
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Pomoc! vir v explorer.exe
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Pomoc! vir v explorer.exe
Ahoj
jeste jen tak pro zajímavost jsem zjistil, ze kvůli ovladaci saskutil se to vypíná. Tak se jeste ptám jestli o tím neco nevítte nez udelám tu opravu.
jeste jen tak pro zajímavost jsem zjistil, ze kvůli ovladaci saskutil se to vypíná. Tak se jeste ptám jestli o tím neco nevítte nez udelám tu opravu.
Re: Pomoc! vir v explorer.exe
SASkutil je ovladač od SAS, program odinstalujte a vložte mi tu log ze rsitu, já ty drivery smažu.
PC pořád padá do bsod? Když tak máte nový minidump?
PC pořád padá do bsod? Když tak máte nový minidump?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pomoc! vir v explorer.exe
Počítač je se mi nerestartuje a tuneup mi hlásí ze by melo byt vse v pohode a poslu tady ten log z rsit.
(pomohla oprava počítače(program ze systému) která pred tím nesla)
(pomohla oprava počítače(program ze systému) která pred tím nesla)
Re: Pomoc! vir v explorer.exe
Poprosím o ten rsit 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pomoc! vir v explorer.exe
Logfile of random's system information tool 1.08 (written by random/random)
Run by Tomáš at 2011-02-21 15:48:17
Microsoft Windows 7 Ultimate
System drive C: has 408 GB (86%) free of 477 GB
Total RAM: 3327 MB (79% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:48:49, on 21.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Tomáš\Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Tomáš.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - *{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - (no file)
R3 - URLSearchHook: (no name) - *{038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: (no name) - {8dcb7100-df86-4384-8842-8fa844297b3f} - (no file)
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 6071 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1789673904-1677065206-1250108036-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1789673904-1677065206-1250108036-1003UA.job
C:\Windows\tasks\RegistryBooster.job
C:\Windows\tasks\TuneUpUtilities_Task_BkGndMaintenance.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-27 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Default Manager"=C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-10 439568]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-12-20 963976]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-21 15:48:17 ----D---- C:\rsit
2011-02-21 15:48:17 ----D---- C:\Program Files\trend micro
2011-02-20 11:09:47 ----SHD---- C:\Config.Msi
2011-02-18 17:11:57 ----D---- C:\Users\Tomáš\AppData\Roaming\Malwarebytes
2011-02-13 21:37:50 ----D---- C:\_OTL
2011-02-13 21:33:11 ----D---- C:\Program Files\CCleaner
2011-02-09 18:19:01 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 18:19:00 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 18:19:00 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 18:19:00 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 18:18:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\jsproxy.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\ieui.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 18:18:54 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 18:18:54 ----A---- C:\Windows\system32\atmfd.dll
2011-02-08 16:14:39 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-02-08 16:14:38 ----D---- C:\ProgramData\Malwarebytes
2011-02-08 16:14:36 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-02-08 16:14:36 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-02-08 15:10:29 ----A---- C:\Windows\ntbtlog.txt
2011-02-06 15:58:05 ----D---- C:\ProgramData\Kaspersky Lab
