mám v koplu virus...
nejde mi zapnout Správce úloh...
nejde mi zapnout regedit...
nouzový režim mi hodí modrou obrazovku PAGE_FAULT_IN_NONPAGED_AREA...
start počítače trvá dlouho, občas taky hodí modrou obrazovku...
Malwarebytes najde Trojan.Downloader který je v Temp složce v dokumentech...
Trojan remover ho smaže ale poté se vytvoří nový...
Hijackthis nechce smazat DisableRegedit=1 pokaždé když ho smaže, vytvoří se znovu...
Avira se mi pokaždé když ji zapnu vypne...
Já už fakt nevím co dál...

Prosím pomocte! Děkuji.
Zde je log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by David at 2011-08-05 14:12:29
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 654 MB (4%) free of 15 GB
Total RAM: 998 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:12:35, on 5.8.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\David\Data aplikací\QipGuard\QipGuard.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Spyware Terminator\Spywareterminator.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Downloads\RSIT.exe
C:\Program Files\trend micro\David.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=102866&gct=hp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\David\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\David\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Documents and Settings\David\Data aplikací\QipGuard\QipGuard.exe
O4 - HKCU\..\Run: [UpdateMyDrivers] C:\Program Files\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe /ot /as /ss
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\pev.cfxxe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe
--
End of file - 10724 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1292428093-839522115-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1292428093-839522115-1004UA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\twpgcxo0.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://eu.ask.com/?l=dis&o=102866&gct=hp"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... YYYYYCZ&q="
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
C:\Program Files\Mozilla Firefox\extensions\
afurladvisor@anchorfree.com
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\twpgcxo0.default\extensions\
toolbar@ask.com
C:\Documents and Settings\David\Data aplikací\Mozilla\Firefox\Profiles\twpgcxo0.default\searchplugins\
askcom.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-23 115072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\David\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-06-09 138240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
Vuze Remote Toolbar - C:\Program Files\Vuze_Remote\prxtbVuze.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
Hotspot Shield Class - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll [2011-05-25 233288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{ba14329e-9550-4989-b3f2-9732e92d17cc} - Vuze Remote Toolbar - C:\Program Files\Vuze_Remote\prxtbVuze.dll [2011-01-17 175912]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe []
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe []
"Persistence"=C:\WINDOWS\system32\igfxpers.exe []
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe []
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2007-08-08 905216]
"ACTray"=C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe []
"ACWLIcon"=C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 105368]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-04-14 421160]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2011-05-17 395144]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe /CHECKNOW []
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 225280]
"TrojanScanner"=C:\Program Files\Trojan Remover\Trjscan.exe [2011-08-04 1233856]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-04-23 205808]
"QIP Internet Guardian"=C:\Documents and Settings\David\Data aplikací\QipGuard\QipGuard.exe [2010-10-20 188416]
"UpdateMyDrivers"=C:\Program Files\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe /ot /as /ss []
"QIP2005"=C:\Program Files\QIP\qip.exe [2010-10-29 3330560]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-08-05 3318784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2010-01-13 205824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ACGina
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Riot Games\League of Legends\air\LolClient.exe"="D:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"D:\Riot Games\League of Legends\game\League of Legends.exe"="D:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"D:\Hry\League of Legends\air\LolClient.exe"="D:\Hry\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"D:\Hry\League of Legends\game\League of Legends.exe"="D:\Hry\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"
"C:\Program Files\Raptr\raptr.exe"="C:\Program Files\Raptr\raptr.exe:*:Enabled:Raptr Client"
"C:\Program Files\Raptr\raptr_im.exe"="C:\Program Files\Raptr\raptr_im.exe:*:Enabled:Raptr IM"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"D:\Hry\League of Legends\lol.launcher.exe"="D:\Hry\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:ipsec"
"C:\Program Files\Total Commander\TOTALCMD.EXE"="C:\Program Files\Total Commander\TOTALCMD.EXE:*:Enabled:ipsec"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"G:\nftu.pif"="G:\nftu.pif:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winmdqa.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winmdqa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winfesvpd.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winfesvpd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winpaenjw.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winpaenjw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winnasnv.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winnasnv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winpejhd.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winpejhd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\iplxs.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\iplxs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winwnpsj.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winwnpsj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\windjxjia.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\windjxjia.exe:*:Enabled:ipsec"
"C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe"="C:\Documents and Settings\David\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe:*:Enabled:ipsec"
"C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"="C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winxlhkt.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winxlhkt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\yyoyx.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\yyoyx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\mvpgmx.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\mvpgmx.exe:*:Enabled:ipsec"
