Stránka 1 z 1

Prosím o kontrolu logu

Napsal: 02 úno 2012 17:39
od Sigmaczek
Zdravím

Prosím o kontrolu logu, občas zamrzá mozzila, mbam byl čistý . Děkuji

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:33:11, on 2.2.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Users\Sigmaczek\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=15383
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Windows\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Windows\WebIE.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SafeQ Client] "C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.6\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RGSC] D:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\SavevidPlug-in\redirect.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Windows\WebIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Windows\WebIE.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12365 bytes

Re: Prosím o kontrolu logu

Napsal: 03 úno 2012 09:03
od jaro3
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=15383
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)


Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Re: Prosím o kontrolu logu

Napsal: 03 úno 2012 09:30
od Sigmaczek
ComboFix 12-02-02.02 - Sigmaczek 03.02.2012 9:17.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.2258 [GMT 1:00]
Spuštěný z: c:\users\Sigmaczek\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\programdata\FullRemove.exe
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\tmpDB98.tmp
c:\windows\SysWow64\tmpDBB8.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-03 do 2012-02-03 )))))))))))))))))))))))))))))))
.
.
2012-02-03 08:14 . 2012-02-03 08:16 -------- d-----w- C:\32788R22FWJFW
2012-02-02 10:04 . 2012-02-02 10:04 -------- d-----w- c:\program files (x86)\Ask.com
2012-01-31 21:22 . 2012-01-31 21:22 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2012-01-31 17:34 . 2012-02-01 08:38 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\GarenaPlus
2012-01-31 17:34 . 2012-01-31 17:34 -------- d-----w- c:\program files (x86)\Garena Plus
2012-01-31 17:34 . 2012-02-01 08:38 -------- d-----w- c:\programdata\GarenaMessenger
2012-01-31 12:34 . 2012-01-31 12:34 491520 ----a-w- c:\windows\WebIE.dll
2012-01-31 12:34 . 2012-01-31 12:34 294912 ----a-w- c:\windows\TrnWord.dll
2012-01-31 12:31 . 2012-01-31 12:31 516096 ----a-w- c:\windows\UN32.EXE
2012-01-31 12:30 . 2012-01-31 12:36 -------- d-----w- C:\TRANSLAT
2012-01-31 12:29 . 2012-01-31 12:29 -------- d-----w- c:\program files (x86)\Elaborate Bytes
2012-01-31 07:48 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E3BDF63F-FBF4-4178-AFF7-C6B9E76A79EA}\mpengine.dll
2012-01-30 22:26 . 2012-01-30 22:26 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2012-01-30 22:26 . 2012-01-30 22:26 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2012-01-30 22:26 . 2003-09-03 01:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2012-01-30 22:26 . 2003-09-03 01:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2012-01-30 22:26 . 2003-09-03 01:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2012-01-30 22:26 . 2003-09-03 01:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2012-01-30 22:26 . 2003-09-03 01:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2012-01-30 22:11 . 2012-01-31 11:22 -------- d-----w- c:\program files (x86)\Valve
2012-01-30 21:45 . 2012-02-02 20:50 -------- d-----w- c:\users\Sigmaczek\AppData\Local\LogMeIn Hamachi
2012-01-30 21:44 . 2012-01-31 10:02 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-sh--we c:\windows\SysWow64\config\systemprofile\Soubory cookie
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-sh--we c:\windows\SysWow64\config\systemprofile\Data aplikací
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Programs
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-----w- c:\users\Sigmaczek\AppData\Local\ArcSoft
2012-01-30 10:31 . 2012-01-30 10:32 -------- d-----w- c:\programdata\ArcSoft
2012-01-30 10:31 . 2012-01-30 10:33 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\ArcSoft
2012-01-30 10:31 . 2006-11-14 10:31 22784 ----a-w- c:\windows\SysWow64\drivers\afc.sys
2012-01-30 10:30 . 2012-01-30 10:30 -------- d-----w- c:\program files (x86)\ArcSoft
2012-01-30 10:30 . 2012-01-30 10:31 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2012-01-30 10:30 . 2005-04-27 15:36 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2012-01-30 10:28 . 2012-01-30 10:28 238 ----a-w- c:\windows\system32\AF15IRTBL.bin
2012-01-30 10:28 . 2012-01-30 10:28 -------- d-----w- c:\program files (x86)\China
2012-01-28 20:35 . 2012-01-28 20:35 2829 ----a-w- c:\windows\War3Unin.pif
2012-01-28 20:35 . 2012-01-28 20:35 126976 ----a-w- c:\windows\War3Unin.exe
2012-01-28 17:31 . 2012-01-28 17:31 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-01-27 11:10 . 2012-01-27 11:11 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Facebook
2012-01-25 13:26 . 2012-01-25 13:26 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Sony Ericsson
2012-01-22 15:58 . 2012-01-22 15:58 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Diagnostics
2012-01-19 14:13 . 2012-01-19 14:13 -------- d-----w- c:\programdata\Codemasters
2012-01-18 19:53 . 2012-01-18 19:53 -------- d--h--w- c:\programdata\CanonBJ
2012-01-18 19:53 . 2008-05-26 19:00 82944 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9E.DLL
