
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
časté zatížení cpu na 99%
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
časté zatížení cpu na 99%
zdravím. mám problém s tím, že když koukám třeba na youtube nebo na nějakej online serial v jakém koliv prohlížeči, tak se po chvilce začne sekat. proces prohlížeče vyleze na vysokou hodnotu. po nějaké době zase nachviličku vše funguje a hned je to zase jeden velkej zásek. nainstaloval jsem si jendu starší hru a u ní to dělá taky. řekl bych že to postupem času čím dál víc narůsta. diky za pomoc.
(svchost.exe má často víc jak 70-100mbram zabráno)
Logfile of random's system information tool 1.09 (written by random/random)
Run by w0lF1-NTB at 2011-11-28 00:23:08
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (19%) free of 16 GB
Total RAM: 511 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:23:11, on 28.11.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acer\Notebook Manager\almxptray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\Saitek\Software\ProfilerU.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
D:\RSIT.exe
C:\Program Files\trend micro\w0lF1-NTB.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook Manager\almxptray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\CplBBQ12.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
O4 - HKCU\..\Run: [AnVir Task Manager Pro] "C:\Program Files\AnVir Task Manager Pro\AnVir.exe" Minimized
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: RailNotification - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
--
End of file - 7554 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1123561945-1177238915-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1123561945-1177238915-1004UA.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\w0lF1-NTB\Data aplikací\Mozilla\Firefox\Profiles\1ux069zw.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, jqs@sun.com:1.0, {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.3"
prefs.js - "keyword.URL" - "http://start.facemoods.com/results.php?f=5&a=tweak&q="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
fcmdSrchtweak.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AcerNotebookManager"=C:\Program Files\Acer\Notebook Manager\almxptray.exe [2003-02-16 504832]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2001-09-04 28672]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2003-06-25 335872]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2003-01-07 46592]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-01-09 126976]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-01-09 581632]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2003-01-21 87751]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2007-02-16 149024]
"LManager"=C:\Program Files\Launch Manager\CplBBQ12.EXE [2003-02-07 180224]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-04-09 2029640]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"SNPSTD2"=C:\WINDOWS\vsnpstd2.exe [2004-06-10 286720]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2011-11-18 98304]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"Profiler"=C:\Program Files\Saitek\Software\ProfilerU.exe [2005-08-30 163840]
"SaiMfd"=C:\Program Files\Saitek\Software\SaiMfd.exe [2005-09-09 126976]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"AGEIA PhysX SysTray"=C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe [2007-07-23 345640]
"AnVir Task Manager Pro"=C:\Program Files\AnVir Task Manager Pro\AnVir.exe [2008-01-26 1808896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2007-02-19 1962896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop]
C:\Documents and Settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe [2011-08-04 1042944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\facemoods]
C:\Program Files\facemoods.com\facemoods\1.4.17.1\facemoodssrv.exe /md I []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\w0lF1-NTB\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-09-15 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe [2011-09-08 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2007-02-19 1188456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-06-12 399736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VVSN]
C:\Program Files\VVSN\VVSN.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Aktualizovat ESET licenci.lnk]
C:\PROGRA~1\ESET\MINODL~1\MINODL~1.EXE [2011-04-10 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BlueSoleil.lnk]
C:\PROGRA~1\IVTCOR~1\BLUESO~1\gprs.exe [2008-03-19 43608]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RailNotification]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2010-01-14 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2010-01-14 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Steam\steamapps\gottsteinpetr\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\gottsteinpetr\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UT3.exe"="C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UT3.exe:*:Enabled:Unreal_Tournament_1"
"C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealFrontend.exe"="C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealFrontend.exe:*:Enabled:Unreal_Tournament_2"
"C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealConsole.exe"="C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealConsole.exe:*:Enabled:Unreal_Tournament_3"
"D:\Program Files\EA Games\Command and Conquer Generals\game.dat"="D:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
"D:\zaloha C\Program Files\Miranda IM\miranda32.exe"="D:\zaloha C\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-11-28 00:23:08 ----D---- C:\rsit
2011-11-28 00:23:08 ----D---- C:\Program Files\trend micro
2011-11-28 00:02:15 ----D---- C:\Program Files\FLV Player
2011-11-27 22:24:31 ----D---- C:\Program Files\AnVir Task Manager Pro
2011-11-27 22:02:33 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-11-27 22:02:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-27 13:58:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-11-27 13:51:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-11-27 13:51:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-11-27 13:51:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-11-27 13:51:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2011-11-27 13:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2483614$
2011-11-27 13:50:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-11-27 13:50:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2011-11-27 13:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-11-27 13:45:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-11-27 13:45:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-11-27 13:42:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2011-11-27 13:42:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-11-27 13:42:43 ----A---- C:\WINDOWS\system32\wmpns.dll
2011-11-27 13:42:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-11-27 13:42:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-11-27 13:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-11-27 13:40:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-11-27 13:40:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-11-27 13:40:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-11-27 13:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-11-27 13:39:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-11-27 13:39:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-11-27 13:38:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-11-27 13:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-11-27 13:38:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2011-11-27 13:38:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-11-27 13:38:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2011-11-27 13:33:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-11-27 13:32:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2011-11-27 13:32:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2011-11-27 13:32:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-11-27 13:32:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-11-27 13:32:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-11-27 13:31:44 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-11-27 13:31:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-11-27 13:27:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-11-27 13:27:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-11-27 13:27:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-11-27 13:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2011-11-27 13:27:24 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-11-27 13:27:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-11-27 13:27:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-11-27 13:26:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-11-27 13:26:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-11-27 13:26:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-11-27 13:26:05 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-11-27 13:25:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-11-27 13:25:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-11-27 13:24:21 ----D---- C:\WINDOWS\SxsCaPendDel
2011-11-27 13:23:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-11-27 13:23:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-11-27 13:22:53 ----D---- C:\WINDOWS\ie8updates
2011-11-27 13:22:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-11-27 13:22:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-11-27 13:22:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-11-27 13:22:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
2011-11-27 13:22:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-11-27 12:10:41 ----D---- C:\Program Files\CCleaner
2011-11-27 12:06:49 ----D---- C:\WINDOWS\system32\appmgmt
2011-11-27 11:56:50 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Malwarebytes
2011-11-27 11:56:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-11-27 09:30:48 ----D---- C:\Program Files\Common Files\Adobe
2011-11-27 09:30:48 ----D---- C:\Program Files\Adobe
2011-11-27 09:22:08 ----D---- C:\Program Files\Common Files\Java
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaws.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaw.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\java.exe
2011-11-26 23:03:03 ----D---- C:\Program Files\Eidos Interactive
2011-11-26 22:11:03 ----RA---- C:\WINDOWS\system32\drivers\SaiMini.sys
2011-11-26 22:10:06 ----A---- C:\WINDOWS\system32\nY.exe
2011-11-26 22:10:05 ----A---- C:\WINDOWS\system32\SAIKICK.dll
2011-11-26 22:09:44 ----D---- C:\Program Files\Saitek
2011-11-26 22:09:29 ----RA---- C:\WINDOWS\system32\drivers\SaiBus.sys
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiD80C0.Dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_10.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0C.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0A.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_09.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_07.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0402.dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\SaiC80C0.Dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\drivers\SaiH80C0.sys
2011-11-24 07:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-11-20 10:05:05 ----D---- C:\Program Files\Common Files\Logitech
2011-11-20 10:05:03 ----D---- C:\Program Files\Logitech
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\ptpusb.dll
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2011-11-18 21:22:20 ----A---- C:\WINDOWS\system32\ptpusd.dll
2011-11-18 17:06:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Nikon
2011-11-18 17:06:42 ----A---- C:\WINDOWS\system32\msvcp71d.dll
2011-11-18 17:06:41 ----A---- C:\WINDOWS\system32\mfc71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr70.dll
2011-11-18 17:06:39 ----A---- C:\WINDOWS\system32\msvcp70.dll
2011-11-18 17:06:38 ----A---- C:\WINDOWS\system32\mfc70.dll
2011-11-18 17:06:37 ----RA---- C:\WINDOWS\system32\NkNEFPlugin.dll
2011-11-18 17:06:36 ----N---- C:\WINDOWS\system32\ATL71.DLL
2011-11-18 17:05:59 ----RA---- C:\WINDOWS\system32\Strato4.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RedEye.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RCSigProc.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn20.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn1120.dll
2011-11-18 17:05:57 ----RA---- C:\WINDOWS\system32\picn1020.dll
2011-11-18 17:05:56 ----RA---- C:\WINDOWS\system32\DRAGNKL1.dll
2011-11-18 17:05:47 ----D---- C:\Program Files\Common Files\muvee Technologies
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\PCDLIB32.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFTIF12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPSD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPNG12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCX12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCT12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFFAX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTKRN12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTIMG12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTFIL12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTEFX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTDIS12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFCMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFBMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC265.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC120V15_32.DLL
2011-11-18 17:04:25 ----D---- C:\Program Files\Nikon
2011-11-18 17:02:59 ----A---- C:\WINDOWS\unvise32qt.exe
2011-11-18 17:02:32 ----D---- C:\WINDOWS\system32\QuickTime
2011-11-18 17:02:31 ----D---- C:\Program Files\QuickTime
2011-11-18 17:02:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\QuickTime
2011-11-18 16:57:57 ----D---- C:\Program Files\Common Files\Nikon
2011-11-11 21:52:28 ----D---- C:\Program Files\directx
2011-11-11 21:51:26 ----D---- C:\Program Files\Rockstar Games
2011-11-11 20:55:17 ----D---- C:\WINDOWS\system32\Adobe
2011-11-11 19:41:24 ----D---- C:\WINDOWS\system32\LogFiles
