
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Podezření na vir - zpomalené PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Podezření na vir - zpomalené PC
Zdravím,
mám takové podezření... Počítač běhá zdá se mi tak nějak zpomaleně, prohlížeč (Firefox) se často zasekává a neodpovídá, mám problémy se spuštěním některých her a nedavno, když jsem jednu hru vypnul jsem na dolní liště v pravo viděl několik zelených ikon, které pak rychle zmizely... Plus nedávno mi PC hodil BSOD o přetížení RAM ve chvíli, kdy jsem nedělal nic tak extra drastického... Je sice možné, že je to tu shoda náhod a já jsem jen paranoidní, ale chtěl bych mít jistotu...
Log z RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Cvach at 2011-11-13 23:34:44
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 19 GB (15%) free of 130 GB
Total RAM: 4094 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:34:49, on 13.11.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Windows\vsnpstd3.exe
D:\Programy\Alwil Software\Avast5\AvastUI.exe
D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\ICQ7.4\ICQ.exe
C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Windows\tsnpstd3.exe
C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
D:\Programy\FRAPS\fraps.exe
C:\Program Files\trend micro\Cvach.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.232.208.116:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 92.62.229.253 10.4.24.238
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe" /md I
O4 - HKCU\..\Run: [avast! Antivirus] D:\Programy\Alwil Software\Avast5\AvastUI.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [EADM] "D:\Programy\Origin\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RGSC] D:\Hry\GTA IV\Rockstar Social Club\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Akamai NetSession Interface] C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.4\ICQ.exe" silent loginmode=4
O4 - HKLM\..\Policies\Explorer\Run: [Java] C:\Users\Cvach\AppData\Roaming\pervious.exe
O4 - HKUS\S-1-5-21-4198012068-3784662148-1576838182-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4198012068-3784662148-1576838182-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: CurseClientStartup.ccip
O4 - Startup: hamachi.lnk = D:\Programy\Hamachi\hamachi.exe
O4 - Startup: Rainmeter.lnk = D:\Programy\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Programy\ICQ 7\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Programy\ICQ 7\ICQ7.5\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - D:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - D:\Programy\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - D:\Hry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - D:\Programy\XAMPP\FileZillaFTP\FileZillaServer.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - D:\Programy\XAMPP\mysql\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @D:\Programy\TumeUp Utilites\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - D:\Programy\TumeUp Utilites\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - D:\Programy\TumeUp Utilites\TuneUpUtilitiesService64.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Programy\Tungle\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13740 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"D:\Programy\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"D:\Programy\Alwil Software\Avast5\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"D:\Programy\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Windows\vsnpstd3.exe"
"D:\Programy\Alwil Software\Avast5\AvastUI.exe"
"D:\Programy\TortoiseSVN\bin\TSVNCache.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe"
"C:\Program Files (x86)\ICQ7.4\ICQ.exe" silent loginmode=4
C:/Users/Cvach/AppData/Local/Akamai/netsession_win.exe --client
"D:\Programy\Rainmeter\Rainmeter.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Windows\tsnpstd3.exe"
"C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe" /md I
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
taskeng.exe {CB6EB8FB-256E-4052-862D-373CD95E823E}
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
C:\Windows\SysWOW64\svchost.exe -k Akamai
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
"C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
D:\Programy\XAMPP\mysql\bin\mysqld.exe --defaults-file=D:\Programy\XAMPP\mysql\bin\my.ini mysql
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"D:\Programy\TumeUp Utilites\TuneUpUtilitiesService64.exe"
D:\Programy\Tungle\Tunngle\TnglCtrl.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3772
"D:\Programy\TumeUp Utilites\TuneUpUtilitiesApp64.exe" /TUStart /pid:3828
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4548.13d44d30.1817475232 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.8.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 4548 "\\.\pipe\gecko-crash-server-pipe.4548" plugin
D:\Programy\FRAPS\fraps.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"D:\Programy\FRAPS\fraps64.dat"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 544 548 556 65536 552
"D:\Programy\RSIT\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-08 49440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll [2011-08-14 270960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
CescrtHlpr Object - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll [2010-10-26 262144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-04-14 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - facemoods Toolbar - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll [2010-10-26 217088]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll [2011-08-14 237680]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-08 9642528]
"COMODO Internet Security"=D:\Programy\COMODO\COMODO Internet Security\cfp.exe [2011-09-16 9048392]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2008-04-04 120328]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-18 843776]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Java"=C:\Users\Cvach\AppData\Roaming\pervious.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"avast! Antivirus"=D:\Programy\Alwil Software\Avast5\AvastUI.exe [2011-09-06 3722416]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-03-16 2988488]
"DAEMON Tools Lite"=D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2011-08-06 3077528]
"EADM"=D:\Programy\Origin\Origin\Origin.exe [2011-11-07 28846216]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-10-13 17351304]
"RGSC"=D:\Hry\GTA IV\Rockstar Social Club\Rockstar Games Social Club\RGSCLauncher.exe [2008-12-12 306088]
"Akamai NetSession Interface"=C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe [2011-11-12 3303000]
"ICQ"=C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-04-30 119608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-08-04 346320]
"tsnpstd3"=C:\Windows\tsnpstd3.exe [2007-06-15 368640]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"facemoods"=C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe [2010-10-26 323584]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Java"=C:\Users\Cvach\AppData\Roaming\pervious.exe []
C:\Users\Cvach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CurseClientStartup.ccip
hamachi.lnk - D:\Programy\Hamachi\hamachi.exe
Rainmeter.lnk - D:\Programy\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2010-11-20 290304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-11-13 23:34:44 ----D---- C:\rsit
2011-11-11 23:24:30 ----D---- C:\Windows\system32\Macromed
2011-11-11 23:11:01 ----N---- C:\Windows\Setup1.exe
2011-11-11 23:11:01 ----A---- C:\Windows\ST6UNST.EXE
2011-11-10 15:41:52 ----D---- C:\Program Files (x86)\Google
2011-11-09 14:17:20 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-11-09 14:17:18 ----A---- C:\Windows\system32\win32k.sys
2011-11-08 17:44:07 ----D---- C:\Users\Cvach\AppData\Roaming\Sony Creative Software Inc
2011-11-07 20:32:59 ----D---- C:\Program Files (x86)\LooksBuilder
2011-11-04 21:45:07 ----D---- C:\Users\Cvach\AppData\Roaming\Voxatron
2011-11-02 21:35:18 ----SHD---- C:\ProgramData\SecuROM
2011-11-02 21:07:11 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-10-27 17:26:17 ----A---- C:\Windows\SYSWOW64\SQSRVRES.DLL
2011-10-27 17:26:17 ----A---- C:\Windows\SYSWOW64\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll
2011-10-27 17:15:28 ----A---- C:\Windows\system32\shell32.dll
2011-10-27 17:15:26 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-10-25 23:43:19 ----D---- C:\Program Files\WMV9_VCM
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\OpenCL.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvoglv64.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcuvid.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcuda.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcompiler.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-10-17 20:05:37 ----D---- C:\Users\Cvach\AppData\Roaming\LolClient
2011-10-17 19:41:40 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-10-17 19:41:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-10-17 19:41:36 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-10-14 23:54:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
======List of files/folders modified in the last 1 months======
2011-11-13 23:34:47 ----D---- C:\Program Files\trend micro
2011-11-13 23:34:46 ----D---- C:\Windows\temp
2011-11-13 23:28:17 ----D---- C:\ProgramData\PMB Files
2011-11-13 23:11:53 ----D---- C:\Users\Cvach\AppData\Roaming\Skype
2011-11-13 20:14:33 ----D---- C:\Windows\system32\Tasks
2011-11-13 20:11:57 ----D---- C:\Users\Cvach\AppData\Roaming\ICQ
2011-11-13 20:11:53 ----D---- C:\Users\Cvach\AppData\Roaming\Hamachi
2011-11-13 20:10:51 ----D---- C:\ProgramData\NVIDIA
2011-11-13 19:58:50 ----D---- C:\Windows\system32\config
2011-11-12 11:41:39 ----SHD---- C:\Windows\Installer
2011-11-12 00:43:53 ----D---- C:\Windows\system32\catroot
2011-11-12 00:43:39 ----SHD---- C:\System Volume Information
2011-11-11 23:50:05 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2011-11-11 23:49:37 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-11-11 23:49:35 ----D---- C:\ProgramData\ICQ
2011-11-11 23:38:55 ----D---- C:\Windows
2011-11-11 23:24:30 ----D---- C:\Windows\System32
2011-11-11 23:11:51 ----D---- C:\Windows\SysWOW64
2011-11-11 19:53:53 ----D---- C:\ProgramData\boost_interprocess
2011-11-11 19:36:46 ----D---- C:\Users\Cvach\AppData\Roaming\Ubisoft
2011-11-11 19:35:54 ----RSD---- C:\Windows\assembly
2011-11-11 16:43:01 ----D---- C:\Users\Cvach\AppData\Roaming\Audacity
2011-11-10 23:49:14 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-11-10 16:45:11 ----D---- C:\Windows\system32\wdi
2011-11-10 15:41:58 ----D---- C:\Windows\Tasks
2011-11-10 15:41:52 ----RD---- C:\Program Files (x86)
2011-11-10 14:07:13 ----D---- C:\Windows\winsxs
2011-11-10 14:05:07 ----D---- C:\Windows\system32\drivers
2011-11-10 14:05:07 ----D---- C:\Program Files\Common Files\System
2011-11-09 22:53:23 ----A---- C:\Windows\system32\MRT.exe
2011-11-09 16:59:57 ----A---- C:\Windows\avp.ini
2011-11-09 15:23:48 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-11-09 14:17:14 ----D---- C:\Windows\system32\catroot2
2011-11-08 23:17:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-11-08 23:17:07 ----D---- C:\Windows\inf
2011-11-08 17:07:32 ----D---- C:\Users\Cvach\AppData\Roaming\Sony
2011-11-06 14:52:47 ----D---- C:\Windows\system32\drivers\etc
2011-11-05 01:43:10 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2011-11-02 21:35:18 ----D---- C:\ProgramData
2011-10-29 00:16:23 ----D---- C:\Users\Cvach\AppData\Roaming\.minecraft
2011-10-28 12:41:17 ----D---- C:\Windows\Microsoft.NET
2011-10-27 17:26:18 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-10-27 17:24:58 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-10-27 17:23:44 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2011-10-27 17:21:34 ----D---- C:\ProgramData\Microsoft Help
2011-10-27 17:18:06 ----A---- C:\Windows\win.ini
2011-10-27 17:10:25 ----D---- C:\Windows\Logs
2011-10-27 17:10:23 ----D---- C:\Program Files (x86)\Microsoft Office
2011-10-27 02:00:48 ----D---- C:\Program Files\Internet Explorer
2011-10-27 02:00:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-10-26 11:03:17 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-10-25 23:43:19 ----RD---- C:\Program Files
2011-10-24 13:40:59 ----D---- C:\Windows\system32\DriverStore
2011-10-24 13:40:26 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-10-19 20:20:50 ----RD---- C:\Program Files (x86)\Skype
2011-10-19 20:20:45 ----D---- C:\ProgramData\Skype
2011-10-19 20:20:39 ----D---- C:\Users\Cvach\AppData\Roaming\Origin
2011-10-15 09:53:00 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-10-15 09:53:00 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-10-15 09:53:00 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvvsvc.exe
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvsvcr.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvsvc64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvshext.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvmctray.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvgenco64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvdispco64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvcpl.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvapi64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys [2006-06-14 14192]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\Windows\System32\drivers\sfvfs02.sys [2007-01-12 106360]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-12 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-09-06 42328]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-09-06 601944]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-09-06 301912]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-09-06 58200]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2011-09-16 252344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-09-16 41712]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-09-16 92688]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys [2011-01-26 30312]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-09-06 24408]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-09-06 65368]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-11-14 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-11-14 43680]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-01-29 33344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-08 2223392]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-07-08 174184]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\D:\Programy\TumeUp Utilites\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\Windows\System32\drivers\sfdrv01a.sys [2006-07-05 77688]
S0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\Windows\System32\drivers\sfsync02.sys [2006-07-10 22936]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2009-07-14 60288]
S3 Avc;Zařízení AVC; C:\Windows\system32\DRIVERS\avc.sys [2009-07-14 48768]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2009-07-14 61440]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 115240]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 19496]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 158760]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 137256]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 34344]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 136744]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 151592]
S3 s125bus;Sony Ericsson Device 125 driver (WDM); C:\Windows\system32\DRIVERS\s125bus.sys [2007-04-24 108296]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s125mdfl.sys [2007-04-24 19720]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s125mdm.sys [2007-04-24 144648]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s125mgmt.sys [2007-04-24 126216]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s125obex.sys [2007-04-24 123656]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-05-02 10503168]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 vpcuxd;Služba zástupné procedury virtualizace rozhraní USB; C:\Windows\system32\drivers\vpcuxd.sys [2010-11-20 16384]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 avast! Antivirus;avast! Antivirus; D:\Programy\Alwil Software\Avast5\AvastSvc.exe [2011-09-06 44768]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 cmdAgent;COMODO Internet Security Helper Service; D:\Programy\COMODO\COMODO Internet Security\cmdagent.exe [2011-09-16 2528096]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2011-09-22 43028328]
R2 mysql;mysql; D:\Programy\XAMPP\mysql\bin\mysqld.exe [2010-12-03 8133120]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-10-26 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2011-09-22 154984]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; D:\Programy\TumeUp Utilites\TuneUpUtilitiesService64.exe [2009-11-17 1353544]
R2 TunngleService;TunngleService; D:\Programy\Tungle\Tunngle\TnglCtrl.exe [2011-08-09 741224]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-10 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; D:\Hry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 FileZilla Server;FileZilla Server FTP server; D:\Programy\XAMPP\FileZillaFTP\FileZillaServer.exe [2010-10-17 742912]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-10-29 655624]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-10 136176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-02-10 150528]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-11-03 419624]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TuneUp.Defrag;@D:\Programy\TumeUp Utilites\TuneUpDefragService.exe,-1; D:\Programy\TumeUp Utilites\TuneUpDefragService.exe [2010-10-24 607048]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-08 1255736]
S4 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
S4 msvsmon90;Visual Studio 2008 Remote Debugger; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2008-07-29 4737024]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-29 935208]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-09-22 370024]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2011-09-22 255336]
-----------------EOF-----------------
mám takové podezření... Počítač běhá zdá se mi tak nějak zpomaleně, prohlížeč (Firefox) se často zasekává a neodpovídá, mám problémy se spuštěním některých her a nedavno, když jsem jednu hru vypnul jsem na dolní liště v pravo viděl několik zelených ikon, které pak rychle zmizely... Plus nedávno mi PC hodil BSOD o přetížení RAM ve chvíli, kdy jsem nedělal nic tak extra drastického... Je sice možné, že je to tu shoda náhod a já jsem jen paranoidní, ale chtěl bych mít jistotu...