2011-02-02 15:22:18 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-02-02 15:22:17 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-02-02 15:22:16 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-02-02 15:22:16 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-02-02 15:22:13 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-02-02 15:21:25 ----A---- C:\Windows\system32\aswBoot.exe
2011-02-02 15:21:23 ----D---- C:\ProgramData\Alwil Software
2011-02-02 15:21:23 ----D---- C:\Program Files\Alwil Software
2011-02-02 15:14:55 ----D---- C:\Users\Tomáš\AppData\Roaming\Opera
2011-02-02 11:09:27 ----D---- C:\Program Files\Opera
2011-02-01 20:10:11 ----D---- C:\Users\Tomáš\AppData\Roaming\SUPERAntiSpyware.com
2011-02-01 20:10:06 ----D---- C:\Program Files\SUPERAntiSpyware
2011-02-01 17:38:43 ----D---- C:\Windows\Minidump
2011-02-01 17:28:06 ----A---- C:\Windows\game.ini
2011-02-01 16:01:19 ----A---- C:\Windows\system32\psisdecd.dll
2011-02-01 16:01:19 ----A---- C:\Windows\system32\msdri.dll
2011-02-01 16:01:19 ----A---- C:\Windows\system32\CPFilters.dll
2011-02-01 15:50:35 ----A---- C:\Windows\system32\oleaut32.dll
2011-02-01 15:38:27 ----D---- C:\Program Files\Microsoft Silverlight
2011-02-01 15:33:19 ----D---- C:\Program Files\Microsoft
2011-02-01 15:33:18 ----D---- C:\Program Files\MSN Toolbar
2011-02-01 15:31:19 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-02-01 15:29:34 ----D---- C:\Windows\system32\directx
2011-01-31 18:47:17 ----A---- C:\Windows\reimage.ini
2011-01-31 18:38:09 ----HDC---- C:\ProgramData\{DE8EABB5-1C85-4410-A68D-79BD8A4518F4}
2011-01-31 18:35:21 ----D---- C:\Users\Tomáš\AppData\Roaming\Uniblue
2011-01-31 16:51:56 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-01-31 16:51:56 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\d3dx10.dll
2011-01-31 16:51:53 ----A---- C:\Windows\system32\xinput1_2.dll
2011-01-31 16:51:53 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-01-31 16:51:53 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-01-31 16:14:41 ----D---- C:\Program Files\DaemonTools_WhenUSave_Installer
2011-01-24 15:42:15 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2011-01-23 15:43:28 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.temp
======List of files/folders modified in the last 1 months======
2011-02-21 15:48:17 ----RD---- C:\Program Files
2011-02-21 15:46:45 ----D---- C:\Windows\Temp
2011-02-21 12:28:24 ----D---- C:\Windows\system32\config
2011-02-21 08:52:36 ----D---- C:\Windows\Prefetch
2011-02-21 08:49:34 ----D---- C:\Windows
2011-02-20 18:31:37 ----D---- C:\ProgramData\TrackMania
2011-02-20 18:31:28 ----D---- C:\Users\Tomáš\AppData\Roaming\Skype
2011-02-20 17:12:21 ----HD---- C:\ProgramData
2011-02-20 17:12:11 ----D---- C:\Users\Tomáš\AppData\Roaming\skypePM
2011-02-20 11:50:07 ----D---- C:\Windows\Tasks
2011-02-20 11:10:02 ----SHD---- C:\Windows\Installer
2011-02-19 17:17:18 ----SD---- C:\Users\Tomáš\AppData\Roaming\Microsoft
2011-02-19 16:03:27 ----D---- C:\Windows\system32\wfp
2011-02-19 16:03:27 ----D---- C:\Windows\system32\catroot2
2011-02-19 16:03:27 ----D---- C:\Windows\System32
2011-02-19 16:03:26 ----D---- C:\Windows\winsxs
2011-02-19 16:03:26 ----D---- C:\Windows\system32\drivers
2011-02-19 16:03:15 ----D---- C:\Windows\registration
2011-02-19 16:02:30 ----SHD---- C:\System Volume Information
2011-02-15 17:37:11 ----D---- C:\Program Files\ICQ6.5
2011-02-15 14:08:52 ----D---- C:\Program Files\Internet Explorer
2011-02-15 14:08:41 ----D---- C:\Windows\system32\migration
2011-02-13 21:43:11 ----D---- C:\Windows\system32\drivers\etc
2011-02-13 21:43:11 ----D---- C:\Windows\system32\drivers\Avg
2011-02-13 21:37:56 ----D---- C:\Program Files\Softonic-Eng7
2011-02-13 21:37:55 ----D---- C:\Program Files\ICQ6Toolbar
2011-02-13 21:37:53 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-02-13 21:37:52 ----D---- C:\Program Files\ToggleEN
2011-02-13 21:33:06 ----D---- C:\Program Files\Google
