\kb127\rules\rules.1.349.50
c:\program files\Dealio\kb127\rules\rules.1.35.48
c:\program files\Dealio\kb127\rules\rules.1.350.50
c:\program files\Dealio\kb127\rules\rules.1.351.51
c:\program files\Dealio\kb127\rules\rules.1.352.54
c:\program files\Dealio\kb127\rules\rules.1.353.51
c:\program files\Dealio\kb127\rules\rules.1.354.51
c:\program files\Dealio\kb127\rules\rules.1.357.62
c:\program files\Dealio\kb127\rules\rules.1.358.52
c:\program files\Dealio\kb127\rules\rules.1.359.52
c:\program files\Dealio\kb127\rules\rules.1.360.53
c:\program files\Dealio\kb127\rules\rules.1.361.54
c:\program files\Dealio\kb127\rules\rules.1.362.68
c:\program files\Dealio\kb127\rules\rules.1.363.58
c:\program files\Dealio\kb127\rules\rules.1.364.54
c:\program files\Dealio\kb127\rules\rules.1.365.53
c:\program files\Dealio\kb127\rules\rules.1.367.56
c:\program files\Dealio\kb127\rules\rules.1.368.58
c:\program files\Dealio\kb127\rules\rules.1.369.55
c:\program files\Dealio\kb127\rules\rules.1.370.56
c:\program files\Dealio\kb127\rules\rules.1.371.56
c:\program files\Dealio\kb127\rules\rules.1.372.57
c:\program files\Dealio\kb127\rules\rules.1.373.55
c:\program files\Dealio\kb127\rules\rules.1.375.56
c:\program files\Dealio\kb127\rules\rules.1.376.57
c:\program files\Dealio\kb127\rules\rules.1.377.55
c:\program files\Dealio\kb127\rules\rules.1.378.65
c:\program files\Dealio\kb127\rules\rules.1.384.58
c:\program files\Dealio\kb127\rules\rules.1.386.71
c:\program files\Dealio\kb127\rules\rules.1.387.59
c:\program files\Dealio\kb127\rules\rules.1.388.59
c:\program files\Dealio\kb127\rules\rules.1.389.59
c:\program files\Dealio\kb127\rules\rules.1.390.60
c:\program files\Dealio\kb127\rules\rules.1.391.60
c:\program files\Dealio\kb127\rules\rules.1.392.60
c:\program files\Dealio\kb127\rules\rules.1.393.60
c:\program files\Dealio\kb127\rules\rules.1.394.60
c:\program files\Dealio\kb127\rules\rules.1.396.61
c:\program files\Dealio\kb127\rules\rules.1.397.61
c:\program files\Dealio\kb127\rules\rules.1.398.60
c:\program files\Dealio\kb127\rules\rules.1.399.60
c:\program files\Dealio\kb127\rules\rules.1.403.61
c:\program files\Dealio\kb127\rules\rules.1.404.63
c:\program files\Dealio\kb127\rules\rules.1.405.61
c:\program files\Dealio\kb127\rules\rules.1.406.61
c:\program files\Dealio\kb127\rules\rules.1.407.76
c:\program files\Dealio\kb127\rules\rules.1.408.63
c:\program files\Dealio\kb127\rules\rules.1.409.61
c:\program files\Dealio\kb127\rules\rules.1.412.62
c:\program files\Dealio\kb127\rules\rules.1.413.62
c:\program files\Dealio\kb127\rules\rules.1.414.62
c:\program files\Dealio\kb127\rules\rules.1.415.62
c:\program files\Dealio\kb127\rules\rules.1.416.62
c:\program files\Dealio\kb127\rules\rules.1.417.62
c:\program files\Dealio\kb127\rules\rules.1.418.62
c:\program files\Dealio\kb127\rules\rules.1.419.62
c:\program files\Dealio\kb127\rules\rules.1.420.62
c:\program files\Dealio\kb127\rules\rules.1.421.62
c:\program files\Dealio\kb127\rules\rules.1.423.63
c:\program files\Dealio\kb127\rules\rules.1.424.63
c:\program files\Dealio\kb127\rules\rules.1.425.63
c:\program files\Dealio\kb127\rules\rules.1.426.63
c:\program files\Dealio\kb127\rules\rules.1.427.63
c:\program files\Dealio\kb127\rules\rules.1.428.65
c:\program files\Dealio\kb127\rules\rules.1.429.63
c:\program files\Dealio\kb127\rules\rules.1.430.63
c:\program files\Dealio\kb127\rules\rules.1.432.65
c:\program files\Dealio\kb127\rules\rules.1.433.64
c:\program files\Dealio\kb127\rules\rules.1.434.65
c:\program files\Dealio\kb127\rules\rules.1.435.64
c:\program files\Dealio\kb127\rules\rules.1.436.76
c:\program files\Dealio\kb127\rules\rules.1.437.64
c:\program files\Dealio\kb127\rules\rules.1.438.71
c:\program files\Dealio\kb127\rules\rules.1.439.71
c:\program files\Dealio\kb127\rules\rules.1.440.75
c:\program files\Dealio\kb127\rules\rules.1.442.73
c:\program files\Dealio\kb127\rules\rules.1.443.73
c:\program files\Dealio\kb127\rules\rules.1.444.73
c:\program files\Dealio\kb127\rules\rules.1.445.68
c:\program files\Dealio\kb127\rules\rules.1.446.69
c:\program files\Dealio\kb127\rules\rules.1.450.67
c:\program files\Dealio\kb127\rules\rules.1.451.67
c:\program files\Dealio\kb127\rules\rules.1.452.68
c:\program files\Dealio\kb127\rules\rules.1.453.68
c:\program files\Dealio\kb127\rules\rules.1.454.69
c:\program files\Dealio\kb127\rules\rules.1.456.69
c:\program files\Dealio\kb127\rules\rules.1.457.75
c:\program files\Dealio\kb127\rules\rules.1.458.70
c:\program files\Dealio\kb127\rules\rules.1.459.70
c:\program files\Dealio\kb127\rules\rules.1.460.69
c:\program files\Dealio\kb127\rules\rules.1.462.74
c:\program files\Dealio\kb127\rules\rules.1.463.69
c:\program files\Dealio\kb127\rules\rules.1.464.70
c:\program files\Dealio\kb127\rules\rules.1.465.68
c:\program files\Dealio\kb127\rules\rules.1.468.70
c:\program files\Dealio\kb127\rules\rules.1.469.70
c:\program files\Dealio\kb127\rules\rules.1.470.70
c:\program files\Dealio\kb127\rules\rules.1.471.73
c:\program files\Dealio\kb127\rules\rules.1.472.70
c:\program files\Dealio\kb127\rules\rules.1.478.74
c:\program files\Dealio\kb127\rules\rules.1.479.73
c:\program files\Dealio\kb127\rules\rules.1.480.68
c:\program files\Dealio\kb127\rules\rules.1.481.71
c:\program files\Dealio\kb127\rules\rules.1.482.74
c:\program files\Dealio\kb127\rules\rules.1.49.67
c:\program files\Dealio\kb127\rules\rules.1.50.43
c:\program files\Dealio\kb127\rules\rules.1.500.71
c:\program files\Dealio\kb127\rules\rules.1.501.74
c:\program files\Dealio\kb127\rules\rules.1.502.71
c:\program files\Dealio\kb127\rules\rules.1.51.69
c:\program files\Dealio\kb127\rules\rules.1.52.72
c:\program files\Dealio\kb127\rules\rules.1.520.76
c:\program files\Dealio\kb127\rules\rules.1.521.76
c:\program files\Dealio\kb127\rules\rules.1.522.76
c:\program files\Dealio\kb127\rules\rules.1.53.51
c:\program files\Dealio\kb127\rules\rules.1.531.76
c:\program files\Dealio\kb127\rules\rules.1.532.75
c:\program files\Dealio\kb127\rules\rules.1.534.75
c:\program files\Dealio\kb127\rules\rules.1.54.47
c:\program files\Dealio\kb127\rules\rules.1.55.45
c:\program files\Dealio\kb127\rules\rules.1.56.69
c:\program files\Dealio\kb127\rules\rules.1.57.43
c:\program files\Dealio\kb127\rules\rules.1.58.47
c:\program files\Dealio\kb127\rules\rules.1.593.76
c:\program files\Dealio\kb127\rules\rules.1.595.76
c:\program files\Dealio\kb127\rules\rules.1.63.57
c:\program files\Dealio\kb127\rules\rules.1.66.47
c:\program files\Dealio\kb127\rules\rules.1.70.75
c:\program files\Dealio\kb127\rules\rules.1.71.43
c:\program files\Dealio\SearchSettingsKit.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ASKUpgrade


((((((((((((((((((((((((( Files Created from 2010-03-09 to 2010-04-09 )))))))))))))))))))))))))))))))
.

2010-04-09 20:14 . 2010-04-09 20:14 -------- d-----w- C:\B
2010-04-09 20:10 . 2010-04-09 20:15 -------- d-----w- c:\users\Briatka\AppData\Local\temp
2010-04-09 20:10 . 2010-04-09 20:10 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-04-09 20:10 . 2010-04-09 20:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-09 19:40 . 2010-04-09 19:44 -------- d-----w- C:\32788R22FWJFW
2010-04-08 19:17 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-04-08 19:17 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-04-08 19:17 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-04-08 18:56 . 2010-04-08 18:56 -------- d-----w- c:\program files\Windows Portable Devices
2010-04-08 18:36 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-04-08 18:32 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-04-08 18:32 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-04-08 18:32 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-04-08 13:00 . 2010-04-08 14:30 -------- d-----w- c:\program files\trend micro
2010-04-08 13:00 . 2010-04-08 13:01 -------- d-----w- C:\rsit
2010-04-07 17:54 . 2010-04-07 17:55 -------- d-----w- c:\windows\system32\ca-ES
2010-04-07 17:54 . 2010-04-07 17:55 -------- d-----w- c:\windows\system32\eu-ES
2010-04-07 17:54 . 2010-04-07 17:55 -------- d-----w- c:\windows\system32\vi-VN
2010-04-07 17:17 . 2010-04-07 17:17 -------- d-----w- c:\windows\system32\EventProviders
2010-04-07 13:48 . 2010-04-07 13:48 -------- d-----w- c:\users\Briatka\AppData\Roaming\PC Tools
2010-04-07 13:48 . 2010-04-07 13:48 -------- d-----w- c:\programdata\PC Tools
2010-04-07 13:10 . 2010-04-07 16:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-07 13:10 . 2010-04-07 16:34 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-06 09:50 . 2010-04-06 09:50 -------- d-----w- c:\users\Briatka\AppData\Roaming\Blue Cat Audio
2010-04-06 09:49 . 2010-04-06 09:49 -------- d-----w- c:\program files\Common Files\VST3
2010-04-06 09:49 . 2010-04-06 09:49 -------- d-----w- c:\program files\iZotope
2010-04-03 07:06 . 2010-04-09 11:50 -------- d-----w- C:\folder ni
2010-04-03 07:05 . 2006-10-04 12:13 393216 ----a-w- c:\windows\system32\NI_IRC_1_2.dll
2010-04-03 07:04 . 2006-10-04 12:13 61440 ----a-w- c:\windows\system32\NI_DFD_1_5.dll
2010-04-03 07:04 . 2006-10-04 12:13 1870336 ----a-w- c:\windows\system32\bconvert.dll
2010-04-02 22:57 . 2010-04-02 22:57 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2010-04-02 17:47 . 2010-04-02 17:47 -------- dc-h--w- c:\programdata\{BF329843-149E-4A5A-82A1-0250286442D0}
2010-04-02 17:45 . 2010-04-02 17:45 -------- dc-h--w- c:\programdata\{4275E5EA-6E30-48EB-A209-F964539CBE1C}
2010-04-01 12:19 . 2010-04-01 12:19 -------- d-----w- c:\program files\CCleaner
2010-03-31 11:08 . 2010-03-31 11:08 -------- d-----w- c:\programdata\Western Digital
2010-03-31 11:07 . 2010-03-31 11:07 -------- d-----w- c:\users\Briatka\AppData\Local\Western Digital
2010-03-29 01:01 . 2010-02-12 10:48 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-03-27 17:12 . 2010-03-27 17:12 -------- d-----w- C:\A
2010-03-11 02:02 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-03-11 02:02 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-03-11 02:02 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-09 20:20 . 2010-04-07 13:48 -------- d-----w- c:\program files\Spyware Doctor
2010-04-09 20:13 . 2009-07-22 11:26 55487 ----a-w- c:\programdata\nvModes.dat
2010-04-09 20:11 . 2008-06-15 10:50 12 ----a-w- c:\windows\bthservsdp.dat
2010-04-08 18:45 . 2010-04-08 18:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-04-08 18:42 . 2010-04-08 18:42 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-04-07 17:55 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-04-07 17:55 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-04-07 16:49 . 2009-07-28 15:54 -------- d-----w- c:\users\Briatka\AppData\Roaming\uTorrent
2010-04-07 16:19 . 2009-04-26 21:03 -------- d-----w- c:\program files\TrojanHunter 5.0
2010-04-07 13:49 . 2010-04-07 13:48 -------- d-----w- c:\program files\Common Files\PC Tools
2010-04-07 13:48 . 2010-04-07 13:48 34870088 ----a-w- c:\users\Briatka\AppData\Roaming\sdasetup.exe
2010-04-03 18:03 . 2008-06-15 11:30 -------- d-----w- c:\program files\Common Files\Java
2010-04-03 07:04 . 2008-08-05 22:26 -------- d-----w- c:\program files\Native Instruments
2010-04-02 23:57 . 2009-01-27 14:26 -------- d-----w- c:\program files\Image-Line
2010-04-02 22:58 . 2008-07-11 19:53 113360 ----a-w- c:\users\Briatka\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-02 22:56 . 2008-08-04 21:15 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-02 17:42 . 2009-07-29 08:34 -------- d-----w- c:\program files\Common Files\Native Instruments
2010-03-11 02:08 . 2008-06-15 11:57 -------- d-----w- c:\programdata\Microsoft Help
2010-03-06 20:20 . 2010-03-06 13:41 -------- d-----w- c:\users\Briatka\AppData\Roaming\foobar2000
2010-03-06 13:41 . 2010-03-06 13:41 -------- d-----w- c:\program files\foobar2000
2010-02-24 09:16 . 2009-10-03 08:15 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39 . 2010-03-31 10:32 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 10:32 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-31 10:32 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-31 10:32 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:33 . 2008-07-13 10:24 -------- d-----w- c:\program files\ESET
2010-02-20 23:04 . 2010-02-20 23:04 -------- d-----w- c:\programdata\Alwil Software
2010-02-20 23:04 . 2010-02-20 23:04 -------- d-----w- c:\program files\Alwil Software
2010-02-17 16:03 . 2008-07-13 21:15 -------- d-----w- c:\users\Briatka\AppData\Roaming\Apple Computer
2010-02-16 14:06 . 2010-02-16 14:06 -------- d-----w- c:\program files\HooTech
2010-02-05 07:25 . 2010-04-07 13:48 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-05 07:18 . 2010-04-07 13:49 100136 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2010-02-05 07:17 . 2010-04-07 13:49 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-25 12:00 . 2010-02-24 08:17 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-24 08:17 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-24 08:17 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-24 08:17 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-24 08:17 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-24 08:17 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-24 08:17 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-24 08:17 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-24 08:17 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-24 08:16 2048 ----a-w- c:\windows\system32\tzres.dll
2008-06-15 10:41 . 2008-06-15 10:41 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]

[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]
2009-11-09 17:38 2331672 ----a-w- c:\program files\DVDVideoSoft\tbDVDV.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]

[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F}"= "c:\program files\DVDVideoSoft\tbDVDV.dll" [2009-11-09 2331672]

[HKEY_CLASSES_ROOT\clsid\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-11-29 59168]
"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2007-12-06 324896]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2007-12-06 214576]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2007-03-09 66176]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-03-05 172032]
"TpShocks"="TpShocks.exe" [2007-11-22 181536]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-03-28 243248]
"LenovoOobeOffers"="c:\swtools\LenovoWelcome\LenovoOobeOffers.exe" [2007-09-25 28672]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-01-09 536576]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-11-15 217176]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2007-04-26 120368]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 419376]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-07-05 419112]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-07-05 124200]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2007-08-09 2630968]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-15 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-09 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-09 92704]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2008-06-09 397456]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-05-11 200069]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-10 1447168]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-01-18 1286608]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-07-09 1282048]

c:\users\Briatka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Orez vaź obrazovky a spŁçśaź programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-6-15 50688]
LenovoRegistration.lnk - c:\swtools\LenovoWelcome\LenovoRegistration.cmd [2007-10-4 166]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-03-15 05:17 89600 ----a-w- c:\windows\System32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2010-01-18 12:14 1286608 ----a-w- c:\program files\Spyware Doctor\pctsTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
2007-12-14 10:36 50472 ------w- c:\program files\CyberLink\PowerDVD8\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
2008-03-20 19:23 83240 ------w- c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
2009-04-26 21:06 1046688 ----a-w- c:\program files\TrojanHunter 5.0\THGuard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):90,b4,a3,61,7c,d6,ca,01

R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-09-23 207280]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-06-12 721904]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2007-10-17 19504]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2006-08-30 13744]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2008-06-10 468224]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-12-09 365280]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-03-15 11152]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2007-03-02 55936]
S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-01-09 569344]
S3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2007-05-22 30336]


--- Other Services/Drivers In Memory ---

*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-04-09 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 13:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Compare Prices with &Dealio - c:\users\Briatka\AppData\LocalLow\Dealio\kb127\res\DealioSearch.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Briatka\AppData\Roaming\Mozilla\Firefox\Profiles\uiicnagu.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2269050&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=2&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\users\Briatka\Program Files\DNA\plugins\npbtdna.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\AskBarDis\bar\bin\askBar.dll
MSConfigStartUp-au - c:\program files\Dealio\DealioAU.exe
MSConfigStartUp-DU Meter - c:\program files\DU Meter\DUMeter.exe
MSConfigStartUp-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-09 22:14
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys acpi.sys hal.dll iaStor.sys spil.sys >>UNKNOWN [0x853D8938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x88bcad24
\Driver\ACPI -> acpi.sys @ 0x805bfd68
\Driver\atapi -> 0x854211f8
\Driver\iaStor -> iaStor.sys @ 0x88535d30
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(728)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll

- - - - - - - > 'Explorer.exe'(2632)
c:\program files\Spyware Doctor\pctgmhk.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\ThinkVantage Fingerprint Software\upeksvr.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\windows\system32\AEADISRV.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\System32\TPHDEXLG.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Completion time: 2010-04-09 22:28:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-09 20:28
ComboFix2.txt 2010-04-08 20:01

Pre-Run: 6 191 783 936 bytes free
Post-Run: 5 879 980 032 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - E7DF011ADC0B8E98458017CB0EF57FCF

Re: Spomalena vista

Napsal: 10 dub 2010 10:34
od Rudy
OK, smazáno. Ještě zkontrolujte MBR: http://www2.gmer.net/mbr/mbr.exe . Dejte log.

Re: Spomalena vista

Napsal: 10 dub 2010 13:51
od skip27
tu je log + este by som rad vedel ci mozem nasledovne veci opravit v ccleaneri http://i41.tinypic.com/ae1jyc.jpg

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

Re: Spomalena vista

Napsal: 10 dub 2010 17:09
od Rudy
MBR i PC vypadá v pořádku. Vše, co CCleaner našel, můžete smazat. Neznám z praxe případ, kdy by smazal něco potřebného.

Re: Spomalena vista

Napsal: 10 dub 2010 17:28
od skip27
takze teraz uz mozem zmazat combofix? dakujem za vas cas

Re: Spomalena vista

Napsal: 10 dub 2010 17:37
od Rudy
ComboFix odinstalujte Start>spustit>(napsat) combofix /uninstall>OK. Nemáte zač!