Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosim o pomoc pomale pc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

prosim o pomoc pomale pc

#1 Příspěvek od Pietro »

prosim o pomoc pc je strasne pomale vykon procesuru je stale 50-100% i kdyz nic nedelam
prikladam log

Logfile of random's system information tool 1.09 (written by random/random)
Run by User at 2011-08-29 19:48:29
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 155 GB (68%) free of 227 GB
Total RAM: 4030 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:50:12, on 29. 8. 2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\T-Mobile Communication Center\TMCC.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\trend micro\User.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPNOT/2
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: HP SimplePass Identity Protection Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\dpotspluginie8.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [TMCC] "C:\Program Files (x86)\T-Mobile Communication Center\TMCC.exe" -m
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [PCSpeedUp] C:\Program Files (x86)\Zrychlenie PC\PCSpeedUp.lnk
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Mobility Manager Service (FMMService) - Flarion Technologies, Inc. - C:\PROGRA~2\T-MOBI~1\drivers\8B589B~1\FMMSER~1.EXE
O23 - Service: FOFDM DHCP Timing - Paradoxx Software - C:\PROGRA~2\T-MOBI~1\FOFDMD~1.EXE
O23 - Service: FOFDM Upgrade (FOFDMUpgrade) - Paradoxx Software - C:\PROGRA~2\T-MOBI~1\FOFDMU~1.EXE
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13317 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
atieclxx
C:\Windows\system32\vcsFPService.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" /background
"C:\Program Files\Hewlett-Packard\HPToneControl\HPToneCtl.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\T-Mobile Communication Center\TMCC.exe" -m
"C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe"
"C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
"C:\Program Files\DigitalPersona\Bin\DpHostW.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\DigitalPersona\Bin\DPAgent.exe"
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\PROGRA~2\T-MOBI~1\drivers\8B589B~1\FMMSER~1.EXE
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\PROGRA~2\T-MOBI~1\FOFDMD~1.EXE
C:\PROGRA~2\T-MOBI~1\FOFDMU~1.EXE
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3892
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2692.8d832e0.247524025 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.6.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 2692 "\\.\pipe\gecko-crash-server-pipe.2692" plugin
taskeng.exe {2770FB4A-B7D3-4BD8-93C8-605DD202392D}
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L PostRepair
"C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" mode=windowless
"C:\Program Files\Alwil Software\Avast5\setup\avast.setup" /downloadpkgs /noreboot /updatevps /verysilent /session "0" /limitcpu
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskmgr.exe /3
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
C:\Windows\sysWOW64\wbem\wmiprvse.exe -secured -Embedding
"C:\Users\User\Downloads\RSITx64.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\servicing\TrustedInstaller.exe

======Scheduled tasks folder======

C:\Windows\tasks\HPCeeScheduleForUser.job

=========Mozilla firefox=========

ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\4lrdw60v.default

prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "otis@digitalpersona.com:5.0.0.4248, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, DTToolbar@toolbarnet.com:1.1.2.0185, bkmrksync@nokia.com:1.0.0.732, 2020Player@2020Technologies.com:5.0.4.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
npdeployJava1.dll
npEModelPlugin.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nsEModelPlugin.xpt
QuickTimePlugin.class

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\4lrdw60v.default\extensions\
2020Player@2020Technologies.com
DTToolbar@toolbarnet.com

C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\4lrdw60v.default\searchplugins\
daemon-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP SimplePass Identity Protection Extension - C:\Program Files\DigitalPersona\Bin\dpotspluginie8.dll [2009-12-31 2213128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-28 43520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-23 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP SimplePass Identity Protection Extension - C:\Program Files (x86)\DigitalPersona\Bin\dpotspluginie8.dll [2009-12-31 1262856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2010-03-25 1548096]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-12-11 1890088]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2010-01-14 487424]
"HP Quick Launch"=C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2010-01-19 451072]
"SmartMenu"=C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2010-01-21 611896]
"HPToneControl"=C:\Program Files\Hewlett-Packard\HPToneControl\HPTonectl.exe [2009-08-20 107832]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2009-12-17 8192]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisorDock"=C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [2010-01-28 1712184]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-01-22 2363392]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"TMCC"=C:\Program Files (x86)\T-Mobile Communication Center\TMCC.exe [2011-05-01 774144]
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"ISUSPM"=C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe [2008-10-21 210208]
"PCSpeedUp"=C:\Program Files (x86)\Zrychlenie PC\PCSpeedUp.lnk [2011-08-28 2419]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gemstrmw]
C:\Windows\system32\gemstrmw.exe /r []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackupReminder]
C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [2009-12-04 3331944]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2010-02-28 172032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files (x86)\Winamp\winampa.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-01-22 98304]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2009-07-17 288080]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Easybits Recovery"=C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [2010-01-25 61112]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2008-12-09 54576]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2010-12-13 421160]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2010-02-28 52920]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EnableShellExecuteHooks"=1
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.inf - open - %SystemRoot%\SysWow64\NOTEPAD.EXE %1
.inf - install - %SystemRoot%\SysWow64\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - %SystemRoot%\SysWow64\WScript.exe "%1" %*
.vbs - open - %SystemRoot%\SysWow64\WScript.exe "%1" %*
.cpl - cplopen - %SystemRoot%\SysWow64\control.exe "%1",%*

======List of files/folders created in the last 1 month======

2011-08-29 19:28:51 ----D---- C:\Program Files\trend micro
2011-08-29 19:28:50 ----D---- C:\rsit
2011-08-29 18:39:34 ----SHD---- C:\Config.Msi
2011-08-28 14:16:14 ----D---- C:\Program Files (x86)\Zrychlenie PC
2011-08-25 20:40:42 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-08-25 20:40:42 ----A---- C:\Windows\system32\tzres.dll
2011-08-23 15:22:17 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-08-23 15:22:14 ----D---- C:\Program Files (x86)\Microsoft Security Client
2011-08-23 15:21:52 ----D---- C:\Program Files\Microsoft Security Client
2011-08-21 18:12:49 ----D---- C:\ProgramData\McAfee
2011-08-18 17:46:28 ----D---- C:\Users\User\AppData\Roaming\Macrovision
2011-08-17 15:47:49 ----D---- C:\Program Files (x86)\Apple Software Update
2011-08-16 18:17:54 ----D---- C:\Program Files\CCleaner
2011-08-14 18:51:49 ----SHD---- C:\$RECYCLE.BIN
2011-08-14 17:47:12 ----A---- C:\Windows\iun6002.exe
2011-08-14 17:46:54 ----D---- C:\Program Files (x86)\Codec Pack - All In 1
2011-08-14 15:34:00 ----D---- C:\ComboFix
2011-08-14 15:21:28 ----D---- C:\Users\User\AppData\Roaming\WildTangent
2011-08-13 21:35:54 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-13 21:35:53 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-13 21:35:50 ----A---- C:\Windows\system32\iertutil.dll
2011-08-13 21:35:49 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-13 21:35:48 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-08-13 21:35:48 ----A---- C:\Windows\system32\ieui.dll
2011-08-13 21:35:43 ----A---- C:\Windows\system32\jscript9.dll
2011-08-13 21:35:42 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-13 21:35:42 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-08-13 21:35:42 ----A---- C:\Windows\system32\url.dll
2011-08-13 21:35:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-13 21:35:41 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-08-13 21:35:41 ----A---- C:\Windows\system32\jscript.dll
2011-08-13 21:35:40 ----A---- C:\Windows\system32\urlmon.dll
2011-08-13 21:35:39 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-13 21:35:39 ----A---- C:\Windows\system32\wininet.dll
2011-08-13 21:35:39 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-13 21:35:38 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-08-13 21:35:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-13 21:35:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-13 21:35:32 ----A---- C:\Windows\system32\mshtml.dll
2011-08-13 21:35:31 ----A---- C:\Windows\system32\ieframe.dll
2011-08-13 00:02:58 ----A---- C:\Windows\NIRCMD.exe
2011-08-13 00:02:58 ----A---- C:\Windows\MBR.exe
2011-08-13 00:02:52 ----A---- C:\Windows\zip.exe
2011-08-13 00:02:52 ----A---- C:\Windows\SWSC.exe
2011-08-13 00:02:52 ----A---- C:\Windows\SWREG.exe
2011-08-13 00:02:52 ----A---- C:\Windows\sed.exe
2011-08-13 00:02:52 ----A---- C:\Windows\PEV.exe
2011-08-13 00:02:52 ----A---- C:\Windows\grep.exe
2011-08-13 00:02:24 ----D---- C:\Windows\ERDNT
2011-08-12 23:59:17 ----D---- C:\Qoobox
2011-08-10 23:35:39 ----A---- C:\Windows\system32\xmllite.dll
2011-08-10 23:35:38 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-10 23:35:37 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-08-10 23:35:37 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-08-10 23:35:37 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-08-10 23:35:37 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-10 23:35:37 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-10 23:35:37 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-10 23:35:37 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-10 23:35:36 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-08-10 23:35:36 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-08-10 23:35:35 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-10 23:35:23 ----A---- C:\Windows\system32\kernel32.dll
2011-08-10 23:35:23 ----A---- C:\Windows\system32\conhost.exe
2011-08-10 23:35:21 ----A---- C:\Windows\system32\wow64.dll
2011-08-10 23:35:21 ----A---- C:\Windows\system32\winsrv.dll
2011-08-10 23:35:21 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-10 23:35:19 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-08-10 23:35:19 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-08-10 23:35:19 ----A---- C:\Windows\system32\wow64win.dll
2011-08-10 23:35:19 ----A---- C:\Windows\system32\wow64cpu.dll
2011-08-10 23:35:19 ----A---- C:\Windows\system32\ntvdm64.dll
2011-08-10 23:35:18 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-10 23:35:16 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-10 23:35:16 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-08-10 23:35:16 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-10 23:35:15 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-10 23:35:14 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-10 23:35:14 ----A---- C:\Windows\SYSWOW64\user.exe
2011-08-10 23:35:14 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-08-10 23:35:11 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-10 23:35:07 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-08-10 23:35:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-10 23:35:06 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-08-02 21:34:22 ----D---- C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-08-02 21:33:49 ----D---- C:\Users\User\AppData\Roaming\hpqLog
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-08-02 19:45:11 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-08-02 19:45:10 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-08-02 19:45:09 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-08-02 19:45:08 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-08-02 19:45:08 ----A---- C:\Windows\system32\msrating.dll
2011-08-02 19:45:08 ----A---- C:\Windows\system32\msls31.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-08-02 19:45:07 ----A---- C:\Windows\system32\pngfilt.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\occache.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\mshtmler.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\mshta.exe
2011-08-02 19:45:07 ----A---- C:\Windows\system32\msfeedssync.exe
2011-08-02 19:45:07 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\imgutil.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\ieUnatt.exe
2011-08-02 19:45:07 ----A---- C:\Windows\system32\iesysprep.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\iepeers.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\ieakui.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\ieaksie.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\ieakeng.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-08-02 19:45:07 ----A---- C:\Windows\system32\admparse.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\wextract.exe
2011-08-02 19:45:06 ----A---- C:\Windows\system32\webcheck.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\vbscript.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\msfeeds.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\licmgr10.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\inseng.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\iexpress.exe
2011-08-02 19:45:06 ----A---- C:\Windows\system32\iesetup.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\iernonce.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\iedkcs32.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\ieapfltr.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\ieapfltr.dat
2011-08-02 19:45:06 ----A---- C:\Windows\system32\ie4uinit.exe
2011-08-02 19:45:06 ----A---- C:\Windows\system32\icardie.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\dxtrans.dll
2011-08-02 19:45:06 ----A---- C:\Windows\system32\dxtmsft.dll
2011-08-02 16:37:20 ----D---- C:\Windows\system32\SPReview
2011-08-02 16:33:16 ----D---- C:\Windows\system32\EventProviders

