Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Jarda62
Návštěvník
Návštěvník
Příspěvky: 170
Registrován: 28 črc 2008 17:59

Prosím o kontrolu

#1 Příspěvek od Jarda62 »

Logfile of random's system information tool 1.06 (written by random/random)
Run by Jarda62 at 2010-01-16 11:58:57
Microsoft Windows 7 Home Premium Service Pack 3
System drive C: has 22 GB (53%) free of 41 GB
Total RAM: 2038 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:59:04, on 16.1.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Windows\system32\svchost.exe
D:\QIP Infium\infium.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jarda62\Desktop\RSIT.exe
C:\Program Files\trend micro\Jarda62.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.1.0.19\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [seafi] C:\Users\Jarda62\seafi.exe
O4 - HKCU\..\Run: [Infium] "D:\QIP Infium\infium.exe" /isolated /autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm (file missing)
O9 - Extra 'Tools' menuitem: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe

--
End of file - 4516 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll [2009-10-29 392560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\17.1.0.19\IPSBHO.DLL [2009-10-01 79224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-07 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\17.1.0.19\coIEPlg.dll [2009-10-29 392560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-11 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-11 150552]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"seafi"=C:\Users\Jarda62\seafi.exe [2009-12-24 122880]
"Infium"=D:\QIP Infium\infium.exe [2009-12-26 6025168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seafi]
C:\Users\Jarda62\seafi.exe [2009-12-24 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-07 149280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-11 218112]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-01-16 11:58:59 ----D---- C:\Program Files\trend micro
2010-01-16 11:58:57 ----D---- C:\rsit
2010-01-16 11:45:03 ----A---- C:\Windows\system32\libusb0.dll
2010-01-15 21:43:07 ----D---- C:\Program Files\Creative
2010-01-15 21:43:07 ----A---- C:\Windows\system32\eax.dll
2010-01-15 21:43:06 ----A---- C:\Windows\IsUninst.exe
2010-01-15 19:57:06 ----D---- C:\ProgramData\FLEXnet
2010-01-15 19:53:09 ----D---- C:\Program Files\Adobe Media Player
2010-01-15 19:51:29 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-01-15 19:48:19 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-01-14 20:31:37 ----D---- C:\Program Files\Adobe
2010-01-13 20:08:25 ----D---- C:\Users\Jarda62\AppData\Roaming\skypePM
2010-01-13 20:06:18 ----D---- C:\Users\Jarda62\AppData\Roaming\Skype
2010-01-13 20:05:51 ----RD---- C:\Program Files\Skype
2010-01-13 20:05:51 ----D---- C:\Program Files\Common Files\Skype
2010-01-13 20:05:48 ----D---- C:\ProgramData\Skype
2010-01-13 15:28:14 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 15:28:14 ----A---- C:\Windows\system32\fontsub.dll
2010-01-12 16:59:54 ----D---- C:\Program Files\SpeedFan
2010-01-12 16:16:00 ----D---- C:\Windows\Sun
2010-01-10 10:12:38 ----D---- C:\Users\Jarda62\AppData\Roaming\Nvu
2010-01-10 10:12:27 ----D---- C:\Program Files\Nvu
2010-01-09 12:42:08 ----D---- C:\Program Files\CCleaner
2010-01-08 21:18:33 ----D---- C:\Program Files\Microsoft Works
2010-01-08 21:18:19 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-08 21:18:19 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-08 21:18:04 ----D---- C:\Windows\PCHEALTH
2010-01-08 21:18:04 ----D---- C:\Program Files\Microsoft.NET
2010-01-08 21:16:30 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-01-08 21:15:44 ----D---- C:\ProgramData\Microsoft Help
2010-01-08 21:15:44 ----D---- C:\Program Files\Microsoft Office
2010-01-08 21:15:22 ----RHD---- C:\MSOCache
2010-01-08 21:02:33 ----D---- C:\Program Files\DAEMON Tools Lite
2010-01-08 21:02:07 ----D---- C:\Users\Jarda62\AppData\Roaming\DAEMON Tools Lite
2010-01-08 21:02:05 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-01-07 22:34:53 ----D---- C:\ProgramData\Adobe
2010-01-07 22:34:51 ----D---- C:\Program Files\Common Files\Adobe
2010-01-07 20:01:37 ----A---- C:\Windows\system32\XAudio2_5.dll
2010-01-07 20:01:37 ----A---- C:\Windows\system32\xactengine3_5.dll
2010-01-07 20:01:37 ----A---- C:\Windows\system32\d3dcsx_42.dll
2010-01-07 20:01:37 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2010-01-07 20:01:36 ----A---- C:\Windows\system32\D3DX9_42.dll
2010-01-07 20:01:36 ----A---- C:\Windows\system32\D3DX9_41.dll
2010-01-07 20:01:36 ----A---- C:\Windows\system32\d3dx11_42.dll
2010-01-07 20:01:36 ----A---- C:\Windows\system32\d3dx10_42.dll
2010-01-07 20:01:36 ----A---- C:\Windows\system32\d3dx10_41.dll
2010-01-07 20:01:36 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2010-01-07 20:01:35 ----A---- C:\Windows\system32\XAudio2_4.dll
2010-01-07 20:01:35 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2010-01-07 20:01:35 ----A---- C:\Windows\system32\xactengine3_4.dll
2010-01-07 20:01:35 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2010-01-07 20:01:35 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-01-07 20:01:35 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-01-07 20:01:35 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-01-07 20:01:34 ----A---- C:\Windows\system32\XAudio2_3.dll
2010-01-07 20:01:34 ----A---- C:\Windows\system32\XAudio2_2.dll
2010-01-07 20:01:34 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2010-01-07 20:01:34 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2010-01-07 20:01:34 ----A---- C:\Windows\system32\xactengine3_3.dll
2010-01-07 20:01:34 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2010-01-07 20:01:33 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-01-07 20:01:33 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-01-07 20:01:33 ----A---- C:\Windows\system32\xactengine3_2.dll
2010-01-07 20:01:33 ----A---- C:\Windows\system32\D3DX9_39.dll
2010-01-07 20:01:33 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-01-07 20:01:33 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-01-07 20:01:32 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-01-07 20:01:32 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-01-07 20:01:32 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-01-07 20:01:32 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-01-07 20:01:32 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-01-07 20:01:32 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-01-07 20:01:32 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-01-07 20:01:31 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-01-07 20:01:31 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-01-07 20:01:31 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-01-07 20:01:31 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-01-07 20:01:31 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-01-07 20:01:30 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-01-07 20:01:30 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-01-07 20:01:30 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-01-07 20:01:30 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-01-07 20:01:30 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-01-07 20:01:30 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-01-07 20:01:29 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-01-07 20:01:29 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-01-07 20:01:29 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-01-07 20:01:29 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-01-07 20:01:29 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-01-07 20:01:29 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-01-07 20:01:28 ----A---- C:\Windows\system32\xinput1_3.dll