2011-02-13 21:31:59 ----D---- C:\Windows\system32\Tasks
2011-02-13 16:32:29 ----D---- C:\Program Files\AVG
2011-02-10 16:32:38 ----D---- C:\Windows\system32\DriverStore
2011-02-09 18:19:38 ----A---- C:\Windows\system32\MRT.exe
2011-02-09 18:18:47 ----D---- C:\Windows\system32\catroot
2011-02-08 18:53:00 ----D---- C:\Program Files\WinRAR
2011-02-08 18:47:16 ----D---- C:\Program Files\GamePark
2011-02-08 17:10:04 ----D---- C:\Windows\Globalization
2011-02-08 15:43:54 ----D---- C:\ProgramData\avg9
2011-02-08 15:24:36 ----D---- C:\Windows\system32\wbem
2011-02-08 15:24:35 ----D---- C:\Windows\system32\CodeIntegrity
2011-02-08 15:24:34 ----D---- C:\Windows\inf
2011-02-08 15:24:34 ----D---- C:\Windows\AppCompat
2011-02-08 15:24:30 ----D---- C:\ProgramData\AVG Security Toolbar
2011-02-08 15:23:54 ----D---- C:\Windows\Microsoft.NET
2011-02-08 15:23:39 ----RSD---- C:\Windows\assembly
2011-02-08 15:22:33 ----SD---- C:\ProgramData\Microsoft
2011-02-08 15:22:24 ----HD---- C:\Program Files\InstallShield Installation Information
2011-02-08 15:22:23 ----D---- C:\Program Files\Conduit
2011-02-08 15:22:12 ----D---- C:\Program Files\Activision
2011-02-03 08:35:10 ----D---- C:\Windows\system32\LogFiles
2011-02-01 16:01:36 ----D---- C:\Windows\ehome
2011-02-01 15:59:44 ----D---- C:\ProgramData\Microsoft Help
2011-02-01 15:31:08 ----D---- C:\Windows\Logs
2011-01-31 16:50:53 ----A---- C:\Windows\system32\PnkBstrB.exe
2011-01-31 16:50:46 ----A---- C:\Windows\system32\PnkBstrA.exe
2011-01-24 16:22:55 ----D---- C:\Program Files\Common Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-01-13 23632]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-01-13 294608]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-01-13 47440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-01-13 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-10-20 5089280]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
S0 qobfd;qobfd; C:\Windows\System32\drivers\jhkw.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 cpuz134;cpuz134; \??\C:\Users\TOM~1\AppData\Local\Temp\cpuz134\cpuz134_x32.sys []
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-10-20 172032]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-01-31 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2011-01-31 103736]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-07-27 249136]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-09-30 1051968]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-13 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TuneUp.Defrag;@C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-10-14 435008]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
Run by Tomáš at 2011-02-21 15:48:17
Microsoft Windows 7 Ultimate
System drive C: has 408 GB (86%) free of 477 GB
Total RAM: 3327 MB (79% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:48:49, on 21.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Tomáš\Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Tomáš.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - *{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - (no file)
R3 - URLSearchHook: (no name) - *{038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: (no name) - {8dcb7100-df86-4384-8842-8fa844297b3f} - (no file)
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 6071 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1789673904-1677065206-1250108036-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1789673904-1677065206-1250108036-1003UA.job
C:\Windows\tasks\RegistryBooster.job
C:\Windows\tasks\TuneUpUtilities_Task_BkGndMaintenance.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-27 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Default Manager"=C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-10 439568]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-12-20 963976]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-02-21 15:48:17 ----D---- C:\rsit