======List of files/folders modified in the last 1 month======

2011-08-29 19:50:03 ----D---- C:\Windows\Temp
2011-08-29 19:49:48 ----D---- C:\Windows\system32\config
2011-08-29 19:42:17 ----A---- C:\Windows\SYSWOW64\log.txt
2011-08-29 19:28:51 ----RD---- C:\Program Files
2011-08-29 19:17:53 ----D---- C:\Windows
2011-08-29 18:42:02 ----SHD---- C:\Windows\Installer
2011-08-29 18:41:16 ----RSD---- C:\Windows\assembly
2011-08-29 18:39:34 ----D---- C:\Program Files (x86)\Hewlett-Packard
2011-08-29 18:37:52 ----D---- C:\SwSetup
2011-08-29 18:36:06 ----SHD---- C:\System Volume Information
2011-08-29 18:34:00 ----RD---- C:\Program Files (x86)
2011-08-29 18:34:00 ----D---- C:\ProgramData
2011-08-29 18:14:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-08-29 18:07:04 ----D---- C:\Program Files (x86)\Winamp
2011-08-27 17:25:07 ----D---- C:\temp
2011-08-27 11:30:51 ----D---- C:\Windows\Tasks
2011-08-27 11:30:51 ----D---- C:\Windows\system32\Tasks
2011-08-26 07:29:33 ----D---- C:\Windows\winsxs
2011-08-26 07:29:23 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-08-26 07:29:23 ----D---- C:\Windows\SYSWOW64\en-US
2011-08-26 07:29:23 ----D---- C:\Windows\SysWOW64
2011-08-26 07:29:23 ----D---- C:\Windows\system32\sk-SK
2011-08-26 07:29:23 ----D---- C:\Windows\system32\en-US
2011-08-26 07:29:23 ----D---- C:\Windows\System32
2011-08-25 20:39:06 ----D---- C:\Windows\system32\catroot
2011-08-25 20:39:05 ----D---- C:\Windows\system32\catroot2
2011-08-23 20:03:14 ----HD---- C:\Windows\msdownld.tmp
2011-08-23 20:03:14 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-23 15:22:17 ----D---- C:\Windows\inf
2011-08-23 15:22:16 ----D---- C:\Windows\system32\drivers
2011-08-23 15:22:14 ----SD---- C:\ProgramData\Microsoft
2011-08-23 15:21:47 ----SD---- C:\Users\User\AppData\Roaming\Microsoft
2011-08-23 14:38:42 ----D---- C:\Windows\system32\NDF
2011-08-23 07:42:03 ----D---- C:\Windows\Microsoft.NET
2011-08-18 17:59:37 ----D---- C:\Program Files (x86)\Microsoft
2011-08-16 18:26:36 ----D---- C:\Users\User\AppData\Roaming\DAEMON Tools Lite
2011-08-16 18:26:36 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-08-16 18:26:13 ----D---- C:\Windows\Minidump
2011-08-16 18:26:13 ----D---- C:\Windows\Logs
2011-08-16 18:26:13 ----D---- C:\Windows\debug
2011-08-14 18:31:50 ----A---- C:\Windows\system.ini
2011-08-14 18:30:34 ----D---- C:\Windows\system32\drivers\etc
2011-08-14 16:19:16 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-14 16:19:15 ----D---- C:\Windows\AppPatch
2011-08-14 16:18:34 ----D---- C:\Program Files\Common Files
2011-08-14 16:18:34 ----D---- C:\Program Files (x86)\Common Files
2011-08-14 15:23:27 ----D---- C:\Windows\SYSWOW64\migration
2011-08-14 15:23:26 ----D---- C:\Windows\system32\migration
2011-08-14 15:23:25 ----D---- C:\Program Files\Internet Explorer
2011-08-14 15:05:04 ----D---- C:\ProgramData\Microsoft Help
2011-08-14 14:39:29 ----A---- C:\Windows\system32\MRT.exe
2011-08-13 21:40:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-12 23:36:13 ----D---- C:\Program Files (x86)\Java
2011-08-05 18:49:21 ----D---- C:\Windows\LiveKernelReports
2011-08-05 13:26:10 ----D---- C:\Users\User\AppData\Roaming\Hewlett-Packard
2011-08-02 21:41:10 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-08-02 21:41:03 ----D---- C:\Windows\Help
2011-08-02 21:17:23 ----D---- C:\ProgramData\Hewlett-Packard
2011-08-02 21:09:24 ----D---- C:\Windows\Prefetch
2011-08-02 21:02:28 ----D---- C:\Windows\system32\wdi
2011-08-02 21:01:49 ----D---- C:\Windows\PolicyDefinitions
2011-08-02 20:27:50 ----D---- C:\Windows\system32\DriverStore
2011-08-02 20:14:38 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-08-02 20:14:38 ----D---- C:\Program Files (x86)\Windows Mail
2011-08-02 20:14:37 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-08-02 20:14:37 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-08-02 20:14:37 ----D---- C:\Program Files (x86)\Windows Media Player
2011-08-02 20:14:29 ----D---- C:\Program Files\Windows Sidebar
2011-08-02 20:14:29 ----D---- C:\Program Files\Windows Mail
2011-08-02 20:14:29 ----D---- C:\Program Files\DVD Maker
2011-08-02 20:14:28 ----D---- C:\Program Files\Windows Portable Devices
2011-08-02 20:14:28 ----D---- C:\Program Files\Windows Media Player
2011-08-02 20:14:27 ----D---- C:\Program Files\Windows Photo Viewer
2011-08-02 20:14:22 ----D---- C:\Windows\servicing
2011-08-02 20:14:22 ----D---- C:\Program Files\Windows Defender
2011-08-02 20:14:21 ----D---- C:\Windows\ehome
2011-08-02 20:14:05 ----D---- C:\Windows\SYSWOW64\da-DK
2011-08-02 20:14:01 ----D---- C:\Windows\SYSWOW64\ko-KR
2011-08-02 20:13:55 ----D---- C:\Windows\SYSWOW64\oobe
2011-08-02 20:13:55 ----D---- C:\Windows\SYSWOW64\it-IT
2011-08-02 20:13:55 ----D---- C:\Windows\SYSWOW64\el-GR
2011-08-02 20:13:55 ----D---- C:\Windows\SYSWOW64\de-DE
2011-08-02 20:13:53 ----D---- C:\Windows\SYSWOW64\sv-SE
2011-08-02 20:13:53 ----D---- C:\Windows\SYSWOW64\ru-RU
2011-08-02 20:13:53 ----D---- C:\Windows\SYSWOW64\fr-FR
2011-08-02 20:13:53 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\zh-CN
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\Setup
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\pt-PT
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\hu-HU
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\he-IL
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\fi-FI
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\en
2011-08-02 20:13:52 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-08-02 20:13:51 ----D---- C:\Windows\SYSWOW64\zh-TW
2011-08-02 20:13:51 ----D---- C:\Windows\SYSWOW64\sppui
2011-08-02 20:13:51 ----D---- C:\Windows\SYSWOW64\ro-RO
2011-08-02 20:13:51 ----D---- C:\Windows\SYSWOW64\pl-PL
2011-08-02 20:13:51 ----D---- C:\Windows\SYSWOW64\ja-JP
2011-08-02 20:13:51 ----D---- C:\Windows\SYSWOW64\es-ES
2011-08-02 20:13:50 ----D---- C:\Windows\SYSWOW64\tr-TR
2011-08-02 20:13:50 ----D---- C:\Windows\SYSWOW64\th-TH
2011-08-02 20:13:49 ----D---- C:\Windows\SYSWOW64\wbem
2011-08-02 20:13:49 ----D---- C:\Windows\SYSWOW64\nl-NL
2011-08-02 20:13:49 ----D---- C:\Windows\SYSWOW64\nb-NO
2011-08-02 20:13:49 ----D---- C:\Windows\SYSWOW64\ar-SA
2011-08-02 20:13:48 ----D---- C:\Windows\SYSWOW64\migwiz
2011-08-02 20:13:47 ----D---- C:\Windows\SYSWOW64\Dism
2011-08-02 20:13:46 ----D---- C:\Windows\SYSWOW64\pt-BR
2011-08-02 20:12:58 ----D---- C:\Windows\system32\da-DK
2011-08-02 20:12:52 ----D---- C:\Windows\system32\ko-KR
2011-08-02 20:12:45 ----D---- C:\Windows\system32\de-DE
2011-08-02 20:12:44 ----D---- C:\Windows\system32\it-IT
2011-08-02 20:12:44 ----D---- C:\Windows\system32\el-GR
2011-08-02 20:12:43 ----D---- C:\Windows\system32\oobe
2011-08-02 20:12:40 ----D---- C:\Windows\system32\ru-RU
2011-08-02 20:12:40 ----D---- C:\Windows\system32\AdvancedInstallers
2011-08-02 20:12:39 ----D---- C:\Windows\system32\sv-SE
2011-08-02 20:12:39 ----D---- C:\Windows\system32\fr-FR
2011-08-02 20:12:38 ----D---- C:\Windows\system32\Setup
2011-08-02 20:12:38 ----D---- C:\Windows\system32\he-IL
2011-08-02 20:12:38 ----D---- C:\Windows\system32\fi-FI
2011-08-02 20:12:37 ----D---- C:\Windows\system32\hu-HU
2011-08-02 20:12:37 ----D---- C:\Windows\system32\cs-CZ
2011-08-02 20:12:36 ----D---- C:\Windows\system32\zh-CN
2011-08-02 20:12:36 ----D---- C:\Windows\system32\pt-PT
2011-08-02 20:12:35 ----D---- C:\Windows\system32\manifeststore
2011-08-02 20:12:35 ----D---- C:\Windows\system32\es-ES
2011-08-02 20:12:34 ----D---- C:\Windows\system32\zh-TW
2011-08-02 20:12:34 ----D---- C:\Windows\system32\pl-PL
2011-08-02 20:12:33 ----D---- C:\Windows\system32\sppui
2011-08-02 20:12:33 ----D---- C:\Windows\system32\ja-JP
2011-08-02 20:12:32 ----D---- C:\Windows\system32\ro-RO
2011-08-02 20:12:29 ----D---- C:\Windows\system32\th-TH
2011-08-02 20:12:28 ----D---- C:\Windows\system32\drivers\pt-BR
2011-08-02 20:12:28 ----D---- C:\Windows\system32\drivers\it-IT
2011-08-02 20:12:27 ----D---- C:\Windows\system32\drivers\pt-PT
2011-08-02 20:12:27 ----D---- C:\Windows\system32\drivers\he-IL
2011-08-02 20:12:26 ----D---- C:\Windows\system32\drivers\pl-PL
2011-08-02 20:12:26 ----D---- C:\Windows\system32\drivers\ko-KR
2011-08-02 20:12:26 ----D---- C:\Windows\system32\drivers\hu-HU
2011-08-02 20:12:25 ----D---- C:\Windows\system32\drivers\nl-NL
2011-08-02 20:12:25 ----D---- C:\Windows\system32\drivers\el-GR
2011-08-02 20:12:24 ----D---- C:\Windows\system32\drivers\tr-TR
2011-08-02 20:12:24 ----D---- C:\Windows\system32\drivers\fr-FR
2011-08-02 20:12:24 ----D---- C:\Windows\system32\drivers\fi-FI
2011-08-02 20:12:23 ----D---- C:\Windows\system32\drivers\th-TH
2011-08-02 20:12:23 ----D---- C:\Windows\system32\drivers\sv-SE
2011-08-02 20:12:22 ----D---- C:\Windows\system32\drivers\zh-TW
2011-08-02 20:12:22 ----D---- C:\Windows\system32\drivers\es-ES
2011-08-02 20:12:21 ----D---- C:\Windows\system32\drivers\zh-CN
2011-08-02 20:12:21 ----D---- C:\Windows\system32\drivers\de-DE
2011-08-02 20:12:21 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-08-02 20:12:20 ----D---- C:\Windows\system32\drivers\ja-JP
2011-08-02 20:12:20 ----D---- C:\Windows\system32\drivers\ar-SA
2011-08-02 20:12:19 ----D---- C:\Windows\system32\drivers\ru-RU
2011-08-02 20:12:19 ----D---- C:\Windows\system32\drivers\ro-RO
2011-08-02 20:12:18 ----D---- C:\Windows\system32\drivers\nb-NO
2011-08-02 20:12:18 ----D---- C:\Windows\system32\drivers\en-US
2011-08-02 20:12:18 ----D---- C:\Windows\system32\drivers\da-DK
2011-08-02 20:12:16 ----D---- C:\Windows\system32\tr-TR
2011-08-02 20:12:15 ----D---- C:\Windows\system32\wbem
2011-08-02 20:12:14 ----D---- C:\Windows\system32\nb-NO
2011-08-02 20:12:13 ----D---- C:\Windows\system32\nl-NL
2011-08-02 20:12:12 ----D---- C:\Windows\system32\ar-SA
2011-08-02 20:12:11 ----D---- C:\Windows\system32\migwiz
2011-08-02 20:12:11 ----D---- C:\Windows\system32\Dism
2011-08-02 20:12:10 ----D---- C:\Windows\system32\pt-BR
2011-08-02 20:11:18 ----RSD---- C:\Windows\Fonts
2011-08-02 20:10:19 ----D---- C:\Windows\system32\Boot
2011-08-02 18:45:28 ----D---- C:\Program Files (x86)\Microsoft Office
2011-08-02 18:23:15 ----A---- C:\Windows\SYSWOW64\msclmd.dll
2011-08-02 18:23:06 ----A---- C:\Windows\system32\msclmd.dll
2011-07-31 13:01:06 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-11-21 537112]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-31 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 28752]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 121936]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 51280]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 DVMIO;DeviceVM IO Service; C:\Windows\system32\DRIVERS\dvmio.sys [2010-01-30 20056]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 20048]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008]
R3 Accelerometer;HP Accelerometer; C:\Windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 41272]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-01-22 6233088]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-01-22 161280]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-09-30 121872]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-01-07 98344]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-07 132648]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-01-07 35104]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-07 21160]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-01-14 505856]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-12-11 301104]
R3 vpcbus;Virtual PC Host Bus Service; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;USB Virtualization Connector Service; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 GemCCID;GemCCID; C:\Windows\System32\Drivers\GemCCID.sys [2009-08-10 119680]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 Leadtek;Leadtek USB Network Interface; C:\Windows\system32\DRIVERS\Leadtek.sys [2011-06-05 77360]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2010-02-26 25088]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-02-26 19456]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-01-12 232992]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-11-28 295424]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2010-02-26 9216]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2010-09-28 51712]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2010-02-26 9216]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-01-22 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-10-16 37664]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-12-29 873248]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128; C:\Program Files\DigitalPersona\Bin\DpHostW.exe [2009-12-30 444680]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe [2010-02-09 338168]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-01-25 514232]
R2 FMMService;Mobility Manager Service; C:\PROGRA~2\T-MOBI~1\drivers\8B589B~1\FMMSER~1.EXE [2011-06-05 40960]
R2 FOFDM DHCP Timing;FOFDM DHCP Timing; C:\PROGRA~2\T-MOBI~1\FOFDMD~1.EXE [2011-02-16 391680]
R2 FOFDMUpgrade;FOFDM Upgrade; C:\PROGRA~2\T-MOBI~1\FOFDMU~1.EXE [2011-02-16 188416]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2011-02-23 125496]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-12-17 102968]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-05 227384]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2009-07-08 30520]
R2 HPWMISVC;HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-01-19 20480]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-01-22 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-10-01 268824]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2010-10-31 66872]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe [2010-01-14 244736]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\Windows\system32\vcsFPService.exe [2010-01-06 2184496]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-07-05 988216]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-12-13 932640]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe [2010-01-04 238328]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-05-25 613888]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2011-02-21 79360]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-31 1255736]

-----------------EOF-----------------
Pietro

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosim o pomoc pomale pc

#2 Příspěvek od Roli »

Zdravím, tohle fixni v HJT :

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [PCSpeedUp] C:\Program Files (x86)\Zrychlenie PC\PCSpeedUp.lnk


HJT najdeš zde :

C:\Program Files\trend micro\User.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Odebrat programy odinstaluj Zrychlenie PC (PCSpeedUp) a Spybot - SD který je už za zenitem.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Pak použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !!!
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

Re: prosim o pomoc pomale pc

#3 Příspěvek od Pietro »

spravil som vsetko podla postutpu

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Verzia databázy: 7606

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

31. 8. 2011 16:21:22
mbam-log-2011-08-31 (16-21-22).txt

Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 172958
Uplynutý čas: 5 min, 49 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
(Škodlivé položky neboli zistené)

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
(Škodlivé položky neboli zistené)
Pietro

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosim o pomoc pomale pc

#4 Příspěvek od Roli »

Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

Re: prosim o pomoc pomale pc

#5 Příspěvek od Pietro »

ComboFix 11-09-01.02 - User . 09. 2011 16:56:44.5.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1051.18.4030.2411 [GMT 2:00]
Running from: c:\users\User\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\iun6002.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-08-01 to 2011-09-01 )))))))))))))))))))))))))))))))
.
.
2011-09-01 15:24 . 2011-09-01 15:24 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-31 14:24 . 2011-08-11 19:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{03DA147C-61E1-4378-8AA8-7CD3DA6B1A16}\mpengine.dll
2011-08-29 20:54 . 2011-08-29 20:54 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2011-08-29 20:54 . 2011-08-29 20:54 -------- d-----w- c:\windows\system32\Macromed
2011-08-29 20:53 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-29 20:53 . 2011-08-29 20:53 -------- d-----w- c:\programdata\Malwarebytes
2011-08-29 20:53 . 2011-08-30 04:45 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-29 20:53 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-29 17:28 . 2011-08-29 17:49 -------- d-----w- c:\program files\trend micro
2011-08-29 17:28 . 2011-08-29 17:32 -------- d-----w- C:\rsit
2011-08-28 12:16 . 2011-08-28 13:05 -------- d-----w- c:\program files (x86)\Zrychlenie PC
2011-08-25 18:44 . 2011-08-11 19:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-25 18:40 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-25 18:40 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-23 13:32 . 2011-08-23 13:31 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6D12F10D-5237-493B-8CC4-1E37C0B90707}\gapaengine.dll
2011-08-23 13:22 . 2011-08-23 13:22 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-08-23 13:21 . 2011-08-23 13:22 -------- d-----w- c:\program files\Microsoft Security Client
2011-08-23 05:50 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{925B45A3-B946-4938-A187-4CFCB5D2AABF}\mpengine.dll
2011-08-21 16:12 . 2011-08-21 16:12 -------- d-----w- c:\programdata\McAfee
2011-08-21 15:55 . 2011-08-29 20:54 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-18 15:46 . 2011-08-18 15:46 -------- d-----w- c:\users\User\AppData\Roaming\Macrovision
2011-08-17 13:47 . 2011-08-17 13:47 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-08-16 16:17 . 2011-08-16 16:18 -------- d-----w- c:\program files\CCleaner
2011-08-14 15:46 . 2011-08-14 15:47 -------- d-----w- c:\program files (x86)\Codec Pack - All In 1
2011-08-14 13:21 . 2011-08-14 13:21 -------- d-----w- c:\users\User\AppData\Roaming\WildTangent
2011-08-13 19:36 . 2011-07-22 05:32 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-08-12 21:38 . 2011-08-12 21:38 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-08-02 19:34 . 2011-08-02 19:34 -------- d-----w- c:\programdata\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-08-02 19:33 . 2011-08-29 16:41 -------- d-----w- c:\users\User\AppData\Roaming\hpqLog
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-02 16:23 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-08-02 16:23 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-16 04:26 . 2011-08-10 21:35 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-06-11 03:07 . 2011-07-13 04:56 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-06-05 10:43 . 2011-06-05 10:43 77360 ----a-w- c:\windows\system32\drivers\Leadtek.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe" [2010-01-28 1712184]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-01-22 2363392]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"TMCC"="c:\program files (x86)\T-Mobile Communication Center\TMCC.exe" [2011-05-01 774144]
"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2008-10-20 210208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2010-01-25 61112]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-12-29 1082656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 GemCCID;GemCCID;c:\windows\system32\Drivers\GemCCID.sys [x]
R3 Leadtek;Leadtek USB Network Interface;c:\windows\system32\DRIVERS\Leadtek.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 aswSP;aswSP; [x]
S1 DVMIO;DeviceVM IO Service;c:\windows\system32\DRIVERS\dvmio.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\swsetup\QuickWeb\QW.SYS\config\DVMExportService.exe [2010-02-08 338168]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-12-16 102968]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-05 227384]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 HPWMISVC;HPWMISVC;c:\program files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-01-18 20480]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2010-01-06 2184496]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-01-22 18:06 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-27 c:\windows\Tasks\HPCeeScheduleForUser.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 11:53]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-14 487424]
"HP Quick Launch"="c:\program files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-01-18 451072]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-01-20 611896]
"HPToneControl"="c:\program files\Hewlett-Packard\HPToneControl\HPTonectl.exe" [2009-08-20 107832]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2009-12-16 8192]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 10.1.1.1 192.168.1.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\4lrdw60v.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-{E92D47A1-D27D-430A-8368-0BAFD956507D} - c:\program files (x86)\InstallShield Installation Information\{E92D47A1-D27D-430A-8368-0BAFD956507D}\setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2324175922-4225097094-681928144-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2324175922-4225097094-681928144-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-2324175922-4225097094-681928144-1000)
@Denied: (2) (LocalSystem)
"Progid"="Outlook.File.vcf"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-09-01 17:58:53
ComboFix-quarantined-files.txt 2011-09-01 15:58
.
Pre-Run: 161 809 137 664 bytes free
Post-Run: 161 920 995 328 bytes free
.
- - End Of File - - 49E450E3410BC17A6C0D662272983F33
Pietro

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosim o pomoc pomale pc

#6 Příspěvek od Roli »

Než budeme pokračovat tak by bylo dobré si ujasnit co vlastně chceš používat za antivir,

nejdříve jsi tam měl Avast teď je to Microsoft Security Essentials.

Tak že jak ?
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

Re: prosim o pomoc pomale pc

#7 Příspěvek od Pietro »

Ten Microsoft jaky bude další postup
Pietro

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosim o pomoc pomale pc

#8 Příspěvek od Roli »

Pokud jsi tak ještě neučinil, přesuň Combofix na plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

File::  
c:\windows\system32\drivers\aswMonFlt.sys

Folder::
c:\programdata\McAfee

Driver::
aswSP
aswFsBlk
aswMonFlt

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

Re: prosim o pomoc pomale pc

#9 Příspěvek od Pietro »

ComboFix 11-09-01.03 - User . 09. 2011 16:17:21.6.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1051.18.4030.2427 [GMT 2:00]
Running from: c:\users\User\Desktop\ComboFix.exe
Command switches used :: c:\users\User\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\windows\system32\drivers\aswMonFlt.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\McAfee
c:\windows\system32\drivers\aswMonFlt.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ASWFSBLK
-------\Legacy_ASWMONFLT
-------\Legacy_ASWSP
-------\Service_aswFsBlk
-------\Service_aswMonFlt
-------\Service_aswSP
.
.
((((((((((((((((((((((((( Files Created from 2011-08-02 to 2011-09-02 )))))))))))))))))))))))))))))))
.
.
2011-09-02 14:28 . 2011-09-02 14:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-01 16:16 . 2011-08-11 19:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FA951AEE-99A6-46A0-B03D-D32A51646D53}\mpengine.dll
2011-08-29 20:54 . 2011-08-29 20:54 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2011-08-29 20:54 . 2011-08-29 20:54 -------- d-----w- c:\windows\system32\Macromed
2011-08-29 20:53 . 2011-07-06 17:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-29 20:53 . 2011-08-29 20:53 -------- d-----w- c:\programdata\Malwarebytes
2011-08-29 20:53 . 2011-08-30 04:45 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-29 20:53 . 2011-07-06 17:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-29 17:28 . 2011-08-29 17:49 -------- d-----w- c:\program files\trend micro
2011-08-29 17:28 . 2011-08-29 17:32 -------- d-----w- C:\rsit
2011-08-28 12:16 . 2011-08-28 13:05 -------- d-----w- c:\program files (x86)\Zrychlenie PC
2011-08-25 18:44 . 2011-08-11 19:10 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-25 18:40 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-25 18:40 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-23 13:32 . 2011-08-23 13:31 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6D12F10D-5237-493B-8CC4-1E37C0B90707}\gapaengine.dll
2011-08-23 13:22 . 2011-08-23 13:22 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-08-23 13:21 . 2011-08-23 13:22 -------- d-----w- c:\program files\Microsoft Security Client
2011-08-23 05:50 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{925B45A3-B946-4938-A187-4CFCB5D2AABF}\mpengine.dll
2011-08-21 15:55 . 2011-08-29 20:54 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-18 15:46 . 2011-08-18 15:46 -------- d-----w- c:\users\User\AppData\Roaming\Macrovision
2011-08-17 13:47 . 2011-08-17 13:47 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-08-16 16:17 . 2011-08-16 16:18 -------- d-----w- c:\program files\CCleaner
2011-08-14 15:46 . 2011-08-14 15:47 -------- d-----w- c:\program files (x86)\Codec Pack - All In 1
2011-08-14 13:21 . 2011-08-14 13:21 -------- d-----w- c:\users\User\AppData\Roaming\WildTangent
2011-08-13 19:36 . 2011-07-22 05:32 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-08-12 21:38 . 2011-08-12 21:38 -------- d-----w- c:\program files (x86)\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-02 17:45 . 2011-08-02 17:45 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-08-02 17:45 . 2011-08-02 17:45 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-08-02 17:45 . 2011-08-02 17:45 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-08-02 17:45 . 2011-08-02 17:45 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-08-02 17:45 . 2011-08-02 17:45 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-08-02 17:45 . 2011-08-02 17:45 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-08-02 17:45 . 2011-08-02 17:45 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-08-02 17:45 . 2011-08-02 17:45 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-08-02 17:45 . 2011-08-02 17:45 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-08-02 17:45 . 2011-08-02 17:45 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-08-02 17:45 . 2011-08-02 17:45 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-08-02 17:45 . 2011-08-02 17:45 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-08-02 17:45 . 2011-08-02 17:45 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-08-02 17:45 . 2011-08-02 17:45 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-08-02 17:45 . 2011-08-02 17:45 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-08-02 17:45 . 2011-08-02 17:45 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-08-02 17:45 . 2011-08-02 17:45 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-08-02 17:45 . 2011-08-02 17:45 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-08-02 17:45 . 2011-08-02 17:45 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-08-02 17:45 . 2011-08-02 17:45 222208 ----a-w- c:\windows\system32\msls31.dll
2011-08-02 17:45 . 2011-08-02 17:45 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-08-02 17:45 . 2011-08-02 17:45 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-08-02 17:45 . 2011-08-02 17:45 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-08-02 17:45 . 2011-08-02 17:45 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-08-02 17:45 . 2011-08-02 17:45 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-08-02 17:45 . 2011-08-02 17:45 12288 ----a-w- c:\windows\system32\mshta.exe
2011-08-02 17:45 . 2011-08-02 17:45 114176 ----a-w- c:\windows\system32\admparse.dll
2011-08-02 17:45 . 2011-08-02 17:45 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-08-02 17:45 . 2011-08-02 17:45 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-08-02 17:45 . 2011-08-02 17:45 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-08-02 17:45 . 2011-08-02 17:45 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-08-02 17:45 . 2011-08-02 17:45 448512 ----a-w- c:\windows\system32\html.iec
2011-08-02 17:45 . 2011-08-02 17:45 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-02 17:45 . 2011-08-02 17:45 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-08-02 17:45 . 2011-08-02 17:45 160256 ----a-w- c:\windows\system32\wextract.exe
2011-08-02 17:45 . 2011-08-02 17:45 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-08-02 16:23 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-08-02 16:23 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-16 04:26 . 2011-08-10 21:35 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-06-11 03:07 . 2011-07-13 04:56 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-06-05 10:43 . 2011-06-05 10:43 77360 ----a-w- c:\windows\system32\drivers\Leadtek.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-09-01_15.24.22 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-09-01 14:18 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-09-02 14:30 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-09-01 14:18 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-09-02 14:30 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-09-01 14:18 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-09-02 14:30 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 05:10 . 2011-09-01 16:05 44378 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-10-29 18:14 . 2011-09-01 16:05 8110 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2324175922-4225097094-681928144-1000_UserData.bin
- 2011-08-31 14:08 . 2011-08-31 14:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-09-02 14:29 . 2011-09-02 14:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-31 14:08 . 2011-08-31 14:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-09-02 14:29 . 2011-09-02 14:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-10-31 13:02 . 2011-09-01 22:22 380060 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 05:01 . 2011-08-30 04:47 416320 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-09-02 14:28 416320 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2010-10-29 19:02 . 2011-09-02 14:28 9308460 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2324175922-4225097094-681928144-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe" [2010-01-28 1712184]
"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-01-22 2363392]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"TMCC"="c:\program files (x86)\T-Mobile Communication Center\TMCC.exe" [2011-05-01 774144]
"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2008-10-20 210208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2010-01-25 61112]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-12-29 1082656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-12-16 102968]
R3 GemCCID;GemCCID;c:\windows\system32\Drivers\GemCCID.sys [x]
R3 Leadtek;Leadtek USB Network Interface;c:\windows\system32\DRIVERS\Leadtek.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [x]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 DVMIO;DeviceVM IO Service;c:\windows\system32\DRIVERS\dvmio.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\swsetup\QuickWeb\QW.SYS\config\DVMExportService.exe [2010-02-08 338168]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-07-05 227384]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
S2 HPWMISVC;HPWMISVC;c:\program files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-01-18 20480]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2010-01-06 2184496]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-01-22 18:06 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-27 c:\windows\Tasks\HPCeeScheduleForUser.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 11:53]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-14 487424]
"HP Quick Launch"="c:\program files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-01-18 451072]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-01-20 611896]
"HPToneControl"="c:\program files\Hewlett-Packard\HPToneControl\HPTonectl.exe" [2009-08-20 107832]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2009-12-16 8192]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
"combofix"="c:\combofix\CF72.3XE" [2010-11-20 345088]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 10.1.1.1 192.168.1.1
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\4lrdw60v.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2324175922-4225097094-681928144-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2324175922-4225097094-681928144-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (S-1-5-21-2324175922-4225097094-681928144-1000)
@Denied: (2) (LocalSystem)
"Progid"="Outlook.File.vcf"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\ezSharedSvcHost.exe
c:\progra~2\T-MOBI~1\drivers\8B589B~1\FMMSER~1.EXE
c:\progra~2\T-MOBI~1\FOFDMU~1.EXE
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2011-09-02 16:36:13 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-02 14:36
ComboFix2.txt 2011-09-01 15:58
.
Pre-Run: 161 742 966 784 bytes free
Post-Run: 162 076 893 184 bytes free
.
- - End Of File - - FC95C751AF1A142E30550F4EB745F66A
Pietro

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosim o pomoc pomale pc

#10 Příspěvek od Roli »

Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Přes Start >> Ovládací panely >> Odebrat programy odinstaluj Malwarebytes' Anti-Malware


Pak dej vědět jaký je stav PC.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

Re: prosim o pomoc pomale pc

#11 Příspěvek od Pietro »

tak jsem udelal vse ale nic pc jede jako stara 486!!!! proste ma spomalene reakce porad je procesor 50-90% vytizeny a fyzicka pamet 46% a vice
a to nemam nic otevrene jenom tohle okno firefox
tak ja nevim budu rad za kazdou radu protoze stimto se neda pracovat
dekuji
Pietro

Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

Re: prosim o pomoc pomale pc

#12 Příspěvek od Pietro »

jo a jeste jak spustim internet explorer myslim ze tam je ted verze 9 tak to uz nejede skoro vubec
Pietro

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosim o pomoc pomale pc

#13 Příspěvek od Roli »

No ono cpát tam antivir za antivirem, používat různé urychlovače PC které stejně nefungují mu na

rychlosti nepřidají.

To že máš vytížení 40% a víc je nepříjmné, ale bohužel zlozvyk Win 7.

Ovšem to zatížení CPU není zrovna ideální.


Jakou používáš verzi Firefoxu ?

Jestli vyšší jak 3.6 zkusil bych se k této vrátit.


Spusť skener Cure It podle TOHOTO návodu

po skončení skenu chci sem výsledky.

(Upozornění je úchylně pomalý a je zapotřebí ho sledovat občas se na něco ptá)
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Pietro
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 14 bře 2006 23:28

Re: prosim o pomoc pomale pc

#14 Příspěvek od Pietro »

ok udelam to ale az zitra uz musim
jo ty ptakoviny jsem tam zacal davat az to zacalo haprovat a nez jsem se uchylil o pomoc jsem
koukal jsem na ten navod a ten program vytvori taky nejaky log nebo co sem mam vlozit
Pietro

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosim o pomoc pomale pc

#15 Příspěvek od Roli »

Ano Cure It umí také vytvořit log jen ho o to musíš při nastavení požádat.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět