Prosím o kontolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

RuLich
nováček
Příspěvky: 13
Registrován: duben 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod RuLich » 16 dub 2010 22:19

System Repair Engineer

Stále scanuje "Windows security update Check" vytížení CPU 55%

Trvá to už dlouho.

je ráno a ještě stále scanuje "Windows security update Check"

Potom se mi ještě strácí nastavení seřazení ikon, viz:

Obrázek
...................................................................................................
Tak se to povedlo žádný čtvereček nebyl zaškrtnut:


2010-04-17,05:05:26

System Repair Engineer 2.8.2.1321
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 3 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Running Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Scheduled Tasks
Windows Security Update Check
API HOOK
Hidden Process


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<DAEMON Tools Lite><"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun> [(Verified)DT Soft Ltd]
<Skype><"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized> [(Verified)Skype Technologies SA]
<SUPERAntiSpyware><D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe> [(Verified)SuperAdBlocker.com]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<avast!><C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe> [(Verified)ALWIL Software]
<UnlockerAssistant><"C:\Program Files\Unlocker\UnlockerAssistant.exe" -H> []
<BluetoothAuthenticationAgent><rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent> [(Verified)Microsoft Windows Component Publisher]
<RTHDCPL><RTHDCPL.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SkyTel><; SkyTel.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit> [(Verified)NVIDIA Corporation]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)NVIDIA Corporation]
<SunJavaUpdateSched><"C:\Program Files\Common Files\Java\Java Update\jusched.exe"> [(Verified)Sun Microsystems, Inc.]
<Adobe Reader Speed Launcher><; "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"> [(Verified)Adobe Systems, Incorporated]
<NeroFilterCheck><; C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe> [(Verified)Nero AG]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
<{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}><D:\Program Files\SUPERAntiSpyware\SASSEH.DLL> [SuperAdBlocker.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<WebCheck><%Systemroot%\system32\webcheck.dll> [(Verified)Microsoft Windows]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [Microsoft Corporation]
<UPnPMonitor><C:\WINDOWS\system32\upnpui.dll> [(Verified)Microsoft Windows Component Publisher]
<SysTray><C:\WINDOWS\system32\stobject.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
<WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<Aktualizace verze aplikace Internet Explorer><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
<Browser Customizations><"C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
<Vlastní nastavení prohlížeče><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Adresář 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Aktualizace plochy systému Windows><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -BaseSettings> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [(Verified)Microsoft Corporation]

==================================
Startup Folders
N/A

==================================
Services
[avast! iAVS4 Control Service / aswUpdSv][Running/Auto Start]
<"C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"><ALWIL Software>
[avast! Antivirus / avast! Antivirus][Running/Auto Start]
<"C:\Program Files\Alwil Software\Avast4\ashServ.exe"><ALWIL Software>
[avast! Mail Scanner / avast! Mail Scanner][Running/Manual Start]
<"C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service><ALWIL Software>
[avast! Web Scanner / avast! Web Scanner][Running/Manual Start]
<"C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service><ALWIL Software>
[ForceWare Intelligent Application Manager (IAM) / ForceWare Intelligent Application Manager (IAM)][Running/Auto Start]
<C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe><>
[Přístup k zařízením standardu HID / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Java Quick Starter / JavaQuickStarterService][Running/Auto Start]
<"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"><Sun Microsystems, Inc.>
[NMIndexingService / NMIndexingService][Stopped/Manual Start]
<"C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe"><Nero AG>
[ForceWare IP service / nSvcIp][Running/Auto Start]
<C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe><>
[NVIDIA Display Driver Service / nvsvc][Running/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[SolidWorks Licensing Service / SolidWorks Licensing Service][Stopped/Disabled]
<"C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe"><SolidWorks>
[Služba Windows Media Player Network Sharing / WMPNetworkSvc][Stopped/Manual Start]
<"C:\Program Files\Windows Media Player\WMPNetwk.exe"><Microsoft Corporation>

==================================
Drivers
[aswFsBlk / aswFsBlk][Running/Auto Start]
<system32\DRIVERS\aswFsBlk.sys><ALWIL Software>
[Bluetooth Audio Service / BlueletAudio][Stopped/Manual Start]
<system32\DRIVERS\blueletaudio.sys><N/A>
[Bluetooth SCO Audio Service / BlueletSCOAudio][Stopped/Manual Start]
<system32\DRIVERS\BlueletSCOAudio.sys><N/A>
[Bluetooth PAN Network Adapter / BT][Stopped/Manual Start]
<system32\DRIVERS\btnetdrv.sys><N/A>
[Bluetooth USB For Bluetooth Service / Btcsrusb][Stopped/Manual Start]
<System32\Drivers\btcusb.sys><N/A>
[Bluetooth HID Enumerator / BTHidEnum][Stopped/Boot Start]
<\SystemRoot\System32\Drivers\vbtenum.sys><N/A>
[Bluetooth HID Manager Service / BTHidMgr][Stopped/Boot Start]
<\SystemRoot\System32\Drivers\BTHidMgr.sys><N/A>
[Enumenátor sběrnice Bluetooth / btkrnl][Stopped/Manual Start]
<system32\DRIVERS\btkrnl.sys><N/A>
[GMSIPCI / GMSIPCI][Stopped/Manual Start]
<\??\E:\INSTALL\GMSIPCI.SYS><N/A>
[Hardlock / Hardlock][Running/Auto Start]
<\??\C:\WINDOWS\system32\drivers\hardlock.sys><Aladdin Knowledge Systems Ltd.>
[Ovladač Microsoft UAA pro sběrnici High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[nvata / nvata][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nvata.sys><NVIDIA Corporation>
[NVIDIA nForce Networking Controller Driver / NVENETFD][Running/Manual Start]
<system32\DRIVERS\NVENETFD.sys><NVIDIA Corporation>
[nvgts / nvgts][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\nvgts.sys><NVIDIA Corporation>
[NVIDIA Network Bus Enumerator / nvnetbus][Running/Manual Start]
<system32\DRIVERS\nvnetbus.sys><NVIDIA Corporation>
[VSO Software pcouffin / pcouffin][Running/Manual Start]
<System32\Drivers\pcouffin.sys><VSO Software>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[SASDIFSV / SASDIFSV][Running/System Start]
<\??\D:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[SASENUM / SASENUM][Running/Manual Start]
<\??\D:\Program Files\SUPERAntiSpyware\SASENUM.SYS><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[SASKUTIL / SASKUTIL][Running/System Start]
<\??\D:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[sptd / sptd][Stopped/Disabled]
<System32\Drivers\sptd.sys><Duplex Secure Ltd.>
[Virtual Serial port driver / VComm][Stopped/Manual Start]
<system32\DRIVERS\VComm.sys><N/A>
[Bluetooth VComm Manager Service / VcommMgr][Stopped/Manual Start]
<System32\Drivers\VcommMgr.sys><N/A>

==================================
Browser Add-ons
[Java(tm) Plug-In 2 SSV Helper]
{DBC80044-A445-435b-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
[JQSIEStartDetectorImpl Class]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, (Signed) Sun Microsystems, Inc.>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\WUWEB.DLL, (Signed) Microsoft Corporation>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
[NVIDIA Smart Scan]
{74DBCB52-F298-4110-951D-AD2FF67BC8AB} <C:\WINDOWS\DOWNLO~1\NVIDIA~1.OCX, NVIDIA>
[Java Plug-in 1.6.0_20]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_20]
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_20]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\npjpi160_20.dll, (Signed) Sun Microsystems, Inc.>
[]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, (Signed) Microsoft Corporation>
[]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <, >
[]
{22BF413B-C6D2-4D91-82A9-A0F997BA588C} <, >
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\msdxm.ocx, (Signed) Microsoft Corporation>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <C:\WINDOWS\system32\mshtml.dll, (Signed) Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[XSL Template]
{2933BF94-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[]
{2A0F3D1B-0909-4FF4-B272-609CCE6054E7} <, >
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx, (Signed) Microsoft Corporation>
[]
{32099AAC-C132-4136-9E9A-4E364A424E17} <, >
[]
{472734EA-242A-422B-ADF8-83D1E48CC825} <, >
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[Microsoft RDP Client Control (redist)]
{4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2} <C:\WINDOWS\system32\mstscax.dll, (Signed) Microsoft Corporation>
[Microsoft RDP Client Control (redist)]
{4EDCB26C-D24C-4e72-AF07-B576699AC0DE} <C:\WINDOWS\system32\mstscax.dll, (Signed) Microsoft Corporation>
[]
{5067A26B-1337-4436-8AFE-EE169C2DA79F} <, >
[isInstalled Class]
{5852F5ED-8BF4-11D4-A245-0080C6F74284} <C:\Program Files\Java\jre6\bin\wsdetect.dll, (Signed) Sun Microsystems, Inc.>
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\WUWEB.DLL, (Signed) Microsoft Corporation>
[]
{68879801-E072-C9D4-67E1-36D8382172D0} <, >
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, (Signed) N/A>
[Microsoft RDP Client Control (redist)]
{7390f3d8-0439-4c05-91e3-cf5cb290c3d0} <C:\WINDOWS\system32\mstscax.dll, (Signed) Microsoft Corporation>
[NVIDIA Smart Scan]
{74DBCB52-F298-4110-951D-AD2FF67BC8AB} <C:\WINDOWS\DOWNLO~1\NVIDIA~1.OCX, NVIDIA>
[Microsoft RDP Client Control (redist)]
{7584c670-2274-4efb-b00b-d6aaba6d3850} <C:\WINDOWS\system32\mstscax.dll, (Signed) Microsoft Corporation>
[]
{77BF5300-1474-4EC7-9980-D32B190E9B07} <, >
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[XML DOM Document 6.0]
{88D96A05-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, (Signed) Microsoft Corporation>
[Free Threaded XML DOM Document 6.0]
{88D96A06-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, (Signed) Microsoft Corporation>
[XSL Template 6.0]
{88D96A08-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, (Signed) Microsoft Corporation>
[XML HTTP 6.0]
{88D96A0A-F192-11D4-A65F-0040963251E5} <C:\WINDOWS\system32\msxml6.dll, (Signed) Microsoft Corporation>
[]
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} <, >
[]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <, >
[Microsoft RDP Client Control (redist)]
{9059f30f-4eb1-4bd2-9fdc-36f43a218f4a} <C:\WINDOWS\system32\mstscax.dll, (Signed) Microsoft Corporation>
[VideoLAN VLC ActiveX Plugin v2]
{9BE31822-FDAD-461B-AD51-BE1D1C159921} <C:\Program Files\VideoLAN\VLC\axvlc.dll, >
[]
{A3C6DAFC-E193-42FC-ADCA-5316B5D6D653} <, >
[]
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} <, >
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>
[Adobe PDF Reader]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll, (Signed) Adobe Systems, Inc.>
[Deployment Toolkit]
{CAFEEFAC-DEC7-0000-0001-ABCDEFFEDCBA} <C:\WINDOWS\system32\deployJava1.dll, (Signed) Sun Microsystems, Inc.>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[Microsoft Url Search Hook]
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx, (Signed) Adobe Systems, Inc.>
[Java(tm) Plug-In 2 SSV Helper]
{DBC80044-A445-435B-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
[Microsoft Silverlight]
{DFEAF541-F3E1-4C24-ACAC-99C30715084A} <c:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll, (Signed) Microsoft Corporation>
[]
{E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[JQSIEStartDetectorImpl Class]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, (Signed) Sun Microsystems, Inc.>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, (Signed) Microsoft Corporation>
[]
{FA9B9510-9FCB-4CA0-818C-5D0987B47C4D} <, >
[]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[]
{FCBCCB87-9224-4B8D-B117-F56D924BEB18} <, >