2010-01-07 20:01:28 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-01-07 20:01:28 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-01-07 20:01:28 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-01-07 20:01:28 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-01-07 20:01:27 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-01-07 20:01:27 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-01-07 20:01:27 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-01-07 20:01:27 ----A---- C:\Windows\system32\d3dx10.dll
2010-01-07 20:01:26 ----A---- C:\Windows\system32\xinput1_2.dll
2010-01-07 20:01:26 ----A---- C:\Windows\system32\xinput1_1.dll
2010-01-07 20:01:26 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-01-07 20:01:26 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-01-07 20:01:26 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-01-07 20:01:26 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-01-07 20:01:26 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-01-07 20:01:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-01-07 20:01:24 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-01-07 20:01:24 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-01-07 20:01:24 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-01-07 20:01:24 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-01-07 20:01:23 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-01-07 20:01:23 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-01-07 20:01:23 ----A---- C:\Windows\system32\d3dx9_26.dll
2010-01-07 20:01:23 ----A---- C:\Windows\system32\d3dx9_25.dll
2010-01-07 20:01:22 ----A---- C:\Windows\system32\d3dx9_24.dll
2010-01-07 19:52:17 ----D---- C:\Windows\system32\directx
2010-01-07 19:51:46 ----D---- C:\Program Files\AviSynth 2.5
2010-01-07 19:51:42 ----D---- C:\Program Files\pspvc
2010-01-07 19:51:42 ----A---- C:\Windows\pspvc_path.ini
2010-01-07 15:08:27 ----D---- C:\Users\Jarda62\AppData\Roaming\VitySoft
2010-01-07 14:20:08 ----A---- C:\Windows\system32\javaws.exe
2010-01-07 14:20:08 ----A---- C:\Windows\system32\javaw.exe
2010-01-07 14:20:08 ----A---- C:\Windows\system32\java.exe
2010-01-07 14:20:08 ----A---- C:\Windows\system32\deploytk.dll
2010-01-07 14:19:58 ----D---- C:\Program Files\Java
2010-01-07 14:19:34 ----SHD---- C:\Windows\Installer
2010-01-06 14:30:35 ----D---- C:\Users\Jarda62\AppData\Roaming\Tific
2010-01-06 14:30:17 ----D---- C:\Program Files\Symantec
2010-01-06 14:30:17 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-01-06 14:30:05 ----D---- C:\Program Files\Norton Internet Security
2010-01-06 14:29:52 ----D---- C:\ProgramData\Norton
2010-01-06 14:29:39 ----D---- C:\ProgramData\NortonInstaller
2010-01-06 14:29:39 ----D---- C:\Program Files\NortonInstaller
2010-01-05 19:11:17 ----D---- C:\Program Files\RocketDock
2010-01-04 19:24:27 ----D---- C:\Users\Jarda62\AppData\Roaming\WinRAR
2010-01-04 19:23:57 ----D---- C:\Program Files\WinRAR
2010-01-04 18:43:44 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-04 18:43:05 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-04 18:40:18 ----A---- C:\Windows\system32\unrar.dll
2010-01-04 18:40:18 ----A---- C:\Windows\avisplitter.ini
2010-01-04 18:40:17 ----A---- C:\Windows\system32\yv12vfw.dll
2010-01-04 18:40:17 ----A---- C:\Windows\system32\xvidvfw.dll
2010-01-04 18:40:17 ----A---- C:\Windows\system32\xvidcore.dll
2010-01-04 18:40:15 ----A---- C:\Windows\system32\ff_vfw.dll.manifest
2010-01-04 18:40:15 ----A---- C:\Windows\system32\ff_vfw.dll
2010-01-04 18:40:14 ----D---- C:\Program Files\K-Lite Codec Pack
2010-01-04 18:39:06 ----D---- C:\Users\Jarda62\AppData\Roaming\Macromedia
2010-01-04 18:39:06 ----D---- C:\Users\Jarda62\AppData\Roaming\Adobe
2010-01-04 18:39:03 ----D---- C:\Windows\system32\Macromed
2010-01-04 17:55:28 ----D---- C:\Users\Jarda62\AppData\Roaming\Mozilla
2010-01-04 17:55:22 ----D---- C:\Program Files\Mozilla Firefox
2010-01-04 17:51:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-04 17:47:51 ----A---- C:\Windows\system32\TVWizudlg.exe
2010-01-04 17:47:51 ----A---- C:\Windows\system32\igfxtvcx.dll
2010-01-04 17:47:50 ----D---- C:\Windows\system32\Lang
2010-01-04 17:47:50 ----D---- C:\Program Files\Intel
2010-01-04 17:45:42 ----A---- C:\Windows\system32\msv1_0.dll
2010-01-04 17:45:31 ----D---- C:\Windows\system32\x64
2010-01-04 17:45:31 ----A---- C:\Windows\system32\igxpun.exe
2010-01-04 17:45:03 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-04 17:44:45 ----A---- C:\Windows\system32\tzres.dll
2010-01-04 17:44:15 ----A---- C:\Windows\system32\MRT.exe
2010-01-04 17:43:18 ----A---- C:\Windows\system32\wmp.dll
2010-01-04 17:43:17 ----A---- C:\Windows\system32\winload.exe
2010-01-04 17:43:17 ----A---- C:\Windows\system32\CertEnroll.dll
2010-01-04 17:43:17 ----A---- C:\Windows\explorer.exe
2010-01-04 17:43:16 ----A---- C:\Windows\system32\wmploc.DLL
2010-01-04 17:43:16 ----A---- C:\Windows\system32\winresume.exe
2010-01-04 17:43:16 ----A---- C:\Windows\system32\atmfd.dll
2010-01-04 17:43:03 ----A---- C:\Windows\system32\mshtml.dll
2010-01-04 17:43:03 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-04 17:42:57 ----A---- C:\Windows\system32\msasn1.dll
2010-01-04 17:40:36 ----D---- C:\Users\Jarda62\AppData\Roaming\Identities
2010-01-04 17:40:28 ----SD---- C:\Users\Jarda62\AppData\Roaming\Microsoft
2010-01-04 17:40:28 ----D---- C:\Users\Jarda62\AppData\Roaming\Media Center Programs
2010-01-04 17:40:16 ----SHD---- C:\Recovery
2010-01-04 17:40:15 ----SHD---- C:\ProgramData\Šablony
2010-01-04 17:40:15 ----SHD---- C:\ProgramData\Plocha
2010-01-04 17:40:15 ----SHD---- C:\ProgramData\Oblíbené položky
2010-01-04 17:40:15 ----SHD---- C:\ProgramData\Nabídka Start
2010-01-04 17:40:15 ----SHD---- C:\ProgramData\Dokumenty
2010-01-04 17:40:15 ----SHD---- C:\ProgramData\Data aplikací
2010-01-04 17:36:34 ----D---- C:\Windows\SoftwareDistribution
2010-01-04 17:34:06 ----D---- C:\Windows\Prefetch
2010-01-04 17:33:52 ----SHD---- C:\System Volume Information
2010-01-04 17:32:46 ----D---- C:\Windows\Panther