Log z RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Cvach at 2011-11-13 23:34:44
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 19 GB (15%) free of 130 GB
Total RAM: 4094 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:34:49, on 13.11.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Windows\vsnpstd3.exe
D:\Programy\Alwil Software\Avast5\AvastUI.exe
D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\ICQ7.4\ICQ.exe
C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Windows\tsnpstd3.exe
C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
D:\Programy\FRAPS\fraps.exe
C:\Program Files\trend micro\Cvach.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.232.208.116:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 92.62.229.253 10.4.24.238
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe" /md I
O4 - HKCU\..\Run: [avast! Antivirus] D:\Programy\Alwil Software\Avast5\AvastUI.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [EADM] "D:\Programy\Origin\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RGSC] D:\Hry\GTA IV\Rockstar Social Club\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Akamai NetSession Interface] C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.4\ICQ.exe" silent loginmode=4
O4 - HKLM\..\Policies\Explorer\Run: [Java] C:\Users\Cvach\AppData\Roaming\pervious.exe
O4 - HKUS\S-1-5-21-4198012068-3784662148-1576838182-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4198012068-3784662148-1576838182-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: CurseClientStartup.ccip
O4 - Startup: hamachi.lnk = D:\Programy\Hamachi\hamachi.exe
O4 - Startup: Rainmeter.lnk = D:\Programy\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Programy\ICQ 7\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Programy\ICQ 7\ICQ7.5\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - D:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - D:\Programy\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - D:\Hry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - D:\Programy\XAMPP\FileZillaFTP\FileZillaServer.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - D:\Programy\XAMPP\mysql\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @D:\Programy\TumeUp Utilites\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - D:\Programy\TumeUp Utilites\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - D:\Programy\TumeUp Utilites\TuneUpUtilitiesService64.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Programy\Tungle\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13740 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"D:\Programy\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"D:\Programy\Alwil Software\Avast5\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"D:\Programy\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Windows\vsnpstd3.exe"
"D:\Programy\Alwil Software\Avast5\AvastUI.exe"
"D:\Programy\TortoiseSVN\bin\TSVNCache.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe"
"C:\Program Files (x86)\ICQ7.4\ICQ.exe" silent loginmode=4
C:/Users/Cvach/AppData/Local/Akamai/netsession_win.exe --client
"D:\Programy\Rainmeter\Rainmeter.exe"
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe"
"C:\Windows\tsnpstd3.exe"
"C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe" /md I
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
taskeng.exe {CB6EB8FB-256E-4052-862D-373CD95E823E}
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
C:\Windows\SysWOW64\svchost.exe -k Akamai
"C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
"C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
D:\Programy\XAMPP\mysql\bin\mysqld.exe --defaults-file=D:\Programy\XAMPP\mysql\bin\my.ini mysql
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"D:\Programy\TumeUp Utilites\TuneUpUtilitiesService64.exe"
D:\Programy\Tungle\Tunngle\TnglCtrl.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3772
"D:\Programy\TumeUp Utilites\TuneUpUtilitiesApp64.exe" /TUStart /pid:3828
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4548.13d44d30.1817475232 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.8.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 4548 "\\.\pipe\gecko-crash-server-pipe.4548" plugin
D:\Programy\FRAPS\fraps.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"D:\Programy\FRAPS\fraps64.dat"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 544 548 556 65536 552
"D:\Programy\RSIT\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-08 49440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll [2011-08-14 270960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
CescrtHlpr Object - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll [2010-10-26 262144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-04-14 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - facemoods Toolbar - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll [2010-10-26 217088]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll [2011-08-14 237680]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-08 9642528]
"COMODO Internet Security"=D:\Programy\COMODO\COMODO Internet Security\cfp.exe [2011-09-16 9048392]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2008-04-04 120328]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-18 843776]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Java"=C:\Users\Cvach\AppData\Roaming\pervious.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"avast! Antivirus"=D:\Programy\Alwil Software\Avast5\AvastUI.exe [2011-09-06 3722416]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-03-16 2988488]
"DAEMON Tools Lite"=D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2011-08-06 3077528]
"EADM"=D:\Programy\Origin\Origin\Origin.exe [2011-11-07 28846216]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-10-13 17351304]
"RGSC"=D:\Hry\GTA IV\Rockstar Social Club\Rockstar Games Social Club\RGSCLauncher.exe [2008-12-12 306088]
"Akamai NetSession Interface"=C:\Users\Cvach\AppData\Local\Akamai\netsession_win.exe [2011-11-12 3303000]
"ICQ"=C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-04-30 119608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCU"=C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [2009-08-04 346320]
"tsnpstd3"=C:\Windows\tsnpstd3.exe [2007-06-15 368640]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"facemoods"=C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe [2010-10-26 323584]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Java"=C:\Users\Cvach\AppData\Roaming\pervious.exe []
C:\Users\Cvach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CurseClientStartup.ccip
hamachi.lnk - D:\Programy\Hamachi\hamachi.exe
Rainmeter.lnk - D:\Programy\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2010-11-20 290304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-11-13 23:34:44 ----D---- C:\rsit
2011-11-11 23:24:30 ----D---- C:\Windows\system32\Macromed
2011-11-11 23:11:01 ----N---- C:\Windows\Setup1.exe
2011-11-11 23:11:01 ----A---- C:\Windows\ST6UNST.EXE
2011-11-10 15:41:52 ----D---- C:\Program Files (x86)\Google
2011-11-09 14:17:20 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-11-09 14:17:18 ----A---- C:\Windows\system32\win32k.sys
2011-11-08 17:44:07 ----D---- C:\Users\Cvach\AppData\Roaming\Sony Creative Software Inc
2011-11-07 20:32:59 ----D---- C:\Program Files (x86)\LooksBuilder
2011-11-04 21:45:07 ----D---- C:\Users\Cvach\AppData\Roaming\Voxatron
2011-11-02 21:35:18 ----SHD---- C:\ProgramData\SecuROM
2011-11-02 21:07:11 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-10-27 17:26:17 ----A---- C:\Windows\SYSWOW64\SQSRVRES.DLL
2011-10-27 17:26:17 ----A---- C:\Windows\SYSWOW64\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll
2011-10-27 17:15:28 ----A---- C:\Windows\system32\shell32.dll
2011-10-27 17:15:26 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-10-25 23:43:19 ----D---- C:\Program Files\WMV9_VCM
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-10-24 13:39:01 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\OpenCL.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvoglv64.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcuvid.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcuda.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\nvcompiler.dll
2011-10-24 13:39:01 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-10-17 20:05:37 ----D---- C:\Users\Cvach\AppData\Roaming\LolClient
2011-10-17 19:41:40 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-10-17 19:41:40 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-10-17 19:41:36 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-10-14 23:54:52 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
======List of files/folders modified in the last 1 months======
2011-11-13 23:34:47 ----D---- C:\Program Files\trend micro
2011-11-13 23:34:46 ----D---- C:\Windows\temp
2011-11-13 23:28:17 ----D---- C:\ProgramData\PMB Files
2011-11-13 23:11:53 ----D---- C:\Users\Cvach\AppData\Roaming\Skype
2011-11-13 20:14:33 ----D---- C:\Windows\system32\Tasks
2011-11-13 20:11:57 ----D---- C:\Users\Cvach\AppData\Roaming\ICQ
2011-11-13 20:11:53 ----D---- C:\Users\Cvach\AppData\Roaming\Hamachi
2011-11-13 20:10:51 ----D---- C:\ProgramData\NVIDIA
2011-11-13 19:58:50 ----D---- C:\Windows\system32\config
2011-11-12 11:41:39 ----SHD---- C:\Windows\Installer
2011-11-12 00:43:53 ----D---- C:\Windows\system32\catroot
2011-11-12 00:43:39 ----SHD---- C:\System Volume Information
2011-11-11 23:50:05 ----D---- C:\Program Files (x86)\ICQ6Toolbar
2011-11-11 23:49:37 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-11-11 23:49:35 ----D---- C:\ProgramData\ICQ
2011-11-11 23:38:55 ----D---- C:\Windows
2011-11-11 23:24:30 ----D---- C:\Windows\System32
2011-11-11 23:11:51 ----D---- C:\Windows\SysWOW64
2011-11-11 19:53:53 ----D---- C:\ProgramData\boost_interprocess
2011-11-11 19:36:46 ----D---- C:\Users\Cvach\AppData\Roaming\Ubisoft
2011-11-11 19:35:54 ----RSD---- C:\Windows\assembly
2011-11-11 16:43:01 ----D---- C:\Users\Cvach\AppData\Roaming\Audacity
2011-11-10 23:49:14 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-11-10 16:45:11 ----D---- C:\Windows\system32\wdi
2011-11-10 15:41:58 ----D---- C:\Windows\Tasks
2011-11-10 15:41:52 ----RD---- C:\Program Files (x86)
2011-11-10 14:07:13 ----D---- C:\Windows\winsxs
2011-11-10 14:05:07 ----D---- C:\Windows\system32\drivers
2011-11-10 14:05:07 ----D---- C:\Program Files\Common Files\System
2011-11-09 22:53:23 ----A---- C:\Windows\system32\MRT.exe
2011-11-09 16:59:57 ----A---- C:\Windows\avp.ini
2011-11-09 15:23:48 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-11-09 14:17:14 ----D---- C:\Windows\system32\catroot2
2011-11-08 23:17:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-11-08 23:17:07 ----D---- C:\Windows\inf
2011-11-08 17:07:32 ----D---- C:\Users\Cvach\AppData\Roaming\Sony
2011-11-06 14:52:47 ----D---- C:\Windows\system32\drivers\etc
2011-11-05 01:43:10 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2011-11-02 21:35:18 ----D---- C:\ProgramData
2011-10-29 00:16:23 ----D---- C:\Users\Cvach\AppData\Roaming\.minecraft
2011-10-28 12:41:17 ----D---- C:\Windows\Microsoft.NET
2011-10-27 17:26:18 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-10-27 17:24:58 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-10-27 17:23:44 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2011-10-27 17:21:34 ----D---- C:\ProgramData\Microsoft Help
2011-10-27 17:18:06 ----A---- C:\Windows\win.ini
2011-10-27 17:10:25 ----D---- C:\Windows\Logs
2011-10-27 17:10:23 ----D---- C:\Program Files (x86)\Microsoft Office
2011-10-27 02:00:48 ----D---- C:\Program Files\Internet Explorer
2011-10-27 02:00:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-10-26 11:03:17 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-10-25 23:43:19 ----RD---- C:\Program Files
2011-10-24 13:40:59 ----D---- C:\Windows\system32\DriverStore
2011-10-24 13:40:26 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-10-19 20:20:50 ----RD---- C:\Program Files (x86)\Skype
2011-10-19 20:20:45 ----D---- C:\ProgramData\Skype
2011-10-19 20:20:39 ----D---- C:\Users\Cvach\AppData\Roaming\Origin
2011-10-15 09:53:00 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-10-15 09:53:00 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-10-15 09:53:00 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvvsvc.exe
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvsvcr.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvsvc64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvshext.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvmctray.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvgenco64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvdispco64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvcpl.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\nvapi64.dll
2011-10-15 09:53:00 ----A---- C:\Windows\system32\easyupdatusapiu64.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys [2006-06-14 14192]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\Windows\System32\drivers\sfvfs02.sys [2007-01-12 106360]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-12 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-09-06 42328]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-09-06 601944]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-09-06 301912]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-09-06 58200]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2011-09-16 252344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2011-09-16 41712]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2011-09-16 92688]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys [2011-01-26 30312]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-09-06 24408]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-09-06 65368]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-11-14 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-11-14 43680]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-01-29 33344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-08 2223392]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2011-07-08 174184]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\D:\Programy\TumeUp Utilites\TuneUpUtilitiesDriver64.sys [2009-10-14 11856]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
S0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\Windows\System32\drivers\sfdrv01a.sys [2006-07-05 77688]
S0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\Windows\System32\drivers\sfsync02.sys [2006-07-10 22936]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2009-07-14 60288]
S3 Avc;Zařízení AVC; C:\Windows\system32\DRIVERS\avc.sys [2009-07-14 48768]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys []
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2009-07-14 61440]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 115240]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 19496]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 158760]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 137256]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 34344]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 136744]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 151592]
S3 s125bus;Sony Ericsson Device 125 driver (WDM); C:\Windows\system32\DRIVERS\s125bus.sys [2007-04-24 108296]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s125mdfl.sys [2007-04-24 19720]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s125mdm.sys [2007-04-24 144648]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s125mgmt.sys [2007-04-24 126216]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s125obex.sys [2007-04-24 123656]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-05-02 10503168]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 vpcuxd;Služba zástupné procedury virtualizace rozhraní USB; C:\Windows\system32\drivers\vpcuxd.sys [2010-11-20 16384]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 avast! Antivirus;avast! Antivirus; D:\Programy\Alwil Software\Avast5\AvastSvc.exe [2011-09-06 44768]
R2 BCUService;Browser Configuration Utility Service; C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 cmdAgent;COMODO Internet Security Helper Service; D:\Programy\COMODO\COMODO Internet Security\cmdagent.exe [2011-09-16 2528096]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2011-09-22 43028328]
R2 mysql;mysql; D:\Programy\XAMPP\mysql\bin\mysqld.exe [2010-12-03 8133120]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1640768]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-10-26 75136]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2011-09-22 154984]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; D:\Programy\TumeUp Utilites\TuneUpUtilitiesService64.exe [2009-11-17 1353544]
R2 TunngleService;TunngleService; D:\Programy\Tungle\Tunngle\TnglCtrl.exe [2011-08-09 741224]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-10 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; D:\Hry\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 FileZilla Server;FileZilla Server FTP server; D:\Programy\XAMPP\FileZillaFTP\FileZillaServer.exe [2010-10-17 742912]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-10-29 655624]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-10 136176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-02-10 150528]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-11-03 419624]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TuneUp.Defrag;@D:\Programy\TumeUp Utilites\TuneUpDefragService.exe,-1; D:\Programy\TumeUp Utilites\TuneUpDefragService.exe [2010-10-24 607048]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-08 1255736]
S4 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
S4 msvsmon90;Visual Studio 2008 Remote Debugger; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2008-07-29 4737024]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-29 935208]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-09-22 370024]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2011-09-22 255336]
-----------------EOF-----------------
- Mc_Murphy
- VIP in memoriam
- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Podezření na vir - zpomalené PC
Zdravím. 
Dej mi minutku, hnedle se na to mrknu.

Dej mi minutku, hnedle se na to mrknu.

- Mc_Murphy
- VIP in memoriam
- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Podezření na vir - zpomalené PC






R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: 92.62.229.253 10.4.24.238
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe" /md I
O4 - HKCU\..\Run: [DAEMON Tools Lite] D:\Programy\Daemon Tools\DAEMON Tools Lite\DTLite.exe
O4 - HKLM\..\Policies\Explorer\Run: [Java] C:\Users\Cvach\AppData\Roaming\pervious.exe
O4 - HKUS\S-1-5-21-4198012068-3784662148-1576838182-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-4198012068-3784662148-1576838182-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
"Fixnout" znamená, že spustíš HJT, zvolíš možnost [Do a system scan only] a zaškrtneš čtvereček vlevo od mnou vypsaných položek. Poté klikneš na [Fix checked] a odsouhlasíš [ANO].
HJT najdeš zde: C:\Program Files\trend micro\Cvach.exe

- http://oldtimer.geekstogo.com/OTM.exe
http://oldtimer.geekstogo.com/OTM.com
http://oldtimer.geekstogo.com/OTM.scr
Do levého okna Paste Instructions for Items to be Moved zkopíruj tento script:
Kód: Vybrat vše
:Services
gupdate
gupdatem
ICQ Service
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Java"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Java"=-
:Files
C:\Users\Cvach\AppData\Roaming\pervious.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Program Files (x86)\BabylonToolbar
C:\Program Files (x86)\facemoods.com
C:\Program Files (x86)\ICQ6Toolbar
%windir%\*.tmp /s
%windir%\system32\SET*.tmp /s
%windir%\system32\*.tmp.dll /s
:Commands
[Purity]
[ResetHosts]
[EmptyTemp]
[EmptyFlash]
[ClearAllRestorePoints]
Po restartu mi sem hoď log, který najdeš v C:\_OTM\MovedFiles\


- Proveď aktualizaci virové databáze.
- V záložce Kontrolor zvol Úplná kontrola a zaškrtni všechny pevné disky, které máš na počítači.
- Předem nic nemaž!!
- MBAM mívá občas falešné detekce, proto vlož jeho log do příspěvku a počkej na posouzení!
Re: Podezření na vir - zpomalené PC
U té proxy, tam si nejsem zrovna jistý, co to dělá, ale nejsem si vědom, že bych tam něco takového úmyslně nastavovat... Co to pro mě znamená popřípadě jak to vypnu?
Tady je log z OTM, vypadá to, že MBAM bude trochu na déle, musím teď někam jít, log z MBAM dodám jak to bude možné:
All processes killed
========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
Error: No service named ICQ Service was found to stop!
Service\Driver key ICQ Service not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\Java not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\Java not found.
========== FILES ==========
File/Folder C:\Users\Cvach\AppData\Roaming\pervious.exe not found.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File/Folder C:\Program Files (x86)\BabylonToolbar not found.
C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7 folder moved successfully.
C:\Program Files (x86)\facemoods.com\facemoods folder moved successfully.
C:\Program Files (x86)\facemoods.com folder moved successfully.
C:\Program Files (x86)\ICQ6Toolbar folder moved successfully.
C:\Windows\msdownld.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5354.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7EA2.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA43C.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPFCC6.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP474D.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP5ACC.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP668F.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPAF77.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPFB05.tmp folder moved successfully.
C:\Windows\Installer\MSI79E2.tmp moved successfully.
C:\Windows\System32\tmp1BA0.tmp moved successfully.
C:\Windows\System32\tmp1BB0.tmp moved successfully.
C:\Windows\temp\Cab118.tmp moved successfully.
C:\Windows\temp\Cab1592.tmp moved successfully.
C:\Windows\temp\Cab17F4.tmp moved successfully.
C:\Windows\temp\Cab19F5.tmp moved successfully.
C:\Windows\temp\Cab1B7B.tmp moved successfully.
C:\Windows\temp\Cab1CE2.tmp moved successfully.
C:\Windows\temp\Cab1D40.tmp moved successfully.
C:\Windows\temp\Cab1D4F.tmp moved successfully.
C:\Windows\temp\Cab20E8.tmp moved successfully.
C:\Windows\temp\Cab2329.tmp moved successfully.
C:\Windows\temp\Cab2461.tmp moved successfully.
C:\Windows\temp\Cab2606.tmp moved successfully.
C:\Windows\temp\Cab2616.tmp moved successfully.
C:\Windows\temp\Cab270.tmp moved successfully.
C:\Windows\temp\Cab2809.tmp moved successfully.
C:\Windows\temp\Cab28B5.tmp moved successfully.
C:\Windows\temp\Cab2922.tmp moved successfully.
C:\Windows\temp\Cab2B92.tmp moved successfully.
C:\Windows\temp\Cab2BA1.tmp moved successfully.
C:\Windows\temp\Cab2D56.tmp moved successfully.
C:\Windows\temp\Cab2E8E.tmp moved successfully.
C:\Windows\temp\Cab3294.tmp moved successfully.
C:\Windows\temp\Cab32B.tmp moved successfully.
C:\Windows\temp\Cab3301.tmp moved successfully.
C:\Windows\temp\Cab335E.tmp moved successfully.
C:\Windows\temp\Cab3361.tmp moved successfully.
C:\Windows\temp\Cab33EF.tmp moved successfully.
C:\Windows\temp\Cab35EE.tmp moved successfully.
C:\Windows\temp\Cab3996.tmp moved successfully.
C:\Windows\temp\Cab39B5.tmp moved successfully.
C:\Windows\temp\Cab3A22.tmp moved successfully.
C:\Windows\temp\Cab3C1E.tmp moved successfully.
C:\Windows\temp\Cab3E18.tmp moved successfully.
C:\Windows\temp\Cab3E37.tmp moved successfully.
C:\Windows\temp\Cab3EC4.tmp moved successfully.
C:\Windows\temp\Cab404A.tmp moved successfully.
C:\Windows\temp\Cab405.tmp moved successfully.
C:\Windows\temp\Cab41EF.tmp moved successfully.
C:\Windows\temp\Cab449D.tmp moved successfully.
C:\Windows\temp\Cab44FB.tmp moved successfully.
C:\Windows\temp\Cab451A.tmp moved successfully.
C:\Windows\temp\Cab47B9.tmp moved successfully.
C:\Windows\temp\Cab4BDE.tmp moved successfully.
C:\Windows\temp\Cab4DE0.tmp moved successfully.
C:\Windows\temp\Cab4FD5.tmp moved successfully.
C:\Windows\temp\Cab5070.tmp moved successfully.
C:\Windows\temp\Cab5169.tmp moved successfully.
C:\Windows\temp\Cab5408.tmp moved successfully.
C:\Windows\temp\Cab55CD.tmp moved successfully.
C:\Windows\temp\Cab56EB.tmp moved successfully.
C:\Windows\temp\Cab59F1.tmp moved successfully.
C:\Windows\temp\Cab5C04.tmp moved successfully.
C:\Windows\temp\Cab5D67.tmp moved successfully.
C:\Windows\temp\Cab5E35.tmp moved successfully.
C:\Windows\temp\Cab6180.tmp moved successfully.
C:\Windows\temp\Cab621D.tmp moved successfully.
C:\Windows\temp\Cab62D2.tmp moved successfully.
C:\Windows\temp\Cab6315.tmp moved successfully.
C:\Windows\temp\Cab6363.tmp moved successfully.
C:\Windows\temp\Cab6A17.tmp moved successfully.
C:\Windows\temp\Cab6AC3.tmp moved successfully.
C:\Windows\temp\Cab6DEE.tmp moved successfully.
C:\Windows\temp\Cab6F2.tmp moved successfully.
C:\Windows\temp\Cab711.tmp moved successfully.
C:\Windows\temp\Cab72F0.tmp moved successfully.
C:\Windows\temp\Cab757D.tmp moved successfully.
C:\Windows\temp\Cab7628.tmp moved successfully.
C:\Windows\temp\Cab782B.tmp moved successfully.
C:\Windows\temp\Cab7879.tmp moved successfully.
C:\Windows\temp\Cab78C7.tmp moved successfully.
C:\Windows\temp\Cab7963.tmp moved successfully.
C:\Windows\temp\Cab817E.tmp moved successfully.
C:\Windows\temp\Cab8352.tmp moved successfully.
C:\Windows\temp\Cab8508.tmp moved successfully.
C:\Windows\temp\Cab8602.tmp moved successfully.
C:\Windows\temp\Cab87B5.tmp moved successfully.
C:\Windows\temp\Cab8B1F.tmp moved successfully.
C:\Windows\temp\Cab8CF3.tmp moved successfully.
C:\Windows\temp\Cab8EC7.tmp moved successfully.
C:\Windows\temp\Cab9185.tmp moved successfully.
C:\Windows\temp\Cab92CD.tmp moved successfully.
C:\Windows\temp\Cab9368.tmp moved successfully.
C:\Windows\temp\Cab9397.tmp moved successfully.
C:\Windows\temp\Cab95E8.tmp moved successfully.
C:\Windows\temp\Cab96B3.tmp moved successfully.
C:\Windows\temp\Cab96E1.tmp moved successfully.
C:\Windows\temp\Cab974F.tmp moved successfully.
C:\Windows\temp\Cab97DE.tmp moved successfully.
C:\Windows\temp\Cab9A99.tmp moved successfully.
C:\Windows\temp\Cab9BF0.tmp moved successfully.
C:\Windows\temp\Cab9C8C.tmp moved successfully.
C:\Windows\temp\Cab9C9C.tmp moved successfully.
C:\Windows\temp\Cab9F40.tmp moved successfully.
C:\Windows\temp\CabA12E.tmp moved successfully.
C:\Windows\temp\CabA14D.tmp moved successfully.
C:\Windows\temp\CabA18B.tmp moved successfully.
C:\Windows\temp\CabA35F.tmp moved successfully.
C:\Windows\temp\CabA497.tmp moved successfully.
C:\Windows\temp\CabA4C6.tmp moved successfully.
C:\Windows\temp\CabA534.tmp moved successfully.
C:\Windows\temp\CabA64C.tmp moved successfully.
C:\Windows\temp\CabA85F.tmp moved successfully.
C:\Windows\temp\CabA9B6.tmp moved successfully.
C:\Windows\temp\CabAA90.tmp moved successfully.
C:\Windows\temp\CabAD00.tmp moved successfully.
C:\Windows\temp\CabAD2F.tmp moved successfully.
C:\Windows\temp\CabAD8D.tmp moved successfully.
C:\Windows\temp\CabAD9C.tmp moved successfully.
C:\Windows\temp\CabADDB.tmp moved successfully.
C:\Windows\temp\CabADFA.tmp moved successfully.
C:\Windows\temp\CabAE86.tmp moved successfully.
C:\Windows\temp\CabAE9B.tmp moved successfully.
C:\Windows\temp\CabB135.tmp moved successfully.
C:\Windows\temp\CabB27C.tmp moved successfully.
C:\Windows\temp\CabB46.tmp moved successfully.
C:\Windows\temp\CabB682.tmp moved successfully.
C:\Windows\temp\CabBBB8.tmp moved successfully.
C:\Windows\temp\CabBC6C.tmp moved successfully.
C:\Windows\temp\CabC293.tmp moved successfully.
C:\Windows\temp\CabC36D.tmp moved successfully.
C:\Windows\temp\CabC3AC.tmp moved successfully.
C:\Windows\temp\CabC4B5.tmp moved successfully.
C:\Windows\temp\CabC727.tmp moved successfully.
C:\Windows\temp\CabC927.tmp moved successfully.
C:\Windows\temp\CabCADC.tmp moved successfully.
C:\Windows\temp\CabCB1B.tmp moved successfully.
C:\Windows\temp\CabCBC6.tmp moved successfully.
C:\Windows\temp\CabCFEF.tmp moved successfully.
C:\Windows\temp\CabD142.tmp moved successfully.
C:\Windows\temp\CabD1C5.tmp moved successfully.
C:\Windows\temp\CabD27A.tmp moved successfully.
C:\Windows\temp\CabD28A.tmp moved successfully.
C:\Windows\temp\CabD2B9.tmp moved successfully.
C:\Windows\temp\CabD45E.tmp moved successfully.
C:\Windows\temp\CabD6ED.tmp moved successfully.
C:\Windows\temp\CabDC98.tmp moved successfully.
C:\Windows\temp\CabDEBA.tmp moved successfully.
C:\Windows\temp\CabE11A.tmp moved successfully.
C:\Windows\temp\CabE57D.tmp moved successfully.
C:\Windows\temp\CabE6B5.tmp moved successfully.
C:\Windows\temp\CabE984.tmp moved successfully.
C:\Windows\temp\CabEACB.tmp moved successfully.
C:\Windows\temp\CabEB28.tmp moved successfully.
C:\Windows\temp\CabEF2E.tmp moved successfully.
C:\Windows\temp\CabEFD.tmp moved successfully.
C:\Windows\temp\CabEFDA.tmp moved successfully.
C:\Windows\temp\CabEFDB.tmp moved successfully.
C:\Windows\temp\CabEFE9.tmp moved successfully.
C:\Windows\temp\CabF16F.tmp moved successfully.
C:\Windows\temp\CabF3B1.tmp moved successfully.
C:\Windows\temp\CabF3C.tmp moved successfully.
C:\Windows\temp\CabF3D0.tmp moved successfully.
C:\Windows\temp\CabF44C.tmp moved successfully.
C:\Windows\temp\CabF4B.tmp moved successfully.
C:\Windows\temp\CabF4C.tmp moved successfully.
C:\Windows\temp\CabF68E.tmp moved successfully.
C:\Windows\temp\CabF787.tmp moved successfully.
C:\Windows\temp\CabF871.tmp moved successfully.
C:\Windows\temp\CabF8BA.tmp moved successfully.
C:\Windows\temp\CabF8BF.tmp moved successfully.
C:\Windows\temp\HFI4E93.tmp moved successfully.
C:\Windows\temp\HFI4F8F.tmp moved successfully.
C:\Windows\temp\IE937A3.tmp folder moved successfully.
C:\Windows\temp\RGI71.tmp moved successfully.
C:\Windows\temp\RGI8356.tmp moved successfully.
C:\Windows\temp\RGIA2BF.tmp moved successfully.
C:\Windows\temp\RGIB08D.tmp moved successfully.
C:\Windows\temp\SPL3A14.tmp moved successfully.
C:\Windows\temp\SPL3B5C.tmp moved successfully.
C:\Windows\temp\SPL3C09.tmp moved successfully.
C:\Windows\temp\SPL3CD5.tmp moved successfully.
C:\Windows\temp\SPLD7E8.tmp moved successfully.
C:\Windows\temp\SPLD837.tmp moved successfully.
C:\Windows\temp\SPLD895.tmp moved successfully.
C:\Windows\temp\SPLD932.tmp moved successfully.
C:\Windows\temp\Tar119.tmp moved successfully.
C:\Windows\temp\Tar1593.tmp moved successfully.
C:\Windows\temp\Tar17F5.tmp moved successfully.
C:\Windows\temp\Tar19F6.tmp moved successfully.
C:\Windows\temp\Tar1B7C.tmp moved successfully.
C:\Windows\temp\Tar1D02.tmp moved successfully.