2011-02-21 15:48:17 ----D---- C:\Program Files\trend micro
2011-02-20 11:09:47 ----SHD---- C:\Config.Msi
2011-02-18 17:11:57 ----D---- C:\Users\Tomáš\AppData\Roaming\Malwarebytes
2011-02-13 21:37:50 ----D---- C:\_OTL
2011-02-13 21:33:11 ----D---- C:\Program Files\CCleaner
2011-02-09 18:19:01 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 18:19:00 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 18:19:00 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 18:19:00 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 18:18:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\jsproxy.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\ieui.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 18:18:59 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 18:18:54 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 18:18:54 ----A---- C:\Windows\system32\atmfd.dll
2011-02-08 16:14:39 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-02-08 16:14:38 ----D---- C:\ProgramData\Malwarebytes
2011-02-08 16:14:36 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-02-08 16:14:36 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-02-08 15:10:29 ----A---- C:\Windows\ntbtlog.txt
2011-02-06 15:58:05 ----D---- C:\ProgramData\Kaspersky Lab
2011-02-02 15:22:18 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-02-02 15:22:17 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-02-02 15:22:16 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-02-02 15:22:16 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-02-02 15:22:13 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-02-02 15:21:25 ----A---- C:\Windows\system32\aswBoot.exe
2011-02-02 15:21:23 ----D---- C:\ProgramData\Alwil Software
2011-02-02 15:21:23 ----D---- C:\Program Files\Alwil Software
2011-02-02 15:14:55 ----D---- C:\Users\Tomáš\AppData\Roaming\Opera
2011-02-02 11:09:27 ----D---- C:\Program Files\Opera
2011-02-01 20:10:11 ----D---- C:\Users\Tomáš\AppData\Roaming\SUPERAntiSpyware.com
2011-02-01 20:10:06 ----D---- C:\Program Files\SUPERAntiSpyware
2011-02-01 17:38:43 ----D---- C:\Windows\Minidump
2011-02-01 17:28:06 ----A---- C:\Windows\game.ini
2011-02-01 16:01:19 ----A---- C:\Windows\system32\psisdecd.dll
2011-02-01 16:01:19 ----A---- C:\Windows\system32\msdri.dll
2011-02-01 16:01:19 ----A---- C:\Windows\system32\CPFilters.dll
2011-02-01 15:50:35 ----A---- C:\Windows\system32\oleaut32.dll
2011-02-01 15:38:27 ----D---- C:\Program Files\Microsoft Silverlight
2011-02-01 15:33:19 ----D---- C:\Program Files\Microsoft
2011-02-01 15:33:18 ----D---- C:\Program Files\MSN Toolbar
2011-02-01 15:31:19 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-02-01 15:31:19 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-02-01 15:31:18 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-02-01 15:31:17 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-02-01 15:31:16 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-02-01 15:31:15 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-02-01 15:31:11 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-02-01 15:31:10 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-02-01 15:31:09 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-02-01 15:31:08 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-02-01 15:31:07 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-02-01 15:29:34 ----D---- C:\Windows\system32\directx
2011-01-31 18:47:17 ----A---- C:\Windows\reimage.ini
2011-01-31 18:38:09 ----HDC---- C:\ProgramData\{DE8EABB5-1C85-4410-A68D-79BD8A4518F4}
2011-01-31 18:35:21 ----D---- C:\Users\Tomáš\AppData\Roaming\Uniblue
2011-01-31 16:51:56 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-01-31 16:51:56 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-01-31 16:51:55 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-01-31 16:51:54 ----A---- C:\Windows\system32\d3dx10.dll
2011-01-31 16:51:53 ----A---- C:\Windows\system32\xinput1_2.dll
2011-01-31 16:51:53 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-01-31 16:51:53 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-01-31 16:14:41 ----D---- C:\Program Files\DaemonTools_WhenUSave_Installer
2011-01-24 15:42:15 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2011-01-23 15:43:28 ----D---- C:\Program Files\Common Files\Blizzard Entertainment.temp
======List of files/folders modified in the last 1 months======
2011-02-21 15:48:17 ----RD---- C:\Program Files
2011-02-21 15:46:45 ----D---- C:\Windows\Temp
2011-02-21 12:28:24 ----D---- C:\Windows\system32\config
2011-02-21 08:52:36 ----D---- C:\Windows\Prefetch
2011-02-21 08:49:34 ----D---- C:\Windows
2011-02-20 18:31:37 ----D---- C:\ProgramData\TrackMania
2011-02-20 18:31:28 ----D---- C:\Users\Tomáš\AppData\Roaming\Skype
2011-02-20 17:12:21 ----HD---- C:\ProgramData
2011-02-20 17:12:11 ----D---- C:\Users\Tomáš\AppData\Roaming\skypePM
2011-02-20 11:50:07 ----D---- C:\Windows\Tasks
2011-02-20 11:10:02 ----SHD---- C:\Windows\Installer
2011-02-19 17:17:18 ----SD---- C:\Users\Tomáš\AppData\Roaming\Microsoft
2011-02-19 16:03:27 ----D---- C:\Windows\system32\wfp
2011-02-19 16:03:27 ----D---- C:\Windows\system32\catroot2
2011-02-19 16:03:27 ----D---- C:\Windows\System32
2011-02-19 16:03:26 ----D---- C:\Windows\winsxs
2011-02-19 16:03:26 ----D---- C:\Windows\system32\drivers
2011-02-19 16:03:15 ----D---- C:\Windows\registration
2011-02-19 16:02:30 ----SHD---- C:\System Volume Information
2011-02-15 17:37:11 ----D---- C:\Program Files\ICQ6.5
2011-02-15 14:08:52 ----D---- C:\Program Files\Internet Explorer
2011-02-15 14:08:41 ----D---- C:\Windows\system32\migration
2011-02-13 21:43:11 ----D---- C:\Windows\system32\drivers\etc
2011-02-13 21:43:11 ----D---- C:\Windows\system32\drivers\Avg
2011-02-13 21:37:56 ----D---- C:\Program Files\Softonic-Eng7
2011-02-13 21:37:55 ----D---- C:\Program Files\ICQ6Toolbar
2011-02-13 21:37:53 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-02-13 21:37:52 ----D---- C:\Program Files\ToggleEN
2011-02-13 21:33:06 ----D---- C:\Program Files\Google
2011-02-13 21:31:59 ----D---- C:\Windows\system32\Tasks
2011-02-13 16:32:29 ----D---- C:\Program Files\AVG
2011-02-10 16:32:38 ----D---- C:\Windows\system32\DriverStore
2011-02-09 18:19:38 ----A---- C:\Windows\system32\MRT.exe
2011-02-09 18:18:47 ----D---- C:\Windows\system32\catroot
2011-02-08 18:53:00 ----D---- C:\Program Files\WinRAR
2011-02-08 18:47:16 ----D---- C:\Program Files\GamePark
2011-02-08 17:10:04 ----D---- C:\Windows\Globalization
2011-02-08 15:43:54 ----D---- C:\ProgramData\avg9
2011-02-08 15:24:36 ----D---- C:\Windows\system32\wbem
2011-02-08 15:24:35 ----D---- C:\Windows\system32\CodeIntegrity
2011-02-08 15:24:34 ----D---- C:\Windows\inf
2011-02-08 15:24:34 ----D---- C:\Windows\AppCompat
2011-02-08 15:24:30 ----D---- C:\ProgramData\AVG Security Toolbar
2011-02-08 15:23:54 ----D---- C:\Windows\Microsoft.NET
2011-02-08 15:23:39 ----RSD---- C:\Windows\assembly
2011-02-08 15:22:33 ----SD---- C:\ProgramData\Microsoft
2011-02-08 15:22:24 ----HD---- C:\Program Files\InstallShield Installation Information
2011-02-08 15:22:23 ----D---- C:\Program Files\Conduit
2011-02-08 15:22:12 ----D---- C:\Program Files\Activision
2011-02-03 08:35:10 ----D---- C:\Windows\system32\LogFiles
2011-02-01 16:01:36 ----D---- C:\Windows\ehome
2011-02-01 15:59:44 ----D---- C:\ProgramData\Microsoft Help
2011-02-01 15:31:08 ----D---- C:\Windows\Logs
2011-01-31 16:50:53 ----A---- C:\Windows\system32\PnkBstrB.exe
