
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Virus cez YouTube , Flash Player upgrate
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Virus cez YouTube , Flash Player upgrate
som jeden z debilov ktory to sitahlo prosim o pomoc log je tu:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomas at 2011-07-25 01:28:09
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (62%) free of 100 GB
Total RAM: 4095 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:28:12, on 25. 7. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Windows\l1rezerv.exe
C:\Windows\systemup.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Tomas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.splashtop.com/asusexpress ... pe%3DWEB01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [37757.exe] "C:\Windows\Temp\37757.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [186233.exe] "C:\Users\Tomas\AppData\Local\Temp\186233.exe"
O4 - HKLM\..\Run: [9250426.exe] "C:\Windows\Temp\9250426.exe"
O4 - HKLM\..\Run: [7318937.exe] "C:\Windows\Temp\7318937.exe"
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [95047160-loader2.exe] "C:\Windows\Temp\95047160-loader2.exe"
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-8-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\Windows\update.tray-7-0\svchost.exe
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (file missing)
O23 - Service: Avira AntiVir Guard (AntiVirService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (file missing)
O23 - Service: ASDR - Unknown owner - C:\Windows\SysWOW64\ASDR.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 12608 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k Akamai
"taskhost.exe"
C:\Windows\SysWOW64\ASDR.exe
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {6B581A33-824E-4AF5-AAAB-56B846240A21}
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
C:\Windows\Explorer.EXE
C:\Windows\update.5.0\svchost.exe srv
C:\Windows\update.2\svchost.exe srv
"C:\Windows\update.5.0\svchost.exe" stand
"C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
C:\Windows\sysdriver32.exe srv
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\update.1\svchost.exe srv
WLIDSvcM.exe 2308
"C:\Windows\update.2\svchost.exe" stand
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Windows\l1rezerv.exe"
"C:\Windows\systemup.exe" stand
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\ufa\ufa.exe -o http://127.0.0.1:32434 -g no
\??\C:\Windows\system32\conhost.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"D:\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default
prefs.js - "browser.startup.homepage" - "google.sk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
FlashGet3.xpi
flashplayer.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
np32dsw.dll
npdeployJava1.dll
ShockwavePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\extensions\
battlefieldheroespatcher@ea.com
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\searchplugins\
daemon-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-23 115072]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01 1144072]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01 1144072]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"=C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [2010-07-22 2636800]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2011-05-23 399736]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-06-15 15141768]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2011-06-24 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast]
C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tray_ico0]
C:\Windows\update.tray-8-0\svchost.exe [2011-07-24 1174016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tray_ico1]
C:\Windows\update.tray-7-0\svchost.exe [2011-07-24 1174016]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-05-24 2439072]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2010-03-05 411864]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-09-30 98304]
"wxpdrv"=C:\Windows\services32.exe [2011-07-24 1174016]
"tray_ico"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"37757.exe"=C:\Windows\Temp\37757.exe [2011-07-24 247296]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-24 247296]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-24 247296]
"186233.exe"=C:\Users\Tomas\AppData\Local\Temp\186233.exe [2011-07-24 247296]
"9250426.exe"=C:\Windows\Temp\9250426.exe [2011-07-24 247296]
"7318937.exe"=C:\Windows\Temp\7318937.exe [2011-07-24 495616]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-24 232960]
"systemup"=C:\Windows\systemup.exe [2011-07-24 114176]
"95047160-loader2.exe"=C:\Windows\Temp\95047160-loader2.exe [2011-07-24 247296]
"tray_ico0"=C:\Windows\update.tray-8-0\svchost.exe [2011-07-24 1174016]
"tray_ico1"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-24 1174016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"D:\Downloads\Flash-Player.exe"="D:\Downloads\Flash-Player.exe:*:Enabled:D:\Downloads\Flash-Player.exe"
"C:\Windows\update.1\svchost.exe"="C:\Windows\update.1\svchost.exe:*:Enabled:C:\Windows\update.1\svchost.exe"
"C:\Windows\services32.exe"="C:\Windows\services32.exe:*:Enabled:C:\Windows\services32.exe"
"C:\Windows\update.tray-8-0\svchost.exe"="C:\Windows\update.tray-8-0\svchost.exe:*:Enabled:C:\Windows\update.tray-8-0\svchost.exe"
"C:\Windows\update.2\svchost.exe"="C:\Windows\update.2\svchost.exe:*:Enabled:C:\Windows\update.2\svchost.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-25 01:03:54 ----D---- C:\Program Files\CCleaner
2011-07-25 00:32:52 ----D---- C:\rsit
2011-07-25 00:32:52 ----D---- C:\Program Files\trend micro
2011-07-24 20:42:23 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-24 20:42:23 ----HD---- C:\Windows\update.tray-7-0
2011-07-24 20:40:52 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-07-24 20:40:51 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-07-24 20:40:47 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-07-24 20:40:46 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-07-24 20:40:46 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-07-24 20:40:44 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-07-24 20:40:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-07-24 20:40:36 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-07-24 20:40:36 ----A---- C:\Windows\avastSS.scr
2011-07-24 20:31:37 ----D---- C:\Windows\ufa
2011-07-24 20:31:37 ----D---- C:\Windows\rpcminer
2011-07-24 20:31:37 ----D---- C:\Windows\phoenix
2011-07-24 20:30:51 ----A---- C:\Windows\unrar.exe
2011-07-24 20:30:23 ----A---- C:\Windows\ddh_iplist.txt
2011-07-24 20:30:05 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-24 20:30:05 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-24 20:28:22 ----A---- C:\Windows\systemup.exe
2011-07-24 20:28:08 ----HD---- C:\Windows\update.5.0
2011-07-24 20:28:07 ----A---- C:\Windows\l1rezerv.exe
2011-07-24 20:27:56 ----HD---- C:\Windows\update.2
2011-07-24 20:27:43 ----A---- C:\Windows\iplist.txt
2011-07-24 20:27:35 ----A---- C:\Windows\sysdriver32_.exe
2011-07-24 20:27:21 ----A---- C:\Windows\sysdriver32.exe
2011-07-24 20:27:13 ----D---- C:\Windows\av_ico
2011-07-24 20:27:04 ----A---- C:\Windows\front_ip_list.txt
2011-07-24 20:25:55 ----HD---- C:\Windows\update.1
2011-07-24 20:25:53 ----HD---- C:\Windows\update.tray-8-0-lnk
2011-07-24 20:25:53 ----HD---- C:\Windows\update.tray-8-0
2011-07-24 20:14:40 ----A---- C:\Windows\winlog-ids.txt
2011-07-24 20:14:40 ----A---- C:\Windows\winlog-dirs.txt
2011-07-24 20:14:37 ----A---- C:\Windows\services32.exe
2011-07-21 22:54:17 ----D---- C:\ProgramData\ATI
2011-07-21 22:44:10 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2011-07-21 22:44:10 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2011-07-21 22:43:58 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2011-07-21 22:43:29 ----A---- C:\Windows\system32\atig6txx.dll
2011-07-21 22:43:19 ----A---- C:\Windows\system32\atieclxx.exe
2011-07-21 22:43:09 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2011-07-21 22:43:08 ----A---- C:\Windows\SYSWOW64\atipdlxx.dll
2011-07-21 22:42:47 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2011-07-21 22:42:47 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2011-07-21 22:42:26 ----A---- C:\Windows\system32\atio6axx.dll
2011-07-21 22:42:18 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2011-07-21 22:42:18 ----A---- C:\Windows\system32\atipblag.dat
2011-07-21 22:42:09 ----A---- C:\Windows\system32\atiumd64.dll
2011-07-21 22:42:04 ----A---- C:\Windows\SYSWOW64\Oemdspif.dll
2011-07-21 22:42:01 ----A---- C:\Windows\system32\atiumd6a.dll
2011-07-21 22:42:01 ----A---- C:\Windows\system32\ATIODE.exe
2011-07-21 22:41:48 ----A---- C:\Windows\system32\atiedu64.dll
2011-07-21 22:40:41 ----A---- C:\Windows\system32\aticaldd64.dll
2011-07-21 22:40:40 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2011-07-21 22:40:30 ----A---- C:\Windows\system32\atiapfxx.exe
2011-07-21 22:40:26 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2011-07-21 22:40:14 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2011-07-21 22:40:12 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2011-07-21 22:40:01 ----A---- C:\Windows\system32\atiicdxx.dat
2011-07-21 22:39:52 ----A---- C:\Windows\system32\atimpc64.dll
2011-07-21 22:39:52 ----A---- C:\Windows\system32\amdpcom64.dll
2011-07-21 22:39:41 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2011-07-21 22:39:39 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2011-07-21 22:39:39 ----A---- C:\Windows\system32\atipdl64.dll
2011-07-21 22:39:36 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2011-07-21 22:39:36 ----A---- C:\Windows\system32\atiglpxx.dll
2011-07-21 22:39:29 ----A---- C:\Windows\system32\ATIODCLI.exe
2011-07-21 22:39:25 ----A---- C:\Windows\system32\ATIDEMGX.dll
2011-07-21 22:39:13 ----A---- C:\Windows\system32\aticalrt64.dll
2011-07-21 22:38:55 ----A---- C:\Windows\system32\atiumd6v.dll
2011-07-21 22:38:31 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2011-07-21 22:38:01 ----A---- C:\Windows\system32\atig6pxx.dll
2011-07-21 22:37:53 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2011-07-21 22:37:53 ----A---- C:\Windows\system32\aticalcl64.dll
2011-07-21 22:37:44 ----A---- C:\Windows\system32\atimuixx.dll
2011-07-21 22:36:44 ----A---- C:\Windows\system32\atiesrxx.exe
2011-07-21 22:36:29 ----A---- C:\Windows\system32\atiu9p64.dll
2011-07-21 22:36:22 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2011-07-21 22:34:29 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2011-07-21 22:34:25 ----A---- C:\Windows\system32\atitmm64.dll
2011-07-21 17:46:18 ----A---- C:\Windows\system32\drivers\AtihdW76.sys
2011-07-20 07:05:57 ----A---- C:\Windows\system32\drivers\IOMap64.sys
2011-07-20 07:03:28 ----A---- C:\Windows\system32\drivers\EIO64.sys
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\url.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\wininet.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\wextract.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\webcheck.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\vbscript.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\urlmon.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\url.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\occache.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msrating.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msls31.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshtml.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshta.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\jscript9.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\jscript.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\inseng.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\imgutil.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iexpress.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iesetup.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iertutil.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iernonce.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iepeers.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieframe.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieapfltr.dat
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieakui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\icardie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\admparse.dll
2011-07-19 13:09:41 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\XpsPrint.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\FntCache.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-07-19 13:09:41 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-07-19 13:09:41 ----A---- C:\Windows\system32\d3d10warp.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\d3d10_1.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\cdd.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-07-19 13:09:40 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-07-19 13:09:40 ----A---- C:\Windows\system32\DWrite.dll
2011-07-19 13:09:40 ----A---- C:\Windows\system32\d2d1.dll
2011-07-16 02:16:45 ----D---- C:\Users\Tomas\AppData\Roaming\Teeworlds
2011-07-14 00:51:14 ----D---- C:\Users\Tomas\AppData\Roaming\vlc
2011-07-14 00:48:26 ----D---- C:\Program Files (x86)\VideoLAN
2011-07-14 00:43:58 ----D---- C:\Windows\sk
2011-07-14 00:37:33 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-07-14 00:30:59 ----DC---- C:\Windows\system32\DRVSTORE
2011-07-14 00:30:59 ----D---- C:\Program Files (x86)\Windows Live
2011-07-14 00:30:59 ----A---- C:\Windows\system32\drivers\fssfltr.sys
2011-07-14 00:29:37 ----D---- C:\Program Files\Windows Live
2011-07-14 00:28:49 ----D---- C:\Program Files (x86)\Microsoft
2011-07-14 00:26:34 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2011-07-14 00:26:34 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2011-07-14 00:26:34 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-07-14 00:26:34 ----A---- C:\Windows\system32\UIRibbon.dll