C:\Windows\temp\Tar1D50.tmp moved successfully.
C:\Windows\temp\Tar1D60.tmp moved successfully.
C:\Windows\temp\Tar20F8.tmp moved successfully.
C:\Windows\temp\Tar23F5.tmp moved successfully.
C:\Windows\temp\Tar2462.tmp moved successfully.
C:\Windows\temp\Tar2617.tmp moved successfully.
C:\Windows\temp\Tar2665.tmp moved successfully.
C:\Windows\temp\Tar271.tmp moved successfully.
C:\Windows\temp\Tar2819.tmp moved successfully.
C:\Windows\temp\Tar28B6.tmp moved successfully.
C:\Windows\temp\Tar2923.tmp moved successfully.
C:\Windows\temp\Tar2B93.tmp moved successfully.
C:\Windows\temp\Tar2BB2.tmp moved successfully.
C:\Windows\temp\Tar2D57.tmp moved successfully.
C:\Windows\temp\Tar2E9F.tmp moved successfully.
C:\Windows\temp\Tar32A4.tmp moved successfully.
C:\Windows\temp\Tar3311.tmp moved successfully.
C:\Windows\temp\Tar3371.tmp moved successfully.
C:\Windows\temp\Tar338E.tmp moved successfully.
C:\Windows\temp\Tar33F0.tmp moved successfully.
C:\Windows\temp\Tar35FE.tmp moved successfully.
C:\Windows\temp\Tar389.tmp moved successfully.
C:\Windows\temp\Tar3997.tmp moved successfully.
C:\Windows\temp\Tar39D5.tmp moved successfully.
C:\Windows\temp\Tar3A42.tmp moved successfully.
C:\Windows\temp\Tar3C2E.tmp moved successfully.
C:\Windows\temp\Tar3E96.tmp moved successfully.
C:\Windows\temp\Tar3EC5.tmp moved successfully.
C:\Windows\temp\Tar3ED4.tmp moved successfully.
C:\Windows\temp\Tar40E7.tmp moved successfully.
C:\Windows\temp\Tar4200.tmp moved successfully.
C:\Windows\temp\Tar435.tmp moved successfully.
C:\Windows\temp\Tar451B.tmp moved successfully.
C:\Windows\temp\Tar4569.tmp moved successfully.
C:\Windows\temp\Tar45E6.tmp moved successfully.
C:\Windows\temp\Tar47E9.tmp moved successfully.
C:\Windows\temp\Tar4BEE.tmp moved successfully.
C:\Windows\temp\Tar4DF1.tmp moved successfully.
C:\Windows\temp\Tar5015.tmp moved successfully.
C:\Windows\temp\Tar5199.tmp moved successfully.
C:\Windows\temp\Tar51A9.tmp moved successfully.
C:\Windows\temp\Tar5409.tmp moved successfully.
C:\Windows\temp\Tar55CE.tmp moved successfully.
C:\Windows\temp\Tar570B.tmp moved successfully.
C:\Windows\temp\Tar5B78.tmp moved successfully.
C:\Windows\temp\Tar5C33.tmp moved successfully.
C:\Windows\temp\Tar5D68.tmp moved successfully.
C:\Windows\temp\Tar5F11.tmp moved successfully.
C:\Windows\temp\Tar61B0.tmp moved successfully.
C:\Windows\temp\Tar621E.tmp moved successfully.
C:\Windows\temp\Tar62F3.tmp moved successfully.
C:\Windows\temp\Tar6316.tmp moved successfully.
C:\Windows\temp\Tar63A3.tmp moved successfully.
C:\Windows\temp\Tar6AD4.tmp moved successfully.
C:\Windows\temp\Tar6AF3.tmp moved successfully.
C:\Windows\temp\Tar6DFF.tmp moved successfully.
C:\Windows\temp\Tar712.tmp moved successfully.
C:\Windows\temp\Tar72F1.tmp moved successfully.
C:\Windows\temp\Tar741.tmp moved successfully.
C:\Windows\temp\Tar761A.tmp moved successfully.
C:\Windows\temp\Tar7629.tmp moved successfully.
C:\Windows\temp\Tar78F7.tmp moved successfully.
C:\Windows\temp\Tar7916.tmp moved successfully.
C:\Windows\temp\Tar7964.tmp moved successfully.
C:\Windows\temp\Tar7A00.tmp moved successfully.
C:\Windows\temp\Tar819E.tmp moved successfully.
C:\Windows\temp\Tar8382.tmp moved successfully.
C:\Windows\temp\Tar8518.tmp moved successfully.
C:\Windows\temp\Tar8622.tmp moved successfully.
C:\Windows\temp\Tar8833.tmp moved successfully.
C:\Windows\temp\Tar8B20.tmp moved successfully.
C:\Windows\temp\Tar8D13.tmp moved successfully.
C:\Windows\temp\Tar8EC8.tmp moved successfully.
C:\Windows\temp\Tar9195.tmp moved successfully.
C:\Windows\temp\Tar92CE.tmp moved successfully.
C:\Windows\temp\Tar9388.tmp moved successfully.
C:\Windows\temp\Tar93B7.tmp moved successfully.
C:\Windows\temp\Tar95E9.tmp moved successfully.
C:\Windows\temp\Tar96B4.tmp moved successfully.
C:\Windows\temp\Tar9702.tmp moved successfully.
C:\Windows\temp\Tar9750.tmp moved successfully.
C:\Windows\temp\Tar97DF.tmp moved successfully.
C:\Windows\temp\Tar9AB9.tmp moved successfully.
C:\Windows\temp\Tar9BF1.tmp moved successfully.
C:\Windows\temp\Tar9C9D.tmp moved successfully.
C:\Windows\temp\Tar9CBC.tmp moved successfully.
C:\Windows\temp\Tar9F41.tmp moved successfully.
C:\Windows\temp\TarA12F.tmp moved successfully.
C:\Windows\temp\TarA16D.tmp moved successfully.
C:\Windows\temp\TarA18C.tmp moved successfully.
C:\Windows\temp\TarA370.tmp moved successfully.
C:\Windows\temp\TarA4A8.tmp moved successfully.
C:\Windows\temp\TarA4D7.tmp moved successfully.
C:\Windows\temp\TarA535.tmp moved successfully.
C:\Windows\temp\TarA64D.tmp moved successfully.
C:\Windows\temp\TarA860.tmp moved successfully.
C:\Windows\temp\TarA9F5.tmp moved successfully.
C:\Windows\temp\TarAB4C.tmp moved successfully.
C:\Windows\temp\TarAD01.tmp moved successfully.
C:\Windows\temp\TarAD4F.tmp moved successfully.
C:\Windows\temp\TarADAD.tmp moved successfully.
C:\Windows\temp\TarADBC.tmp moved successfully.
C:\Windows\temp\TarADDC.tmp moved successfully.
C:\Windows\temp\TarAE0B.tmp moved successfully.
C:\Windows\temp\TarAE87.tmp moved successfully.
C:\Windows\temp\TarAEAB.tmp moved successfully.
C:\Windows\temp\TarB145.tmp moved successfully.
C:\Windows\temp\TarB28D.tmp moved successfully.
C:\Windows\temp\TarB47.tmp moved successfully.
C:\Windows\temp\TarB7F9.tmp moved successfully.
C:\Windows\temp\TarBBC9.tmp moved successfully.
C:\Windows\temp\TarBC6D.tmp moved successfully.
C:\Windows\temp\TarC320.tmp moved successfully.
C:\Windows\temp\TarC39D.tmp moved successfully.
C:\Windows\temp\TarC3AD.tmp moved successfully.
C:\Windows\temp\TarC571.tmp moved successfully.
C:\Windows\temp\TarC728.tmp moved successfully.
C:\Windows\temp\TarCA8F.tmp moved successfully.
C:\Windows\temp\TarCADD.tmp moved successfully.
C:\Windows\temp\TarCB5A.tmp moved successfully.
C:\Windows\temp\TarCD7C.tmp moved successfully.
C:\Windows\temp\TarCFF0.tmp moved successfully.
C:\Windows\temp\TarD143.tmp moved successfully.
C:\Windows\temp\TarD1C6.tmp moved successfully.
C:\Windows\temp\TarD2E8.tmp moved successfully.
C:\Windows\temp\TarD3A4.tmp moved successfully.
C:\Windows\temp\TarD48E.tmp moved successfully.
C:\Windows\temp\TarD597.tmp moved successfully.
C:\Windows\temp\TarD6EE.tmp moved successfully.
C:\Windows\temp\TarDC99.tmp moved successfully.
C:\Windows\temp\TarDECB.tmp moved successfully.
C:\Windows\temp\TarE1A8.tmp moved successfully.
C:\Windows\temp\TarE59E.tmp moved successfully.
C:\Windows\temp\TarE6C6.tmp moved successfully.
C:\Windows\temp\TarE985.tmp moved successfully.
C:\Windows\temp\TarEACC.tmp moved successfully.
C:\Windows\temp\TarEE83.tmp moved successfully.
C:\Windows\temp\TarEF2F.tmp moved successfully.
C:\Windows\temp\TarEFDB.tmp moved successfully.
C:\Windows\temp\TarEFE.tmp moved successfully.
C:\Windows\temp\TarF067.tmp moved successfully.
C:\Windows\temp\TarF086.tmp moved successfully.
C:\Windows\temp\TarF180.tmp moved successfully.
C:\Windows\temp\TarF3B2.tmp moved successfully.
C:\Windows\temp\TarF3D1.tmp moved successfully.
C:\Windows\temp\TarF45D.tmp moved successfully.
C:\Windows\temp\TarF4C.tmp moved successfully.
C:\Windows\temp\TarF4D.tmp moved successfully.
C:\Windows\temp\TarF68F.tmp moved successfully.
C:\Windows\temp\TarF798.tmp moved successfully.
C:\Windows\temp\TarF8CB.tmp moved successfully.
C:\Windows\temp\TarF8D0.tmp moved successfully.
C:\Windows\temp\TarF8D1.tmp moved successfully.
C:\Windows\temp\TarFE8.tmp moved successfully.
C:\Windows\temp\TFR3CF.tmp moved successfully.
C:\Windows\temp\TFR600F.tmp moved successfully.
C:\Windows\temp\TFR7135.tmp moved successfully.
C:\Windows\temp\TFR8937.tmp moved successfully.
C:\Windows\temp\TFR9522.tmp moved successfully.
C:\Windows\temp\TFRBEA.tmp moved successfully.
C:\Windows\temp\TFRE286.tmp moved successfully.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\system32\*.tmp.dll not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Cvach
->Temp folder emptied: 1832250008 bytes
->Temporary Internet Files folder emptied: 74317023 bytes
->Java cache emptied: 11851138 bytes
->FireFox cache emptied: 50781750 bytes
->Opera cache emptied: 25935678 bytes
->Flash cache emptied: 149309 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 543514923 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50373 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 2 421,00 mb
[EMPTYFLASH]
User: All Users
User: Cvach
->Flash cache emptied: 0 bytes
User: Default
User: Default User
User: Public
User: UpdatusUser
Total Flash Files Cleaned = 0,00 mb
Restore point Set: OTM Restore Point
OTM by OldTimer - Version 3.1.19.0 log created on 11142011_150958
Files moved on Reboot...
C:\Users\Cvach\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Tady je log z OTM, vypadá to, že MBAM bude trochu na déle, musím teď někam jít, log z MBAM dodám jak to bude možné:
All processes killed
========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
Error: No service named ICQ Service was found to stop!
Service\Driver key ICQ Service not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\Java not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\Java not found.
========== FILES ==========
File/Folder C:\Users\Cvach\AppData\Roaming\pervious.exe not found.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File/Folder C:\Program Files (x86)\BabylonToolbar not found.
C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.7 folder moved successfully.
C:\Program Files (x86)\facemoods.com\facemoods folder moved successfully.
C:\Program Files (x86)\facemoods.com folder moved successfully.
C:\Program Files (x86)\ICQ6Toolbar folder moved successfully.
C:\Windows\msdownld.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5354.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7EA2.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA43C.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPFCC6.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP474D.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP5ACC.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP668F.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPAF77.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPFB05.tmp folder moved successfully.
C:\Windows\Installer\MSI79E2.tmp moved successfully.
C:\Windows\System32\tmp1BA0.tmp moved successfully.
C:\Windows\System32\tmp1BB0.tmp moved successfully.
C:\Windows\temp\Cab118.tmp moved successfully.
C:\Windows\temp\Cab1592.tmp moved successfully.
C:\Windows\temp\Cab17F4.tmp moved successfully.
C:\Windows\temp\Cab19F5.tmp moved successfully.
C:\Windows\temp\Cab1B7B.tmp moved successfully.
C:\Windows\temp\Cab1CE2.tmp moved successfully.
C:\Windows\temp\Cab1D40.tmp moved successfully.
C:\Windows\temp\Cab1D4F.tmp moved successfully.
C:\Windows\temp\Cab20E8.tmp moved successfully.
C:\Windows\temp\Cab2329.tmp moved successfully.
C:\Windows\temp\Cab2461.tmp moved successfully.
C:\Windows\temp\Cab2606.tmp moved successfully.
C:\Windows\temp\Cab2616.tmp moved successfully.
C:\Windows\temp\Cab270.tmp moved successfully.
C:\Windows\temp\Cab2809.tmp moved successfully.
C:\Windows\temp\Cab28B5.tmp moved successfully.
C:\Windows\temp\Cab2922.tmp moved successfully.
C:\Windows\temp\Cab2B92.tmp moved successfully.
C:\Windows\temp\Cab2BA1.tmp moved successfully.
C:\Windows\temp\Cab2D56.tmp moved successfully.
C:\Windows\temp\Cab2E8E.tmp moved successfully.
C:\Windows\temp\Cab3294.tmp moved successfully.
C:\Windows\temp\Cab32B.tmp moved successfully.
C:\Windows\temp\Cab3301.tmp moved successfully.
C:\Windows\temp\Cab335E.tmp moved successfully.
C:\Windows\temp\Cab3361.tmp moved successfully.
C:\Windows\temp\Cab33EF.tmp moved successfully.
C:\Windows\temp\Cab35EE.tmp moved successfully.
C:\Windows\temp\Cab3996.tmp moved successfully.
C:\Windows\temp\Cab39B5.tmp moved successfully.
C:\Windows\temp\Cab3A22.tmp moved successfully.
C:\Windows\temp\Cab3C1E.tmp moved successfully.
C:\Windows\temp\Cab3E18.tmp moved successfully.
C:\Windows\temp\Cab3E37.tmp moved successfully.
C:\Windows\temp\Cab3EC4.tmp moved successfully.
C:\Windows\temp\Cab404A.tmp moved successfully.
C:\Windows\temp\Cab405.tmp moved successfully.
C:\Windows\temp\Cab41EF.tmp moved successfully.
C:\Windows\temp\Cab449D.tmp moved successfully.
C:\Windows\temp\Cab44FB.tmp moved successfully.
C:\Windows\temp\Cab451A.tmp moved successfully.
C:\Windows\temp\Cab47B9.tmp moved successfully.
C:\Windows\temp\Cab4BDE.tmp moved successfully.
C:\Windows\temp\Cab4DE0.tmp moved successfully.
C:\Windows\temp\Cab4FD5.tmp moved successfully.
C:\Windows\temp\Cab5070.tmp moved successfully.
C:\Windows\temp\Cab5169.tmp moved successfully.
C:\Windows\temp\Cab5408.tmp moved successfully.
C:\Windows\temp\Cab55CD.tmp moved successfully.
C:\Windows\temp\Cab56EB.tmp moved successfully.
C:\Windows\temp\Cab59F1.tmp moved successfully.
C:\Windows\temp\Cab5C04.tmp moved successfully.
C:\Windows\temp\Cab5D67.tmp moved successfully.
C:\Windows\temp\Cab5E35.tmp moved successfully.
C:\Windows\temp\Cab6180.tmp moved successfully.
C:\Windows\temp\Cab621D.tmp moved successfully.
C:\Windows\temp\Cab62D2.tmp moved successfully.
C:\Windows\temp\Cab6315.tmp moved successfully.
C:\Windows\temp\Cab6363.tmp moved successfully.
C:\Windows\temp\Cab6A17.tmp moved successfully.
C:\Windows\temp\Cab6AC3.tmp moved successfully.
C:\Windows\temp\Cab6DEE.tmp moved successfully.
C:\Windows\temp\Cab6F2.tmp moved successfully.
C:\Windows\temp\Cab711.tmp moved successfully.
C:\Windows\temp\Cab72F0.tmp moved successfully.
C:\Windows\temp\Cab757D.tmp moved successfully.
C:\Windows\temp\Cab7628.tmp moved successfully.
C:\Windows\temp\Cab782B.tmp moved successfully.
C:\Windows\temp\Cab7879.tmp moved successfully.
C:\Windows\temp\Cab78C7.tmp moved successfully.
C:\Windows\temp\Cab7963.tmp moved successfully.
C:\Windows\temp\Cab817E.tmp moved successfully.
C:\Windows\temp\Cab8352.tmp moved successfully.
C:\Windows\temp\Cab8508.tmp moved successfully.
C:\Windows\temp\Cab8602.tmp moved successfully.
C:\Windows\temp\Cab87B5.tmp moved successfully.
C:\Windows\temp\Cab8B1F.tmp moved successfully.
C:\Windows\temp\Cab8CF3.tmp moved successfully.
C:\Windows\temp\Cab8EC7.tmp moved successfully.
C:\Windows\temp\Cab9185.tmp moved successfully.
C:\Windows\temp\Cab92CD.tmp moved successfully.
C:\Windows\temp\Cab9368.tmp moved successfully.
C:\Windows\temp\Cab9397.tmp moved successfully.
C:\Windows\temp\Cab95E8.tmp moved successfully.
C:\Windows\temp\Cab96B3.tmp moved successfully.
C:\Windows\temp\Cab96E1.tmp moved successfully.
C:\Windows\temp\Cab974F.tmp moved successfully.
C:\Windows\temp\Cab97DE.tmp moved successfully.
C:\Windows\temp\Cab9A99.tmp moved successfully.
C:\Windows\temp\Cab9BF0.tmp moved successfully.
C:\Windows\temp\Cab9C8C.tmp moved successfully.
C:\Windows\temp\Cab9C9C.tmp moved successfully.
C:\Windows\temp\Cab9F40.tmp moved successfully.
C:\Windows\temp\CabA12E.tmp moved successfully.
C:\Windows\temp\CabA14D.tmp moved successfully.
C:\Windows\temp\CabA18B.tmp moved successfully.
C:\Windows\temp\CabA35F.tmp moved successfully.
C:\Windows\temp\CabA497.tmp moved successfully.
C:\Windows\temp\CabA4C6.tmp moved successfully.
C:\Windows\temp\CabA534.tmp moved successfully.
C:\Windows\temp\CabA64C.tmp moved successfully.
C:\Windows\temp\CabA85F.tmp moved successfully.
C:\Windows\temp\CabA9B6.tmp moved successfully.
C:\Windows\temp\CabAA90.tmp moved successfully.
C:\Windows\temp\CabAD00.tmp moved successfully.
C:\Windows\temp\CabAD2F.tmp moved successfully.
C:\Windows\temp\CabAD8D.tmp moved successfully.
C:\Windows\temp\CabAD9C.tmp moved successfully.
C:\Windows\temp\CabADDB.tmp moved successfully.
C:\Windows\temp\CabADFA.tmp moved successfully.
C:\Windows\temp\CabAE86.tmp moved successfully.
C:\Windows\temp\CabAE9B.tmp moved successfully.
C:\Windows\temp\CabB135.tmp moved successfully.
C:\Windows\temp\CabB27C.tmp moved successfully.
C:\Windows\temp\CabB46.tmp moved successfully.
C:\Windows\temp\CabB682.tmp moved successfully.
C:\Windows\temp\CabBBB8.tmp moved successfully.
C:\Windows\temp\CabBC6C.tmp moved successfully.
C:\Windows\temp\CabC293.tmp moved successfully.
C:\Windows\temp\CabC36D.tmp moved successfully.
C:\Windows\temp\CabC3AC.tmp moved successfully.
C:\Windows\temp\CabC4B5.tmp moved successfully.
C:\Windows\temp\CabC727.tmp moved successfully.
C:\Windows\temp\CabC927.tmp moved successfully.
C:\Windows\temp\CabCADC.tmp moved successfully.
C:\Windows\temp\CabCB1B.tmp moved successfully.
C:\Windows\temp\CabCBC6.tmp moved successfully.
C:\Windows\temp\CabCFEF.tmp moved successfully.
C:\Windows\temp\CabD142.tmp moved successfully.
C:\Windows\temp\CabD1C5.tmp moved successfully.
C:\Windows\temp\CabD27A.tmp moved successfully.
C:\Windows\temp\CabD28A.tmp moved successfully.
C:\Windows\temp\CabD2B9.tmp moved successfully.
C:\Windows\temp\CabD45E.tmp moved successfully.
C:\Windows\temp\CabD6ED.tmp moved successfully.
C:\Windows\temp\CabDC98.tmp moved successfully.
C:\Windows\temp\CabDEBA.tmp moved successfully.
C:\Windows\temp\CabE11A.tmp moved successfully.
C:\Windows\temp\CabE57D.tmp moved successfully.
C:\Windows\temp\CabE6B5.tmp moved successfully.
C:\Windows\temp\CabE984.tmp moved successfully.
C:\Windows\temp\CabEACB.tmp moved successfully.
C:\Windows\temp\CabEB28.tmp moved successfully.
C:\Windows\temp\CabEF2E.tmp moved successfully.
C:\Windows\temp\CabEFD.tmp moved successfully.
C:\Windows\temp\CabEFDA.tmp moved successfully.
C:\Windows\temp\CabEFDB.tmp moved successfully.
C:\Windows\temp\CabEFE9.tmp moved successfully.
C:\Windows\temp\CabF16F.tmp moved successfully.
C:\Windows\temp\CabF3B1.tmp moved successfully.
C:\Windows\temp\CabF3C.tmp moved successfully.
C:\Windows\temp\CabF3D0.tmp moved successfully.
C:\Windows\temp\CabF44C.tmp moved successfully.
C:\Windows\temp\CabF4B.tmp moved successfully.
C:\Windows\temp\CabF4C.tmp moved successfully.
C:\Windows\temp\CabF68E.tmp moved successfully.
C:\Windows\temp\CabF787.tmp moved successfully.
C:\Windows\temp\CabF871.tmp moved successfully.
C:\Windows\temp\CabF8BA.tmp moved successfully.
C:\Windows\temp\CabF8BF.tmp moved successfully.
C:\Windows\temp\HFI4E93.tmp moved successfully.
C:\Windows\temp\HFI4F8F.tmp moved successfully.
C:\Windows\temp\IE937A3.tmp folder moved successfully.
C:\Windows\temp\RGI71.tmp moved successfully.
C:\Windows\temp\RGI8356.tmp moved successfully.
C:\Windows\temp\RGIA2BF.tmp moved successfully.
C:\Windows\temp\RGIB08D.tmp moved successfully.
C:\Windows\temp\SPL3A14.tmp moved successfully.
C:\Windows\temp\SPL3B5C.tmp moved successfully.
C:\Windows\temp\SPL3C09.tmp moved successfully.
C:\Windows\temp\SPL3CD5.tmp moved successfully.
C:\Windows\temp\SPLD7E8.tmp moved successfully.
C:\Windows\temp\SPLD837.tmp moved successfully.
C:\Windows\temp\SPLD895.tmp moved successfully.
C:\Windows\temp\SPLD932.tmp moved successfully.
C:\Windows\temp\Tar119.tmp moved successfully.
C:\Windows\temp\Tar1593.tmp moved successfully.
C:\Windows\temp\Tar17F5.tmp moved successfully.
C:\Windows\temp\Tar19F6.tmp moved successfully.
C:\Windows\temp\Tar1B7C.tmp moved successfully.
C:\Windows\temp\Tar1D02.tmp moved successfully.
C:\Windows\temp\Tar1D50.tmp moved successfully.
C:\Windows\temp\Tar1D60.tmp moved successfully.
C:\Windows\temp\Tar20F8.tmp moved successfully.
C:\Windows\temp\Tar23F5.tmp moved successfully.
C:\Windows\temp\Tar2462.tmp moved successfully.
C:\Windows\temp\Tar2617.tmp moved successfully.
C:\Windows\temp\Tar2665.tmp moved successfully.
C:\Windows\temp\Tar271.tmp moved successfully.
C:\Windows\temp\Tar2819.tmp moved successfully.
C:\Windows\temp\Tar28B6.tmp moved successfully.
C:\Windows\temp\Tar2923.tmp moved successfully.
C:\Windows\temp\Tar2B93.tmp moved successfully.
C:\Windows\temp\Tar2BB2.tmp moved successfully.
C:\Windows\temp\Tar2D57.tmp moved successfully.
C:\Windows\temp\Tar2E9F.tmp moved successfully.
C:\Windows\temp\Tar32A4.tmp moved successfully.
C:\Windows\temp\Tar3311.tmp moved successfully.
C:\Windows\temp\Tar3371.tmp moved successfully.
C:\Windows\temp\Tar338E.tmp moved successfully.
C:\Windows\temp\Tar33F0.tmp moved successfully.
C:\Windows\temp\Tar35FE.tmp moved successfully.
C:\Windows\temp\Tar389.tmp moved successfully.
C:\Windows\temp\Tar3997.tmp moved successfully.
C:\Windows\temp\Tar39D5.tmp moved successfully.
C:\Windows\temp\Tar3A42.tmp moved successfully.
C:\Windows\temp\Tar3C2E.tmp moved successfully.
C:\Windows\temp\Tar3E96.tmp moved successfully.
C:\Windows\temp\Tar3EC5.tmp moved successfully.
C:\Windows\temp\Tar3ED4.tmp moved successfully.
C:\Windows\temp\Tar40E7.tmp moved successfully.
C:\Windows\temp\Tar4200.tmp moved successfully.
C:\Windows\temp\Tar435.tmp moved successfully.
C:\Windows\temp\Tar451B.tmp moved successfully.
C:\Windows\temp\Tar4569.tmp moved successfully.
C:\Windows\temp\Tar45E6.tmp moved successfully.
C:\Windows\temp\Tar47E9.tmp moved successfully.
C:\Windows\temp\Tar4BEE.tmp moved successfully.
C:\Windows\temp\Tar4DF1.tmp moved successfully.
C:\Windows\temp\Tar5015.tmp moved successfully.
C:\Windows\temp\Tar5199.tmp moved successfully.
C:\Windows\temp\Tar51A9.tmp moved successfully.
C:\Windows\temp\Tar5409.tmp moved successfully.
C:\Windows\temp\Tar55CE.tmp moved successfully.
C:\Windows\temp\Tar570B.tmp moved successfully.
C:\Windows\temp\Tar5B78.tmp moved successfully.
C:\Windows\temp\Tar5C33.tmp moved successfully.
C:\Windows\temp\Tar5D68.tmp moved successfully.
C:\Windows\temp\Tar5F11.tmp moved successfully.
C:\Windows\temp\Tar61B0.tmp moved successfully.
C:\Windows\temp\Tar621E.tmp moved successfully.
C:\Windows\temp\Tar62F3.tmp moved successfully.
C:\Windows\temp\Tar6316.tmp moved successfully.
C:\Windows\temp\Tar63A3.tmp moved successfully.
C:\Windows\temp\Tar6AD4.tmp moved successfully.
C:\Windows\temp\Tar6AF3.tmp moved successfully.
C:\Windows\temp\Tar6DFF.tmp moved successfully.
C:\Windows\temp\Tar712.tmp moved successfully.
C:\Windows\temp\Tar72F1.tmp moved successfully.
C:\Windows\temp\Tar741.tmp moved successfully.
C:\Windows\temp\Tar761A.tmp moved successfully.
C:\Windows\temp\Tar7629.tmp moved successfully.
C:\Windows\temp\Tar78F7.tmp moved successfully.
C:\Windows\temp\Tar7916.tmp moved successfully.
C:\Windows\temp\Tar7964.tmp moved successfully.
C:\Windows\temp\Tar7A00.tmp moved successfully.
C:\Windows\temp\Tar819E.tmp moved successfully.
C:\Windows\temp\Tar8382.tmp moved successfully.
C:\Windows\temp\Tar8518.tmp moved successfully.
C:\Windows\temp\Tar8622.tmp moved successfully.
C:\Windows\temp\Tar8833.tmp moved successfully.
C:\Windows\temp\Tar8B20.tmp moved successfully.
C:\Windows\temp\Tar8D13.tmp moved successfully.
C:\Windows\temp\Tar8EC8.tmp moved successfully.
C:\Windows\temp\Tar9195.tmp moved successfully.
C:\Windows\temp\Tar92CE.tmp moved successfully.
C:\Windows\temp\Tar9388.tmp moved successfully.
C:\Windows\temp\Tar93B7.tmp moved successfully.
C:\Windows\temp\Tar95E9.tmp moved successfully.
C:\Windows\temp\Tar96B4.tmp moved successfully.
C:\Windows\temp\Tar9702.tmp moved successfully.
C:\Windows\temp\Tar9750.tmp moved successfully.
C:\Windows\temp\Tar97DF.tmp moved successfully.
C:\Windows\temp\Tar9AB9.tmp moved successfully.
C:\Windows\temp\Tar9BF1.tmp moved successfully.
C:\Windows\temp\Tar9C9D.tmp moved successfully.
C:\Windows\temp\Tar9CBC.tmp moved successfully.
C:\Windows\temp\Tar9F41.tmp moved successfully.
C:\Windows\temp\TarA12F.tmp moved successfully.
C:\Windows\temp\TarA16D.tmp moved successfully.
C:\Windows\temp\TarA18C.tmp moved successfully.
C:\Windows\temp\TarA370.tmp moved successfully.
C:\Windows\temp\TarA4A8.tmp moved successfully.
C:\Windows\temp\TarA4D7.tmp moved successfully.
C:\Windows\temp\TarA535.tmp moved successfully.
C:\Windows\temp\TarA64D.tmp moved successfully.
C:\Windows\temp\TarA860.tmp moved successfully.
C:\Windows\temp\TarA9F5.tmp moved successfully.
C:\Windows\temp\TarAB4C.tmp moved successfully.
C:\Windows\temp\TarAD01.tmp moved successfully.
C:\Windows\temp\TarAD4F.tmp moved successfully.
C:\Windows\temp\TarADAD.tmp moved successfully.
C:\Windows\temp\TarADBC.tmp moved successfully.
C:\Windows\temp\TarADDC.tmp moved successfully.
C:\Windows\temp\TarAE0B.tmp moved successfully.
C:\Windows\temp\TarAE87.tmp moved successfully.
C:\Windows\temp\TarAEAB.tmp moved successfully.
C:\Windows\temp\TarB145.tmp moved successfully.
C:\Windows\temp\TarB28D.tmp moved successfully.
C:\Windows\temp\TarB47.tmp moved successfully.
C:\Windows\temp\TarB7F9.tmp moved successfully.
C:\Windows\temp\TarBBC9.tmp moved successfully.
C:\Windows\temp\TarBC6D.tmp moved successfully.
C:\Windows\temp\TarC320.tmp moved successfully.
C:\Windows\temp\TarC39D.tmp moved successfully.
C:\Windows\temp\TarC3AD.tmp moved successfully.
C:\Windows\temp\TarC571.tmp moved successfully.
C:\Windows\temp\TarC728.tmp moved successfully.
C:\Windows\temp\TarCA8F.tmp moved successfully.
C:\Windows\temp\TarCADD.tmp moved successfully.
C:\Windows\temp\TarCB5A.tmp moved successfully.
C:\Windows\temp\TarCD7C.tmp moved successfully.
C:\Windows\temp\TarCFF0.tmp moved successfully.
C:\Windows\temp\TarD143.tmp moved successfully.
C:\Windows\temp\TarD1C6.tmp moved successfully.
C:\Windows\temp\TarD2E8.tmp moved successfully.
C:\Windows\temp\TarD3A4.tmp moved successfully.
C:\Windows\temp\TarD48E.tmp moved successfully.
C:\Windows\temp\TarD597.tmp moved successfully.
C:\Windows\temp\TarD6EE.tmp moved successfully.
C:\Windows\temp\TarDC99.tmp moved successfully.
C:\Windows\temp\TarDECB.tmp moved successfully.
C:\Windows\temp\TarE1A8.tmp moved successfully.
C:\Windows\temp\TarE59E.tmp moved successfully.
C:\Windows\temp\TarE6C6.tmp moved successfully.
C:\Windows\temp\TarE985.tmp moved successfully.
C:\Windows\temp\TarEACC.tmp moved successfully.
C:\Windows\temp\TarEE83.tmp moved successfully.
C:\Windows\temp\TarEF2F.tmp moved successfully.
C:\Windows\temp\TarEFDB.tmp moved successfully.
C:\Windows\temp\TarEFE.tmp moved successfully.
C:\Windows\temp\TarF067.tmp moved successfully.
C:\Windows\temp\TarF086.tmp moved successfully.
C:\Windows\temp\TarF180.tmp moved successfully.
C:\Windows\temp\TarF3B2.tmp moved successfully.
C:\Windows\temp\TarF3D1.tmp moved successfully.
C:\Windows\temp\TarF45D.tmp moved successfully.
C:\Windows\temp\TarF4C.tmp moved successfully.
C:\Windows\temp\TarF4D.tmp moved successfully.
C:\Windows\temp\TarF68F.tmp moved successfully.
C:\Windows\temp\TarF798.tmp moved successfully.
C:\Windows\temp\TarF8CB.tmp moved successfully.
C:\Windows\temp\TarF8D0.tmp moved successfully.
C:\Windows\temp\TarF8D1.tmp moved successfully.
C:\Windows\temp\TarFE8.tmp moved successfully.
C:\Windows\temp\TFR3CF.tmp moved successfully.
C:\Windows\temp\TFR600F.tmp moved successfully.
C:\Windows\temp\TFR7135.tmp moved successfully.
C:\Windows\temp\TFR8937.tmp moved successfully.
C:\Windows\temp\TFR9522.tmp moved successfully.
C:\Windows\temp\TFRBEA.tmp moved successfully.
C:\Windows\temp\TFRE286.tmp moved successfully.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\system32\*.tmp.dll not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Cvach
->Temp folder emptied: 1832250008 bytes
->Temporary Internet Files folder emptied: 74317023 bytes
->Java cache emptied: 11851138 bytes
->FireFox cache emptied: 50781750 bytes
->Opera cache emptied: 25935678 bytes
->Flash cache emptied: 149309 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 543514923 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50373 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 2 421,00 mb
[EMPTYFLASH]
User: All Users
User: Cvach
->Flash cache emptied: 0 bytes
User: Default
User: Default User
User: Public
User: UpdatusUser
Total Flash Files Cleaned = 0,00 mb
Restore point Set: OTM Restore Point
OTM by OldTimer - Version 3.1.19.0 log created on 11142011_150958
Files moved on Reboot...
C:\Users\Cvach\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Re: Podezření na vir - zpomalené PC
Log z MBAM:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Verze databáze: 8160
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
14.11.2011 19:20:51
mbam-log-2011-11-14 (19-20-45).txt
Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 1003226
Uplynulý čas: 1 hodin, 54 minut, 23 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 2
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 15
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDownloads (Adware.EasyDownloads) -> No action taken.
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> No action taken.
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\program files (x86)\easy downloads\uninstall.exe (Adware.EasyDownloads) -> No action taken.
c:\Users\Cvach\AppData\Roaming\Ubisoft\assassin's creed 2\ubiorbitapi_r2.dll (Trojan.Agent.CK) -> No action taken.
d:\Hry\call of duty 6 modern warfare 2\call of duty modern warfare 2\modern warfare 2\teknogods_mw2sp.exe (Backdoor.Agent.Gen) -> No action taken.
d:\Hry\Dirt 3!\SKIDROW.dll (Trojan.Downloader.H) -> No action taken.
d:\Hry\Dirt 3!\dirt.3.crack.only-skidrow\SKIDROW\SKIDROW.dll (Trojan.Downloader.H) -> No action taken.
d:\Hry\GTA IV\gta iv (gta 4), crack, návod, čeština\razor crack\launchgtaiv.exe (Risktool.Crack) -> No action taken.
d:\Media\Other\mediapluginsetup.exe (Spyware.GamePlayLabs) -> No action taken.
d:\Programy\darksteam\darksteam\darksteam.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\Launcher.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\plus login.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\preloader.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\sourcesdk.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\sony vegas\sony vegas pro 10.0a build 387\Keygen.exe (RiskWare.Tool.CK) -> No action taken.
d:\Programy\wow server\treetree 4.0.6\atree 4.0.6 13623x33\tools\4.0.6a patchers\4.0.6a patcher\wowpatcher(13623).exe (HackTool.Agent) -> No action taken.
c:\Users\Cvach\AppData\Roaming\data.dat (Stolen.Data) -> No action taken.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Verze databáze: 8160
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
14.11.2011 19:20:51
mbam-log-2011-11-14 (19-20-45).txt
Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 1003226
Uplynulý čas: 1 hodin, 54 minut, 23 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 2
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 15
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDownloads (Adware.EasyDownloads) -> No action taken.
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> No action taken.
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\program files (x86)\easy downloads\uninstall.exe (Adware.EasyDownloads) -> No action taken.
c:\Users\Cvach\AppData\Roaming\Ubisoft\assassin's creed 2\ubiorbitapi_r2.dll (Trojan.Agent.CK) -> No action taken.
d:\Hry\call of duty 6 modern warfare 2\call of duty modern warfare 2\modern warfare 2\teknogods_mw2sp.exe (Backdoor.Agent.Gen) -> No action taken.
d:\Hry\Dirt 3!\SKIDROW.dll (Trojan.Downloader.H) -> No action taken.
d:\Hry\Dirt 3!\dirt.3.crack.only-skidrow\SKIDROW\SKIDROW.dll (Trojan.Downloader.H) -> No action taken.
d:\Hry\GTA IV\gta iv (gta 4), crack, návod, čeština\razor crack\launchgtaiv.exe (Risktool.Crack) -> No action taken.
d:\Media\Other\mediapluginsetup.exe (Spyware.GamePlayLabs) -> No action taken.
d:\Programy\darksteam\darksteam\darksteam.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\Launcher.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\plus login.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\preloader.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\darksteam\darksteam\sourcesdk.exe (VirTool.DelfInject) -> No action taken.
d:\Programy\sony vegas\sony vegas pro 10.0a build 387\Keygen.exe (RiskWare.Tool.CK) -> No action taken.
d:\Programy\wow server\treetree 4.0.6\atree 4.0.6 13623x33\tools\4.0.6a patchers\4.0.6a patcher\wowpatcher(13623).exe (HackTool.Agent) -> No action taken.
c:\Users\Cvach\AppData\Roaming\data.dat (Stolen.Data) -> No action taken.
- Mc_Murphy
- VIP in memoriam
- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Podezření na vir - zpomalené PC
Tak fixni ještě tento řádek:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.232.208.116:8080
Zkontroluj Firefox, jestli nemá proxy nastavené. Mělo by to být někde zde:
Firefox > Možnosti > Možnosti > Rozšířené > Síť > Nastavení připojení > Bez proxy serveru.
Já si zatím počkám ještě na log z MBAMu.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 203.232.208.116:8080

Firefox > Možnosti > Možnosti > Rozšířené > Síť > Nastavení připojení > Bez proxy serveru.

- Mc_Murphy
- VIP in memoriam
- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Podezření na vir - zpomalené PC




Re: Podezření na vir - zpomalené PC
Tvari se dobre tak asi myslim, ze je vyreseno... Diky moc
!

- Mc_Murphy
- VIP in memoriam
- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Podezření na vir - zpomalené PC
OK, tak ještě dočistíme a máme hotovo.
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Pokud nemáš, stáhni CCleaner z tohoto odkazu.
CCleaner doporučuji používat cca jednou za týden.
... a pokud nejsou žádné dotazy, bylo by to z mé strany vše.

- Stáhni a spusť.
- Klikni na CleanUp a potvrď YES.
- Program uklidí a může (nemusí) restartovat PC.

- Stáhni a spusť.
- Klikni na Start a potvrď OK.
- Program uklidí a může (nemusí) restartovat PC.
- Po použití utilitu smaž.

- Panel čistič
- Vše nech jak je, jen dej Analyzovat a poté Spustit CCleaner.
- Panel registry
- Klikni na Hledej problémy.
- Následně na Opravit problémy - zálohu registrů doporučuji udělat, oprav všechny problémy.
- Postup opakuj, dokud nebude bez problémů - většinou cca 3x.
- Panel nástroje
- Zde můžeš odinstalovat nepotřebné programy.

... a pokud nejsou žádné dotazy, bylo by to z mé strany vše.

Re: Podezření na vir - zpomalené PC
Tak myslím, že je hotovo, tak ještě jednou děkuji mockrát a přeji hezký zbytek dne
.

- Mc_Murphy
- VIP in memoriam
- Příspěvky: 6706
- Registrován: 03 lis 2008 15:55
- Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Podezření na vir - zpomalené PC
Není vůbec zač a rádo se stalo.
Přeji také pěkný den. 

