
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Zpomalené PC, pády, neůmyslné restarty.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpomalené PC, pády, neůmyslné restarty.
Dobrý den, chtěl bych vás poprosit o zkontrolování PC. Poslední dobou sem i dějí divné věci a také se mi zdá dost zpomalený. Předem děkuji za váš čas.
Problémy:
Zabrzděný Počítač.
Neúmyslné vypínání, restarty.
Crashe a Errory ve Hrách a Systému.
Problémy:
Zabrzděný Počítač.
Neúmyslné vypínání, restarty.
Crashe a Errory ve Hrách a Systému.
Naposledy upravil(a) Kastab dne 23 zář 2011 08:55, celkem upraveno 1 x.
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Zpomalené PC, pády, neůmyslné restarty.
Dobré ránko 
nejsem bohužel věštec a věšteckou kouli má pouze náš admin,tak mi prosím vložte pro začátek log z RSIT,návod vás povede: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895

nejsem bohužel věštec a věšteckou kouli má pouze náš admin,tak mi prosím vložte pro začátek log z RSIT,návod vás povede: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895
Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Zpomalené PC, pády, neůmyslné restarty.
Oh, promiňte.
Logfile of random's system information tool 1.09 (written by random/random)
Run by wqrxs at 2011-09-19 18:32:40
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 47 GB (21%) free of 230 GB
Total RAM: 1023 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:32:48, on 19.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Gamesy\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Gamesy\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.33\deploy\LoLLauncher.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\wqrxs\Plocha\RSIT.exe
C:\Program Files\trend micro\wqrxs.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5419 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core1cc0b11bfe8090a.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003UA.job
C:\WINDOWS\tasks\WGASetup.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-03-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-11-04 1753192]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-05-03 399736]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\wqrxs\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-02-28 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2011-08-18 17360520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-05-03 399736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 409088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 4.0"=2
"Nero BackItUp Scheduler 3"=2
"Hamachi2Svc"=2
"PLFlash DeviceIoControl Service"=2
"JavaQuickStarterService"=2
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe:*:Enabled:iw3mp"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Gamesy\League of Legends\air\LolClient.exe"="C:\Gamesy\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\League of Legends\game\League of Legends.exe"="C:\Gamesy\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin:*:Enabled:client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe:*:Enabled:Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Gamesy\League of Legends\lol.launcher.exe"="C:\Gamesy\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Gamesy\Lolko\air\LolClient.exe"="C:\Gamesy\Lolko\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\Lolko\game\League of Legends.exe"="C:\Gamesy\Lolko\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Gamesy\Counter-Strike Source\hl2.exe"="C:\Gamesy\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"C:\Gamesy\The Settlers 7 - Paths to a Kingdom\Data\Base\_Dbg\Bin\Release\Settlers7R.exe"="C:\Gamesy\The Settlers 7 - Paths to a Kingdom\Data\Base\_Dbg\Bin\Release\Settlers7R.exe:*:Enabled:The Settlers 7 - Paths to a Kingdom"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"wave5"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer4"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"VIDC.FPS1"=frapsvid.dll
"VIDC.FMVC"=fmcodec.dll
======List of files/folders created in the last 1 month======
2011-09-17 22:48:04 ----D---- C:\Program Files\DsNET Corp
2011-09-17 09:37:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-15 23:06:23 ----A---- C:\WINDOWS\eReg.dat
2011-09-15 22:59:13 ----A---- C:\WINDOWS\CD_Start.INI
2011-09-14 13:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-14 07:24:08 ----SHD---- C:\found.000
2011-09-07 22:14:13 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Prison Break
2011-09-07 11:57:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2607712$
2011-09-06 05:24:09 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Opera
2011-09-06 05:24:01 ----D---- C:\Program Files\Opera
2011-09-06 05:15:12 ----A---- C:\WINDOWS\system32\msvcr71.dll
2011-09-06 05:15:11 ----A---- C:\WINDOWS\system32\msvcp71.dll
2011-09-06 05:13:06 ----A---- C:\WINDOWS\system32\mfc71.dll
2011-09-05 12:20:41 ----A---- C:\WINDOWS\WORDPAD.INI
2011-09-04 19:59:01 ----D---- C:\WINDOWS\system32\appmgmt
2011-09-03 09:56:15 ----D---- C:\Program Files\Ubisoft
2011-08-31 07:20:01 ----D---- C:\Program Files\GamePark2
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\psisdecd.dll
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\wstcodec.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\streamip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\slip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\ndisip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\nabtsfec.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\msdv.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\mpe.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\ccdecode.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\bdasup.sys
2011-08-30 23:22:28 ----A---- C:\WINDOWS\system32\drivers\atksgt.sys
2011-08-30 23:22:27 ----A---- C:\WINDOWS\system32\drivers\lirsgt.sys
2011-08-29 17:30:03 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Allstar
2011-08-29 10:23:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-08-29 10:22:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-08-29 10:21:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-08-29 10:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-08-29 10:21:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-08-29 10:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-08-29 10:16:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-08-29 10:16:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