2012-01-18 19:53 . 2008-05-26 19:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9E.DLL
2012-01-18 19:53 . 2008-05-26 19:00 279040 ----a-w- c:\windows\system32\CNMLM9E.DLL
2012-01-18 10:30 . 2012-01-18 15:43 -------- d-----w- c:\users\Sigmaczek\AppData\Local\id Software
2012-01-18 10:27 . 2012-01-28 17:26 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
2012-01-17 06:11 . 2012-01-17 06:11 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\.minecraft
2012-01-16 07:56 . 2012-01-16 07:56 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-01-16 07:54 . 2008-07-10 10:00 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-16 07:51 . 2012-01-16 07:51 -------- d-----w- c:\users\Sigmaczek\AppData\Local\2K Games
2012-01-13 12:08 . 2005-11-13 22:20 204800 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-01-13 12:08 . 2005-11-13 22:19 65024 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2012-01-13 12:08 . 2012-01-13 12:08 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-01-13 12:08 . 2012-01-13 12:08 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-01-13 12:08 . 2005-11-13 22:22 757760 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-01-13 12:08 . 2005-11-13 22:22 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-01-13 12:08 . 2005-11-13 22:21 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-01-13 12:08 . 2005-11-13 22:19 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-01-11 06:09 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 06:09 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 06:09 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 06:09 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 06:09 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 06:09 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 06:09 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 06:09 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-09 07:23 . 2012-01-09 07:23 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\IrfanView
2012-01-09 07:23 . 2012-01-09 07:23 -------- d-----w- c:\program files (x86)\IrfanView
2012-01-09 00:22 . 2003-07-15 06:30 21941 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\STRINGS.JS
2012-01-09 00:22 . 2003-07-15 06:30 18690 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\PRELOAD.JS
2012-01-09 00:22 . 2003-07-15 06:30 14396 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\FPLIB.JS
2012-01-09 00:22 . 2003-07-15 06:30 11729 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\_JMPMENU.JS
2012-01-09 00:22 . 2003-07-15 06:30 18219 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\SETTEXT.JS
2012-01-09 00:22 . 2003-07-15 06:30 15020 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\_PRELOAD.JS
2012-01-09 00:22 . 2003-07-15 06:30 13773 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\DOM.JS
2012-01-09 00:22 . 2003-07-15 06:30 11988 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\GETOBJ.JS
2012-01-09 00:03 . 2012-01-30 05:17 -------- d-----w- c:\programdata\Agama Web Menus
2012-01-08 23:04 . 2012-01-08 23:07 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\GHISLER
2012-01-08 23:04 . 2012-01-08 23:04 -------- d-----w- C:\totalcmd
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2012-01-08 15:30 . 2012-01-28 17:26 107832 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-08 15:29 . 2012-01-18 10:27 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-25 20:33 . 2011-12-25 20:33 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-12-25 20:33 . 2011-12-25 20:33 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-12-25 20:33 . 2011-12-25 20:33 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-12-25 20:33 . 2011-12-25 20:33 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-12-25 20:33 . 2011-12-25 20:33 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-12-25 20:33 . 2011-12-25 20:33 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-12-25 20:33 . 2011-12-25 20:33 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-12-25 20:33 . 2011-12-25 20:33 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-12-25 20:33 . 2011-12-25 20:33 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-12-25 20:33 . 2011-12-25 20:33 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-12-25 20:33 . 2011-12-25 20:33 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-12-25 20:33 . 2011-12-25 20:33 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-12-25 20:33 . 2011-12-25 20:33 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-12-25 20:33 . 2011-12-25 20:33 448512 ----a-w- c:\windows\system32\html.iec
2011-12-25 20:33 . 2011-12-25 20:33 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-12-25 20:33 . 2011-12-25 20:33 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-12-25 20:33 . 2011-12-25 20:33 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-12-25 20:33 . 2011-12-25 20:33 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-25 20:33 . 2011-12-25 20:33 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-12-25 20:33 . 2011-12-25 20:33 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-25 20:33 . 2011-12-25 20:33 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-12-25 20:33 . 2011-12-25 20:33 2309120 ----a-w- c:\windows\system32\jscript9.dll
2011-12-25 20:33 . 2011-12-25 20:33 222208 ----a-w- c:\windows\system32\msls31.dll
2011-12-25 20:33 . 2011-12-25 20:33 1798144 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-12-25 20:33 . 2011-12-25 20:33 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-12-25 20:33 . 2011-12-25 20:33 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-12-25 20:33 . 2011-12-25 20:33 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-12-25 20:33 . 2011-12-25 20:33 160256 ----a-w- c:\windows\system32\wextract.exe
2011-12-25 20:33 . 2011-12-25 20:33 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-12-25 20:33 . 2011-12-25 20:33 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-12-25 20:33 . 2011-12-25 20:33 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-25 20:33 . 2011-12-25 20:33 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-12-25 20:33 . 2011-12-25 20:33 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-12-25 20:33 . 2011-12-25 20:33 1390080 ----a-w- c:\windows\system32\wininet.dll
2011-12-25 20:33 . 2011-12-25 20:33 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-12-25 20:33 . 2011-12-25 20:33 12288 ----a-w- c:\windows\system32\mshta.exe
2011-12-25 20:33 . 2011-12-25 20:33 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-12-25 20:33 . 2011-12-25 20:33 114176 ----a-w- c:\windows\system32\admparse.dll
2011-12-25 20:33 . 2011-12-25 20:33 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
2011-12-25 20:33 . 2011-12-25 20:33 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-12-25 20:33 . 2011-12-25 20:33 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-12-25 20:33 . 2011-12-25 20:33 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-12-25 20:22 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-25 20:22 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-12-23 21:14 . 2011-12-22 13:36 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-22 22:22 . 2011-12-22 22:22 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-12-10 14:24 . 2011-12-23 22:21 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-07 09:39 . 2011-12-22 12:19 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 18:01 . 2011-12-24 22:30 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-12-24 22:30 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-11-28 18:01 . 2011-12-22 11:58 256960 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:54 . 2011-12-24 22:30 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-12-24 22:30 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-12-24 22:30 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-12-24 22:30 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-12-24 22:30 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2011-12-24 22:30 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-24 04:52 . 2011-12-23 10:09 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-17 06:35 . 2012-01-12 13:31 340992 ----a-w- c:\windows\system32\schannel.dll
2011-11-17 05:34 . 2012-01-12 13:31 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 15:31 1514152 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17762440]
"ICQ"="c:\program files (x86)\ICQ7.6\ICQ.exe" [2011-12-22 127040]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SafeQ Client"="c:\program files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe" [2010-09-29 262144]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 135664]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-12-22 1030600]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 135664]
R3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys [x]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [x]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [x]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [x]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [x]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [x]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [x]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2011-08-03 468432]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-231062597-2546089165-273083180-1001Core.job
- c:\users\Sigmaczek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-27 11:10]
.
2012-02-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-231062597-2546089165-273083180-1001UA.job
- c:\users\Sigmaczek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-27 11:10]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 08:26]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 08:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.cz/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Save video on Savevid.com - c:\program files (x86)\SavevidPlug-in\redirect.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
Trusted Zone: vsb.cz\vpn
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\shell32.dll
FF - ProfilePath - c:\users\Sigmaczek\AppData\Roaming\Mozilla\Firefox\Profiles\k8rrht8l.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: network.proxy.type - 0
.
.
------- Asociace souborů -------
.
JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-A-PDF Split_is1 - d:\a-pdf split\unins000.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Fraps - d:\fraps\uninstall.exe
AddRemove-GameParkClient_is1 - d:\gamepark\unins000.exe
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
Celkový čas: 2012-02-03 09:29:35
ComboFix-quarantined-files.txt 2012-02-03 08:29
.
Před spuštěním: 51 438 616 576 bytes free
Po spuštění: Volných bajtů: 51 347 578 880
.
- - End Of File - - 35AC25AAE28C9F59A778C5616EB4292A