======List of files/folders modified in the last 1 months======

2010-01-16 11:58:59 ----RD---- C:\Program Files
2010-01-16 11:58:59 ----D---- C:\Windows\Temp
2010-01-16 11:50:32 ----D---- C:\Windows\system32\config
2010-01-16 11:46:04 ----D---- C:\Windows\system32\drivers
2010-01-16 11:46:04 ----D---- C:\Windows\System32
2010-01-16 11:45:57 ----D---- C:\Windows\inf
2010-01-16 11:45:41 ----D---- C:\Windows\system32\DriverStore
2010-01-15 21:43:14 ----D---- C:\Windows
2010-01-15 19:57:06 ----HD---- C:\ProgramData
2010-01-15 19:52:43 ----RSD---- C:\Windows\Fonts
2010-01-15 19:51:29 ----D---- C:\Program Files\Common Files
2010-01-14 14:37:53 ----D---- C:\Windows\debug
2010-01-13 20:06:16 ----D---- C:\Windows\system32\Tasks
2010-01-13 15:42:37 ----D---- C:\Windows\winsxs
2010-01-13 15:27:58 ----D---- C:\Windows\system32\catroot
2010-01-11 14:14:35 ----D---- C:\Windows\system32\catroot2
2010-01-09 19:26:11 ----RSD---- C:\Windows\assembly
2010-01-08 23:23:14 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-08 21:18:26 ----D---- C:\Program Files\MSBuild
2010-01-08 21:18:04 ----SD---- C:\ProgramData\Microsoft
2010-01-08 21:16:14 ----D---- C:\Windows\ShellNew
2010-01-08 21:14:23 ----D---- C:\Windows\system32\LogFiles
2010-01-07 20:01:21 ----D---- C:\Windows\Microsoft.NET
2010-01-07 19:52:17 ----D---- C:\Windows\Logs
2010-01-04 22:41:06 ----D---- C:\Windows\system32\wdi
2010-01-04 20:25:46 ----D---- C:\Windows\rescache
2010-01-04 19:11:04 ----D---- C:\Program Files\Internet Explorer
2010-01-04 18:02:09 ----D---- C:\Windows\system32\CodeIntegrity
2010-01-04 17:45:58 ----D---- C:\Windows\system32\Boot
2010-01-04 17:45:58 ----D---- C:\Windows\ehome
2010-01-04 17:45:58 ----D---- C:\Windows\AppPatch
2010-01-04 17:45:58 ----D---- C:\Program Files\Windows Media Player
2010-01-04 17:44:51 ----D---- C:\Windows\system32\cs-CZ
2010-01-04 17:44:35 ----D---- C:\Windows\system32\wbem
2010-01-04 17:44:02 ----D---- C:\Windows\system32\restore
2010-01-04 17:40:35 ----SHD---- C:\$Recycle.Bin
2010-01-04 17:40:26 ----RD---- C:\Users
2010-01-04 17:40:15 ----D---- C:\Program Files\Windows NT
2010-01-04 17:37:15 ----D---- C:\Windows\system32\sysprep
2010-01-04 17:32:28 ----D---- C:\Windows\system32\oobe
2010-01-04 17:32:28 ----D---- C:\Windows\Setup

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHDrvx86.sys [2009-12-05 529456]
R1 blbdrive;blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys [2009-07-14 35328]
R1 ccHP;Symantec Hash Provider; C:\Windows\system32\drivers\NIS\1101000.013\ccHPx86.sys [2009-10-20 501888]
R1 DfsC;@%systemroot%\system32\drivers\dfsc.sys,-101; C:\Windows\System32\Drivers\dfsc.sys [2009-07-14 78336]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2010-01-06 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100112.001\IDSvix86.sys [2009-10-28 343088]
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys [2009-07-14 16896]
R1 RDPENCDD;@%systemroot%\system32\drivers\RDPENCDD.sys,-101; C:\Windows\system32\drivers\rdpencdd.sys [2009-07-14 6656]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1101000.013\SRTSPX.SYS [2009-10-09 43696]
R1 SymIRON;Symantec Iron Driver; C:\Windows\System32\Drivers\NIS\1101000.013\Ironx86.SYS [2009-10-09 114736]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver; C:\Windows\System32\Drivers\NIS\1101000.013\SYMTDIV.SYS [2009-10-15 339504]
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys [2009-07-14 74240]
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys [2009-07-14 63488]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-08-14 74720]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver; C:\Windows\system32\DRIVERS\lltdio.sys [2009-07-14 48128]
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys [2009-07-14 86528]
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys [2009-07-14 586752]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\Windows\system32\DRIVERS\rspndr.sys [2009-07-14 60928]
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys [2009-07-14 34816]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2009-10-13 49152]
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys [2009-07-14 69632]
R3 CompositeBus;Ovladač rozpoznávacího modulu složené sběrnice; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys [2009-10-02 728648]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-01-06 102448]
R3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 HDAudBus;Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio; C:\Windows\system32\DRIVERS\HDAudBus.sys [2009-07-14 108544]
R3 HidUsb;Ovladač třídy standardu HID Microsoft; C:\Windows\system32\DRIVERS\hidusb.sys [2009-07-14 24064]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-11 4805120]
R3 intelppm;Ovladač procesoru Intel; C:\Windows\system32\DRIVERS\intelppm.sys [2009-07-14 53760]
R3 monitor;Služba ovladače funkce třídy monitorů Microsoft; C:\Windows\system32\DRIVERS\monitor.sys [2009-07-14 23552]
R3 mouhid;Ovladač myši standardu HID; C:\Windows\system32\DRIVERS\mouhid.sys [2009-07-14 26112]
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys [2009-07-14 60416]
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys [2009-07-14 221184]
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys [2009-07-14 95744]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100115.019\NAVENG.SYS [2010-01-06 84912]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100115.019\NAVEX15.SYS [2010-01-06 1323568]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys [2009-07-14 75264]
R3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NIS\1101000.013\SRTSP.SYS [2009-10-09 325168]
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys [2009-07-14 306688]
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [2009-07-14 113664]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2010-01-06 124976]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys [2009-07-14 108544]
R3 umbus;Ovladač sběrnice UMBus Enumerator; C:\Windows\system32\DRIVERS\umbus.sys [2009-07-14 39936]
R3 usbehci;Ovladač miniportu vylepšeného hostitelského řadiče Microsoft USB 2.0; C:\Windows\system32\DRIVERS\usbehci.sys [2009-07-14 41472]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\Windows\system32\DRIVERS\usbhub.sys [2009-07-14 258560]
R3 usbuhci;Ovladač miniportu univerzálního hostitelského řadiče Microsoft USB; C:\Windows\system32\DRIVERS\usbuhci.sys [2009-07-14 24064]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
S3 a9j5o16r;a9j5o16r; C:\Windows\system32\drivers\a9j5o16r.sys []
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 adp94xx;adp94xx; C:\Windows\system32\DRIVERS\adp94xx.sys [2009-07-14 422976]
S3 adpahci;adpahci; C:\Windows\system32\DRIVERS\adpahci.sys [2009-07-14 297552]
S3 adpu320;adpu320; C:\Windows\system32\DRIVERS\adpu320.sys [2009-07-14 146512]
S3 agp440;Intel AGP Bus Filter; C:\Windows\system32\DRIVERS\agp440.sys [2009-07-14 53312]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 amdide;amdide; C:\Windows\system32\DRIVERS\amdide.sys [2009-07-14 14912]
S3 AmdK8;AMD K8 Processor Driver; C:\Windows\system32\DRIVERS\amdk8.sys [2009-07-14 55296]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 arc;arc; C:\Windows\system32\DRIVERS\arc.sys [2009-07-14 76368]
S3 arcsas;arcsas; C:\Windows\system32\DRIVERS\arcsas.sys [2009-07-14 86608]
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver; C:\Windows\system32\DRIVERS\BrFiltLo.sys [2009-07-13 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver; C:\Windows\system32\DRIVERS\BrFiltUp.sys [2009-07-13 5248]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM); C:\Windows\System32\Drivers\Brserid.sys [2009-07-14 272128]
S3 BrSerWdm;Brother WDM Serial driver; C:\Windows\System32\Drivers\BrSerWdm.sys [2009-07-13 62336]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem; C:\Windows\System32\Drivers\BrUsbMdm.sys [2009-07-13 12160]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\Windows\System32\Drivers\BrUsbSer.sys [2009-07-13 11904]
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\Windows\system32\DRIVERS\bthmodem.sys [2009-07-14 56320]
S3 circlass;Consumer IR Devices; C:\Windows\system32\DRIVERS\circlass.sys [2009-07-14 37888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 Compbatt;Compbatt; C:\Windows\system32\DRIVERS\compbatt.sys [2009-07-14 19024]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 elxstor;elxstor; C:\Windows\system32\DRIVERS\elxstor.sys [2009-07-14 453712]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys [2009-07-14 142336]
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys [2009-07-14 28160]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\system32\DRIVERS\gagp30kx.sys [2009-07-14 57936]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HidBth;Microsoft Bluetooth HID Miniport; C:\Windows\system32\DRIVERS\hidbth.sys [2009-07-14 91136]
S3 HidIr;Microsoft Infrared HID Driver; C:\Windows\system32\DRIVERS\hidir.sys [2009-07-14 37888]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 iaStorV;iaStorV; C:\Windows\system32\DRIVERS\iaStorV.sys [2009-07-14 332352]
S3 iirsp;iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [2009-07-14 41040]
S3 IPMIDRV;IPMIDRV; C:\Windows\system32\DRIVERS\IPMIDrv.sys [2009-07-14 65536]
S3 isapnp;isapnp; C:\Windows\system32\DRIVERS\isapnp.sys [2009-07-14 46656]
S3 iScsiPrt;iScsiPort Driver; C:\Windows\system32\DRIVERS\msiscsi.sys [2009-07-14 186960]
S3 kbdhid;Keyboard HID Driver; C:\Windows\system32\DRIVERS\kbdhid.sys [2009-07-14 28160]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120; C:\Windows\system32\DRIVERS\libusb0.sys [2006-04-23 29184]
S3 LSI_FC;LSI_FC; C:\Windows\system32\DRIVERS\lsi_fc.sys [2009-07-14 95824]
S3 LSI_SAS;LSI_SAS; C:\Windows\system32\DRIVERS\lsi_sas.sys [2009-07-14 89168]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 LSI_SCSI;LSI_SCSI; C:\Windows\system32\DRIVERS\lsi_scsi.sys [2009-07-14 96848]
S3 megasas;megasas; C:\Windows\system32\DRIVERS\megasas.sys [2009-07-14 30800]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mpio;mpio; C:\Windows\system32\DRIVERS\mpio.sys [2009-07-14 130624]
S3 msahci;msahci; C:\Windows\system32\DRIVERS\msahci.sys [2009-07-14 27712]
S3 msdsm;msdsm; C:\Windows\system32\DRIVERS\msdsm.sys [2009-07-14 115792]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys [2009-07-14 162896]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NativeWifiP;NativeWiFi Filter; C:\Windows\system32\DRIVERS\nwifi.sys [2009-07-14 267264]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 nfrd960;nfrd960; C:\Windows\system32\DRIVERS\nfrd960.sys [2009-07-14 44624]
S3 nv_agp;NVIDIA nForce AGP Bus Filter; C:\Windows\system32\DRIVERS\nv_agp.sys [2009-07-14 105024]
S3 nvraid;nvraid; C:\Windows\system32\DRIVERS\nvraid.sys [2009-07-14 117312]
S3 nvstor;nvstor; C:\Windows\system32\DRIVERS\nvstor.sys [2009-07-14 142416]
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy); C:\Windows\system32\DRIVERS\ohci1394.sys [2009-07-14 62464]
S3 ql2300;ql2300; C:\Windows\system32\DRIVERS\ql2300.sys [2009-07-14 1383488]
S3 ql40xx;ql40xx; C:\Windows\system32\DRIVERS\ql40xx.sys [2009-07-14 106064]
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys [2009-07-14 31744]
S3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
S3 sbp2port;sbp2port; C:\Windows\system32\DRIVERS\sbp2port.sys [2009-07-14 85568]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 sermouse;Serial Mouse Driver; C:\Windows\system32\DRIVERS\sermouse.sys [2009-07-14 19968]
S3 sffdisk;SFF Storage Class Driver; C:\Windows\system32\DRIVERS\sffdisk.sys [2009-07-14 11264]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC; C:\Windows\system32\DRIVERS\sffp_mmc.sys [2009-07-14 12288]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\Windows\system32\DRIVERS\sffp_sd.sys [2009-07-14 12800]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SiSRaid2;SiSRaid2; C:\Windows\system32\DRIVERS\SiSRaid2.sys [2009-07-14 40016]
S3 SiSRaid4;SiSRaid4; C:\Windows\system32\DRIVERS\sisraid4.sys [2009-07-14 77888]
S3 Smb;@%SystemRoot%\system32\tcpipcfg.dll,-50005; C:\Windows\system32\DRIVERS\smb.sys [2009-07-14 71168]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 TCPIP6;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys [2009-07-14 1285712]
S3 tssecsrv;@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101; C:\Windows\System32\DRIVERS\tssecsrv.sys [2009-07-14 30208]
S3 uagp35;Microsoft AGPv3.5 Filter; C:\Windows\system32\DRIVERS\uagp35.sys [2009-07-14 55888]
S3 uliagpkx;Uli AGP Bus Filter; C:\Windows\system32\DRIVERS\uliagpkx.sys [2009-07-14 57424]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\Windows\system32\DRIVERS\usbccgp.sys [2009-07-14 75264]
S3 usbcir;eHome Infrared Receiver (USBCIR); C:\Windows\system32\DRIVERS\usbcir.sys [2009-07-14 86016]
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbohci.sys [2009-07-14 20480]
S3 usbprint;Microsoft USB PRINTER Class; C:\Windows\system32\DRIVERS\usbprint.sys [2009-07-14 19968]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\Windows\system32\DRIVERS\USBSTOR.SYS [2009-07-14 74752]
S3 vga;vga; C:\Windows\system32\DRIVERS\vgapnp.sys [2009-07-14 26112]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vsmraid;vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys [2009-07-14 141904]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WacomPen;Wacom Serial Pen HID Driver; C:\Windows\system32\DRIVERS\wacompen.sys [2009-07-14 21632]
S3 Wd;Wd; C:\Windows\system32\DRIVERS\wd.sys [2009-07-14 19024]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
S4 crcdisk;Crcdisk Filter Driver; C:\Windows\system32\DRIVERS\crcdisk.sys [2009-07-14 22096]
S4 ws2ifsl;@%systemroot%\System32\drivers\ws2ifsl.sys,-1000; C:\Windows\system32\drivers\ws2ifsl.sys [2009-07-14 16384]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AudioEndpointBuilder;@%SystemRoot%\system32\audiosrv.dll,-204; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe [2009-10-20 126392]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 UxSms;@%SystemRoot%\system32\dwm.exe,-2000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WMPNetworkSvc;@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101; C:\Program Files\Windows Media Player\wmpnetwk.exe [2009-07-14 1121280]
R2 WSearch;@%systemroot%\system32\SearchIndexer.exe,-103; C:\Windows\system32\SearchIndexer.exe [2009-07-14 428032]
R2 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe [2009-07-14 22528]
R3 netprofm;@%SystemRoot%\system32\netprofm.dll,-202; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-06-10 66384]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\Windows\ehome\ehRecvr.exe [2009-07-14 557056]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\Windows\ehome\ehsched.exe [2009-07-14 94720]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-01-15 655624]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2009-06-10 42856]
S3 idsvc;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2009-06-10 878416]
S3 IPBusEnum;@%systemroot%\system32\IPBusEnum.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe [2009-07-14 12800]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TBS;@%SystemRoot%\system32\tbssvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2009-07-14 204800]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe [2009-07-14 35840]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe [2009-07-14 452608]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinDefend;@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2009-06-10 128848]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu

#2 Příspěvek od Rudy »

Pokud tento soubor neznáte: C:\Users\Jarda62\seafi.exe , otestujte jeju online na www.virustotal.com .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jarda62
Návštěvník
Návštěvník
Příspěvky: 170
Registrován: 28 črc 2008 17:59

Re: Prosím o kontrolu

#3 Příspěvek od Jarda62 »


Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu

#4 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jarda62
Návštěvník
Návštěvník
Příspěvky: 170
Registrován: 28 črc 2008 17:59

Re: Prosím o kontrolu

#5 Příspěvek od Jarda62 »

ComboFix 10-01-16.03 - Jarda62 17.01.2010 20:36:09.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.2038.1480 [GMT 1:00]
Spuštěný z: c:\users\Jarda62\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Soubory vytvořené od 2009-12-17 do 2010-01-17 )))))))))))))))))))))))))))))))
.

2010-01-17 17:38 . 2010-01-06 13:37 84912 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVENG.SYS
2010-01-17 17:38 . 2010-01-06 13:37 371248 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\EECTRL.SYS
2010-01-17 17:38 . 2010-01-06 13:37 2747440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\CCERASER.DLL
2010-01-17 17:38 . 2010-01-06 13:37 259440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\ECMSVR32.DLL
2010-01-17 17:38 . 2010-01-06 13:37 177520 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVENG32.DLL
2010-01-17 17:38 . 2010-01-06 13:37 1647984 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVEX32A.DLL
2010-01-17 17:38 . 2010-01-06 13:37 1323568 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVEX15.SYS
2010-01-17 17:38 . 2010-01-06 13:37 102448 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\ERASER.SYS
2010-01-16 18:53 . 2010-01-16 18:54 -------- d-----w- c:\users\Jarda62\AppData\Local\CrashDumps
2010-01-16 18:27 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSvix86.sys
2010-01-16 18:27 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSXpx86.sys
2010-01-16 18:27 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\Scxpx86.dll
2010-01-16 18:27 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSxpx86.dll
2010-01-16 18:27 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSviA64.sys
2010-01-16 11:05 . 2010-01-16 11:05 -------- d-----w- c:\program files\SystemRequirementsLab
2010-01-16 11:05 . 2010-01-16 11:05 -------- d-----w- c:\users\Jarda62\SystemRequirementsLab
2010-01-16 10:58 . 2010-01-16 10:59 -------- d-----w- c:\program files\trend micro
2010-01-16 10:58 . 2010-01-16 10:59 -------- d-----w- C:\rsit
2010-01-16 10:45 . 2006-04-23 03:34 42496 ----a-w- c:\windows\system32\libusb0.dll
2010-01-16 10:45 . 2006-04-23 03:34 29184 ----a-w- c:\windows\system32\drivers\libusb0.sys
2010-01-15 20:43 . 2010-01-15 20:43 -------- d-----w- c:\program files\Creative
2010-01-15 20:43 . 2002-06-06 13:38 139264 ----a-w- c:\windows\system32\eax.dll
2010-01-15 20:43 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-01-15 18:57 . 2010-01-15 18:57 -------- d-----w- c:\programdata\FLEXnet
2010-01-15 18:53 . 2010-01-15 18:53 -------- d-----w- c:\program files\Adobe Media Player
2010-01-15 18:51 . 2010-01-15 18:51 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-15 18:48 . 2010-01-15 18:48 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-01-15 14:14 . 2009-02-16 21:12 53248 ----a-w- c:\users\Jarda62\AppData\Roaming\Mozilla\Firefox\Profiles\4p6tj99m.default\extensions\StrataBuddy@ReduxTeam\components\dwmxpcom.dll
2010-01-13 19:08 . 2010-01-13 19:08 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-13 19:08 . 2010-01-13 19:08 -------- d-----w- c:\users\Jarda62\AppData\Roaming\skypePM
2010-01-13 19:06 . 2010-01-16 16:41 -------- d-----w- c:\users\Jarda62\AppData\Roaming\Skype
2010-01-13 19:05 . 2010-01-13 19:07 -------- d-----r- c:\program files\Skype
2010-01-13 19:05 . 2010-01-13 19:05 -------- d-----w- c:\program files\Common Files\Skype
2010-01-13 19:05 . 2010-01-13 19:05 -------- d-----w- c:\programdata\Skype
2010-01-13 14:28 . 2009-10-19 14:10 108544 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 14:28 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-01-12 15:59 . 2010-01-14 20:37 -------- d-----w- c:\program files\SpeedFan
2010-01-12 15:16 . 2010-01-12 15:16 -------- d-----w- c:\windows\Sun
2010-01-10 09:12 . 2010-01-10 09:12 -------- d-----w- c:\users\Jarda62\AppData\Roaming\Nvu
2010-01-10 09:12 . 2010-01-10 09:12 -------- d-----w- c:\program files\Nvu
2010-01-09 11:42 . 2010-01-09 11:42 -------- d-----w- c:\program files\CCleaner
2010-01-08 21:02 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSvix86.sys
2010-01-08 21:02 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSXpx86.sys
2010-01-08 21:02 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\Scxpx86.dll
2010-01-08 21:02 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSxpx86.dll
2010-01-08 21:02 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSviA64.sys
2010-01-08 20:18 . 2010-01-08 22:23 -------- d-----w- c:\program files\Microsoft Works
2010-01-08 20:18 . 2010-01-08 20:18 -------- d-----w- c:\windows\PCHEALTH
2010-01-08 20:18 . 2010-01-08 20:18 -------- d-----w- c:\program files\Microsoft.NET
2010-01-08 20:16 . 2010-01-08 20:16 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-01-08 20:15 . 2010-01-08 20:15 -------- d-----w- c:\users\Jarda62\AppData\Local\Microsoft Help
2010-01-08 20:15 . 2010-01-13 14:29 -------- d-----w- c:\programdata\Microsoft Help
2010-01-08 20:15 . 2010-01-08 20:15 -------- d-----r- C:\MSOCache
2010-01-08 20:02 . 2010-01-08 20:02 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-08 20:02 . 2010-01-08 20:02 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-08 20:02 . 2010-01-08 20:12 -------- d-----w- c:\users\Jarda62\AppData\Roaming\DAEMON Tools Lite
2010-01-08 20:02 . 2010-01-08 20:02 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-01-07 21:35 . 2010-01-15 19:05 -------- d-----w- c:\users\Jarda62\AppData\Local\Adobe
2010-01-07 21:34 . 2010-01-15 18:53 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-07 18:51 . 2010-01-07 18:51 -------- d-----w- c:\program files\AviSynth 2.5
2010-01-07 18:51 . 2010-01-07 18:51 -------- d-----w- c:\program files\pspvc
2010-01-07 14:08 . 2010-01-07 14:08 -------- d-----w- c:\users\Jarda62\AppData\Roaming\VitySoft
2010-01-07 13:20 . 2010-01-07 13:19 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-07 13:19 . 2010-01-07 13:19 -------- d-----w- c:\program files\Java
2010-01-07 13:19 . 2010-01-16 11:05 -------- d-sh--w- c:\windows\Installer
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\users\Jarda62\AppData\Local\Tific
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\users\Jarda62\AppData\Roaming\Tific
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\users\Jarda62\AppData\Local\Symantec
2010-01-06 13:30 . 2009-10-29 02:31 784752 ----a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\components\coFFPlgn.dll
2010-01-06 13:30 . 2010-01-06 13:30 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-06 13:30 . 2010-01-06 13:39 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\program files\Symantec
2010-01-06 13:30 . 2010-01-06 13:30 965488 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\OCS\hsplayer.dll
2010-01-06 13:30 . 2009-08-30 00:16 164216 ----a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\components\IPSFFPl.dll
2010-01-06 13:30 . 2010-01-12 15:06 -------- d-----w- c:\windows\system32\drivers\NIS
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\program files\Norton Internet Security
2010-01-06 13:29 . 2010-01-06 18:33 -------- d-----w- c:\programdata\Norton
2010-01-06 13:29 . 2010-01-06 13:42 -------- d-----w- c:\programdata\NortonInstaller
2010-01-06 13:29 . 2010-01-06 13:29 -------- d-----w- c:\program files\NortonInstaller
2010-01-05 18:11 . 2010-01-05 18:11 -------- d-----w- c:\program files\RocketDock
2010-01-04 17:43 . 2010-01-04 17:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-04 17:43 . 2010-01-04 17:43 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-04 17:40 . 2009-12-12 14:15 178176 ----a-w- c:\windows\system32\unrar.dll
2010-01-04 17:40 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-04 17:40 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-04 17:40 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-01-04 17:40 . 2010-01-04 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-04 17:40 . 2010-01-05 15:18 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-01-04 17:39 . 2010-01-04 17:39 -------- d-----w- c:\windows\system32\Macromed
2010-01-04 17:13 . 2010-01-15 18:57 84120 ----a-w- c:\users\Jarda62\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-04 16:55 . 2010-01-04 16:55 0 ----a-w- c:\windows\nsreg.dat
2010-01-04 16:55 . 2010-01-04 16:55 -------- d-----w- c:\users\Jarda62\AppData\Local\Mozilla
2010-01-04 16:47 . 2009-09-11 08:36 398336 ----a-w- c:\windows\system32\TVWizudlg.exe
2010-01-04 16:47 . 2009-09-11 08:36 140288 ----a-w- c:\windows\system32\igfxtvcx.dll
2010-01-04 16:47 . 2010-01-04 16:47 -------- d-----w- c:\windows\system32\Lang
2010-01-04 16:47 . 2010-01-04 16:47 -------- d-----w- c:\program files\Intel
2010-01-04 16:45 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-01-04 16:45 . 2010-01-04 16:45 -------- d-----w- c:\windows\system32\x64
2010-01-04 16:45 . 2009-09-11 16:15 1002008 ----a-w- c:\windows\system32\igxpun.exe
2010-01-04 16:45 . 2009-11-02 19:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2010-01-04 16:44 . 2009-10-29 07:22 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-04 16:44 . 2010-01-17 19:39 -------- d-----w- c:\windows\system32\wbem\Performance
2010-01-04 16:43 . 2009-10-02 04:06 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-01-04 16:43 . 2009-09-03 07:04 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
2010-01-04 16:43 . 2009-08-19 07:20 507568 ----a-w- c:\windows\system32\winload.exe
2010-01-04 16:43 . 2009-08-03 05:35 2613248 ----a-w- c:\windows\explorer.exe
2010-01-04 16:43 . 2009-08-29 06:54 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-01-04 16:43 . 2009-08-19 07:20 442920 ----a-w- c:\windows\system32\winresume.exe
2010-01-04 16:43 . 2009-07-30 04:44 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-01-04 16:42 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-01-04 16:32 . 2010-01-04 16:40 -------- d-----w- c:\windows\Panther

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 19:39 . 2009-07-14 08:44 622422 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 19:39 . 2009-07-14 08:44 118604 ----a-w- c:\windows\system32\perfc005.dat
2010-01-08 20:18 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-01-06 13:30 . 2010-01-06 13:30 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-06 13:30 . 2010-01-06 13:30 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-04 16:50 . 2010-01-04 16:50 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Plocha
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Oblíbené položky
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Šablony
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Nabídka Start
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Dokumenty
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Data aplikací
2009-12-05 04:54 . 2009-12-05 04:54 529456 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHDrvx86.sys
2009-12-05 04:54 . 2009-12-05 04:54 201616 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHRules.dll
2009-12-05 04:54 . 2009-12-05 04:54 1405840 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHEngine.dll
2009-12-05 04:54 . 2009-12-05 04:54 668720 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHDrvx64.sys
2009-12-05 04:54 . 2009-12-05 04:54 610704 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\bbRGen.dll
2009-10-28 22:37 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-10-28 22:37 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-10-28 22:37 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Infium"="d:\qip infium\infium.exe" [2009-12-26 6025168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-11 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-11 150552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-07 13:20 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

R0 SymDS;Symantec Data Store;c:\windows\System32\drivers\NIS\1101000.013\SymDS.sys [6.1.2010 14:42 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NIS\1101000.013\SymEFA.sys [6.1.2010 14:42 171056]
R1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHDrvx86.sys [5.12.2009 5:54 529456]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NIS\1101000.013\cchpx86.sys [6.1.2010 14:42 501888]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSvix86.sys [16.1.2010 19:27 343088]
R1 SymIRON;Symantec Iron Driver;c:\windows\System32\drivers\NIS\1101000.013\Ironx86.sys [6.1.2010 14:42 114736]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\drivers\NIS\1101000.013\symtdiv.sys [6.1.2010 14:42 339504]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe [6.1.2010 14:42 126392]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [13.10.2009 2:16 49152]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6.1.2010 14:37 102448]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [8.1.2010 21:02 691696]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\System32\drivers\libusb0.sys [16.1.2010 11:45 29184]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\Get Styles\ct.htm
FF - ProfilePath - c:\users\Jarda62\AppData\Roaming\Mozilla\Firefox\Profiles\4p6tj99m.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - component: c:\users\Jarda62\AppData\Roaming\Mozilla\Firefox\Profiles\4p6tj99m.default\extensions\StrataBuddy@ReduxTeam\components\dwmxpcom.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-seafi - c:\users\Jarda62\seafi.exe
MSConfigStartUp-seafi - c:\users\Jarda62\seafi.exe
AddRemove-QIP Infium - c:\program files\QIP Infium\unins000.exe



[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.1.0.19\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-01-17 20:43:54
ComboFix-quarantined-files.txt 2010-01-17 19:43

Před spuštěním: Volných bajtů: 23 986 823 168
Po spuštění: Volných bajtů: 23 913 816 064

- - End Of File - - 07F77C613ECCAB69BBDA7FBAD32664C8

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu

#6 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Collect::
C:\Users\Jarda62\seafi.exe

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"seafi"=-
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jarda62
Návštěvník
Návštěvník
Příspěvky: 170
Registrován: 28 črc 2008 17:59

Re: Prosím o kontrolu

#7 Příspěvek od Jarda62 »

ComboFix 10-01-16.03 - Jarda62 17.01.2010 21:23:31.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.2038.1185 [GMT 1:00]
Spuštěný z: c:\users\Jarda62\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Jarda62\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Soubory vytvořené od 2009-12-17 do 2010-01-17 )))))))))))))))))))))))))))))))
.