2011-11-07 23:00:19 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-11-07 23:00:17 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-11-07 23:00:16 ----D---- C:\Program Files\PDFCreator
2011-11-07 22:56:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alibre Design
2011-11-07 22:54:15 ----D---- C:\Program Files\Alibre Design
2011-11-07 22:32:18 ----A---- C:\WINDOWS\WDIRECT.INI
2011-11-06 22:51:55 ----D---- C:\Program Files\DOSBox-0.74
======List of files/folders modified in the last 1 month======
2011-11-28 00:23:08 ----RD---- C:\Program Files
2011-11-28 00:23:08 ----D---- C:\WINDOWS\Temp
2011-11-28 00:22:46 ----D---- C:\WINDOWS\Prefetch
2011-11-27 23:55:52 ----D---- C:\WINDOWS
2011-11-27 23:55:51 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-27 23:55:47 ----SHD---- C:\WINDOWS\Installer
2011-11-27 23:32:04 ----D---- C:\WINDOWS\system32
2011-11-27 23:32:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-11-27 22:55:06 ----D---- C:\WINDOWS\system32\drivers
2011-11-27 22:37:27 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-11-27 15:09:17 ----D---- C:\WINDOWS\Microsoft.NET
2011-11-27 14:38:29 ----SH---- C:\boot.ini
2011-11-27 14:38:29 ----A---- C:\WINDOWS\win.ini
2011-11-27 14:38:29 ----A---- C:\WINDOWS\system.ini
2011-11-27 14:06:53 ----RSD---- C:\WINDOWS\assembly
2011-11-27 14:03:10 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\uTorrent
2011-11-27 14:01:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-27 13:59:00 ----HD---- C:\WINDOWS\inf
2011-11-27 13:57:50 ----D---- C:\WINDOWS\WinSxS
2011-11-27 13:51:50 ----HD---- C:\WINDOWS\$hf_mig$
2011-11-27 13:42:12 ----D---- C:\Program Files\Microsoft ActiveSync
2011-11-27 13:40:56 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-27 13:32:27 ----D---- C:\Program Files\Internet Explorer
2011-11-27 13:25:37 ----D---- C:\Program Files\Outlook Express
2011-11-27 13:24:50 ----D---- C:\WINDOWS\system32\URTTemp
2011-11-27 12:13:42 ----D---- C:\Program Files\Steam
2011-11-27 12:13:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\DAEMON Tools Lite
2011-11-27 12:13:34 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Skype
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Minidump
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Logs
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Debug
2011-11-27 12:06:47 ----RD---- C:\Program Files\Skype
2011-11-27 12:06:15 ----D---- C:\Casino
2011-11-27 11:54:41 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-11-27 11:54:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-11-27 09:30:36 ----D---- C:\Program Files\Common Files
2011-11-27 09:30:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-11-27 09:21:42 ----D---- C:\Program Files\Java
2011-11-26 22:09:43 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-22 22:00:47 ----D---- C:\WINDOWS\system32\Restore
2011-11-22 21:14:13 ----A---- C:\WINDOWS\NeroDigital.ini
2011-11-18 17:06:37 ----RSD---- C:\WINDOWS\Fonts
2011-11-12 07:55:45 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\System32\Drivers\vbtenum.sys [2007-03-05 20880]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [2007-03-05 35600]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2010-01-14 61824]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-10-30 114048]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2010-10-30 392320]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-02-13 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-04-09 55768]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 acernbm;acernbm; C:\WINDOWS\system32\drivers\acernbm.sys [2003-01-13 6538]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-04-09 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-04-09 133000]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-10-30 32768]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2003-01-21 1164576]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-01-10 695852]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2010-01-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2003-06-25 587264]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-06-24 34312]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-06-24 27656]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2003-01-16 16256]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-04-09 33096]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2010-01-14 61824]
R3 PRISM;Wistron NeWeb 802.11b Wireless LAN PCI Card Driver; C:\WINDOWS\system32\DRIVERS\EM9NDS.sys [2002-05-31 51200]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-04-14 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 SaiMini;SaiMini; C:\WINDOWS\system32\DRIVERS\SaiMini.sys [2005-09-09 13824]
R3 SaiNtBus;SaiNtBus; C:\WINDOWS\system32\drivers\SaiBus.sys [2005-09-09 35200]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2003-01-09 266768]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2010-01-14 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver; C:\WINDOWS\System32\Drivers\WBMS.SYS [2002-11-07 30208]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver; C:\WINDOWS\System32\Drivers\WBSD.SYS [2002-11-28 25600]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2010-04-27 22856]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2010-04-27 15048]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2010-04-27 66632]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-06-24 38920]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Packet;Packet Protocol Driver; \??\C:\WINDOWS\system32\packet.sys []
S3 SaiH80C0;SaiH80C0; C:\WINDOWS\system32\DRIVERS\SaiH80C0.sys [2005-09-12 176384]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 snpstd2;VideoCAM Look; C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-07-28 334080]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2010-04-27 37704]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2010-04-27 31816]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2007-02-16 411168]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2003-06-25 294912]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [2008-03-19 166520]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
R2 Start BT in service;Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2008-03-19 51816]
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-04-09 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
(svchost.exe má často víc jak 70-100mbram zabráno)
Logfile of random's system information tool 1.09 (written by random/random)
Run by w0lF1-NTB at 2011-11-28 00:23:08
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (19%) free of 16 GB
Total RAM: 511 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:23:11, on 28.11.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acer\Notebook Manager\almxptray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\Saitek\Software\ProfilerU.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
D:\RSIT.exe
C:\Program Files\trend micro\w0lF1-NTB.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook Manager\almxptray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\CplBBQ12.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
O4 - HKCU\..\Run: [AnVir Task Manager Pro] "C:\Program Files\AnVir Task Manager Pro\AnVir.exe" Minimized
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: RailNotification - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
--
End of file - 7554 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1123561945-1177238915-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1123561945-1177238915-1004UA.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\w0lF1-NTB\Data aplikací\Mozilla\Firefox\Profiles\1ux069zw.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, jqs@sun.com:1.0, {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.3"
prefs.js - "keyword.URL" - "http://start.facemoods.com/results.php?f=5&a=tweak&q="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
fcmdSrchtweak.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AcerNotebookManager"=C:\Program Files\Acer\Notebook Manager\almxptray.exe [2003-02-16 504832]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2001-09-04 28672]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2003-06-25 335872]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2003-01-07 46592]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-01-09 126976]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-01-09 581632]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2003-01-21 87751]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2007-02-16 149024]
"LManager"=C:\Program Files\Launch Manager\CplBBQ12.EXE [2003-02-07 180224]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-04-09 2029640]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"SNPSTD2"=C:\WINDOWS\vsnpstd2.exe [2004-06-10 286720]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2011-11-18 98304]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"Profiler"=C:\Program Files\Saitek\Software\ProfilerU.exe [2005-08-30 163840]
"SaiMfd"=C:\Program Files\Saitek\Software\SaiMfd.exe [2005-09-09 126976]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"AGEIA PhysX SysTray"=C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe [2007-07-23 345640]
"AnVir Task Manager Pro"=C:\Program Files\AnVir Task Manager Pro\AnVir.exe [2008-01-26 1808896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2007-02-19 1962896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop]
C:\Documents and Settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe [2011-08-04 1042944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\facemoods]
C:\Program Files\facemoods.com\facemoods\1.4.17.1\facemoodssrv.exe /md I []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\w0lF1-NTB\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-09-15 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe [2011-09-08 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2007-02-19 1188456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-06-12 399736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VVSN]
C:\Program Files\VVSN\VVSN.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Aktualizovat ESET licenci.lnk]
C:\PROGRA~1\ESET\MINODL~1\MINODL~1.EXE [2011-04-10 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BlueSoleil.lnk]
C:\PROGRA~1\IVTCOR~1\BLUESO~1\gprs.exe [2008-03-19 43608]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RailNotification]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2010-01-14 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2010-01-14 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Steam\steamapps\gottsteinpetr\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\gottsteinpetr\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UT3.exe"="C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UT3.exe:*:Enabled:Unreal_Tournament_1"
"C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealFrontend.exe"="C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealFrontend.exe:*:Enabled:Unreal_Tournament_2"
"C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealConsole.exe"="C:\Documents and Settings\w0lF1-NTB\Games\Unreal Tournament 3\Binaries\UnrealConsole.exe:*:Enabled:Unreal_Tournament_3"
"D:\Program Files\EA Games\Command and Conquer Generals\game.dat"="D:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
"D:\zaloha C\Program Files\Miranda IM\miranda32.exe"="D:\zaloha C\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-11-28 00:23:08 ----D---- C:\rsit
2011-11-28 00:23:08 ----D---- C:\Program Files\trend micro
2011-11-28 00:02:15 ----D---- C:\Program Files\FLV Player
2011-11-27 22:24:31 ----D---- C:\Program Files\AnVir Task Manager Pro
2011-11-27 22:02:33 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-11-27 22:02:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-27 13:58:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-11-27 13:51:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-11-27 13:51:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-11-27 13:51:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-11-27 13:51:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2011-11-27 13:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2483614$
2011-11-27 13:50:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-11-27 13:50:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2011-11-27 13:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-11-27 13:45:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-11-27 13:45:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-11-27 13:42:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2011-11-27 13:42:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-11-27 13:42:43 ----A---- C:\WINDOWS\system32\wmpns.dll
2011-11-27 13:42:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-11-27 13:42:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-11-27 13:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-11-27 13:40:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-11-27 13:40:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-11-27 13:40:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-11-27 13:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-11-27 13:39:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-11-27 13:39:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-11-27 13:38:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-11-27 13:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-11-27 13:38:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2011-11-27 13:38:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-11-27 13:38:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2011-11-27 13:33:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-11-27 13:32:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2011-11-27 13:32:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2011-11-27 13:32:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-11-27 13:32:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-11-27 13:32:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-11-27 13:31:44 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-11-27 13:31:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-11-27 13:27:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-11-27 13:27:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-11-27 13:27:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-11-27 13:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2011-11-27 13:27:24 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-11-27 13:27:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-11-27 13:27:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-11-27 13:26:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-11-27 13:26:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-11-27 13:26:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-11-27 13:26:05 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-11-27 13:25:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-11-27 13:25:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-11-27 13:24:21 ----D---- C:\WINDOWS\SxsCaPendDel
