Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
AsiStarnu
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 11 říj 2008 11:19

Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#1 Příspěvek od AsiStarnu »

Dobry den,
chtel bych pozadat o kontrolu PC.
Jedna se o PC me matky, u ktery byl nalezen vir Win32:Hupigon-ONX [Trj] po spuštění antivir u AVAST po restaru.
Infikován byl soubor hiberfil.sys, ale nešel přesunout do truhly, smazat ani vyléčit :-)
Nyní, cca po 7 dnech jsem spustil pes SKYPE - sdilenou obrazovku a "poradil" doma jak postupovat při stažení a spuštění programu HijackThis.
Vygeneroval se log, který zasílám ke kontrole.

Díky za info.

*-*-*-*-*
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:54:49, on 7.1.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Hit\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{13320E7A-5E7E-41AB-AA29-4B6C8C2464FE}: NameServer = 194.228.41.65,194.228.41.113
O17 - HKLM\System\CS1\Services\Tcpip\..\{13320E7A-5E7E-41AB-AA29-4B6C8C2464FE}: NameServer = 194.228.41.65,194.228.41.113
O17 - HKLM\System\CS4\Services\Tcpip\..\{13320E7A-5E7E-41AB-AA29-4B6C8C2464FE}: NameServer = 194.228.41.65,194.228.41.113
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SWIHPWMI - Sierra Wireless Inc. - c:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe

--
End of file - 5836 bytes
*-*-*-*-*

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#2 Příspěvek od JaRon »

tak uvod mas za sebou :) a teraz log RSIT
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

AsiStarnu
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 11 říj 2008 11:19

Re: Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#3 Příspěvek od AsiStarnu »

:-)

Logfile of random's system information tool 1.09 (written by random/random)
Run by mam at 2013-01-07 14:24:58
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 20 GB (57%) free of 35 GB
Total RAM: 2039 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:25:01, on 7.1.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\mam\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\mam.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{13320E7A-5E7E-41AB-AA29-4B6C8C2464FE}: NameServer = 194.228.41.65,194.228.41.113
O17 - HKLM\System\CS1\Services\Tcpip\..\{13320E7A-5E7E-41AB-AA29-4B6C8C2464FE}: NameServer = 194.228.41.65,194.228.41.113
O17 - HKLM\System\CS4\Services\Tcpip\..\{13320E7A-5E7E-41AB-AA29-4B6C8C2464FE}: NameServer = 194.228.41.65,194.228.41.113
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SWIHPWMI - Sierra Wireless Inc. - c:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe

--
End of file - 6181 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\WGASetup.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\mam\Data aplikací\Mozilla\Firefox\Profiles\qmlhcgvx.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-11-20 488752]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-01-18 1028096]
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe [2009-07-16 141848]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe [2009-07-16 166424]
"Persistence"=C:\WINDOWS\System32\igfxpers.exe [2009-07-16 137752]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2006-02-22 40960]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2005-12-12 88203]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-10-19 177456]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-01-05 872448]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2009-07-06 208896]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\Documents and Settings\mam\Local Settings\Data aplikací\CrossLoop\vncviewer.exe"="C:\Documents and Settings\mam\Local Settings\Data aplikací\CrossLoop\vncviewer.exe:*:Enabled:vncviewer.exe"
"C:\Documents and Settings\mam\Local Settings\Data aplikací\CrossLoop\tvnserver.exe"="C:\Documents and Settings\mam\Local Settings\Data aplikací\CrossLoop\tvnserver.exe:*:Enabled:tvnserver.exe"
"C:\Documents and Settings\mam\Local Settings\Data aplikací\CrossLoop\CrossLoopConnect.exe"="C:\Documents and Settings\mam\Local Settings\Data aplikací\CrossLoop\CrossLoopConnect.exe:*:Enabled:CrossLoop - Simple Secure Screen Sharing"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======List of files/folders created in the last 1 month======

2013-01-07 14:24:58 ----D---- C:\rsit
2013-01-07 14:24:58 ----D---- C:\Program Files\trend micro
2013-01-07 13:49:59 ----D---- C:\Hit
2013-01-06 07:03:09 ----D---- C:\Documents and Settings\mam\Data aplikací\OpenOffice.org
2012-12-29 18:49:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2012-12-29 18:48:57 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2012-12-29 18:43:22 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2012-12-29 18:41:15 ----SHD---- C:\Config.Msi
2012-12-28 22:24:43 ----D---- C:\Program Files\Common Files\Adobe
2012-12-28 22:24:43 ----D---- C:\Program Files\Adobe
2012-12-28 22:23:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-12-28 20:59:10 ----D---- C:\Documents and Settings\mam\Data aplikací\vlc
2012-12-28 20:58:20 ----D---- C:\Program Files\VideoLAN
2012-12-28 15:32:56 ----D---- C:\WINDOWS\system32\XPSViewer
2012-12-28 15:32:51 ----D---- C:\Program Files\MSBuild
2012-12-28 15:32:50 ----D---- C:\WINDOWS\system32\en-US
2012-12-28 15:32:42 ----D---- C:\Program Files\Reference Assemblies
2012-12-28 15:32:07 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2012-12-28 15:32:07 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2012-12-28 15:32:07 ----N---- C:\WINDOWS\system32\prntvpt.dll
2012-12-28 15:27:05 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-12-28 15:26:52 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-12-28 15:26:41 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-12-28 15:24:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2012-12-28 15:24:26 ----D---- C:\WINDOWS\ie8updates
2012-12-28 15:24:08 ----D---- C:\WINDOWS\WBEM
2012-12-28 15:22:54 ----HDC---- C:\WINDOWS\ie8
2012-12-28 15:18:59 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2012-12-28 15:18:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2012-12-28 15:18:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2012-12-28 15:18:38 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-12-28 15:18:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2012-12-28 15:18:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-12-28 15:18:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2012-12-28 15:18:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2012-12-28 15:18:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2012-12-28 15:17:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2012-12-28 15:17:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2012-12-28 15:17:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2646524$
2012-12-28 15:17:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2779030$
2012-12-28 15:17:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2012-12-28 15:17:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2012-12-28 15:17:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2012-12-28 15:17:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2012-12-28 15:17:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2012-12-28 15:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2012-12-28 15:16:48 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-12-28 15:16:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2779562$
2012-12-28 15:16:40 ----D---- C:\WINDOWS\system32\KB905474
2012-12-28 15:16:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2012-12-28 15:16:22 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-12-28 15:16:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2012-12-28 15:16:09 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-12-28 15:16:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2012-12-28 15:15:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2012-12-28 15:15:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2724197$
2012-12-28 15:15:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-12-28 15:15:34 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-12-28 15:15:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2012-12-28 15:15:22 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2012-12-28 15:15:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2012-12-28 15:15:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2012-12-28 15:15:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2012-12-28 15:14:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2736233$
2012-12-28 15:14:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-12-28 15:14:42 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2012-12-28 15:14:37 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-12-28 15:14:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-12-28 15:14:25 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2012-12-28 15:14:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2012-12-28 15:14:14 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-12-28 15:14:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2510581$
2012-12-28 15:14:02 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2012-12-28 15:13:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2012-12-28 15:13:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-12-28 15:13:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-12-28 15:13:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2012-12-28 15:13:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-12-28 15:13:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2012-12-28 15:13:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2624667$