"C:\Program Files\DivX\DivX Update\DivXUpdate.exe"="C:\Program Files\DivX\DivX Update\DivXUpdate.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\txbiph.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\txbiph.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\hkkl.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\hkkl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\toid.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\toid.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winxques.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winxques.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\efdbl.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\efdbl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winxdaer.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winxdaer.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winqexjif.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winqexjif.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winloxhmx.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winloxhmx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winjfgrh.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winjfgrh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winjgkn.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winjgkn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\yagb.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\yagb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\pcgor.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\pcgor.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\xuwuob.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\xuwuob.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\lyyl.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\lyyl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\yrnq.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\yrnq.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wuauclt.exe"="C:\WINDOWS\system32\wuauclt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winsbain.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winsbain.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winsgqpy.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winsgqpy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\windhdldt.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\windhdldt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winmgyop.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winmgyop.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\hossvy.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\hossvy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\gtuq.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\gtuq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winfshjae.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winfshjae.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\bvqwq.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\bvqwq.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxtray.exe"="C:\WINDOWS\system32\igfxtray.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winbohjs.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winbohjs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winfqitd.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winfqitd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\ctrtmr.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\ctrtmr.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\hkcmd.exe"="C:\WINDOWS\system32\hkcmd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\qohiq.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\qohiq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\phle.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\phle.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\wincwuoki.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\wincwuoki.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winoshipl.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winoshipl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winrpgu.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winrpgu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\wincexc.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\wincexc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winajyipw.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winajyipw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winxjgqbr.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winxjgqbr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\eybpr.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\eybpr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\ymlas.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\ymlas.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winheabea.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winheabea.exe:*:Enabled:ipsec"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\qpokp.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\qpokp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winbdbvcm.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winbdbvcm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winrbjlw.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winrbjlw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winupnjnm.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winupnjnm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winoduee.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winoduee.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winemvsw.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winemvsw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\biqfv.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\biqfv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winsacch.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winsacch.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winionarp.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winionarp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\vaaxy.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\vaaxy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winetagen.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winetagen.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\txgu.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\txgu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winlejp.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winlejp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winhetpb.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winhetpb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winyaqh.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winyaqh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\xegtq.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\xegtq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winlyno.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winlyno.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\ydfkac.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\ydfkac.exe:*:Enabled:ipsec"
"C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winhvuqf.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winhvuqf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winqodln.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winqodln.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winvafmg.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winvafmg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\wincdoacg.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\wincdoacg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\odyja.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\odyja.exe:*:Enabled:ipsec"
"C:\DOCUME~1\David\LOCALS~1\Temp\winmtep.exe"="C:\DOCUME~1\David\LOCALS~1\Temp\winmtep.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=divx.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.DIVX"=DivX.dll
======List of files/folders created in the last 1 month======
2011-08-05 14:12:30 ----D---- C:\Program Files\trend micro
2011-08-05 14:12:29 ----D---- C:\rsit
2011-08-05 14:06:20 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-08-05 14:06:19 ----D---- C:\Documents and Settings\David\Data aplikací\Spyware Terminator