2011-11-27 13:23:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-11-27 13:23:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-11-27 13:22:53 ----D---- C:\WINDOWS\ie8updates
2011-11-27 13:22:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-11-27 13:22:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-11-27 13:22:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-11-27 13:22:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
2011-11-27 13:22:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-11-27 12:10:41 ----D---- C:\Program Files\CCleaner
2011-11-27 12:06:49 ----D---- C:\WINDOWS\system32\appmgmt
2011-11-27 11:56:50 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Malwarebytes
2011-11-27 11:56:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-11-27 09:30:48 ----D---- C:\Program Files\Common Files\Adobe
2011-11-27 09:30:48 ----D---- C:\Program Files\Adobe
2011-11-27 09:22:08 ----D---- C:\Program Files\Common Files\Java
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaws.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaw.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\java.exe
2011-11-26 23:03:03 ----D---- C:\Program Files\Eidos Interactive
2011-11-26 22:11:03 ----RA---- C:\WINDOWS\system32\drivers\SaiMini.sys
2011-11-26 22:10:06 ----A---- C:\WINDOWS\system32\nY.exe
2011-11-26 22:10:05 ----A---- C:\WINDOWS\system32\SAIKICK.dll
2011-11-26 22:09:44 ----D---- C:\Program Files\Saitek
2011-11-26 22:09:29 ----RA---- C:\WINDOWS\system32\drivers\SaiBus.sys
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiD80C0.Dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_10.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0C.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0A.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_09.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_07.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0402.dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\SaiC80C0.Dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\drivers\SaiH80C0.sys
2011-11-24 07:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-11-20 10:05:05 ----D---- C:\Program Files\Common Files\Logitech
2011-11-20 10:05:03 ----D---- C:\Program Files\Logitech
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\ptpusb.dll
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2011-11-18 21:22:20 ----A---- C:\WINDOWS\system32\ptpusd.dll
2011-11-18 17:06:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Nikon
2011-11-18 17:06:42 ----A---- C:\WINDOWS\system32\msvcp71d.dll
2011-11-18 17:06:41 ----A---- C:\WINDOWS\system32\mfc71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr70.dll
2011-11-18 17:06:39 ----A---- C:\WINDOWS\system32\msvcp70.dll
2011-11-18 17:06:38 ----A---- C:\WINDOWS\system32\mfc70.dll
2011-11-18 17:06:37 ----RA---- C:\WINDOWS\system32\NkNEFPlugin.dll
2011-11-18 17:06:36 ----N---- C:\WINDOWS\system32\ATL71.DLL
2011-11-18 17:05:59 ----RA---- C:\WINDOWS\system32\Strato4.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RedEye.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RCSigProc.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn20.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn1120.dll
2011-11-18 17:05:57 ----RA---- C:\WINDOWS\system32\picn1020.dll
2011-11-18 17:05:56 ----RA---- C:\WINDOWS\system32\DRAGNKL1.dll
2011-11-18 17:05:47 ----D---- C:\Program Files\Common Files\muvee Technologies
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\PCDLIB32.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFTIF12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPSD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPNG12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCX12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCT12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFFAX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTKRN12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTIMG12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTFIL12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTEFX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTDIS12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFCMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFBMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC265.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC120V15_32.DLL
2011-11-18 17:04:25 ----D---- C:\Program Files\Nikon
2011-11-18 17:02:59 ----A---- C:\WINDOWS\unvise32qt.exe
2011-11-18 17:02:32 ----D---- C:\WINDOWS\system32\QuickTime
2011-11-18 17:02:31 ----D---- C:\Program Files\QuickTime
2011-11-18 17:02:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\QuickTime
2011-11-18 16:57:57 ----D---- C:\Program Files\Common Files\Nikon
2011-11-11 21:52:28 ----D---- C:\Program Files\directx
2011-11-11 21:51:26 ----D---- C:\Program Files\Rockstar Games
2011-11-11 20:55:17 ----D---- C:\WINDOWS\system32\Adobe
2011-11-11 19:41:24 ----D---- C:\WINDOWS\system32\LogFiles
2011-11-07 23:00:19 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-11-07 23:00:17 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-11-07 23:00:16 ----D---- C:\Program Files\PDFCreator
2011-11-07 22:56:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alibre Design
2011-11-07 22:54:15 ----D---- C:\Program Files\Alibre Design
2011-11-07 22:32:18 ----A---- C:\WINDOWS\WDIRECT.INI
2011-11-06 22:51:55 ----D---- C:\Program Files\DOSBox-0.74
======List of files/folders modified in the last 1 month======
2011-11-28 00:23:08 ----RD---- C:\Program Files
2011-11-28 00:23:08 ----D---- C:\WINDOWS\Temp
2011-11-28 00:22:46 ----D---- C:\WINDOWS\Prefetch
2011-11-27 23:55:52 ----D---- C:\WINDOWS
2011-11-27 23:55:51 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-27 23:55:47 ----SHD---- C:\WINDOWS\Installer
2011-11-27 23:32:04 ----D---- C:\WINDOWS\system32
2011-11-27 23:32:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-11-27 22:55:06 ----D---- C:\WINDOWS\system32\drivers
2011-11-27 22:37:27 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-11-27 15:09:17 ----D---- C:\WINDOWS\Microsoft.NET
2011-11-27 14:38:29 ----SH---- C:\boot.ini
2011-11-27 14:38:29 ----A---- C:\WINDOWS\win.ini
2011-11-27 14:38:29 ----A---- C:\WINDOWS\system.ini
2011-11-27 14:06:53 ----RSD---- C:\WINDOWS\assembly
2011-11-27 14:03:10 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\uTorrent
2011-11-27 14:01:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-27 13:59:00 ----HD---- C:\WINDOWS\inf
2011-11-27 13:57:50 ----D---- C:\WINDOWS\WinSxS
2011-11-27 13:51:50 ----HD---- C:\WINDOWS\$hf_mig$
2011-11-27 13:42:12 ----D---- C:\Program Files\Microsoft ActiveSync
2011-11-27 13:40:56 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-27 13:32:27 ----D---- C:\Program Files\Internet Explorer
2011-11-27 13:25:37 ----D---- C:\Program Files\Outlook Express
2011-11-27 13:24:50 ----D---- C:\WINDOWS\system32\URTTemp
2011-11-27 12:13:42 ----D---- C:\Program Files\Steam
2011-11-27 12:13:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\DAEMON Tools Lite
2011-11-27 12:13:34 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Skype
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Minidump
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Logs
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Debug
2011-11-27 12:06:47 ----RD---- C:\Program Files\Skype
2011-11-27 12:06:15 ----D---- C:\Casino
2011-11-27 11:54:41 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-11-27 11:54:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-11-27 09:30:36 ----D---- C:\Program Files\Common Files
2011-11-27 09:30:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-11-27 09:21:42 ----D---- C:\Program Files\Java
2011-11-26 22:09:43 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-22 22:00:47 ----D---- C:\WINDOWS\system32\Restore
2011-11-22 21:14:13 ----A---- C:\WINDOWS\NeroDigital.ini
2011-11-18 17:06:37 ----RSD---- C:\WINDOWS\Fonts
2011-11-12 07:55:45 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\System32\Drivers\vbtenum.sys [2007-03-05 20880]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [2007-03-05 35600]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2010-01-14 61824]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-10-30 114048]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2010-10-30 392320]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-02-13 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-04-09 55768]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 acernbm;acernbm; C:\WINDOWS\system32\drivers\acernbm.sys [2003-01-13 6538]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-04-09 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-04-09 133000]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-10-30 32768]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2003-01-21 1164576]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-01-10 695852]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2010-01-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2003-06-25 587264]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-06-24 34312]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-06-24 27656]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2003-01-16 16256]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-04-09 33096]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2010-01-14 61824]
R3 PRISM;Wistron NeWeb 802.11b Wireless LAN PCI Card Driver; C:\WINDOWS\system32\DRIVERS\EM9NDS.sys [2002-05-31 51200]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-04-14 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 SaiMini;SaiMini; C:\WINDOWS\system32\DRIVERS\SaiMini.sys [2005-09-09 13824]
R3 SaiNtBus;SaiNtBus; C:\WINDOWS\system32\drivers\SaiBus.sys [2005-09-09 35200]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2003-01-09 266768]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2010-01-14 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver; C:\WINDOWS\System32\Drivers\WBMS.SYS [2002-11-07 30208]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver; C:\WINDOWS\System32\Drivers\WBSD.SYS [2002-11-28 25600]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2010-04-27 22856]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2010-04-27 15048]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2010-04-27 66632]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-06-24 38920]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Packet;Packet Protocol Driver; \??\C:\WINDOWS\system32\packet.sys []
S3 SaiH80C0;SaiH80C0; C:\WINDOWS\system32\DRIVERS\SaiH80C0.sys [2005-09-12 176384]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 snpstd2;VideoCAM Look; C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-07-28 334080]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2010-04-27 37704]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2010-04-27 31816]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2007-02-16 411168]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2003-06-25 294912]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [2008-03-19 166520]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
R2 Start BT in service;Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2008-03-19 51816]
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-04-09 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Re: časté zatížení cpu na 99%
ahoj,
stiahni a uloz na plochu ComboFix
potom spust pod uctom s administratorskym opravnenim
akcia trva cca. 5-10 minut, niekedy i dlhsie -, Pocas scanu nespustaj ziadne ine aplikacie
Nie je dovod na paniku ak stroj bude restartovany
upozornenie: ak pouzivas antispyware s rezidentnim stitem, ten pred scanom vypni.
po restarte aplikacie vytvori log, ulozeny na C:\Combofix.txt (jeho obsah vloz sem)
stiahni a uloz na plochu ComboFix
potom spust pod uctom s administratorskym opravnenim
akcia trva cca. 5-10 minut, niekedy i dlhsie -, Pocas scanu nespustaj ziadne ine aplikacie
Nie je dovod na paniku ak stroj bude restartovany
upozornenie: ak pouzivas antispyware s rezidentnim stitem, ten pred scanom vypni.
po restarte aplikacie vytvori log, ulozeny na C:\Combofix.txt (jeho obsah vloz sem)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: časté zatížení cpu na 99%
tady je log z combo.. docela mi dalo zabrat vypnout NOD /nakonec sem ho musel odinstalovat pač to prostě jinak nešlo/
ComboFix 11-11-28.02 - w0lF1-NTB 28.11.2011 15:00:11.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.168 [GMT 1:00]
Spuštěný z: c:\documents and settings\w0lF1-NTB\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\AnVir Task Manager Pro\AnVIr.exe
c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin2.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin3.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin4.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin5.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin6.dll
c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll
c:\program files\QuickTime\Plugins\npqtplugin2.dll
c:\program files\QuickTime\Plugins\npqtplugin3.dll
c:\program files\QuickTime\Plugins\npqtplugin4.dll
c:\program files\QuickTime\Plugins\npqtplugin5.dll
c:\program files\QuickTime\Plugins\npqtplugin6.dll
c:\program files\QuickTime\Plugins\npqtplugin7.dll
c:\windows\iun6002.exe
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-28 do 2011-11-28 )))))))))))))))))))))))))))))))
.
.
2011-11-27 23:23 . 2011-11-27 23:23 -------- d-----w- C:\rsit