==================================
Running Processes
[PID: 412 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 460 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 484 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[PID: 528 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 540 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[PID: 716 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe] [NVIDIA Corporation, 4.00.1381.9621]
[C:\WINDOWS\system32\nvapi.dll] [NVIDIA Corporation, 6.14.11.9621]
[PID: 744 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 792 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 936 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 996 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[PID: 1064 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[PID: 1084 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[c:\windows\system32\dot3msm.dll] [Společnost Microsoft, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 1188 / SYSTEM][C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1367, 0]
[PID: 1244 / SYSTEM][C:\Program Files\Alwil Software\Avast4\ashServ.exe] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswAux.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswEngin.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswScan.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashBase.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashTask.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswInteg.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswIdle.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Aavm4h.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AavmRpch.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Czech\Base.dll] [ALWIL Software, 4, 8, 1356, 0]
[C:\Program Files\Alwil Software\Avast4\AhResMai.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ahResMes.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AhResNS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AhResOut.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ahResP2P.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AhResStd.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AhResWS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashSSqlt.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\asw5Ldr.dll] [ALWIL Software, 1, 0, 0, 1]
[PID: 1492 / RuLich][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\BROWSEUI.dll] [Společnost Microsoft, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[D:\Program Files\SUPERAntiSpyware\SASSEH.DLL] [SuperAdBlocker.com, 1, 0, 0, 1012]
[C:\Program Files\Ace Utilities\wipext.dll] [, 1, 0, 0, 4]
[C:\Program Files\WinRAR\rarext.dll] [, ]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, ]
[C:\Program Files\UltraISO\isoshell.dll] [EZB Systems, Inc., 1, 0, 0, 2]
[C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll] [Malwarebytes Corporation, 1.45]
[C:\PROGRA~1\GLARYU~1\CONTEX~1.DLL] [Glarysoft Ltd, 2.20.0.831]
[C:\PROGRA~1\GLARYU~1\rtl70.bpl] [Borland Software Corporation, 7.0.4.453]
[C:\PROGRA~1\GLARYU~1\vcl70.bpl] [Borland Software Corporation, 7.0.4.453]
[C:\Program Files\Alwil Software\Avast4\ashShell.dll] [ALWIL Software, 4, 8, 1367, 0]
[D:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL] [SUPERAntiSpyware.com, 1, 0, 0, 1004]
[C:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll] [Nero AG, 3, 3, 1, 1]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll] [Microsoft Corporation, 5.2.6001.22319 (vistasp1_ldr.081126-1506)]
[C:\Program Files\7-Zip\7-zip.dll] [Igor Pavlov, 4.64]
[C:\WINDOWS\system32\CmdLineExt.dll] [Sony DADC Austria AG., 1,1,224,0]
[PID: 1636 / RuLich][C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Czech\Base.dll] [ALWIL Software, 4, 8, 1356, 0]
[C:\Program Files\Alwil Software\Avast4\Czech\Lang.dll] [ALWIL Software, 4, 8, 1356, 0]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[c:\program files\alwil software\avast4\ahruimai.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\ashUInt.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\uiAux2.dll] [ALWIL Software, 4, 8, 1317, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\XT1922.dll] [Codejock Software, 1, 9, 4, 0]
[c:\program files\alwil software\avast4\ahruimes.dll] [ALWIL Software, 4, 8, 1367, 0]
[c:\program files\alwil software\avast4\ahruins.dll] [ALWIL Software, 4, 8, 1367, 0]
[c:\program files\alwil software\avast4\ahruiout.dll] [ALWIL Software, 4, 8, 1367, 0]
[c:\program files\alwil software\avast4\ahruip2p.dll] [ALWIL Software, 4, 8, 1367, 0]
[c:\program files\alwil software\avast4\ahruistd.dll] [ALWIL Software, 4, 8, 1367, 0]
[c:\program files\alwil software\avast4\ahruiws.dll] [ALWIL Software, 4, 8, 1367, 0]
[PID: 1644 / RuLich][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, ]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1652 / RuLich][C:\WINDOWS\system32\rundll32.exe] [Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1672 / RuLich][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.1.1.4]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1752 / RuLich][C:\Program Files\Common Files\Java\Java Update\jusched.exe] [Sun Microsystems, Inc., 2.0.2.1]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1772 / RuLich][C:\Program Files\Skype\Phone\Skype.exe] [Skype Technologies S.A., 4.2.0.155]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll] [Microsoft Corporation, 5.2.6001.22319 (vistasp1_ldr.081126-1506)]
[C:\WINDOWS\system32\netfxperf.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll] [Microsoft Corporation, 1.1.4322.2443]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[PID: 228 / RuLich][D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe] [SUPERAntiSpyware.com, 4, 35, 0, 1002]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[D:\Program Files\SUPERAntiSpyware\deupx.dll] [SuperAntiSpyware.com, 1, 0, 0, 2]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Documents and Settings\RuLich\Data aplikací\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL] [N/A, ]
[C:\Documents and Settings\RuLich\Data aplikací\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll] [N/A, ]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[D:\Program Files\SUPERAntiSpyware\SASSEH.DLL] [SuperAdBlocker.com, 1, 0, 0, 1012]
[PID: 1516 / RuLich][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1500 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll] [Microsoft Corporation, 6.1.2600.5635 (xpsp_sp3_qfe.080704-1744)]
[PID: 1912 / LOCAL SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1940 / SYSTEM][C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe] [, 1, 0, 1, 0]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\NMI.dll] [NVIDIA Corporation, 2, 2, 0, 7313]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll] [N/A, ]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll] [N/A, ]
[PID: 2024 / SYSTEM][C:\Program Files\Java\jre6\bin\jqs.exe] [Sun Microsystems, Inc., 6.0.200.2]
[C:\Program Files\Java\jre6\bin\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\netfxperf.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll] [Microsoft Corporation, 1.1.4322.2443]
[C:\Program Files\Java\jre6\bin\client\jvm.dll] [Sun Microsystems, Inc., 16.3.0.01]
[PID: 776 / SYSTEM][C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe] [, 2, 2, 0, 7313]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll] [N/A, ]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\NMI.dll] [NVIDIA Corporation, 2, 2, 0, 7313]
[C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll] [N/A, ]
[PID: 1600 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe] [(Verified) Microsoft Corporation, 7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834)]
[PID: 2264 / RuLich][C:\WINDOWS\system32\wscntfy.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 2312 / SYSTEM][C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashBase.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashTask.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswAux.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Aavm4h.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AavmRpch.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AhResMai.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Czech\Base.dll] [ALWIL Software, 4, 8, 1356, 0]
[C:\Program Files\Alwil Software\Avast4\aswEngin.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswScan.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Czech\Lang.dll] [ALWIL Software, 4, 8, 1356, 0]
[C:\WINDOWS\system32\MFC71.DLL] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Alwil Software\Avast4\Czech\langmai.dll] [ALWIL Software, 4, 8, 1356, 0]
[PID: 2392 / SYSTEM][C:\Program Files\Alwil Software\Avast4\ashWebSv.exe] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashBase.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\WINDOWS\system32\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\WINDOWS\system32\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnB.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswCmnS.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Aavm4h.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\AavmRpch.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashTask.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswAux.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\Czech\Base.dll] [ALWIL Software, 4, 8, 1356, 0]
[C:\Program Files\Alwil Software\Avast4\aswEngin.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\aswScan.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll] [ALWIL Software, 4, 8, 1367, 0]
[C:\PROGRA~1\ALWILS~1\Avast4\AhResWs.dll] [ALWIL Software, 4, 8, 1367, 0]
[PID: 2532 / SYSTEM][C:\WINDOWS\system32\wbem\wmiapsrv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
[PID: 2664 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 3308 / RuLich][C:\Program Files\Skype\Plugin Manager\skypePM.exe] [Skype Technologies, 2.0.0.67]
[C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll] [EasyBits Media AS, 2.0.1.144]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 1732 / RuLich][C:\Documents and Settings\RuLich\Plocha\SREngLdr.EXE] [Smallfrogs Studio, 2.8.2.1321]
[PID: 3208 / RuLich][C:\Documents and Settings\RuLich\Plocha\SRE18af41ff.EXE] [Smallfrogs Studio, 2.8.2.1321]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[PID: 712 / RuLich][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\WINDOWS\system32\IEFRAME.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Internet Explorer\ieproxy.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\WINDOWS\system32\msfeeds.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[PID: 4084 / RuLich][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\WINDOWS\system32\IEFRAME.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Internet Explorer\xpshims.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Program Files\Internet Explorer\ieproxy.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Java\jre6\bin\jp2ssv.dll] [Sun Microsystems, Inc., 6.0.200.2]
[C:\Program Files\Java\jre6\bin\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll] [Sun Microsystems, Inc., 6.0.200.2]
[C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx] [Adobe Systems, Inc., 10,0,22,87]
[C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll] [Microsoft Corporation, 5.2.6001.22319 (vistasp1_ldr.081126-1506)]
[PID: 688 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[PID: 2544 / RuLich][C:\Documents and Settings\RuLich\Plocha\SRE18af41ff.EXE] [Smallfrogs Studio, 2.8.2.1321]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)]
[C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, ]
[C:\Documents and Settings\RuLich\Plocha\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1 localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1644, C:\PROGRAM FILES\UNLOCKER\UNLOCKERASSISTANT.EXE]

==================================
Scheduled Tasks
N/A

==================================
Windows Security Update Check
N/A

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================

Reklama
RuLich
nováček
Příspěvky: 13
Registrován: duben 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod RuLich » 17 dub 2010 05:43

Po restartu to vypadá dobře ale když chci v ovládacích panelech otevřít Síťová připojení, tak naskočí hodiny a nic:
Obrázek
Když v procesech ukončím tento proces:
Obrázek
Tak se Síťová připojení otevře ale není tam žádná ikona,
a ve Správci zařízení jsou:
Obrázek

Když poté uzavřu všechna okna a otevřu Poznámkový blok, změní se lišta v klasické nastavení:
Obrázek
A opět nefunguje Seřazení ikon.
................
V Bráně firewal mám jen toto připojení a začli skákat různé procesy a změnil se i vzhled:

Obrázek
............................
Další problémy:
Obrázek
Obrázek
Ale službe je spuštěna:
Obrázek
...............................
Další problem, přestal jít zvuk, při pokusu ve správci zařízení "Vyhledat změny harwardu" Modrá obrazovka:
STOP: 0x0000007E (RtkHDAud.sxs)
Tak zvuk už je v pořádku instalace nového ovladače.
Mám dojem že to vypadá na reinstal.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43292
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod jaro3 » 17 dub 2010 10:34

Zkus přeinstalovat síť .kartu a nastavit znovu nové připojení.

Ten Dial-a-fix si už použil?

Zkus stáhnout tuto záplatu:
http://www.microsoft.com/downloads/deta ... laylang=cs

Stáhni si CKScanner

a ulož si ho na Plochu.

•Dvojklikem spusť CKScanner.exe a klikni na Search For Files.
•Po dokončení skenování klikni na Save List To File. Na Plochu se ti uloží CKFiles.txt.
•Ten mi sem zkopíruj
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

RuLich
nováček
Příspěvky: 13
Registrován: duben 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod RuLich » 17 dub 2010 13:35

Aktualizace nejde prý mám novější.
Log:

CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\rulich\oblíbené položky\crack\angernet.org free software area - download full games.url
c:\documents and settings\rulich\oblíbené položky\crack\applian mp3 magic 2.02 warez download crack serial keygen full version free.url
c:\documents and settings\rulich\oblíbené položky\crack\battlefield 2 @ phazeddl.com.url
c:\documents and settings\rulich\oblíbené položky\crack\bookmarks.html
c:\documents and settings\rulich\oblíbené položky\crack\crack-locator.com.url
c:\documents and settings\rulich\oblíbené položky\crack\crackdb.org - apps - i2.url
c:\documents and settings\rulich\oblíbené položky\crack\crackhell.com - crack serial warez xxx toplist.url
c:\documents and settings\rulich\oblíbené položky\crack\cracks, serials, keygen, iso for free download! page - g.url
c:\documents and settings\rulich\oblíbené položky\crack\download crack serial - download cracks serials no porn popups! no stupid trojans and exploits!.url
c:\documents and settings\rulich\oblíbené položky\crack\download free warez @ fullforum.com(!!!).url
c:\documents and settings\rulich\oblíbené položky\crack\freeserials.htm
c:\documents and settings\rulich\oblíbené položky\crack\full version download with crack serial keygen torrent rapidshare.url
c:\documents and settings\rulich\oblíbené položky\crack\gameburnworld- no-cd-no-dvd patches, game fixes, trainers, cheats.url
c:\documents and settings\rulich\oblíbené položky\crack\gamecopyworld - main.url
c:\documents and settings\rulich\oblíbené položky\crack\gamecopyworld - mirrors - no-cd, no-dvd patches, game fixes, trainers & cheats.url
c:\documents and settings\rulich\oblíbené položky\crack\infernal warez.url
c:\documents and settings\rulich\oblíbené položky\crack\keygen.ms - generates cracks serials keygens for the software to unlock it for free.url
c:\documents and settings\rulich\oblíbené položky\crack\keygen.ws.url
c:\documents and settings\rulich\oblíbené položky\crack\megagames - pc game fixes.url
c:\documents and settings\rulich\oblíbené položky\crack\p30world english version archives.url
c:\documents and settings\rulich\oblíbené položky\crack\rapidshare warez - fullversion warez downloads.url
c:\documents and settings\rulich\oblíbené položky\crack\the pirate bay - the worlds largest bittorrent tracker.url
c:\documents and settings\rulich\oblíbené položky\crack\uploter.net- direct download link.url
c:\documents and settings\rulich\oblíbené položky\crack\vertus full warez downloads - vertus serial, vertus crack, vertus full torrent, vertus+searial+crack.rar.url
c:\documents and settings\rulich\oblíbené položky\crack\warez rips home.url
c:\documents and settings\rulich\oblíbené položky\crack\wareznova - free full game downloads, mp3, and movies.url
c:\documents and settings\rulich\oblíbené položky\crack\češtiny a cracky do her a programů - !!!! Čti !!!!!.url
c:\documents and settings\rulich\oblíbené položky\fora\astalavista.ms forum view forum - cracks and serials.url
c:\documents and settings\rulich\oblíbené položky\fora\filez.cz - vaše cesta do světa warez! (gamez, moviez, crackz, appz links).url
c:\documents and settings\rulich\oblíbené položky\hackování\soom.cz - cracking.url
c:\documents and settings\rulich\oblíbené položky\links\runtime getdataback for fat ntfs 4.0 warez download, crack, serial, keygen, full version from worldwarez.url
c:\documents and settings\rulich\plocha\programy\heslo\live cd ophcrack\ophcrack-xp-livecd-2.3.1.iso
c:\documents and settings\rulich\plocha\programy\heslo\live cd ophvistacrack\ophcrack-vista-livecd-2.3.1.iso
c:\documents and settings\rulich\plocha\slow-pcfighter\slow-pcfighter.1.0.93.cracked-snd.zip
c:\documents and settings\rulich\plocha\slow-pcfighter\nová složka\slow-pcfighter.1.0.93\slow-pcfighter.1.0.93.cracked-snd\popis.txt
c:\documents and settings\rulich\plocha\slow-pcfighter\nová složka\slow-pcfighter.1.0.93\slow-pcfighter.1.0.93.cracked-snd\slow-pcfighter.exe
c:\documents and settings\rulich\plocha\slow-pcfighter\nová složka\slow-pcfighter.1.0.93\slow-pcfighter.1.0.93.cracked-snd\snd.nfo
scanner sequence 3.ZZ.11
----- EOF -----

RuLich
nováček
Příspěvky: 13
Registrován: duben 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod RuLich » 17 dub 2010 20:41

Po přeinstalování síťové karty strašné problémy se připojit na internet teď se mi to teprve podařilo stále využití procesoru 95 %.,
Asi to vzdám a přeinstaluji systém . Bojuji jen proto že bych chtěl vědět co to je. Děkuji za ochotu a trpělivost

Ano "Dial-a-fix " jsem použil něco to načítalo z CD ale výsledek žádný.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43292
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod jaro3 » 17 dub 2010 23:31

Vypni si rez.ochrany i firewall.
Stáhni si Dr. Web CureIt
dej update , po aktualizaci dej start.
Tlacitky dole muzeš soubor léčit(systémové soubory), smazat, přesunout nebo přejmenovat

Stáhni si MGADiag

na plochu. Poklepej na MGADiag.exe, klikni na Run a Run znovu, poté klikni na Continue , pak na Copy. Nyní otevři Notepad ( poznámkový blok) a pravým tl. myši vlož celý text . Ulož si ho na plochu a zkopíruj sem celý jeho obsah.

Stáhni si CKScanner by askey127

na svojí plochu.Poklepej na CKScanner.exe a poté klikni na Search For Files.
Začne sken , po jeho skončení klikni na Save List To File. Na ploše se objeví soubor s názvem CKFiles.txt . Otevři ho a zkopíruj sem celý jeho obsah..

Stáhni si RootRepeal

Rozbal si archív třeba do C:\RootRepeal
Poklepej na RootRepeal.exe ke startu programu ( ve vistě pravým a vybrat spustit jako administrátor).
Klikni v dolní části na Files a potom na Scan .
Objeví se dialog.okno, dej zatržítko na disk, který chceš skenovat( nejčastěji na C:\ , a potom na OK.
Program začne skenovat zatržený disk. Když sken skončí , budou tam vypsané soubory, ale ne všechny musí být legitimní. Klikni na Save Report a ulož si log do dokumentů. Vlož sem prosím celý jeho obsah.

Je to záhada, ještě to zkus...

Pak ještě ta oprava, můžeš zkusit i toto:
Win XP Manager
Tady je Návod

download:
http://www.yamicsoft.com/xpmanager/
http://www.slunecnice.cz/sw/winxp-manager/
http://www.stahuj.centrum.cz/utility_a_ ... p-manager/

Je to shareware na určitou dobu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

RuLich
nováček
Příspěvky: 13
Registrován: duben 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod RuLich » 18 dub 2010 12:31

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A
Windows Product Key: *****-*****-QW3HM-JGRQX-KM77T
Windows Product Key Hash: NiGGJUBjRyjHCl1UtP6NiEnsppE=
Windows Product ID: 55703-640-0185941-23223
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.3.0.pro
ID: {E2654799-3D13-4CF1-8FDC-C486C79E9AFF}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: Registered, 1.7.69.2
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A
Version: N/A

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-230-1

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{E2654799-3D13-4CF1-8FDC-C486C79E9AFF}</UGUID><Version>1.9.0027.0</Version><OS>5.1.2600.2.00010100.3.0.pro</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-KM77T</PKey><PID>55703-640-0185941-23223</PID><PIDType>1</PIDType><SID>S-1-5-21-839522115-884357618-1801674531</SID><SYSTEM><Manufacturer>MSI</Manufacturer><Model>MS-7350</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>V2.7</Version><SMBIOSVersion major="2" minor="5"/><Date>20081209000000.000000+000</Date></BIOS><HWID>F87A37970184CE7A</HWID><UserLCID>0405</UserLCID><SystemLCID>0405</SystemLCID><TimeZone>Střední Evropa (běžný čas)(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>

Licensing Data-->
N/A

Windows Activation Technologies-->
N/A

HWID Data-->
N/A

OEM Activation 1.0 Data-->
BIOS string matches: yes
Marker string from BIOS: 13B96:GENUINE C&C INC|5E5C:HITACHI, Ltd|5E5C:HITACHI, Ltd|5E5C:HITACHI, Ltd
Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005

OEM Activation 2.0 Data-->
N/A

..................................................................

CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\rulich\oblíbené položky\crack\angernet.org free software area - download full games.url
c:\documents and settings\rulich\oblíbené položky\crack\applian mp3 magic 2.02 warez download crack serial keygen full version free.url
c:\documents and settings\rulich\oblíbené položky\crack\battlefield 2 @ phazeddl.com.url
c:\documents and settings\rulich\oblíbené položky\crack\bookmarks.html
c:\documents and settings\rulich\oblíbené položky\crack\crack-locator.com.url
c:\documents and settings\rulich\oblíbené položky\crack\crackdb.org - apps - i2.url
c:\documents and settings\rulich\oblíbené položky\crack\crackhell.com - crack serial warez xxx toplist.url
c:\documents and settings\rulich\oblíbené položky\crack\cracks, serials, keygen, iso for free download! page - g.url
c:\documents and settings\rulich\oblíbené položky\crack\download crack serial - download cracks serials no porn popups! no stupid trojans and exploits!.url
c:\documents and settings\rulich\oblíbené položky\crack\download free warez @ fullforum.com(!!!).url
c:\documents and settings\rulich\oblíbené položky\crack\freeserials.htm
c:\documents and settings\rulich\oblíbené položky\crack\full version download with crack serial keygen torrent rapidshare.url
c:\documents and settings\rulich\oblíbené položky\crack\gameburnworld- no-cd-no-dvd patches, game fixes, trainers, cheats.url
c:\documents and settings\rulich\oblíbené položky\crack\gamecopyworld - main.url
c:\documents and settings\rulich\oblíbené položky\crack\gamecopyworld - mirrors - no-cd, no-dvd patches, game fixes, trainers & cheats.url
c:\documents and settings\rulich\oblíbené položky\crack\infernal warez.url
c:\documents and settings\rulich\oblíbené položky\crack\keygen.ms - generates cracks serials keygens for the software to unlock it for free.url
c:\documents and settings\rulich\oblíbené položky\crack\keygen.ws.url
c:\documents and settings\rulich\oblíbené položky\crack\megagames - pc game fixes.url
c:\documents and settings\rulich\oblíbené položky\crack\p30world english version archives.url
c:\documents and settings\rulich\oblíbené položky\crack\rapidshare warez - fullversion warez downloads.url
c:\documents and settings\rulich\oblíbené položky\crack\the pirate bay - the worlds largest bittorrent tracker.url
c:\documents and settings\rulich\oblíbené položky\crack\uploter.net- direct download link.url
c:\documents and settings\rulich\oblíbené položky\crack\vertus full warez downloads - vertus serial, vertus crack, vertus full torrent, vertus+searial+crack.rar.url
c:\documents and settings\rulich\oblíbené položky\crack\warez rips home.url
c:\documents and settings\rulich\oblíbené položky\crack\wareznova - free full game downloads, mp3, and movies.url
c:\documents and settings\rulich\oblíbené položky\crack\češtiny a cracky do her a programů - !!!! Čti !!!!!.url
c:\documents and settings\rulich\oblíbené položky\fora\astalavista.ms forum view forum - cracks and serials.url
c:\documents and settings\rulich\oblíbené položky\fora\filez.cz - vaše cesta do světa warez! (gamez, moviez, crackz, appz links).url
c:\documents and settings\rulich\oblíbené položky\hackování\soom.cz - cracking.url
c:\documents and settings\rulich\oblíbené položky\links\runtime getdataback for fat ntfs 4.0 warez download, crack, serial, keygen, full version from worldwarez.url
c:\documents and settings\rulich\plocha\programy\heslo\live cd ophcrack\ophcrack-xp-livecd-2.3.1.iso
c:\documents and settings\rulich\plocha\programy\heslo\live cd ophvistacrack\ophcrack-vista-livecd-2.3.1.iso
c:\documents and settings\rulich\plocha\slow-pcfighter\slow-pcfighter.1.0.93.cracked-snd.zip
c:\documents and settings\rulich\plocha\slow-pcfighter\nová složka\slow-pcfighter.1.0.93\slow-pcfighter.1.0.93.cracked-snd\popis.txt
c:\documents and settings\rulich\plocha\slow-pcfighter\nová složka\slow-pcfighter.1.0.93\slow-pcfighter.1.0.93.cracked-snd\slow-pcfighter.exe
c:\documents and settings\rulich\plocha\slow-pcfighter\nová složka\slow-pcfighter.1.0.93\slow-pcfighter.1.0.93.cracked-snd\snd.nfo
scanner sequence 3.ZZ.11
----- EOF -----
...................................................................................

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/04/18 12:29
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Hidden/Locked Files
-------------------
Path: c:\windows\temp\~df84ee.tmp
Status: Allocation size mismatch (API: 786432, Raw: 16384)

Path: c:\documents and settings\rulich\local settings\temporary internet files\content.ie5\jd2g30x9\viewtopic[2].htm
Status: Allocation size mismatch (API: 249856, Raw: 262144)

Path: C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\Content.IE5\OU11B29Q\1[1].htm
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\Content.IE5\OU11B29Q\1[2].htm
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\Content.IE5\OU11B29Q\generic[4].htm
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\Content.IE5\OU11B29Q\spc[2].php
Status: Visible to the Windows API, but not on disk.

Path: c:\documents and settings\rulich\local settings\data aplikací\microsoft\internet explorer\recovery\active\recoverystore.{1e22a6ce-4ac8-11df-8feb-0019dbcaa077}.dat
Status: Size mismatch (API: 7680, Raw: 8704)

Path: c:\documents and settings\rulich\local settings\data aplikací\microsoft\internet explorer\recovery\active\{fcb68795-4ad2-11df-8feb-0019dbcaa077}.dat
Status: Size mismatch (API: 375808, Raw: 368128)

Path: C:\Documents and Settings\RuLich\Local Settings\Data aplikací\Microsoft\Internet Explorer\Recovery\Active\{17D8A92F-4AD5-11DF-8FEB-0019DBCAA077}.dat
Status: Visible to the Windows API, but not on disk.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43292
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod jaro3 » 18 dub 2010 13:20

Stáhni si program OTM (by OldTimer)
a ulož si ho na disk C a spusť ho.
- Do levého sloupce (Paste Instructions for Items to be Moved) zkopíruj tyto cesty:
Poznámka: Nepoužij k označení funkci VYBRAT VŠE

Kód: Vybrat vše

:Processes
explorer.exe

:Services

:Reg

:Files
c:\windows\temp\~df84ee.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

- Po zkopírování klikni na tlačítko MoveIt! a vlož sem následně celý obsah z pravého sloupce, jinak uložený ve složce C:\_OTMoveIt\MovedFiles\, který bude informovat o výsledcích
- Je možné, že pokud nebudou moci být soubory odstraněny, budeš dotázán na restart počítače, v tom případě restart potvrď.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

RuLich
nováček
Příspěvky: 13
Registrován: duben 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod RuLich » 18 dub 2010 14:22

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder c:\windows\temp\~df84ee.tmp not found.
File/Folder C:\WINDOWS\System32\*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder c:\windows\Tasks\*.job not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: RuLich
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 14804253 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 638 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 670929 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 15,00 mb


OTM by OldTimer - Version 3.1.10.2 log created on 04182010_141948

Files moved on Reboot...
C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\Content.IE5\OU11B29Q\ads[6].htm moved successfully.
C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\Content.IE5\H527B25Y\ads[5].htm moved successfully.
C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\Content.IE5\DFF6MB8U\viewtopic[3].htm moved successfully.
C:\Documents and Settings\RuLich\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_6a4.dat moved successfully.
File C:\WINDOWS\temp\~DF8CAD.tmp not found!
File C:\WINDOWS\temp\~DF928C.tmp not found!
File C:\WINDOWS\temp\~DFA9CA.tmp not found!
File C:\WINDOWS\temp\~DFAA86.tmp not found!

Registry entries deleted on Reboot...

......................................
Stále když chci otevřít Síťová připojení se to sekne načítají se hodiny až při ukončení svchost.exe se to otevře,
ale ikony tam nejsou, začnou problikávat ikony na ploše a začne se měnit lista na klasické nastavení.
Menůže to být Bluetooth, nějaká ikona je v Ovládacích panelech a kdysi se mi naistalovalo jakési připojení na lište vedle hodin byla ještě jedna ikona síťového připojeni a bylo to na Bluetooth.
A nejde spustit Brána Firewall

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43292
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontolu logu

Příspěvekod jaro3 » 18 dub 2010 15:25

Viry to nebude , spíš než na poškození systému , bych usuzoval na chyby na disku. Zkontroluj HDD na chyby a RAM Memtestem.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Google [Bot] a 119 hostů