2011-07-14 00:26:03 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-07-14 00:26:03 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-07-14 00:26:03 ----A---- C:\Windows\system32\mfps.dll
2011-07-14 00:26:02 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-07-14 00:26:02 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-07-14 00:26:02 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-07-14 00:26:02 ----A---- C:\Windows\system32\mf.dll
2011-07-12 18:19:50 ----D---- C:\Users\Tomas\AppData\Roaming\ts3overlay
2011-07-12 18:15:44 ----D---- C:\Users\Tomas\AppData\Roaming\TS3Client
2011-07-10 17:09:20 ----D---- C:\Program Files (x86)\Microsoft Games
2011-06-27 19:45:10 ----D---- C:\Users\Tomas\AppData\Roaming\Zoner
2011-06-27 19:44:52 ----D---- C:\Program Files (x86)\Zoner
======List of files/folders modified in the last 1 month======
2011-07-25 01:28:13 ----D---- C:\Windows\Temp
2011-07-25 01:12:40 ----D---- C:\Windows
2011-07-25 01:08:25 ----D---- C:\Users\Tomas\AppData\Roaming\DAEMON Tools Lite
2011-07-25 01:08:24 ----D---- C:\Program Files (x86)\Steam
2011-07-25 01:08:23 ----D---- C:\Users\Tomas\AppData\Roaming\uTorrent
2011-07-25 01:08:23 ----D---- C:\Users\Tomas\AppData\Roaming\Skype
2011-07-25 01:06:01 ----D---- C:\Windows\Logs
2011-07-25 01:06:01 ----D---- C:\Windows\debug
2011-07-25 01:03:54 ----RD---- C:\Program Files
2011-07-25 00:53:01 ----D---- C:\Windows\system32\catroot
2011-07-25 00:52:56 ----RD---- C:\Program Files (x86)
2011-07-25 00:52:56 ----HD---- C:\ProgramData
2011-07-25 00:07:09 ----SHD---- C:\Windows\Installer
2011-07-25 00:07:09 ----D---- C:\Program Files (x86)\Common Files
2011-07-25 00:07:00 ----D---- C:\Windows\SysWOW64
2011-07-25 00:06:46 ----SHD---- C:\System Volume Information
2011-07-24 20:58:29 ----D---- C:\Windows\SYSWOW64\Macromed
2011-07-24 20:40:52 ----D---- C:\Windows\system32\drivers
2011-07-24 20:40:44 ----D---- C:\Windows\System32
2011-07-24 20:29:14 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-07-24 20:28:18 ----D---- C:\Windows\system32\drivers\etc
2011-07-24 20:14:49 ----D---- C:\Windows\system32\config
2011-07-23 16:56:45 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-07-22 11:38:29 ----SD---- C:\Users\Tomas\AppData\Roaming\Microsoft
2011-07-21 22:54:06 ----D---- C:\Program Files\ATI Technologies
2011-07-21 22:53:17 ----RSD---- C:\Windows\assembly
2011-07-21 22:52:56 ----D---- C:\Windows\system32\DriverStore
2011-07-21 22:52:56 ----D---- C:\Windows\inf
2011-07-21 22:44:10 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2011-07-21 22:43:52 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2011-07-21 22:43:15 ----A---- C:\Windows\system32\atidxx64.dll
2011-07-21 22:43:03 ----A---- C:\Windows\system32\atiuxp64.dll
2011-07-21 22:41:21 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2011-07-21 22:39:22 ----A---- C:\Windows\system32\coinst.dll
2011-07-21 22:38:31 ----A---- C:\Windows\system32\atiadlxx.dll
2011-07-21 22:34:27 ----A---- C:\Windows\system32\aticfx64.dll
2011-07-20 22:46:19 ----D---- C:\Windows\system32\catroot2
2011-07-20 20:02:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-20 07:04:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-07-20 07:03:58 ----D---- C:\Program Files (x86)\ASUS
2011-07-19 23:38:07 ----D---- C:\Windows\Downloaded Program Files
2011-07-19 21:27:07 ----D---- C:\Downloads
2011-07-19 13:19:02 ----D---- C:\Windows\winsxs
2011-07-19 13:17:08 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-07-19 13:17:08 ----D---- C:\Windows\system32\sk-SK
2011-07-19 13:17:08 ----D---- C:\Program Files\Internet Explorer
2011-07-19 13:17:08 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-19 13:17:07 ----D---- C:\Windows\SYSWOW64\migration
2011-07-19 13:17:07 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-19 13:17:07 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-07-19 13:17:05 ----D---- C:\Windows\system32\migration
2011-07-19 13:17:05 ----D---- C:\Windows\system32\en-US
2011-07-19 13:17:05 ----D---- C:\Windows\system32\cs-CZ
2011-07-19 13:17:05 ----D---- C:\Windows\PolicyDefinitions
2011-07-18 19:29:05 ----D---- C:\Windows\Prefetch
2011-07-14 12:46:58 ----D---- C:\Windows\Microsoft.NET
2011-07-14 00:39:54 ----D---- C:\Users\Tomas\AppData\Roaming\DivX
2011-07-14 00:33:54 ----D---- C:\Windows\system32\Tasks
2011-07-14 00:33:26 ----SD---- C:\ProgramData\Microsoft
2011-07-14 00:29:58 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-07-14 00:26:15 ----D---- C:\Windows\SoftwareDistribution
2011-07-11 10:18:14 ----D---- C:\Program Files (x86)\FlashGet
2011-07-10 16:43:23 ----D---- C:\ProgramData\DivX
2011-07-10 16:43:23 ----D---- C:\Program Files (x86)\DivX
2011-06-26 00:35:28 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2010-04-08 244328]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-06-17 116568]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-22 254528]
R1 EIO64;EIO Driver; C:\Windows\system32\DRIVERS\EIO64.sys [2011-07-20 16384]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-06-17 83120]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-21 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-21 309760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-08-16 116240]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys [2010-03-04 349416]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-05-15 1327520]
R4 IOMap;IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [2010-02-22 23680]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-11-18 123408]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 X6va005;X6va005; \??\C:\Users\Tomas\AppData\Local\Temp\005F132.tmp []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-21 204288]
R2 ASDR;ASDR; C:\Windows\SysWOW64\ASDR.exe [2009-07-27 61440]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2010-01-21 496232]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2010-01-21 209000]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-05-29 75136]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-03-28 249648]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-24 340992]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-24 495616]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-24 247296]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-24 1174016]
S2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe []
S2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-07-14 411432]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomas at 2011-07-25 01:28:09
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (62%) free of 100 GB
Total RAM: 4095 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:28:12, on 25. 7. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Windows\l1rezerv.exe
C:\Windows\systemup.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Tomas.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.splashtop.com/asusexpress ... pe%3DWEB01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [37757.exe] "C:\Windows\Temp\37757.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [186233.exe] "C:\Users\Tomas\AppData\Local\Temp\186233.exe"
O4 - HKLM\..\Run: [9250426.exe] "C:\Windows\Temp\9250426.exe"
O4 - HKLM\..\Run: [7318937.exe] "C:\Windows\Temp\7318937.exe"
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [95047160-loader2.exe] "C:\Windows\Temp\95047160-loader2.exe"
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-8-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\Windows\update.tray-7-0\svchost.exe
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (file missing)
O23 - Service: Avira AntiVir Guard (AntiVirService) - Unknown owner - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (file missing)
O23 - Service: ASDR - Unknown owner - C:\Windows\SysWOW64\ASDR.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 12608 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k Akamai
"taskhost.exe"
C:\Windows\SysWOW64\ASDR.exe
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {6B581A33-824E-4AF5-AAAB-56B846240A21}
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
C:\Windows\Explorer.EXE
C:\Windows\update.5.0\svchost.exe srv
C:\Windows\update.2\svchost.exe srv
"C:\Windows\update.5.0\svchost.exe" stand
"C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
C:\Windows\sysdriver32.exe srv
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\update.1\svchost.exe srv
WLIDSvcM.exe 2308
"C:\Windows\update.2\svchost.exe" stand
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Windows\l1rezerv.exe"
"C:\Windows\systemup.exe" stand
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\ufa\ufa.exe -o http://127.0.0.1:32434 -g no
\??\C:\Windows\system32\conhost.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"D:\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default
prefs.js - "browser.startup.homepage" - "google.sk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
FlashGet3.xpi
flashplayer.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
np32dsw.dll
npdeployJava1.dll
ShockwavePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\extensions\
battlefieldheroespatcher@ea.com
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\searchplugins\
daemon-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-23 115072]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2011-05-13 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01 1144072]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-04-01 1144072]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"=C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [2010-07-22 2636800]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2011-05-23 399736]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-06-15 15141768]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2011-06-24 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast]
C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tray_ico0]
C:\Windows\update.tray-8-0\svchost.exe [2011-07-24 1174016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tray_ico1]
C:\Windows\update.tray-7-0\svchost.exe [2011-07-24 1174016]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-05-24 2439072]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2010-03-05 411864]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-09-30 98304]
"wxpdrv"=C:\Windows\services32.exe [2011-07-24 1174016]
"tray_ico"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"37757.exe"=C:\Windows\Temp\37757.exe [2011-07-24 247296]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-24 247296]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-24 247296]
"186233.exe"=C:\Users\Tomas\AppData\Local\Temp\186233.exe [2011-07-24 247296]
"9250426.exe"=C:\Windows\Temp\9250426.exe [2011-07-24 247296]
"7318937.exe"=C:\Windows\Temp\7318937.exe [2011-07-24 495616]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-24 232960]
"systemup"=C:\Windows\systemup.exe [2011-07-24 114176]
"95047160-loader2.exe"=C:\Windows\Temp\95047160-loader2.exe [2011-07-24 247296]
"tray_ico0"=C:\Windows\update.tray-8-0\svchost.exe [2011-07-24 1174016]
"tray_ico1"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-24 1174016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"D:\Downloads\Flash-Player.exe"="D:\Downloads\Flash-Player.exe:*:Enabled:D:\Downloads\Flash-Player.exe"
"C:\Windows\update.1\svchost.exe"="C:\Windows\update.1\svchost.exe:*:Enabled:C:\Windows\update.1\svchost.exe"
"C:\Windows\services32.exe"="C:\Windows\services32.exe:*:Enabled:C:\Windows\services32.exe"
"C:\Windows\update.tray-8-0\svchost.exe"="C:\Windows\update.tray-8-0\svchost.exe:*:Enabled:C:\Windows\update.tray-8-0\svchost.exe"
"C:\Windows\update.2\svchost.exe"="C:\Windows\update.2\svchost.exe:*:Enabled:C:\Windows\update.2\svchost.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-25 01:03:54 ----D---- C:\Program Files\CCleaner
2011-07-25 00:32:52 ----D---- C:\rsit
2011-07-25 00:32:52 ----D---- C:\Program Files\trend micro
2011-07-24 20:42:23 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-24 20:42:23 ----HD---- C:\Windows\update.tray-7-0
2011-07-24 20:40:52 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-07-24 20:40:51 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-07-24 20:40:47 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-07-24 20:40:46 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-07-24 20:40:46 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-07-24 20:40:44 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-07-24 20:40:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-07-24 20:40:36 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-07-24 20:40:36 ----A---- C:\Windows\avastSS.scr
2011-07-24 20:31:37 ----D---- C:\Windows\ufa
2011-07-24 20:31:37 ----D---- C:\Windows\rpcminer
2011-07-24 20:31:37 ----D---- C:\Windows\phoenix
2011-07-24 20:30:51 ----A---- C:\Windows\unrar.exe
2011-07-24 20:30:23 ----A---- C:\Windows\ddh_iplist.txt
2011-07-24 20:30:05 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-24 20:30:05 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-24 20:28:22 ----A---- C:\Windows\systemup.exe
2011-07-24 20:28:08 ----HD---- C:\Windows\update.5.0
2011-07-24 20:28:07 ----A---- C:\Windows\l1rezerv.exe
2011-07-24 20:27:56 ----HD---- C:\Windows\update.2
2011-07-24 20:27:43 ----A---- C:\Windows\iplist.txt
2011-07-24 20:27:35 ----A---- C:\Windows\sysdriver32_.exe
2011-07-24 20:27:21 ----A---- C:\Windows\sysdriver32.exe
2011-07-24 20:27:13 ----D---- C:\Windows\av_ico
2011-07-24 20:27:04 ----A---- C:\Windows\front_ip_list.txt
2011-07-24 20:25:55 ----HD---- C:\Windows\update.1
2011-07-24 20:25:53 ----HD---- C:\Windows\update.tray-8-0-lnk
2011-07-24 20:25:53 ----HD---- C:\Windows\update.tray-8-0
2011-07-24 20:14:40 ----A---- C:\Windows\winlog-ids.txt
2011-07-24 20:14:40 ----A---- C:\Windows\winlog-dirs.txt
2011-07-24 20:14:37 ----A---- C:\Windows\services32.exe
2011-07-21 22:54:17 ----D---- C:\ProgramData\ATI
2011-07-21 22:44:10 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2011-07-21 22:44:10 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2011-07-21 22:43:58 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2011-07-21 22:43:29 ----A---- C:\Windows\system32\atig6txx.dll
2011-07-21 22:43:19 ----A---- C:\Windows\system32\atieclxx.exe
2011-07-21 22:43:09 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2011-07-21 22:43:08 ----A---- C:\Windows\SYSWOW64\atipdlxx.dll
2011-07-21 22:42:47 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2011-07-21 22:42:47 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2011-07-21 22:42:26 ----A---- C:\Windows\system32\atio6axx.dll
2011-07-21 22:42:18 ----A---- C:\Windows\SYSWOW64\atipblag.dat
2011-07-21 22:42:18 ----A---- C:\Windows\system32\atipblag.dat
2011-07-21 22:42:09 ----A---- C:\Windows\system32\atiumd64.dll
2011-07-21 22:42:04 ----A---- C:\Windows\SYSWOW64\Oemdspif.dll
2011-07-21 22:42:01 ----A---- C:\Windows\system32\atiumd6a.dll
2011-07-21 22:42:01 ----A---- C:\Windows\system32\ATIODE.exe
2011-07-21 22:41:48 ----A---- C:\Windows\system32\atiedu64.dll
2011-07-21 22:40:41 ----A---- C:\Windows\system32\aticaldd64.dll
2011-07-21 22:40:40 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2011-07-21 22:40:30 ----A---- C:\Windows\system32\atiapfxx.exe
2011-07-21 22:40:26 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2011-07-21 22:40:14 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2011-07-21 22:40:12 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2011-07-21 22:40:01 ----A---- C:\Windows\system32\atiicdxx.dat
2011-07-21 22:39:52 ----A---- C:\Windows\system32\atimpc64.dll
2011-07-21 22:39:52 ----A---- C:\Windows\system32\amdpcom64.dll
2011-07-21 22:39:41 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2011-07-21 22:39:39 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2011-07-21 22:39:39 ----A---- C:\Windows\system32\atipdl64.dll
2011-07-21 22:39:36 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2011-07-21 22:39:36 ----A---- C:\Windows\system32\atiglpxx.dll
2011-07-21 22:39:29 ----A---- C:\Windows\system32\ATIODCLI.exe
2011-07-21 22:39:25 ----A---- C:\Windows\system32\ATIDEMGX.dll
2011-07-21 22:39:13 ----A---- C:\Windows\system32\aticalrt64.dll
2011-07-21 22:38:55 ----A---- C:\Windows\system32\atiumd6v.dll
2011-07-21 22:38:31 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2011-07-21 22:38:01 ----A---- C:\Windows\system32\atig6pxx.dll
2011-07-21 22:37:53 ----A---- C:\Windows\SYSWOW64\atiumdmv.dll
2011-07-21 22:37:53 ----A---- C:\Windows\system32\aticalcl64.dll
2011-07-21 22:37:44 ----A---- C:\Windows\system32\atimuixx.dll
2011-07-21 22:36:44 ----A---- C:\Windows\system32\atiesrxx.exe
2011-07-21 22:36:29 ----A---- C:\Windows\system32\atiu9p64.dll
2011-07-21 22:36:22 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2011-07-21 22:34:29 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2011-07-21 22:34:25 ----A---- C:\Windows\system32\atitmm64.dll
2011-07-21 17:46:18 ----A---- C:\Windows\system32\drivers\AtihdW76.sys
2011-07-20 07:05:57 ----A---- C:\Windows\system32\drivers\IOMap64.sys
2011-07-20 07:03:28 ----A---- C:\Windows\system32\drivers\EIO64.sys
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-07-19 13:13:44 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\url.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-07-19 13:13:43 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\wininet.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\wextract.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\webcheck.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\vbscript.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\urlmon.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\url.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\occache.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msrating.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msls31.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshtml.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\mshta.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\jscript9.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\jscript.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\inseng.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\imgutil.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iexpress.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iesetup.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iertutil.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iernonce.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iepeers.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieframe.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieapfltr.dat
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieakui.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-19 13:13:43 ----A---- C:\Windows\system32\icardie.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-19 13:13:43 ----A---- C:\Windows\system32\admparse.dll
2011-07-19 13:09:41 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\XpsPrint.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\FntCache.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-07-19 13:09:41 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-07-19 13:09:41 ----A---- C:\Windows\system32\d3d10warp.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\d3d10_1.dll
2011-07-19 13:09:41 ----A---- C:\Windows\system32\cdd.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-07-19 13:09:40 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-07-19 13:09:40 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-07-19 13:09:40 ----A---- C:\Windows\system32\DWrite.dll
2011-07-19 13:09:40 ----A---- C:\Windows\system32\d2d1.dll
2011-07-16 02:16:45 ----D---- C:\Users\Tomas\AppData\Roaming\Teeworlds
2011-07-14 00:51:14 ----D---- C:\Users\Tomas\AppData\Roaming\vlc
2011-07-14 00:48:26 ----D---- C:\Program Files (x86)\VideoLAN
2011-07-14 00:43:58 ----D---- C:\Windows\sk
2011-07-14 00:37:33 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-07-14 00:30:59 ----DC---- C:\Windows\system32\DRVSTORE
2011-07-14 00:30:59 ----D---- C:\Program Files (x86)\Windows Live
2011-07-14 00:30:59 ----A---- C:\Windows\system32\drivers\fssfltr.sys
2011-07-14 00:29:37 ----D---- C:\Program Files\Windows Live
2011-07-14 00:28:49 ----D---- C:\Program Files (x86)\Microsoft
2011-07-14 00:26:34 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2011-07-14 00:26:34 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2011-07-14 00:26:34 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-07-14 00:26:34 ----A---- C:\Windows\system32\UIRibbon.dll
2011-07-14 00:26:03 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-07-14 00:26:03 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-07-14 00:26:03 ----A---- C:\Windows\system32\mfps.dll
2011-07-14 00:26:02 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-07-14 00:26:02 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-07-14 00:26:02 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-07-14 00:26:02 ----A---- C:\Windows\system32\mf.dll
2011-07-12 18:19:50 ----D---- C:\Users\Tomas\AppData\Roaming\ts3overlay
2011-07-12 18:15:44 ----D---- C:\Users\Tomas\AppData\Roaming\TS3Client
2011-07-10 17:09:20 ----D---- C:\Program Files (x86)\Microsoft Games
2011-06-27 19:45:10 ----D---- C:\Users\Tomas\AppData\Roaming\Zoner
2011-06-27 19:44:52 ----D---- C:\Program Files (x86)\Zoner
======List of files/folders modified in the last 1 month======
2011-07-25 01:28:13 ----D---- C:\Windows\Temp
2011-07-25 01:12:40 ----D---- C:\Windows
2011-07-25 01:08:25 ----D---- C:\Users\Tomas\AppData\Roaming\DAEMON Tools Lite
2011-07-25 01:08:24 ----D---- C:\Program Files (x86)\Steam
2011-07-25 01:08:23 ----D---- C:\Users\Tomas\AppData\Roaming\uTorrent
2011-07-25 01:08:23 ----D---- C:\Users\Tomas\AppData\Roaming\Skype
2011-07-25 01:06:01 ----D---- C:\Windows\Logs
2011-07-25 01:06:01 ----D---- C:\Windows\debug
2011-07-25 01:03:54 ----RD---- C:\Program Files
2011-07-25 00:53:01 ----D---- C:\Windows\system32\catroot
2011-07-25 00:52:56 ----RD---- C:\Program Files (x86)
2011-07-25 00:52:56 ----HD---- C:\ProgramData
2011-07-25 00:07:09 ----SHD---- C:\Windows\Installer
2011-07-25 00:07:09 ----D---- C:\Program Files (x86)\Common Files
2011-07-25 00:07:00 ----D---- C:\Windows\SysWOW64
2011-07-25 00:06:46 ----SHD---- C:\System Volume Information
2011-07-24 20:58:29 ----D---- C:\Windows\SYSWOW64\Macromed
2011-07-24 20:40:52 ----D---- C:\Windows\system32\drivers
2011-07-24 20:40:44 ----D---- C:\Windows\System32
2011-07-24 20:29:14 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-07-24 20:28:18 ----D---- C:\Windows\system32\drivers\etc
2011-07-24 20:14:49 ----D---- C:\Windows\system32\config
2011-07-23 16:56:45 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-07-22 11:38:29 ----SD---- C:\Users\Tomas\AppData\Roaming\Microsoft
2011-07-21 22:54:06 ----D---- C:\Program Files\ATI Technologies
2011-07-21 22:53:17 ----RSD---- C:\Windows\assembly
2011-07-21 22:52:56 ----D---- C:\Windows\system32\DriverStore
2011-07-21 22:52:56 ----D---- C:\Windows\inf
2011-07-21 22:44:10 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2011-07-21 22:43:52 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2011-07-21 22:43:15 ----A---- C:\Windows\system32\atidxx64.dll
2011-07-21 22:43:03 ----A---- C:\Windows\system32\atiuxp64.dll
2011-07-21 22:41:21 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2011-07-21 22:39:22 ----A---- C:\Windows\system32\coinst.dll
2011-07-21 22:38:31 ----A---- C:\Windows\system32\atiadlxx.dll
2011-07-21 22:34:27 ----A---- C:\Windows\system32\aticfx64.dll
2011-07-20 22:46:19 ----D---- C:\Windows\system32\catroot2
2011-07-20 20:02:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-20 07:04:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-07-20 07:03:58 ----D---- C:\Program Files (x86)\ASUS
2011-07-19 23:38:07 ----D---- C:\Windows\Downloaded Program Files
2011-07-19 21:27:07 ----D---- C:\Downloads
2011-07-19 13:19:02 ----D---- C:\Windows\winsxs
2011-07-19 13:17:08 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-07-19 13:17:08 ----D---- C:\Windows\system32\sk-SK
2011-07-19 13:17:08 ----D---- C:\Program Files\Internet Explorer
2011-07-19 13:17:08 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-19 13:17:07 ----D---- C:\Windows\SYSWOW64\migration
2011-07-19 13:17:07 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-19 13:17:07 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-07-19 13:17:05 ----D---- C:\Windows\system32\migration
2011-07-19 13:17:05 ----D---- C:\Windows\system32\en-US
2011-07-19 13:17:05 ----D---- C:\Windows\system32\cs-CZ
2011-07-19 13:17:05 ----D---- C:\Windows\PolicyDefinitions
2011-07-18 19:29:05 ----D---- C:\Windows\Prefetch
2011-07-14 12:46:58 ----D---- C:\Windows\Microsoft.NET
2011-07-14 00:39:54 ----D---- C:\Users\Tomas\AppData\Roaming\DivX
2011-07-14 00:33:54 ----D---- C:\Windows\system32\Tasks
2011-07-14 00:33:26 ----SD---- C:\ProgramData\Microsoft
2011-07-14 00:29:58 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-07-14 00:26:15 ----D---- C:\Windows\SoftwareDistribution
2011-07-11 10:18:14 ----D---- C:\Program Files (x86)\FlashGet
2011-07-10 16:43:23 ----D---- C:\ProgramData\DivX
2011-07-10 16:43:23 ----D---- C:\Program Files (x86)\DivX
2011-06-26 00:35:28 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2010-04-08 244328]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-06-17 116568]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-22 254528]
R1 EIO64;EIO Driver; C:\Windows\system32\DRIVERS\EIO64.sys [2011-07-20 16384]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-06-17 83120]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-21 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-21 309760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-08-16 116240]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 NVNET;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6264.sys [2010-03-04 349416]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-05-15 1327520]
R4 IOMap;IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [2010-02-22 23680]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-11-18 123408]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 X6va005;X6va005; \??\C:\Users\Tomas\AppData\Local\Temp\005F132.tmp []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-21 204288]
R2 ASDR;ASDR; C:\Windows\SysWOW64\ASDR.exe [2009-07-27 61440]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2010-01-21 496232]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2010-01-21 209000]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-05-29 75136]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-03-28 249648]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-24 340992]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-24 495616]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-24 247296]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-24 1174016]
S2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe []
S2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-07-14 411432]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
Re: Virus cez YouTube , Flash Player upgrate
Zdravim a pekny den preji
Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com
Aplikujte RogueKiller
Jeste znovu RogueKiller ale nyni s moznosti 3 a pote jeste jednou s moznosti 4
RKill i RogueKiller by mely udelat logy, vlozte mi je sem
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe


- Pokud ho havet blokuje, pouzijte jeden z nasledujicich
motji píše: Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr
Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne temer okamzite a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Ted nerestartujte PC - prisli byste o ucinek RKillu

stell píše: pouzijes RogueKiller>.spustis>>stlac 2> [enter] log vloz sem
http://www.viry.cz/forum/viewtopic.php? ... 05#p981205


PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Virus cez YouTube , Flash Player upgrate
Rkill :
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on . 07. 2011 at 16:35:47.
Operating System: Windows 7 Ultimate
Processes terminated by Rkill or while it was running:
Rkill completed on . 07. 2011 at 16:35:57.
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on . 07. 2011 at 16:35:47.
Operating System: Windows 7 Ultimate
Processes terminated by Rkill or while it was running:
Rkill completed on . 07. 2011 at 16:35:57.
Re: Virus cez YouTube , Flash Player upgrate
Roguekiller- RKreport1:
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomas [Admin rights]
Mode: Remove -- Date : 07/25/2011 16:37:02
Bad processes: 5
[SVCHOST] svchost.exe -- c:\windows\update.5.0\svchost.exe -> KILLED
[SUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.2\svchost.exe -> KILLED
[SUSP PATH] l1rezerv.exe -- c:\windows\l1rezerv.exe -> KILLED
[SUSP PATH] systemup.exe -- c:\windows\systemup.exe -> KILLED
Registry Entries: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomas [Admin rights]
Mode: Remove -- Date : 07/25/2011 16:37:02
Bad processes: 5
[SVCHOST] svchost.exe -- c:\windows\update.5.0\svchost.exe -> KILLED
[SUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED
[SVCHOST] svchost.exe -- c:\windows\update.2\svchost.exe -> KILLED
[SUSP PATH] l1rezerv.exe -- c:\windows\l1rezerv.exe -> KILLED
[SUSP PATH] systemup.exe -- c:\windows\systemup.exe -> KILLED
Registry Entries: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
Re: Virus cez YouTube , Flash Player upgrate
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomas [Admin rights]
Mode: HOSTSFix -- Date : 07/25/2011 16:37:13
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomas [Admin rights]
Mode: HOSTSFix -- Date : 07/25/2011 16:37:13
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Re: Virus cez YouTube , Flash Player upgrate
RogueKiller-RKreport 3:
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomas [Admin rights]
Mode: ProxyFix -- Date : 07/25/2011 16:37:44
Bad processes: 0
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
P.S. Este som nepouzil ten Combofix pretoze pretym ste mali napisane ze mam vlozit Logy z Rkill a RogueKiller, tak racej pockam co nato poviete.
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Tomas [Admin rights]
Mode: ProxyFix -- Date : 07/25/2011 16:37:44
Bad processes: 0
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
P.S. Este som nepouzil ten Combofix pretoze pretym ste mali napisane ze mam vlozit Logy z Rkill a RogueKiller, tak racej pockam co nato poviete.

Re: Virus cez YouTube , Flash Player upgrate
Fajn, vrhnete se na ComboFix 

Re: Virus cez YouTube , Flash Player upgrate
ComboFix :
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.4095.2782 [GMT 2:00]
Running from: c:\users\Tomas\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tomas\AppData\Roaming\BITS
c:\users\Tomas\AppData\Roaming\BITS\BITS.ini
c:\users\Tomas\AppData\Roaming\BITS\P2PCfg.ini
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\services32.exe
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\systemup.exe
c:\windows\Temp\37757.exe
c:\windows\TEMP\5490510.exe
c:\windows\Temp\95047160-loader2.exe
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\update.tray-7-0\svchost.exe
c:\windows\update.tray-8-0\svchost.exe
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Service_srvbtcclient
-------\Service_srvbtcclient
.
.
((((((((((((((((((((((((( Files Created from 2011-06-25 to 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-25 15:29 . 2011-07-25 15:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-25 15:25 . 2011-07-25 15:25 -------- d-----w- C:\32788R22FWJFW
2011-07-24 23:03 . 2011-07-24 23:03 -------- d-----w- c:\program files\CCleaner
2011-07-24 22:32 . 2011-07-25 14:28 -------- d-----w- c:\program files\trend micro
2011-07-24 22:32 . 2011-07-24 22:33 -------- d-----w- C:\rsit
2011-07-24 18:42 . 2011-07-25 15:29 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-24 18:42 . 2011-07-24 18:42 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-07-24 18:40 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 18:40 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 18:40 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 18:40 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 18:40 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 18:40 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-24 18:40 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 18:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 18:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-24 18:31 . 2011-07-24 18:31 -------- d-----w- c:\windows\ufa
2011-07-24 18:31 . 2011-07-24 18:31 -------- d-----w- c:\windows\rpcminer
2011-07-24 18:31 . 2011-07-24 18:31 -------- d-----w- c:\windows\phoenix
2011-07-24 18:30 . 2011-07-24 18:31 246272 ----a-w- c:\windows\unrar.exe
2011-07-24 18:27 . 2011-07-24 18:43 -------- d-----w- c:\windows\av_ico
2011-07-24 18:25 . 2011-07-25 15:29 -------- d--h--w- c:\windows\update.tray-8-0
2011-07-24 18:25 . 2011-07-24 18:25 -------- d--h--w- c:\windows\update.tray-8-0-lnk
2011-07-23 14:56 . 2011-07-23 14:56 476904 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-07-21 20:54 . 2011-07-21 20:54 -------- d-----w- c:\programdata\ATI
2011-07-21 20:44 . 2011-07-21 20:44 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-21 20:44 . 2011-07-21 20:44 262144 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-07-21 20:43 . 2011-07-21 20:44 4219904 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-07-21 20:43 . 2011-07-21 20:43 39936 ----a-w- c:\windows\system32\atig6txx.dll
2011-07-21 20:43 . 2011-07-21 20:43 485376 ----a-w- c:\windows\system32\atieclxx.exe
2011-07-21 20:43 . 2011-07-21 20:43 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-07-21 20:43 . 2011-07-21 20:43 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\atimpc32.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2011-07-21 20:42 . 2011-07-21 20:45 23336960 ----a-w- c:\windows\system32\atio6axx.dll
2011-07-21 20:42 . 2011-07-21 20:43 5486592 ----a-w- c:\windows\system32\atiumd64.dll
2011-07-21 20:42 . 2011-07-21 20:42 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-07-21 20:39 . 2011-07-21 20:39 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
2011-07-21 20:39 . 2011-07-21 20:39 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2011-07-21 20:38 . 2011-07-21 20:39 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2011-07-21 20:38 . 2011-07-21 20:40 9359872 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-07-21 20:38 . 2011-07-21 20:38 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2011-07-21 20:37 . 2011-07-21 20:38 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2011-07-21 20:37 . 2011-07-21 20:38 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2011-07-21 20:37 . 2011-07-21 20:37 16384 ----a-w- c:\windows\system32\atimuixx.dll
2011-07-21 20:36 . 2011-07-21 20:37 204288 ----a-w- c:\windows\system32\atiesrxx.exe
2011-07-21 20:36 . 2011-07-21 20:36 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-07-21 20:36 . 2011-07-21 20:36 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-07-21 20:34 . 2011-07-21 20:35 6847488 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-07-21 20:34 . 2011-07-21 20:34 120320 ----a-w- c:\windows\system32\atitmm64.dll
2011-07-21 15:46 . 2010-08-16 04:42 116240 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2011-07-20 05:05 . 2010-02-22 13:46 23680 ----a-w- c:\windows\system32\drivers\IOMap64.sys
2011-07-20 05:03 . 2011-07-20 05:03 16384 ----a-w- c:\windows\system32\drivers\EIO64.sys
2011-07-19 21:38 . 2003-08-15 14:02 69632 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe
2011-07-19 21:38 . 2003-08-15 14:01 380928 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2011-07-19 21:38 . 2003-08-15 13:57 212992 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
2011-07-19 20:29 . 2011-07-19 20:29 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2011-07-19 20:29 . 2003-09-03 00:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2011-07-19 20:29 . 2003-09-03 00:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2011-07-19 20:29 . 2003-09-03 00:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2011-07-19 20:29 . 2003-09-03 00:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2011-07-19 20:29 . 2003-09-03 00:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2011-07-19 20:29 . 2003-09-03 00:23 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-07-19 20:29 . 2011-07-19 20:29 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2011-07-19 11:09 . 2011-07-19 11:09 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-18 21:02 . 2011-07-25 15:30 -------- d-----w- c:\program files (x86)\Common Files\Akamai
2011-07-16 00:16 . 2011-07-16 00:18 -------- d-----w- c:\users\Tomas\AppData\Roaming\Teeworlds
2011-07-14 11:26 . 2003-02-11 04:02 32768 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\np32dsw.dll
2011-07-13 22:51 . 2011-07-13 22:52 -------- d-----w- c:\users\Tomas\AppData\Roaming\vlc
2011-07-13 22:48 . 2011-07-13 22:48 -------- d-----w- c:\program files (x86)\VideoLAN
2011-07-13 22:43 . 2011-07-13 22:43 -------- d-----w- c:\windows\sk
2011-07-13 22:37 . 2011-07-13 22:37 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-07-13 22:30 . 2011-07-13 22:44 -------- d-----w- c:\program files (x86)\Windows Live
2011-07-13 22:30 . 2011-07-13 22:30 -------- dc----w- c:\windows\system32\DRVSTORE
2011-07-13 22:30 . 2011-05-13 13:37 48488 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-07-13 22:29 . 2011-07-13 22:30 -------- d-----w- c:\program files\Windows Live
2011-07-13 22:28 . 2011-07-13 22:28 -------- d-----w- c:\program files (x86)\Microsoft
2011-07-13 22:26 . 2010-08-11 05:19 3860992 ----a-w- c:\windows\system32\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 05:13 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-07-13 22:26 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2011-07-13 22:26 . 2010-05-23 10:11 196608 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 206848 ----a-w- c:\windows\system32\mfps.dll
2011-07-13 22:26 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2011-07-13 22:26 . 2010-05-23 08:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 08:35 4068864 ----a-w- c:\windows\system32\mf.dll
2011-07-13 22:25 . 2011-07-13 23:03 -------- d-----w- c:\users\Tomas\AppData\Local\Windows Live
2011-07-13 22:25 . 2011-07-13 22:25 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2011-07-12 16:19 . 2011-07-12 16:19 -------- d-----w- c:\users\Tomas\AppData\Roaming\ts3overlay
2011-07-12 16:15 . 2011-07-12 16:22 -------- d-----w- c:\users\Tomas\AppData\Roaming\TS3Client
2011-07-10 15:09 . 2011-07-10 15:09 -------- d-----w- c:\program files (x86)\Microsoft Games
2011-07-10 14:44 . 2011-07-10 14:44 -------- d-----w- c:\users\Tomas\AppData\Local\DDMSettings
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Roaming\Zoner
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Local\Zoner
2011-06-27 17:44 . 2011-06-27 17:44 -------- d-----w- c:\program files (x86)\Zoner
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\EA Core
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\Electronic Arts
2011-06-25 19:30 . 2011-07-19 21:35 -------- d-----w- c:\program files (x86)\Common Files\BioWare
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-24 18:29 . 2011-05-22 10:38 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-07-24 18:29 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 18:22 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-07-23 14:56 . 2011-05-30 21:18 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-21 20:44 . 2009-12-11 06:50 29184 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-07-21 20:43 . 2009-12-11 07:04 4017152 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-07-21 20:43 . 2009-12-11 07:31 5008384 ----a-w- c:\windows\system32\atidxx64.dll
2011-07-21 20:43 . 2009-12-11 06:50 40960 ----a-w- c:\windows\system32\atiuxp64.dll
2011-07-21 20:41 . 2009-12-11 07:22 4330496 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-07-21 20:39 . 2011-05-20 20:10 58880 ----a-w- c:\windows\system32\coinst.dll
2011-07-21 20:38 . 2009-12-11 06:51 366592 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-21 20:34 . 2009-12-11 07:34 811008 ----a-w- c:\windows\system32\aticfx64.dll
2011-07-13 22:29 . 2009-08-18 09:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-17 10:37 . 2011-05-20 21:15 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-17 10:37 . 2011-05-20 21:15 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2011-05-29 17:30 . 2011-05-22 10:34 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-05-26 16:42 . 2011-05-26 16:42 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-05-25 15:53 . 2011-05-25 15:53 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-05-24 21:02 . 2011-05-24 21:02 2434856 ----a-w- c:\windows\SysWow64\pbsvc_bc2.exe
2011-05-22 14:41 . 2011-05-22 14:41 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-05-22 14:41 . 2011-05-22 14:41 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-05-21 22:27 . 2011-05-21 22:27 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-18 10:37 . 2011-05-21 12:52 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26CBFC4B-A5B2-4E58-A23E-768A18FBE802}\mpengine.dll
2011-05-13 14:03 . 2011-05-13 14:03 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll
2011-05-13 13:42 . 2011-05-13 13:42 302448 ----a-w- c:\windows\WLXPGSS.SCR
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-05-23 399736]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-06-24 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-05-24 2439072]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-30 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
R3 X6va005;X6va005;c:\users\Tomas\AppData\Local\Temp\005F132.tmp [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 12:19]
.
2011-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 12:19]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF20332.cfxxe" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.splashtop.com/asusexpressgate/mb/searchAPI.php?SE=yahoo&QS=http%3A%2F%2Fsearch.yahoo.com%2Fsearch%3Ffr%3Dfp-devicevm%26type%3DWEB01
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: ????3?? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\
FF - prefs.js: browser.search.selectedEngine - Atlas
FF - prefs.js: browser.startup.homepage - google.sk
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-wxpdrv - c:\windows\services32.exe
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Wow6432Node-HKLM-Run-sysdriver32.exe - c:\windows\sysdriver32.exe
Wow6432Node-HKLM-Run-sysdriver32_.exe - c:\windows\sysdriver32_.exe
Wow6432Node-HKLM-Run-l1rezerv.exe - c:\windows\l1rezerv.exe
Wow6432Node-HKLM-Run-systemup - c:\windows\systemup.exe
Wow6432Node-HKLM-Run-tray_ico0 - c:\windows\update.tray-8-0\svchost.exe
Wow6432Node-HKLM-Run-tray_ico1 - c:\windows\update.tray-7-0\svchost.exe
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_e477fed.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_e477fed.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Tomas\AppData\Local\Temp\005F132.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\ASDR.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\ASUS\SmartDoctor\SmartDoctor.exe
c:\program files (x86)\Common Files\Steam\SteamService.exe
.
**************************************************************************
.
Completion time: 2011-07-25 17:33:45 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-25 15:33
.
Pre-Run: 64 819 580 928 bytes free
Post-Run: 64 375 820 288 bytes free
.
- - End Of File - - 75AB4A33142D54DE1240F84F7DD592F9
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.4095.2782 [GMT 2:00]
Running from: c:\users\Tomas\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tomas\AppData\Roaming\BITS
c:\users\Tomas\AppData\Roaming\BITS\BITS.ini
c:\users\Tomas\AppData\Roaming\BITS\P2PCfg.ini
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\services32.exe
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\systemup.exe
c:\windows\Temp\37757.exe
c:\windows\TEMP\5490510.exe
c:\windows\Temp\95047160-loader2.exe
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\update.tray-7-0\svchost.exe
c:\windows\update.tray-8-0\svchost.exe
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Service_srvbtcclient
-------\Service_srvbtcclient
.
.
((((((((((((((((((((((((( Files Created from 2011-06-25 to 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-25 15:29 . 2011-07-25 15:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-25 15:25 . 2011-07-25 15:25 -------- d-----w- C:\32788R22FWJFW
2011-07-24 23:03 . 2011-07-24 23:03 -------- d-----w- c:\program files\CCleaner
2011-07-24 22:32 . 2011-07-25 14:28 -------- d-----w- c:\program files\trend micro
2011-07-24 22:32 . 2011-07-24 22:33 -------- d-----w- C:\rsit
2011-07-24 18:42 . 2011-07-25 15:29 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-24 18:42 . 2011-07-24 18:42 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-07-24 18:40 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 18:40 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 18:40 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 18:40 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 18:40 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 18:40 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-24 18:40 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 18:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 18:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-24 18:31 . 2011-07-24 18:31 -------- d-----w- c:\windows\ufa
2011-07-24 18:31 . 2011-07-24 18:31 -------- d-----w- c:\windows\rpcminer
2011-07-24 18:31 . 2011-07-24 18:31 -------- d-----w- c:\windows\phoenix
2011-07-24 18:30 . 2011-07-24 18:31 246272 ----a-w- c:\windows\unrar.exe
2011-07-24 18:27 . 2011-07-24 18:43 -------- d-----w- c:\windows\av_ico
2011-07-24 18:25 . 2011-07-25 15:29 -------- d--h--w- c:\windows\update.tray-8-0
2011-07-24 18:25 . 2011-07-24 18:25 -------- d--h--w- c:\windows\update.tray-8-0-lnk
2011-07-23 14:56 . 2011-07-23 14:56 476904 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-07-21 20:54 . 2011-07-21 20:54 -------- d-----w- c:\programdata\ATI
2011-07-21 20:44 . 2011-07-21 20:44 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-21 20:44 . 2011-07-21 20:44 262144 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-07-21 20:43 . 2011-07-21 20:44 4219904 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-07-21 20:43 . 2011-07-21 20:43 39936 ----a-w- c:\windows\system32\atig6txx.dll
2011-07-21 20:43 . 2011-07-21 20:43 485376 ----a-w- c:\windows\system32\atieclxx.exe
2011-07-21 20:43 . 2011-07-21 20:43 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-07-21 20:43 . 2011-07-21 20:43 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\atimpc32.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2011-07-21 20:42 . 2011-07-21 20:45 23336960 ----a-w- c:\windows\system32\atio6axx.dll
2011-07-21 20:42 . 2011-07-21 20:43 5486592 ----a-w- c:\windows\system32\atiumd64.dll
2011-07-21 20:42 . 2011-07-21 20:42 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-07-21 20:39 . 2011-07-21 20:39 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
2011-07-21 20:39 . 2011-07-21 20:39 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2011-07-21 20:38 . 2011-07-21 20:39 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2011-07-21 20:38 . 2011-07-21 20:40 9359872 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-07-21 20:38 . 2011-07-21 20:38 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2011-07-21 20:37 . 2011-07-21 20:38 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2011-07-21 20:37 . 2011-07-21 20:38 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2011-07-21 20:37 . 2011-07-21 20:37 16384 ----a-w- c:\windows\system32\atimuixx.dll
2011-07-21 20:36 . 2011-07-21 20:37 204288 ----a-w- c:\windows\system32\atiesrxx.exe
2011-07-21 20:36 . 2011-07-21 20:36 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-07-21 20:36 . 2011-07-21 20:36 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-07-21 20:34 . 2011-07-21 20:35 6847488 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-07-21 20:34 . 2011-07-21 20:34 120320 ----a-w- c:\windows\system32\atitmm64.dll
2011-07-21 15:46 . 2010-08-16 04:42 116240 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2011-07-20 05:05 . 2010-02-22 13:46 23680 ----a-w- c:\windows\system32\drivers\IOMap64.sys
2011-07-20 05:03 . 2011-07-20 05:03 16384 ----a-w- c:\windows\system32\drivers\EIO64.sys
2011-07-19 21:38 . 2003-08-15 14:02 69632 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe
2011-07-19 21:38 . 2003-08-15 14:01 380928 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2011-07-19 21:38 . 2003-08-15 13:57 212992 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
2011-07-19 20:29 . 2011-07-19 20:29 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2011-07-19 20:29 . 2003-09-03 00:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2011-07-19 20:29 . 2003-09-03 00:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2011-07-19 20:29 . 2003-09-03 00:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2011-07-19 20:29 . 2003-09-03 00:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2011-07-19 20:29 . 2003-09-03 00:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2011-07-19 20:29 . 2003-09-03 00:23 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-07-19 20:29 . 2011-07-19 20:29 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2011-07-19 11:09 . 2011-07-19 11:09 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-18 21:02 . 2011-07-25 15:30 -------- d-----w- c:\program files (x86)\Common Files\Akamai
2011-07-16 00:16 . 2011-07-16 00:18 -------- d-----w- c:\users\Tomas\AppData\Roaming\Teeworlds
2011-07-14 11:26 . 2003-02-11 04:02 32768 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\np32dsw.dll
2011-07-13 22:51 . 2011-07-13 22:52 -------- d-----w- c:\users\Tomas\AppData\Roaming\vlc
2011-07-13 22:48 . 2011-07-13 22:48 -------- d-----w- c:\program files (x86)\VideoLAN
2011-07-13 22:43 . 2011-07-13 22:43 -------- d-----w- c:\windows\sk
2011-07-13 22:37 . 2011-07-13 22:37 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-07-13 22:30 . 2011-07-13 22:44 -------- d-----w- c:\program files (x86)\Windows Live
2011-07-13 22:30 . 2011-07-13 22:30 -------- dc----w- c:\windows\system32\DRVSTORE
2011-07-13 22:30 . 2011-05-13 13:37 48488 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-07-13 22:29 . 2011-07-13 22:30 -------- d-----w- c:\program files\Windows Live
2011-07-13 22:28 . 2011-07-13 22:28 -------- d-----w- c:\program files (x86)\Microsoft
2011-07-13 22:26 . 2010-08-11 05:19 3860992 ----a-w- c:\windows\system32\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 05:13 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-07-13 22:26 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2011-07-13 22:26 . 2010-05-23 10:11 196608 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 206848 ----a-w- c:\windows\system32\mfps.dll
2011-07-13 22:26 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2011-07-13 22:26 . 2010-05-23 08:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 08:35 4068864 ----a-w- c:\windows\system32\mf.dll
2011-07-13 22:25 . 2011-07-13 23:03 -------- d-----w- c:\users\Tomas\AppData\Local\Windows Live
2011-07-13 22:25 . 2011-07-13 22:25 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2011-07-12 16:19 . 2011-07-12 16:19 -------- d-----w- c:\users\Tomas\AppData\Roaming\ts3overlay
2011-07-12 16:15 . 2011-07-12 16:22 -------- d-----w- c:\users\Tomas\AppData\Roaming\TS3Client
2011-07-10 15:09 . 2011-07-10 15:09 -------- d-----w- c:\program files (x86)\Microsoft Games
2011-07-10 14:44 . 2011-07-10 14:44 -------- d-----w- c:\users\Tomas\AppData\Local\DDMSettings
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Roaming\Zoner
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Local\Zoner
2011-06-27 17:44 . 2011-06-27 17:44 -------- d-----w- c:\program files (x86)\Zoner
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\EA Core
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\Electronic Arts
2011-06-25 19:30 . 2011-07-19 21:35 -------- d-----w- c:\program files (x86)\Common Files\BioWare
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-24 18:29 . 2011-05-22 10:38 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-07-24 18:29 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 18:22 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-07-23 14:56 . 2011-05-30 21:18 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-21 20:44 . 2009-12-11 06:50 29184 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-07-21 20:43 . 2009-12-11 07:04 4017152 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-07-21 20:43 . 2009-12-11 07:31 5008384 ----a-w- c:\windows\system32\atidxx64.dll
2011-07-21 20:43 . 2009-12-11 06:50 40960 ----a-w- c:\windows\system32\atiuxp64.dll
2011-07-21 20:41 . 2009-12-11 07:22 4330496 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-07-21 20:39 . 2011-05-20 20:10 58880 ----a-w- c:\windows\system32\coinst.dll
2011-07-21 20:38 . 2009-12-11 06:51 366592 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-21 20:34 . 2009-12-11 07:34 811008 ----a-w- c:\windows\system32\aticfx64.dll
2011-07-13 22:29 . 2009-08-18 09:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-17 10:37 . 2011-05-20 21:15 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-17 10:37 . 2011-05-20 21:15 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2011-05-29 17:30 . 2011-05-22 10:34 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-05-26 16:42 . 2011-05-26 16:42 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-05-25 15:53 . 2011-05-25 15:53 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-05-24 21:02 . 2011-05-24 21:02 2434856 ----a-w- c:\windows\SysWow64\pbsvc_bc2.exe
2011-05-22 14:41 . 2011-05-22 14:41 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-05-22 14:41 . 2011-05-22 14:41 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-05-21 22:27 . 2011-05-21 22:27 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-18 10:37 . 2011-05-21 12:52 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26CBFC4B-A5B2-4E58-A23E-768A18FBE802}\mpengine.dll
2011-05-13 14:03 . 2011-05-13 14:03 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll
2011-05-13 13:42 . 2011-05-13 13:42 302448 ----a-w- c:\windows\WLXPGSS.SCR
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2011-05-23 399736]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-06-15 15141768]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-06-24 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-05-24 2439072]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-30 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 135664]
R3 X6va005;X6va005;c:\users\Tomas\AppData\Local\Temp\005F132.tmp [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 12:19]
.
2011-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-04 12:19]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF20332.cfxxe" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.splashtop.com/asusexpressgate/mb/searchAPI.php?SE=yahoo&QS=http%3A%2F%2Fsearch.yahoo.com%2Fsearch%3Ffr%3Dfp-devicevm%26type%3DWEB01
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: ????3?? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\
FF - prefs.js: browser.search.selectedEngine - Atlas
FF - prefs.js: browser.startup.homepage - google.sk
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-wxpdrv - c:\windows\services32.exe
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Wow6432Node-HKLM-Run-sysdriver32.exe - c:\windows\sysdriver32.exe
Wow6432Node-HKLM-Run-sysdriver32_.exe - c:\windows\sysdriver32_.exe
Wow6432Node-HKLM-Run-l1rezerv.exe - c:\windows\l1rezerv.exe
Wow6432Node-HKLM-Run-systemup - c:\windows\systemup.exe
Wow6432Node-HKLM-Run-tray_ico0 - c:\windows\update.tray-8-0\svchost.exe
Wow6432Node-HKLM-Run-tray_ico1 - c:\windows\update.tray-7-0\svchost.exe
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_e477fed.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="C:/Program Files (x86)/Common Files/Akamai/netsession_win_e477fed.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Tomas\AppData\Local\Temp\005F132.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\ASDR.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\ASUS\SmartDoctor\SmartDoctor.exe
c:\program files (x86)\Common Files\Steam\SteamService.exe
.
**************************************************************************
.
Completion time: 2011-07-25 17:33:45 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-25 15:33
.
Pre-Run: 64 819 580 928 bytes free
Post-Run: 64 375 820 288 bytes free
.
- - End Of File - - 75AB4A33142D54DE1240F84F7DD592F9
Re: Virus cez YouTube , Flash Player upgrate

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: File:: c:\users\Tomas\AppData\Local\Temp\005F132.tmp c:\windows\Tasks\GoogleUpdateTaskMachineCore.job c:\windows\Tasks\GoogleUpdateTaskMachineUA.job c:\windows\unrar.exe Folder:: c:\windows\update.tray-7-0 c:\windows\update.tray-7-0-lnk c:\windows\ufa c:\windows\rpcminer c:\windows\phoenix c:\windows\av_ico c:\windows\update.tray-8-0 c:\windows\update.tray-8-0-lnk c:\program files (x86)\Common Files\Akamai c:\program files (x86)\uTorrentBar Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"=- [-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"=- [-HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"=- "uTorrent"=- "Skype"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BCU"=- "DivXUpdate"=- [HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000000 "DisableThumbnailCache"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "combofix"= Driver:: gupdate gupdatem X6va005 Akamai NetSvc:: Akamai DDS:: uStart Page = hxxp://search.splashtop.com/asusexpress ... pe%3DWEB01 RegLock:: [HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź] [HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] RegNull:: [HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź] [HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc] Reboot::
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte

Re: Virus cez YouTube , Flash Player upgrate
ComboFix 11-07-25.02 - Tomas . 07. 2011 17:49:16.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.4095.2822 [GMT 2:00]
Running from: c:\users\Tomas\Desktop\ComboFix.exe
Command switches used :: c:\users\Tomas\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Tomas\AppData\Local\Temp\005F132.tmp"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\Akamai
c:\program files (x86)\Common Files\Akamai\AdminTool.exe
c:\program files (x86)\Common Files\Akamai\appregistry.dat
c:\program files (x86)\Common Files\Akamai\client.ini
c:\program files (x86)\Common Files\Akamai\client.ini.json
c:\program files (x86)\Common Files\Akamai\ControlPanel.exe
c:\program files (x86)\Common Files\Akamai\CplTasks.xml
c:\program files (x86)\Common Files\Akamai\euc_state.json
c:\program files (x86)\Common Files\Akamai\guid.ini
c:\program files (x86)\Common Files\Akamai\Languages\csy.dll
c:\program files (x86)\Common Files\Akamai\Languages\dan.dll
c:\program files (x86)\Common Files\Akamai\Languages\deu.dll
c:\program files (x86)\Common Files\Akamai\Languages\esp.dll
c:\program files (x86)\Common Files\Akamai\Languages\fin.dll
c:\program files (x86)\Common Files\Akamai\Languages\fra.dll
c:\program files (x86)\Common Files\Akamai\Languages\chs.dll
c:\program files (x86)\Common Files\Akamai\Languages\cht.dll
c:\program files (x86)\Common Files\Akamai\Languages\ita.dll
c:\program files (x86)\Common Files\Akamai\Languages\jpn.dll
c:\program files (x86)\Common Files\Akamai\Languages\kor.dll
c:\program files (x86)\Common Files\Akamai\Languages\nld.dll
c:\program files (x86)\Common Files\Akamai\Languages\nor.dll
c:\program files (x86)\Common Files\Akamai\Languages\plk.dll
c:\program files (x86)\Common Files\Akamai\Languages\ptb.dll
c:\program files (x86)\Common Files\Akamai\Languages\ptg.dll
c:\program files (x86)\Common Files\Akamai\Languages\rus.dll
c:\program files (x86)\Common Files\Akamai\Languages\sve.dll
c:\program files (x86)\Common Files\Akamai\Languages\trk.dll
c:\program files (x86)\Common Files\Akamai\Logs\debug.log
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110718_210345.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110718_220346.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110718_230347.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_101103.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_111103.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_111833.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_121110.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_131110.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_141111.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_151111.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_161111.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_163023.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_173023.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_183023.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_193024.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_203024.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_213025.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_223025.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_233025.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_003026.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_013027.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_023028.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_033028.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_043029.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_050555.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_144759.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_154800.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_164801.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_175628.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_185628.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_195629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_205629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_215629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_225629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_235630.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_015632.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_025632.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_035632.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_045633.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_151208.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_161209.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_171209.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_191211.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_205624.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_215625.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_225626.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_235626.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_005627.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_093041.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_103041.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_113042.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_123043.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_133043.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_143043.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_153044.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_163044.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_183046.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_193046.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_203047.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_213048.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_083946.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_093622.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_103623.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_113624.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_144826.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_154827.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_164827.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_174828.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_184828.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_194828.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_211818.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_221819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_231819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_001819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_011819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_134457.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_144458.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_154458.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_164458.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_174459.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_182710.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_184350.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_184645.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_185434.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_215459.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_221514.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_222445.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_225538.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_140252.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_143255.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_152551.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_153054.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_154807.sent
c:\program files (x86)\Common Files\Akamai\netsession_win_e477fed.dll
c:\program files (x86)\Common Files\Akamai\readme.txt
c:\program files (x86)\Common Files\Akamai\root.pem
c:\program files (x86)\Common Files\Akamai\rswinui.exe
c:\program files (x86)\Common Files\Akamai\uninstall.exe
c:\program files (x86)\uTorrentBar
c:\program files (x86)\uTorrentBar\GottenAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\INSTALL.LOG
c:\program files (x86)\uTorrentBar\OtherAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\SharedAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\tbuTor.dll
c:\program files (x86)\uTorrentBar\toolbar.cfg
c:\program files (x86)\uTorrentBar\ToolbarContextMenu.xml
c:\program files (x86)\uTorrentBar\UNWISE.EXE
c:\program files (x86)\uTorrentBar\uTorrentBarToolbarHelper.exe
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_avira_start.ico
c:\windows\phoenix
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0-lnk\svchost.exe
c:\windows\update.tray-7-0
c:\windows\update.tray-8-0-lnk
c:\windows\update.tray-8-0-lnk\svchost.exe
c:\windows\update.tray-8-0
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_X6VA005
-------\Service_Akamai
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_X6va005
.
.
((((((((((((((((((((((((( Files Created from 2011-06-25 to 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-24 23:03 . 2011-07-24 23:03 -------- d-----w- c:\program files\CCleaner
2011-07-24 22:32 . 2011-07-25 14:28 -------- d-----w- c:\program files\trend micro
2011-07-24 22:32 . 2011-07-24 22:33 -------- d-----w- C:\rsit
2011-07-24 18:40 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 18:40 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 18:40 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 18:40 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 18:40 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 18:40 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-24 18:40 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 18:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 18:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-23 14:56 . 2011-07-23 14:56 476904 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-07-21 20:54 . 2011-07-21 20:54 -------- d-----w- c:\programdata\ATI
2011-07-21 20:44 . 2011-07-21 20:44 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-21 20:44 . 2011-07-21 20:44 262144 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-07-21 20:43 . 2011-07-21 20:44 4219904 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-07-21 20:43 . 2011-07-21 20:43 39936 ----a-w- c:\windows\system32\atig6txx.dll
2011-07-21 20:43 . 2011-07-21 20:43 485376 ----a-w- c:\windows\system32\atieclxx.exe
2011-07-21 20:43 . 2011-07-21 20:43 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-07-21 20:43 . 2011-07-21 20:43 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\atimpc32.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2011-07-21 20:42 . 2011-07-21 20:45 23336960 ----a-w- c:\windows\system32\atio6axx.dll
2011-07-21 20:42 . 2011-07-21 20:43 5486592 ----a-w- c:\windows\system32\atiumd64.dll
2011-07-21 20:42 . 2011-07-21 20:42 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-07-21 20:39 . 2011-07-21 20:39 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
2011-07-21 20:39 . 2011-07-21 20:39 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2011-07-21 20:38 . 2011-07-21 20:39 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2011-07-21 20:38 . 2011-07-21 20:40 9359872 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-07-21 20:38 . 2011-07-21 20:38 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2011-07-21 20:37 . 2011-07-21 20:38 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2011-07-21 20:37 . 2011-07-21 20:38 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2011-07-21 20:37 . 2011-07-21 20:37 16384 ----a-w- c:\windows\system32\atimuixx.dll
2011-07-21 20:36 . 2011-07-21 20:37 204288 ----a-w- c:\windows\system32\atiesrxx.exe
2011-07-21 20:36 . 2011-07-21 20:36 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-07-21 20:36 . 2011-07-21 20:36 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-07-21 20:34 . 2011-07-21 20:35 6847488 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-07-21 20:34 . 2011-07-21 20:34 120320 ----a-w- c:\windows\system32\atitmm64.dll
2011-07-21 15:46 . 2010-08-16 04:42 116240 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2011-07-20 05:05 . 2010-02-22 13:46 23680 ----a-w- c:\windows\system32\drivers\IOMap64.sys
2011-07-20 05:03 . 2011-07-20 05:03 16384 ----a-w- c:\windows\system32\drivers\EIO64.sys
2011-07-19 21:38 . 2003-08-15 14:02 69632 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe
2011-07-19 21:38 . 2003-08-15 14:01 380928 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2011-07-19 21:38 . 2003-08-15 13:57 212992 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
2011-07-19 20:29 . 2011-07-19 20:29 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2011-07-19 20:29 . 2003-09-03 00:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2011-07-19 20:29 . 2003-09-03 00:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2011-07-19 20:29 . 2003-09-03 00:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2011-07-19 20:29 . 2003-09-03 00:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2011-07-19 20:29 . 2003-09-03 00:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2011-07-19 20:29 . 2003-09-03 00:23 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-07-19 20:29 . 2011-07-19 20:29 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2011-07-19 11:09 . 2011-07-19 11:09 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-16 00:16 . 2011-07-16 00:18 -------- d-----w- c:\users\Tomas\AppData\Roaming\Teeworlds
2011-07-14 11:26 . 2003-02-11 04:02 32768 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\np32dsw.dll
2011-07-13 22:51 . 2011-07-13 22:52 -------- d-----w- c:\users\Tomas\AppData\Roaming\vlc
2011-07-13 22:48 . 2011-07-13 22:48 -------- d-----w- c:\program files (x86)\VideoLAN
2011-07-13 22:43 . 2011-07-13 22:43 -------- d-----w- c:\windows\sk
2011-07-13 22:37 . 2011-07-13 22:37 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-07-13 22:30 . 2011-07-13 22:44 -------- d-----w- c:\program files (x86)\Windows Live
2011-07-13 22:30 . 2011-07-13 22:30 -------- dc----w- c:\windows\system32\DRVSTORE
2011-07-13 22:30 . 2011-05-13 13:37 48488 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-07-13 22:29 . 2011-07-13 22:30 -------- d-----w- c:\program files\Windows Live
2011-07-13 22:28 . 2011-07-13 22:28 -------- d-----w- c:\program files (x86)\Microsoft
2011-07-13 22:26 . 2010-08-11 05:19 3860992 ----a-w- c:\windows\system32\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 05:13 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-07-13 22:26 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2011-07-13 22:26 . 2010-05-23 10:11 196608 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 206848 ----a-w- c:\windows\system32\mfps.dll
2011-07-13 22:26 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2011-07-13 22:26 . 2010-05-23 08:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 08:35 4068864 ----a-w- c:\windows\system32\mf.dll
2011-07-13 22:25 . 2011-07-13 23:03 -------- d-----w- c:\users\Tomas\AppData\Local\Windows Live
2011-07-13 22:25 . 2011-07-13 22:25 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2011-07-12 16:19 . 2011-07-12 16:19 -------- d-----w- c:\users\Tomas\AppData\Roaming\ts3overlay
2011-07-12 16:15 . 2011-07-12 16:22 -------- d-----w- c:\users\Tomas\AppData\Roaming\TS3Client
2011-07-10 15:09 . 2011-07-10 15:09 -------- d-----w- c:\program files (x86)\Microsoft Games
2011-07-10 14:44 . 2011-07-10 14:44 -------- d-----w- c:\users\Tomas\AppData\Local\DDMSettings
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Roaming\Zoner
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Local\Zoner
2011-06-27 17:44 . 2011-06-27 17:44 -------- d-----w- c:\program files (x86)\Zoner
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\EA Core
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\Electronic Arts
2011-06-25 19:30 . 2011-07-19 21:35 -------- d-----w- c:\program files (x86)\Common Files\BioWare
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-24 18:29 . 2011-05-22 10:38 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-07-24 18:29 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 18:22 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-07-23 14:56 . 2011-05-30 21:18 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-21 20:44 . 2009-12-11 06:50 29184 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-07-21 20:43 . 2009-12-11 07:04 4017152 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-07-21 20:43 . 2009-12-11 07:31 5008384 ----a-w- c:\windows\system32\atidxx64.dll
2011-07-21 20:43 . 2009-12-11 06:50 40960 ----a-w- c:\windows\system32\atiuxp64.dll
2011-07-21 20:41 . 2009-12-11 07:22 4330496 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-07-21 20:39 . 2011-05-20 20:10 58880 ----a-w- c:\windows\system32\coinst.dll
2011-07-21 20:38 . 2009-12-11 06:51 366592 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-21 20:34 . 2009-12-11 07:34 811008 ----a-w- c:\windows\system32\aticfx64.dll
2011-07-13 22:29 . 2009-08-18 09:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-17 10:37 . 2011-05-20 21:15 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-17 10:37 . 2011-05-20 21:15 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2011-05-29 17:30 . 2011-05-22 10:34 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-05-26 16:42 . 2011-05-26 16:42 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-05-25 15:53 . 2011-05-25 15:53 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-05-24 21:02 . 2011-05-24 21:02 2434856 ----a-w- c:\windows\SysWow64\pbsvc_bc2.exe
2011-05-22 14:41 . 2011-05-22 14:41 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-05-22 14:41 . 2011-05-22 14:41 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-05-21 22:27 . 2011-05-21 22:27 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-18 10:37 . 2011-05-21 12:52 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26CBFC4B-A5B2-4E58-A23E-768A18FBE802}\mpengine.dll
2011-05-13 14:03 . 2011-05-13 14:03 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll
2011-05-13 13:42 . 2011-05-13 13:42 302448 ----a-w- c:\windows\WLXPGSS.SCR
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-25_15.31.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2011-07-25 15:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-07-25 15:31 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-07-25 15:53 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-25 15:31 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-25 15:53 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-25 15:31 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 05:10 . 2011-07-25 14:34 30736 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-25 15:32 30736 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-05-20 20:05 . 2011-07-25 15:32 8280 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-609175540-4704254-350555894-1000_UserData.bin
- 2011-07-25 15:30 . 2011-07-25 15:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-25 15:53 . 2011-07-25 15:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-25 15:30 . 2011-07-25 15:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-25 15:53 . 2011-07-25 15:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-07-25 15:29 391132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-25 15:52 391132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-05-21 23:09 . 2011-07-25 15:52 6759560 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-609175540-4704254-350555894-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-06-24 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-05-24 2439072]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-30 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S4 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF24698.cfxxe" [X]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: ????3?? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\
FF - prefs.js: browser.search.selectedEngine - Atlas
FF - prefs.js: browser.startup.homepage - google.sk
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-Akamai - c:\program files (x86)\Common Files\Akamai\uninstall.exe
AddRemove-uTorrentBar Toolbar - c:\progra~2\UTORRE~1\UNWISE.EXE
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\ASDR.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
.
**************************************************************************
.
Completion time: 2011-07-25 17:56:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-25 15:56
ComboFix2.txt 2011-07-25 15:33
.
Pre-Run: 64 425 267 200 bytes free
Post-Run: 64 154 603 520 bytes free
.
- - End Of File - - C5013AE94128FF75D2331F311B72DBA5
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.4095.2822 [GMT 2:00]
Running from: c:\users\Tomas\Desktop\ComboFix.exe
Command switches used :: c:\users\Tomas\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Tomas\AppData\Local\Temp\005F132.tmp"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\Akamai
c:\program files (x86)\Common Files\Akamai\AdminTool.exe
c:\program files (x86)\Common Files\Akamai\appregistry.dat
c:\program files (x86)\Common Files\Akamai\client.ini
c:\program files (x86)\Common Files\Akamai\client.ini.json
c:\program files (x86)\Common Files\Akamai\ControlPanel.exe
c:\program files (x86)\Common Files\Akamai\CplTasks.xml
c:\program files (x86)\Common Files\Akamai\euc_state.json
c:\program files (x86)\Common Files\Akamai\guid.ini
c:\program files (x86)\Common Files\Akamai\Languages\csy.dll
c:\program files (x86)\Common Files\Akamai\Languages\dan.dll
c:\program files (x86)\Common Files\Akamai\Languages\deu.dll
c:\program files (x86)\Common Files\Akamai\Languages\esp.dll
c:\program files (x86)\Common Files\Akamai\Languages\fin.dll
c:\program files (x86)\Common Files\Akamai\Languages\fra.dll
c:\program files (x86)\Common Files\Akamai\Languages\chs.dll
c:\program files (x86)\Common Files\Akamai\Languages\cht.dll
c:\program files (x86)\Common Files\Akamai\Languages\ita.dll
c:\program files (x86)\Common Files\Akamai\Languages\jpn.dll
c:\program files (x86)\Common Files\Akamai\Languages\kor.dll
c:\program files (x86)\Common Files\Akamai\Languages\nld.dll
c:\program files (x86)\Common Files\Akamai\Languages\nor.dll
c:\program files (x86)\Common Files\Akamai\Languages\plk.dll
c:\program files (x86)\Common Files\Akamai\Languages\ptb.dll
c:\program files (x86)\Common Files\Akamai\Languages\ptg.dll
c:\program files (x86)\Common Files\Akamai\Languages\rus.dll
c:\program files (x86)\Common Files\Akamai\Languages\sve.dll
c:\program files (x86)\Common Files\Akamai\Languages\trk.dll
c:\program files (x86)\Common Files\Akamai\Logs\debug.log
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110718_210345.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110718_220346.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110718_230347.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_101103.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_111103.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_111833.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_121110.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_131110.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_141111.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_151111.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_161111.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_163023.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_173023.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_183023.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_193024.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_203024.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_213025.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_223025.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110719_233025.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_003026.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_013027.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_023028.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_033028.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_043029.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_050555.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_144759.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_154800.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_164801.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_175628.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_185628.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_195629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_205629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_215629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_225629.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110720_235630.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_015632.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_025632.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_035632.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_045633.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_151208.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_161209.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_171209.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_191211.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_205624.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_215625.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_225626.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110721_235626.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_005627.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_093041.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_103041.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_113042.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_123043.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_133043.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_143043.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_153044.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_163044.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_183046.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_193046.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_203047.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110722_213048.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_083946.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_093622.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_103623.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_113624.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_144826.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_154827.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_164827.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_174828.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_184828.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_194828.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_211818.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_221819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110723_231819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_001819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_011819.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_134457.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_144458.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_154458.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_164458.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_174459.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_182710.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_184350.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_184645.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_185434.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_215459.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_221514.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_222445.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110724_225538.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_140252.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_143255.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_152551.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_153054.sent
c:\program files (x86)\Common Files\Akamai\Logs\debug.log.110725_154807.sent
c:\program files (x86)\Common Files\Akamai\netsession_win_e477fed.dll
c:\program files (x86)\Common Files\Akamai\readme.txt
c:\program files (x86)\Common Files\Akamai\root.pem
c:\program files (x86)\Common Files\Akamai\rswinui.exe
c:\program files (x86)\Common Files\Akamai\uninstall.exe
c:\program files (x86)\uTorrentBar
c:\program files (x86)\uTorrentBar\GottenAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\INSTALL.LOG
c:\program files (x86)\uTorrentBar\OtherAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\SharedAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\tbuTor.dll
c:\program files (x86)\uTorrentBar\toolbar.cfg
c:\program files (x86)\uTorrentBar\ToolbarContextMenu.xml
c:\program files (x86)\uTorrentBar\UNWISE.EXE
c:\program files (x86)\uTorrentBar\uTorrentBarToolbarHelper.exe
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_avira_start.ico
c:\windows\phoenix
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0-lnk\svchost.exe
c:\windows\update.tray-7-0
c:\windows\update.tray-8-0-lnk
c:\windows\update.tray-8-0-lnk\svchost.exe
c:\windows\update.tray-8-0
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_X6VA005
-------\Service_Akamai
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_X6va005
.
.
((((((((((((((((((((((((( Files Created from 2011-06-25 to 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-24 23:03 . 2011-07-24 23:03 -------- d-----w- c:\program files\CCleaner
2011-07-24 22:32 . 2011-07-25 14:28 -------- d-----w- c:\program files\trend micro
2011-07-24 22:32 . 2011-07-24 22:33 -------- d-----w- C:\rsit
2011-07-24 18:40 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 18:40 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 18:40 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 18:40 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 18:40 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 18:40 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-24 18:40 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 18:40 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 18:40 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-07-23 14:56 . 2011-07-23 14:56 476904 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-07-21 20:54 . 2011-07-21 20:54 -------- d-----w- c:\programdata\ATI
2011-07-21 20:44 . 2011-07-21 20:44 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-07-21 20:44 . 2011-07-21 20:44 262144 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2011-07-21 20:43 . 2011-07-21 20:44 4219904 ----a-w- c:\windows\SysWow64\atidxx32.dll
2011-07-21 20:43 . 2011-07-21 20:43 39936 ----a-w- c:\windows\system32\atig6txx.dll
2011-07-21 20:43 . 2011-07-21 20:43 485376 ----a-w- c:\windows\system32\atieclxx.exe
2011-07-21 20:43 . 2011-07-21 20:43 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2011-07-21 20:43 . 2011-07-21 20:43 356352 ----a-w- c:\windows\SysWow64\atipdlxx.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\atimpc32.dll
2011-07-21 20:42 . 2011-07-21 20:43 52736 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2011-07-21 20:42 . 2011-07-21 20:45 23336960 ----a-w- c:\windows\system32\atio6axx.dll
2011-07-21 20:42 . 2011-07-21 20:43 5486592 ----a-w- c:\windows\system32\atiumd64.dll
2011-07-21 20:42 . 2011-07-21 20:42 278528 ----a-w- c:\windows\SysWow64\Oemdspif.dll
2011-07-21 20:39 . 2011-07-21 20:39 423424 ----a-w- c:\windows\system32\atipdl64.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\ATIODCLI.exe
2011-07-21 20:39 . 2011-07-21 20:39 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-07-21 20:39 . 2011-07-21 20:39 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2011-07-21 20:38 . 2011-07-21 20:39 1113088 ----a-w- c:\windows\system32\atiumd6v.dll
2011-07-21 20:38 . 2011-07-21 20:40 9359872 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2011-07-21 20:38 . 2011-07-21 20:38 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2011-07-21 20:37 . 2011-07-21 20:38 1828864 ----a-w- c:\windows\SysWow64\atiumdmv.dll
2011-07-21 20:37 . 2011-07-21 20:38 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2011-07-21 20:37 . 2011-07-21 20:37 16384 ----a-w- c:\windows\system32\atimuixx.dll
2011-07-21 20:36 . 2011-07-21 20:37 204288 ----a-w- c:\windows\system32\atiesrxx.exe
2011-07-21 20:36 . 2011-07-21 20:36 38912 ----a-w- c:\windows\system32\atiu9p64.dll
2011-07-21 20:36 . 2011-07-21 20:36 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2011-07-21 20:34 . 2011-07-21 20:35 6847488 ----a-w- c:\windows\SysWow64\aticaldd.dll
2011-07-21 20:34 . 2011-07-21 20:34 120320 ----a-w- c:\windows\system32\atitmm64.dll
2011-07-21 15:46 . 2010-08-16 04:42 116240 ----a-w- c:\windows\system32\drivers\AtihdW76.sys
2011-07-20 05:05 . 2010-02-22 13:46 23680 ----a-w- c:\windows\system32\drivers\IOMap64.sys
2011-07-20 05:03 . 2011-07-20 05:03 16384 ----a-w- c:\windows\system32\drivers\EIO64.sys
2011-07-19 21:38 . 2003-08-15 14:02 69632 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe
2011-07-19 21:38 . 2003-08-15 14:01 380928 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2011-07-19 21:38 . 2003-08-15 13:57 212992 ------w- c:\program files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
2011-07-19 20:29 . 2011-07-19 20:29 184452 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2011-07-19 20:29 . 2003-09-03 00:28 724992 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2011-07-19 20:29 . 2003-09-03 00:27 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2011-07-19 20:29 . 2003-09-03 00:26 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2011-07-19 20:29 . 2003-09-03 00:26 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2011-07-19 20:29 . 2003-09-03 00:25 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2011-07-19 20:29 . 2003-09-03 00:23 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-07-19 20:29 . 2011-07-19 20:29 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2011-07-19 11:09 . 2011-07-19 11:09 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-16 00:16 . 2011-07-16 00:18 -------- d-----w- c:\users\Tomas\AppData\Roaming\Teeworlds
2011-07-14 11:26 . 2003-02-11 04:02 32768 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\np32dsw.dll
2011-07-13 22:51 . 2011-07-13 22:52 -------- d-----w- c:\users\Tomas\AppData\Roaming\vlc
2011-07-13 22:48 . 2011-07-13 22:48 -------- d-----w- c:\program files (x86)\VideoLAN
2011-07-13 22:43 . 2011-07-13 22:43 -------- d-----w- c:\windows\sk
2011-07-13 22:37 . 2011-07-13 22:37 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2011-07-13 22:30 . 2011-07-13 22:44 -------- d-----w- c:\program files (x86)\Windows Live
2011-07-13 22:30 . 2011-07-13 22:30 -------- dc----w- c:\windows\system32\DRVSTORE
2011-07-13 22:30 . 2011-05-13 13:37 48488 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-07-13 22:29 . 2011-07-13 22:30 -------- d-----w- c:\program files\Windows Live
2011-07-13 22:28 . 2011-07-13 22:28 -------- d-----w- c:\program files (x86)\Microsoft
2011-07-13 22:26 . 2010-08-11 05:19 3860992 ----a-w- c:\windows\system32\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 05:13 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-07-13 22:26 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2011-07-13 22:26 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2011-07-13 22:26 . 2010-05-23 10:11 196608 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-07-13 22:26 . 2010-05-23 08:35 206848 ----a-w- c:\windows\system32\mfps.dll
2011-07-13 22:26 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\SysWow64\mf.dll
2011-07-13 22:26 . 2010-05-23 08:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-07-13 22:26 . 2010-05-23 08:35 4068864 ----a-w- c:\windows\system32\mf.dll
2011-07-13 22:25 . 2011-07-13 23:03 -------- d-----w- c:\users\Tomas\AppData\Local\Windows Live
2011-07-13 22:25 . 2011-07-13 22:25 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
2011-07-12 16:19 . 2011-07-12 16:19 -------- d-----w- c:\users\Tomas\AppData\Roaming\ts3overlay
2011-07-12 16:15 . 2011-07-12 16:22 -------- d-----w- c:\users\Tomas\AppData\Roaming\TS3Client
2011-07-10 15:09 . 2011-07-10 15:09 -------- d-----w- c:\program files (x86)\Microsoft Games
2011-07-10 14:44 . 2011-07-10 14:44 -------- d-----w- c:\users\Tomas\AppData\Local\DDMSettings
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Roaming\Zoner
2011-06-27 17:45 . 2011-06-27 17:45 -------- d-----w- c:\users\Tomas\AppData\Local\Zoner
2011-06-27 17:44 . 2011-06-27 17:44 -------- d-----w- c:\program files (x86)\Zoner
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\EA Core
2011-06-25 19:43 . 2011-06-25 19:43 -------- d-----w- c:\programdata\Electronic Arts
2011-06-25 19:30 . 2011-07-19 21:35 -------- d-----w- c:\program files (x86)\Common Files\BioWare
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-24 18:29 . 2011-05-22 10:38 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-07-24 18:29 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-24 18:22 . 2011-05-22 10:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-07-23 14:56 . 2011-05-30 21:18 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-07-21 20:44 . 2009-12-11 06:50 29184 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-07-21 20:43 . 2009-12-11 07:04 4017152 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-07-21 20:43 . 2009-12-11 07:31 5008384 ----a-w- c:\windows\system32\atidxx64.dll
2011-07-21 20:43 . 2009-12-11 06:50 40960 ----a-w- c:\windows\system32\atiuxp64.dll
2011-07-21 20:41 . 2009-12-11 07:22 4330496 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-07-21 20:39 . 2011-05-20 20:10 58880 ----a-w- c:\windows\system32\coinst.dll
2011-07-21 20:38 . 2009-12-11 06:51 366592 ----a-w- c:\windows\system32\atiadlxx.dll
2011-07-21 20:34 . 2009-12-11 07:34 811008 ----a-w- c:\windows\system32\aticfx64.dll
2011-07-13 22:29 . 2009-08-18 09:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-17 10:37 . 2011-05-20 21:15 83120 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-17 10:37 . 2011-05-20 21:15 116568 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2011-05-29 17:30 . 2011-05-22 10:34 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-05-26 16:42 . 2011-05-26 16:42 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-05-25 15:53 . 2011-05-25 15:53 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-05-24 21:02 . 2011-05-24 21:02 2434856 ----a-w- c:\windows\SysWow64\pbsvc_bc2.exe
2011-05-22 14:41 . 2011-05-22 14:41 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-05-22 14:41 . 2011-05-22 14:41 458048 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-05-21 22:27 . 2011-05-21 22:27 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-05-18 10:37 . 2011-05-21 12:52 8718160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26CBFC4B-A5B2-4E58-A23E-768A18FBE802}\mpengine.dll
2011-05-13 14:03 . 2011-05-13 14:03 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll
2011-05-13 13:42 . 2011-05-13 13:42 302448 ----a-w- c:\windows\WLXPGSS.SCR
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-25_15.31.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2011-07-25 15:53 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-07-25 15:31 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-07-25 15:53 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-25 15:31 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-25 15:53 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-25 15:31 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 05:10 . 2011-07-25 14:34 30736 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-07-25 15:32 30736 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-05-20 20:05 . 2011-07-25 15:32 8280 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-609175540-4704254-350555894-1000_UserData.bin
- 2011-07-25 15:30 . 2011-07-25 15:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-25 15:53 . 2011-07-25 15:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-25 15:30 . 2011-07-25 15:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-25 15:53 . 2011-07-25 15:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-07-25 15:29 391132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-25 15:52 391132 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-05-21 23:09 . 2011-07-25 15:52 6759560 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-609175540-4704254-350555894-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"="c:\program files (x86)\OSCAR Editor X7\OscarEditor.exe" [2010-07-22 2636800]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-06-24 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-05-24 2439072]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-30 98304]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S4 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF24698.cfxxe" [X]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: ????3?? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\Tomas\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\6h769uyq.default\
FF - prefs.js: browser.search.selectedEngine - Atlas
FF - prefs.js: browser.startup.homepage - google.sk
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-Akamai - c:\program files (x86)\Common Files\Akamai\uninstall.exe
AddRemove-uTorrentBar Toolbar - c:\progra~2\UTORRE~1\UNWISE.EXE
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-609175540-4704254-350555894-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\Tomas\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SysWOW64\ASDR.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
.
**************************************************************************
.
Completion time: 2011-07-25 17:56:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-25 15:56
ComboFix2.txt 2011-07-25 15:33
.
Pre-Run: 64 425 267 200 bytes free
Post-Run: 64 154 603 520 bytes free
.
- - End Of File - - C5013AE94128FF75D2331F311B72DBA5
Re: Virus cez YouTube , Flash Player upgrate
Jak se chova PC 

Re: Virus cez YouTube , Flash Player upgrate
nezbadal som ziadnu zmenu ale nasiel som nejake nove zlozky ktore som nevytvoril : D\$RECYCLE.BIN a D\Config.Msi neviete co to je?
Re: Virus cez YouTube , Flash Player upgrate
a este ze ten ram okien vyzera ako by to nebol Win 7 ale Win 95 to tak vyzera odkedy tam je ta haved
Re: Virus cez YouTube , Flash Player upgrate

- Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
- Napiste ComboFix /Uninstall
- Stisknete Enter
- Tohle smaze Combofix a jeho slozky

- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)



- Provedte aktualizaci - treti zalozka
- Provedte uplny sken - nic nemazte
- MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
Re: Virus cez YouTube , Flash Player upgrate
aky log treba vlozit do toho Anti malvare?