Re: Prosím o kontrolu logu

Napsal: 03 úno 2012 11:20
od jaro3
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

Folder::
C:\32788R22FWJFW
c:\program files (x86)\Ask.com

Registry::
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR

na svojí plochu.Poklepej na aswMBR.exe. Klikni na Scan.
Po skenu klikni na aswASW.log a ulož si ho na plochu , vlož sem celý obsak toho logu.

Re: Prosím o kontrolu logu

Napsal: 03 úno 2012 11:41
od Sigmaczek
ComboFix 12-02-02.02 - Sigmaczek 03.02.2012 11:30:13.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3949.2038 [GMT 1:00]
Spuštěný z: c:\users\Sigmaczek\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Sigmaczek\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\32788R22FWJFW
c:\32788r22fwjfw\EN-US\cmd.3XE.mui
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_a7bb.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\Common Files\ASPG_icon.ico
c:\programdata\FullRemove.exe
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\tmpDB98.tmp
c:\windows\SysWow64\tmpDBB8.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-03 do 2012-02-03 )))))))))))))))))))))))))))))))
.
.
2012-02-03 10:37 . 2012-02-03 10:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-03 08:19 . 2012-02-03 08:19 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E3BDF63F-FBF4-4178-AFF7-C6B9E76A79EA}\offreg.dll
2012-01-31 21:22 . 2012-01-31 21:22 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller
2012-01-31 17:34 . 2012-02-01 08:38 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\GarenaPlus
2012-01-31 17:34 . 2012-01-31 17:34 -------- d-----w- c:\program files (x86)\Garena Plus
2012-01-31 17:34 . 2012-02-01 08:38 -------- d-----w- c:\programdata\GarenaMessenger
2012-01-31 12:34 . 2012-01-31 12:34 491520 ----a-w- c:\windows\WebIE.dll
2012-01-31 12:34 . 2012-01-31 12:34 294912 ----a-w- c:\windows\TrnWord.dll
2012-01-31 12:31 . 2012-01-31 12:31 516096 ----a-w- c:\windows\UN32.EXE
2012-01-31 12:30 . 2012-01-31 12:36 -------- d-----w- C:\TRANSLAT
2012-01-31 12:29 . 2012-01-31 12:29 -------- d-----w- c:\program files (x86)\Elaborate Bytes
2012-01-31 07:48 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E3BDF63F-FBF4-4178-AFF7-C6B9E76A79EA}\mpengine.dll
2012-01-30 22:26 . 2012-01-30 22:26 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2012-01-30 22:26 . 2012-01-30 22:26 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2012-01-30 22:26 . 2003-09-03 01:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2012-01-30 22:26 . 2003-09-03 01:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2012-01-30 22:26 . 2003-09-03 01:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2012-01-30 22:26 . 2003-09-03 01:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2012-01-30 22:26 . 2003-09-03 01:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2012-01-30 22:11 . 2012-01-31 11:22 -------- d-----w- c:\program files (x86)\Valve
2012-01-30 21:45 . 2012-02-02 20:50 -------- d-----w- c:\users\Sigmaczek\AppData\Local\LogMeIn Hamachi
2012-01-30 21:44 . 2012-01-31 10:02 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-sh--we c:\windows\SysWow64\config\systemprofile\Soubory cookie
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-sh--we c:\windows\SysWow64\config\systemprofile\Data aplikací
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Programs
2012-01-30 10:32 . 2012-01-30 10:32 -------- d-----w- c:\users\Sigmaczek\AppData\Local\ArcSoft
2012-01-30 10:31 . 2012-01-30 10:32 -------- d-----w- c:\programdata\ArcSoft
2012-01-30 10:31 . 2012-01-30 10:33 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\ArcSoft
2012-01-30 10:31 . 2006-11-14 10:31 22784 ----a-w- c:\windows\SysWow64\drivers\afc.sys
2012-01-30 10:30 . 2012-01-30 10:30 -------- d-----w- c:\program files (x86)\ArcSoft
2012-01-30 10:30 . 2012-01-30 10:31 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2012-01-30 10:30 . 2005-04-27 15:36 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2012-01-30 10:28 . 2012-01-30 10:28 238 ----a-w- c:\windows\system32\AF15IRTBL.bin
2012-01-30 10:28 . 2012-01-30 10:28 -------- d-----w- c:\program files (x86)\China
2012-01-28 20:35 . 2012-01-28 20:35 2829 ----a-w- c:\windows\War3Unin.pif
2012-01-28 20:35 . 2012-01-28 20:35 126976 ----a-w- c:\windows\War3Unin.exe
2012-01-28 17:31 . 2012-01-28 17:31 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2012-01-27 11:10 . 2012-01-27 11:11 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Facebook
2012-01-25 13:26 . 2012-01-25 13:26 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Sony Ericsson
2012-01-22 15:58 . 2012-01-22 15:58 -------- d-----w- c:\users\Sigmaczek\AppData\Local\Diagnostics
2012-01-19 14:13 . 2012-01-19 14:13 -------- d-----w- c:\programdata\Codemasters
2012-01-18 19:53 . 2012-01-18 19:53 -------- d--h--w- c:\programdata\CanonBJ
2012-01-18 19:53 . 2008-05-26 19:00 82944 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9E.DLL
2012-01-18 19:53 . 2008-05-26 19:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9E.DLL
2012-01-18 19:53 . 2008-05-26 19:00 279040 ----a-w- c:\windows\system32\CNMLM9E.DLL
2012-01-18 10:30 . 2012-01-18 15:43 -------- d-----w- c:\users\Sigmaczek\AppData\Local\id Software
2012-01-18 10:27 . 2012-01-28 17:26 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
2012-01-17 06:11 . 2012-01-17 06:11 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\.minecraft