2011-11-27 23:23 . 2011-11-27 23:23 -------- d-----w- c:\program files\trend micro
2011-11-27 23:02 . 2011-11-27 23:02 -------- d-----w- c:\program files\FLV Player
2011-11-27 21:24 . 2011-11-28 14:07 -------- d-----w- c:\program files\AnVir Task Manager Pro
2011-11-27 21:24 . 2011-11-28 13:20 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\AnVir
2011-11-27 21:02 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-27 21:02 . 2011-11-27 21:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-27 12:42 . 2008-04-14 11:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-11-27 12:24 . 2011-11-27 13:01 -------- d-----w- c:\windows\SxsCaPendDel
2011-11-27 12:22 . 2011-11-27 12:32 -------- d-----w- c:\windows\ie8updates
2011-11-27 12:14 . 2010-12-21 11:26 1034240 -c----w- c:\windows\system32\dllcache\mstsc.exe
2011-11-27 12:14 . 2010-12-22 11:29 2690560 -c----w- c:\windows\system32\dllcache\mstscax.dll
2011-11-27 12:08 . 2011-07-15 13:29 457856 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-11-27 11:55 . 2011-08-22 23:40 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-11-27 11:55 . 2011-08-22 23:40 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-11-27 11:55 . 2011-08-22 23:40 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-11-27 11:55 . 2011-08-22 23:40 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-11-27 11:55 . 2011-08-22 23:40 2001408 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-11-27 11:55 . 2011-08-22 23:40 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-11-27 11:55 . 2011-08-22 23:40 11084288 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-11-27 11:50 . 2010-12-09 15:14 2150912 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-11-27 11:50 . 2010-12-09 15:14 2194944 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-11-27 11:50 . 2010-12-09 15:14 2029056 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-11-27 11:10 . 2011-11-27 11:10 -------- d-----w- c:\program files\CCleaner
2011-11-27 10:56 . 2011-11-27 10:56 -------- d-----w- c:\documents and settings\w0lF1-NTB\Data aplikací\Malwarebytes
2011-11-27 10:56 . 2011-11-27 10:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-27 08:30 . 2011-11-27 08:30 -------- d-----w- c:\program files\Common Files\Adobe
2011-11-27 08:22 . 2011-11-27 08:22 -------- d-----w- c:\program files\Common Files\Java
2011-11-26 22:03 . 2011-11-26 22:03 -------- d-----w- c:\program files\Eidos Interactive
2011-11-26 21:11 . 2005-09-09 16:08 13824 ----a-r- c:\windows\system32\drivers\SaiMini.sys
2011-11-26 21:10 . 2005-09-09 16:36 155648 ----a-w- c:\windows\system32\nY.exe
2011-11-26 21:10 . 2005-08-30 14:02 45056 ----a-w- c:\windows\system32\SAIKICK.dll
2011-11-26 21:09 . 2011-11-26 21:09 -------- d-----w- c:\program files\Saitek
2011-11-26 21:09 . 2004-10-22 01:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2011-11-26 21:09 . 2004-10-22 01:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2011-11-26 21:09 . 2004-10-22 01:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2011-11-26 21:09 . 2004-10-22 01:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2011-11-26 21:09 . 2004-10-22 01:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2011-11-26 21:09 . 2011-11-26 21:09 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2011-11-26 21:09 . 2005-09-09 16:08 35200 ----a-r- c:\windows\system32\drivers\SaiBus.sys
2011-11-26 21:09 . 2011-11-26 21:09 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2011-11-26 21:04 . 2005-09-12 11:53 3153920 ----a-r- c:\windows\system32\SaiD80C0.Dll
2011-11-26 21:04 . 2005-08-31 09:31 5120 ----a-r- c:\windows\system32\SaiC80C0_0402.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_10.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_0C.dll
2011-11-26 21:04 . 2005-08-17 17:25 8704 ----a-r- c:\windows\system32\SaiC80C0_0A.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_09.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_07.dll
2011-11-26 21:04 . 2005-09-12 11:57 1269760 ----a-r- c:\windows\system32\SaiC80C0.Dll
2011-11-26 21:04 . 2005-09-12 11:50 176384 ----a-r- c:\windows\system32\drivers\SaiH80C0.sys
2011-11-20 09:07 . 2011-11-20 09:07 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Logitech
2011-11-20 09:05 . 2011-11-20 09:05 -------- d-----w- c:\program files\Common Files\Logitech
2011-11-20 09:05 . 2011-11-20 09:05 -------- d-----w- c:\program files\Logitech
2011-11-19 19:52 . 2011-11-19 19:52 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Pixology
2011-11-18 20:22 . 2008-04-13 22:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2011-11-18 20:22 . 2008-04-13 22:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-11-18 20:22 . 2001-10-24 10:25 5632 ----a-w- c:\windows\system32\ptpusb.dll
2011-11-18 20:22 . 2008-04-14 06:51 159232 ----a-w- c:\windows\system32\ptpusd.dll
2011-11-18 16:06 . 2011-11-18 16:06 -------- d-----w- c:\documents and settings\w0lF1-NTB\Data aplikací\Nikon
2011-11-18 16:06 . 2003-03-19 11:04 765952 ----a-w- c:\windows\system32\msvcp71d.dll
2011-11-18 16:06 . 2003-03-19 12:28 2179072 ----a-w- c:\windows\system32\mfc71d.dll
2011-11-18 16:06 . 2003-03-19 11:03 544768 ----a-w- c:\windows\system32\msvcr71d.dll
2011-11-18 16:06 . 2002-01-06 04:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2011-11-18 16:06 . 2002-01-05 19:40 487424 ----a-w- c:\windows\system32\msvcp70.dll
2011-11-18 16:06 . 2002-01-06 05:48 974848 ----a-w- c:\windows\system32\mfc70.dll
2011-11-18 16:06 . 2005-01-25 19:14 2867200 ----a-r- c:\windows\system32\NkNEFPlugin.dll
2011-11-18 16:06 . 2003-03-19 11:05 106496 ------w- c:\windows\system32\ATL71.DLL
2011-11-18 16:05 . 2004-07-20 08:45 176128 ----a-r- c:\windows\system32\Strato4.dll
2011-11-18 16:05 . 2004-08-03 20:47 48128 ----a-r- c:\windows\system32\picn20.dll
2011-11-18 16:05 . 2004-08-03 20:47 180224 ----a-r- c:\windows\system32\picn1120.dll
2011-11-18 16:05 . 2004-07-12 08:59 110592 ----a-r- c:\windows\system32\RCSigProc.dll
2011-11-18 16:05 . 2004-06-21 13:27 54784 ----a-r- c:\windows\system32\RedEye.dll
2011-11-18 16:05 . 2004-08-03 20:47 155648 ----a-r- c:\windows\system32\picn1020.dll
2011-11-18 16:05 . 2004-06-21 13:08 495616 ----a-r- c:\windows\system32\DRAGNKL1.dll
2011-11-18 16:05 . 2011-11-18 16:05 -------- d-----w- c:\program files\Common Files\muvee Technologies
2011-11-18 16:02 . 1999-11-10 11:05 86016 ----a-w- c:\windows\unvise32qt.exe
2011-11-18 16:02 . 2011-11-18 16:02 106496 ----a-w- c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
2011-11-18 16:02 . 2011-11-18 16:02 106496 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-11-18 16:02 . 2011-11-18 16:02 -------- d-----w- c:\windows\system32\QuickTime
2011-11-18 16:02 . 2011-11-18 16:03 -------- d-----w- c:\program files\QuickTime
2011-11-18 16:02 . 2011-11-18 16:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\QuickTime
2011-11-18 15:57 . 2011-11-18 16:07 -------- d-----w- c:\program files\Common Files\Nikon
2011-11-11 20:52 . 2011-11-11 20:52 -------- d-----w- c:\program files\directx
2011-11-11 20:51 . 2011-11-11 20:51 -------- d-----w- c:\program files\Rockstar Games
2011-11-11 19:55 . 2011-11-11 19:55 -------- d-----w- c:\windows\system32\Adobe
2011-11-11 18:41 . 2011-11-11 18:41 -------- d-----w- c:\windows\system32\LogFiles
2011-11-07 22:00 . 2004-03-09 00:00 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2011-11-07 22:00 . 2001-10-28 16:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-11-07 22:00 . 1998-06-24 00:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2011-11-07 22:00 . 1998-07-06 00:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-11-07 22:00 . 2011-11-07 22:01 -------- d-----w- c:\program files\PDFCreator
2011-11-07 21:58 . 2011-11-07 21:58 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Alibre Design
2011-11-07 21:56 . 2011-11-07 21:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alibre Design
2011-11-07 21:54 . 2011-11-07 22:01 -------- d-----w- c:\program files\Alibre Design
2011-11-06 21:54 . 2011-11-06 21:54 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\DOSBox
2011-11-06 21:51 . 2011-11-12 11:09 -------- d-----w- c:\program files\DOSBox-0.74
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-28 20:29 . 2011-10-28 20:29 760856 ----a-w- C:\SpywareTerminatorSetup.exe
2011-10-28 20:08 . 2011-10-28 20:08 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-28 19:37 . 2011-10-28 19:00 126633208 ----a-w- C:\Ad-Aware90Install.exe
2011-10-10 14:21 . 2010-06-14 15:18 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 04:06 . 2010-06-14 17:56 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 01:37 . 2010-06-14 17:56 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:05 . 2010-01-14 14:59 602624 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2010-01-14 15:06 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2010-01-14 15:01 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 2010-01-14 15:01 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:08 . 2010-01-14 15:02 1867904 ----a-w- c:\windows\system32\win32k.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-10-09 . FF876311F58C86EC3E1A24F585949C25 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"AGEIA PhysX SysTray"="c:\program files\AGEIA Technologies\bin\TrayIcon.exe" [2007-07-23 345640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AcerNotebookManager"="c:\program files\Acer\Notebook Manager\almxptray.exe" [2003-02-16 504832]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-06-25 335872]
"SoundMan"="SOUNDMAN.EXE" [2003-01-07 46592]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-01-09 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-01-09 581632]
"AGRSMMSG"="AGRSMMSG.exe" [2003-01-21 87751]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-02-16 149024]
"LManager"="c:\program files\Launch Manager\CplBBQ12.EXE" [2003-02-07 180224]
"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-06-10 286720]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-11-18 98304]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"Profiler"="c:\program files\Saitek\Software\ProfilerU.exe" [2005-08-30 163840]
"SaiMfd"="c:\program files\Saitek\Software\SaiMfd.exe" [2005-09-09 126976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2011-11-18 118784]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2010-01-14 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Aktualizovat ESET licenci.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Aktualizovat ESET licenci.lnk
backup=c:\windows\pss\Aktualizovat ESET licenci.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-02-19 14:38 1962896 ----a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 11:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop]
2011-08-04 07:40 1042944 ----a-w- c:\documents and settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-09-15 10:32 136176 ----atw- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 05:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-09-08 08:07 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-02-19 14:32 1188456 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-06-12 12:27 399736 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"d:\\zaloha C\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [13.2.2011 17:42 218688]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9.4.2009 14:18 107256]
R2 acernbm;acernbm;c:\windows\system32\drivers\acernbm.sys [14.6.2010 17:44 6538]
R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [19.3.2008 15:52 51816]
R3 PRISM;Wistron NeWeb 802.11b Wireless LAN PCI Card Driver;c:\windows\system32\drivers\EM9NDS.sys [14.6.2010 18:27 51200]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;c:\windows\system32\drivers\wbms.sys [14.6.2010 18:27 30208]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [14.6.2010 18:27 25600]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [14.1.2010 16:04 9472]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 SaiH80C0;SaiH80C0;c:\windows\system32\drivers\SaiH80C0.sys [26.11.2011 22:04 176384]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.1.2010 16:01 14848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.11.1.1
FF - ProfilePath - c:\documents and settings\w0lF1-NTB\Data aplikací\Mozilla\Firefox\Profiles\1ux069zw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://start.facemoods.com/results.php?f=5&a=tweak&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-RailNotification - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-AnVir Task Manager Pro - c:\program files\AnVir Task Manager Pro\AnVir.exe
MSConfigStartUp-egui - c:\program files\ESET\ESET Smart Security\egui.exe
MSConfigStartUp-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.1\facemoodssrv.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
MSConfigStartUp-VVSN - c:\program files\VVSN\VVSN.exe
AddRemove-AnVir Task Manager Pro - c:\program files\AnVir Task Manager Pro\AnVir.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-28 15:09
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(912)
c:\windows\system32\relog_ap.dll
.
Celkový čas: 2011-11-28 15:16:11
ComboFix-quarantined-files.txt 2011-11-28 14:16
.
Před spuštěním: 3 526 418 432
Po spuštění: 3 548 389 376
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 176BD4CBCD8F8BE5970434633005526E
ComboFix 11-11-28.02 - w0lF1-NTB 28.11.2011 15:00:11.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.168 [GMT 1:00]
Spuštěný z: c:\documents and settings\w0lF1-NTB\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\AnVir Task Manager Pro\AnVIr.exe
c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin2.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin3.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin4.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin5.dll
c:\program files\Mozilla Firefox\Plugins\npqtplugin6.dll
c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll
c:\program files\QuickTime\Plugins\npqtplugin2.dll
c:\program files\QuickTime\Plugins\npqtplugin3.dll
c:\program files\QuickTime\Plugins\npqtplugin4.dll
c:\program files\QuickTime\Plugins\npqtplugin5.dll
c:\program files\QuickTime\Plugins\npqtplugin6.dll
c:\program files\QuickTime\Plugins\npqtplugin7.dll
c:\windows\iun6002.exe
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-28 do 2011-11-28 )))))))))))))))))))))))))))))))
.
.
2011-11-27 23:23 . 2011-11-27 23:23 -------- d-----w- C:\rsit
2011-11-27 23:23 . 2011-11-27 23:23 -------- d-----w- c:\program files\trend micro
2011-11-27 23:02 . 2011-11-27 23:02 -------- d-----w- c:\program files\FLV Player
2011-11-27 21:24 . 2011-11-28 14:07 -------- d-----w- c:\program files\AnVir Task Manager Pro
2011-11-27 21:24 . 2011-11-28 13:20 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\AnVir
2011-11-27 21:02 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-27 21:02 . 2011-11-27 21:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-27 12:42 . 2008-04-14 11:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-11-27 12:24 . 2011-11-27 13:01 -------- d-----w- c:\windows\SxsCaPendDel
2011-11-27 12:22 . 2011-11-27 12:32 -------- d-----w- c:\windows\ie8updates
2011-11-27 12:14 . 2010-12-21 11:26 1034240 -c----w- c:\windows\system32\dllcache\mstsc.exe
2011-11-27 12:14 . 2010-12-22 11:29 2690560 -c----w- c:\windows\system32\dllcache\mstscax.dll
2011-11-27 12:08 . 2011-07-15 13:29 457856 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-11-27 11:55 . 2011-08-22 23:40 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-11-27 11:55 . 2011-08-22 23:40 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-11-27 11:55 . 2011-08-22 23:40 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-11-27 11:55 . 2011-08-22 23:40 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-11-27 11:55 . 2011-08-22 23:40 2001408 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-11-27 11:55 . 2011-08-22 23:40 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-11-27 11:55 . 2011-08-22 23:40 11084288 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-11-27 11:50 . 2010-12-09 15:14 2150912 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-11-27 11:50 . 2010-12-09 15:14 2194944 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-11-27 11:50 . 2010-12-09 15:14 2029056 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-11-27 11:10 . 2011-11-27 11:10 -------- d-----w- c:\program files\CCleaner
2011-11-27 10:56 . 2011-11-27 10:56 -------- d-----w- c:\documents and settings\w0lF1-NTB\Data aplikací\Malwarebytes
2011-11-27 10:56 . 2011-11-27 10:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-27 08:30 . 2011-11-27 08:30 -------- d-----w- c:\program files\Common Files\Adobe
2011-11-27 08:22 . 2011-11-27 08:22 -------- d-----w- c:\program files\Common Files\Java
2011-11-26 22:03 . 2011-11-26 22:03 -------- d-----w- c:\program files\Eidos Interactive
2011-11-26 21:11 . 2005-09-09 16:08 13824 ----a-r- c:\windows\system32\drivers\SaiMini.sys
2011-11-26 21:10 . 2005-09-09 16:36 155648 ----a-w- c:\windows\system32\nY.exe
2011-11-26 21:10 . 2005-08-30 14:02 45056 ----a-w- c:\windows\system32\SAIKICK.dll
2011-11-26 21:09 . 2011-11-26 21:09 -------- d-----w- c:\program files\Saitek
2011-11-26 21:09 . 2004-10-22 01:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2011-11-26 21:09 . 2004-10-22 01:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2011-11-26 21:09 . 2004-10-22 01:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2011-11-26 21:09 . 2004-10-22 01:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2011-11-26 21:09 . 2004-10-22 01:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2011-11-26 21:09 . 2011-11-26 21:09 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2011-11-26 21:09 . 2005-09-09 16:08 35200 ----a-r- c:\windows\system32\drivers\SaiBus.sys
2011-11-26 21:09 . 2011-11-26 21:09 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2011-11-26 21:04 . 2005-09-12 11:53 3153920 ----a-r- c:\windows\system32\SaiD80C0.Dll
2011-11-26 21:04 . 2005-08-31 09:31 5120 ----a-r- c:\windows\system32\SaiC80C0_0402.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_10.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_0C.dll
2011-11-26 21:04 . 2005-08-17 17:25 8704 ----a-r- c:\windows\system32\SaiC80C0_0A.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_09.dll
2011-11-26 21:04 . 2005-08-17 17:25 6656 ----a-r- c:\windows\system32\SaiC80C0_07.dll
2011-11-26 21:04 . 2005-09-12 11:57 1269760 ----a-r- c:\windows\system32\SaiC80C0.Dll
2011-11-26 21:04 . 2005-09-12 11:50 176384 ----a-r- c:\windows\system32\drivers\SaiH80C0.sys
2011-11-20 09:07 . 2011-11-20 09:07 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Logitech
2011-11-20 09:05 . 2011-11-20 09:05 -------- d-----w- c:\program files\Common Files\Logitech
2011-11-20 09:05 . 2011-11-20 09:05 -------- d-----w- c:\program files\Logitech
2011-11-19 19:52 . 2011-11-19 19:52 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Pixology
2011-11-18 20:22 . 2008-04-13 22:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2011-11-18 20:22 . 2008-04-13 22:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-11-18 20:22 . 2001-10-24 10:25 5632 ----a-w- c:\windows\system32\ptpusb.dll
2011-11-18 20:22 . 2008-04-14 06:51 159232 ----a-w- c:\windows\system32\ptpusd.dll
2011-11-18 16:06 . 2011-11-18 16:06 -------- d-----w- c:\documents and settings\w0lF1-NTB\Data aplikací\Nikon
2011-11-18 16:06 . 2003-03-19 11:04 765952 ----a-w- c:\windows\system32\msvcp71d.dll
2011-11-18 16:06 . 2003-03-19 12:28 2179072 ----a-w- c:\windows\system32\mfc71d.dll
2011-11-18 16:06 . 2003-03-19 11:03 544768 ----a-w- c:\windows\system32\msvcr71d.dll
2011-11-18 16:06 . 2002-01-06 04:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2011-11-18 16:06 . 2002-01-05 19:40 487424 ----a-w- c:\windows\system32\msvcp70.dll
2011-11-18 16:06 . 2002-01-06 05:48 974848 ----a-w- c:\windows\system32\mfc70.dll
2011-11-18 16:06 . 2005-01-25 19:14 2867200 ----a-r- c:\windows\system32\NkNEFPlugin.dll
2011-11-18 16:06 . 2003-03-19 11:05 106496 ------w- c:\windows\system32\ATL71.DLL
2011-11-18 16:05 . 2004-07-20 08:45 176128 ----a-r- c:\windows\system32\Strato4.dll
2011-11-18 16:05 . 2004-08-03 20:47 48128 ----a-r- c:\windows\system32\picn20.dll
2011-11-18 16:05 . 2004-08-03 20:47 180224 ----a-r- c:\windows\system32\picn1120.dll
2011-11-18 16:05 . 2004-07-12 08:59 110592 ----a-r- c:\windows\system32\RCSigProc.dll
2011-11-18 16:05 . 2004-06-21 13:27 54784 ----a-r- c:\windows\system32\RedEye.dll
2011-11-18 16:05 . 2004-08-03 20:47 155648 ----a-r- c:\windows\system32\picn1020.dll
2011-11-18 16:05 . 2004-06-21 13:08 495616 ----a-r- c:\windows\system32\DRAGNKL1.dll
2011-11-18 16:05 . 2011-11-18 16:05 -------- d-----w- c:\program files\Common Files\muvee Technologies
2011-11-18 16:02 . 1999-11-10 11:05 86016 ----a-w- c:\windows\unvise32qt.exe
2011-11-18 16:02 . 2011-11-18 16:02 106496 ----a-w- c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
2011-11-18 16:02 . 2011-11-18 16:02 106496 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-11-18 16:02 . 2011-11-18 16:02 -------- d-----w- c:\windows\system32\QuickTime
2011-11-18 16:02 . 2011-11-18 16:03 -------- d-----w- c:\program files\QuickTime
2011-11-18 16:02 . 2011-11-18 16:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\QuickTime
2011-11-18 15:57 . 2011-11-18 16:07 -------- d-----w- c:\program files\Common Files\Nikon
2011-11-11 20:52 . 2011-11-11 20:52 -------- d-----w- c:\program files\directx
2011-11-11 20:51 . 2011-11-11 20:51 -------- d-----w- c:\program files\Rockstar Games
2011-11-11 19:55 . 2011-11-11 19:55 -------- d-----w- c:\windows\system32\Adobe
2011-11-11 18:41 . 2011-11-11 18:41 -------- d-----w- c:\windows\system32\LogFiles
2011-11-07 22:00 . 2004-03-09 00:00 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2011-11-07 22:00 . 2001-10-28 16:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-11-07 22:00 . 1998-06-24 00:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2011-11-07 22:00 . 1998-07-06 00:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-11-07 22:00 . 2011-11-07 22:01 -------- d-----w- c:\program files\PDFCreator
2011-11-07 21:58 . 2011-11-07 21:58 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Alibre Design
2011-11-07 21:56 . 2011-11-07 21:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alibre Design
2011-11-07 21:54 . 2011-11-07 22:01 -------- d-----w- c:\program files\Alibre Design
2011-11-06 21:54 . 2011-11-06 21:54 -------- d-----w- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\DOSBox
2011-11-06 21:51 . 2011-11-12 11:09 -------- d-----w- c:\program files\DOSBox-0.74
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-28 20:29 . 2011-10-28 20:29 760856 ----a-w- C:\SpywareTerminatorSetup.exe
2011-10-28 20:08 . 2011-10-28 20:08 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-28 19:37 . 2011-10-28 19:00 126633208 ----a-w- C:\Ad-Aware90Install.exe
2011-10-10 14:21 . 2010-06-14 15:18 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 04:06 . 2010-06-14 17:56 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 01:37 . 2010-06-14 17:56 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:05 . 2010-01-14 14:59 602624 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2010-01-14 15:06 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2010-01-14 15:01 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 2010-01-14 15:01 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:08 . 2010-01-14 15:02 1867904 ----a-w- c:\windows\system32\win32k.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-10-09 . FF876311F58C86EC3E1A24F585949C25 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"AGEIA PhysX SysTray"="c:\program files\AGEIA Technologies\bin\TrayIcon.exe" [2007-07-23 345640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AcerNotebookManager"="c:\program files\Acer\Notebook Manager\almxptray.exe" [2003-02-16 504832]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-06-25 335872]
"SoundMan"="SOUNDMAN.EXE" [2003-01-07 46592]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-01-09 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-01-09 581632]
"AGRSMMSG"="AGRSMMSG.exe" [2003-01-21 87751]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-02-16 149024]
"LManager"="c:\program files\Launch Manager\CplBBQ12.EXE" [2003-02-07 180224]
"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-06-10 286720]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-11-18 98304]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"Profiler"="c:\program files\Saitek\Software\ProfilerU.exe" [2005-08-30 163840]
"SaiMfd"="c:\program files\Saitek\Software\SaiMfd.exe" [2005-09-09 126976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2011-11-18 118784]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2010-01-14 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Aktualizovat ESET licenci.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Aktualizovat ESET licenci.lnk
backup=c:\windows\pss\Aktualizovat ESET licenci.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-02-19 14:38 1962896 ----a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 11:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop]
2011-08-04 07:40 1042944 ----a-w- c:\documents and settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-09-15 10:32 136176 ----atw- c:\documents and settings\w0lF1-NTB\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 05:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-09-08 08:07 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-02-19 14:32 1188456 ----a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-06-12 12:27 399736 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"d:\\zaloha C\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [13.2.2011 17:42 218688]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9.4.2009 14:18 107256]
R2 acernbm;acernbm;c:\windows\system32\drivers\acernbm.sys [14.6.2010 17:44 6538]
R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [19.3.2008 15:52 51816]
R3 PRISM;Wistron NeWeb 802.11b Wireless LAN PCI Card Driver;c:\windows\system32\drivers\EM9NDS.sys [14.6.2010 18:27 51200]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;c:\windows\system32\drivers\wbms.sys [14.6.2010 18:27 30208]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [14.6.2010 18:27 25600]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [14.1.2010 16:04 9472]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 SaiH80C0;SaiH80C0;c:\windows\system32\drivers\SaiH80C0.sys [26.11.2011 22:04 176384]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.1.2010 16:01 14848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.11.1.1
FF - ProfilePath - c:\documents and settings\w0lF1-NTB\Data aplikací\Mozilla\Firefox\Profiles\1ux069zw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://start.facemoods.com/results.php?f=5&a=tweak&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-RailNotification - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-AnVir Task Manager Pro - c:\program files\AnVir Task Manager Pro\AnVir.exe
MSConfigStartUp-egui - c:\program files\ESET\ESET Smart Security\egui.exe
MSConfigStartUp-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.1\facemoodssrv.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
MSConfigStartUp-VVSN - c:\program files\VVSN\VVSN.exe
AddRemove-AnVir Task Manager Pro - c:\program files\AnVir Task Manager Pro\AnVir.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-28 15:09
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(912)
c:\windows\system32\relog_ap.dll
.
Celkový čas: 2011-11-28 15:16:11
ComboFix-quarantined-files.txt 2011-11-28 14:16
.