======List of files/folders modified in the last 1 month======
2011-09-19 18:32:43 ----D---- C:\Program Files\trend micro
2011-09-19 18:06:47 ----D---- C:\WINDOWS\Temp
2011-09-19 18:05:44 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\uTorrent
2011-09-19 14:49:05 ----D---- C:\WINDOWS\Microsoft.NET
2011-09-19 12:09:56 ----D---- C:\WINDOWS\system32
2011-09-19 12:09:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-19 08:51:47 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-19 08:51:43 ----SHD---- C:\WINDOWS\Installer
2011-09-19 08:02:26 ----D---- C:\WINDOWS
2011-09-19 05:01:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\PMB Files
2011-09-18 12:38:13 ----D---- C:\WINDOWS\Prefetch
2011-09-18 10:22:52 ----D---- C:\WINDOWS\Debug
2011-09-17 22:48:22 ----HD---- C:\WINDOWS\inf
2011-09-17 22:48:21 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-17 22:48:04 ----RD---- C:\Program Files
2011-09-17 09:37:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-17 09:28:36 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-16 06:37:13 ----D---- C:\Gamesy
2011-09-16 06:27:22 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2011-09-16 05:33:55 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-15 23:12:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-15 23:02:29 ----RSD---- C:\WINDOWS\Fonts
2011-09-15 20:51:16 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Skype
2011-09-15 14:54:33 ----A---- C:\WINDOWS\NeroDigital.ini
2011-09-15 06:07:55 ----D---- C:\Program Files\DaemonicMU Season IV
2011-09-13 23:08:54 ----D---- C:\WINDOWS\WinSxS
2011-09-13 23:08:46 ----D---- C:\WINDOWS\system32\DirectX
2011-09-13 23:08:03 ----RSD---- C:\WINDOWS\assembly
2011-09-10 09:57:19 ----D---- C:\WINDOWS\security
2011-09-09 11:12:04 ----A---- C:\WINDOWS\system32\crypt32.dll
2011-09-08 13:07:22 ----A---- C:\WINDOWS\win.ini
2011-09-08 13:07:22 ----A---- C:\WINDOWS\system.ini
2011-09-08 13:07:21 ----D---- C:\WINDOWS\pss
2011-09-06 22:45:29 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-09-06 01:33:13 ----D---- C:\WINDOWS\Minidump
2011-09-05 18:11:36 ----D---- C:\Program Files\Mozilla Firefox
2011-09-03 18:02:52 ----RD---- C:\Program Files\Skype
2011-09-03 18:02:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-09-03 15:01:15 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2011-08-31 07:10:47 ----D---- C:\WINDOWS\RegisteredPackages
2011-08-31 07:10:45 ----D---- C:\WINDOWS\system32\drivers
2011-08-31 07:09:56 ----A---- C:\WINDOWS\game.ini
2011-08-30 17:14:50 ----D---- C:\Program Files\Common Files\InstallShield
2011-08-29 10:16:47 ----D---- C:\Program Files\Internet Explorer
2011-08-29 10:16:40 ----D---- C:\WINDOWS\ie8updates
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-09-06 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-03-01 218688]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-09-06 110552]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-08-30 279712]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-08-30 25888]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-11-12 100456]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-03-01 75136]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-03-05 153376]
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-05-15 935208]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
S4 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by wqrxs at 2011-09-19 18:32:40
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 47 GB (21%) free of 230 GB
Total RAM: 1023 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:32:48, on 19.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Gamesy\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Gamesy\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.33\deploy\LoLLauncher.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\wqrxs\Plocha\RSIT.exe
C:\Program Files\trend micro\wqrxs.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5419 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core1cc0b11bfe8090a.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003UA.job
C:\WINDOWS\tasks\WGASetup.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-03-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-09-06 806456]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-11-04 1753192]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-05-03 399736]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\wqrxs\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-02-28 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2011-08-18 17360520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-05-03 399736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 409088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 4.0"=2
"Nero BackItUp Scheduler 3"=2
"Hamachi2Svc"=2
"PLFlash DeviceIoControl Service"=2
"JavaQuickStarterService"=2
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe:*:Enabled:iw3mp"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Gamesy\League of Legends\air\LolClient.exe"="C:\Gamesy\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\League of Legends\game\League of Legends.exe"="C:\Gamesy\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin:*:Enabled:client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe:*:Enabled:Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Gamesy\League of Legends\lol.launcher.exe"="C:\Gamesy\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Gamesy\Lolko\air\LolClient.exe"="C:\Gamesy\Lolko\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\Lolko\game\League of Legends.exe"="C:\Gamesy\Lolko\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Gamesy\Counter-Strike Source\hl2.exe"="C:\Gamesy\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"C:\Gamesy\The Settlers 7 - Paths to a Kingdom\Data\Base\_Dbg\Bin\Release\Settlers7R.exe"="C:\Gamesy\The Settlers 7 - Paths to a Kingdom\Data\Base\_Dbg\Bin\Release\Settlers7R.exe:*:Enabled:The Settlers 7 - Paths to a Kingdom"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"wave5"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer4"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"VIDC.FPS1"=frapsvid.dll
"VIDC.FMVC"=fmcodec.dll
======List of files/folders created in the last 1 month======
2011-09-17 22:48:04 ----D---- C:\Program Files\DsNET Corp
2011-09-17 09:37:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-15 23:06:23 ----A---- C:\WINDOWS\eReg.dat
2011-09-15 22:59:13 ----A---- C:\WINDOWS\CD_Start.INI
2011-09-14 13:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-14 07:24:08 ----SHD---- C:\found.000
2011-09-07 22:14:13 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Prison Break
2011-09-07 11:57:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2607712$
2011-09-06 05:24:09 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Opera
2011-09-06 05:24:01 ----D---- C:\Program Files\Opera
2011-09-06 05:15:12 ----A---- C:\WINDOWS\system32\msvcr71.dll
2011-09-06 05:15:11 ----A---- C:\WINDOWS\system32\msvcp71.dll
2011-09-06 05:13:06 ----A---- C:\WINDOWS\system32\mfc71.dll
2011-09-05 12:20:41 ----A---- C:\WINDOWS\WORDPAD.INI
2011-09-04 19:59:01 ----D---- C:\WINDOWS\system32\appmgmt
2011-09-03 09:56:15 ----D---- C:\Program Files\Ubisoft
2011-08-31 07:20:01 ----D---- C:\Program Files\GamePark2
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\psisdecd.dll
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\wstcodec.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\streamip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\slip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\ndisip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\nabtsfec.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\msdv.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\mpe.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\ccdecode.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\bdasup.sys
2011-08-30 23:22:28 ----A---- C:\WINDOWS\system32\drivers\atksgt.sys
2011-08-30 23:22:27 ----A---- C:\WINDOWS\system32\drivers\lirsgt.sys
2011-08-29 17:30:03 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Allstar
2011-08-29 10:23:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-08-29 10:22:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-08-29 10:21:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-08-29 10:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-08-29 10:21:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-08-29 10:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-08-29 10:16:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-08-29 10:16:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
======List of files/folders modified in the last 1 month======
2011-09-19 18:32:43 ----D---- C:\Program Files\trend micro
2011-09-19 18:06:47 ----D---- C:\WINDOWS\Temp
2011-09-19 18:05:44 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\uTorrent
2011-09-19 14:49:05 ----D---- C:\WINDOWS\Microsoft.NET
2011-09-19 12:09:56 ----D---- C:\WINDOWS\system32
2011-09-19 12:09:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-19 08:51:47 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-19 08:51:43 ----SHD---- C:\WINDOWS\Installer
2011-09-19 08:02:26 ----D---- C:\WINDOWS
2011-09-19 05:01:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\PMB Files
2011-09-18 12:38:13 ----D---- C:\WINDOWS\Prefetch
2011-09-18 10:22:52 ----D---- C:\WINDOWS\Debug
2011-09-17 22:48:22 ----HD---- C:\WINDOWS\inf
2011-09-17 22:48:21 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-17 22:48:04 ----RD---- C:\Program Files
2011-09-17 09:37:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-17 09:28:36 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-16 06:37:13 ----D---- C:\Gamesy
2011-09-16 06:27:22 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2011-09-16 05:33:55 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-15 23:12:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-15 23:02:29 ----RSD---- C:\WINDOWS\Fonts
2011-09-15 20:51:16 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Skype
2011-09-15 14:54:33 ----A---- C:\WINDOWS\NeroDigital.ini
2011-09-15 06:07:55 ----D---- C:\Program Files\DaemonicMU Season IV
2011-09-13 23:08:54 ----D---- C:\WINDOWS\WinSxS
2011-09-13 23:08:46 ----D---- C:\WINDOWS\system32\DirectX
2011-09-13 23:08:03 ----RSD---- C:\WINDOWS\assembly
2011-09-10 09:57:19 ----D---- C:\WINDOWS\security
2011-09-09 11:12:04 ----A---- C:\WINDOWS\system32\crypt32.dll
2011-09-08 13:07:22 ----A---- C:\WINDOWS\win.ini
2011-09-08 13:07:22 ----A---- C:\WINDOWS\system.ini
2011-09-08 13:07:21 ----D---- C:\WINDOWS\pss
2011-09-06 22:45:29 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-09-06 01:33:13 ----D---- C:\WINDOWS\Minidump
2011-09-05 18:11:36 ----D---- C:\Program Files\Mozilla Firefox
2011-09-03 18:02:52 ----RD---- C:\Program Files\Skype
2011-09-03 18:02:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-09-03 15:01:15 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2011-08-31 07:10:47 ----D---- C:\WINDOWS\RegisteredPackages
2011-08-31 07:10:45 ----D---- C:\WINDOWS\system32\drivers
2011-08-31 07:09:56 ----A---- C:\WINDOWS\game.ini
2011-08-30 17:14:50 ----D---- C:\Program Files\Common Files\InstallShield
2011-08-29 10:16:47 ----D---- C:\Program Files\Internet Explorer
2011-08-29 10:16:40 ----D---- C:\WINDOWS\ie8updates
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-09-06 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-03-01 218688]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-09-06 110552]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-08-30 279712]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-08-30 25888]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-11-12 100456]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-03-01 75136]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-03-05 153376]
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-05-15 935208]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
S4 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
-----------------EOF-----------------
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Zpomalené PC, pády, neůmyslné restarty.
Mrknu na to zítra,zatím mám pro vás bojový úkol
Jděte do složky C:\Windows\Minidump, pokud zde najdete soubory,tak je zabalte( třeba programem winrar) a nahrajte na http://www.leteckaposta.cz , sem mi vložte odkaz na stažení


Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Zpomalené PC, pády, neůmyslné restarty.
Je tu chyba ovladače od Avastu..zkusil bych odinstalovat avast pomocí utility: http://files.avast.com/files/eng/aswclear.exe
Poté sledujte jak se chová počítač..později nainstalujeme znovu Avast nebo vybereme jiný AV
Ještě vám doporučím údržbu pc..
TFC
Údržba PC:
1)Čištění dočasných složek + neplatné registry
Ccleaner
Defraggler
FileHippo.com Update Checker
Jak se chová PC 
Poté sledujte jak se chová počítač..později nainstalujeme znovu Avast nebo vybereme jiný AV



- Stáhneme a spustíme program
- Klikneme na Start a potvrdíme OK
- Program začne uklízet,poté restartuje pc
- po použití program smažte
Údržba PC:
1)Čištění dočasných složek + neplatné registry

- Stáhneme a nainstalujeme program
- Spustíme program
- ČISTIČ
Windows zde necháme vše jak je (pokud používáme IE,tak odškrkneme jeho položky) a zaškrkneme položky Start Menu zástupci a Zástupci na ploše a odškrkneme volbu Zbytky souborů v paměti
Aplikace - necháme jak je,ale pokud používáme nějaký prohlížeč (Google chrome,Firefox,Opera..) tak odškrkneme jeho položky
>Stiskeneme tlačítko Analyzovat a poté Spustit Cleaner - Registry
>Stiskneme tlačítko Hledej problémy,program začne hledat neplatné registry..podé zvolíme Opravit vybrané problémy..
>Program se zeptá,zda chceme vytvořit zálohu registrů,zvolíme ano a uložíme si někde zálohu(kdyby byli po opravení registru s něčím problémy,tak zálohu obnovíme tak,že spustíme uloženou zálohu a potvrdíme ano),dále zvolíme Opravit všechny problémy a Zavřít
>opakujte dokud nebude registr bez problémů - Program používáme 1x 14dní (záleží na používání pc,můžeme i jednou týdně)


- Stáhneme a nainstalujeme program
- Spustíme program
- Vybereme disk ( C:,D:..prostě který používáme)
- Pokud je ve sloupci Fragmentace více než 5% dejte Defragmentovat
- Proveďte se všemi používanými disky
- Provádíme 1x za měsíc


- Stáhneme a nainstalujeme program(Při instalaci odškrkneme volbu Run at Startup )
- Spustíme program
- Program vyhledá nainstalované programy v PC a zjistí dostupné aktualizace
- Poté se vám otevře internetová stránka,kde budou nabídnuté aplikace k aktualizování
>X Updates Detected..to jsou dostupné aktualizace..
> klikneme na zelenou šipečku a stáhneme program,poté nainstalujeme jeho aktuální verzi
>X Beta Updates Detected..tyto aktualizace nestahujte,jedná se o betaverze,které jsou ve vývoji a jsou nestabilní
- Provádíme 1x za 14 dní nebo jednou za měsíc


Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Zpomalené PC, pády, neůmyslné restarty.
Dobrý den na PC mi vyšel čas až dnes, tak se do toho pustím a pak dám vědět
.
Zjištěné problémy:
Když chci nainstalovat novější verzi Display ovladačů a updatnout Daemon Tools, tak mi to hodí Modrou Smrt.
Také se mi už 2x od sebe vypnul sám počítač (jako by ho někdo odpojil ze zásuvky a zase zapojil), ale to si myslím, že je jen dočasné, protože byla mnoha instalací a odinstalací za jedno spuštění
.
// Zatím PC běží svižnější než předtím,
// Ještě se pokusím dořešit problémy s tím Deamonem a Ovladačem na Grafiku v nouzovém režimu, kdyby byl ještě nějaký problém tak napíši. Zatím vše vypadá dobře
. Až odejdu nechám PC defragmentovat, jinak jsem udělal zatím vše podle vašich pokynů.

Zjištěné problémy:
Když chci nainstalovat novější verzi Display ovladačů a updatnout Daemon Tools, tak mi to hodí Modrou Smrt.
Také se mi už 2x od sebe vypnul sám počítač (jako by ho někdo odpojil ze zásuvky a zase zapojil), ale to si myslím, že je jen dočasné, protože byla mnoha instalací a odinstalací za jedno spuštění

// Zatím PC běží svižnější než předtím,
// Ještě se pokusím dořešit problémy s tím Deamonem a Ovladačem na Grafiku v nouzovém režimu, kdyby byl ještě nějaký problém tak napíši. Zatím vše vypadá dobře

- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Zpomalené PC, pády, neůmyslné restarty.
Počkám na výsledek v nouzovém režimu 

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Zpomalené PC, pády, neůmyslné restarty.
Dobrý den omlouvám se, ale dříve jsem se k PC nedostal, v nouzovém režimu jsem vše nainstaloval. Dnes se mi, ale vyskytl další problém a to s tím, že se mi do jedné hodiny restartoval desetkrát počítač. Dám log z Rsitu.
Logfile of random's system information tool 1.09 (written by random/random)
Run by wqrxs at 2011-09-25 21:12:37
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 65 GB (28%) free of 230 GB
Total RAM: 1023 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:12:40, on 25.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\wqrxs\Plocha\RSIT.exe
C:\Program Files\trend micro\wqrxs.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Aktualizovat ESET licenci.lnk = C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 6763519312
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5650 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core1cc0b11bfe8090a.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003UA.job
C:\WINDOWS\tasks\WGASetup.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
wikipedia.xml
yahoo.xml
C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default\extensions\
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-08-16 3942048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-09-23 56712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet []
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-05-04 252136]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-08 3076144]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com]
C:\Program Files\FileHippo.com\UpdateChecker.exe [2010-08-09 248832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\wqrxs\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-02-28 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-04-16 3872080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2011-09-12 17351304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-09-23 641400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 409088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 4.0"=2
"Nero BackItUp Scheduler 3"=2
"Hamachi2Svc"=2
"PLFlash DeviceIoControl Service"=2
"JavaQuickStarterService"=2
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Aktualizovat ESET licenci.lnk - C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe:*:Enabled:iw3mp"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Gamesy\League of Legends\air\LolClient.exe"="C:\Gamesy\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\League of Legends\game\League of Legends.exe"="C:\Gamesy\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin:*:Enabled:client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe:*:Enabled:Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Gamesy\League of Legends\lol.launcher.exe"="C:\Gamesy\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Gamesy\Lolko\air\LolClient.exe"="C:\Gamesy\Lolko\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\Lolko\game\League of Legends.exe"="C:\Gamesy\Lolko\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Gamesy\Counter-Strike Source\hl2.exe"="C:\Gamesy\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"wave5"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer4"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"VIDC.FPS1"=frapsvid.dll
"msacm.siren"=sirenacm.dll
======List of files/folders created in the last 1 month======
2011-09-24 20:38:52 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-09-24 20:28:18 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2011-09-23 09:19:20 ----D---- C:\Program Files\TNod User & Password Finder
2011-09-23 09:06:08 ----D---- C:\Program Files\ESET
2011-09-23 09:06:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-09-23 08:51:09 ----A---- C:\WINDOWS\system32\msi.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msisip.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msimsg.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msihnd.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msiexec.exe
2011-09-23 08:50:32 ----D---- C:\Program Files\Microsoft
2011-09-23 08:50:18 ----D---- C:\Program Files\Windows Live SkyDrive
2011-09-23 08:49:55 ----D---- C:\Program Files\Windows Live
2011-09-23 08:47:37 ----D---- C:\Program Files\Common Files\Windows Live
2011-09-23 08:38:19 ----A---- C:\Documents and Settings\wqrxs\Data aplikací\pcouffin.sys
2011-09-23 08:38:19 ----A---- C:\Documents and Settings\wqrxs\Data aplikací\inst.exe
2011-09-23 08:28:43 ----D---- C:\Program Files\Common Files\Java
2011-09-23 08:28:28 ----A---- C:\WINDOWS\system32\javaws.exe
2011-09-23 08:28:28 ----A---- C:\WINDOWS\system32\javaw.exe
2011-09-23 08:28:28 ----A---- C:\WINDOWS\system32\java.exe
2011-09-23 08:21:21 ----D---- C:\Program Files\FileHippo.com
2011-09-23 07:20:30 ----SHD---- C:\Config.Msi
2011-09-17 22:48:04 ----D---- C:\Program Files\DsNET Corp
2011-09-17 09:37:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-15 23:06:23 ----A---- C:\WINDOWS\eReg.dat
2011-09-15 22:59:13 ----A---- C:\WINDOWS\CD_Start.INI
2011-09-14 13:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-14 07:24:08 ----SHD---- C:\found.000
2011-09-07 22:14:13 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Prison Break
2011-09-07 11:57:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2607712$
2011-09-06 05:24:09 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Opera
2011-09-06 05:24:01 ----D---- C:\Program Files\Opera
2011-09-06 05:15:12 ----A---- C:\WINDOWS\system32\msvcr71.dll
2011-09-06 05:15:11 ----A---- C:\WINDOWS\system32\msvcp71.dll
2011-09-06 05:13:06 ----A---- C:\WINDOWS\system32\mfc71.dll
2011-09-05 12:20:41 ----A---- C:\WINDOWS\WORDPAD.INI
2011-09-04 19:59:01 ----D---- C:\WINDOWS\system32\appmgmt
2011-08-31 07:20:01 ----D---- C:\Program Files\GamePark2
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\psisdecd.dll
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\wstcodec.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\streamip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\slip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\ndisip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\nabtsfec.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\msdv.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\mpe.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\ccdecode.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\bdasup.sys
2011-08-30 23:22:28 ----A---- C:\WINDOWS\system32\drivers\atksgt.sys
2011-08-30 23:22:27 ----A---- C:\WINDOWS\system32\drivers\lirsgt.sys
2011-08-29 17:30:03 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Allstar
2011-08-29 10:23:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-08-29 10:22:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-08-29 10:21:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-08-29 10:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-08-29 10:21:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-08-29 10:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-08-29 10:16:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-08-29 10:16:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
======List of files/folders modified in the last 1 month======
2011-09-25 21:12:39 ----D---- C:\Program Files\trend micro
2011-09-25 20:58:32 ----D---- C:\WINDOWS\Temp
2011-09-25 20:52:03 ----D---- C:\WINDOWS
2011-09-25 18:08:11 ----D---- C:\WINDOWS\Minidump
2011-09-25 18:03:20 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-25 17:34:21 ----SHD---- C:\WINDOWS\Installer
2011-09-25 17:34:21 ----D---- C:\WINDOWS\system32\DirectX
2011-09-25 17:34:20 ----HD---- C:\WINDOWS\inf
2011-09-25 17:34:10 ----RSD---- C:\WINDOWS\assembly
2011-09-25 17:33:55 ----D---- C:\WINDOWS\Logs
2011-09-25 17:32:59 ----D---- C:\WINDOWS\Prefetch
2011-09-25 17:10:39 ----D---- C:\WINDOWS\Microsoft.NET
2011-09-25 16:55:46 ----D---- C:\WINDOWS\system32
2011-09-24 21:15:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-24 20:28:25 ----D---- C:\WINDOWS\WinSxS
2011-09-24 20:28:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-24 20:24:33 ----D---- C:\WINDOWS\SxsCaPendDel
2011-09-24 20:24:01 ----D---- C:\Gamesy
2011-09-23 11:43:25 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\DAEMON Tools Lite
2011-09-23 11:43:24 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\uTorrent
2011-09-23 10:06:50 ----A---- C:\WINDOWS\NeroDigital.ini
2011-09-23 09:38:54 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-09-23 09:38:54 ----D---- C:\WINDOWS\SoftwareDistribution
2011-09-23 09:36:36 ----A---- C:\WINDOWS\win.ini
2011-09-23 09:36:36 ----A---- C:\WINDOWS\system.ini
2011-09-23 09:19:20 ----RD---- C:\Program Files
2011-09-23 09:16:24 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-23 09:06:58 ----D---- C:\WINDOWS\system32\drivers
2011-09-23 09:00:17 ----SD---- C:\WINDOWS\Tasks
2011-09-23 08:56:55 ----D---- C:\WINDOWS\Help
2011-09-23 08:55:22 ----D---- C:\Program Files\World of Warcraft TBC
2011-09-23 08:50:03 ----RSD---- C:\WINDOWS\Fonts
2011-09-23 08:47:37 ----D---- C:\Program Files\Common Files
2011-09-23 08:47:24 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-09-23 08:46:27 ----D---- C:\Program Files\Mozilla Firefox
2011-09-23 08:42:31 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Skype
2011-09-23 08:38:33 ----D---- C:\Program Files\VSO
2011-09-23 08:38:19 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Vso
2011-09-23 08:37:34 ----D---- C:\Program Files\uTorrent
2011-09-23 08:31:59 ----RD---- C:\Program Files\Skype
2011-09-23 08:31:07 ----D---- C:\Program Files\The KMPlayer
2011-09-23 08:28:14 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-09-23 08:28:11 ----D---- C:\Program Files\Java
2011-09-23 08:25:44 ----D---- C:\Program Files\WinRAR
2011-09-23 08:23:08 ----D---- C:\Program Files\CCleaner
2011-09-23 08:14:53 ----D---- C:\Program Files\AVAST Software
2011-09-21 14:32:00 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-18 10:22:52 ----D---- C:\WINDOWS\Debug
2011-09-17 09:28:36 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-16 06:27:22 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2011-09-15 23:12:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-15 06:07:55 ----D---- C:\Program Files\DaemonicMU Season IV
2011-09-10 09:57:19 ----D---- C:\WINDOWS\security
2011-09-09 11:12:04 ----A---- C:\WINDOWS\system32\crypt32.dll
2011-09-08 13:07:21 ----D---- C:\WINDOWS\pss
2011-09-03 18:02:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-09-03 15:01:15 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2011-08-31 07:10:47 ----D---- C:\WINDOWS\RegisteredPackages
2011-08-31 07:09:56 ----A---- C:\WINDOWS\game.ini
2011-08-30 17:14:50 ----D---- C:\Program Files\Common Files\InstallShield
2011-08-29 10:16:47 ----D---- C:\Program Files\Internet Explorer
2011-08-29 10:16:40 ----D---- C:\WINDOWS\ie8updates
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-03-01 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2011-08-04 103112]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-08-30 279712]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-08-30 25888]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-11-12 100456]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-09-08 974944]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-03-01 75136]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2011-09-23 161664]
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-05-15 935208]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
S4 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by wqrxs at 2011-09-25 21:12:37
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 65 GB (28%) free of 230 GB
Total RAM: 1023 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:12:40, on 25.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\wqrxs\Plocha\RSIT.exe
C:\Program Files\trend micro\wqrxs.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Aktualizovat ESET licenci.lnk = C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 6763519312
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5650 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003Core1cc0b11bfe8090a.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-113007714-682003330-1003UA.job
C:\WINDOWS\tasks\WGASetup.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
wikipedia.xml
yahoo.xml
C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default\extensions\
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
C:\Documents and Settings\wqrxs\Data aplikací\Mozilla\Firefox\Profiles\4aaxh742.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-08-16 3942048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-09-23 56712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet []
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-05-04 252136]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-09-08 3076144]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com]
C:\Program Files\FileHippo.com\UpdateChecker.exe [2010-08-09 248832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\wqrxs\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-02-28 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-04-16 3872080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2011-09-12 17351304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-09-23 641400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 409088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 4.0"=2
"Nero BackItUp Scheduler 3"=2
"Hamachi2Svc"=2
"PLFlash DeviceIoControl Service"=2
"JavaQuickStarterService"=2
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Aktualizovat ESET licenci.lnk - C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4\iw3mp.exe:*:Enabled:iw3mp"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Gamesy\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="C:\Gamesy\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Gamesy\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Gamesy\League of Legends\air\LolClient.exe"="C:\Gamesy\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\League of Legends\game\League of Legends.exe"="C:\Gamesy\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\client.bin:*:Enabled:client"
"C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe"="C:\Program Files\Movie Maker\Movie Maker\Sindicate\Launcher.exe:*:Enabled:Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.937\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX00.843\Patcher\celestialworld.bin:*:Enabled:celestialworld"
"C:\Gamesy\League of Legends\lol.launcher.exe"="C:\Gamesy\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX10.281\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX19.7531\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe"="C:\Documents and Settings\wqrxs\Local Settings\Temp\Rar$EX59.937\Dinamik Mt2\mc.exe:*:Enabled:mc"
"C:\Gamesy\Lolko\air\LolClient.exe"="C:\Gamesy\Lolko\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"C:\Gamesy\Lolko\game\League of Legends.exe"="C:\Gamesy\Lolko\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Gamesy\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Gamesy\Counter-Strike Source\hl2.exe"="C:\Gamesy\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"wave5"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer4"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"VIDC.FPS1"=frapsvid.dll
"msacm.siren"=sirenacm.dll
======List of files/folders created in the last 1 month======
2011-09-24 20:38:52 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-09-24 20:28:18 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2011-09-23 09:19:20 ----D---- C:\Program Files\TNod User & Password Finder
2011-09-23 09:06:08 ----D---- C:\Program Files\ESET
2011-09-23 09:06:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-09-23 08:51:09 ----A---- C:\WINDOWS\system32\msi.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msisip.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msimsg.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msihnd.dll
2011-09-23 08:51:08 ----A---- C:\WINDOWS\system32\msiexec.exe
2011-09-23 08:50:32 ----D---- C:\Program Files\Microsoft
2011-09-23 08:50:18 ----D---- C:\Program Files\Windows Live SkyDrive
2011-09-23 08:49:55 ----D---- C:\Program Files\Windows Live
2011-09-23 08:47:37 ----D---- C:\Program Files\Common Files\Windows Live
2011-09-23 08:38:19 ----A---- C:\Documents and Settings\wqrxs\Data aplikací\pcouffin.sys
2011-09-23 08:38:19 ----A---- C:\Documents and Settings\wqrxs\Data aplikací\inst.exe
2011-09-23 08:28:43 ----D---- C:\Program Files\Common Files\Java
2011-09-23 08:28:28 ----A---- C:\WINDOWS\system32\javaws.exe
2011-09-23 08:28:28 ----A---- C:\WINDOWS\system32\javaw.exe
2011-09-23 08:28:28 ----A---- C:\WINDOWS\system32\java.exe
2011-09-23 08:21:21 ----D---- C:\Program Files\FileHippo.com
2011-09-23 07:20:30 ----SHD---- C:\Config.Msi
2011-09-17 22:48:04 ----D---- C:\Program Files\DsNET Corp
2011-09-17 09:37:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2616676$
2011-09-15 23:06:23 ----A---- C:\WINDOWS\eReg.dat
2011-09-15 22:59:13 ----A---- C:\WINDOWS\CD_Start.INI
2011-09-14 13:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-09-14 07:24:08 ----SHD---- C:\found.000
2011-09-07 22:14:13 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Prison Break
2011-09-07 11:57:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2607712$
2011-09-06 05:24:09 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Opera
2011-09-06 05:24:01 ----D---- C:\Program Files\Opera
2011-09-06 05:15:12 ----A---- C:\WINDOWS\system32\msvcr71.dll
2011-09-06 05:15:11 ----A---- C:\WINDOWS\system32\msvcp71.dll
2011-09-06 05:13:06 ----A---- C:\WINDOWS\system32\mfc71.dll
2011-09-05 12:20:41 ----A---- C:\WINDOWS\WORDPAD.INI
2011-09-04 19:59:01 ----D---- C:\WINDOWS\system32\appmgmt
2011-08-31 07:20:01 ----D---- C:\Program Files\GamePark2
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\psisdecd.dll
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\wstcodec.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\streamip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\slip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\ndisip.sys
2011-08-31 07:10:21 ----A---- C:\WINDOWS\system32\drivers\nabtsfec.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\msdv.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\mpe.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\ccdecode.sys
2011-08-31 07:10:20 ----A---- C:\WINDOWS\system32\drivers\bdasup.sys
2011-08-30 23:22:28 ----A---- C:\WINDOWS\system32\drivers\atksgt.sys
2011-08-30 23:22:27 ----A---- C:\WINDOWS\system32\drivers\lirsgt.sys
2011-08-29 17:30:03 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Allstar
2011-08-29 10:23:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-08-29 10:22:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-08-29 10:21:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-08-29 10:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-08-29 10:21:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-08-29 10:16:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-08-29 10:16:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-08-29 10:16:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
======List of files/folders modified in the last 1 month======
2011-09-25 21:12:39 ----D---- C:\Program Files\trend micro
2011-09-25 20:58:32 ----D---- C:\WINDOWS\Temp
2011-09-25 20:52:03 ----D---- C:\WINDOWS
2011-09-25 18:08:11 ----D---- C:\WINDOWS\Minidump
2011-09-25 18:03:20 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-25 17:34:21 ----SHD---- C:\WINDOWS\Installer
2011-09-25 17:34:21 ----D---- C:\WINDOWS\system32\DirectX
2011-09-25 17:34:20 ----HD---- C:\WINDOWS\inf
2011-09-25 17:34:10 ----RSD---- C:\WINDOWS\assembly
2011-09-25 17:33:55 ----D---- C:\WINDOWS\Logs
2011-09-25 17:32:59 ----D---- C:\WINDOWS\Prefetch
2011-09-25 17:10:39 ----D---- C:\WINDOWS\Microsoft.NET
2011-09-25 16:55:46 ----D---- C:\WINDOWS\system32
2011-09-24 21:15:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-24 20:28:25 ----D---- C:\WINDOWS\WinSxS
2011-09-24 20:28:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-24 20:24:33 ----D---- C:\WINDOWS\SxsCaPendDel
2011-09-24 20:24:01 ----D---- C:\Gamesy
2011-09-23 11:43:25 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\DAEMON Tools Lite
2011-09-23 11:43:24 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\uTorrent
2011-09-23 10:06:50 ----A---- C:\WINDOWS\NeroDigital.ini
2011-09-23 09:38:54 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-09-23 09:38:54 ----D---- C:\WINDOWS\SoftwareDistribution
2011-09-23 09:36:36 ----A---- C:\WINDOWS\win.ini
2011-09-23 09:36:36 ----A---- C:\WINDOWS\system.ini
2011-09-23 09:19:20 ----RD---- C:\Program Files
2011-09-23 09:16:24 ----HD---- C:\WINDOWS\$hf_mig$
2011-09-23 09:06:58 ----D---- C:\WINDOWS\system32\drivers
2011-09-23 09:00:17 ----SD---- C:\WINDOWS\Tasks
2011-09-23 08:56:55 ----D---- C:\WINDOWS\Help
2011-09-23 08:55:22 ----D---- C:\Program Files\World of Warcraft TBC
2011-09-23 08:50:03 ----RSD---- C:\WINDOWS\Fonts
2011-09-23 08:47:37 ----D---- C:\Program Files\Common Files
2011-09-23 08:47:24 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-09-23 08:46:27 ----D---- C:\Program Files\Mozilla Firefox
2011-09-23 08:42:31 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Skype
2011-09-23 08:38:33 ----D---- C:\Program Files\VSO
2011-09-23 08:38:19 ----D---- C:\Documents and Settings\wqrxs\Data aplikací\Vso
2011-09-23 08:37:34 ----D---- C:\Program Files\uTorrent
2011-09-23 08:31:59 ----RD---- C:\Program Files\Skype
2011-09-23 08:31:07 ----D---- C:\Program Files\The KMPlayer
2011-09-23 08:28:14 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-09-23 08:28:11 ----D---- C:\Program Files\Java
2011-09-23 08:25:44 ----D---- C:\Program Files\WinRAR
2011-09-23 08:23:08 ----D---- C:\Program Files\CCleaner
2011-09-23 08:14:53 ----D---- C:\Program Files\AVAST Software
2011-09-21 14:32:00 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-18 10:22:52 ----D---- C:\WINDOWS\Debug
2011-09-17 09:28:36 ----A---- C:\WINDOWS\system32\MRT.exe
2011-09-16 06:27:22 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2011-09-15 23:12:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-15 06:07:55 ----D---- C:\Program Files\DaemonicMU Season IV
2011-09-10 09:57:19 ----D---- C:\WINDOWS\security
2011-09-09 11:12:04 ----A---- C:\WINDOWS\system32\crypt32.dll
2011-09-08 13:07:21 ----D---- C:\WINDOWS\pss
2011-09-03 18:02:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-09-03 15:01:15 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2011-08-31 07:10:47 ----D---- C:\WINDOWS\RegisteredPackages
2011-08-31 07:09:56 ----A---- C:\WINDOWS\game.ini
2011-08-30 17:14:50 ----D---- C:\Program Files\Common Files\InstallShield
2011-08-29 10:16:47 ----D---- C:\Program Files\Internet Explorer
2011-08-29 10:16:40 ----D---- C:\WINDOWS\ie8updates
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-05-17 92800]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-03-01 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2011-08-04 103112]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-08-30 279712]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-08-30 25888]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-11-12 100456]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-09-08 974944]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-03-01 75136]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2011-09-23 161664]
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-05-15 935208]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
S4 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
-----------------EOF-----------------
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Zpomalené PC, pády, neůmyslné restarty.
Bohužel nebudeme moci dále pokračovat,dokud budete mít v pc nelegální programy... Jako je třeba ESET
Pravidla fora: č.1 a č.2, č.3

Pravidla fora: č.1 a č.2, č.3
Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2