2012-01-16 07:56 . 2012-01-16 07:56 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2012-01-16 07:54 . 2008-07-10 10:00 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-16 07:51 . 2012-01-16 07:51 -------- d-----w- c:\users\Sigmaczek\AppData\Local\2K Games
2012-01-13 12:08 . 2005-11-13 22:20 204800 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-01-13 12:08 . 2005-11-13 22:19 65024 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2012-01-13 12:08 . 2012-01-13 12:08 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-01-13 12:08 . 2012-01-13 12:08 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-01-13 12:08 . 2005-11-13 22:22 757760 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-01-13 12:08 . 2005-11-13 22:22 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-01-13 12:08 . 2005-11-13 22:21 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-01-13 12:08 . 2005-11-13 22:19 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-01-11 06:09 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 06:09 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 06:09 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 06:09 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 06:09 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 06:09 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 06:09 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 06:09 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-09 07:23 . 2012-01-09 07:23 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\IrfanView
2012-01-09 07:23 . 2012-01-09 07:23 -------- d-----w- c:\program files (x86)\IrfanView
2012-01-09 00:22 . 2003-07-15 06:30 21941 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\STRINGS.JS
2012-01-09 00:22 . 2003-07-15 06:30 18690 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\PRELOAD.JS
2012-01-09 00:22 . 2003-07-15 06:30 14396 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\FPLIB.JS
2012-01-09 00:22 . 2003-07-15 06:30 11729 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\_JMPMENU.JS
2012-01-09 00:22 . 2003-07-15 06:30 18219 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\SETTEXT.JS
2012-01-09 00:22 . 2003-07-15 06:30 15020 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\_PRELOAD.JS
2012-01-09 00:22 . 2003-07-15 06:30 13773 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\DOM.JS
2012-01-09 00:22 . 2003-07-15 06:30 11988 ----a-w- c:\users\Sigmaczek\AppData\Roaming\Microsoft\FrontPage\Behaviors\Actions\GETOBJ.JS
2012-01-09 00:03 . 2012-01-30 05:17 -------- d-----w- c:\programdata\Agama Web Menus
2012-01-08 23:04 . 2012-01-08 23:07 -------- d-----w- c:\users\Sigmaczek\AppData\Roaming\GHISLER
2012-01-08 23:04 . 2012-01-08 23:04 -------- d-----w- C:\totalcmd
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2012-01-08 23:04 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2012-01-08 15:30 . 2012-01-28 17:26 107832 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-08 15:29 . 2012-01-18 10:27 75064 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-25 20:33 . 2011-12-25 20:33 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-12-25 20:33 . 2011-12-25 20:33 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-12-25 20:33 . 2011-12-25 20:33 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-12-25 20:33 . 2011-12-25 20:33 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-12-25 20:33 . 2011-12-25 20:33 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-12-25 20:33 . 2011-12-25 20:33 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-12-25 20:33 . 2011-12-25 20:33 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-12-25 20:33 . 2011-12-25 20:33 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-12-25 20:33 . 2011-12-25 20:33 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-12-25 20:33 . 2011-12-25 20:33 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-12-25 20:33 . 2011-12-25 20:33 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-12-25 20:33 . 2011-12-25 20:33 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-12-25 20:33 . 2011-12-25 20:33 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-12-25 20:33 . 2011-12-25 20:33 448512 ----a-w- c:\windows\system32\html.iec
2011-12-25 20:33 . 2011-12-25 20:33 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-12-25 20:33 . 2011-12-25 20:33 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-12-25 20:33 . 2011-12-25 20:33 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-12-25 20:33 . 2011-12-25 20:33 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-25 20:33 . 2011-12-25 20:33 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-12-25 20:33 . 2011-12-25 20:33 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-12-25 20:33 . 2011-12-25 20:33 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-12-25 20:33 . 2011-12-25 20:33 2309120 ----a-w- c:\windows\system32\jscript9.dll
2011-12-25 20:33 . 2011-12-25 20:33 222208 ----a-w- c:\windows\system32\msls31.dll
2011-12-25 20:33 . 2011-12-25 20:33 1798144 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-12-25 20:33 . 2011-12-25 20:33 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-12-25 20:33 . 2011-12-25 20:33 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-12-25 20:33 . 2011-12-25 20:33 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-12-25 20:33 . 2011-12-25 20:33 160256 ----a-w- c:\windows\system32\wextract.exe
2011-12-25 20:33 . 2011-12-25 20:33 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-12-25 20:33 . 2011-12-25 20:33 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-12-25 20:33 . 2011-12-25 20:33 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-25 20:33 . 2011-12-25 20:33 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-12-25 20:33 . 2011-12-25 20:33 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-12-25 20:33 . 2011-12-25 20:33 1390080 ----a-w- c:\windows\system32\wininet.dll
2011-12-25 20:33 . 2011-12-25 20:33 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-12-25 20:33 . 2011-12-25 20:33 12288 ----a-w- c:\windows\system32\mshta.exe
2011-12-25 20:33 . 2011-12-25 20:33 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-12-25 20:33 . 2011-12-25 20:33 114176 ----a-w- c:\windows\system32\admparse.dll
2011-12-25 20:33 . 2011-12-25 20:33 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
2011-12-25 20:33 . 2011-12-25 20:33 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-12-25 20:33 . 2011-12-25 20:33 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-12-25 20:33 . 2011-12-25 20:33 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-12-25 20:22 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-25 20:22 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-12-23 21:14 . 2011-12-22 13:36 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-22 22:22 . 2011-12-22 22:22 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-12-10 14:24 . 2011-12-23 22:21 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-07 09:39 . 2011-12-22 12:19 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 18:01 . 2011-12-24 22:30 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-12-24 22:30 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-11-28 18:01 . 2011-12-22 11:58 256960 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:54 . 2011-12-24 22:30 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-12-24 22:30 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-12-24 22:30 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-12-24 22:30 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-12-24 22:30 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2011-12-24 22:30 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-24 04:52 . 2011-12-23 10:09 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-17 06:35 . 2012-01-12 13:31 340992 ----a-w- c:\windows\system32\schannel.dll
2011-11-17 05:34 . 2012-01-12 13:31 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17762440]
"ICQ"="c:\program files (x86)\ICQ7.6\ICQ.exe" [2011-12-22 127040]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SafeQ Client"="c:\program files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe" [2010-09-29 262144]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-02-04 7350912]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 1079584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 135664]
R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-12-22 1030600]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 135664]
R3 IT9135BDA;IT9135 BDA Devices;c:\windows\system32\Drivers\IT9135BDA.sys [x]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [x]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [x]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [x]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [x]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [x]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [x]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2011-08-03 468432]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-231062597-2546089165-273083180-1001Core.job
- c:\users\Sigmaczek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-27 11:10]
.
2012-02-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-231062597-2546089165-273083180-1001UA.job
- c:\users\Sigmaczek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-01-27 11:10]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 08:26]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-24 08:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.cz/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Save video on Savevid.com - c:\program files (x86)\SavevidPlug-in\redirect.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
Trusted Zone: vsb.cz\vpn
TCP: DhcpNameServer = 94.74.192.252 94.74.192.244
FF - ProfilePath - c:\users\Sigmaczek\AppData\Roaming\Mozilla\Firefox\Profiles\k8rrht8l.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-A-PDF Split_is1 - d:\a-pdf split\unins000.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Fraps - d:\fraps\uninstall.exe
AddRemove-GameParkClient_is1 - d:\gamepark\unins000.exe
AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files (x86)\Ask.com\Updater\Updater.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-231062597-2546089165-273083180-1001\Software\SecuROM\License information*]
"datasecu"=hex:96,09,1b,04,05,62,cf,7a,59,54,d1,bf,5d,cd,e7,00,5b,d6,b2,48,08,
34,3a,de,73,72,28,12,c8,44,ed,25,d3,4c,67,a8,41,a5,a3,f8,86,53,95,66,7a,e2,\
"rkeysecu"=hex:5d,7c,7f,06,b2,19,11,4f,13,7d,87,43,75,df,0e,ea
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-02-03 11:40:24
ComboFix-quarantined-files.txt 2012-02-03 10:40
.
Před spuštěním: Volných bajtů: 51 587 162 112
Po spuštění: Volných bajtů: 51 449 180 160
.
- - End Of File - - D20BE9582BF909A9EB29831372E18037

Re: Prosím o kontrolu logu

Napsal: 03 úno 2012 11:41
od Sigmaczek
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:41:28, on 3.2.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Users\Sigmaczek\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Windows\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Windows\WebIE.dll
O4 - HKLM\..\Run: [SafeQ Client] "C:\Program Files (x86)\Y Soft\SafeQ Client\Client\SafeQ Client.exe"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.6\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Save video on Savevid.com - C:\Program Files (x86)\SavevidPlug-in\redirect.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Windows\WebIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Windows\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Windows\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Windows\WebIE.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11340 bytes

Re: Prosím o kontrolu logu

Napsal: 03 úno 2012 11:49
od Sigmaczek
aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-02-03 11:43:00
-----------------------------
11:43:00.157 OS Version: Windows x64 6.1.7601 Service Pack 1
11:43:00.157 Number of processors: 4 586 0x2505
11:43:00.157 ComputerName: SIGMACZEK-PC UserName: Sigmaczek
11:43:00.781 Initialize success
11:43:00.843 AVAST engine defs: 12020300
11:43:11.326 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:43:11.326 Disk 0 Vendor: ST950042 0003 Size: 476940MB BusType: 3
11:43:11.357 Disk 0 MBR read successfully
11:43:11.357 Disk 0 MBR scan
11:43:11.357 Disk 0 Windows 7 default MBR code
11:43:11.373 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 20002 MB offset 63
11:43:11.373 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 119235 MB offset 40965752
11:43:11.373 Disk 0 Partition - 00 0F Extended LBA 337701 MB offset 285159424
11:43:11.404 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 337700 MB offset 285161472
11:43:11.404 Service scanning
11:43:12.699 Modules scanning
11:43:12.699 Disk 0 trace - called modules:
11:43:12.715 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
11:43:12.730 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c9a060]
11:43:12.746 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> [0xfffffa80049c20b0]
11:43:12.746 5 ACPI.sys[fffff88000f5d7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80049c7050]
11:43:16.739 AVAST engine scan C:\Windows
11:43:19.189 AVAST engine scan C:\Windows\system32
11:45:21.742 AVAST engine scan C:\Windows\system32\drivers
11:45:33.099 AVAST engine scan C:\Users\Sigmaczek
11:47:27.713 AVAST engine scan C:\ProgramData
11:48:17.196 Scan finished successfully
11:48:31.267 Disk 0 MBR has been saved successfully to "C:\Users\Sigmaczek\Desktop\MBR.dat"
11:48:31.267 The log file has been saved successfully to "C:\Users\Sigmaczek\Desktop\aswMBR.txt"

Re: Prosím o kontrolu logu  Vyřešeno

Napsal: 03 úno 2012 15:25
od jaro3
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj antivir a antispyware ,následně T-Cleaner smaž a zapni si znovu antivir a antispyware.


Napiš , jak to vypadá.

Re: Prosím o kontrolu logu

Napsal: 04 úno 2012 08:49
od Sigmaczek
Tak vypadá to dobře, je to rychlejší a neseká se to . Moc děkuji za pomoc !