2010-01-17 20:29 . 2010-01-17 20:29 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-17 20:29 . 2010-01-17 20:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-17 19:43 . 2010-01-17 20:29 -------- d-----w- c:\users\Jarda62\AppData\Local\temp
2010-01-17 17:38 . 2010-01-06 13:37 84912 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVENG.SYS
2010-01-17 17:38 . 2010-01-06 13:37 371248 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\EECTRL.SYS
2010-01-17 17:38 . 2010-01-06 13:37 2747440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\CCERASER.DLL
2010-01-17 17:38 . 2010-01-06 13:37 259440 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\ECMSVR32.DLL
2010-01-17 17:38 . 2010-01-06 13:37 177520 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVENG32.DLL
2010-01-17 17:38 . 2010-01-06 13:37 1647984 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVEX32A.DLL
2010-01-17 17:38 . 2010-01-06 13:37 1323568 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\NAVEX15.SYS
2010-01-17 17:38 . 2010-01-06 13:37 102448 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100117.002\ERASER.SYS
2010-01-16 18:53 . 2010-01-16 18:54 -------- d-----w- c:\users\Jarda62\AppData\Local\CrashDumps
2010-01-16 18:27 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSvix86.sys
2010-01-16 18:27 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSXpx86.sys
2010-01-16 18:27 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\Scxpx86.dll
2010-01-16 18:27 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSxpx86.dll
2010-01-16 18:27 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSviA64.sys
2010-01-16 11:05 . 2010-01-16 11:05 -------- d-----w- c:\program files\SystemRequirementsLab
2010-01-16 11:05 . 2010-01-16 11:05 -------- d-----w- c:\users\Jarda62\SystemRequirementsLab
2010-01-16 10:58 . 2010-01-16 10:59 -------- d-----w- c:\program files\trend micro
2010-01-16 10:58 . 2010-01-16 10:59 -------- d-----w- C:\rsit
2010-01-16 10:45 . 2006-04-23 03:34 42496 ----a-w- c:\windows\system32\libusb0.dll
2010-01-16 10:45 . 2006-04-23 03:34 29184 ----a-w- c:\windows\system32\drivers\libusb0.sys
2010-01-15 20:43 . 2010-01-15 20:43 -------- d-----w- c:\program files\Creative
2010-01-15 20:43 . 2002-06-06 13:38 139264 ----a-w- c:\windows\system32\eax.dll
2010-01-15 20:43 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-01-15 18:57 . 2010-01-15 18:57 -------- d-----w- c:\programdata\FLEXnet
2010-01-15 18:53 . 2010-01-15 18:53 -------- d-----w- c:\program files\Adobe Media Player
2010-01-15 18:51 . 2010-01-15 18:51 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-15 18:48 . 2010-01-15 18:48 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-01-15 14:14 . 2009-02-16 21:12 53248 ----a-w- c:\users\Jarda62\AppData\Roaming\Mozilla\Firefox\Profiles\4p6tj99m.default\extensions\StrataBuddy@ReduxTeam\components\dwmxpcom.dll
2010-01-13 19:08 . 2010-01-13 19:08 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-13 19:08 . 2010-01-13 19:08 -------- d-----w- c:\users\Jarda62\AppData\Roaming\skypePM
2010-01-13 19:06 . 2010-01-16 16:41 -------- d-----w- c:\users\Jarda62\AppData\Roaming\Skype
2010-01-13 19:05 . 2010-01-13 19:07 -------- d-----r- c:\program files\Skype
2010-01-13 19:05 . 2010-01-13 19:05 -------- d-----w- c:\program files\Common Files\Skype
2010-01-13 19:05 . 2010-01-13 19:05 -------- d-----w- c:\programdata\Skype
2010-01-13 14:28 . 2009-10-19 14:10 108544 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 14:28 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-01-12 15:59 . 2010-01-14 20:37 -------- d-----w- c:\program files\SpeedFan
2010-01-12 15:16 . 2010-01-12 15:16 -------- d-----w- c:\windows\Sun
2010-01-10 09:12 . 2010-01-10 09:12 -------- d-----w- c:\users\Jarda62\AppData\Roaming\Nvu
2010-01-10 09:12 . 2010-01-10 09:12 -------- d-----w- c:\program files\Nvu
2010-01-09 11:42 . 2010-01-09 11:42 -------- d-----w- c:\program files\CCleaner
2010-01-08 21:02 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSvix86.sys
2010-01-08 21:02 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSXpx86.sys
2010-01-08 21:02 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\Scxpx86.dll
2010-01-08 21:02 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSxpx86.dll
2010-01-08 21:02 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100106.001\IDSviA64.sys
2010-01-08 20:18 . 2010-01-08 22:23 -------- d-----w- c:\program files\Microsoft Works
2010-01-08 20:18 . 2010-01-08 20:18 -------- d-----w- c:\windows\PCHEALTH
2010-01-08 20:18 . 2010-01-08 20:18 -------- d-----w- c:\program files\Microsoft.NET
2010-01-08 20:16 . 2010-01-08 20:16 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-01-08 20:15 . 2010-01-08 20:15 -------- d-----w- c:\users\Jarda62\AppData\Local\Microsoft Help
2010-01-08 20:15 . 2010-01-13 14:29 -------- d-----w- c:\programdata\Microsoft Help
2010-01-08 20:15 . 2010-01-08 20:15 -------- d-----r- C:\MSOCache
2010-01-08 20:02 . 2010-01-08 20:02 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-08 20:02 . 2010-01-08 20:02 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-08 20:02 . 2010-01-08 20:12 -------- d-----w- c:\users\Jarda62\AppData\Roaming\DAEMON Tools Lite
2010-01-08 20:02 . 2010-01-08 20:02 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-01-07 21:35 . 2010-01-15 19:05 -------- d-----w- c:\users\Jarda62\AppData\Local\Adobe
2010-01-07 21:34 . 2010-01-15 18:53 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-07 18:51 . 2010-01-07 18:51 -------- d-----w- c:\program files\AviSynth 2.5
2010-01-07 18:51 . 2010-01-07 18:51 -------- d-----w- c:\program files\pspvc
2010-01-07 14:08 . 2010-01-07 14:08 -------- d-----w- c:\users\Jarda62\AppData\Roaming\VitySoft
2010-01-07 13:20 . 2010-01-07 13:19 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-07 13:19 . 2010-01-07 13:19 -------- d-----w- c:\program files\Java
2010-01-07 13:19 . 2010-01-16 11:05 -------- d-sh--w- c:\windows\Installer
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\users\Jarda62\AppData\Local\Tific
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\users\Jarda62\AppData\Roaming\Tific
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\users\Jarda62\AppData\Local\Symantec
2010-01-06 13:30 . 2009-10-29 02:31 784752 ----a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\components\coFFPlgn.dll
2010-01-06 13:30 . 2010-01-06 13:30 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-06 13:30 . 2010-01-06 13:39 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\program files\Symantec
2010-01-06 13:30 . 2010-01-06 13:30 965488 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\OCS\hsplayer.dll
2010-01-06 13:30 . 2009-08-30 00:16 164216 ----a-r- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\components\IPSFFPl.dll
2010-01-06 13:30 . 2010-01-12 15:06 -------- d-----w- c:\windows\system32\drivers\NIS
2010-01-06 13:30 . 2010-01-06 13:30 -------- d-----w- c:\program files\Norton Internet Security
2010-01-06 13:29 . 2010-01-06 18:33 -------- d-----w- c:\programdata\Norton
2010-01-06 13:29 . 2010-01-06 13:42 -------- d-----w- c:\programdata\NortonInstaller
2010-01-06 13:29 . 2010-01-06 13:29 -------- d-----w- c:\program files\NortonInstaller
2010-01-05 18:11 . 2010-01-05 18:11 -------- d-----w- c:\program files\RocketDock
2010-01-04 17:43 . 2010-01-04 17:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-04 17:43 . 2010-01-04 17:43 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-04 17:40 . 2009-12-12 14:15 178176 ----a-w- c:\windows\system32\unrar.dll
2010-01-04 17:40 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-04 17:40 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-04 17:40 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-01-04 17:40 . 2010-01-04 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-04 17:40 . 2010-01-05 15:18 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-01-04 17:39 . 2010-01-04 17:39 -------- d-----w- c:\windows\system32\Macromed
2010-01-04 17:13 . 2010-01-15 18:57 84120 ----a-w- c:\users\Jarda62\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-04 16:55 . 2010-01-04 16:55 0 ----a-w- c:\windows\nsreg.dat
2010-01-04 16:55 . 2010-01-04 16:55 -------- d-----w- c:\users\Jarda62\AppData\Local\Mozilla
2010-01-04 16:47 . 2009-09-11 08:36 398336 ----a-w- c:\windows\system32\TVWizudlg.exe
2010-01-04 16:47 . 2009-09-11 08:36 140288 ----a-w- c:\windows\system32\igfxtvcx.dll
2010-01-04 16:47 . 2010-01-04 16:47 -------- d-----w- c:\windows\system32\Lang
2010-01-04 16:47 . 2010-01-04 16:47 -------- d-----w- c:\program files\Intel
2010-01-04 16:45 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-01-04 16:45 . 2010-01-04 16:45 -------- d-----w- c:\windows\system32\x64
2010-01-04 16:45 . 2009-09-11 16:15 1002008 ----a-w- c:\windows\system32\igxpun.exe
2010-01-04 16:45 . 2009-11-02 19:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2010-01-04 16:44 . 2009-10-29 07:22 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-04 16:44 . 2010-01-17 19:39 -------- d-----w- c:\windows\system32\wbem\Performance
2010-01-04 16:43 . 2009-10-02 04:06 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-01-04 16:43 . 2009-09-03 07:04 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
2010-01-04 16:43 . 2009-08-19 07:20 507568 ----a-w- c:\windows\system32\winload.exe
2010-01-04 16:43 . 2009-08-03 05:35 2613248 ----a-w- c:\windows\explorer.exe
2010-01-04 16:43 . 2009-08-29 06:54 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-01-04 16:43 . 2009-08-19 07:20 442920 ----a-w- c:\windows\system32\winresume.exe
2010-01-04 16:43 . 2009-07-30 04:44 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-01-04 16:42 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-01-04 16:32 . 2010-01-04 16:40 -------- d-----w- c:\windows\Panther

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 19:39 . 2009-07-14 08:44 622422 ----a-w- c:\windows\system32\perfh005.dat
2010-01-17 19:39 . 2009-07-14 08:44 118604 ----a-w- c:\windows\system32\perfc005.dat
2010-01-08 20:18 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-01-06 13:30 . 2010-01-06 13:30 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-06 13:30 . 2010-01-06 13:30 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-04 16:50 . 2010-01-04 16:50 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Plocha
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Oblíbené položky
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Šablony
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Nabídka Start
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Dokumenty
2010-01-04 16:40 . 2010-01-04 16:40 -------- d-sh--we c:\programdata\Data aplikací
2009-12-05 04:54 . 2009-12-05 04:54 529456 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHDrvx86.sys
2009-12-05 04:54 . 2009-12-05 04:54 201616 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHRules.dll
2009-12-05 04:54 . 2009-12-05 04:54 1405840 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHEngine.dll
2009-12-05 04:54 . 2009-12-05 04:54 668720 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHDrvx64.sys
2009-12-05 04:54 . 2009-12-05 04:54 610704 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\bbRGen.dll
2009-10-28 22:37 . 2009-10-28 22:37 343088 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-10-28 22:37 . 2009-10-28 22:37 329592 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-10-28 22:37 . 2009-10-28 22:37 811896 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 488312 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-10-28 22:37 . 2009-10-28 22:37 466992 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Infium"="d:\qip infium\infium.exe" [2009-12-26 6025168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-11 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-11 150552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-07 13:20 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

R0 SymDS;Symantec Data Store;c:\windows\System32\drivers\NIS\1101000.013\SymDS.sys [6.1.2010 14:42 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NIS\1101000.013\SymEFA.sys [6.1.2010 14:42 171056]
R1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20091205.001\BHDrvx86.sys [5.12.2009 5:54 529456]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NIS\1101000.013\cchpx86.sys [6.1.2010 14:42 501888]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100116.002\IDSvix86.sys [16.1.2010 19:27 343088]
R1 SymIRON;Symantec Iron Driver;c:\windows\System32\drivers\NIS\1101000.013\Ironx86.sys [6.1.2010 14:42 114736]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\drivers\NIS\1101000.013\symtdiv.sys [6.1.2010 14:42 339504]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe [6.1.2010 14:42 126392]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [13.10.2009 2:16 49152]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6.1.2010 14:37 102448]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [8.1.2010 21:02 691696]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\System32\drivers\libusb0.sys [16.1.2010 11:45 29184]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\Get Styles\ct.htm
FF - ProfilePath - c:\users\Jarda62\AppData\Roaming\Mozilla\Firefox\Profiles\4p6tj99m.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - component: c:\users\Jarda62\AppData\Roaming\Mozilla\Firefox\Profiles\4p6tj99m.default\extensions\StrataBuddy@ReduxTeam\components\dwmxpcom.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.1.0.19\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.1.0.19\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2010-01-17 21:31:50
ComboFix-quarantined-files.txt 2010-01-17 20:31
ComboFix2.txt 2010-01-17 19:43

Před spuštěním: Volných bajtů: 23 953 326 080
Po spuštění: Volných bajtů: 23 908 368 384

- - End Of File - - 48EA84B3E8D390C259C7666BA3A650A3

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu

#8 Příspěvek od Rudy »

Log vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jarda62
Návštěvník
Návštěvník
Příspěvky: 170
Registrován: 28 črc 2008 17:59

Re: Prosím o kontrolu

#9 Příspěvek od Jarda62 »

OK Díky

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu

#10 Příspěvek od Rudy »

Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět