
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
facebook vir
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
facebook vir
Logfile of random's system information tool 1.09 (written by random/random)
Run by Martin at 2011-08-22 13:47:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 17 GB (22%) free of 76 GB
Total RAM: 3071 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:48:07, on 22.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\DllHost.exe
D:\World of Warcraft\Wow.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [1707595.exe] "C:\Windows\Temp\1707595.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ShowAnalyzerMaster - Dragon Global - C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\SysWOW64\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11720 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
ATKOSD.exe
KBFiltr.exe
WDC.exe
taskeng.exe {875145E1-496C-4CC9-933F-96919B41F5D7}
C:\Windows\SysWOW64\nvSCPAPISvr.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\ASUS\Net4Switch\Net4Switch.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\SysWOW64\DllHost.exe /Processid:{FCC74B77-EC3E-4DD8-A80B-008A702075A9}
"C:\Program Files\Windows Sidebar\sidebar.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"D:\World of Warcraft\Wow.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=408.658a990.1340092272 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.6.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 408 "\\.\pipe\gecko-crash-server-pipe.408" plugin
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"c:\program files\windows defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 9CC5D8BB-24B2-EE03-4C66-84EF4EA6A20E -Reinvoke
"C:\Users\Martin\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default
prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT17505 ... hSource=13"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\extensions\
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2008-12-08 68960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-09-16 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2010-09-16 318960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2008-12-04 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-09-16 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2010-09-16 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2010-09-16 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-09-16 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-09-16 256112]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [2010-03-16 1754448]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-12-11 16414824]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-09-30 621440]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2009-09-02 323584]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2918656]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-09-16 3054136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boingo Wi-Fi]
C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2010-09-16 2429]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-21 9639424]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2009-10-27 6998656]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2009-08-20 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-07-19 421736]
"tray_ico"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"1707595.exe"=C:\Windows\Temp\1707595.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-08-22 13:47:58 ----D---- C:\rsit
2011-08-22 13:47:58 ----D---- C:\Program Files\trend micro
2011-08-22 11:43:20 ----D---- C:\ProgramData\ESET
2011-08-22 11:43:20 ----D---- C:\Program Files\ESET
2011-08-21 17:47:32 ----D---- C:\ProgramData\AVAST Software
2011-08-21 17:47:32 ----D---- C:\Program Files\AVAST Software
2011-08-21 17:18:05 ----A---- C:\ProgramData\NTUSER.DAT
2011-08-20 08:38:20 ----D---- C:\Users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 08:38:20 ----D---- C:\Users\Martin\AppData\Roaming\BSplayer
2011-08-20 08:38:19 ----D---- C:\Program Files (x86)\Webteh
2011-08-19 13:16:38 ----HD---- C:\Windows\update.7.1
2011-08-19 10:40:09 ----D---- C:\Windows\ufa
2011-08-19 10:40:09 ----D---- C:\Windows\rpcminer
2011-08-19 10:40:09 ----D---- C:\Windows\phoenix
2011-08-19 10:38:43 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-19 10:38:33 ----A---- C:\Windows\unrar.exe
2011-08-19 10:38:19 ----HD---- C:\Windows\update.5.0
2011-08-19 10:38:11 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-19 10:37:44 ----HD---- C:\Windows\update.2
2011-08-19 10:34:26 ----A---- C:\Windows\iplist.txt
2011-08-19 10:33:20 ----D---- C:\Windows\av_ico
2011-08-19 10:33:15 ----A---- C:\Windows\front_ip_list.txt
2011-08-19 10:23:18 ----HD---- C:\Windows\update.1
2011-08-19 10:23:15 ----HD---- C:\Windows\update.tray-9-0-lnk
2011-08-19 10:23:15 ----HD---- C:\Windows\update.tray-9-0
2011-08-19 10:23:14 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-08-19 10:23:14 ----HD---- C:\Windows\update.tray-7-0
2011-08-19 10:09:21 ----A---- C:\Windows\winlog-ids.txt
2011-08-19 10:09:21 ----A---- C:\Windows\winlog-dirs.txt
2011-08-14 22:13:23 ----D---- C:\Program Files (x86)\Veetle
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-08-12 05:42:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-08-12 05:42:39 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-08-12 05:42:37 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-08-12 05:42:37 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-08-12 05:42:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-08-12 05:42:35 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-08-12 05:42:34 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-08-12 05:42:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-08-12 05:42:33 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-08-12 05:42:27 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-08-12 05:42:27 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-08-12 05:42:26 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-08-12 05:42:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-08-12 05:42:25 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-08-12 05:42:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-08-12 05:42:25 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-08-12 05:42:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-08-12 05:42:23 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-08-12 05:42:18 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-08-12 05:42:18 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-08-12 05:42:17 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-08-12 05:42:17 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-08-12 05:42:17 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-08-12 05:42:17 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-08-12 05:42:15 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-08-12 05:42:15 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-08-12 05:42:14 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-08-12 05:42:14 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-08-12 05:42:13 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-08-12 05:42:13 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-08-12 05:42:12 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-08-12 05:42:11 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-08-12 05:42:11 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-08-12 05:42:10 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-08-12 05:42:10 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-08-12 05:42:09 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-08-12 05:42:09 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-08-12 05:42:08 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-08-12 05:42:08 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-08-12 05:42:05 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-08-12 05:42:04 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-08-12 05:42:04 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-08-12 05:41:59 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-08-12 05:41:57 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-08-12 05:41:57 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-08-12 05:41:56 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-08-12 05:41:56 ----A---- C:\Windows\system32\xinput1_3.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-08-12 05:41:54 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-08-12 05:41:54 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-08-12 05:41:51 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-08-12 05:41:51 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-08-12 05:41:50 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-08-12 05:41:50 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-08-12 05:41:50 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-08-12 05:41:50 ----A---- C:\Windows\system32\d3dx10.dll
2011-08-12 05:41:48 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-08-12 05:41:48 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-08-12 05:41:47 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-08-12 05:41:47 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-08-12 05:41:46 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-08-12 05:41:46 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-08-12 05:41:45 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-08-12 05:41:45 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xinput1_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xinput1_1.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-08-12 05:41:43 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-08-12 05:41:43 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-08-12 05:41:38 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-08-12 05:41:38 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-08-12 05:41:36 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-08-12 05:41:36 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-08-12 05:41:36 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-08-12 05:41:36 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-08-12 05:41:34 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-08-12 05:41:34 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-08-12 05:41:34 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-08-12 05:41:34 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-08-12 05:41:33 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-08-12 05:41:33 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-08-12 05:41:09 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-08-11 15:50:51 ----D---- C:\Program Files\CCleaner
2011-08-11 14:00:10 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-11 14:00:10 ----A---- C:\Windows\system32\xmllite.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 14:00:04 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 13:59:53 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 13:59:53 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 13:59:52 ----A---- C:\Windows\system32\wow64.dll
2011-08-11 13:59:52 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 13:59:52 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 13:59:51 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-08-11 13:59:51 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-08-11 13:59:51 ----A---- C:\Windows\system32\wow64win.dll
2011-08-11 13:59:51 ----A---- C:\Windows\system32\ntvdm64.dll
2011-08-11 13:59:50 ----A---- C:\Windows\system32\wow64cpu.dll
2011-08-11 13:59:49 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 13:59:48 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-08-11 13:59:48 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 13:59:46 ----A---- C:\Windows\SYSWOW64\user.exe
2011-08-11 13:59:46 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-08-11 13:59:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 13:59:39 ----A---- C:\Windows\system32\mshtml.dll
2011-08-11 13:59:35 ----A---- C:\Windows\system32\iertutil.dll
2011-08-11 13:59:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-11 13:59:33 ----A---- C:\Windows\system32\ieframe.dll
2011-08-11 13:59:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-11 13:59:29 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-11 13:59:29 ----A---- C:\Windows\system32\urlmon.dll
2011-08-11 13:59:28 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-11 13:59:28 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-11 13:59:28 ----A---- C:\Windows\system32\wininet.dll
2011-08-11 13:59:28 ----A---- C:\Windows\system32\msfeeds.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\url.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\ieui.dll
2011-08-11 13:59:26 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-08-11 13:59:26 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-11 13:59:22 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-08-11 13:59:22 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 13:59:21 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-08-10 17:39:50 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2011-08-10 17:39:30 ----RD---- C:\Program Files (x86)\Skype
2011-08-10 17:39:21 ----D---- C:\ProgramData\Skype
2011-08-10 16:48:53 ----D---- C:\ProgramData\Blizzard
2011-08-09 13:02:33 ----D---- C:\Program Files\Zrychleni Pocitace
2011-08-09 13:02:20 ----D---- C:\Users\Martin\AppData\Roaming\OpenCandy
2011-08-09 13:01:22 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-08-09 13:01:09 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-08-09 13:00:44 ----D---- C:\Users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 13:00:40 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-08-09 12:50:00 ----D---- C:\Users\Martin\AppData\Roaming\CyberLink
2011-08-08 18:45:35 ----D---- C:\ProgramData\VirtualizedApplications
2011-08-05 19:27:49 ----D---- C:\Users\Martin\AppData\Roaming\Leawo
2011-08-05 19:27:23 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-08-05 19:24:05 ----D---- C:\ProgramData\Dragon Global
2011-08-05 19:24:05 ----D---- C:\Program Files (x86)\Dragon Global
2011-08-05 19:22:46 ----D---- C:\Program Files (x86)\DVRMSToolbox
2011-07-30 12:27:31 ----D---- C:\Program Files\iPod
2011-07-30 12:27:29 ----D---- C:\Program Files\iTunes
2011-07-30 12:27:29 ----D---- C:\Program Files (x86)\iTunes
2011-07-30 12:25:54 ----D---- C:\Program Files\Bonjour
2011-07-30 12:25:54 ----D---- C:\Program Files (x86)\Bonjour
======List of files/folders modified in the last 1 month======
2011-08-22 13:48:07 ----D---- C:\Windows\Temp
2011-08-22 13:47:58 ----RD---- C:\Program Files
2011-08-22 13:46:36 ----D---- C:\Windows
2011-08-22 12:42:34 ----SHD---- C:\System Volume Information
2011-08-22 11:55:25 ----D---- C:\Windows\system32\config
2011-08-22 11:45:05 ----D---- C:\Windows\inf
2011-08-22 11:43:51 ----SHD---- C:\Windows\Installer
2011-08-22 11:43:44 ----D---- C:\Windows\system32\DriverStore
2011-08-22 11:43:44 ----D---- C:\Windows\system32\drivers
2011-08-22 11:43:44 ----D---- C:\Windows\system32\catroot
2011-08-22 11:43:41 ----D---- C:\Windows\system32\catroot2
2011-08-22 11:43:20 ----HD---- C:\ProgramData
2011-08-22 11:42:26 ----D---- C:\Windows\SysWOW64
2011-08-22 11:39:57 ----D---- C:\Windows\system32\Tasks
2011-08-22 11:35:12 ----D---- C:\Users\Martin\AppData\Roaming\TS3Client
2011-08-22 11:35:08 ----D---- C:\Windows\Logs
2011-08-22 11:35:08 ----D---- C:\Windows\debug
2011-08-22 09:37:06 ----D---- C:\Windows\system32\drivers\etc
2011-08-22 09:29:42 ----D---- C:\ProgramData\NVIDIA
2011-08-22 09:29:15 ----RD---- C:\Program Files (x86)
2011-08-21 17:17:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-08-21 15:00:55 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-08-20 05:11:37 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-08-13 16:31:19 ----D---- C:\Windows\System32
2011-08-13 16:31:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-13 15:25:38 ----D---- C:\Users\Martin\AppData\Roaming\Adobe
2011-08-12 15:39:32 ----D---- C:\Windows\Microsoft.NET
2011-08-12 15:39:31 ----RSD---- C:\Windows\assembly
2011-08-12 09:00:07 ----D---- C:\Windows\system32\NDF
2011-08-12 04:59:58 ----D---- C:\Windows\winsxs
2011-08-12 04:57:24 ----D---- C:\Windows\AppPatch
2011-08-12 04:57:23 ----D---- C:\Windows\SYSWOW64\migration
2011-08-12 04:57:23 ----D---- C:\Program Files\Internet Explorer
2011-08-12 04:57:23 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-12 04:57:19 ----D---- C:\Windows\system32\migration
2011-08-11 22:14:24 ----D---- C:\ProgramData\Microsoft Help
2011-08-11 22:11:03 ----A---- C:\Windows\system32\MRT.exe
2011-08-10 17:40:42 ----D---- C:\Program Files (x86)\Google
2011-08-10 17:40:04 ----D---- C:\Windows\Tasks
2011-08-09 13:07:09 ----SD---- C:\Users\Martin\AppData\Roaming\Microsoft
2011-08-09 12:49:53 ----D---- C:\ProgramData\CyberLink
2011-08-08 22:18:36 ----D---- C:\Users\Martin\AppData\Roaming\SoftGrid Client
2011-08-06 19:05:01 ----D---- C:\ProgramData\ASUS
2011-07-26 14:02:20 ----D---- C:\Windows\rescache
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-06-15 35384]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2010-04-27 244328]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-09 270912]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 125296]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 17464]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-22 2229280]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2009-08-21 84512]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-28 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-18 236544]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 61792]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-09-17 359552]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-05-25 37664]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-11-10 96896]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-07-12 387944]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-12-11 392296]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 ShowAnalyzerMaster;ShowAnalyzerMaster; C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
R3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-07-19 934760]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 42360]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-09-16 182768]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-06-17 1255736]
-----------------EOF-----------------
Run by Martin at 2011-08-22 13:47:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 17 GB (22%) free of 76 GB
Total RAM: 3071 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:48:07, on 22.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\DllHost.exe
D:\World of Warcraft\Wow.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [1707595.exe] "C:\Windows\Temp\1707595.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ShowAnalyzerMaster - Dragon Global - C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\SysWOW64\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11720 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
