http://www.virustotal.com/cs/analisis/4 ... 1245104416
Som to kus blba, nevšimol som si, že stačí dať v tej tabuľke názov súboru a nájde si ho. Dnes som to robil cez virustotal prvý krát, tak prepáč.
Prosím o kontrolu logu, sekanie a spomalenie PC Vyřešeno
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Pokud to není šmejd, spíš bych počítal, že to je něco k tomu Ericssonu. Nemůžu o tom nic najít
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Asi áno našiel som tam jeden hpe.dll medzi pluginmi, tak to tam tiež bude asi zašité v nejakom podpriečinku.
Takže môžem dočistiť PC Ccleanerom,windowsdoctorom,tuneupom,fcleanerom,wise reg.wisw disc .? Nemám zbytočne veľa tých programov na údržbu?
Ale keď každý nájde stále ešte nejaké registre.
Takže môžem dočistiť PC Ccleanerom,windowsdoctorom,tuneupom,fcleanerom,wise reg.wisw disc .? Nemám zbytočne veľa tých programov na údržbu?

- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Nech si CCleaner, TuneUp, FCleaner, Wise.
Cleaner-Rychlý, FCleaner-důkladný, Wise - nej čistič registru. TuneUp neznám (Mám ASC v3). Zbytek je zbytečný.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
File::
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_4ae13d6c.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_294823.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_18be6784.exe
Folder::
c:\program files\ICQ6Toolbar
RegNull::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
Driver::
VideoAcceleratorService;VideoAcceleratorService
VideoAcceleratorService
esihdrv;esihdrv
esihdrv
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Cleaner-Rychlý, FCleaner-důkladný, Wise - nej čistič registru. TuneUp neznám (Mám ASC v3). Zbytek je zbytečný.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
File::
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_4ae13d6c.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_294823.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_18be6784.exe
Folder::
c:\program files\ICQ6Toolbar
RegNull::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
Driver::
VideoAcceleratorService;VideoAcceleratorService
VideoAcceleratorService
esihdrv;esihdrv
esihdrv
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
ComboFix 09-06-15.04 - PC 16.06.2009 1:05.9 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1380 [GMT 2:00]
Running from: c:\documents and settings\PC\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\PC\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
"c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_18be6784.exe"
"c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_294823.exe"
"c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_4ae13d6c.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ICQ6Toolbar
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_18be6784.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_294823.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_4ae13d6c.exe
c:\program files\ICQ6Toolbar\ICQToolBar.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ESIHDRV
-------\Legacy_VIDEOACCELERATORSERVICE
-------\Service_esihdrv
-------\Service_VideoAcceleratorService
((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.
2009-06-15 19:27 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 19:27 . 2009-06-15 19:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 19:27 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 18:56 . 2009-06-15 18:56 -------- d-----w- c:\program files\Trend Micro
2009-06-12 15:49 . 2009-06-12 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-06-12 06:42 . 2009-06-12 06:42 -------- d-----w- c:\windows\Downloaded Installations
2009-06-12 06:33 . 2009-06-12 06:56 -------- d-----w- c:\program files\Wise Registry Cleaner
2009-06-12 06:31 . 2009-06-12 06:31 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\ImTOO Software Studio
2009-06-12 06:30 . 2009-06-12 06:30 -------- d-----w- c:\program files\ImTOO
2009-06-12 06:29 . 2009-06-12 06:30 -------- d-----w- c:\program files\BurnAware Free
2009-06-10 04:26 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 04:26 . 2009-04-30 21:22 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-06-10 04:26 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 04:26 . 2009-04-30 21:22 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-06-08 13:18 . 2009-06-08 13:18 603904 ----a-w- c:\windows\system32\TUProgSt.exe
2009-06-08 13:18 . 2008-12-11 11:31 27904 ----a-w- c:\windows\system32\uxtuneup.dll
2009-06-08 13:18 . 2009-06-08 13:18 360192 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-08 13:02 . 2009-06-08 13:02 -------- d-----w- c:\program files\Opera 10 Beta
2009-06-05 15:19 . 2009-06-05 15:19 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\GHISLER
2009-06-03 13:12 . 2009-06-03 13:12 -------- d-----w- c:\program files\Common Files\Diskeeper Corporation
2009-06-03 13:12 . 2009-06-03 13:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Diskeeper Corporation
2009-06-03 13:12 . 2009-06-03 13:12 -------- d-----w- c:\program files\Diskeeper Corporation
2009-06-03 10:07 . 2009-06-03 10:07 -------- d-----w- c:\program files\iPod
2009-06-03 10:00 . 2009-06-03 10:00 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-02 21:05 . 2009-06-02 21:05 -------- d-----w- c:\documents and settings\PC\Application Data\FTWeak
2009-06-02 21:05 . 2009-06-02 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\FTWeak
2009-06-02 21:05 . 2009-06-02 21:05 -------- d-----w- c:\program files\FCleaner
2009-06-01 13:08 . 2009-06-01 13:08 -------- d-----w- c:\program files\ESET
2009-05-30 22:51 . 2008-02-12 13:59 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-30 22:44 . 2009-05-30 22:44 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\Sony Ericsson
2009-05-30 22:44 . 2009-05-30 22:44 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-05-30 22:40 . 2008-02-12 13:59 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-05-30 22:40 . 2009-05-30 22:40 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-30 21:25 . 2009-06-12 06:43 -------- d-----w- c:\program files\Wise Disk Cleaner
2009-05-30 20:58 . 2009-05-30 20:58 -------- d-----r- c:\program files\Skype
2009-05-29 10:50 . 2009-05-29 10:50 -------- d-----w- c:\windows\Sun
2009-05-28 15:08 . 2009-05-28 15:08 -------- d-----w- c:\program files\CCleaner
2009-05-22 18:41 . 2009-05-22 18:41 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-22 18:34 . 2009-05-22 18:34 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\Apple
2009-05-22 11:16 . 2009-05-22 11:16 -------- d-----w- c:\documents and settings\PC\Application Data\ESET
2009-05-22 10:29 . 2009-05-22 10:31 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-21 21:27 . 2009-05-21 21:27 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Labpixies
2009-05-21 21:27 . 2009-05-21 21:27 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-05-21 05:17 . 2009-06-03 13:32 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-20 07:50 . 2009-05-20 07:50 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-05-20 07:49 . 2009-05-20 07:49 -------- d-----w- c:\windows\system32\wbem\Repository
2009-05-19 18:40 . 2009-05-20 18:16 -------- d-----w- c:\windows\Downloaded Program Files
2009-05-19 16:01 . 2009-05-20 08:22 -------- d-----w- c:\program files\Pothos
2009-05-18 21:56 . 2009-05-18 21:56 -------- d-----w- c:\program files\filehippo.com
2009-05-18 20:37 . 2009-05-30 19:58 -------- d-----w- c:\program files\Wisdom-soft
2009-05-18 20:37 . 2009-05-18 20:37 -------- d-----w- c:\program files\Wisdom-soft ScreenHunter 5 Free
2009-05-18 20:35 . 2009-05-19 16:12 -------- d-----w- c:\program files\ICQ6.5
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 23:07 . 2009-04-30 11:58 -------- d-----w- c:\program files\PeerGuardian2
2009-06-15 19:22 . 2008-12-23 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-15 19:11 . 2009-03-07 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-15 18:56 . 2009-03-17 16:26 -------- d-----w- c:\program files\INŠTALÁCIE
2009-06-15 18:24 . 2008-11-01 15:31 1 ----a-w- c:\documents and settings\PC\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-15 12:00 . 2009-03-13 10:36 -------- d-----w- c:\documents and settings\PC\Application Data\AIMP
2009-06-15 08:37 . 2008-11-01 14:44 196608 ----a-w- c:\windows\system32\drivers\nStandard.bin
2009-06-12 15:53 . 2009-04-25 12:15 -------- d-----w- c:\documents and settings\PC\Application Data\vlc
2009-06-12 15:49 . 2009-04-03 07:37 -------- d-----w- c:\documents and settings\PC\Application Data\DAEMON Tools Lite
2009-06-12 09:30 . 2009-06-12 09:28 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-12 08:28 . 2009-04-22 15:48 -------- d-----w- c:\documents and settings\PC\Application Data\cspa
2009-06-08 13:23 . 2009-05-11 12:42 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-06-08 13:06 . 2009-02-07 14:37 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-08 12:59 . 2009-04-25 12:13 -------- d-----w- c:\program files\VideoLAN
2009-06-03 10:07 . 2008-12-13 19:31 -------- d-----w- c:\program files\iTunes
2009-06-03 10:07 . 2008-11-03 18:05 -------- d-----w- c:\program files\Common Files\Apple
2009-06-03 10:05 . 2008-12-13 19:30 -------- d-----w- c:\program files\QuickTime
2009-06-02 16:24 . 2008-12-23 19:56 -------- d-----w- c:\program files\Google
2009-06-02 16:11 . 2009-06-12 09:28 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-05-30 22:35 . 2008-12-05 16:38 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-30 22:13 . 2008-12-04 17:00 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-05-30 21:01 . 2008-11-22 12:52 -------- d-----w- c:\documents and settings\PC\Application Data\Skype
2009-05-30 20:58 . 2008-11-22 12:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-05-29 21:37 . 2009-06-12 09:28 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-05-29 21:31 . 2009-06-12 09:28 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-05-29 11:36 . 2009-03-12 22:33 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-29 11:36 . 2008-11-03 18:05 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-19 16:12 . 2009-03-23 20:41 -------- d-----w- c:\program files\Laplink Everywhere
2009-05-19 16:11 . 2009-04-24 16:41 -------- d-----w- c:\program files\SpeedBit Video Accelerator
2009-05-19 16:11 . 2009-05-07 22:41 -------- d-----w- c:\program files\QuickMediaConverter
2009-05-19 16:11 . 2009-03-31 08:06 -------- d-----w- c:\program files\Common Files\intervations
2009-05-19 16:11 . 2009-02-21 11:18 -------- d-----w- c:\program files\MP3Gain
2009-05-19 16:11 . 2009-02-12 18:39 -------- d-----w- c:\program files\data
2009-05-19 16:10 . 2009-02-12 20:29 -------- d-----w- c:\program files\Common Files\Common Share
2009-05-19 16:10 . 2008-11-04 14:16 -------- d-----w- c:\documents and settings\PC\Application Data\Zoner
2009-05-19 16:10 . 2008-11-29 12:34 -------- d-----w- c:\documents and settings\PC\Application Data\Corel
2009-05-19 16:10 . 2008-11-26 10:26 -------- d-----w- c:\documents and settings\PC\Application Data\NCH Swift Sound
2009-05-19 16:10 . 2008-11-03 18:06 -------- d-----w- c:\documents and settings\PC\Application Data\Apple Computer
2009-05-19 16:10 . 2008-11-26 10:27 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-05-19 16:09 . 2009-04-26 21:37 -------- d-----w- c:\documents and settings\PC\Application Data\XnView
2009-05-18 20:35 . 2008-11-19 19:18 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2009-05-16 22:43 . 2009-05-16 22:43 -------- d-----w- c:\documents and settings\PC\Application Data\Sproqit Technologies
2009-05-15 14:37 . 2008-11-19 18:29 -------- d-----w- c:\documents and settings\PC\Application Data\Sony
2009-05-15 14:36 . 2009-05-15 14:36 -------- d-----w- c:\program files\Common Files\Sony Shared
2009-05-15 14:36 . 2009-05-15 14:36 -------- d-----w- c:\program files\Sony
2009-05-15 14:36 . 2008-11-04 06:53 -------- d-----w- c:\program files\Sony Ericsson
2009-05-15 14:12 . 2009-05-15 14:12 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeE99C.dll
2009-05-15 14:12 . 2009-05-15 14:12 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeE99C.dll
2009-05-15 14:12 . 2008-11-01 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-14 20:50 . 2009-05-14 20:50 -------- d-----w- c:\documents and settings\PC\Application Data\KC Softwares
2009-05-14 13:49 . 2009-05-14 13:49 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-05-14 13:49 . 2009-05-14 13:49 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-05-14 13:49 . 2009-05-14 13:49 133000 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-05-14 13:47 . 2009-05-14 13:47 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-05-14 13:41 . 2009-05-14 13:41 114472 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-05-13 11:48 . 2009-05-13 11:48 -------- d-----w- c:\program files\Defraggler
2009-05-13 05:15 . 2008-02-12 13:59 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-08 23:16 . 2009-05-08 23:16 -------- d-----w- c:\documents and settings\All Users\Application Data\DFX
2009-05-08 23:16 . 2009-05-08 23:16 -------- d-----w- c:\program files\Common Files\DFX
2009-05-07 22:03 . 2009-05-07 22:03 -------- d-----w- c:\program files\TweakNow PowerPack 2009
2009-05-07 17:34 . 2009-05-07 17:34 -------- d-----w- c:\program files\JlgSolera
2009-05-07 16:57 . 2008-11-26 10:27 -------- d-----w- c:\program files\NCH Software
2009-05-07 16:20 . 2008-11-01 14:56 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-07 15:32 . 2008-02-12 13:58 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 15:02 . 2009-05-07 15:02 12620 ---ha-w- c:\windows\system32\mlfcache.dat
2009-05-05 21:01 . 2009-05-05 21:01 -------- d-----w- c:\documents and settings\PC\Application Data\Red Kawa
2009-05-05 20:59 . 2009-05-05 20:59 -------- d-----w- c:\program files\Red Kawa
2009-05-04 15:42 . 2009-05-04 15:42 -------- d-----w- c:\documents and settings\PC\Application Data\Smart PC Solutions
2009-05-04 15:42 . 2009-05-04 15:42 -------- d-----w- c:\program files\Smart PC Solutions
2009-05-04 12:30 . 2008-11-03 15:33 17088 ----a-w- c:\documents and settings\PC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-04 12:17 . 2009-05-04 12:17 -------- d-----w- c:\program files\Joboshare
2009-05-04 12:07 . 2009-05-04 12:07 -------- d-----w- c:\program files\OpenOffice.org 3
2009-05-04 11:57 . 2009-03-13 10:36 -------- d-----w- c:\program files\AIMP2
2009-05-04 10:33 . 2009-04-15 14:20 -------- d-----w- c:\program files\Raxco
2009-05-04 08:33 . 2009-05-04 08:33 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-05-03 20:39 . 2009-02-18 07:30 2710528 ----a-w- c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe
2009-05-03 20:37 . 2009-02-18 07:28 2285056 ----a-w- c:\windows\system32\TUKernel.exe
2009-05-02 14:53 . 2009-05-02 14:53 -------- d-----w- c:\program files\ImageWalker
2009-05-02 13:12 . 2009-05-02 13:12 -------- d-----w- c:\program files\ClickClean
2009-05-02 12:49 . 2008-12-27 11:41 47360 ----a-w- c:\documents and settings\PC\Application Data\pcouffin.sys
2009-05-02 12:49 . 2008-12-27 11:41 47360 ----a-w- c:\documents and settings\PC\Application Data\pcouffin.sys
2009-05-01 21:02 . 2009-06-12 09:28 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-06-12 09:28 685056 ----a-w- c:\windows\system32\divx.dll
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-29 14:01 . 2009-04-29 14:01 -------- d-----w- c:\program files\Paragon Software
2009-04-29 13:52 . 2008-11-01 20:35 -------- d-----w- c:\program files\Common Files\InstallShield
2009-04-28 18:46 . 2008-11-22 12:53 -------- d-----w- c:\documents and settings\PC\Application Data\skypePM
2009-04-27 23:09 . 2009-04-27 23:09 -------- d-----w- c:\documents and settings\PC\Application Data\FDRLab
2009-04-27 23:01 . 2009-04-27 23:01 -------- d-----w- c:\program files\Free Audio Pack
2009-04-27 22:52 . 2008-11-01 15:16 -------- d-----w- c:\program files\totalcmd
2009-04-27 21:09 . 2008-11-01 14:55 -------- d-----w- c:\program files\Common Files\Ahead
2009-04-27 15:35 . 2009-04-27 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\DynAdvance
2009-04-26 21:51 . 2009-04-26 21:51 -------- d-----w- c:\documents and settings\PC\Application Data\Auslogics
2009-04-26 21:42 . 2009-04-26 21:42 -------- d-----w- c:\program files\DynAdvance
2009-04-25 12:12 . 2009-04-25 12:09 16742799 ----a-w- c:\documents and settings\PC\Application Data\OpenCandy\vlc-0.9.9-win32.exe
2009-04-25 12:09 . 2009-03-30 12:57 -------- d-----w- c:\documents and settings\PC\Application Data\OpenCandy
2009-04-25 12:09 . 2009-04-25 12:09 -------- d-----w- c:\program files\VDOWNLOADER
2009-04-24 17:38 . 2009-04-24 17:38 -------- d-----w- c:\program files\VS Revo Group
2009-04-24 16:41 . 2009-02-12 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2009-04-24 16:34 . 2009-04-24 16:34 50688 ----a-w- c:\windows\system32\wbhelp2.dll
2009-03-28 19:37 . 2009-03-28 17:11 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-15_21.20.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-15 23:08 . 2009-06-15 23:08 16384 c:\windows\temp\Perflib_Perfdata_548.dat
+ 2009-06-15 23:08 . 2009-06-15 23:08 16384 c:\windows\temp\Perflib_Perfdata_210.dat
+ 2009-06-15 23:05 . 2009-06-15 23:04 389120 c:\windows\system32\CF11400.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-02-12 15360]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2009-04-24 2545256]
"Google Desktop"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-05-16 30192]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-23 39408]
"PeerGuardian 2"="c:\program files\PeerGuardian2\pg2.exe" [2007-01-29 1432064]
"HDeck MFC Application"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-16 8491008]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-02-12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"OEXPRESS"=c:\documents and settings\All Users\Application Data\LangSoft\OETRN.EXE
"DAEMON Tools Lite"=c:\program files\DAEMON Tools Lite\daemon.exe
"filehippo.com"="c:\program files\filehippo.com\UpdateChecker.exe" /background
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" silent
"Google Updater"=c:\program files\Google\Google Updater\GoogleUpdater.exe
"FTweakFCleaner"=c:\program files\FCleaner\FCleaner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"ASUSGamerOSD"=c:\program files\ASUS\GamerOSD\GamerOSD.exe
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
"SearchSettings"=c:\program files\Search Settings\SearchSettings.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Laplink Everywhere\\LLServerMain2.exe"=
"c:\\Program Files\\Laplink Everywhere\\WSC.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [29.4.2009 16:02 40368]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14.5.2009 15:47 731840]
R2 ServerProxyService;ServerProxyService;c:\program files\Laplink Everywhere\ServerProxyService.exe [26.8.2005 10:14 131072]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [8.6.2009 15:18 603904]
R2 winShadow;winShadow;c:\program files\Laplink\winShadow\shwSrvc.exe [26.8.2005 11:12 274432]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [1.11.2008 16:20 222976]
S2 gupdate1c9b074adf011ba;Google Update Service (gupdate1c9b074adf011ba);c:\program files\Google\Update\GoogleUpdate.exe [29.3.2009 15:45 133104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [18.3.2009 14:44 13224]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [28.3.2009 21:37 30192]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [15.2.2007 19:48 26624]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PGFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-06-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-23 18:05]
2009-06-15 c:\windows\Tasks\User_Feed_Synchronization-{85C6AB20-180E-4DBB-B8B0-D4674D7D1EEC}.job
- c:\windows\system32\msfeedssync.exe [2009-04-25 02:31]
2009-06-15 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
LSP: c:\progra~1\SPEEDB~2\sblsp.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 01:09
Windows 5.1.2600 Service Pack 3, v.5755 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(788)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CF11400.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\BurnAware Free\nmsaccessu.exe
c:\windows\system32\nvsvc32.exe
.
**************************************************************************
.
Completion time: 2009-06-15 1:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-15 23:11
ComboFix2.txt 2009-06-15 21:22
Pre-Run: 73 424 113 664 bytes free
Post-Run: 6 adresárov, 73 411 153 920 voľných bajtov
331 --- E O F --- 2009-06-10 04:53
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1380 [GMT 2:00]
Running from: c:\documents and settings\PC\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\PC\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
"c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_18be6784.exe"
"c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_294823.exe"
"c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_4ae13d6c.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ICQ6Toolbar
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_18be6784.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_294823.exe
c:\documents and settings\PC\Application Data\Microsoft\Installer\{B435AE22-F62A-4402-A4E5-E612631B92C9}\_4ae13d6c.exe
c:\program files\ICQ6Toolbar\ICQToolBar.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ESIHDRV
-------\Legacy_VIDEOACCELERATORSERVICE
-------\Service_esihdrv
-------\Service_VideoAcceleratorService
((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.
2009-06-15 19:27 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 19:27 . 2009-06-15 19:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 19:27 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 18:56 . 2009-06-15 18:56 -------- d-----w- c:\program files\Trend Micro
2009-06-12 15:49 . 2009-06-12 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-06-12 06:42 . 2009-06-12 06:42 -------- d-----w- c:\windows\Downloaded Installations
2009-06-12 06:33 . 2009-06-12 06:56 -------- d-----w- c:\program files\Wise Registry Cleaner
2009-06-12 06:31 . 2009-06-12 06:31 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\ImTOO Software Studio
2009-06-12 06:30 . 2009-06-12 06:30 -------- d-----w- c:\program files\ImTOO
2009-06-12 06:29 . 2009-06-12 06:30 -------- d-----w- c:\program files\BurnAware Free
2009-06-10 04:26 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 04:26 . 2009-04-30 21:22 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-06-10 04:26 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 04:26 . 2009-04-30 21:22 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-06-08 13:18 . 2009-06-08 13:18 603904 ----a-w- c:\windows\system32\TUProgSt.exe
2009-06-08 13:18 . 2008-12-11 11:31 27904 ----a-w- c:\windows\system32\uxtuneup.dll
2009-06-08 13:18 . 2009-06-08 13:18 360192 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-08 13:02 . 2009-06-08 13:02 -------- d-----w- c:\program files\Opera 10 Beta
2009-06-05 15:19 . 2009-06-05 15:19 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\GHISLER
2009-06-03 13:12 . 2009-06-03 13:12 -------- d-----w- c:\program files\Common Files\Diskeeper Corporation
2009-06-03 13:12 . 2009-06-03 13:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Diskeeper Corporation
2009-06-03 13:12 . 2009-06-03 13:12 -------- d-----w- c:\program files\Diskeeper Corporation
2009-06-03 10:07 . 2009-06-03 10:07 -------- d-----w- c:\program files\iPod
2009-06-03 10:00 . 2009-06-03 10:00 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-02 21:05 . 2009-06-02 21:05 -------- d-----w- c:\documents and settings\PC\Application Data\FTWeak
2009-06-02 21:05 . 2009-06-02 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\FTWeak
2009-06-02 21:05 . 2009-06-02 21:05 -------- d-----w- c:\program files\FCleaner
2009-06-01 13:08 . 2009-06-01 13:08 -------- d-----w- c:\program files\ESET
2009-05-30 22:51 . 2008-02-12 13:59 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-30 22:44 . 2009-05-30 22:44 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\Sony Ericsson
2009-05-30 22:44 . 2009-05-30 22:44 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-05-30 22:40 . 2008-02-12 13:59 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-05-30 22:40 . 2009-05-30 22:40 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-30 21:25 . 2009-06-12 06:43 -------- d-----w- c:\program files\Wise Disk Cleaner
2009-05-30 20:58 . 2009-05-30 20:58 -------- d-----r- c:\program files\Skype
2009-05-29 10:50 . 2009-05-29 10:50 -------- d-----w- c:\windows\Sun
2009-05-28 15:08 . 2009-05-28 15:08 -------- d-----w- c:\program files\CCleaner
2009-05-22 18:41 . 2009-05-22 18:41 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-22 18:34 . 2009-05-22 18:34 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\Apple
2009-05-22 11:16 . 2009-05-22 11:16 -------- d-----w- c:\documents and settings\PC\Application Data\ESET
2009-05-22 10:29 . 2009-05-22 10:31 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-21 21:27 . 2009-05-21 21:27 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Labpixies
2009-05-21 21:27 . 2009-05-21 21:27 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-05-21 05:17 . 2009-06-03 13:32 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-20 07:50 . 2009-05-20 07:50 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-05-20 07:49 . 2009-05-20 07:49 -------- d-----w- c:\windows\system32\wbem\Repository
2009-05-19 18:40 . 2009-05-20 18:16 -------- d-----w- c:\windows\Downloaded Program Files
2009-05-19 16:01 . 2009-05-20 08:22 -------- d-----w- c:\program files\Pothos
2009-05-18 21:56 . 2009-05-18 21:56 -------- d-----w- c:\program files\filehippo.com
2009-05-18 20:37 . 2009-05-30 19:58 -------- d-----w- c:\program files\Wisdom-soft
2009-05-18 20:37 . 2009-05-18 20:37 -------- d-----w- c:\program files\Wisdom-soft ScreenHunter 5 Free
2009-05-18 20:35 . 2009-05-19 16:12 -------- d-----w- c:\program files\ICQ6.5
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 23:07 . 2009-04-30 11:58 -------- d-----w- c:\program files\PeerGuardian2
2009-06-15 19:22 . 2008-12-23 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-15 19:11 . 2009-03-07 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-15 18:56 . 2009-03-17 16:26 -------- d-----w- c:\program files\INŠTALÁCIE
2009-06-15 18:24 . 2008-11-01 15:31 1 ----a-w- c:\documents and settings\PC\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-15 12:00 . 2009-03-13 10:36 -------- d-----w- c:\documents and settings\PC\Application Data\AIMP
2009-06-15 08:37 . 2008-11-01 14:44 196608 ----a-w- c:\windows\system32\drivers\nStandard.bin
2009-06-12 15:53 . 2009-04-25 12:15 -------- d-----w- c:\documents and settings\PC\Application Data\vlc
2009-06-12 15:49 . 2009-04-03 07:37 -------- d-----w- c:\documents and settings\PC\Application Data\DAEMON Tools Lite
2009-06-12 09:30 . 2009-06-12 09:28 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-12 08:28 . 2009-04-22 15:48 -------- d-----w- c:\documents and settings\PC\Application Data\cspa
2009-06-08 13:23 . 2009-05-11 12:42 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-06-08 13:06 . 2009-02-07 14:37 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-08 12:59 . 2009-04-25 12:13 -------- d-----w- c:\program files\VideoLAN
2009-06-03 10:07 . 2008-12-13 19:31 -------- d-----w- c:\program files\iTunes
2009-06-03 10:07 . 2008-11-03 18:05 -------- d-----w- c:\program files\Common Files\Apple
2009-06-03 10:05 . 2008-12-13 19:30 -------- d-----w- c:\program files\QuickTime
2009-06-02 16:24 . 2008-12-23 19:56 -------- d-----w- c:\program files\Google
2009-06-02 16:11 . 2009-06-12 09:28 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-05-30 22:35 . 2008-12-05 16:38 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-30 22:13 . 2008-12-04 17:00 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-05-30 21:01 . 2008-11-22 12:52 -------- d-----w- c:\documents and settings\PC\Application Data\Skype
2009-05-30 20:58 . 2008-11-22 12:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-05-29 21:37 . 2009-06-12 09:28 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-05-29 21:31 . 2009-06-12 09:28 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-05-29 11:36 . 2009-03-12 22:33 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-29 11:36 . 2008-11-03 18:05 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-19 16:12 . 2009-03-23 20:41 -------- d-----w- c:\program files\Laplink Everywhere
2009-05-19 16:11 . 2009-04-24 16:41 -------- d-----w- c:\program files\SpeedBit Video Accelerator
2009-05-19 16:11 . 2009-05-07 22:41 -------- d-----w- c:\program files\QuickMediaConverter
2009-05-19 16:11 . 2009-03-31 08:06 -------- d-----w- c:\program files\Common Files\intervations
2009-05-19 16:11 . 2009-02-21 11:18 -------- d-----w- c:\program files\MP3Gain
2009-05-19 16:11 . 2009-02-12 18:39 -------- d-----w- c:\program files\data
2009-05-19 16:10 . 2009-02-12 20:29 -------- d-----w- c:\program files\Common Files\Common Share
2009-05-19 16:10 . 2008-11-04 14:16 -------- d-----w- c:\documents and settings\PC\Application Data\Zoner
2009-05-19 16:10 . 2008-11-29 12:34 -------- d-----w- c:\documents and settings\PC\Application Data\Corel
2009-05-19 16:10 . 2008-11-26 10:26 -------- d-----w- c:\documents and settings\PC\Application Data\NCH Swift Sound
2009-05-19 16:10 . 2008-11-03 18:06 -------- d-----w- c:\documents and settings\PC\Application Data\Apple Computer
2009-05-19 16:10 . 2008-11-26 10:27 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-05-19 16:09 . 2009-04-26 21:37 -------- d-----w- c:\documents and settings\PC\Application Data\XnView
2009-05-18 20:35 . 2008-11-19 19:18 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2009-05-16 22:43 . 2009-05-16 22:43 -------- d-----w- c:\documents and settings\PC\Application Data\Sproqit Technologies
2009-05-15 14:37 . 2008-11-19 18:29 -------- d-----w- c:\documents and settings\PC\Application Data\Sony
2009-05-15 14:36 . 2009-05-15 14:36 -------- d-----w- c:\program files\Common Files\Sony Shared
2009-05-15 14:36 . 2009-05-15 14:36 -------- d-----w- c:\program files\Sony
2009-05-15 14:36 . 2008-11-04 06:53 -------- d-----w- c:\program files\Sony Ericsson
2009-05-15 14:12 . 2009-05-15 14:12 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeE99C.dll
2009-05-15 14:12 . 2009-05-15 14:12 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeE99C.dll
2009-05-15 14:12 . 2008-11-01 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-14 20:50 . 2009-05-14 20:50 -------- d-----w- c:\documents and settings\PC\Application Data\KC Softwares
2009-05-14 13:49 . 2009-05-14 13:49 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-05-14 13:49 . 2009-05-14 13:49 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-05-14 13:49 . 2009-05-14 13:49 133000 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-05-14 13:47 . 2009-05-14 13:47 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-05-14 13:41 . 2009-05-14 13:41 114472 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-05-13 11:48 . 2009-05-13 11:48 -------- d-----w- c:\program files\Defraggler
2009-05-13 05:15 . 2008-02-12 13:59 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-08 23:16 . 2009-05-08 23:16 -------- d-----w- c:\documents and settings\All Users\Application Data\DFX
2009-05-08 23:16 . 2009-05-08 23:16 -------- d-----w- c:\program files\Common Files\DFX
2009-05-07 22:03 . 2009-05-07 22:03 -------- d-----w- c:\program files\TweakNow PowerPack 2009
2009-05-07 17:34 . 2009-05-07 17:34 -------- d-----w- c:\program files\JlgSolera
2009-05-07 16:57 . 2008-11-26 10:27 -------- d-----w- c:\program files\NCH Software
2009-05-07 16:20 . 2008-11-01 14:56 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-07 15:32 . 2008-02-12 13:58 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 15:02 . 2009-05-07 15:02 12620 ---ha-w- c:\windows\system32\mlfcache.dat
2009-05-05 21:01 . 2009-05-05 21:01 -------- d-----w- c:\documents and settings\PC\Application Data\Red Kawa
2009-05-05 20:59 . 2009-05-05 20:59 -------- d-----w- c:\program files\Red Kawa
2009-05-04 15:42 . 2009-05-04 15:42 -------- d-----w- c:\documents and settings\PC\Application Data\Smart PC Solutions
2009-05-04 15:42 . 2009-05-04 15:42 -------- d-----w- c:\program files\Smart PC Solutions
2009-05-04 12:30 . 2008-11-03 15:33 17088 ----a-w- c:\documents and settings\PC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-04 12:17 . 2009-05-04 12:17 -------- d-----w- c:\program files\Joboshare
2009-05-04 12:07 . 2009-05-04 12:07 -------- d-----w- c:\program files\OpenOffice.org 3
2009-05-04 11:57 . 2009-03-13 10:36 -------- d-----w- c:\program files\AIMP2
2009-05-04 10:33 . 2009-04-15 14:20 -------- d-----w- c:\program files\Raxco
2009-05-04 08:33 . 2009-05-04 08:33 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-05-03 20:39 . 2009-02-18 07:30 2710528 ----a-w- c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe
2009-05-03 20:37 . 2009-02-18 07:28 2285056 ----a-w- c:\windows\system32\TUKernel.exe
2009-05-02 14:53 . 2009-05-02 14:53 -------- d-----w- c:\program files\ImageWalker
2009-05-02 13:12 . 2009-05-02 13:12 -------- d-----w- c:\program files\ClickClean
2009-05-02 12:49 . 2008-12-27 11:41 47360 ----a-w- c:\documents and settings\PC\Application Data\pcouffin.sys
2009-05-02 12:49 . 2008-12-27 11:41 47360 ----a-w- c:\documents and settings\PC\Application Data\pcouffin.sys
2009-05-01 21:02 . 2009-06-12 09:28 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-06-12 09:28 685056 ----a-w- c:\windows\system32\divx.dll
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-29 14:01 . 2009-04-29 14:01 -------- d-----w- c:\program files\Paragon Software
2009-04-29 13:52 . 2008-11-01 20:35 -------- d-----w- c:\program files\Common Files\InstallShield
2009-04-28 18:46 . 2008-11-22 12:53 -------- d-----w- c:\documents and settings\PC\Application Data\skypePM
2009-04-27 23:09 . 2009-04-27 23:09 -------- d-----w- c:\documents and settings\PC\Application Data\FDRLab
2009-04-27 23:01 . 2009-04-27 23:01 -------- d-----w- c:\program files\Free Audio Pack
2009-04-27 22:52 . 2008-11-01 15:16 -------- d-----w- c:\program files\totalcmd
2009-04-27 21:09 . 2008-11-01 14:55 -------- d-----w- c:\program files\Common Files\Ahead
2009-04-27 15:35 . 2009-04-27 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\DynAdvance
2009-04-26 21:51 . 2009-04-26 21:51 -------- d-----w- c:\documents and settings\PC\Application Data\Auslogics
2009-04-26 21:42 . 2009-04-26 21:42 -------- d-----w- c:\program files\DynAdvance
2009-04-25 12:12 . 2009-04-25 12:09 16742799 ----a-w- c:\documents and settings\PC\Application Data\OpenCandy\vlc-0.9.9-win32.exe
2009-04-25 12:09 . 2009-03-30 12:57 -------- d-----w- c:\documents and settings\PC\Application Data\OpenCandy
2009-04-25 12:09 . 2009-04-25 12:09 -------- d-----w- c:\program files\VDOWNLOADER
2009-04-24 17:38 . 2009-04-24 17:38 -------- d-----w- c:\program files\VS Revo Group
2009-04-24 16:41 . 2009-02-12 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2009-04-24 16:34 . 2009-04-24 16:34 50688 ----a-w- c:\windows\system32\wbhelp2.dll
2009-03-28 19:37 . 2009-03-28 17:11 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-15_21.20.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-15 23:08 . 2009-06-15 23:08 16384 c:\windows\temp\Perflib_Perfdata_548.dat
+ 2009-06-15 23:08 . 2009-06-15 23:08 16384 c:\windows\temp\Perflib_Perfdata_210.dat
+ 2009-06-15 23:05 . 2009-06-15 23:04 389120 c:\windows\system32\CF11400.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-02-12 15360]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2009-04-24 2545256]
"Google Desktop"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-05-16 30192]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-23 39408]
"PeerGuardian 2"="c:\program files\PeerGuardian2\pg2.exe" [2007-01-29 1432064]
"HDeck MFC Application"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-16 8491008]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-02-12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"OEXPRESS"=c:\documents and settings\All Users\Application Data\LangSoft\OETRN.EXE
"DAEMON Tools Lite"=c:\program files\DAEMON Tools Lite\daemon.exe
"filehippo.com"="c:\program files\filehippo.com\UpdateChecker.exe" /background
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" silent
"Google Updater"=c:\program files\Google\Google Updater\GoogleUpdater.exe
"FTweakFCleaner"=c:\program files\FCleaner\FCleaner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"ASUSGamerOSD"=c:\program files\ASUS\GamerOSD\GamerOSD.exe
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
"SearchSettings"=c:\program files\Search Settings\SearchSettings.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Laplink Everywhere\\LLServerMain2.exe"=
"c:\\Program Files\\Laplink Everywhere\\WSC.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [29.4.2009 16:02 40368]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14.5.2009 15:47 731840]
R2 ServerProxyService;ServerProxyService;c:\program files\Laplink Everywhere\ServerProxyService.exe [26.8.2005 10:14 131072]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [8.6.2009 15:18 603904]
R2 winShadow;winShadow;c:\program files\Laplink\winShadow\shwSrvc.exe [26.8.2005 11:12 274432]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [1.11.2008 16:20 222976]
S2 gupdate1c9b074adf011ba;Google Update Service (gupdate1c9b074adf011ba);c:\program files\Google\Update\GoogleUpdate.exe [29.3.2009 15:45 133104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [18.3.2009 14:44 13224]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [28.3.2009 21:37 30192]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [15.2.2007 19:48 26624]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PGFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-06-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-23 18:05]
2009-06-15 c:\windows\Tasks\User_Feed_Synchronization-{85C6AB20-180E-4DBB-B8B0-D4674D7D1EEC}.job
- c:\windows\system32\msfeedssync.exe [2009-04-25 02:31]
2009-06-15 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Application Data\LangSoft\WebIE.dll
LSP: c:\progra~1\SPEEDB~2\sblsp.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 01:09
Windows 5.1.2600 Service Pack 3, v.5755 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(788)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CF11400.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\BurnAware Free\nmsaccessu.exe
c:\windows\system32\nvsvc32.exe
.
**************************************************************************
.
Completion time: 2009-06-15 1:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-15 23:11
ComboFix2.txt 2009-06-15 21:22
Pre-Run: 73 424 113 664 bytes free
Post-Run: 6 adresárov, 73 411 153 920 voľných bajtov
331 --- E O F --- 2009-06-10 04:53
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:13:49, on 16.6.2009
Platform: Windows XP SP3, v.5755 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\BurnAware Free\nmsaccessu.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\Laplink Everywhere\ServerProxyService.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Laplink\winShadow\shwSrvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
O4 - HKCU\..\Run: [Google Desktop] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [PeerGuardian 2] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [HDeck MFC Application] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7316118328
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c9b074adf011ba) (gupdate1c9b074adf011ba) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\BurnAware Free\nmsaccessu.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServerProxyService - Unknown owner - C:\Program Files\Laplink Everywhere\ServerProxyService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: winShadow - OmniCom Technologies - C:\Program Files\Laplink\winShadow\shwSrvc.exe
--
End of file - 10346 bytes
Scan saved at 1:13:49, on 16.6.2009
Platform: Windows XP SP3, v.5755 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\BurnAware Free\nmsaccessu.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\Laplink Everywhere\ServerProxyService.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Laplink\winShadow\shwSrvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
O4 - HKCU\..\Run: [Google Desktop] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [PeerGuardian 2] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [HDeck MFC Application] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Application Data\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7316118328
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c9b074adf011ba) (gupdate1c9b074adf011ba) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\BurnAware Free\nmsaccessu.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServerProxyService - Unknown owner - C:\Program Files\Laplink Everywhere\ServerProxyService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: winShadow - OmniCom Technologies - C:\Program Files\Laplink\winShadow\shwSrvc.exe
--
End of file - 10346 bytes
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Stáhni si LSPFix .
Návod je tady: http://cexx.org/lspfix.htm (originál)
Knihovnu sblsp.dll by měl označit jako špatnou, přesuň jí do prava a pak Finish.
Návod je tady: http://cexx.org/lspfix.htm (originál)
Toto je nástroj na odstraňování knihoven (.dll) ktere jsou připojeny na vrstvu Winsock. V logu z HJT jsou oznacovany jako O10.
Nejprve si stáhněte program LSP-Fix . Poté program spusťte a zaškrtněte volbu I know what I'm doing poté kliknutím myši v seznamu KEPP vyberte knihovnu kterou chcete odstranit a pomocí tlačítka >> jí přesunete do seznamu knihoven které budou odstraněny (REMOVE). Tlačítkem << ji můžete případně vrátit zpět. Pokud máte seznamy upraveny tak jak potřebujete klikněte na tlačítko Finish.
Knihovnu sblsp.dll by měl označit jako špatnou, přesuň jí do prava a pak Finish.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Program som spustil. Výsledok: No problems found. Pri tej sblsp.dll je (protocol handler), ale je to aj pri druhej, tak teraz neviem či mám tú sblsp.dll vymazať, keď program ukazuje, že no problem?
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Knihovna by měla být snad pro SpeedBit Video Akcelerátor. V umístění Program Files.
Je ještě řešení. Měl by to opravit (pokud je to chyba) Spybot S+D. Stáhni si tedy Spybot, nainstaluj ho a spusť ho. Pokud to odstraní, je to v pořádku, pokud ne, je to taky v pořádku.
Jinak tam problém není.
Odinstaluj ComboFix.
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix[mezera]/u
takže jestli nejsou problémy,tak vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,SDFixu,Avengeru,MWAVu atd.-stáhneš->spustíš
(pozn.Pokud máš AVG, před stažením T-Cleaneru a po dobu čištění deaktivuj AVG, následně T-Cleaner smaž
a zapni si AVG.)
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni select all found, pak klik empty selected.
Pokud chceš zachovat svoje uložená hesla, klikni na No.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache,
cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer,
Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Je ještě řešení. Měl by to opravit (pokud je to chyba) Spybot S+D. Stáhni si tedy Spybot, nainstaluj ho a spusť ho. Pokud to odstraní, je to v pořádku, pokud ne, je to taky v pořádku.
Jinak tam problém není.
Odinstaluj ComboFix.
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix[mezera]/u
takže jestli nejsou problémy,tak vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,SDFixu,Avengeru,MWAVu atd.-stáhneš->spustíš
(pozn.Pokud máš AVG, před stažením T-Cleaneru a po dobu čištění deaktivuj AVG, následně T-Cleaner smaž
a zapni si AVG.)
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni select all found, pak klik empty selected.
Pokud chceš zachovat svoje uložená hesla, klikni na No.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache,
cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer,
Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: Prosím o kontrolu logu, sekanie a spomalenie PC
Spybot mám nainštalovaný stále, takže zajtra ho spustím a ráno dočistím všetko. Ďakujem veľmi pekne za čas strávený som mnou pri PC a za veľkú pomoc.PC už ide tak ako predtým(rýchlo).Pozrel som si tvoju fotku a zdá sa mi, že sme možno aj vekovo na tom rovnako, ja 38. Dobrú noc.
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Prosím o kontrolu logu, sekanie a spomalenie PC Vyřešeno
A pokud máš příbuzný v ZM tak si připrav na léto k Mníchovy velký peníze
a nebo do Nitry pod Zobor




Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 86 hostů