Před spuštěním: 3 526 418 432
Po spuštění: 3 548 389 376
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 176BD4CBCD8F8BE5970434633005526E
Re: časté zatížení cpu na 99%
odinstaluj Ad-aware vycisti s CCleanerom a napis ci je to lepsie 

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: časté zatížení cpu na 99%
ad-awar už dávno nemám . jen tam po něm něco zustalo. cleanerem to project můžu ,ale to sem dělal 3x včera :/ . možná že se to seká o kousek mín jinak stejý problém
Re: časté zatížení cpu na 99%
OKi prescanuj PC s MBAM - uplna kontrola
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: časté zatížení cpu na 99%
provedl jsem. něco to našlo, ale stále problém
Malwarebytes' Anti-Malware
www.malwarebytes.org
Verze databáze:
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
29.11.2011 15:08:55
mbam-log-2011-11-29 (15-08-55).txt
Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 201673
Uplynulý čas: 35 minut, 20 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 6
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\system volume information\_restore{903ffc4c-9e7f-4c6f-a6fb-91546097929f}\RP519\A0055151.exe (Riskware.KG) -> Quarantined and deleted successfully.
c:\system volume information\_restore{903ffc4c-9e7f-4c6f-a6fb-91546097929f}\RP519\A0055154.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\torrenty\eset antivirus & smart security 4.2.71.2\minodlogin 3.9.7.0.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\z C\eset-antivirus-license-finder-minodlogin-3-7-5-1.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\z C\cs\eset-antivirus-license-finder-minodlogin-3-7-5-1.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\zaloha C\mini\eset antivirus license finder (minodlogin) 3.8.1.2.exe (Riskware.KG) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware
www.malwarebytes.org
Verze databáze:
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
29.11.2011 15:08:55
mbam-log-2011-11-29 (15-08-55).txt
Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 201673
Uplynulý čas: 35 minut, 20 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 6
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\system volume information\_restore{903ffc4c-9e7f-4c6f-a6fb-91546097929f}\RP519\A0055151.exe (Riskware.KG) -> Quarantined and deleted successfully.
c:\system volume information\_restore{903ffc4c-9e7f-4c6f-a6fb-91546097929f}\RP519\A0055154.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\torrenty\eset antivirus & smart security 4.2.71.2\minodlogin 3.9.7.0.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\z C\eset-antivirus-license-finder-minodlogin-3-7-5-1.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\z C\cs\eset-antivirus-license-finder-minodlogin-3-7-5-1.exe (Riskware.KG) -> Quarantined and deleted successfully.
d:\zaloha C\mini\eset antivirus license finder (minodlogin) 3.8.1.2.exe (Riskware.KG) -> Quarantined and deleted successfully.
Re: časté zatížení cpu na 99%
odstran nelegalny ESS
a napis ci problem pretrvava bez AV 


FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: časté zatížení cpu na 99%
to jsem udělal už před combofix. fingery jsou taky odinstalovaný jen zustalo pár souboru který jsem taky odstranil. chci se zeptat. nemůže to bejt něco společnýho s aktualizacema windows?
Re: časté zatížení cpu na 99%
vloz aktualny log RSIT
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: časté zatížení cpu na 99%
Logfile of random's system information tool 1.09 (written by random/random)
Run by w0lF1-NTB at 2011-11-30 09:06:50
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (17%) free of 16 GB
Total RAM: 511 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:07:04, on 30.11.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acer\Notebook Manager\almxptray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Launch Manager\CplBBQ12.EXE
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Saitek\Software\ProfilerU.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
D:\RSIT.exe
C:\Program Files\trend micro\w0lF1-NTB.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook Manager\almxptray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\CplBBQ12.EXE
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
--
End of file - 7268 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IType_exe.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\w0lF1-NTB\Data aplikací\Mozilla\Firefox\Profiles\1ux069zw.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, jqs@sun.com:1.0, {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.3"
prefs.js - "keyword.URL" - "http://start.facemoods.com/results.php?f=5&a=tweak&q="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
fcmdSrchtweak.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AcerNotebookManager"=C:\Program Files\Acer\Notebook Manager\almxptray.exe [2003-02-16 504832]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2001-09-04 28672]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2003-06-25 335872]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2003-01-07 46592]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-01-09 126976]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-01-09 581632]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2003-01-21 87751]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2007-02-16 149024]
"LManager"=C:\Program Files\Launch Manager\CplBBQ12.EXE [2003-02-07 180224]
"SNPSTD2"=C:\WINDOWS\vsnpstd2.exe [2004-06-10 286720]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2011-11-18 98304]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"Profiler"=C:\Program Files\Saitek\Software\ProfilerU.exe [2005-08-30 163840]
"SaiMfd"=C:\Program Files\Saitek\Software\SaiMfd.exe [2005-09-09 126976]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 3080264]
"itype"=c:\Program Files\Microsoft IntelliType Pro\itype.exe [2009-06-01 1501064]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"AGEIA PhysX SysTray"=C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe [2007-07-23 345640]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2007-02-19 1962896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop]
C:\Documents and Settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe [2011-08-04 1042944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\w0lF1-NTB\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-09-15 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe [2011-09-08 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2007-02-19 1188456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-06-12 399736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Aktualizovat ESET licenci.lnk]
C:\PROGRA~1\ESET\MINODL~1\MINODL~1.EXE -d 10000 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BlueSoleil.lnk]
C:\PROGRA~1\IVTCOR~1\BLUESO~1\gprs.exe [2008-03-19 43608]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2010-01-14 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2010-01-14 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\EA Games\Command and Conquer Generals\game.dat"="D:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
"D:\zaloha C\Program Files\Miranda IM\miranda32.exe"="D:\zaloha C\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-11-30 08:56:57 ----D---- C:\Program Files\Microsoft Silverlight
2011-11-30 08:54:15 ----A---- C:\WINDOWS\imsins.BAK
2011-11-29 15:21:08 ----D---- C:\Program Files\Microsoft IntelliType Pro
2011-11-29 15:09:24 ----A---- C:\mbam-log-2011-11-29 (15-08-55).txt
2011-11-29 15:08:42 ----A---- C:\mbam-log-2011-11-29 (15-08-34).txt
2011-11-29 14:32:04 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-11-29 14:32:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-28 16:58:49 ----SHD---- C:\RECYCLER
2011-11-28 15:33:44 ----D---- C:\Program Files\ESET
2011-11-28 15:16:14 ----A---- C:\ComboFix.txt
2011-11-28 14:57:41 ----A---- C:\Boot.bak
2011-11-28 14:57:36 ----RASHD---- C:\cmdcons
2011-11-28 14:55:16 ----A---- C:\WINDOWS\zip.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\SWSC.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\SWREG.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\sed.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\PEV.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\NIRCMD.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\MBR.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\grep.exe
2011-11-28 14:55:06 ----D---- C:\WINDOWS\ERDNT
2011-11-28 14:07:23 ----D---- C:\Qoobox
2011-11-28 00:23:08 ----D---- C:\rsit
2011-11-28 00:23:08 ----D---- C:\Program Files\trend micro
2011-11-28 00:02:15 ----D---- C:\Program Files\FLV Player
2011-11-27 22:24:31 ----D---- C:\Program Files\AnVir Task Manager Pro
2011-11-27 13:58:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-11-27 13:51:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-11-27 13:51:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-11-27 13:51:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-11-27 13:51:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2011-11-27 13:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2483614$
2011-11-27 13:50:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-11-27 13:50:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2011-11-27 13:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-11-27 13:45:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-11-27 13:45:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-11-27 13:42:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2011-11-27 13:42:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-11-27 13:42:43 ----A---- C:\WINDOWS\system32\wmpns.dll
2011-11-27 13:42:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-11-27 13:42:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-11-27 13:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-11-27 13:40:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-11-27 13:40:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-11-27 13:40:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-11-27 13:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-11-27 13:39:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-11-27 13:39:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-11-27 13:38:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-11-27 13:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-11-27 13:38:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2011-11-27 13:38:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-11-27 13:38:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2011-11-27 13:33:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-11-27 13:32:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2011-11-27 13:32:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2011-11-27 13:32:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-11-27 13:32:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-11-27 13:32:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-11-27 13:31:44 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-11-27 13:31:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-11-27 13:27:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-11-27 13:27:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-11-27 13:27:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-11-27 13:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2011-11-27 13:27:24 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-11-27 13:27:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-11-27 13:27:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-11-27 13:26:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-11-27 13:26:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-11-27 13:26:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-11-27 13:26:05 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-11-27 13:25:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-11-27 13:25:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-11-27 13:24:21 ----D---- C:\WINDOWS\SxsCaPendDel
2011-11-27 13:23:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-11-27 13:23:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-11-27 13:22:53 ----D---- C:\WINDOWS\ie8updates
2011-11-27 13:22:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-11-27 13:22:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-11-27 13:22:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-11-27 13:22:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
2011-11-27 13:22:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-11-27 12:10:41 ----D---- C:\Program Files\CCleaner
2011-11-27 12:06:49 ----D---- C:\WINDOWS\system32\appmgmt
2011-11-27 11:56:50 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Malwarebytes
2011-11-27 11:56:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-11-27 09:30:48 ----D---- C:\Program Files\Common Files\Adobe
2011-11-27 09:30:48 ----D---- C:\Program Files\Adobe
2011-11-27 09:22:08 ----D---- C:\Program Files\Common Files\Java
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaws.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaw.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\java.exe
2011-11-26 23:03:03 ----D---- C:\Program Files\Eidos Interactive
2011-11-26 22:11:03 ----RA---- C:\WINDOWS\system32\drivers\SaiMini.sys
2011-11-26 22:10:06 ----A---- C:\WINDOWS\system32\nY.exe
2011-11-26 22:10:05 ----A---- C:\WINDOWS\system32\SAIKICK.dll
2011-11-26 22:09:44 ----D---- C:\Program Files\Saitek
2011-11-26 22:09:29 ----RA---- C:\WINDOWS\system32\drivers\SaiBus.sys
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiD80C0.Dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_10.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0C.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0A.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_09.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_07.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0402.dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\SaiC80C0.Dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\drivers\SaiH80C0.sys
2011-11-24 07:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-11-20 10:05:05 ----D---- C:\Program Files\Common Files\Logitech
2011-11-20 10:05:03 ----D---- C:\Program Files\Logitech
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\ptpusb.dll
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2011-11-18 21:22:20 ----A---- C:\WINDOWS\system32\ptpusd.dll
2011-11-18 17:06:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Nikon
2011-11-18 17:06:42 ----A---- C:\WINDOWS\system32\msvcp71d.dll
2011-11-18 17:06:41 ----A---- C:\WINDOWS\system32\mfc71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr70.dll
2011-11-18 17:06:39 ----A---- C:\WINDOWS\system32\msvcp70.dll
2011-11-18 17:06:38 ----A---- C:\WINDOWS\system32\mfc70.dll
2011-11-18 17:06:37 ----RA---- C:\WINDOWS\system32\NkNEFPlugin.dll
2011-11-18 17:06:36 ----N---- C:\WINDOWS\system32\ATL71.DLL
2011-11-18 17:05:59 ----RA---- C:\WINDOWS\system32\Strato4.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RedEye.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RCSigProc.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn20.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn1120.dll
2011-11-18 17:05:57 ----RA---- C:\WINDOWS\system32\picn1020.dll
2011-11-18 17:05:56 ----RA---- C:\WINDOWS\system32\DRAGNKL1.dll
2011-11-18 17:05:47 ----D---- C:\Program Files\Common Files\muvee Technologies
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\PCDLIB32.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFTIF12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPSD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPNG12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCX12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCT12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFFAX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTKRN12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTIMG12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTFIL12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTEFX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTDIS12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFCMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFBMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC265.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC120V15_32.DLL
2011-11-18 17:04:25 ----D---- C:\Program Files\Nikon
2011-11-18 17:02:59 ----A---- C:\WINDOWS\unvise32qt.exe
2011-11-18 17:02:32 ----D---- C:\WINDOWS\system32\QuickTime
2011-11-18 17:02:31 ----D---- C:\Program Files\QuickTime
2011-11-18 17:02:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\QuickTime
2011-11-18 16:57:57 ----D---- C:\Program Files\Common Files\Nikon
2011-11-11 21:52:28 ----D---- C:\Program Files\directx
2011-11-11 21:51:26 ----D---- C:\Program Files\Rockstar Games
2011-11-11 20:55:17 ----D---- C:\WINDOWS\system32\Adobe
2011-11-11 19:41:24 ----D---- C:\WINDOWS\system32\LogFiles
2011-11-07 23:00:19 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-11-07 23:00:17 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-11-07 23:00:16 ----D---- C:\Program Files\PDFCreator
2011-11-07 22:56:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alibre Design
2011-11-07 22:54:15 ----D---- C:\Program Files\Alibre Design
2011-11-07 22:32:18 ----A---- C:\WINDOWS\WDIRECT.INI
2011-11-06 22:51:55 ----D---- C:\Program Files\DOSBox-0.74
======List of files/folders modified in the last 1 month======
2011-11-30 09:06:56 ----D---- C:\WINDOWS\Prefetch
2011-11-30 09:02:03 ----D---- C:\WINDOWS\Temp
2011-11-30 09:00:47 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-30 08:59:43 ----D---- C:\WINDOWS\system32\drivers
2011-11-30 08:57:22 ----SHD---- C:\WINDOWS\Installer
2011-11-30 08:57:22 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-11-30 08:56:57 ----RD---- C:\Program Files
2011-11-30 08:55:54 ----D---- C:\WINDOWS
2011-11-30 08:55:37 ----D---- C:\WINDOWS\system32
2011-11-30 08:55:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-11-30 08:54:59 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-30 08:04:25 ----D---- C:\WINDOWS\system32\URTTemp
2011-11-30 06:11:49 ----D---- C:\Program Files\Launch Manager
2011-11-29 18:53:42 ----SD---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Microsoft
2011-11-29 18:53:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Adobe
2011-11-29 15:27:26 ----SD---- C:\WINDOWS\Tasks
2011-11-29 15:21:28 ----HD---- C:\WINDOWS\inf
2011-11-29 15:21:12 ----RSD---- C:\WINDOWS\Fonts
2011-11-28 20:43:01 ----D---- C:\WINDOWS\Debug
2011-11-28 15:10:06 ----A---- C:\WINDOWS\system.ini
2011-11-28 15:09:32 ----D---- C:\WINDOWS\system32\drivers\etc
2011-11-28 15:04:19 ----D---- C:\WINDOWS\AppPatch
2011-11-28 15:04:15 ----D---- C:\Program Files\Common Files
2011-11-28 14:57:41 ----RASH---- C:\boot.ini
2011-11-28 14:27:57 ----A---- C:\WINDOWS\win.ini
2011-11-28 00:41:42 ----A---- C:\WINDOWS\NeroDigital.ini
2011-11-27 22:37:58 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2011-11-27 15:09:17 ----D---- C:\WINDOWS\Microsoft.NET
2011-11-27 14:37:43 ----D---- C:\WINDOWS\pss
2011-11-27 14:06:53 ----RSD---- C:\WINDOWS\assembly
2011-11-27 14:03:10 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\uTorrent
2011-11-27 14:01:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-27 13:57:50 ----D---- C:\WINDOWS\WinSxS
2011-11-27 13:51:50 ----HD---- C:\WINDOWS\$hf_mig$
2011-11-27 13:42:12 ----D---- C:\Program Files\Microsoft ActiveSync
2011-11-27 13:40:56 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-27 13:32:27 ----D---- C:\Program Files\Internet Explorer
2011-11-27 13:25:37 ----D---- C:\Program Files\Outlook Express
2011-11-27 12:13:42 ----D---- C:\Program Files\Steam
2011-11-27 12:13:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\DAEMON Tools Lite
2011-11-27 12:13:34 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Skype
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Minidump
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Logs
2011-11-27 12:06:47 ----RD---- C:\Program Files\Skype
2011-11-27 12:06:15 ----D---- C:\Casino
2011-11-27 11:54:41 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-11-27 11:54:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-11-27 09:30:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-11-27 09:21:42 ----D---- C:\Program Files\Java
2011-11-26 22:09:43 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-26 22:08:29 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-11-22 22:00:47 ----D---- C:\WINDOWS\system32\Restore
2011-11-12 07:55:45 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\System32\Drivers\vbtenum.sys [2007-03-05 20880]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [2007-03-05 35600]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2010-01-14 61824]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-10-30 114048]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2010-10-30 392320]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-02-13 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2011-08-04 61936]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 acernbm;acernbm; C:\WINDOWS\system32\drivers\acernbm.sys [2003-01-13 6538]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-10-30 32768]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2003-01-21 1164576]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-01-10 695852]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2010-01-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2003-06-25 587264]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-06-24 34312]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-06-24 27656]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2003-01-16 16256]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2011-08-09 39824]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2010-01-14 61824]
R3 PRISM;Wistron NeWeb 802.11b Wireless LAN PCI Card Driver; C:\WINDOWS\system32\DRIVERS\EM9NDS.sys [2002-05-31 51200]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-04-14 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 SaiMini;SaiMini; C:\WINDOWS\system32\DRIVERS\SaiMini.sys [2005-09-09 13824]
R3 SaiNtBus;SaiNtBus; C:\WINDOWS\system32\drivers\SaiBus.sys [2005-09-09 35200]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2003-01-09 266768]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2010-01-14 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver; C:\WINDOWS\System32\Drivers\WBMS.SYS [2002-11-07 30208]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver; C:\WINDOWS\System32\Drivers\WBSD.SYS [2002-11-28 25600]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2010-04-27 22856]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2010-04-27 15048]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2010-04-27 66632]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-06-24 38920]
S3 catchme;catchme; \??\C:\DOCUME~1\W0LF1-~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Packet;Packet Protocol Driver; \??\C:\WINDOWS\system32\packet.sys []
S3 SaiH80C0;SaiH80C0; C:\WINDOWS\system32\DRIVERS\SaiH80C0.sys [2005-09-12 176384]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 snpstd2;VideoCAM Look; C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-07-28 334080]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2010-04-27 37704]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2010-04-27 31816]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2007-02-16 411168]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2003-06-25 294912]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [2008-03-19 166520]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2011-09-22 974944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 Start BT in service;Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2008-03-19 51816]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Run by w0lF1-NTB at 2011-11-30 09:06:50
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (17%) free of 16 GB
Total RAM: 511 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:07:04, on 30.11.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acer\Notebook Manager\almxptray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Launch Manager\CplBBQ12.EXE
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Saitek\Software\ProfilerU.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
D:\RSIT.exe
C:\Program Files\trend micro\w0lF1-NTB.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AcerNotebookManager] C:\Program Files\Acer\Notebook Manager\almxptray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\CplBBQ12.EXE
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
--
End of file - 7268 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IType_exe.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\w0lF1-NTB\Data aplikací\Mozilla\Firefox\Profiles\1ux069zw.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, jqs@sun.com:1.0, {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.3"
prefs.js - "keyword.URL" - "http://start.facemoods.com/results.php?f=5&a=tweak&q="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
fcmdSrchtweak.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AcerNotebookManager"=C:\Program Files\Acer\Notebook Manager\almxptray.exe [2003-02-16 504832]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2001-09-04 28672]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2003-06-25 335872]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2003-01-07 46592]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-01-09 126976]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-01-09 581632]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2003-01-21 87751]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2007-02-16 149024]
"LManager"=C:\Program Files\Launch Manager\CplBBQ12.EXE [2003-02-07 180224]
"SNPSTD2"=C:\WINDOWS\vsnpstd2.exe [2004-06-10 286720]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2011-11-18 98304]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"Profiler"=C:\Program Files\Saitek\Software\ProfilerU.exe [2005-08-30 163840]
"SaiMfd"=C:\Program Files\Saitek\Software\SaiMfd.exe [2005-09-09 126976]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-09-22 3080264]
"itype"=c:\Program Files\Microsoft IntelliType Pro\itype.exe [2009-06-01 1501064]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"AGEIA PhysX SysTray"=C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe [2007-07-23 345640]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2007-02-19 1962896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Badoo Desktop]
C:\Documents and Settings\All Users\Data aplikací\Badoo\Badoo Desktop\1.6.38.1042\Badoo.Desktop.exe [2011-08-04 1042944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\w0lF1-NTB\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-09-15 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe [2011-09-08 1242448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2007-02-19 1188456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-06-12 399736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Aktualizovat ESET licenci.lnk]
C:\PROGRA~1\ESET\MINODL~1\MINODL~1.EXE -d 10000 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^BlueSoleil.lnk]
C:\PROGRA~1\IVTCOR~1\BLUESO~1\gprs.exe [2008-03-19 43608]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2010-01-14 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2010-01-14 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2010-01-14 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\EA Games\Command and Conquer Generals\game.dat"="D:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
"D:\zaloha C\Program Files\Miranda IM\miranda32.exe"="D:\zaloha C\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-11-30 08:56:57 ----D---- C:\Program Files\Microsoft Silverlight
2011-11-30 08:54:15 ----A---- C:\WINDOWS\imsins.BAK
2011-11-29 15:21:08 ----D---- C:\Program Files\Microsoft IntelliType Pro
2011-11-29 15:09:24 ----A---- C:\mbam-log-2011-11-29 (15-08-55).txt
2011-11-29 15:08:42 ----A---- C:\mbam-log-2011-11-29 (15-08-34).txt
2011-11-29 14:32:04 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-11-29 14:32:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-11-28 16:58:49 ----SHD---- C:\RECYCLER
2011-11-28 15:33:44 ----D---- C:\Program Files\ESET
2011-11-28 15:16:14 ----A---- C:\ComboFix.txt
2011-11-28 14:57:41 ----A---- C:\Boot.bak
2011-11-28 14:57:36 ----RASHD---- C:\cmdcons
2011-11-28 14:55:16 ----A---- C:\WINDOWS\zip.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\SWSC.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\SWREG.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\sed.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\PEV.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\NIRCMD.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\MBR.exe
2011-11-28 14:55:16 ----A---- C:\WINDOWS\grep.exe
2011-11-28 14:55:06 ----D---- C:\WINDOWS\ERDNT
2011-11-28 14:07:23 ----D---- C:\Qoobox
2011-11-28 00:23:08 ----D---- C:\rsit
2011-11-28 00:23:08 ----D---- C:\Program Files\trend micro
2011-11-28 00:02:15 ----D---- C:\Program Files\FLV Player
2011-11-27 22:24:31 ----D---- C:\Program Files\AnVir Task Manager Pro
2011-11-27 13:58:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2570791$
2011-11-27 13:51:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2011-11-27 13:51:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-11-27 13:51:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-11-27 13:51:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2011-11-27 13:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2483614$
2011-11-27 13:50:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2478971$
2011-11-27 13:50:22 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2011-11-27 13:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2011-11-27 13:45:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-11-27 13:45:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2011-11-27 13:42:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2011-11-27 13:42:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2011-11-27 13:42:43 ----A---- C:\WINDOWS\system32\wmpns.dll
2011-11-27 13:42:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2011-11-27 13:42:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2011-11-27 13:41:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2011-11-27 13:40:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2011-11-27 13:40:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2011-11-27 13:40:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2011-11-27 13:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2011-11-27 13:39:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2011-11-27 13:39:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-11-27 13:38:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-11-27 13:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2011-11-27 13:38:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2641690$
2011-11-27 13:38:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2483185$
2011-11-27 13:38:02 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2011-11-27 13:33:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2011-11-27 13:32:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2567053$
2011-11-27 13:32:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2011-11-27 13:32:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2011-11-27 13:32:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-11-27 13:32:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-11-27 13:31:44 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2011-11-27 13:31:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2412687$
2011-11-27 13:27:49 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2011-11-27 13:27:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2011-11-27 13:27:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2508272$
2011-11-27 13:27:31 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2011-11-27 13:27:24 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2011-11-27 13:27:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-11-27 13:27:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2507618$
2011-11-27 13:26:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2419632$
2011-11-27 13:26:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2011-11-27 13:26:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2011-11-27 13:26:05 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2011-11-27 13:25:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2011-11-27 13:25:21 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2011-11-27 13:24:21 ----D---- C:\WINDOWS\SxsCaPendDel
2011-11-27 13:23:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2011-11-27 13:23:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-11-27 13:22:53 ----D---- C:\WINDOWS\ie8updates
2011-11-27 13:22:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2478960$
2011-11-27 13:22:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2393802$
2011-11-27 13:22:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-11-27 13:22:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
2011-11-27 13:22:16 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2011-11-27 12:10:41 ----D---- C:\Program Files\CCleaner
2011-11-27 12:06:49 ----D---- C:\WINDOWS\system32\appmgmt
2011-11-27 11:56:50 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Malwarebytes
2011-11-27 11:56:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-11-27 09:30:48 ----D---- C:\Program Files\Common Files\Adobe
2011-11-27 09:30:48 ----D---- C:\Program Files\Adobe
2011-11-27 09:22:08 ----D---- C:\Program Files\Common Files\Java
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaws.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\javaw.exe
2011-11-27 09:21:49 ----A---- C:\WINDOWS\system32\java.exe
2011-11-26 23:03:03 ----D---- C:\Program Files\Eidos Interactive
2011-11-26 22:11:03 ----RA---- C:\WINDOWS\system32\drivers\SaiMini.sys
2011-11-26 22:10:06 ----A---- C:\WINDOWS\system32\nY.exe
2011-11-26 22:10:05 ----A---- C:\WINDOWS\system32\SAIKICK.dll
2011-11-26 22:09:44 ----D---- C:\Program Files\Saitek
2011-11-26 22:09:29 ----RA---- C:\WINDOWS\system32\drivers\SaiBus.sys
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiD80C0.Dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_10.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0C.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0A.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_09.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_07.dll
2011-11-26 22:04:57 ----RA---- C:\WINDOWS\system32\SaiC80C0_0402.dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\SaiC80C0.Dll
2011-11-26 22:04:56 ----RA---- C:\WINDOWS\system32\drivers\SaiH80C0.sys
2011-11-24 07:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2011-11-20 10:05:05 ----D---- C:\Program Files\Common Files\Logitech
2011-11-20 10:05:03 ----D---- C:\Program Files\Logitech
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\ptpusb.dll
2011-11-18 21:22:21 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2011-11-18 21:22:20 ----A---- C:\WINDOWS\system32\ptpusd.dll
2011-11-18 17:06:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Nikon
2011-11-18 17:06:42 ----A---- C:\WINDOWS\system32\msvcp71d.dll
2011-11-18 17:06:41 ----A---- C:\WINDOWS\system32\mfc71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr71d.dll
2011-11-18 17:06:40 ----A---- C:\WINDOWS\system32\msvcr70.dll
2011-11-18 17:06:39 ----A---- C:\WINDOWS\system32\msvcp70.dll
2011-11-18 17:06:38 ----A---- C:\WINDOWS\system32\mfc70.dll
2011-11-18 17:06:37 ----RA---- C:\WINDOWS\system32\NkNEFPlugin.dll
2011-11-18 17:06:36 ----N---- C:\WINDOWS\system32\ATL71.DLL
2011-11-18 17:05:59 ----RA---- C:\WINDOWS\system32\Strato4.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RedEye.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\RCSigProc.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn20.dll
2011-11-18 17:05:58 ----RA---- C:\WINDOWS\system32\picn1120.dll
2011-11-18 17:05:57 ----RA---- C:\WINDOWS\system32\picn1020.dll
2011-11-18 17:05:56 ----RA---- C:\WINDOWS\system32\DRAGNKL1.dll
2011-11-18 17:05:47 ----D---- C:\Program Files\Common Files\muvee Technologies
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\PCDLIB32.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFTIF12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPSD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPNG12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCX12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCT12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFPCD12N.DLL
2011-11-18 17:04:33 ----A---- C:\WINDOWS\system32\LFFAX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTKRN12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTIMG12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTFIL12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTEFX12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LTDIS12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFCMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\LFBMP12N.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC265.DLL
2011-11-18 17:04:32 ----A---- C:\WINDOWS\system32\DC120V15_32.DLL
2011-11-18 17:04:25 ----D---- C:\Program Files\Nikon
2011-11-18 17:02:59 ----A---- C:\WINDOWS\unvise32qt.exe
2011-11-18 17:02:32 ----D---- C:\WINDOWS\system32\QuickTime
2011-11-18 17:02:31 ----D---- C:\Program Files\QuickTime
2011-11-18 17:02:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\QuickTime
2011-11-18 16:57:57 ----D---- C:\Program Files\Common Files\Nikon
2011-11-11 21:52:28 ----D---- C:\Program Files\directx
2011-11-11 21:51:26 ----D---- C:\Program Files\Rockstar Games
2011-11-11 20:55:17 ----D---- C:\WINDOWS\system32\Adobe
2011-11-11 19:41:24 ----D---- C:\WINDOWS\system32\LogFiles
2011-11-07 23:00:19 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2011-11-07 23:00:17 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2011-11-07 23:00:16 ----D---- C:\Program Files\PDFCreator
2011-11-07 22:56:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alibre Design
2011-11-07 22:54:15 ----D---- C:\Program Files\Alibre Design
2011-11-07 22:32:18 ----A---- C:\WINDOWS\WDIRECT.INI
2011-11-06 22:51:55 ----D---- C:\Program Files\DOSBox-0.74
======List of files/folders modified in the last 1 month======
2011-11-30 09:06:56 ----D---- C:\WINDOWS\Prefetch
2011-11-30 09:02:03 ----D---- C:\WINDOWS\Temp
2011-11-30 09:00:47 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-11-30 08:59:43 ----D---- C:\WINDOWS\system32\drivers
2011-11-30 08:57:22 ----SHD---- C:\WINDOWS\Installer
2011-11-30 08:57:22 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-11-30 08:56:57 ----RD---- C:\Program Files
2011-11-30 08:55:54 ----D---- C:\WINDOWS
2011-11-30 08:55:37 ----D---- C:\WINDOWS\system32
2011-11-30 08:55:36 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-11-30 08:54:59 ----D---- C:\WINDOWS\system32\CatRoot2
2011-11-30 08:04:25 ----D---- C:\WINDOWS\system32\URTTemp
2011-11-30 06:11:49 ----D---- C:\Program Files\Launch Manager
2011-11-29 18:53:42 ----SD---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Microsoft
2011-11-29 18:53:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Adobe
2011-11-29 15:27:26 ----SD---- C:\WINDOWS\Tasks
2011-11-29 15:21:28 ----HD---- C:\WINDOWS\inf
2011-11-29 15:21:12 ----RSD---- C:\WINDOWS\Fonts
2011-11-28 20:43:01 ----D---- C:\WINDOWS\Debug
2011-11-28 15:10:06 ----A---- C:\WINDOWS\system.ini
2011-11-28 15:09:32 ----D---- C:\WINDOWS\system32\drivers\etc
2011-11-28 15:04:19 ----D---- C:\WINDOWS\AppPatch
2011-11-28 15:04:15 ----D---- C:\Program Files\Common Files
2011-11-28 14:57:41 ----RASH---- C:\boot.ini
2011-11-28 14:27:57 ----A---- C:\WINDOWS\win.ini
2011-11-28 00:41:42 ----A---- C:\WINDOWS\NeroDigital.ini
2011-11-27 22:37:58 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2011-11-27 15:09:17 ----D---- C:\WINDOWS\Microsoft.NET
2011-11-27 14:37:43 ----D---- C:\WINDOWS\pss
2011-11-27 14:06:53 ----RSD---- C:\WINDOWS\assembly
2011-11-27 14:03:10 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\uTorrent
2011-11-27 14:01:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-11-27 13:57:50 ----D---- C:\WINDOWS\WinSxS
2011-11-27 13:51:50 ----HD---- C:\WINDOWS\$hf_mig$
2011-11-27 13:42:12 ----D---- C:\Program Files\Microsoft ActiveSync
2011-11-27 13:40:56 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-27 13:32:27 ----D---- C:\Program Files\Internet Explorer
2011-11-27 13:25:37 ----D---- C:\Program Files\Outlook Express
2011-11-27 12:13:42 ----D---- C:\Program Files\Steam
2011-11-27 12:13:42 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\DAEMON Tools Lite
2011-11-27 12:13:34 ----D---- C:\Documents and Settings\w0lF1-NTB\Data aplikací\Skype
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Minidump
2011-11-27 12:13:23 ----D---- C:\WINDOWS\Logs
2011-11-27 12:06:47 ----RD---- C:\Program Files\Skype
2011-11-27 12:06:15 ----D---- C:\Casino
2011-11-27 11:54:41 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-11-27 11:54:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-11-27 09:30:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-11-27 09:21:42 ----D---- C:\Program Files\Java
2011-11-26 22:09:43 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-26 22:08:29 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-11-22 22:00:47 ----D---- C:\WINDOWS\system32\Restore
2011-11-12 07:55:45 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\System32\Drivers\vbtenum.sys [2007-03-05 20880]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [2007-03-05 35600]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2010-01-14 61824]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-10-30 114048]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2010-10-30 392320]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-02-13 218688]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2011-08-04 61936]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 acernbm;acernbm; C:\WINDOWS\system32\drivers\acernbm.sys [2003-01-13 6538]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2011-08-09 154136]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2010-01-14 62848]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-10-30 32768]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2003-01-21 1164576]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-01-10 695852]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2010-01-14 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2003-06-25 587264]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-06-24 34312]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-06-24 27656]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2003-01-16 16256]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2011-08-09 39824]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2010-01-14 61824]
R3 PRISM;Wistron NeWeb 802.11b Wireless LAN PCI Card Driver; C:\WINDOWS\system32\DRIVERS\EM9NDS.sys [2002-05-31 51200]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-04-14 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 SaiMini;SaiMini; C:\WINDOWS\system32\DRIVERS\SaiMini.sys [2005-09-09 13824]
R3 SaiNtBus;SaiNtBus; C:\WINDOWS\system32\drivers\SaiBus.sys [2005-09-09 35200]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2003-01-09 266768]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2010-01-14 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver; C:\WINDOWS\System32\Drivers\WBMS.SYS [2002-11-07 30208]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver; C:\WINDOWS\System32\Drivers\WBSD.SYS [2002-11-28 25600]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2010-04-27 22856]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2010-04-27 15048]
R3 WmXlCore;Logitech Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2010-04-27 66632]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2010-01-14 9472]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S3 Bridge;Most MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2008-04-14 71552]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-06-24 38920]
S3 catchme;catchme; \??\C:\DOCUME~1\W0LF1-~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Packet;Packet Protocol Driver; \??\C:\WINDOWS\system32\packet.sys []
S3 SaiH80C0;SaiH80C0; C:\WINDOWS\system32\DRIVERS\SaiH80C0.sys [2005-09-12 176384]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 snpstd2;VideoCAM Look; C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-07-28 334080]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2010-04-27 37704]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\WINDOWS\system32\drivers\WmHidLo.sys [2010-04-27 31816]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2010-01-14 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2010-01-14 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2010-01-14 133632]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2007-02-16 411168]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2003-06-25 294912]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [2008-03-19 166520]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2011-09-22 974944]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 Start BT in service;Start BT in service; C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2008-03-19 51816]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2010-01-14 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-01-14 14848]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Re: časté zatížení cpu na 99%
C:\Program Files\ESET\ESET Smart Security je stale tam - odinstaluj to - neverim, ze ho mas kupeny a moze byt zdrojom Tvojich problemov ,,,
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: časté zatížení cpu na 99%
před combo fix jsem odinstaloval nelegál eset smart 4. nasledně jsme si stahl trial verzi eset 5 mohu udělat screen. opravdu tam nic nemám..
Re: časté zatížení cpu na 99%
no TRIAL verzia pokial nechces NOD kupit nema zmysel ,,,
praveze som chcel aby si odskusal, ci sa budu vyskytovat nejake problemy bez AV - potom by si AV nainstaloval free - Avira, Avast apod.
praveze som chcel aby si odskusal, ci sa budu vyskytovat nejake problemy bez AV - potom by si AV nainstaloval free - Avira, Avast apod.
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: časté zatížení cpu na 99%
nemyslím si že to nemá smysl.. stačí si každej měsic založit novej email a nechat si poslat trial klíč. není na tom nic nelegálního a je to s aktualizacema. každopádně du ho tedy odinstalovat a uvidm v průběhu dne jak se to bude chovat.