ATKOSD.exe
KBFiltr.exe
WDC.exe
taskeng.exe {875145E1-496C-4CC9-933F-96919B41F5D7}
C:\Windows\SysWOW64\nvSCPAPISvr.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\ASUS\Net4Switch\Net4Switch.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\SysWOW64\DllHost.exe /Processid:{FCC74B77-EC3E-4DD8-A80B-008A702075A9}
"C:\Program Files\Windows Sidebar\sidebar.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"D:\World of Warcraft\Wow.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=408.658a990.1340092272 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.6.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 408 "\\.\pipe\gecko-crash-server-pipe.408" plugin
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"c:\program files\windows defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 9CC5D8BB-24B2-EE03-4C66-84EF4EA6A20E -Reinvoke
"C:\Users\Martin\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default
prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT17505 ... hSource=13"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\extensions\
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2008-12-08 68960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-09-16 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2010-09-16 318960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2008-12-04 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-09-16 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2010-09-16 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2010-09-16 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-09-16 346736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-09-16 256112]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [2010-03-16 1754448]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-12-11 16414824]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-09-30 621440]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2009-09-02 323584]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2918656]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-09-16 3054136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boingo Wi-Fi]
C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2010-09-16 2429]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-21 9639424]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2009-10-27 6998656]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2009-08-20 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-07-19 421736]
"tray_ico"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"1707595.exe"=C:\Windows\Temp\1707595.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-08-22 13:47:58 ----D---- C:\rsit
2011-08-22 13:47:58 ----D---- C:\Program Files\trend micro
2011-08-22 11:43:20 ----D---- C:\ProgramData\ESET
2011-08-22 11:43:20 ----D---- C:\Program Files\ESET
2011-08-21 17:47:32 ----D---- C:\ProgramData\AVAST Software
2011-08-21 17:47:32 ----D---- C:\Program Files\AVAST Software
2011-08-21 17:18:05 ----A---- C:\ProgramData\NTUSER.DAT
2011-08-20 08:38:20 ----D---- C:\Users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 08:38:20 ----D---- C:\Users\Martin\AppData\Roaming\BSplayer
2011-08-20 08:38:19 ----D---- C:\Program Files (x86)\Webteh
2011-08-19 13:16:38 ----HD---- C:\Windows\update.7.1
2011-08-19 10:40:09 ----D---- C:\Windows\ufa
2011-08-19 10:40:09 ----D---- C:\Windows\rpcminer
2011-08-19 10:40:09 ----D---- C:\Windows\phoenix
2011-08-19 10:38:43 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-19 10:38:33 ----A---- C:\Windows\unrar.exe
2011-08-19 10:38:19 ----HD---- C:\Windows\update.5.0
2011-08-19 10:38:11 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-19 10:37:44 ----HD---- C:\Windows\update.2
2011-08-19 10:34:26 ----A---- C:\Windows\iplist.txt
2011-08-19 10:33:20 ----D---- C:\Windows\av_ico
2011-08-19 10:33:15 ----A---- C:\Windows\front_ip_list.txt
2011-08-19 10:23:18 ----HD---- C:\Windows\update.1
2011-08-19 10:23:15 ----HD---- C:\Windows\update.tray-9-0-lnk
2011-08-19 10:23:15 ----HD---- C:\Windows\update.tray-9-0
2011-08-19 10:23:14 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-08-19 10:23:14 ----HD---- C:\Windows\update.tray-7-0
2011-08-19 10:09:21 ----A---- C:\Windows\winlog-ids.txt
2011-08-19 10:09:21 ----A---- C:\Windows\winlog-dirs.txt
2011-08-14 22:13:23 ----D---- C:\Program Files (x86)\Veetle
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-08-12 05:42:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-08-12 05:42:39 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-08-12 05:42:37 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-08-12 05:42:37 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-08-12 05:42:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-08-12 05:42:35 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-08-12 05:42:34 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-08-12 05:42:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-08-12 05:42:33 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-08-12 05:42:27 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-08-12 05:42:27 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-08-12 05:42:26 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-08-12 05:42:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-08-12 05:42:25 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-08-12 05:42:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-08-12 05:42:25 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-08-12 05:42:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-08-12 05:42:23 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-08-12 05:42:18 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-08-12 05:42:18 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-08-12 05:42:17 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-08-12 05:42:17 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-08-12 05:42:17 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-08-12 05:42:17 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-08-12 05:42:15 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-08-12 05:42:15 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-08-12 05:42:14 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-08-12 05:42:14 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-08-12 05:42:13 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-08-12 05:42:13 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-08-12 05:42:12 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-08-12 05:42:11 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-08-12 05:42:11 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-08-12 05:42:10 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-08-12 05:42:10 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-08-12 05:42:09 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-08-12 05:42:09 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-08-12 05:42:08 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-08-12 05:42:08 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-08-12 05:42:05 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-08-12 05:42:04 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-08-12 05:42:04 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-08-12 05:41:59 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-08-12 05:41:57 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-08-12 05:41:57 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-08-12 05:41:56 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-08-12 05:41:56 ----A---- C:\Windows\system32\xinput1_3.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-08-12 05:41:54 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-08-12 05:41:54 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-08-12 05:41:51 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-08-12 05:41:51 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-08-12 05:41:50 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-08-12 05:41:50 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-08-12 05:41:50 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-08-12 05:41:50 ----A---- C:\Windows\system32\d3dx10.dll
2011-08-12 05:41:48 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-08-12 05:41:48 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-08-12 05:41:47 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-08-12 05:41:47 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-08-12 05:41:46 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-08-12 05:41:46 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-08-12 05:41:45 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-08-12 05:41:45 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xinput1_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xinput1_1.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-08-12 05:41:43 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-08-12 05:41:43 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-08-12 05:41:38 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-08-12 05:41:38 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-08-12 05:41:36 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-08-12 05:41:36 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-08-12 05:41:36 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-08-12 05:41:36 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-08-12 05:41:34 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-08-12 05:41:34 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-08-12 05:41:34 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-08-12 05:41:34 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-08-12 05:41:33 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-08-12 05:41:33 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-08-12 05:41:09 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-08-11 15:50:51 ----D---- C:\Program Files\CCleaner
2011-08-11 14:00:10 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-11 14:00:10 ----A---- C:\Windows\system32\xmllite.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 14:00:04 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 13:59:53 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 13:59:53 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 13:59:52 ----A---- C:\Windows\system32\wow64.dll
2011-08-11 13:59:52 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 13:59:52 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 13:59:51 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-08-11 13:59:51 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-08-11 13:59:51 ----A---- C:\Windows\system32\wow64win.dll
2011-08-11 13:59:51 ----A---- C:\Windows\system32\ntvdm64.dll
2011-08-11 13:59:50 ----A---- C:\Windows\system32\wow64cpu.dll
2011-08-11 13:59:49 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 13:59:48 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-08-11 13:59:48 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 13:59:46 ----A---- C:\Windows\SYSWOW64\user.exe
2011-08-11 13:59:46 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-08-11 13:59:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 13:59:39 ----A---- C:\Windows\system32\mshtml.dll
2011-08-11 13:59:35 ----A---- C:\Windows\system32\iertutil.dll
2011-08-11 13:59:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-11 13:59:33 ----A---- C:\Windows\system32\ieframe.dll
2011-08-11 13:59:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-11 13:59:29 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-11 13:59:29 ----A---- C:\Windows\system32\urlmon.dll
2011-08-11 13:59:28 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-11 13:59:28 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-11 13:59:28 ----A---- C:\Windows\system32\wininet.dll
2011-08-11 13:59:28 ----A---- C:\Windows\system32\msfeeds.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\url.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\ieui.dll
2011-08-11 13:59:26 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-08-11 13:59:26 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-11 13:59:22 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-08-11 13:59:22 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 13:59:21 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-08-10 17:39:50 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2011-08-10 17:39:30 ----RD---- C:\Program Files (x86)\Skype
2011-08-10 17:39:21 ----D---- C:\ProgramData\Skype
2011-08-10 16:48:53 ----D---- C:\ProgramData\Blizzard
2011-08-09 13:02:33 ----D---- C:\Program Files\Zrychleni Pocitace
2011-08-09 13:02:20 ----D---- C:\Users\Martin\AppData\Roaming\OpenCandy
2011-08-09 13:01:22 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-08-09 13:01:09 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-08-09 13:00:44 ----D---- C:\Users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 13:00:40 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-08-09 12:50:00 ----D---- C:\Users\Martin\AppData\Roaming\CyberLink
2011-08-08 18:45:35 ----D---- C:\ProgramData\VirtualizedApplications
2011-08-05 19:27:49 ----D---- C:\Users\Martin\AppData\Roaming\Leawo
2011-08-05 19:27:23 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-08-05 19:24:05 ----D---- C:\ProgramData\Dragon Global
2011-08-05 19:24:05 ----D---- C:\Program Files (x86)\Dragon Global
2011-08-05 19:22:46 ----D---- C:\Program Files (x86)\DVRMSToolbox
2011-07-30 12:27:31 ----D---- C:\Program Files\iPod
2011-07-30 12:27:29 ----D---- C:\Program Files\iTunes
2011-07-30 12:27:29 ----D---- C:\Program Files (x86)\iTunes
2011-07-30 12:25:54 ----D---- C:\Program Files\Bonjour
2011-07-30 12:25:54 ----D---- C:\Program Files (x86)\Bonjour
======List of files/folders modified in the last 1 month======
2011-08-22 13:48:07 ----D---- C:\Windows\Temp
2011-08-22 13:47:58 ----RD---- C:\Program Files
2011-08-22 13:46:36 ----D---- C:\Windows
2011-08-22 12:42:34 ----SHD---- C:\System Volume Information
2011-08-22 11:55:25 ----D---- C:\Windows\system32\config
2011-08-22 11:45:05 ----D---- C:\Windows\inf
2011-08-22 11:43:51 ----SHD---- C:\Windows\Installer
2011-08-22 11:43:44 ----D---- C:\Windows\system32\DriverStore
2011-08-22 11:43:44 ----D---- C:\Windows\system32\drivers
2011-08-22 11:43:44 ----D---- C:\Windows\system32\catroot
2011-08-22 11:43:41 ----D---- C:\Windows\system32\catroot2
2011-08-22 11:43:20 ----HD---- C:\ProgramData
2011-08-22 11:42:26 ----D---- C:\Windows\SysWOW64
2011-08-22 11:39:57 ----D---- C:\Windows\system32\Tasks
2011-08-22 11:35:12 ----D---- C:\Users\Martin\AppData\Roaming\TS3Client
2011-08-22 11:35:08 ----D---- C:\Windows\Logs
2011-08-22 11:35:08 ----D---- C:\Windows\debug
2011-08-22 09:37:06 ----D---- C:\Windows\system32\drivers\etc
2011-08-22 09:29:42 ----D---- C:\ProgramData\NVIDIA
2011-08-22 09:29:15 ----RD---- C:\Program Files (x86)
2011-08-21 17:17:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-08-21 15:00:55 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-08-20 05:11:37 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-08-13 16:31:19 ----D---- C:\Windows\System32
2011-08-13 16:31:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-13 15:25:38 ----D---- C:\Users\Martin\AppData\Roaming\Adobe
2011-08-12 15:39:32 ----D---- C:\Windows\Microsoft.NET
2011-08-12 15:39:31 ----RSD---- C:\Windows\assembly
2011-08-12 09:00:07 ----D---- C:\Windows\system32\NDF
2011-08-12 04:59:58 ----D---- C:\Windows\winsxs
2011-08-12 04:57:24 ----D---- C:\Windows\AppPatch
2011-08-12 04:57:23 ----D---- C:\Windows\SYSWOW64\migration
2011-08-12 04:57:23 ----D---- C:\Program Files\Internet Explorer
2011-08-12 04:57:23 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-12 04:57:19 ----D---- C:\Windows\system32\migration
2011-08-11 22:14:24 ----D---- C:\ProgramData\Microsoft Help
2011-08-11 22:11:03 ----A---- C:\Windows\system32\MRT.exe
2011-08-10 17:40:42 ----D---- C:\Program Files (x86)\Google
2011-08-10 17:40:04 ----D---- C:\Windows\Tasks
2011-08-09 13:07:09 ----SD---- C:\Users\Martin\AppData\Roaming\Microsoft
2011-08-09 12:49:53 ----D---- C:\ProgramData\CyberLink
2011-08-08 22:18:36 ----D---- C:\Users\Martin\AppData\Roaming\SoftGrid Client
2011-08-06 19:05:01 ----D---- C:\ProgramData\ASUS
2011-07-26 14:02:20 ----D---- C:\Windows\rescache
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-06-15 35384]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2010-04-27 244328]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-09 270912]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 125296]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 17464]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-22 2229280]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2009-08-21 84512]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-28 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-18 236544]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 61792]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-09-17 359552]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-05-25 37664]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-11-10 96896]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-07-12 387944]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-12-11 392296]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 ShowAnalyzerMaster;ShowAnalyzerMaster; C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
R3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-07-19 934760]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 42360]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-09-16 182768]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-06-17 1255736]
-----------------EOF-----------------
Re: facebook vir
Zdravím, tohle fixni v HJT :
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [1707595.exe] "C:\Windows\Temp\1707595.exe"
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
HJT najdeš zde :
C:\Program Files\trend micro\Martin.exe
Fix znamená že spustíš HJT
jako admin
v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :
Služba Google Update (gupdate)
Služba Google Update (gupdatem)
Google Software Updater (gusvc)
McAfee Security Scan Component Host Service
klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.
Přes Odebrat programy odinstaluj vše od McAfee
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Pak použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !!!
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [1707595.exe] "C:\Windows\Temp\1707595.exe"
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
HJT najdeš zde :
C:\Program Files\trend micro\Martin.exe
Fix znamená že spustíš HJT

v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :
Služba Google Update (gupdate)
Služba Google Update (gupdatem)
Google Software Updater (gusvc)
McAfee Security Scan Component Host Service
klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.
Přes Odebrat programy odinstaluj vše od McAfee
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Pak použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !!!
Re: facebook vir
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Verze databáze: 7535
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
22.8.2011 17:08:49
mbam-log-2011-08-22 (17-08-41).txt
Typ kontroly: Rychlý test
Testované objekty: 172227
Uplynulý čas: 3 minut, 44 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 5
Infikované hodnoty v registru: 1
Infikované datové položky v registru: 3
Infikované složky: 1
Infikované soubory: 14
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> No action taken.
Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> No action taken.
Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Infikované složky:
c:\Windows\rpcminer (Trojan.BCMiner) -> No action taken.
Infikované soubory:
c:\Windows\rpcminer\bitcoinmineropencl.cl (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_10.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_11.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_20.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\cudart32_32_16.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\curllib.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\libeay32.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\libsasl.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\openldap.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-4way.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-cpu.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-cuda.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-opencl.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\ssleay32.dll (Trojan.BCMiner) -> No action taken.
www.malwarebytes.org
Verze databáze: 7535
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
22.8.2011 17:08:49
mbam-log-2011-08-22 (17-08-41).txt
Typ kontroly: Rychlý test
Testované objekty: 172227
Uplynulý čas: 3 minut, 44 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 5
Infikované hodnoty v registru: 1
Infikované datové položky v registru: 3
Infikované složky: 1
Infikované soubory: 14
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> No action taken.
Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> No action taken.
Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Infikované složky:
c:\Windows\rpcminer (Trojan.BCMiner) -> No action taken.
Infikované soubory:
c:\Windows\rpcminer\bitcoinmineropencl.cl (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_10.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_11.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_20.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\cudart32_32_16.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\curllib.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\libeay32.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\libsasl.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\openldap.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-4way.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-cpu.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-cuda.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-opencl.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\ssleay32.dll (Trojan.BCMiner) -> No action taken.
Re: facebook vir
To co Mbam našel nech smazat.
Nyní použijeme větší kalibr tak že pozorně čti, protože tenhle softík netoleruje chyby.
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Nyní použijeme větší kalibr tak že pozorně čti, protože tenhle softík netoleruje chyby.
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Re: facebook vir
ComboFix 11-08-23.01 - Martin 23.08.2011 11:59:29.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3071.1709 [GMT 2:00]
Spuštěný z: c:\users\Martin\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\programdata\ntuser.dat
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-23 do 2011-08-23 )))))))))))))))))))))))))))))))
.
.
2011-08-23 10:05 . 2011-08-23 10:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-23 09:57 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FC62B65-97E7-4FB2-9C05-78319483F57A}\mpengine.dll
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\users\Martin\AppData\Roaming\Malwarebytes
2011-08-22 14:15 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\programdata\Malwarebytes
2011-08-22 14:15 . 2011-08-22 15:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-22 14:15 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 11:47 . 2011-08-22 13:20 -------- d-----w- c:\program files\trend micro
2011-08-22 11:47 . 2011-08-22 11:48 -------- d-----w- C:\rsit
2011-08-22 09:44 . 2011-08-22 09:44 -------- d-----w- c:\users\Martin\AppData\Local\ESET
2011-08-22 09:43 . 2011-08-22 09:43 -------- d-----w- c:\program files\ESET
2011-08-21 15:47 . 2011-08-22 09:42 -------- d-----w- c:\programdata\AVAST Software
2011-08-21 15:47 . 2011-08-21 15:47 -------- d-----w- c:\program files\AVAST Software
2011-08-20 06:38 . 2011-08-20 06:42 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\program files (x86)\Webteh
2011-08-19 11:16 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.7.1
2011-08-19 08:40 . 2011-08-21 13:06 -------- d-----w- c:\windows\ufa
2011-08-19 08:38 . 2011-08-21 13:06 246272 ----a-w- c:\windows\unrar.exe
2011-08-19 08:33 . 2011-08-19 08:33 -------- d-----w- c:\windows\av_ico
2011-08-19 08:23 . 2011-08-22 10:25 -------- d--h--w- c:\windows\update.tray-9-0-lnk
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-9-0
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-7-0
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-08-14 20:13 . 2011-08-14 20:13 -------- d-----w- c:\program files (x86)\Veetle
2011-08-14 20:05 . 2011-08-14 20:05 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-13 13:25 . 2011-08-13 13:26 -------- d-----w- c:\users\Martin\AppData\Local\Adobe
2011-08-12 03:41 . 2007-05-16 14:45 506728 ----a-w- c:\windows\system32\d3dx10_34.dll
2011-08-11 13:50 . 2011-08-11 13:50 -------- d-----w- c:\program files\CCleaner
2011-08-10 16:30 . 2011-08-10 16:30 -------- d-----w- c:\users\Martin\AppData\Local\2K Games
2011-08-10 15:39 . 2011-08-11 14:04 -------- d-----w- c:\users\Martin\AppData\Roaming\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----r- c:\program files (x86)\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----w- c:\programdata\Skype
2011-08-10 14:48 . 2011-08-10 14:48 -------- d-----w- c:\programdata\Blizzard
2011-08-09 11:02 . 2011-08-09 16:13 -------- d-----w- c:\program files\Zrychleni Pocitace
2011-08-09 11:02 . 2011-08-09 15:13 -------- d-----w- c:\users\Martin\AppData\Local\OpenCandy
2011-08-09 11:02 . 2011-08-09 11:02 -------- d-----w- c:\users\Martin\AppData\Roaming\OpenCandy
2011-08-09 11:01 . 2011-08-09 11:01 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-09 11:01 . 2011-08-09 11:01 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-22 09:35 -------- d-----w- c:\users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-12 03:38 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Public\CyberLink
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Martin\AppData\Roaming\CyberLink
2011-08-08 16:45 . 2011-08-09 03:32 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-06 17:04 . 2011-08-06 17:04 -------- d-----w- c:\users\Martin\AppData\Local\ASUS
2011-08-05 17:27 . 2011-08-05 17:27 -------- d-----w- c:\users\Martin\AppData\Roaming\Leawo
2011-08-05 17:27 . 2008-10-28 08:10 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2011-08-05 17:27 . 2008-10-08 07:45 606208 ----a-w- c:\windows\SysWow64\xvidcore.dll
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\programdata\Dragon Global
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\program files (x86)\Dragon Global
2011-08-05 17:23 . 2011-08-05 17:39 -------- d-----w- c:\users\Public\DvrmsToolbox
2011-08-05 17:22 . 2011-08-05 17:41 -------- d-----w- c:\program files (x86)\DVRMSToolbox
2011-07-30 10:27 . 2011-07-30 10:27 -------- d-----w- c:\program files\iPod
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files\iTunes
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files (x86)\iTunes
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files\Bonjour
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files (x86)\Bonjour
2011-07-29 18:32 . 2011-07-29 19:07 -------- d-----w- c:\users\Martin\AppData\Local\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 04:26 . 2011-08-11 11:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-04 11:43 . 2011-06-15 14:58 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-22 16:33 . 2011-06-22 16:33 34064 ----a-w- c:\windows\SysWow64\lhacm.acm
2011-06-20 06:54 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-20 06:54 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-06-15 15:31 . 2011-06-15 15:31 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-06-11 03:07 . 2011-07-13 11:55 3137536 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2009-10-27 6998656]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2009-08-20 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-9-16 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-9-16 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 ShowAnalyzerMaster;ShowAnalyzerMaster;c:\program files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
2011-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 14:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 16414824]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2918656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Toolbar-Locked - (no file)
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
AddRemove-Counter-Strike 1.6 v42b instalace - c:\program files (x86)\Counter-Strike 1.6\Uninstal.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-23 12:11:37 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-23 10:11
.
Před spuštěním: Volných bajtů: 17 837 584 384
Po spuštění: Volných bajtů: 17 426 857 984
.
- - End Of File - - 7F3FE910DE45000CE5C87171D9E9B7EB
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3071.1709 [GMT 2:00]
Spuštěný z: c:\users\Martin\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\programdata\ntuser.dat
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-23 do 2011-08-23 )))))))))))))))))))))))))))))))
.
.
2011-08-23 10:05 . 2011-08-23 10:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-23 09:57 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FC62B65-97E7-4FB2-9C05-78319483F57A}\mpengine.dll
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\users\Martin\AppData\Roaming\Malwarebytes
2011-08-22 14:15 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\programdata\Malwarebytes
2011-08-22 14:15 . 2011-08-22 15:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-22 14:15 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 11:47 . 2011-08-22 13:20 -------- d-----w- c:\program files\trend micro
2011-08-22 11:47 . 2011-08-22 11:48 -------- d-----w- C:\rsit
2011-08-22 09:44 . 2011-08-22 09:44 -------- d-----w- c:\users\Martin\AppData\Local\ESET
2011-08-22 09:43 . 2011-08-22 09:43 -------- d-----w- c:\program files\ESET
2011-08-21 15:47 . 2011-08-22 09:42 -------- d-----w- c:\programdata\AVAST Software
2011-08-21 15:47 . 2011-08-21 15:47 -------- d-----w- c:\program files\AVAST Software
2011-08-20 06:38 . 2011-08-20 06:42 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\program files (x86)\Webteh
2011-08-19 11:16 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.7.1
2011-08-19 08:40 . 2011-08-21 13:06 -------- d-----w- c:\windows\ufa
2011-08-19 08:38 . 2011-08-21 13:06 246272 ----a-w- c:\windows\unrar.exe
2011-08-19 08:33 . 2011-08-19 08:33 -------- d-----w- c:\windows\av_ico
2011-08-19 08:23 . 2011-08-22 10:25 -------- d--h--w- c:\windows\update.tray-9-0-lnk
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-9-0
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-7-0
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-08-14 20:13 . 2011-08-14 20:13 -------- d-----w- c:\program files (x86)\Veetle
2011-08-14 20:05 . 2011-08-14 20:05 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-13 13:25 . 2011-08-13 13:26 -------- d-----w- c:\users\Martin\AppData\Local\Adobe
2011-08-12 03:41 . 2007-05-16 14:45 506728 ----a-w- c:\windows\system32\d3dx10_34.dll
2011-08-11 13:50 . 2011-08-11 13:50 -------- d-----w- c:\program files\CCleaner
2011-08-10 16:30 . 2011-08-10 16:30 -------- d-----w- c:\users\Martin\AppData\Local\2K Games
2011-08-10 15:39 . 2011-08-11 14:04 -------- d-----w- c:\users\Martin\AppData\Roaming\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----r- c:\program files (x86)\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----w- c:\programdata\Skype
2011-08-10 14:48 . 2011-08-10 14:48 -------- d-----w- c:\programdata\Blizzard
2011-08-09 11:02 . 2011-08-09 16:13 -------- d-----w- c:\program files\Zrychleni Pocitace
2011-08-09 11:02 . 2011-08-09 15:13 -------- d-----w- c:\users\Martin\AppData\Local\OpenCandy
2011-08-09 11:02 . 2011-08-09 11:02 -------- d-----w- c:\users\Martin\AppData\Roaming\OpenCandy
2011-08-09 11:01 . 2011-08-09 11:01 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-09 11:01 . 2011-08-09 11:01 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-22 09:35 -------- d-----w- c:\users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-12 03:38 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Public\CyberLink
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Martin\AppData\Roaming\CyberLink
2011-08-08 16:45 . 2011-08-09 03:32 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-06 17:04 . 2011-08-06 17:04 -------- d-----w- c:\users\Martin\AppData\Local\ASUS
2011-08-05 17:27 . 2011-08-05 17:27 -------- d-----w- c:\users\Martin\AppData\Roaming\Leawo
2011-08-05 17:27 . 2008-10-28 08:10 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2011-08-05 17:27 . 2008-10-08 07:45 606208 ----a-w- c:\windows\SysWow64\xvidcore.dll
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\programdata\Dragon Global
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\program files (x86)\Dragon Global
2011-08-05 17:23 . 2011-08-05 17:39 -------- d-----w- c:\users\Public\DvrmsToolbox
2011-08-05 17:22 . 2011-08-05 17:41 -------- d-----w- c:\program files (x86)\DVRMSToolbox
2011-07-30 10:27 . 2011-07-30 10:27 -------- d-----w- c:\program files\iPod
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files\iTunes
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files (x86)\iTunes
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files\Bonjour
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files (x86)\Bonjour
2011-07-29 18:32 . 2011-07-29 19:07 -------- d-----w- c:\users\Martin\AppData\Local\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 04:26 . 2011-08-11 11:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-04 11:43 . 2011-06-15 14:58 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-22 16:33 . 2011-06-22 16:33 34064 ----a-w- c:\windows\SysWow64\lhacm.acm
2011-06-20 06:54 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-20 06:54 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-06-15 15:31 . 2011-06-15 15:31 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-06-11 03:07 . 2011-07-13 11:55 3137536 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2009-10-27 6998656]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2009-08-20 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-9-16 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-9-16 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 ShowAnalyzerMaster;ShowAnalyzerMaster;c:\program files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
2011-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 14:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 16414824]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2918656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Toolbar-Locked - (no file)
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
AddRemove-Counter-Strike 1.6 v42b instalace - c:\program files (x86)\Counter-Strike 1.6\Uninstal.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-23 12:11:37 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-23 10:11
.
Před spuštěním: Volných bajtů: 17 837 584 384
Po spuštění: Volných bajtů: 17 426 857 984
.
- - End Of File - - 7F3FE910DE45000CE5C87171D9E9B7EB
Re: facebook vir
Pokud jsi tak ještě neučinil, přesuň Combofix na Plochu
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
Kód: Vybrat vše
File::
c:\windows\unrar.exe
Folder::
c:\windows\update.7.1
c:\windows\ufa
c:\windows\av_ico
c:\windows\update.tray-9-0-lnk
c:\windows\update.tray-9-0
c:\windows\update.tray-7-0
c:\windows\update.tray-7-0-lnk
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000000
"DisableThumbnailCache"=dword:00000000
FireFox::
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT17505 ... hSource=13
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
Re: facebook vir
ComboFix 11-08-23.01 - Martin 23.08.2011 13:34:46.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3071.1121 [GMT 2:00]
Spuštěný z: c:\users\Martin\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Martin\Desktop\CFScript.txt.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_mcafee_start.ico
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.7.1
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0
c:\windows\update.tray-9-0-lnk
c:\windows\update.tray-9-0
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-23 do 2011-08-23 )))))))))))))))))))))))))))))))
.
.
2011-08-23 11:40 . 2011-08-23 11:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-23 09:57 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FC62B65-97E7-4FB2-9C05-78319483F57A}\mpengine.dll
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\users\Martin\AppData\Roaming\Malwarebytes
2011-08-22 14:15 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\programdata\Malwarebytes
2011-08-22 14:15 . 2011-08-22 15:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-22 14:15 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 11:47 . 2011-08-22 13:20 -------- d-----w- c:\program files\trend micro
2011-08-22 11:47 . 2011-08-22 11:48 -------- d-----w- C:\rsit
2011-08-22 09:44 . 2011-08-22 09:44 -------- d-----w- c:\users\Martin\AppData\Local\ESET
2011-08-22 09:43 . 2011-08-22 09:43 -------- d-----w- c:\program files\ESET
2011-08-21 15:47 . 2011-08-22 09:42 -------- d-----w- c:\programdata\AVAST Software
2011-08-21 15:47 . 2011-08-21 15:47 -------- d-----w- c:\program files\AVAST Software
2011-08-20 06:38 . 2011-08-20 06:42 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\program files (x86)\Webteh
2011-08-14 20:13 . 2011-08-14 20:13 -------- d-----w- c:\program files (x86)\Veetle
2011-08-14 20:05 . 2011-08-14 20:05 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-13 13:25 . 2011-08-13 13:26 -------- d-----w- c:\users\Martin\AppData\Local\Adobe
2011-08-12 03:41 . 2007-05-16 14:45 506728 ----a-w- c:\windows\system32\d3dx10_34.dll
2011-08-11 13:50 . 2011-08-11 13:50 -------- d-----w- c:\program files\CCleaner
2011-08-10 16:30 . 2011-08-10 16:30 -------- d-----w- c:\users\Martin\AppData\Local\2K Games
2011-08-10 15:39 . 2011-08-11 14:04 -------- d-----w- c:\users\Martin\AppData\Roaming\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----r- c:\program files (x86)\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----w- c:\programdata\Skype
2011-08-10 14:48 . 2011-08-10 14:48 -------- d-----w- c:\programdata\Blizzard
2011-08-09 11:02 . 2011-08-09 16:13 -------- d-----w- c:\program files\Zrychleni Pocitace
2011-08-09 11:02 . 2011-08-09 15:13 -------- d-----w- c:\users\Martin\AppData\Local\OpenCandy
2011-08-09 11:02 . 2011-08-09 11:02 -------- d-----w- c:\users\Martin\AppData\Roaming\OpenCandy
2011-08-09 11:01 . 2011-08-09 11:01 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-09 11:01 . 2011-08-09 11:01 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-22 09:35 -------- d-----w- c:\users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-12 03:38 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Public\CyberLink
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Martin\AppData\Roaming\CyberLink
2011-08-08 16:45 . 2011-08-09 03:32 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-06 17:04 . 2011-08-06 17:04 -------- d-----w- c:\users\Martin\AppData\Local\ASUS
2011-08-05 17:27 . 2011-08-05 17:27 -------- d-----w- c:\users\Martin\AppData\Roaming\Leawo
2011-08-05 17:27 . 2008-10-28 08:10 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2011-08-05 17:27 . 2008-10-08 07:45 606208 ----a-w- c:\windows\SysWow64\xvidcore.dll
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\programdata\Dragon Global
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\program files (x86)\Dragon Global
2011-08-05 17:23 . 2011-08-05 17:39 -------- d-----w- c:\users\Public\DvrmsToolbox
2011-08-05 17:22 . 2011-08-05 17:41 -------- d-----w- c:\program files (x86)\DVRMSToolbox
2011-07-30 10:27 . 2011-07-30 10:27 -------- d-----w- c:\program files\iPod
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files\iTunes
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files (x86)\iTunes
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files\Bonjour
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files (x86)\Bonjour
2011-07-29 18:32 . 2011-07-29 19:07 -------- d-----w- c:\users\Martin\AppData\Local\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 04:26 . 2011-08-11 11:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-04 11:43 . 2011-06-15 14:58 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-22 16:33 . 2011-06-22 16:33 34064 ----a-w- c:\windows\SysWow64\lhacm.acm
2011-06-20 06:54 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-20 06:54 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-06-15 15:31 . 2011-06-15 15:31 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-06-11 03:07 . 2011-07-13 11:55 3137536 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-23_10.07.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-23 11:41 . 2011-08-23 11:41 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-08-23 10:05 . 2011-08-23 10:05 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-16 19:48 . 2011-08-23 10:08 41650 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-23 10:08 41500 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-06-15 13:59 . 2011-08-23 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-15 13:59 . 2011-08-23 11:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-15 13:59 . 2011-08-23 11:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-06-15 13:59 . 2011-08-23 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-06-15 13:54 . 2011-08-23 10:08 9994 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1504789416-810619661-2310688379-1000_UserData.bin
+ 2011-08-23 11:41 . 2011-08-23 11:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-23 10:06 . 2011-08-23 10:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-23 11:41 . 2011-08-23 11:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-23 10:06 . 2011-08-23 10:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-08-23 10:05 389832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-08-23 11:41 389832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-08-19 08:34 . 2011-08-23 11:41 390600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1504789416-810619661-2310688379-1000-12288.dat
- 2011-08-19 08:34 . 2011-08-23 10:05 390600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1504789416-810619661-2310688379-1000-12288.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 2146304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 2146304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2009-10-27 6998656]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2009-08-20 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-9-16 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-9-16 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 ShowAnalyzerMaster;ShowAnalyzerMaster;c:\program files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 14:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 16414824]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2918656]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\windows\AsScrPro.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-23 13:47:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-23 11:46
ComboFix2.txt 2011-08-23 10:11
.
Před spuštěním: Volných bajtů: 17 179 639 808
Po spuštění: Volných bajtů: 17 108 942 848
.
- - End Of File - - 3B23DB4DF25F6B9BBF862811DDE7B1F4
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3071.1121 [GMT 2:00]
Spuštěný z: c:\users\Martin\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Martin\Desktop\CFScript.txt.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_mcafee_start.ico
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.7.1
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0
c:\windows\update.tray-9-0-lnk
c:\windows\update.tray-9-0
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-23 do 2011-08-23 )))))))))))))))))))))))))))))))
.
.
2011-08-23 11:40 . 2011-08-23 11:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-23 09:57 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FC62B65-97E7-4FB2-9C05-78319483F57A}\mpengine.dll
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\users\Martin\AppData\Roaming\Malwarebytes
2011-08-22 14:15 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\programdata\Malwarebytes
2011-08-22 14:15 . 2011-08-22 15:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-22 14:15 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 11:47 . 2011-08-22 13:20 -------- d-----w- c:\program files\trend micro
2011-08-22 11:47 . 2011-08-22 11:48 -------- d-----w- C:\rsit
2011-08-22 09:44 . 2011-08-22 09:44 -------- d-----w- c:\users\Martin\AppData\Local\ESET
2011-08-22 09:43 . 2011-08-22 09:43 -------- d-----w- c:\program files\ESET
2011-08-21 15:47 . 2011-08-22 09:42 -------- d-----w- c:\programdata\AVAST Software
2011-08-21 15:47 . 2011-08-21 15:47 -------- d-----w- c:\program files\AVAST Software
2011-08-20 06:38 . 2011-08-20 06:42 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\program files (x86)\Webteh
2011-08-14 20:13 . 2011-08-14 20:13 -------- d-----w- c:\program files (x86)\Veetle
2011-08-14 20:05 . 2011-08-14 20:05 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-13 13:25 . 2011-08-13 13:26 -------- d-----w- c:\users\Martin\AppData\Local\Adobe
2011-08-12 03:41 . 2007-05-16 14:45 506728 ----a-w- c:\windows\system32\d3dx10_34.dll
2011-08-11 13:50 . 2011-08-11 13:50 -------- d-----w- c:\program files\CCleaner
2011-08-10 16:30 . 2011-08-10 16:30 -------- d-----w- c:\users\Martin\AppData\Local\2K Games
2011-08-10 15:39 . 2011-08-11 14:04 -------- d-----w- c:\users\Martin\AppData\Roaming\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----r- c:\program files (x86)\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----w- c:\programdata\Skype
2011-08-10 14:48 . 2011-08-10 14:48 -------- d-----w- c:\programdata\Blizzard
2011-08-09 11:02 . 2011-08-09 16:13 -------- d-----w- c:\program files\Zrychleni Pocitace
2011-08-09 11:02 . 2011-08-09 15:13 -------- d-----w- c:\users\Martin\AppData\Local\OpenCandy
2011-08-09 11:02 . 2011-08-09 11:02 -------- d-----w- c:\users\Martin\AppData\Roaming\OpenCandy
2011-08-09 11:01 . 2011-08-09 11:01 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-09 11:01 . 2011-08-09 11:01 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-22 09:35 -------- d-----w- c:\users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-12 03:38 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Public\CyberLink
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Martin\AppData\Roaming\CyberLink
2011-08-08 16:45 . 2011-08-09 03:32 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-06 17:04 . 2011-08-06 17:04 -------- d-----w- c:\users\Martin\AppData\Local\ASUS
2011-08-05 17:27 . 2011-08-05 17:27 -------- d-----w- c:\users\Martin\AppData\Roaming\Leawo
2011-08-05 17:27 . 2008-10-28 08:10 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2011-08-05 17:27 . 2008-10-08 07:45 606208 ----a-w- c:\windows\SysWow64\xvidcore.dll
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\programdata\Dragon Global
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\program files (x86)\Dragon Global
2011-08-05 17:23 . 2011-08-05 17:39 -------- d-----w- c:\users\Public\DvrmsToolbox
2011-08-05 17:22 . 2011-08-05 17:41 -------- d-----w- c:\program files (x86)\DVRMSToolbox
2011-07-30 10:27 . 2011-07-30 10:27 -------- d-----w- c:\program files\iPod
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files\iTunes
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files (x86)\iTunes
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files\Bonjour
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files (x86)\Bonjour
2011-07-29 18:32 . 2011-07-29 19:07 -------- d-----w- c:\users\Martin\AppData\Local\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 04:26 . 2011-08-11 11:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-04 11:43 . 2011-06-15 14:58 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-22 16:33 . 2011-06-22 16:33 34064 ----a-w- c:\windows\SysWow64\lhacm.acm
2011-06-20 06:54 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-20 06:54 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-06-15 15:31 . 2011-06-15 15:31 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-06-11 03:07 . 2011-07-13 11:55 3137536 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-23_10.07.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-23 11:41 . 2011-08-23 11:41 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-08-23 10:05 . 2011-08-23 10:05 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-16 19:48 . 2011-08-23 10:08 41650 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-23 10:08 41500 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-06-15 13:59 . 2011-08-23 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-15 13:59 . 2011-08-23 11:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-15 13:59 . 2011-08-23 11:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-06-15 13:59 . 2011-08-23 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-06-15 13:54 . 2011-08-23 10:08 9994 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1504789416-810619661-2310688379-1000_UserData.bin
+ 2011-08-23 11:41 . 2011-08-23 11:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-23 10:06 . 2011-08-23 10:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-23 11:41 . 2011-08-23 11:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-23 10:06 . 2011-08-23 10:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-08-23 10:05 389832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-08-23 11:41 389832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-08-19 08:34 . 2011-08-23 11:41 390600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1504789416-810619661-2310688379-1000-12288.dat
- 2011-08-19 08:34 . 2011-08-23 10:05 390600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1504789416-810619661-2310688379-1000-12288.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 2146304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 2146304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2009-10-27 6998656]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2009-08-20 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-9-16 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-9-16 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 ShowAnalyzerMaster;ShowAnalyzerMaster;c:\program files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 14:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 16414824]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2918656]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\windows\AsScrPro.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-23 13:47:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-23 11:46
ComboFix2.txt 2011-08-23 10:11
.
Před spuštěním: Volných bajtů: 17 179 639 808
Po spuštění: Volných bajtů: 17 108 942 848
.
- - End Of File - - 3B23DB4DF25F6B9BBF862811DDE7B1F4
Re: facebook vir
Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Pak znovu použij Mbam, ale tentokrát dej kompletní kontrolu a opět mi sem dej log dříve než něco smažeš.
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Pak znovu použij Mbam, ale tentokrát dej kompletní kontrolu a opět mi sem dej log dříve než něco smažeš.
Re: facebook vir
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Verze databáze: 7535
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
23.8.2011 18:38:06
mbam-log-2011-08-23 (18-38-06).txt
Typ kontroly: Úplný test (C:\|D:\|Q:\|)
Testované objekty: 296024
Uplynulý čas: 48 minut, 57 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
www.malwarebytes.org
Verze databáze: 7535
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
23.8.2011 18:38:06
mbam-log-2011-08-23 (18-38-06).txt
Typ kontroly: Úplný test (C:\|D:\|Q:\|)
Testované objekty: 296024
Uplynulý čas: 48 minut, 57 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Re: facebook vir
super, ty jo díky moc
tohle je nejužitečnější stránka na kterou sem kdy narazil ! du vám udělat reklamu na facebooku 


Re: facebook vir
A proč ne, jen abychom pak tady stíhalijaryman píše:du vám udělat reklamu na facebooku

No vidíšjaryman píše:tohle je nejužitečnější stránka na kterou sem kdy narazil !

Není zač a příště neklikej kam nemášjaryman píše:super, ty jo díky moc