2012-12-28 15:13:04 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2012-12-28 15:12:59 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-12-28 15:12:53 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-12-28 15:12:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2012-12-28 15:12:38 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-12-28 15:12:33 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-12-28 15:12:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2012-12-28 15:12:21 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-12-28 15:12:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2753842-v2$
2012-12-28 15:12:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-12-28 15:12:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2012-12-28 15:11:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2761465$
2012-12-28 15:11:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2012-12-28 15:11:35 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2012-12-28 15:11:30 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-12-28 15:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2012-12-28 15:11:19 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2012-12-28 15:11:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-12-28 15:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2012-12-28 15:11:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2012-12-28 15:10:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2012-12-28 15:10:50 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2012-12-28 15:10:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2012-12-28 15:10:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2012-12-28 15:10:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2012-12-28 15:10:26 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-12-28 15:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2012-12-28 15:10:10 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2012-12-28 15:10:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2012-12-28 15:09:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2012-12-28 15:09:51 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-12-28 15:09:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2012-12-28 15:09:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2012-12-28 15:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2012-12-28 15:09:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-12-28 15:09:22 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-12-28 15:09:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2012-12-28 15:09:11 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-12-28 15:09:06 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-12-28 15:09:00 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2012-12-28 15:08:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2012-12-28 15:08:50 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-12-28 15:08:45 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-12-28 15:08:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2618451$
2012-12-28 15:08:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2661254-v2$
2012-12-28 15:08:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-12-28 15:08:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2012-12-28 15:08:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2012-12-28 15:07:58 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2012-12-28 15:07:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2544521$
2012-12-28 15:07:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2012-12-28 15:07:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2012-12-28 15:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-12-28 15:07:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2012-12-28 15:07:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2012-12-28 15:07:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2012-12-28 15:07:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2012-12-28 15:06:05 ----A---- C:\WINDOWS\system32\MRT.exe
2012-12-28 15:05:55 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-12-28 15:05:47 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-12-28 15:05:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2012-12-28 15:05:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2012-12-28 14:53:05 ----N---- C:\WINDOWS\system32\browserchoice.exe
2012-12-28 14:47:12 ----N---- C:\WINDOWS\system32\iacenc.dll
2012-12-28 14:43:22 ----D---- C:\WINDOWS\system32\PreInstall
2012-12-28 14:43:20 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2012-12-28 14:43:20 ----HD---- C:\WINDOWS\$hf_mig$
2012-12-28 14:41:39 ----D---- C:\Documents and Settings\mam\Data aplikací\TightVNC
2012-12-28 13:44:25 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2012-12-28 13:29:34 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2012-12-28 13:29:31 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys
2012-12-28 09:18:20 ----D---- C:\Documents and Settings\mam\Data aplikací\Macromedia
2012-12-28 09:18:19 ----D---- C:\Documents and Settings\mam\Data aplikací\Adobe
2012-12-28 09:17:55 ----A---- C:\WINDOWS\system32\drivers\MSTEE.sys
2012-12-28 09:17:51 ----A---- C:\WINDOWS\system32\drivers\NdisIP.sys
2012-12-28 09:17:49 ----A---- C:\WINDOWS\system32\drivers\StreamIP.sys
2012-12-28 09:17:47 ----A---- C:\WINDOWS\system32\drivers\SLIP.sys
2012-12-28 09:17:45 ----A---- C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2012-12-28 09:17:43 ----A---- C:\WINDOWS\system32\drivers\NABTSFEC.sys
2012-12-28 09:17:41 ----A---- C:\WINDOWS\system32\drivers\CCDECODE.sys
2012-12-28 09:17:35 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2012-12-28 09:17:31 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2012-12-28 09:14:57 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-12-12 12:27:55 ----A---- C:\WINDOWS\WININIT.INI
2012-12-12 12:27:39 ----D---- C:\Program Files\Sonic
2012-12-12 12:27:33 ----D---- C:\Program Files\Common Files\Sonic Shared

======List of files/folders modified in the last 1 month======

2013-01-07 14:24:58 ----RD---- C:\Program Files
2013-01-07 14:19:26 ----D---- C:\Documents and Settings\mam\Data aplikací\Skype
2013-01-07 13:53:49 ----D---- C:\WINDOWS\Temp
2013-01-07 13:16:21 ----SD---- C:\WINDOWS\Tasks
2013-01-07 08:55:31 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-01-06 07:03:08 ----D---- C:\WINDOWS\Prefetch
2013-01-05 14:45:09 ----D---- C:\WINDOWS\system32
2013-01-05 14:45:09 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-12-30 23:23:39 ----D---- C:\WINDOWS\system32\CatRoot2
2012-12-30 23:15:55 ----HD---- C:\WINDOWS\inf
2012-12-30 23:15:55 ----D---- C:\WINDOWS
2012-12-29 19:39:41 ----RSD---- C:\WINDOWS\assembly
2012-12-29 19:38:59 ----D---- C:\WINDOWS\Microsoft.NET
2012-12-29 18:49:37 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-12-29 18:49:30 ----SHD---- C:\WINDOWS\Installer
2012-12-29 18:48:59 ----D---- C:\WINDOWS\system32\drivers
2012-12-29 18:47:57 ----D---- C:\WINDOWS\WinSxS
2012-12-29 18:45:21 ----D---- C:\WINDOWS\system32\CatRoot
2012-12-28 23:17:28 ----D---- C:\WINDOWS\Debug
2012-12-28 22:25:32 ----SD---- C:\Documents and Settings\mam\Data aplikací\Microsoft
2012-12-28 22:24:43 ----D---- C:\Program Files\Common Files
2012-12-28 20:04:55 ----D---- C:\WINDOWS\system32\cs-cz
2012-12-28 20:04:55 ----D---- C:\WINDOWS\Help
2012-12-28 20:04:55 ----D---- C:\Program Files\Internet Explorer
2012-12-28 20:04:54 ----D---- C:\WINDOWS\system32\wbem
2012-12-28 20:04:54 ----D---- C:\WINDOWS\AppPatch
2012-12-28 15:32:47 ----RSD---- C:\WINDOWS\Fonts
2012-12-28 15:32:18 ----D---- C:\WINDOWS\system32\spool
2012-12-28 15:30:34 ----D---- C:\WINDOWS\system32\mui
2012-12-28 15:24:10 ----D---- C:\WINDOWS\system32\config
2012-12-28 15:23:57 ----D---- C:\WINDOWS\Media
2012-12-28 15:19:01 ----D---- C:\Program Files\Messenger
2012-12-28 15:09:29 ----D---- C:\Program Files\Outlook Express
2012-12-28 15:09:03 ----D---- C:\Program Files\Movie Maker
2012-12-28 14:35:07 ----D---- C:\Program Files\CCleaner
2012-12-28 13:44:32 ----D---- C:\WINDOWS\SoftwareDistribution
2012-12-28 13:44:28 ----HD---- C:\Program Files\WindowsUpdate
2012-12-16 13:23:59 ----A---- C:\WINDOWS\system32\atmfd.dll
2012-12-12 12:45:00 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-12-12 12:28:35 ----D---- C:\SWSetup
2012-12-12 11:20:20 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdis;avast! Firewall NDIS Filter Service; C:\WINDOWS\system32\DRIVERS\aswNdis.sys [2012-09-21 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\WINDOWS\system32\drivers\aswNdis2.sys [2012-10-30 199320]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-04-25 20640]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-10-30 25256]
R1 aswFW;avast! TDI Firewall driver; C:\WINDOWS\system32\drivers\aswFW.sys [2012-10-30 106560]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2012-10-30 20624]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\AswRdr.sys [2012-10-30 35928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-10-30 738504]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-10-30 361032]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-30 54232]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-10-30 21256]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-10-30 97608]
R2 irda;Protokol IrDA; C:\WINDOWS\System32\DRIVERS\irda.sys [2008-04-14 88192]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-10-01 281600]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-12-12 1120352]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\WINDOWS\system32\DRIVERS\ATSwpDrv.sys [2007-08-28 146560]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2005-10-26 142720]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [2012-12-06 1123328]
R3 GTIPCI21;GTIPCI21; C:\WINDOWS\System32\DRIVERS\gtipci21.sys [2007-05-09 97280]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\igxpmp32.sys [2009-07-06 5854752]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 sdbus;sdbus; C:\WINDOWS\System32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\System32\DRIVERS\smcirda.sys [2001-10-24 35913]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\System32\DRIVERS\SynTP.sys [2008-01-18 220640]
R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2007-12-14 290816]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\System32\PCTINDIS5.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SWIHPWMI;SWIHPWMI; c:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [2006-09-22 280096]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe [2007-11-29 144688]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-29 115168]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#4 Příspěvek od JaRon »

citat kolegu:
Pokud vypneš "Podporu režimu spánku" v Ovládací panely -> Možnosti napájení -> Režim spánku ...
bude systémem rezervované místo na disku uvolněno a soubor "hiberfil.sys" zmizí - po vyčištění disku a defragmentaci můžeš opět "Podporu režimu spánku" zapnout - určitě už v ní žádná bleška nebude
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

AsiStarnu
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 11 říj 2008 11:19

Re: Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#5 Příspěvek od AsiStarnu »

jak prosté :-), instrukce jsem dal dál ...
tedy jednalo se vlastně o trojana, nebo co vlastně je ta blecha :-).

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#6 Příspěvek od JaRon »

som mierne na pochybnostiach, ci vobec o nejaku nakazu islo ,,, mozno falosny poplach
navod kolegu cernohousa zabezpeci, ze "vsetko je ako ma byt = 100% ciste"
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

AsiStarnu
Návštěvník
Návštěvník
Příspěvky: 45
Registrován: 11 říj 2008 11:19

Re: Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#7 Příspěvek od AsiStarnu »

... tak antivir po restartu nenašel žádný problém. :)
Díky moc za rady!

Pěkný den.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Prosím o kontrolu - nalezen Win32:Hupigon-ONX [Trj]

#8 Příspěvek od JaRon »

aj za kolegu: radi sme pomohli :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Zamčeno