2011-01-31 16:50:46 ----A---- C:\Windows\system32\PnkBstrA.exe
2011-01-24 16:22:55 ----D---- C:\Program Files\Common Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-01-13 23632]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-01-13 294608]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-01-13 47440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-01-13 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-01-13 51280]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-10-20 5089280]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
S0 qobfd;qobfd; C:\Windows\System32\drivers\jhkw.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 cpuz134;cpuz134; \??\C:\Users\TOM~1\AppData\Local\Temp\cpuz134\cpuz134_x32.sys []
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-10-20 172032]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-01-31 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2011-01-31 103736]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-07-27 249136]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-09-30 1051968]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-13 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TuneUp.Defrag;@C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-10-14 435008]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
Re: Pomoc! vir v explorer.exe
Vidím tam jeden driver který se mi moc nelíbí
, odstřelím ho. Ty ovladače od SASU Vám raději můžu smazat?

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pomoc! vir v explorer.exe
Jo můžete 

Re: Pomoc! vir v explorer.exe
SAS nejdřív odinstalujte
Spustte OTL
-do bílého okna dole skopírujte tento skript:
-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde

-do bílého okna dole skopírujte tento skript:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\ProgramData\Kaspersky Lab
C:\Users\Tomáš\AppData\Roaming\SUPERAntiSpyware.com
C:\Program Files\SUPERAntiSpyware
C:\Program Files\DaemonTools_WhenUSave_Installer
C:\Windows\System32\drivers\jhkw.sys
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8dcb7100-df86-4384-8842-8fa844297b3f}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware (reboot)"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
:services
qobfd
SASDIFSV
SASKUTIL
:commands
[emptytemp]
[EMPTYFLASH]
[Reboot]
-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pomoc! vir v explorer.exe
a jak ho odinstaluji ja v program files mám jen jakýsi dll a ani v programu pridat či odebrat zadny uninstal neni.
a u otl mám zase zaskrtnout ty 3 veci?

Re: Pomoc! vir v explorer.exe
V přidat odebrat program ten program nemáte? Nemáte to SAS, který se neinstaluje?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pomoc! vir v explorer.exe
tak to tedy newim ale myslim si ze jsem ten sas instaloval
Re: Pomoc! vir v explorer.exe
Podívejte se v přidat odebrat programy, pokud je nainstalvoaný, musí tam - superantispyware
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Pomoc! vir v explorer.exe
Ahoj, nechci radit, ale AVG bych raději nepoužíval. Zkusil bych Nod 32.. já ted zkouším Avast.
Re: Pomoc! vir v explorer.exe
jj AVG je uz pryc 
V přidat nebo odebrat to tam není ten superantispyware
jo a zase se to nedky pri stratu restartne (udelám tu opravu cd Win7)

V přidat nebo odebrat to tam není ten superantispyware
jo a zase se to nedky pri stratu restartne (udelám tu opravu cd Win7)
Re: Pomoc! vir v explorer.exe
Udělejte ještě ten skript na OTL.
NO já nevím, ale oprava systému by Vám mohla možná udělat ještě větší binec. Spíš si zazálohujte data a pokud by to moc zlobilo, tak lepší bude reinstal systému.
NO já nevím, ale oprava systému by Vám mohla možná udělat ještě větší binec. Spíš si zazálohujte data a pokud by to moc zlobilo, tak lepší bude reinstal systému.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.