Internet jde jenom v nouzovém režimu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
El Bunda
Level 2.5
Level 2.5
Příspěvky: 292
Registrován: leden 08
Pohlaví: Nespecifikováno
Stav:
Offline

Internet jde jenom v nouzovém režimu

Příspěvekod El Bunda » 01 úno 2010 15:58

Zdravím,
bratránkův počítač se chová poměrně divně. Nejdříve přestal fungovat internet. Brátránek PC spustil v Nouzovém režimu a vše fungovalo normálně (ovšem v Normálním řežimu ne). Tak jsem naklusal já a přeinstaloval jsem mu ovladače od síťovky. Několik hodin to fungovalo a teď to zase jde jenom přes Nouzový režim. Tak vám tedy posílám log na kontrolu. Díky.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:56:51, on 1.2.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\PC\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 208.180.60.126:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_1.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_1.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_1.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Google Update] "C:\Users\PC\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe

--
End of file - 6342 bytes
Ahh the internet... where no means yes and yes means anal.

Reklama
Uživatelský avatar
El Bunda
Level 2.5
Level 2.5
Příspěvky: 292
Registrován: leden 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Internet jde jenom v nouzovém režimu

Příspěvekod El Bunda » 01 úno 2010 17:08

Combofix:

ComboFix 10-01-31.05 - PC 01.02.2010 17:01:59.1.2 - x86 NETWORK
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.1023.627 [GMT 1:00]
Spuštěný z: c:\users\PC\Desktop\ComboFix.exe
SP: Spyware Terminator *enabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ICQ6.5\ICQLRun.exe
c:\users\PC\AppData\Roaming\Desktopicon
c:\users\PC\AppData\Roaming\Desktopicon\eBayShortcuts.exe
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\twain_32.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-01 do 2010-02-01 )))))))))))))))))))))))))))))))
.

2010-02-01 16:06 . 2010-02-01 16:06 -------- d-----w- c:\users\PC\AppData\Local\temp
2010-02-01 16:06 . 2010-02-01 16:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-01 15:38 . 2006-08-21 10:24 363008 ----a-w- c:\windows\system32\idecoiins.dll
2010-02-01 15:38 . 2006-08-21 10:24 363008 ----a-w- c:\windows\system32\idecoi.dll
2010-02-01 15:38 . 2006-08-21 10:24 105344 ----a-w- c:\windows\system32\drivers\nvata.sys
2010-02-01 15:38 . 2006-08-18 02:28 35840 ----a-w- c:\windows\system32\NVCOI.DLL
2010-02-01 15:37 . 2009-04-28 23:46 143360 ----a-w- c:\windows\system32\nvconrm.dll
2010-02-01 15:37 . 2006-09-11 11:45 19968 ----a-w- c:\windows\system32\drivers\nvnetbus.sys
2010-02-01 15:37 . 2006-09-11 11:45 110592 ----a-w- c:\windows\system32\drivers\nvtcp.sys
2010-02-01 15:37 . 2006-09-11 11:45 1161088 ----a-w- c:\windows\system32\drivers\nvnrm.sys
2010-02-01 15:37 . 2006-09-11 11:43 11264 ----a-w- c:\windows\system32\bdco1ins.dll
2010-02-01 15:37 . 2006-09-11 11:43 11264 ----a-w- c:\windows\system32\bdco1.dll
2010-02-01 15:37 . 2006-09-11 11:44 261632 ----a-w- c:\windows\system32\drivers\nvsnpu.sys
2010-02-01 15:13 . 2010-02-01 15:13 -------- d-----w- c:\program files\ToniArts
2010-01-29 09:51 . 2009-04-30 11:46 704512 ----a-w- c:\windows\system32\cohelper.dll
2010-01-29 09:51 . 2006-08-14 04:09 1428 ----a-r- c:\windows\system32\drivers\nvphy.bin
2010-01-28 16:18 . 2010-02-01 15:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-28 16:16 . 2010-01-28 16:16 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-28 15:23 . 2010-01-21 16:12 52224 ----a-w- c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\j7riojd6.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\FFExternalAlert.dll
2010-01-28 15:23 . 2010-01-21 16:12 101376 ----a-w- c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\j7riojd6.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.dll
2010-01-25 13:37 . 2010-01-25 13:37 500 ----a-w- c:\windows\eReg.dat
2010-01-25 13:37 . 1999-04-02 15:37 33792 ----a-r- c:\windows\NPSExec.exe
2010-01-25 13:37 . 1997-01-22 21:26 565760 ----a-r- c:\windows\system32\MSVCP50.DLL
2010-01-25 13:37 . 2010-01-25 13:37 -------- d-----w- c:\program files\Electronic Arts
2010-01-25 13:35 . 2010-01-25 13:35 -------- d-----w- c:\program files\Maxis
2010-01-23 18:33 . 2010-01-23 18:33 -------- d-----w- c:\users\PC\AppData\Local\Adobe
2010-01-23 18:32 . 2010-01-23 18:32 -------- d-----w- c:\programdata\FLEXnet
2010-01-22 19:31 . 2009-12-19 09:02 977920 ----a-w- c:\windows\system32\wininet.dll
2010-01-22 15:47 . 2010-01-22 16:06 -------- d-----w- c:\users\PC\AppData\Roaming\IObit
2010-01-22 15:47 . 2010-01-22 15:47 -------- d-----w- c:\program files\IObit
2010-01-19 17:20 . 2009-07-30 01:36 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-01-19 17:20 . 2010-01-22 14:48 -------- d-----w- C:\NVIDIA
2010-01-19 16:36 . 2010-01-19 16:56 -------- d-----w- c:\program files\Lavalys
2010-01-17 10:37 . 2010-01-17 10:37 4726 ----a-w- C:\cc_20100117_113703.reg
2010-01-17 10:23 . 2010-01-17 10:23 -------- d-----w- c:\program files\Bonjour
2010-01-17 10:16 . 2010-01-17 10:16 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-01-17 10:14 . 2010-01-17 10:23 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-14 15:47 . 2010-01-14 15:52 -------- d-----w- c:\users\PC\AppData\Roaming\TuxPaint
2010-01-14 15:47 . 2010-01-17 11:36 -------- d-----w- c:\program files\TuxPaint
2010-01-13 09:52 . 2009-10-19 14:10 108544 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 09:52 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-01-08 11:51 . 2010-01-08 11:51 -------- d-----w- c:\program files\MultiScreen
2010-01-08 11:42 . 2008-06-24 12:45 1414440 ----a-w- c:\windows\system32\ShellManager310E2D762.dll
2010-01-08 11:34 . 2010-01-08 11:34 -------- d-----w- c:\program files\EA Sports
2010-01-08 11:33 . 1998-10-29 16:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-01-07 19:13 . 2010-01-07 19:13 -------- d-----w- c:\program files\TeamViewer
2010-01-07 19:09 . 2010-01-07 19:09 -------- d-----w- c:\program files\QS
2010-01-07 19:08 . 2010-01-22 16:03 -------- d-----w- c:\users\PC\AppData\Roaming\TeamViewer
2010-01-07 19:08 . 2010-01-07 19:08 -------- d-----w- c:\users\PC\temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 16:06 . 2009-09-27 22:12 -------- d-----w- c:\program files\ICQ6.5
2010-02-01 15:47 . 2009-07-27 20:22 613484 ----a-w- c:\windows\system32\perfh005.dat
2010-02-01 15:47 . 2009-07-27 20:22 115784 ----a-w- c:\windows\system32\perfc005.dat
2010-02-01 06:28 . 2009-09-27 22:46 -------- d-----w- c:\users\PC\AppData\Roaming\Spyware Terminator
2010-01-22 16:03 . 2009-09-29 12:17 -------- d-----w- c:\users\PC\AppData\Roaming\Vso
2010-01-22 16:03 . 2009-11-07 16:32 -------- d-----w- c:\program files\MotoGP2 Demo
2010-01-22 16:03 . 2009-10-18 13:13 -------- d-----w- c:\program files\VirtualDJ
2010-01-22 16:03 . 2009-10-10 19:36 -------- d-----w- c:\program files\BS_Player
2010-01-22 16:02 . 2009-10-31 21:17 -------- d-----w- c:\users\PC\AppData\Roaming\uTorrent
2010-01-17 12:14 . 2009-12-25 14:00 -------- d-----w- c:\users\PC\AppData\Roaming\vlc
2010-01-17 12:12 . 2009-09-27 21:30 109984 ----a-w- c:\users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-17 06:53 . 2009-09-27 22:46 -------- d-----w- c:\programdata\Spyware Terminator
2010-01-14 10:12 . 2009-10-03 09:35 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-08 11:43 . 2009-11-19 20:51 -------- d-----w- c:\program files\Common Files\Nero
2010-01-08 11:43 . 2009-11-19 20:51 -------- d-----w- c:\programdata\Nero
2010-01-08 11:37 . 2009-11-07 16:14 -------- d-----w- c:\program files\GameSpy Arcade
2010-01-08 11:36 . 2009-10-31 21:17 -------- d-----w- c:\program files\uTorrent
2010-01-05 17:15 . 2009-09-27 22:15 -------- d-----w- c:\users\PC\AppData\Roaming\ICQ
2009-12-26 14:35 . 2009-12-25 16:05 -------- d-----w- c:\users\PC\AppData\Roaming\dvdcss
2009-12-25 13:52 . 2009-12-25 13:52 -------- d-----w- c:\program files\VideoLAN
2009-12-23 18:59 . 2009-10-10 14:52 -------- d-----w- c:\users\PC\AppData\Roaming\Nero
2009-12-23 18:50 . 2009-11-19 20:51 -------- d-----w- c:\program files\Nero
2009-12-22 08:08 . 2009-11-26 17:59 -------- d-----w- c:\program files\Google
2009-12-11 20:26 . 2009-12-11 20:26 532480 ----a-w- c:\windows\system32\Rocky Title SS.scr
2009-12-11 20:25 . 2009-12-11 20:25 532480 ----a-w- c:\windows\system32\Rocky1 Workout.scr
2009-12-11 20:02 . 2009-12-11 20:02 532480 ----a-w- c:\windows\system32\Rocky Balboa Title SS.scr
2009-12-07 19:46 . 2009-09-27 22:03 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_1.dll" [2010-01-08 2166296]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-01-08 20:27 2166296 ----a-w- c:\program files\BS_Player\tbBS_1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_1.dll" [2010-01-08 2166296]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_1.dll" [2010-01-08 2166296]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-11-21 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-09-27 2173440]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

c:\users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave2"=wdmaud.drv

S1 CXAVSAUD;Prolink 2388x Audio Capture;c:\windows\System32\drivers\pvavsaud.sys [25.10.2005 8:56 11008]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [27.9.2009 23:46 142592]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [16.5.2009 4:23 176128]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [27.9.2009 23:03 108289]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [26.11.2009 18:59 135664]
S2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [25.6.2009 8:22 185640]
.
Obsah adresáře 'Naplánované úlohy'

2010-02-01 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-01-22 14:33]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-26 17:59]

2010-01-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-26 17:59]

2010-01-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-590774779-2709692406-2949326145-1001Core.job
- c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-21 22:16]

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-590774779-2709692406-2949326145-1001UA.job
- c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-21 22:16]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com?SearchSource= ... =CT1750559
uInternet Settings,ProxyServer = 208.180.60.126:8080
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\j7riojd6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://szn.cz/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 1750559&q=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\users\PC\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\program files\AskBarDis\bar\bin\askBar.dll
HKLM-RunOnce-<NO NAME> - (no file)


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-02-01 17:07:57
ComboFix-quarantined-files.txt 2010-02-01 16:07

Před spuštěním: 7 027 163 136
Po spuštění: 6 927 945 728

- - End Of File - - ED973C63CD780C9CB36CB1768381B51E
Ahh the internet... where no means yes and yes means anal.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 80 hostů