2011-08-05 14:06:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-08-05 14:06:13 ----D---- C:\Program Files\Spyware Terminator
2011-08-04 14:22:11 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2011-08-04 14:21:11 ----A---- C:\WINDOWS\system32\ztvunrar36.dll
2011-08-04 14:21:11 ----A---- C:\WINDOWS\system32\ztvunace26.dll
2011-08-04 14:21:11 ----A---- C:\WINDOWS\system32\ztvcabinet.dll
2011-08-04 14:21:11 ----A---- C:\WINDOWS\system32\UNRAR3.dll
2011-08-04 14:21:11 ----A---- C:\WINDOWS\system32\unacev2.dll
2011-08-04 14:21:10 ----D---- C:\Program Files\Trojan Remover
2011-08-04 14:21:10 ----D---- C:\Documents and Settings\David\Data aplikací\Simply Super Software
2011-08-04 14:21:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Simply Super Software
2011-08-04 12:58:37 ----SD---- C:\ComboFix
2011-08-04 12:57:14 ----A---- C:\WINDOWS\system32\CF3894.exe
2011-08-04 12:56:45 ----A---- C:\WINDOWS\system32\CF3780.exe
2011-08-04 12:47:08 ----A---- C:\Boot.bak
2011-08-04 12:47:01 ----RASHD---- C:\cmdcons
2011-08-04 12:45:32 ----A---- C:\WINDOWS\zip.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\SWSC.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\SWREG.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\sed.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\PEV.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\NIRCMD.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\MBR.exe
2011-08-04 12:45:32 ----A---- C:\WINDOWS\grep.exe
2011-08-04 12:45:25 ----D---- C:\WINDOWS\ERDNT
2011-08-04 12:44:56 ----D---- C:\Qoobox
2011-08-04 12:13:07 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-08-04 12:12:02 ----A---- C:\WINDOWS\system32\gpedit.msc
2011-08-04 12:12:02 ----A---- C:\WINDOWS\system32\gpedit.dll
2011-08-04 12:12:01 ----A---- C:\WINDOWS\system32\fdeploy.dll
2011-08-04 12:12:01 ----A---- C:\WINDOWS\system32\fde.dll
2011-08-04 12:12:01 ----A---- C:\WINDOWS\system32\appmgr.dll
2011-08-04 12:12:01 ----A---- C:\WINDOWS\system32\appmgmts.dll
2011-08-04 12:12:00 ----A---- C:\WINDOWS\system32\gptext.dll
2011-08-04 10:51:10 ----D---- C:\Documents and Settings\David\Data aplikací\Malwarebytes
2011-08-04 10:50:49 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-08-04 10:50:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-08-04 10:50:45 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-08-04 10:50:45 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-07-27 17:14:16 ----D---- C:\Program Files\Sony Ericsson
2011-07-27 17:14:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony Ericsson
2011-07-26 10:21:40 ----D---- C:\Documents and Settings\David\Data aplikací\COWON
2011-07-26 10:00:39 ----D---- C:\Program Files\Common Files\COWON
2011-07-26 10:00:35 ----D---- C:\Program Files\JetAudio
======List of files/folders modified in the last 1 month======
2011-08-05 14:12:30 ----D---- C:\Program Files
2011-08-05 14:06:21 ----D---- C:\WINDOWS\system32\drivers
2011-08-05 14:05:43 ----D---- C:\WINDOWS\system32
2011-08-05 14:05:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-08-05 14:04:22 ----D---- C:\WINDOWS\Temp
2011-08-04 18:56:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-04 17:17:59 ----D---- C:\WINDOWS\Prefetch
2011-08-04 14:45:45 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-04 14:45:12 ----D---- C:\WINDOWS\Minidump
2011-08-04 14:45:12 ----D---- C:\WINDOWS
2011-08-04 12:47:08 ----RASH---- C:\boot.ini
2011-08-04 12:42:27 ----D---- C:\WINDOWS\EHome
2011-08-04 12:03:02 ----RSD---- C:\WINDOWS\assembly
2011-08-04 10:51:05 ----SHD---- C:\WINDOWS\Installer
2011-08-04 10:20:25 ----D---- C:\Documents and Settings\David\Data aplikací\Sony
2011-08-03 23:20:45 ----D---- C:\Documents and Settings\David\Data aplikací\Skype
2011-08-03 11:29:12 ----D---- C:\WINDOWS\system32\Restore
2011-08-02 12:53:47 ----A---- C:\WINDOWS\win.ini
2011-07-30 11:25:56 ----RSD---- C:\WINDOWS\Fonts
2011-07-27 19:26:43 ----HD---- C:\WINDOWS\inf
2011-07-27 17:32:26 ----D---- C:\Program Files\Mozilla Firefox
2011-07-27 17:16:26 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-07-27 17:14:16 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-26 10:00:39 ----D---- C:\Program Files\Common Files
2011-07-26 09:54:09 ----D---- C:\WINDOWS\system32\LogFiles
2011-07-22 13:45:33 ----A---- C:\WINDOWS\system.ini
2011-07-21 18:00:24 ----D---- C:\Program Files\Hotspot Shield
2011-07-08 11:18:42 ----D---- C:\WINDOWS\peernet
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\System32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R1 ANC;ANC; C:\WINDOWS\System32\drivers\ANC.SYS [2011-04-08 11520]
R1 IBMTPCHK;IBMTPCHK; \??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2010-05-19 13952]
R3 abp470n5;abp470n5; \??\C:\WINDOWS\system32\drivers\goumop.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-04-24 308736]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2008-04-24 103424]
R3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2009-09-18 533152]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2010-09-23 993576]
R3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2010-09-16 51752]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2009-06-18 234496]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HssDrv;Hotspot Shield Helper Miniport; C:\WINDOWS\system32\DRIVERS\HssDrv.sys [2010-09-22 37376]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2010-01-13 1730272]
R3 NETwLx32; Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETwLx32.sys [2010-10-07 6609920]
R3 sdbus;sdbus; C:\WINDOWS\System32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2011-04-15 32768]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\safedrv.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 sffdisk;Ovladač třídy úložiště SFF; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2008-04-14 11904]
S3 sffp_sd;Ovladač protokolu úložiště SFF pro paměť sběrnici SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2008-04-14 11008]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2011-02-18 41984]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcPrfMgrSvc;Ac Profile Manager Service; C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe [2011-04-14 103784]
R2 AcSvc;Access Connections Main Service; C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe [2011-04-14 243048]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-04-06 349472]
R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe [2010-09-22 349528]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2010-12-17 936208]
R2 hshld;Hotspot Shield Service; C:\Program Files\Hotspot Shield\bin\openvpnas.exe [2011-07-01 298824]
R2 HssSrv;Hotspot Shield Routing Service; C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe [2011-05-25 363336]
R2 HssWd;Hotspot Shield Monitoring Service; C:\Program Files\Hotspot Shield\bin\hsswd.exe [2011-05-25 329544]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2010-12-17 477456]
R2 S24EventMonitor;Intel(R) PROSet/Wireless WiFi Service; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [2010-12-23 915728]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-08-05 496128]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-04-14 820520]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\pev.cfxxe [2011-06-26 256000]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 HssTrayService;Hotspot Shield Tray Service; C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE [2011-07-01 133608]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [2010-12-31 20549]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe [2010-12-31 8133120]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]
-----------------EOF-----------------