Facebook virus
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Facebook virus
Dobrý den, na fb jsem kliknul na video na youtube a od té doby se vkládají stejná videa na zdi různých skupin, vyskakují panely s facebook aplikacemi a všechny panely v prohlížeči se neustále načítají. Díky za pomoc při řešení problému.
Můj log z RSITu:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Masrtin Šrut at 2012-01-10 14:18:04
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 2 GB (3%) free of 87 GB
Total RAM: 4094 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:18:08, on 10.1.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\QIP 2010\qip.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASC.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\trend micro\Masrtin Šrut.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=b044dd4c- ... 1c259274bf
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=b044dd4c- ... 1c259274bf
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: StartSearchToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Advanced SystemCare 4] "C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe"
O4 - HKCU\..\Run: [TorrentEasy_a947c5ada5068d58c8fd584efffe15d34926567a] "C:\Users\Masrtin Šrut\Downloads\TorrentEasy-cadence-orcad-v16-3-shooters.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files (x86)\QIP\qip.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} (Activex Control) - http://mhd.frag.cz/loadgame_et.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AcPrfMgrSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
O23 - Service: AcSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
O23 - Service: Cadence License Manager - Macrovision Corporation - C:\Cadence\LicenseManager\lmgrd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IPS Core Service (IPSSVC) - Unknown owner - C:\Windows\system32\IPSSVC.EXE (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Upek Service (UpekSrvc) - UPEK Inc. - C:\Program Files\ThinkVantage Fingerprint Software\upeksrvc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13023 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
C:\Windows\system32\IPSSVC.EXE
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe"
C:\Windows\system32\AEADISRV.EXE
"C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe"
C:\Cadence\LicenseManager\lmgrd.exe
\??\C:\Windows\system32\conhost.exe "1224299272-2040782960267031664120571402019059545391659194717-2066013689-69220378
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe"
"C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe"
"C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"
"C:\Program Files\ThinkVantage Fingerprint Software\upeksrvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe"
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Cadence\LicenseManager\lmgrd.exe" -c "C:\Cadence\LicenseManager\orcad_163.lic" -l "C:\Cadence\LicenseManager\debug.log" -z
"C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe" -Embedding
WLIDSvcM.exe 2396
"C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe" /IpNotifyInstance
"C:\Windows\System32\TpShocks.exe"
"C:\Program Files\Lenovo\AwayTask\AwaySch.EXE"
"C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe"
"C:\Program Files\Apoint2K\Apoint.exe"
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe"
"C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "-1818806280-1071796852-28637869111368811381729348869-289642480-240017671767937425
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe"
"C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE"
"C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
"C:\Program Files (x86)\QIP 2010\qip.exe"
C:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
"taskhost.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASC.exe" /quickcare
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6360.dfab6c0.567956565 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 6360 "\\.\pipe\gecko-crash-server-pipe.6360" plugin
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6360.53f1d50.1196875173 "C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 6360 "\\.\pipe\gecko-crash-server-pipe.6360" plugin
"C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -restart
cdslmd.exe -T MartinSrut-PC 10.8 -1 -c "C:\Cadence\LicenseManager\orcad_163.lic" --lmgrd_start 4f0a21c1 -l "C:\Cadence\LicenseManager\debug.log"
"C:\Program Files\ProgDVB\ProgDvbNet.exe"
taskeng.exe {773A14B1-4D51-4AA9-9B64-2334F8130FA1}
"C:\Users\Masrtin Šrut\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
C:\Windows\tasks\SystemToolsDailyTest.job
C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "vshare@toolbar:1.0.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"
prefs.js - "keyword.URL" - "http://vshare.toolbarhome.com/search.aspx?srch=ku&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448]
"Description"=6.0.12.448
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/vbp;version=0.9.17]
"Description"=Veetle Broadcaster Plugin
"Path"=C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsILegitCheckPlugin.xpt
nsIQTScriptablePlugin.xpt
nsJSRealPlayerPlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npdrmv2.dll
npdsplay.dll
npLegitCheckPlugin.dll
NPOFF12.DLL
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
npvsharetvplg.dll
npwmsdrm.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\extensions\
plugin@gameplaylabs.com
vshare@toolbar
{32a1fd71-835e-4b11-8e54-886fda0b4c89}-trash
C:\Users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\searchplugins\
daemon-search.xml
google-cz.xml
qip-search.xml
startsear.xml
web-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}]
IE5BarLauncherBHO Class - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll [2011-11-24 178048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2009-10-30 1678792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2009-10-30 1019336]
{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - StartSearchToolBar - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll [2011-11-24 178048]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"=C:\Windows\system32\TpShocks.exe [2009-03-05 228128]
"AwaySch"=C:\Program Files\Lenovo\AwayTask\AwaySch.EXE [2006-11-07 109608]
"TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2009-03-13 68976]
"LENOVO.TPFNF6R"=C:\Program Files\Lenovo\HOTKEY\TPFNF6R.exe [2009-08-20 62752]
"nwiz"=nwiz.exe /install []
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-09-05 16336488]
"AcWin7Hlpr"=C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [2009-10-13 36864]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2009-09-09 245760]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"EPSON Stylus DX6000 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.EXE [2006-02-13 131072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Advanced SystemCare 4"=C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe [2011-04-21 402832]
"TorrentEasy_a947c5ada5068d58c8fd584efffe15d34926567a"=C:\Users\Masrtin [2011-04-08 1740]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"=C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2008-03-04 487424]
"LPManager"=C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe [2009-07-23 185688]
"LPMailChecker"=C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe [2009-07-23 124248]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2009-07-01 37888]
"TkBellExe"=C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe [2009-12-11 198160]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-03-18 207360]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2009-05-21 135432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
ACGina
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"[INSTALLDIR]CKOUT.exe"="[INSTALLDIR]CKOUT.exe:*:Enabled:CKOUT.exe (CadenceLicenseManager)"
"[INSTALLDIR]NEOLINLD.exe"="[INSTALLDIR]NEOLINLD.exe:*:Enabled:NEOLINLD.exe (CadenceLicenseManager)"
"[INSTALLDIR]alta.exe"="[INSTALLDIR]alta.exe:*:Enabled:alta.exe (CadenceLicenseManager)"
"[INSTALLDIR]ambitd.exe"="[INSTALLDIR]ambitd.exe:*:Enabled:ambitd.exe (CadenceLicenseManager)"
"[INSTALLDIR]axislmd.exe"="[INSTALLDIR]axislmd.exe:*:Enabled:axislmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]cadmosd.exe"="[INSTALLDIR]cadmosd.exe:*:Enabled:cadmosd.exe (CadenceLicenseManager)"
"[INSTALLDIR]cdslmd.exe"="[INSTALLDIR]cdslmd.exe:*:Enabled:cdslmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]dailmd.exe"="[INSTALLDIR]dailmd.exe:*:Enabled:dailmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]dsmtlmd.exe"="[INSTALLDIR]dsmtlmd.exe:*:Enabled:dsmtlmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe"="[INSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe:*:Enabled:CDS_FLEXId_Dongle_Driver_Installer.exe (CadenceLicenseManager)"
"[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe"="[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe:*:Enabled:FLEXId_Dongle_Driver_Installer.exe (CadenceLicenseManager)"
"[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe"="[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe:*:Enabled:FLEXId_Dongle_Driver_Installer_64.exe (CadenceLicenseManager)"
"[INSTALLDIR]g2c_d.exe"="[INSTALLDIR]g2c_d.exe:*:Enabled:g2c_d.exe (CadenceLicenseManager)"
"[INSTALLDIR]hlds.exe"="[INSTALLDIR]hlds.exe:*:Enabled:hlds.exe (CadenceLicenseManager)"
"[INSTALLDIR]installs.exe"="[INSTALLDIR]installs.exe:*:Enabled:installs.exe (CadenceLicenseManager)"
"[INSTALLDIR]k2techld.exe"="[INSTALLDIR]k2techld.exe:*:Enabled:k2techld.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmCheckExpiration.exe"="[INSTALLDIR]lmCheckExpiration.exe:*:Enabled:lmCheckExpiration.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmgrd.exe"="[INSTALLDIR]lmgrd.exe:*:Enabled:lmgrd.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmtools.exe"="[INSTALLDIR]lmtools.exe:*:Enabled:lmtools.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmutil.exe"="[INSTALLDIR]lmutil.exe:*:Enabled:lmutil.exe (CadenceLicenseManager)"
"[INSTALLDIR]perf_test.exe"="[INSTALLDIR]perf_test.exe:*:Enabled:perf_test.exe (CadenceLicenseManager)"
"[INSTALLDIR]platod.exe"="[INSTALLDIR]platod.exe:*:Enabled:platod.exe (CadenceLicenseManager)"
"[INSTALLDIR]qtdaemon.exe"="[INSTALLDIR]qtdaemon.exe:*:Enabled:qtdaemon.exe (CadenceLicenseManager)"
"[INSTALLDIR]qtrekd.exe"="[INSTALLDIR]qtrekd.exe:*:Enabled:qtrekd.exe (CadenceLicenseManager)"
"[INSTALLDIR]simplexlmd.exe"="[INSTALLDIR]simplexlmd.exe:*:Enabled:simplexlmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]spdaemon.exe"="[INSTALLDIR]spdaemon.exe:*:Enabled:spdaemon.exe (CadenceLicenseManager)"
"[INSTALLDIR]speedd.exe"="[INSTALLDIR]speedd.exe:*:Enabled:speedd.exe (CadenceLicenseManager)"
"[INSTALLDIR]verisityd.exe"="[INSTALLDIR]verisityd.exe:*:Enabled:verisityd.exe (CadenceLicenseManager)"
"[INSTALLDIR]verplex.exe"="[INSTALLDIR]verplex.exe:*:Enabled:verplex.exe (CadenceLicenseManager)"
"[INSTALLDIR]LicenseClientConfiguration.exe"="[INSTALLDIR]LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration.exe (CadenceLicenseManager)"
"[INSTALLDIR]LicenseServerConfiguration.exe"="[INSTALLDIR]LicenseServerConfiguration.exe:*:Enabled:LicenseServerConfiguration.exe (CadenceLicenseManager)"
"[INSTALLDIR]Licensing\LicenseClientConfiguration.exe"="[INSTALLDIR]Licensing\LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration.exe (spb16.3)"
"[INSTALLDIR]tools\bin\versionviewer.exe"="[INSTALLDIR]tools\bin\versionviewer.exe:*:Enabled:versionviewer.exe (spb16.3)"
"[INSTALLDIR]tools\bin\switchversion.exe"="[INSTALLDIR]tools\bin\switchversion.exe:*:Enabled:switchversion.exe (spb16.3)"
"[INSTALLDIR]tools\pcb\bin\sys_root.exe"="[INSTALLDIR]tools\pcb\bin\sys_root.exe:*:Enabled:sys_root.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdnshelp.exe"="[INSTALLDIR]tools\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe"="[INSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe:*:Enabled:_cdnshelp.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe"="[INSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe"="[INSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe:*:Enabled:cdnshelpindexer.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\indexer.exe"="[INSTALLDIR]tools\cdnshelp\bin\indexer.exe:*:Enabled:indexer.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\tagtest.exe"="[INSTALLDIR]tools\cdnshelp\bin\tagtest.exe:*:Enabled:tagtest.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\topicgen.exe"="[INSTALLDIR]tools\cdnshelp\bin\topicgen.exe:*:Enabled:topicgen.exe (spb16.3)"
"[INSTALLDIR]tools\capture\Pcadi.exe"="[INSTALLDIR]tools\capture\Pcadi.exe:*:Enabled:Pcadi.exe (spb16.3)"
"[INSTALLDIR]tools\capture\comp16.exe"="[INSTALLDIR]tools\capture\comp16.exe:*:Enabled:comp16.exe (spb16.3)"
"[INSTALLDIR]tools\capture\Capture.exe"="[INSTALLDIR]tools\capture\Capture.exe:*:Enabled:Capture.exe (spb16.3)"
"[INSTALLDIR]tools\capture\pstswp.exe"="[INSTALLDIR]tools\capture\pstswp.exe:*:Enabled:pstswp.exe (spb16.3)"
"[INSTALLDIR]tools\capture\tutorial\Captutor.exe"="[INSTALLDIR]tools\capture\tutorial\Captutor.exe:*:Enabled:Captutor.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsOaPathUtil.exe"="[INSTALLDIR]tools\bin\cdsOaPathUtil.exe:*:Enabled:cdsOaPathUtil.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsUnzip.exe"="[INSTALLDIR]tools\bin\cdsUnzip.exe:*:Enabled:cdsUnzip.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsZip.exe"="[INSTALLDIR]tools\bin\cdsZip.exe:*:Enabled:cdsZip.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cds_root.exe"="[INSTALLDIR]tools\bin\cds_root.exe:*:Enabled:cds_root.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsinfo.exe"="[INSTALLDIR]tools\bin\cdsinfo.exe:*:Enabled:cdsinfo.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdswhich.exe"="[INSTALLDIR]tools\bin\cdswhich.exe:*:Enabled:cdswhich.exe (spb16.3)"
"[INSTALLDIR]tools\bin\clsAdminTool.exe"="[INSTALLDIR]tools\bin\clsAdminTool.exe:*:Enabled:clsAdminTool.exe (spb16.3)"
"[INSTALLDIR]tools\bin\clsbd.exe"="[INSTALLDIR]tools\bin\clsbd.exe:*:Enabled:clsbd.exe (spb16.3)"
"[INSTALLDIR]tools\bin\dregprint.exe"="[INSTALLDIR]tools\bin\dregprint.exe:*:Enabled:dregprint.exe (spb16.3)"
"[INSTALLDIR]tools\bin\nmp.exe"="[INSTALLDIR]tools\bin\nmp.exe:*:Enabled:nmp.exe (spb16.3)"
"[INSTALLDIR]tools\bin\nmppath.exe"="[INSTALLDIR]tools\bin\nmppath.exe:*:Enabled:nmppath.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\java-rmi.exe"="[INSTALLDIR]tools\jre\bin\java-rmi.exe:*:Enabled:java-rmi.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\java.exe"="[INSTALLDIR]tools\jre\bin\java.exe:*:Enabled:java.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\javacpl.exe"="[INSTALLDIR]tools\jre\bin\javacpl.exe:*:Enabled:javacpl.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\javaw.exe"="[INSTALLDIR]tools\jre\bin\javaw.exe:*:Enabled:javaw.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\javaws.exe"="[INSTALLDIR]tools\jre\bin\javaws.exe:*:Enabled:javaws.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\jucheck.exe"="[INSTALLDIR]tools\jre\bin\jucheck.exe:*:Enabled:jucheck.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\jureg.exe"="[INSTALLDIR]tools\jre\bin\jureg.exe:*:Enabled:jureg.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\jusched.exe"="[INSTALLDIR]tools\jre\bin\jusched.exe:*:Enabled:jusched.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\keytool.exe"="[INSTALLDIR]tools\jre\bin\keytool.exe:*:Enabled:keytool.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\kinit.exe"="[INSTALLDIR]tools\jre\bin\kinit.exe:*:Enabled:kinit.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\klist.exe"="[INSTALLDIR]tools\jre\bin\klist.exe:*:Enabled:klist.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\ktab.exe"="[INSTALLDIR]tools\jre\bin\ktab.exe:*:Enabled:ktab.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\orbd.exe"="[INSTALLDIR]tools\jre\bin\orbd.exe:*:Enabled:orbd.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\pack200.exe"="[INSTALLDIR]tools\jre\bin\pack200.exe:*:Enabled:pack200.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\policytool.exe"="[INSTALLDIR]tools\jre\bin\policytool.exe:*:Enabled:policytool.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\rmid.exe"="[INSTALLDIR]tools\jre\bin\rmid.exe:*:Enabled:rmid.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\rmiregistry.exe"="[INSTALLDIR]tools\jre\bin\rmiregistry.exe:*:Enabled:rmiregistry.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\servertool.exe"="[INSTALLDIR]tools\jre\bin\servertool.exe:*:Enabled:servertool.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\ssvagent.exe"="[INSTALLDIR]tools\jre\bin\ssvagent.exe:*:Enabled:ssvagent.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\tnameserv.exe"="[INSTALLDIR]tools\jre\bin\tnameserv.exe:*:Enabled:tnameserv.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\unpack200.exe"="[INSTALLDIR]tools\jre\bin\unpack200.exe:*:Enabled:unpack200.exe (spb16.3)"
"[INSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe"="[INSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe:*:Enabled:tclsh80.exe (spb16.3)"
"[INSTALLDIR]tools\tcltk\tcl\bin\wish80.exe"="[INSTALLDIR]tools\tcltk\tcl\bin\wish80.exe:*:Enabled:wish80.exe (spb16.3)"
"[INSTALLDIR]tools\bin\clu.exe"="[INSTALLDIR]tools\bin\clu.exe:*:Enabled:clu.exe (spb16.3)"
"[INSTALLDIR]tools\bin\van.exe"="[INSTALLDIR]tools\bin\van.exe:*:Enabled:van.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cmfeedback.exe"="[INSTALLDIR]tools\bin\cmfeedback.exe:*:Enabled:cmfeedback.exe (spb16.3)"
"[INSTALLDIR]tools\bin\consmgr.exe"="[INSTALLDIR]tools\bin\consmgr.exe:*:Enabled:consmgr.exe (spb16.3)"
"[INSTALLDIR]tools\bin\emsChecker.exe"="[INSTALLDIR]tools\bin\emsChecker.exe:*:Enabled:emsChecker.exe (spb16.3)"
"[INSTALLDIR]tools\bin\emsMkError.exe"="[INSTALLDIR]tools\bin\emsMkError.exe:*:Enabled:emsMkError.exe (spb16.3)"
"[INSTALLDIR]tools\bin\msgHelp.exe"="[INSTALLDIR]tools\bin\msgHelp.exe:*:Enabled:msgHelp.exe (spb16.3)"
"[INSTALLDIR]tools\bin\eoa.exe"="[INSTALLDIR]tools\bin\eoa.exe:*:Enabled:eoa.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsMsgServer.exe"="[INSTALLDIR]tools\bin\cdsMsgServer.exe:*:Enabled:cdsMsgServer.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsNameServer.exe"="[INSTALLDIR]tools\bin\cdsNameServer.exe:*:Enabled:cdsNameServer.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsRemote.exe"="[INSTALLDIR]tools\bin\cdsRemote.exe:*:Enabled:cdsRemote.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsRemshClient.exe"="[INSTALLDIR]tools\bin\cdsRemshClient.exe:*:Enabled:cdsRemshClient.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsRunHidden.exe"="[INSTALLDIR]tools\bin\cdsRunHidden.exe:*:Enabled:cdsRunHidden.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsServIpc.exe"="[INSTALLDIR]tools\bin\cdsServIpc.exe:*:Enabled:cdsServIpc.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsmps.exe"="[INSTALLDIR]tools\bin\cdsmps.exe:*:Enabled:cdsmps.exe (spb16.3)"
"[INSTALLDIR]tools\bin\mpsinfo.exe"="[INSTALLDIR]tools\bin\mpsinfo.exe:*:Enabled:mpsinfo.exe (spb16.3)"
"[INSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe"="[INSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe:*:Enabled:def2oa.exe (spb16.3)"
"[INSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe"="[INSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe:*:Enabled:lef2oa.exe (spb16.3)"
"[INSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe"="[INSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe:*:Enabled:oa2def.exe (spb16.3)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - C:\Windows\NOTEPAD.EXE %1
======List of files/folders created in the last 1 month======
2012-01-10 13:37:17 ----D---- C:\Program Files\trend micro
2012-01-10 13:37:14 ----D---- C:\rsit
2012-01-07 18:29:42 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-07 18:29:19 ----D---- C:\Program Files (x86)\Avidemux 2.5
2012-01-02 22:57:14 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 22:57:06 ----D---- C:\ProgramData\Graboid Inc
2012-01-02 22:44:35 ----D---- C:\Program Files (x86)\Graboid
2011-12-26 13:23:08 ----D---- C:\WinSetupFromUSB
2011-12-26 13:18:21 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 19:10:48 ----AD---- C:\makebootable
2011-12-18 10:44:11 ----D---- C:\Windows\system32\SPReview
2011-12-18 10:09:48 ----D---- C:\Windows\system32\EventProviders
2011-12-15 15:26:42 ----A---- C:\Windows\SYSWOW64\WMIMPLEX.dll
2011-12-15 15:26:42 ----A---- C:\Windows\SYSWOW64\maplecompat.dll
2011-12-15 15:26:42 ----A---- C:\Windows\SYSWOW64\maplec.dll
2011-12-15 15:26:29 ----D---- C:\watcom-1.3
2011-12-15 15:23:43 ----HD---- C:\Program Files (x86)\Zero G Registry
2011-12-15 15:23:43 ----D---- C:\Program Files (x86)\Maple 12
2011-12-15 08:21:45 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-15 08:21:33 ----A---- C:\Windows\system32\ieframe.dll
2011-12-15 08:21:31 ----A---- C:\Windows\system32\mshtml.dll
2011-12-15 08:21:29 ----A---- C:\Windows\system32\wininet.dll
2011-12-15 08:21:28 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-15 08:21:26 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-15 08:21:25 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-15 08:21:25 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-15 08:21:25 ----A---- C:\Windows\system32\urlmon.dll
2011-12-15 08:21:23 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-12-15 08:21:23 ----A---- C:\Windows\system32\msfeeds.dll
2011-12-15 08:21:22 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-15 08:21:22 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-15 08:21:22 ----A---- C:\Windows\system32\ieui.dll
2011-12-15 08:21:22 ----A---- C:\Windows\system32\iertutil.dll
2011-12-15 08:21:21 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-15 08:21:21 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-15 08:21:20 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-15 08:21:20 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-15 08:21:20 ----A---- C:\Windows\system32\url.dll
2011-12-15 08:21:20 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-15 08:20:25 ----A---- C:\Windows\system32\win32k.sys
2011-12-15 08:20:23 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-15 08:20:23 ----A---- C:\Windows\system32\EncDec.dll
2011-12-15 08:20:11 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-15 08:20:11 ----A---- C:\Windows\system32\tzres.dll
======List of files/folders modified in the last 1 month======
2012-01-10 13:42:29 ----D---- C:\Windows\Prefetch
2012-01-10 13:37:47 ----D---- C:\Windows\Temp
2012-01-10 13:37:17 ----RD---- C:\Program Files
2012-01-10 08:32:25 ----D---- C:\Windows\system32\config
2012-01-09 20:07:29 ----D---- C:\Windows\debug
2012-01-09 20:07:29 ----D---- C:\Windows
2012-01-09 20:04:48 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\Winamp
2012-01-09 16:52:30 ----D---- C:\Windows\System32
2012-01-09 16:52:30 ----D---- C:\Windows\inf
2012-01-09 16:52:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-09 00:17:45 ----SHD---- C:\System Volume Information
2012-01-09 00:08:06 ----A---- C:\Windows\system32\PROCDB.INI
2012-01-09 00:07:32 ----A---- C:\Windows\system32\IPSCtrl.INI
2012-01-08 15:09:50 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-07 18:29:19 ----RD---- C:\Program Files (x86)
2012-01-05 03:15:43 ----D---- C:\Windows\Microsoft.NET
2012-01-05 03:15:28 ----RSD---- C:\Windows\assembly
2012-01-05 03:07:26 ----D---- C:\Windows\winsxs
2012-01-05 03:06:59 ----SHD---- C:\Windows\Installer
2012-01-04 10:04:17 ----D---- C:\Windows\system32\catroot
2012-01-04 10:04:16 ----D---- C:\Windows\system32\catroot2
2012-01-02 22:57:06 ----HD---- C:\ProgramData
2011-12-28 14:50:17 ----D---- C:\Temp
2011-12-28 12:35:33 ----D---- C:\text
2011-12-28 03:02:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-12-26 13:18:13 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-18 11:43:05 ----ASHD---- C:\Boot
2011-12-18 11:41:07 ----D---- C:\Windows\system32\DriverStore
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Media Player
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Mail
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Sidebar
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Portable Devices
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Photo Viewer
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Media Player
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Mail
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Journal
2011-12-18 11:33:58 ----D---- C:\Program Files\Internet Explorer
2011-12-18 11:33:58 ----D---- C:\Program Files\DVD Maker
2011-12-18 11:33:57 ----D---- C:\Program Files\Common Files\System
2011-12-18 11:33:56 ----D---- C:\Windows\servicing
2011-12-18 11:33:56 ----D---- C:\Program Files\Windows Defender
2011-12-18 11:33:55 ----D---- C:\Windows\ehome
2011-12-18 11:33:47 ----D---- C:\Windows\SYSWOW64\oobe
2011-12-18 11:33:47 ----D---- C:\Windows\SYSWOW64\da-DK
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\Setup
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\migration
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\cs
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\wbem
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\sppui
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\es-ES
2011-12-18 11:33:44 ----D---- C:\Windows\SYSWOW64\migwiz
2011-12-18 11:33:44 ----D---- C:\Windows\SYSWOW64\Dism
2011-12-18 11:33:44 ----D---- C:\Windows\SysWOW64
2011-12-18 11:33:33 ----D---- C:\Windows\system32\oobe
2011-12-18 11:33:33 ----D---- C:\Windows\system32\en-US
2011-12-18 11:33:33 ----D---- C:\Windows\system32\da-DK
2011-12-18 11:33:33 ----D---- C:\Windows\PolicyDefinitions
2011-12-18 11:33:32 ----D---- C:\Windows\system32\Setup
2011-12-18 11:33:32 ----D---- C:\Windows\system32\migration
2011-12-18 11:33:32 ----D---- C:\Windows\system32\cs
2011-12-18 11:33:32 ----D---- C:\Windows\system32\AdvancedInstallers
2011-12-18 11:33:30 ----D---- C:\Windows\system32\sppui
2011-12-18 11:33:30 ----D---- C:\Windows\system32\manifeststore
2011-12-18 11:33:30 ----D---- C:\Windows\system32\es-ES
2011-12-18 11:33:30 ----D---- C:\Windows\system32\cs-CZ
2011-12-18 11:33:29 ----D---- C:\Windows\system32\wbem
2011-12-18 11:33:29 ----D---- C:\Windows\system32\migwiz
2011-12-18 11:33:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-12-18 11:33:29 ----D---- C:\Windows\system32\drivers
2011-12-18 11:33:29 ----D---- C:\Windows\system32\Dism
2011-12-18 11:33:18 ----RSD---- C:\Windows\Fonts
2011-12-18 11:33:18 ----D---- C:\Windows\AppPatch
2011-12-18 11:33:11 ----D---- C:\Windows\system32\Boot
2011-12-18 10:57:17 ----A---- C:\Windows\SYSWOW64\msclmd.dll
2011-12-18 10:57:16 ----A---- C:\Windows\system32\msclmd.dll
2011-12-16 03:08:18 ----A---- C:\Windows\system32\MRT.exe
2011-12-16 03:07:20 ----D---- C:\ProgramData\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-02-11 407576]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 Shockprf;Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [2009-03-04 133672]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-11-03 834544]
R0 TPDIGIMN;TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [2009-03-04 23592]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 MpKslb1c976df;MpKslb1c976df; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0EE2B5FB-A884-4BF6-A462-B359FBB7E3C5}\MpKslb1c976df.sys []
R1 MpKslfa375e01;MpKslfa375e01; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{7FA4BA57-AAC0-4680-A649-1DA4D64654E5}\MpKslfa375e01.sys [2012-01-09 35664]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2009-07-28 13104]
R2 PROCDD;IPS Helper Driver; C:\Windows\system32\DRIVERS\PROCDD.SYS [2006-11-06 12592]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmpx64.sys [2008-02-21 62976]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimspx64.sys [2007-07-26 55296]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2007-07-27 57856]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-05-18 497152]
R3 AF15BDA;WinFast DTV Dongle Gold BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 507392]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-09-09 180784]
R3 e1express;Intel(R) PRO/1000 – ovladač PCI Express síťového připojení; C:\Windows\system32\DRIVERS\e1e6032e.sys [2009-06-10 278016]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2009-03-19 30760]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2007-02-19 27136]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2008-12-08 62992]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S1 ctojhfpr;ctojhfpr; \??\C:\Windows\system32\drivers\ctojhfpr.sys []
S1 ghqmnmzn;ghqmnmzn; \??\C:\Windows\system32\drivers\ghqmnmzn.sys []
S1 otlezioe;otlezioe; \??\C:\Windows\system32\drivers\otlezioe.sys []
S1 uwfaxxfb;uwfaxxfb; \??\C:\Windows\system32\drivers\uwfaxxfb.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-03-23 98344]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2010-03-23 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-03-23 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-03-23 21288]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\nmwcdx64.sys [2007-06-28 173056]
S3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 AcPrfMgrSvc;AcPrfMgrSvc; C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe [2009-12-11 124264]
R2 AcSvc;AcSvc; C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe [2009-12-11 255336]
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-04-21 352656]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2008-07-15 111616]
R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [2010-02-17 873248]
R2 Cadence License Manager;Cadence License Manager; C:\Cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2009-03-19 45344]
R2 IPSSVC;IPS Core Service; C:\Windows\system32\IPSSVC.EXE [2007-01-30 135216]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-05 382568]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2009-06-12 28672]
R2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-09-26 644408]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
R2 TVT Scheduler;TVT Scheduler; C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe [2008-03-04 1122304]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UpekSrvc;Upek Service; C:\Program Files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG64.exe [2009-03-04 47656]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1255736]
S4 ApRunSvc;Alps Application Launcher Service; C:\Program Files\Apoint2K\ApRunSvc.exe []
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
Můj log z RSITu:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Masrtin Šrut at 2012-01-10 14:18:04
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 2 GB (3%) free of 87 GB
Total RAM: 4094 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:18:08, on 10.1.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\QIP 2010\qip.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASC.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\trend micro\Masrtin Šrut.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=b044dd4c- ... 1c259274bf
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=2&cf=b044dd4c- ... 1c259274bf
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: StartSearchToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Advanced SystemCare 4] "C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe"
O4 - HKCU\..\Run: [TorrentEasy_a947c5ada5068d58c8fd584efffe15d34926567a] "C:\Users\Masrtin Šrut\Downloads\TorrentEasy-cadence-orcad-v16-3-shooters.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files (x86)\QIP\qip.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} (Activex Control) - http://mhd.frag.cz/loadgame_et.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AcPrfMgrSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
O23 - Service: AcSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
O23 - Service: Cadence License Manager - Macrovision Corporation - C:\Cadence\LicenseManager\lmgrd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IPS Core Service (IPSSVC) - Unknown owner - C:\Windows\system32\IPSSVC.EXE (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Upek Service (UpekSrvc) - UPEK Inc. - C:\Program Files\ThinkVantage Fingerprint Software\upeksrvc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13023 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
C:\Windows\system32\IPSSVC.EXE
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe"
C:\Windows\system32\AEADISRV.EXE
"C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe"
C:\Cadence\LicenseManager\lmgrd.exe
\??\C:\Windows\system32\conhost.exe "1224299272-2040782960267031664120571402019059545391659194717-2066013689-69220378
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe"
"C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe"
"C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"
"C:\Program Files\ThinkVantage Fingerprint Software\upeksrvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe"
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Cadence\LicenseManager\lmgrd.exe" -c "C:\Cadence\LicenseManager\orcad_163.lic" -l "C:\Cadence\LicenseManager\debug.log" -z
"C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe" -Embedding
WLIDSvcM.exe 2396
"C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe" /IpNotifyInstance
"C:\Windows\System32\TpShocks.exe"
"C:\Program Files\Lenovo\AwayTask\AwaySch.EXE"
"C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe"
"C:\Program Files\Apoint2K\Apoint.exe"
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe"
"C:\Program Files\Apoint2K\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "-1818806280-1071796852-28637869111368811381729348869-289642480-240017671767937425
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe"
"C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE"
"C:\Program Files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
"C:\Program Files (x86)\QIP 2010\qip.exe"
C:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
"taskhost.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASC.exe" /quickcare
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6360.dfab6c0.567956565 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 6360 "\\.\pipe\gecko-crash-server-pipe.6360" plugin
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6360.53f1d50.1196875173 "C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 6360 "\\.\pipe\gecko-crash-server-pipe.6360" plugin
"C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -restart
cdslmd.exe -T MartinSrut-PC 10.8 -1 -c "C:\Cadence\LicenseManager\orcad_163.lic" --lmgrd_start 4f0a21c1 -l "C:\Cadence\LicenseManager\debug.log"
"C:\Program Files\ProgDVB\ProgDvbNet.exe"
taskeng.exe {773A14B1-4D51-4AA9-9B64-2334F8130FA1}
"C:\Users\Masrtin Šrut\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
C:\Windows\tasks\SystemToolsDailyTest.job
C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "vshare@toolbar:1.0.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"
prefs.js - "keyword.URL" - "http://vshare.toolbarhome.com/search.aspx?srch=ku&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448]
"Description"=6.0.12.448
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/vbp;version=0.9.17]
"Description"=Veetle Broadcaster Plugin
"Path"=C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsILegitCheckPlugin.xpt
nsIQTScriptablePlugin.xpt
nsJSRealPlayerPlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npdrmv2.dll
npdsplay.dll
npLegitCheckPlugin.dll
NPOFF12.DLL
NPOFFICE.DLL
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
npvsharetvplg.dll
npwmsdrm.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\extensions\
plugin@gameplaylabs.com
vshare@toolbar
{32a1fd71-835e-4b11-8e54-886fda0b4c89}-trash
C:\Users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\searchplugins\
daemon-search.xml
google-cz.xml
qip-search.xml
startsear.xml
web-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}]
IE5BarLauncherBHO Class - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll [2011-11-24 178048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2009-10-30 1678792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2009-10-30 1019336]
{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - StartSearchToolBar - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll [2011-11-24 178048]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"=C:\Windows\system32\TpShocks.exe [2009-03-05 228128]
"AwaySch"=C:\Program Files\Lenovo\AwayTask\AwaySch.EXE [2006-11-07 109608]
"TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2009-03-13 68976]
"LENOVO.TPFNF6R"=C:\Program Files\Lenovo\HOTKEY\TPFNF6R.exe [2009-08-20 62752]
"nwiz"=nwiz.exe /install []
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-09-05 16336488]
"AcWin7Hlpr"=C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [2009-10-13 36864]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2009-09-09 245760]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"EPSON Stylus DX6000 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.EXE [2006-02-13 131072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Advanced SystemCare 4"=C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe [2011-04-21 402832]
"TorrentEasy_a947c5ada5068d58c8fd584efffe15d34926567a"=C:\Users\Masrtin [2011-04-08 1740]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"=C:\Program Files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [2008-03-04 487424]
"LPManager"=C:\PROGRA~2\THINKV~1\PrdCtr\LPMGR.exe [2009-07-23 185688]
"LPMailChecker"=C:\PROGRA~2\THINKV~1\PrdCtr\LPMLCHK.exe [2009-07-23 124248]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2009-07-01 37888]
"TkBellExe"=C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe [2009-12-11 198160]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-03-18 207360]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2009-05-21 135432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
ACGina
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"[INSTALLDIR]CKOUT.exe"="[INSTALLDIR]CKOUT.exe:*:Enabled:CKOUT.exe (CadenceLicenseManager)"
"[INSTALLDIR]NEOLINLD.exe"="[INSTALLDIR]NEOLINLD.exe:*:Enabled:NEOLINLD.exe (CadenceLicenseManager)"
"[INSTALLDIR]alta.exe"="[INSTALLDIR]alta.exe:*:Enabled:alta.exe (CadenceLicenseManager)"
"[INSTALLDIR]ambitd.exe"="[INSTALLDIR]ambitd.exe:*:Enabled:ambitd.exe (CadenceLicenseManager)"
"[INSTALLDIR]axislmd.exe"="[INSTALLDIR]axislmd.exe:*:Enabled:axislmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]cadmosd.exe"="[INSTALLDIR]cadmosd.exe:*:Enabled:cadmosd.exe (CadenceLicenseManager)"
"[INSTALLDIR]cdslmd.exe"="[INSTALLDIR]cdslmd.exe:*:Enabled:cdslmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]dailmd.exe"="[INSTALLDIR]dailmd.exe:*:Enabled:dailmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]dsmtlmd.exe"="[INSTALLDIR]dsmtlmd.exe:*:Enabled:dsmtlmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe"="[INSTALLDIR]flexid\CDS_FLEXId_Dongle_Driver_Installer.exe:*:Enabled:CDS_FLEXId_Dongle_Driver_Installer.exe (CadenceLicenseManager)"
"[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe"="[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer.exe:*:Enabled:FLEXId_Dongle_Driver_Installer.exe (CadenceLicenseManager)"
"[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe"="[INSTALLDIR]flexid\FLEXId_Dongle_Driver_Installer_64.exe:*:Enabled:FLEXId_Dongle_Driver_Installer_64.exe (CadenceLicenseManager)"
"[INSTALLDIR]g2c_d.exe"="[INSTALLDIR]g2c_d.exe:*:Enabled:g2c_d.exe (CadenceLicenseManager)"
"[INSTALLDIR]hlds.exe"="[INSTALLDIR]hlds.exe:*:Enabled:hlds.exe (CadenceLicenseManager)"
"[INSTALLDIR]installs.exe"="[INSTALLDIR]installs.exe:*:Enabled:installs.exe (CadenceLicenseManager)"
"[INSTALLDIR]k2techld.exe"="[INSTALLDIR]k2techld.exe:*:Enabled:k2techld.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmCheckExpiration.exe"="[INSTALLDIR]lmCheckExpiration.exe:*:Enabled:lmCheckExpiration.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmgrd.exe"="[INSTALLDIR]lmgrd.exe:*:Enabled:lmgrd.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmtools.exe"="[INSTALLDIR]lmtools.exe:*:Enabled:lmtools.exe (CadenceLicenseManager)"
"[INSTALLDIR]lmutil.exe"="[INSTALLDIR]lmutil.exe:*:Enabled:lmutil.exe (CadenceLicenseManager)"
"[INSTALLDIR]perf_test.exe"="[INSTALLDIR]perf_test.exe:*:Enabled:perf_test.exe (CadenceLicenseManager)"
"[INSTALLDIR]platod.exe"="[INSTALLDIR]platod.exe:*:Enabled:platod.exe (CadenceLicenseManager)"
"[INSTALLDIR]qtdaemon.exe"="[INSTALLDIR]qtdaemon.exe:*:Enabled:qtdaemon.exe (CadenceLicenseManager)"
"[INSTALLDIR]qtrekd.exe"="[INSTALLDIR]qtrekd.exe:*:Enabled:qtrekd.exe (CadenceLicenseManager)"
"[INSTALLDIR]simplexlmd.exe"="[INSTALLDIR]simplexlmd.exe:*:Enabled:simplexlmd.exe (CadenceLicenseManager)"
"[INSTALLDIR]spdaemon.exe"="[INSTALLDIR]spdaemon.exe:*:Enabled:spdaemon.exe (CadenceLicenseManager)"
"[INSTALLDIR]speedd.exe"="[INSTALLDIR]speedd.exe:*:Enabled:speedd.exe (CadenceLicenseManager)"
"[INSTALLDIR]verisityd.exe"="[INSTALLDIR]verisityd.exe:*:Enabled:verisityd.exe (CadenceLicenseManager)"
"[INSTALLDIR]verplex.exe"="[INSTALLDIR]verplex.exe:*:Enabled:verplex.exe (CadenceLicenseManager)"
"[INSTALLDIR]LicenseClientConfiguration.exe"="[INSTALLDIR]LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration.exe (CadenceLicenseManager)"
"[INSTALLDIR]LicenseServerConfiguration.exe"="[INSTALLDIR]LicenseServerConfiguration.exe:*:Enabled:LicenseServerConfiguration.exe (CadenceLicenseManager)"
"[INSTALLDIR]Licensing\LicenseClientConfiguration.exe"="[INSTALLDIR]Licensing\LicenseClientConfiguration.exe:*:Enabled:LicenseClientConfiguration.exe (spb16.3)"
"[INSTALLDIR]tools\bin\versionviewer.exe"="[INSTALLDIR]tools\bin\versionviewer.exe:*:Enabled:versionviewer.exe (spb16.3)"
"[INSTALLDIR]tools\bin\switchversion.exe"="[INSTALLDIR]tools\bin\switchversion.exe:*:Enabled:switchversion.exe (spb16.3)"
"[INSTALLDIR]tools\pcb\bin\sys_root.exe"="[INSTALLDIR]tools\pcb\bin\sys_root.exe:*:Enabled:sys_root.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdnshelp.exe"="[INSTALLDIR]tools\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe"="[INSTALLDIR]tools\cdnshelp\bin\_cdnshelp.exe:*:Enabled:_cdnshelp.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe"="[INSTALLDIR]tools\cdnshelp\bin\cdnshelp.exe:*:Enabled:cdnshelp.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe"="[INSTALLDIR]tools\cdnshelp\bin\cdnshelpindexer.exe:*:Enabled:cdnshelpindexer.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\indexer.exe"="[INSTALLDIR]tools\cdnshelp\bin\indexer.exe:*:Enabled:indexer.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\tagtest.exe"="[INSTALLDIR]tools\cdnshelp\bin\tagtest.exe:*:Enabled:tagtest.exe (spb16.3)"
"[INSTALLDIR]tools\cdnshelp\bin\topicgen.exe"="[INSTALLDIR]tools\cdnshelp\bin\topicgen.exe:*:Enabled:topicgen.exe (spb16.3)"
"[INSTALLDIR]tools\capture\Pcadi.exe"="[INSTALLDIR]tools\capture\Pcadi.exe:*:Enabled:Pcadi.exe (spb16.3)"
"[INSTALLDIR]tools\capture\comp16.exe"="[INSTALLDIR]tools\capture\comp16.exe:*:Enabled:comp16.exe (spb16.3)"
"[INSTALLDIR]tools\capture\Capture.exe"="[INSTALLDIR]tools\capture\Capture.exe:*:Enabled:Capture.exe (spb16.3)"
"[INSTALLDIR]tools\capture\pstswp.exe"="[INSTALLDIR]tools\capture\pstswp.exe:*:Enabled:pstswp.exe (spb16.3)"
"[INSTALLDIR]tools\capture\tutorial\Captutor.exe"="[INSTALLDIR]tools\capture\tutorial\Captutor.exe:*:Enabled:Captutor.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsOaPathUtil.exe"="[INSTALLDIR]tools\bin\cdsOaPathUtil.exe:*:Enabled:cdsOaPathUtil.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsUnzip.exe"="[INSTALLDIR]tools\bin\cdsUnzip.exe:*:Enabled:cdsUnzip.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsZip.exe"="[INSTALLDIR]tools\bin\cdsZip.exe:*:Enabled:cdsZip.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cds_root.exe"="[INSTALLDIR]tools\bin\cds_root.exe:*:Enabled:cds_root.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsinfo.exe"="[INSTALLDIR]tools\bin\cdsinfo.exe:*:Enabled:cdsinfo.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdswhich.exe"="[INSTALLDIR]tools\bin\cdswhich.exe:*:Enabled:cdswhich.exe (spb16.3)"
"[INSTALLDIR]tools\bin\clsAdminTool.exe"="[INSTALLDIR]tools\bin\clsAdminTool.exe:*:Enabled:clsAdminTool.exe (spb16.3)"
"[INSTALLDIR]tools\bin\clsbd.exe"="[INSTALLDIR]tools\bin\clsbd.exe:*:Enabled:clsbd.exe (spb16.3)"
"[INSTALLDIR]tools\bin\dregprint.exe"="[INSTALLDIR]tools\bin\dregprint.exe:*:Enabled:dregprint.exe (spb16.3)"
"[INSTALLDIR]tools\bin\nmp.exe"="[INSTALLDIR]tools\bin\nmp.exe:*:Enabled:nmp.exe (spb16.3)"
"[INSTALLDIR]tools\bin\nmppath.exe"="[INSTALLDIR]tools\bin\nmppath.exe:*:Enabled:nmppath.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\java-rmi.exe"="[INSTALLDIR]tools\jre\bin\java-rmi.exe:*:Enabled:java-rmi.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\java.exe"="[INSTALLDIR]tools\jre\bin\java.exe:*:Enabled:java.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\javacpl.exe"="[INSTALLDIR]tools\jre\bin\javacpl.exe:*:Enabled:javacpl.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\javaw.exe"="[INSTALLDIR]tools\jre\bin\javaw.exe:*:Enabled:javaw.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\javaws.exe"="[INSTALLDIR]tools\jre\bin\javaws.exe:*:Enabled:javaws.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\jucheck.exe"="[INSTALLDIR]tools\jre\bin\jucheck.exe:*:Enabled:jucheck.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\jureg.exe"="[INSTALLDIR]tools\jre\bin\jureg.exe:*:Enabled:jureg.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\jusched.exe"="[INSTALLDIR]tools\jre\bin\jusched.exe:*:Enabled:jusched.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\keytool.exe"="[INSTALLDIR]tools\jre\bin\keytool.exe:*:Enabled:keytool.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\kinit.exe"="[INSTALLDIR]tools\jre\bin\kinit.exe:*:Enabled:kinit.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\klist.exe"="[INSTALLDIR]tools\jre\bin\klist.exe:*:Enabled:klist.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\ktab.exe"="[INSTALLDIR]tools\jre\bin\ktab.exe:*:Enabled:ktab.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\orbd.exe"="[INSTALLDIR]tools\jre\bin\orbd.exe:*:Enabled:orbd.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\pack200.exe"="[INSTALLDIR]tools\jre\bin\pack200.exe:*:Enabled:pack200.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\policytool.exe"="[INSTALLDIR]tools\jre\bin\policytool.exe:*:Enabled:policytool.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\rmid.exe"="[INSTALLDIR]tools\jre\bin\rmid.exe:*:Enabled:rmid.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\rmiregistry.exe"="[INSTALLDIR]tools\jre\bin\rmiregistry.exe:*:Enabled:rmiregistry.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\servertool.exe"="[INSTALLDIR]tools\jre\bin\servertool.exe:*:Enabled:servertool.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\ssvagent.exe"="[INSTALLDIR]tools\jre\bin\ssvagent.exe:*:Enabled:ssvagent.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\tnameserv.exe"="[INSTALLDIR]tools\jre\bin\tnameserv.exe:*:Enabled:tnameserv.exe (spb16.3)"
"[INSTALLDIR]tools\jre\bin\unpack200.exe"="[INSTALLDIR]tools\jre\bin\unpack200.exe:*:Enabled:unpack200.exe (spb16.3)"
"[INSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe"="[INSTALLDIR]tools\tcltk\tcl\bin\tclsh80.exe:*:Enabled:tclsh80.exe (spb16.3)"
"[INSTALLDIR]tools\tcltk\tcl\bin\wish80.exe"="[INSTALLDIR]tools\tcltk\tcl\bin\wish80.exe:*:Enabled:wish80.exe (spb16.3)"
"[INSTALLDIR]tools\bin\clu.exe"="[INSTALLDIR]tools\bin\clu.exe:*:Enabled:clu.exe (spb16.3)"
"[INSTALLDIR]tools\bin\van.exe"="[INSTALLDIR]tools\bin\van.exe:*:Enabled:van.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cmfeedback.exe"="[INSTALLDIR]tools\bin\cmfeedback.exe:*:Enabled:cmfeedback.exe (spb16.3)"
"[INSTALLDIR]tools\bin\consmgr.exe"="[INSTALLDIR]tools\bin\consmgr.exe:*:Enabled:consmgr.exe (spb16.3)"
"[INSTALLDIR]tools\bin\emsChecker.exe"="[INSTALLDIR]tools\bin\emsChecker.exe:*:Enabled:emsChecker.exe (spb16.3)"
"[INSTALLDIR]tools\bin\emsMkError.exe"="[INSTALLDIR]tools\bin\emsMkError.exe:*:Enabled:emsMkError.exe (spb16.3)"
"[INSTALLDIR]tools\bin\msgHelp.exe"="[INSTALLDIR]tools\bin\msgHelp.exe:*:Enabled:msgHelp.exe (spb16.3)"
"[INSTALLDIR]tools\bin\eoa.exe"="[INSTALLDIR]tools\bin\eoa.exe:*:Enabled:eoa.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsMsgServer.exe"="[INSTALLDIR]tools\bin\cdsMsgServer.exe:*:Enabled:cdsMsgServer.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsNameServer.exe"="[INSTALLDIR]tools\bin\cdsNameServer.exe:*:Enabled:cdsNameServer.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsRemote.exe"="[INSTALLDIR]tools\bin\cdsRemote.exe:*:Enabled:cdsRemote.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsRemshClient.exe"="[INSTALLDIR]tools\bin\cdsRemshClient.exe:*:Enabled:cdsRemshClient.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsRunHidden.exe"="[INSTALLDIR]tools\bin\cdsRunHidden.exe:*:Enabled:cdsRunHidden.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsServIpc.exe"="[INSTALLDIR]tools\bin\cdsServIpc.exe:*:Enabled:cdsServIpc.exe (spb16.3)"
"[INSTALLDIR]tools\bin\cdsmps.exe"="[INSTALLDIR]tools\bin\cdsmps.exe:*:Enabled:cdsmps.exe (spb16.3)"
"[INSTALLDIR]tools\bin\mpsinfo.exe"="[INSTALLDIR]tools\bin\mpsinfo.exe:*:Enabled:mpsinfo.exe (spb16.3)"
"[INSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe"="[INSTALLDIR]OpenAccess\bin\win32\opt\def2oa.exe:*:Enabled:def2oa.exe (spb16.3)"
"[INSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe"="[INSTALLDIR]OpenAccess\bin\win32\opt\lef2oa.exe:*:Enabled:lef2oa.exe (spb16.3)"
"[INSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe"="[INSTALLDIR]OpenAccess\bin\win32\opt\oa2def.exe:*:Enabled:oa2def.exe (spb16.3)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - C:\Windows\NOTEPAD.EXE %1
======List of files/folders created in the last 1 month======
2012-01-10 13:37:17 ----D---- C:\Program Files\trend micro
2012-01-10 13:37:14 ----D---- C:\rsit
2012-01-07 18:29:42 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-07 18:29:19 ----D---- C:\Program Files (x86)\Avidemux 2.5
2012-01-02 22:57:14 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 22:57:06 ----D---- C:\ProgramData\Graboid Inc
2012-01-02 22:44:35 ----D---- C:\Program Files (x86)\Graboid
2011-12-26 13:23:08 ----D---- C:\WinSetupFromUSB
2011-12-26 13:18:21 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 19:10:48 ----AD---- C:\makebootable
2011-12-18 10:44:11 ----D---- C:\Windows\system32\SPReview
2011-12-18 10:09:48 ----D---- C:\Windows\system32\EventProviders
2011-12-15 15:26:42 ----A---- C:\Windows\SYSWOW64\WMIMPLEX.dll
2011-12-15 15:26:42 ----A---- C:\Windows\SYSWOW64\maplecompat.dll
2011-12-15 15:26:42 ----A---- C:\Windows\SYSWOW64\maplec.dll
2011-12-15 15:26:29 ----D---- C:\watcom-1.3
2011-12-15 15:23:43 ----HD---- C:\Program Files (x86)\Zero G Registry
2011-12-15 15:23:43 ----D---- C:\Program Files (x86)\Maple 12
2011-12-15 08:21:45 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-15 08:21:33 ----A---- C:\Windows\system32\ieframe.dll
2011-12-15 08:21:31 ----A---- C:\Windows\system32\mshtml.dll
2011-12-15 08:21:29 ----A---- C:\Windows\system32\wininet.dll
2011-12-15 08:21:28 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-15 08:21:26 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-15 08:21:25 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-15 08:21:25 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-15 08:21:25 ----A---- C:\Windows\system32\urlmon.dll
2011-12-15 08:21:23 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-12-15 08:21:23 ----A---- C:\Windows\system32\msfeeds.dll
2011-12-15 08:21:22 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-15 08:21:22 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-15 08:21:22 ----A---- C:\Windows\system32\ieui.dll
2011-12-15 08:21:22 ----A---- C:\Windows\system32\iertutil.dll
2011-12-15 08:21:21 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-15 08:21:21 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-15 08:21:20 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-15 08:21:20 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-15 08:21:20 ----A---- C:\Windows\system32\url.dll
2011-12-15 08:21:20 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-15 08:20:25 ----A---- C:\Windows\system32\win32k.sys
2011-12-15 08:20:23 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-15 08:20:23 ----A---- C:\Windows\system32\EncDec.dll
2011-12-15 08:20:11 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-15 08:20:11 ----A---- C:\Windows\system32\tzres.dll
======List of files/folders modified in the last 1 month======
2012-01-10 13:42:29 ----D---- C:\Windows\Prefetch
2012-01-10 13:37:47 ----D---- C:\Windows\Temp
2012-01-10 13:37:17 ----RD---- C:\Program Files
2012-01-10 08:32:25 ----D---- C:\Windows\system32\config
2012-01-09 20:07:29 ----D---- C:\Windows\debug
2012-01-09 20:07:29 ----D---- C:\Windows
2012-01-09 20:04:48 ----D---- C:\Users\Masrtin Šrut\AppData\Roaming\Winamp
2012-01-09 16:52:30 ----D---- C:\Windows\System32
2012-01-09 16:52:30 ----D---- C:\Windows\inf
2012-01-09 16:52:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-09 00:17:45 ----SHD---- C:\System Volume Information
2012-01-09 00:08:06 ----A---- C:\Windows\system32\PROCDB.INI
2012-01-09 00:07:32 ----A---- C:\Windows\system32\IPSCtrl.INI
2012-01-08 15:09:50 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-07 18:29:19 ----RD---- C:\Program Files (x86)
2012-01-05 03:15:43 ----D---- C:\Windows\Microsoft.NET
2012-01-05 03:15:28 ----RSD---- C:\Windows\assembly
2012-01-05 03:07:26 ----D---- C:\Windows\winsxs
2012-01-05 03:06:59 ----SHD---- C:\Windows\Installer
2012-01-04 10:04:17 ----D---- C:\Windows\system32\catroot
2012-01-04 10:04:16 ----D---- C:\Windows\system32\catroot2
2012-01-02 22:57:06 ----HD---- C:\ProgramData
2011-12-28 14:50:17 ----D---- C:\Temp
2011-12-28 12:35:33 ----D---- C:\text
2011-12-28 03:02:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-12-26 13:18:13 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-18 11:43:05 ----ASHD---- C:\Boot
2011-12-18 11:41:07 ----D---- C:\Windows\system32\DriverStore
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Media Player
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Windows Mail
2011-12-18 11:34:01 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Sidebar
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Portable Devices
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Photo Viewer
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Media Player
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Mail
2011-12-18 11:33:58 ----D---- C:\Program Files\Windows Journal
2011-12-18 11:33:58 ----D---- C:\Program Files\Internet Explorer
2011-12-18 11:33:58 ----D---- C:\Program Files\DVD Maker
2011-12-18 11:33:57 ----D---- C:\Program Files\Common Files\System
2011-12-18 11:33:56 ----D---- C:\Windows\servicing
2011-12-18 11:33:56 ----D---- C:\Program Files\Windows Defender
2011-12-18 11:33:55 ----D---- C:\Windows\ehome
2011-12-18 11:33:47 ----D---- C:\Windows\SYSWOW64\oobe
2011-12-18 11:33:47 ----D---- C:\Windows\SYSWOW64\da-DK
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\Setup
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\migration
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\cs
2011-12-18 11:33:46 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\wbem
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\sppui
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-12-18 11:33:45 ----D---- C:\Windows\SYSWOW64\es-ES
2011-12-18 11:33:44 ----D---- C:\Windows\SYSWOW64\migwiz
2011-12-18 11:33:44 ----D---- C:\Windows\SYSWOW64\Dism
2011-12-18 11:33:44 ----D---- C:\Windows\SysWOW64
2011-12-18 11:33:33 ----D---- C:\Windows\system32\oobe
2011-12-18 11:33:33 ----D---- C:\Windows\system32\en-US
2011-12-18 11:33:33 ----D---- C:\Windows\system32\da-DK
2011-12-18 11:33:33 ----D---- C:\Windows\PolicyDefinitions
2011-12-18 11:33:32 ----D---- C:\Windows\system32\Setup
2011-12-18 11:33:32 ----D---- C:\Windows\system32\migration
2011-12-18 11:33:32 ----D---- C:\Windows\system32\cs
2011-12-18 11:33:32 ----D---- C:\Windows\system32\AdvancedInstallers
2011-12-18 11:33:30 ----D---- C:\Windows\system32\sppui
2011-12-18 11:33:30 ----D---- C:\Windows\system32\manifeststore
2011-12-18 11:33:30 ----D---- C:\Windows\system32\es-ES
2011-12-18 11:33:30 ----D---- C:\Windows\system32\cs-CZ
2011-12-18 11:33:29 ----D---- C:\Windows\system32\wbem
2011-12-18 11:33:29 ----D---- C:\Windows\system32\migwiz
2011-12-18 11:33:29 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-12-18 11:33:29 ----D---- C:\Windows\system32\drivers
2011-12-18 11:33:29 ----D---- C:\Windows\system32\Dism
2011-12-18 11:33:18 ----RSD---- C:\Windows\Fonts
2011-12-18 11:33:18 ----D---- C:\Windows\AppPatch
2011-12-18 11:33:11 ----D---- C:\Windows\system32\Boot
2011-12-18 10:57:17 ----A---- C:\Windows\SYSWOW64\msclmd.dll
2011-12-18 10:57:16 ----A---- C:\Windows\system32\msclmd.dll
2011-12-16 03:08:18 ----A---- C:\Windows\system32\MRT.exe
2011-12-16 03:07:20 ----D---- C:\ProgramData\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-02-11 407576]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 Shockprf;Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [2009-03-04 133672]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-11-03 834544]
R0 TPDIGIMN;TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [2009-03-04 23592]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 MpKslb1c976df;MpKslb1c976df; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0EE2B5FB-A884-4BF6-A462-B359FBB7E3C5}\MpKslb1c976df.sys []
R1 MpKslfa375e01;MpKslfa375e01; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{7FA4BA57-AAC0-4680-A649-1DA4D64654E5}\MpKslfa375e01.sys [2012-01-09 35664]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2009-07-28 13104]
R2 PROCDD;IPS Helper Driver; C:\Windows\system32\DRIVERS\PROCDD.SYS [2006-11-06 12592]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmpx64.sys [2008-02-21 62976]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimspx64.sys [2007-07-26 55296]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdpx64.sys [2007-07-27 57856]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-05-18 497152]
R3 AF15BDA;WinFast DTV Dongle Gold BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 507392]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-09-09 180784]
R3 e1express;Intel(R) PRO/1000 – ovladač PCI Express síťového připojení; C:\Windows\system32\DRIVERS\e1e6032e.sys [2009-06-10 278016]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2009-03-19 30760]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2007-02-19 27136]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2008-12-08 62992]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S1 ctojhfpr;ctojhfpr; \??\C:\Windows\system32\drivers\ctojhfpr.sys []
S1 ghqmnmzn;ghqmnmzn; \??\C:\Windows\system32\drivers\ghqmnmzn.sys []
S1 otlezioe;otlezioe; \??\C:\Windows\system32\drivers\otlezioe.sys []
S1 uwfaxxfb;uwfaxxfb; \??\C:\Windows\system32\drivers\uwfaxxfb.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-03-23 98344]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2010-03-23 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-03-23 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-03-23 21288]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\nmwcdx64.sys [2007-06-28 173056]
S3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 AcPrfMgrSvc;AcPrfMgrSvc; C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe [2009-12-11 124264]
R2 AcSvc;AcSvc; C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe [2009-12-11 255336]
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-04-21 352656]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2008-07-15 111616]
R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [2010-02-17 873248]
R2 Cadence License Manager;Cadence License Manager; C:\Cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2009-03-19 45344]
R2 IPSSVC;IPS Core Service; C:\Windows\system32\IPSSVC.EXE [2007-01-30 135216]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-09-05 382568]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2009-06-12 28672]
R2 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2007-09-26 644408]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
R2 TVT Scheduler;TVT Scheduler; C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe [2008-03-04 1122304]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UpekSrvc;Upek Service; C:\Program Files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG64.exe [2009-03-04 47656]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1255736]
S4 ApRunSvc;Alps Application Launcher Service; C:\Program Files\Apoint2K\ApRunSvc.exe []
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 Lis 2008 15:55
- Místo/Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Facebook virus
Zdravím. 
Facebook vir tam tedy nevidím, ale mrkneme na to.
Nejprve ale potřebujeme trochu více místa na systémovém disku C:\ => 2 GB je opravdu málo, systém se dusí! Takže něco vymaž, odinstaluj, vyčisti.
Odinstaluj DAEMON Tools Toolbar a StartSearchToolBar.
Doporučuji svižně odinstalovat Advanced SystemCare 4 a následně i vše od IObit. Jsou to čínské programy, které hledají nesmyslné a neexistující problémy. Tvůrci software ukradli databázi havěti jiné renomované společnosti a účinek na PC je spíše nulový až negativní. 
Až to vše provedeš, stáhni RogueKiller - http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
- Ukonči všechny programy!
- Pokud používáš Win Vista či Win 7, klikni na RogueKiller pravým myšítkem a dej Run As Administrator či Spustit jako správce.
- Zvol možnost 2 a potvrď [Enter].
- Utilita provede svou činnost a dá log - ten mi sem vlož.
- Nyní znovu stejný postup, ale zvol možnost 3 a poté ještě jednou s možností 4 - logy mi sem opět vlož.
Re: Facebook virus
RogueKiller V6.2.3 [01/09/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Masrtin Šrut [Admin rights]
Mode: Remove -- Date : 01/10/2012 23:51:07
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 7 ¤¤¤
[SUSP PATH] {7B02EF0B-A410-4938-8480-9BA26420A627}.job : C:\Users\MASRTI~1\AppData\Local\Temp\x.exe -> DELETED
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609} : NameServer (10.20.100.1) -> NOT REMOVED, USE DNSFIX
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609} : NameServer (10.20.100.1) -> NOT REMOVED, USE DNSFIX
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 6e477e22b7f5172c0efe470ac46f0d78
[BSP] 7fe9dcab88cabb969e90e5dfa5a16ed3 : Windows 7 MBR Code
Partition table:
0 - [XXXXXX] NTFS [HIDDEN!] Offset (sectors): 2048 | Size: 6816 Mo
1 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 13316096 | Size: 91111 Mo
2 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 191268864 | Size: 62109 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V6.2.3 [01/09/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Masrtin Šrut [Admin rights]
Mode: HOSTSFix -- Date : 01/10/2012 23:52:13
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V6.2.3 [01/09/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Masrtin Šrut [Admin rights]
Mode: ProxyFix -- Date : 01/10/2012 23:52:27
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Masrtin Šrut [Admin rights]
Mode: Remove -- Date : 01/10/2012 23:51:07
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 7 ¤¤¤
[SUSP PATH] {7B02EF0B-A410-4938-8480-9BA26420A627}.job : C:\Users\MASRTI~1\AppData\Local\Temp\x.exe -> DELETED
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609} : NameServer (10.20.100.1) -> NOT REMOVED, USE DNSFIX
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609} : NameServer (10.20.100.1) -> NOT REMOVED, USE DNSFIX
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 6e477e22b7f5172c0efe470ac46f0d78
[BSP] 7fe9dcab88cabb969e90e5dfa5a16ed3 : Windows 7 MBR Code
Partition table:
0 - [XXXXXX] NTFS [HIDDEN!] Offset (sectors): 2048 | Size: 6816 Mo
1 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 13316096 | Size: 91111 Mo
2 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 191268864 | Size: 62109 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V6.2.3 [01/09/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Masrtin Šrut [Admin rights]
Mode: HOSTSFix -- Date : 01/10/2012 23:52:13
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V6.2.3 [01/09/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Masrtin Šrut [Admin rights]
Mode: ProxyFix -- Date : 01/10/2012 23:52:27
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Registry Entries: 0 ¤¤¤
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 Lis 2008 15:55
- Místo/Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Facebook virus
- Otevři položku Správa disků a udělej mi screen, který bych rád viděl.
- Návod na vytvoření screenu je zde: http://www.viry.cz/forum/viewtopic.php?f=11&t=14114
Kód: Vybrat vše
%windir%\system32\wbem\wmic.exe partition get name,bootable,size,type > "%userprofile%\Desktop\disk.txt"- Klikni na [OK].
- Na Ploše se vytvoří log s názvem disk.txt - jeho obsah mi sem také vlož.
Ještě udělej scan pomocí TDSS Killer.
- Dvojklik na TDSSKiller.exe, potom kliknout na Spustit kontrolu - Start Scan.
- Pokud je detekován infikovaný soubor(y), bude předvolená akce Cure, klikni na tlačítko Continue.
- Pokud je detekovaný podezřelý (suspicious) soubor, bude předvolená akce Skip, klikni na Continue.
- Program Tě může požádat, abys restartoval počítač pro dokončení procesu. Klikni na Reboot Now.
- Jestli se restart nevyžaduje, klikni na tlačítko Report. Soubor s logem by se měl objevit. Zkopíruj ho a vlož jej sem.
- Je-li vyžadován restart počítače, zpráva je k dispozici ve Tvém kořenovém adresáři (například C:\ složka) ve formě "TDSSKiller. _log.txt".
Re: Facebook virus
Nejde mi provést ten druhý bod, nevytvoří se mi ten textový soubor disk.txt
Musím v tom kopírovaným řádku něco pozměnit?
Musím v tom kopírovaným řádku něco pozměnit?
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Facebook virus
Ak mozem,, sprav takto,
1:Prikaz zadaj do prikazoveho riadku, tak ako tu to mam napisane, alebo s[rav batak.
Prikazovy riadok
1:Prikaz zadaj do prikazoveho riadku, tak ako tu to mam napisane, alebo s[rav batak.
Prikazovy riadok
Re: Facebook virus

Uploaded with ImageShack.us
Bootable Name Size Type
FALSE Disk #0, Partition #0 6816792576 Unknown
TRUE Disk #0, Partition #1 91111817216 Installable File System
FALSE Disk #0, Partition #2 62109253632 Installable File System
13:18:28.0998 4356 TDSS rootkit removing tool 2.7.0.0 Jan 10 2012 09:14:26
13:18:29.0234 4356 ============================================================
13:18:29.0234 4356 Current date / time: 2012/01/11 13:18:29.0234
13:18:29.0234 4356 SystemInfo:
13:18:29.0234 4356
13:18:29.0234 4356 OS Version: 6.1.7601 ServicePack: 1.0
13:18:29.0234 4356 Product type: Workstation
13:18:29.0234 4356 ComputerName: MARTINSRUT-PC
13:18:29.0235 4356 UserName: Masrtin Šrut
13:18:29.0235 4356 Windows directory: C:\Windows
13:18:29.0235 4356 System windows directory: C:\Windows
13:18:29.0235 4356 Running under WOW64
13:18:29.0235 4356 Processor architecture: Intel x64
13:18:29.0235 4356 Number of processors: 2
13:18:29.0235 4356 Page size: 0x1000
13:18:29.0235 4356 Boot type: Normal boot
13:18:29.0235 4356 ============================================================
13:18:30.0189 4356 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000, SectorSize: 0x200, Cylinders: 0x50C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K', Flags 0x00000040
13:18:30.0301 4356 Initialize success
13:18:38.0009 1132 ============================================================
13:18:38.0009 1132 Scan started
13:18:38.0009 1132 Mode: Manual;
13:18:38.0009 1132 ============================================================
13:18:39.0052 1132 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
13:18:39.0055 1132 1394ohci - ok
13:18:39.0258 1132 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
13:18:39.0263 1132 ACPI - ok
13:18:39.0373 1132 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
13:18:39.0374 1132 AcpiPmi - ok
13:18:39.0526 1132 ADIHdAudAddService (560649e6a9c11f6124f97310ef387c45) C:\Windows\system32\drivers\ADIHdAud.sys
13:18:39.0534 1132 ADIHdAudAddService - ok
13:18:39.0618 1132 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
13:18:39.0626 1132 adp94xx - ok
13:18:39.0713 1132 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
13:18:39.0719 1132 adpahci - ok
13:18:39.0784 1132 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
13:18:39.0787 1132 adpu320 - ok
13:18:39.0964 1132 AF15BDA (0517e1670a58213e3f206066cd209273) C:\Windows\system32\DRIVERS\AF15BDA.sys
13:18:39.0972 1132 AF15BDA - ok
13:18:40.0140 1132 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
13:18:40.0149 1132 AFD - ok
13:18:40.0329 1132 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
13:18:40.0331 1132 agp440 - ok
13:18:40.0456 1132 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
13:18:40.0457 1132 aliide - ok
13:18:40.0487 1132 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
13:18:40.0488 1132 amdide - ok
13:18:40.0545 1132 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
13:18:40.0547 1132 AmdK8 - ok
13:18:40.0568 1132 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
13:18:40.0570 1132 AmdPPM - ok
13:18:40.0746 1132 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
13:18:40.0748 1132 amdsata - ok
13:18:40.0924 1132 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
13:18:40.0928 1132 amdsbs - ok
13:18:41.0100 1132 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
13:18:41.0101 1132 amdxata - ok
13:18:41.0208 1132 ApfiltrService (83f32e0e9c644b3cdba7f5d1d9159ad3) C:\Windows\system32\DRIVERS\Apfiltr.sys
13:18:41.0210 1132 ApfiltrService - ok
13:18:41.0293 1132 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
13:18:41.0297 1132 AppID - ok
13:18:41.0539 1132 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
13:18:41.0542 1132 arc - ok
13:18:41.0897 1132 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
13:18:41.0899 1132 arcsas - ok
13:18:42.0060 1132 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
13:18:42.0061 1132 AsyncMac - ok
13:18:42.0231 1132 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
13:18:42.0231 1132 atapi - ok
13:18:42.0419 1132 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
13:18:42.0427 1132 b06bdrv - ok
13:18:42.0601 1132 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
13:18:42.0606 1132 b57nd60a - ok
13:18:42.0762 1132 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
13:18:42.0763 1132 Beep - ok
13:18:42.0948 1132 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
13:18:42.0951 1132 blbdrive - ok
13:18:43.0111 1132 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
13:18:43.0113 1132 bowser - ok
13:18:43.0213 1132 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:18:43.0214 1132 BrFiltLo - ok
13:18:43.0243 1132 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:18:43.0245 1132 BrFiltUp - ok
13:18:43.0303 1132 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
13:18:43.0308 1132 Brserid - ok
13:18:43.0336 1132 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
13:18:43.0338 1132 BrSerWdm - ok
13:18:43.0492 1132 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:18:43.0493 1132 BrUsbMdm - ok
13:18:43.0673 1132 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
13:18:43.0674 1132 BrUsbSer - ok
13:18:43.0849 1132 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
13:18:43.0850 1132 BthEnum - ok
13:18:44.0001 1132 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
13:18:44.0003 1132 BTHMODEM - ok
13:18:44.0170 1132 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
13:18:44.0172 1132 BthPan - ok
13:18:44.0359 1132 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
13:18:44.0370 1132 BTHPORT - ok
13:18:44.0535 1132 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
13:18:44.0537 1132 BTHUSB - ok
13:18:44.0721 1132 btwaudio (a72a9101f9730db7332714e566614e4d) C:\Windows\system32\drivers\btwaudio.sys
13:18:44.0723 1132 btwaudio - ok
13:18:44.0888 1132 btwavdt (5ceec634b617525f2b6ad29f871033f7) C:\Windows\system32\drivers\btwavdt.sys
13:18:44.0892 1132 btwavdt - ok
13:18:45.0066 1132 btwl2cap (6149301dc3f81d6f9667a3fbac410975) C:\Windows\system32\DRIVERS\btwl2cap.sys
13:18:45.0067 1132 btwl2cap - ok
13:18:45.0240 1132 btwrchid (2af5604d28bef77b7cf4b9d232fe7cd3) C:\Windows\system32\DRIVERS\btwrchid.sys
13:18:45.0241 1132 btwrchid - ok
13:18:45.0357 1132 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
13:18:45.0359 1132 cdfs - ok
13:18:45.0452 1132 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
13:18:45.0455 1132 cdrom - ok
13:18:45.0561 1132 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
13:18:45.0562 1132 circlass - ok
13:18:45.0618 1132 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
13:18:45.0623 1132 CLFS - ok
13:18:45.0771 1132 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
13:18:45.0772 1132 CmBatt - ok
13:18:45.0833 1132 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
13:18:45.0834 1132 cmdide - ok
13:18:45.0916 1132 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
13:18:45.0924 1132 CNG - ok
13:18:46.0081 1132 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
13:18:46.0082 1132 Compbatt - ok
13:18:46.0262 1132 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
13:18:46.0263 1132 CompositeBus - ok
13:18:46.0421 1132 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
13:18:46.0422 1132 crcdisk - ok
13:18:46.0618 1132 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
13:18:46.0626 1132 CSC - ok
13:18:46.0795 1132 ctojhfpr - ok
13:18:47.0023 1132 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
13:18:47.0025 1132 DfsC - ok
13:18:47.0181 1132 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
13:18:47.0205 1132 discache - ok
13:18:47.0322 1132 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
13:18:47.0324 1132 Disk - ok
13:18:47.0387 1132 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
13:18:47.0388 1132 drmkaud - ok
13:18:47.0511 1132 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
13:18:47.0518 1132 DXGKrnl - ok
13:18:47.0619 1132 e1express (416a2007878ed1d6fc5dddb9e1f6db3e) C:\Windows\system32\DRIVERS\e1e6032e.sys
13:18:47.0624 1132 e1express - ok
13:18:47.0768 1132 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
13:18:47.0859 1132 ebdrv - ok
13:18:47.0996 1132 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
13:18:48.0006 1132 elxstor - ok
13:18:48.0114 1132 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
13:18:48.0115 1132 ErrDev - ok
13:18:48.0224 1132 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
13:18:48.0228 1132 exfat - ok
13:18:48.0258 1132 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
13:18:48.0262 1132 fastfat - ok
13:18:48.0427 1132 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
13:18:48.0428 1132 fdc - ok
13:18:48.0605 1132 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
13:18:48.0607 1132 FileInfo - ok
13:18:48.0756 1132 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
13:18:48.0757 1132 Filetrace - ok
13:18:48.0901 1132 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
13:18:48.0902 1132 flpydisk - ok
13:18:49.0074 1132 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
13:18:49.0080 1132 FltMgr - ok
13:18:49.0235 1132 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
13:18:49.0236 1132 FsDepends - ok
13:18:49.0325 1132 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
13:18:49.0327 1132 Fs_Rec - ok
13:18:49.0406 1132 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
13:18:49.0410 1132 fvevol - ok
13:18:49.0566 1132 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:18:49.0569 1132 gagp30kx - ok
13:18:49.0706 1132 ghqmnmzn - ok
13:18:49.0915 1132 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
13:18:49.0917 1132 hcw85cir - ok
13:18:50.0084 1132 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
13:18:50.0090 1132 HdAudAddService - ok
13:18:50.0251 1132 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
13:18:50.0253 1132 HDAudBus - ok
13:18:50.0394 1132 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
13:18:50.0396 1132 HidBatt - ok
13:18:50.0547 1132 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
13:18:50.0555 1132 HidBth - ok
13:18:50.0661 1132 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
13:18:50.0662 1132 HidIr - ok
13:18:50.0760 1132 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
13:18:50.0761 1132 HidUsb - ok
13:18:50.0946 1132 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
13:18:50.0948 1132 HpSAMD - ok
13:18:51.0118 1132 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
13:18:51.0131 1132 HTTP - ok
13:18:51.0241 1132 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
13:18:51.0242 1132 hwpolicy - ok
13:18:51.0299 1132 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
13:18:51.0301 1132 i8042prt - ok
13:18:51.0368 1132 iaStor (1adaa4f16073fd0c7270f451fd024e97) C:\Windows\system32\DRIVERS\iaStor.sys
13:18:51.0375 1132 iaStor - ok
13:18:51.0552 1132 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
13:18:51.0559 1132 iaStorV - ok
13:18:51.0712 1132 IBMPMDRV (80b477b0d066c25dbf673abff3e3b9d6) C:\Windows\system32\DRIVERS\ibmpmdrv.sys
13:18:51.0713 1132 IBMPMDRV - ok
13:18:51.0882 1132 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
13:18:51.0884 1132 iirsp - ok
13:18:52.0054 1132 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
13:18:52.0056 1132 intelide - ok
13:18:52.0230 1132 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
13:18:52.0231 1132 intelppm - ok
13:18:52.0331 1132 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:18:52.0333 1132 IpFilterDriver - ok
13:18:52.0386 1132 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
13:18:52.0388 1132 IPMIDRV - ok
13:18:52.0427 1132 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
13:18:52.0430 1132 IPNAT - ok
13:18:52.0612 1132 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
13:18:52.0613 1132 IRENUM - ok
13:18:52.0724 1132 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
13:18:52.0725 1132 isapnp - ok
13:18:52.0784 1132 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
13:18:52.0789 1132 iScsiPrt - ok
13:18:52.0822 1132 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
13:18:52.0823 1132 kbdclass - ok
13:18:52.0998 1132 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
13:18:52.0999 1132 kbdhid - ok
13:18:53.0161 1132 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
13:18:53.0163 1132 KSecDD - ok
13:18:53.0267 1132 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
13:18:53.0270 1132 KSecPkg - ok
13:18:53.0327 1132 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
13:18:53.0328 1132 ksthunk - ok
13:18:53.0478 1132 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
13:18:53.0491 1132 lltdio - ok
13:18:53.0569 1132 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:18:53.0571 1132 LSI_FC - ok
13:18:53.0593 1132 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:18:53.0596 1132 LSI_SAS - ok
13:18:53.0734 1132 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:18:53.0736 1132 LSI_SAS2 - ok
13:18:53.0885 1132 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:18:53.0887 1132 LSI_SCSI - ok
13:18:54.0024 1132 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
13:18:54.0026 1132 luafv - ok
13:18:54.0171 1132 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
13:18:54.0173 1132 megasas - ok
13:18:54.0328 1132 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
13:18:54.0333 1132 MegaSR - ok
13:18:54.0486 1132 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
13:18:54.0487 1132 Modem - ok
13:18:54.0632 1132 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
13:18:54.0633 1132 monitor - ok
13:18:54.0794 1132 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
13:18:54.0795 1132 mouclass - ok
13:18:54.0945 1132 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
13:18:54.0946 1132 mouhid - ok
13:18:55.0112 1132 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
13:18:55.0114 1132 mountmgr - ok
13:18:55.0241 1132 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\Windows\system32\DRIVERS\MpFilter.sys
13:18:55.0243 1132 MpFilter - ok
13:18:55.0302 1132 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
13:18:55.0306 1132 mpio - ok
13:18:55.0500 1132 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\Windows\system32\DRIVERS\MpNWMon.sys
13:18:55.0501 1132 MpNWMon - ok
13:18:55.0542 1132 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
13:18:55.0544 1132 mpsdrv - ok
13:18:55.0605 1132 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
13:18:55.0608 1132 MRxDAV - ok
13:18:55.0689 1132 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:18:55.0693 1132 mrxsmb - ok
13:18:55.0779 1132 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:18:55.0785 1132 mrxsmb10 - ok
13:18:55.0877 1132 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:18:55.0879 1132 mrxsmb20 - ok
13:18:55.0936 1132 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
13:18:55.0937 1132 msahci - ok
13:18:56.0004 1132 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
13:18:56.0007 1132 msdsm - ok
13:18:56.0119 1132 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
13:18:56.0120 1132 Msfs - ok
13:18:56.0186 1132 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
13:18:56.0187 1132 mshidkmdf - ok
13:18:56.0254 1132 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
13:18:56.0256 1132 msisadrv - ok
13:18:56.0416 1132 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
13:18:56.0417 1132 MSKSSRV - ok
13:18:56.0657 1132 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
13:18:56.0658 1132 MSPCLOCK - ok
13:18:56.0809 1132 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
13:18:56.0810 1132 MSPQM - ok
13:18:56.0964 1132 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
13:18:56.0970 1132 MsRPC - ok
13:18:57.0138 1132 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
13:18:57.0139 1132 mssmbios - ok
13:18:57.0276 1132 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
13:18:57.0277 1132 MSTEE - ok
13:18:57.0331 1132 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
13:18:57.0333 1132 MTConfig - ok
13:18:57.0371 1132 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
13:18:57.0373 1132 Mup - ok
13:18:57.0471 1132 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
13:18:57.0477 1132 NativeWifiP - ok
13:18:57.0584 1132 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
13:18:57.0599 1132 NDIS - ok
13:18:57.0694 1132 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
13:18:57.0696 1132 NdisCap - ok
13:18:57.0754 1132 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
13:18:57.0756 1132 NdisTapi - ok
13:18:57.0803 1132 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
13:18:57.0804 1132 Ndisuio - ok
13:18:57.0861 1132 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
13:18:57.0865 1132 NdisWan - ok
13:18:58.0791 1132 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
13:18:59.0081 1132 NDProxy - ok
13:18:59.0157 1132 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
13:18:59.0159 1132 NetBIOS - ok
13:18:59.0262 1132 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
13:18:59.0267 1132 NetBT - ok
13:18:59.0557 1132 netw5v64 (64428dfdaf6e88366cb51f45a79c5f69) C:\Windows\system32\DRIVERS\netw5v64.sys
13:18:59.0697 1132 netw5v64 - ok
13:18:59.0801 1132 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
13:18:59.0805 1132 nfrd960 - ok
13:18:59.0862 1132 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
13:18:59.0863 1132 NisDrv - ok
13:19:00.0012 1132 nmwcdx64 (ad8c3895155ee8d057f073856b2d5851) C:\Windows\system32\drivers\nmwcdx64.sys
13:19:00.0015 1132 nmwcdx64 - ok
13:19:00.0069 1132 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
13:19:00.0070 1132 Npfs - ok
13:19:00.0107 1132 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
13:19:00.0109 1132 nsiproxy - ok
13:19:00.0207 1132 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
13:19:00.0233 1132 Ntfs - ok
13:19:00.0317 1132 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
13:19:00.0318 1132 Null - ok
13:19:00.0636 1132 nvlddmkm (5d0c43555b4244d9f5699a12288d1847) C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:19:00.0710 1132 nvlddmkm - ok
13:19:00.0887 1132 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
13:19:00.0890 1132 nvraid - ok
13:19:00.0929 1132 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
13:19:00.0932 1132 nvstor - ok
13:19:01.0100 1132 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
13:19:01.0102 1132 nv_agp - ok
13:19:01.0179 1132 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
13:19:01.0182 1132 ohci1394 - ok
13:19:01.0339 1132 otlezioe - ok
13:19:01.0386 1132 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
13:19:01.0389 1132 Parport - ok
13:19:01.0446 1132 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
13:19:01.0448 1132 partmgr - ok
13:19:01.0585 1132 PCDSRVC{127174DC-C366ED8B-06000000}_0 (51209fbdb13a46e05c1b0077a9310264) c:\program files\pc-doctor\pcdsrvc_x64.pkms
13:19:01.0948 1132 PCDSRVC{127174DC-C366ED8B-06000000}_0 - ok
13:19:02.0030 1132 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 (51209fbdb13a46e05c1b0077a9310264) c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms
13:19:02.0033 1132 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - ok
13:19:02.0151 1132 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
13:19:02.0155 1132 pci - ok
13:19:02.0211 1132 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
13:19:02.0212 1132 pciide - ok
13:19:02.0278 1132 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
13:19:02.0282 1132 pcmcia - ok
13:19:02.0355 1132 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
13:19:02.0357 1132 pcw - ok
13:19:02.0422 1132 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
13:19:02.0432 1132 PEAUTH - ok
13:19:02.0598 1132 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
13:19:02.0600 1132 PptpMiniport - ok
13:19:02.0651 1132 PROCDD (05ffeb3eff3e6a61ee1681c195156341) C:\Windows\system32\DRIVERS\PROCDD.SYS
13:19:02.0658 1132 PROCDD - ok
13:19:02.0719 1132 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
13:19:02.0721 1132 Processor - ok
13:19:02.0818 1132 psadd (4a768fb063a38b0a78ad97617d3a04f5) C:\Windows\system32\DRIVERS\psadd.sys
13:19:02.0820 1132 psadd - ok
13:19:02.0900 1132 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
13:19:02.0903 1132 Psched - ok
13:19:02.0996 1132 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
13:19:03.0021 1132 ql2300 - ok
13:19:03.0112 1132 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
13:19:03.0115 1132 ql40xx - ok
13:19:03.0166 1132 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
13:19:03.0169 1132 QWAVEdrv - ok
13:19:03.0222 1132 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
13:19:03.0223 1132 RasAcd - ok
13:19:03.0319 1132 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:19:03.0321 1132 RasAgileVpn - ok
13:19:03.0384 1132 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:19:03.0387 1132 Rasl2tp - ok
13:19:03.0437 1132 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
13:19:03.0440 1132 RasPppoe - ok
13:19:03.0530 1132 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
13:19:03.0532 1132 RasSstp - ok
13:19:03.0601 1132 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
13:19:03.0606 1132 rdbss - ok
13:19:03.0633 1132 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
13:19:03.0635 1132 rdpbus - ok
13:19:03.0728 1132 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:19:03.0729 1132 RDPCDD - ok
13:19:03.0785 1132 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
13:19:03.0788 1132 RDPDR - ok
13:19:03.0827 1132 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
13:19:03.0829 1132 RDPENCDD - ok
13:19:03.0923 1132 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
13:19:03.0924 1132 RDPREFMP - ok
13:19:03.0978 1132 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
13:19:03.0982 1132 RDPWD - ok
13:19:04.0051 1132 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
13:19:04.0055 1132 rdyboost - ok
13:19:04.0162 1132 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
13:19:04.0165 1132 RFCOMM - ok
13:19:04.0212 1132 rimmptsk (d13d70fac45fc1df69f88559b1f72f0a) C:\Windows\system32\DRIVERS\rimmpx64.sys
13:19:04.0214 1132 rimmptsk - ok
13:19:04.0238 1132 rimsptsk (bb9edc55b0b8cb4fcd713428820e0776) C:\Windows\system32\DRIVERS\rimspx64.sys
13:19:04.0240 1132 rimsptsk - ok
13:19:04.0329 1132 rismxdp (481c3fdeacaae04b74c58288dbc91df9) C:\Windows\system32\DRIVERS\rixdpx64.sys
13:19:04.0331 1132 rismxdp - ok
13:19:04.0384 1132 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
13:19:04.0386 1132 rspndr - ok
13:19:04.0483 1132 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
13:19:04.0484 1132 s3cap - ok
13:19:04.0525 1132 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
13:19:04.0528 1132 sbp2port - ok
13:19:04.0579 1132 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
13:19:04.0580 1132 scfilter - ok
13:19:04.0706 1132 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
13:19:04.0708 1132 sdbus - ok
13:19:04.0764 1132 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
13:19:04.0765 1132 secdrv - ok
13:19:04.0801 1132 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
13:19:04.0803 1132 Serenum - ok
13:19:04.0895 1132 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
13:19:04.0897 1132 Serial - ok
13:19:04.0949 1132 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
13:19:04.0950 1132 sermouse - ok
13:19:05.0011 1132 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
13:19:05.0013 1132 sffdisk - ok
13:19:05.0116 1132 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
13:19:05.0118 1132 sffp_mmc - ok
13:19:05.0148 1132 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
13:19:05.0150 1132 sffp_sd - ok
13:19:05.0195 1132 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
13:19:05.0196 1132 sfloppy - ok
13:19:05.0344 1132 Shockprf (22bbe329f0909054d4dd74164def317a) C:\Windows\system32\DRIVERS\Apsx64.sys
13:19:05.0348 1132 Shockprf - ok
13:19:05.0394 1132 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:19:05.0395 1132 SiSRaid2 - ok
13:19:05.0421 1132 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
13:19:05.0423 1132 SiSRaid4 - ok
13:19:05.0520 1132 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
13:19:05.0523 1132 Smb - ok
13:19:05.0576 1132 smihlp (c5b1a19b14f19b08ae72fcb20a3075b6) C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys
13:19:05.0577 1132 smihlp - ok
13:19:05.0680 1132 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
13:19:05.0682 1132 spldr - ok
13:19:05.0788 1132 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
13:19:05.0788 1132 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
13:19:05.0791 1132 sptd ( LockedFile.Multi.Generic ) - warning
13:19:05.0791 1132 sptd - detected LockedFile.Multi.Generic (1)
13:19:05.0891 1132 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
13:19:05.0898 1132 srv - ok
13:19:05.0963 1132 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
13:19:05.0970 1132 srv2 - ok
13:19:06.0067 1132 SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
13:19:06.0072 1132 SrvHsfHDA - ok
13:19:06.0154 1132 SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
13:19:06.0178 1132 SrvHsfV92 - ok
13:19:06.0286 1132 SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
13:19:06.0297 1132 SrvHsfWinac - ok
13:19:06.0401 1132 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
13:19:06.0404 1132 srvnet - ok
13:19:06.0444 1132 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
13:19:06.0445 1132 stexstor - ok
13:19:06.0525 1132 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
13:19:06.0527 1132 storflt - ok
13:19:06.0629 1132 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
13:19:06.0631 1132 storvsc - ok
13:19:06.0702 1132 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
13:19:06.0703 1132 swenum - ok
13:19:06.0829 1132 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
13:19:06.0861 1132 Tcpip - ok
13:19:07.0018 1132 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
13:19:07.0030 1132 TCPIP6 - ok
13:19:07.0143 1132 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
13:19:07.0144 1132 tcpipreg - ok
13:19:07.0239 1132 TcUsb (7932512d8a34c5675c8f237daf39f66b) C:\Windows\system32\Drivers\tcusb.sys
13:19:07.0241 1132 TcUsb - ok
13:19:07.0336 1132 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
13:19:07.0337 1132 TDPIPE - ok
13:19:07.0366 1132 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
13:19:07.0367 1132 TDTCP - ok
13:19:07.0449 1132 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
13:19:07.0452 1132 tdx - ok
13:19:07.0563 1132 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
13:19:07.0564 1132 TermDD - ok
13:19:07.0625 1132 TPDIGIMN (8e91bec15a2fba05813cb8f924901b03) C:\Windows\system32\DRIVERS\ApsHM64.sys
13:19:07.0626 1132 TPDIGIMN - ok
13:19:07.0746 1132 TPM (dbcc20c02e8a3e43b03c304a4e40a84f) C:\Windows\system32\drivers\tpm.sys
13:19:07.0748 1132 TPM - ok
13:19:07.0789 1132 TPPWRIF (2c067e01d6bbccc88b233b868e210907) C:\Windows\system32\drivers\Tppwr64v.sys
13:19:07.0790 1132 TPPWRIF - ok
13:19:07.0866 1132 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:19:07.0868 1132 tssecsrv - ok
13:19:07.0983 1132 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
13:19:07.0984 1132 TsUsbFlt - ok
13:19:08.0055 1132 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
13:19:08.0058 1132 tunnel - ok
13:19:08.0094 1132 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
13:19:08.0096 1132 uagp35 - ok
13:19:08.0213 1132 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
13:19:08.0219 1132 udfs - ok
13:19:08.0286 1132 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
13:19:08.0288 1132 uliagpkx - ok
13:19:08.0330 1132 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
13:19:08.0332 1132 umbus - ok
13:19:08.0419 1132 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
13:19:08.0420 1132 UmPass - ok
13:19:08.0503 1132 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
13:19:08.0513 1132 usbccgp - ok
13:19:08.0563 1132 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
13:19:08.0566 1132 usbcir - ok
13:19:08.0680 1132 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
13:19:08.0681 1132 usbehci - ok
13:19:08.0725 1132 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
13:19:08.0730 1132 usbhub - ok
13:19:08.0757 1132 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
13:19:08.0758 1132 usbohci - ok
13:19:08.0856 1132 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
13:19:08.0857 1132 usbprint - ok
13:19:08.0919 1132 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:19:08.0921 1132 USBSTOR - ok
13:19:08.0962 1132 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
13:19:08.0964 1132 usbuhci - ok
13:19:09.0074 1132 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\Windows\system32\DRIVERS\usb8023x.sys
13:19:09.0075 1132 usb_rndisx - ok
13:19:09.0124 1132 uwfaxxfb - ok
13:19:09.0253 1132 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
13:19:09.0255 1132 vdrvroot - ok
13:19:09.0314 1132 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
13:19:09.0316 1132 vga - ok
13:19:09.0339 1132 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
13:19:09.0341 1132 VgaSave - ok
13:19:09.0396 1132 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
13:19:09.0401 1132 vhdmp - ok
13:19:09.0519 1132 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
13:19:09.0521 1132 viaide - ok
13:19:09.0569 1132 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
13:19:09.0573 1132 vmbus - ok
13:19:09.0602 1132 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
13:19:09.0603 1132 VMBusHID - ok
13:19:09.0627 1132 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
13:19:09.0629 1132 volmgr - ok
13:19:09.0736 1132 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
13:19:09.0742 1132 volmgrx - ok
13:19:09.0805 1132 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
13:19:09.0811 1132 volsnap - ok
13:19:09.0911 1132 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
13:19:09.0914 1132 vsmraid - ok
13:19:09.0947 1132 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
13:19:09.0948 1132 vwifibus - ok
13:19:09.0988 1132 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
13:19:09.0990 1132 WacomPen - ok
13:19:10.0084 1132 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:19:10.0086 1132 WANARP - ok
13:19:10.0101 1132 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:19:10.0102 1132 Wanarpv6 - ok
13:19:10.0192 1132 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
13:19:10.0193 1132 Wd - ok
13:19:10.0303 1132 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
13:19:10.0313 1132 Wdf01000 - ok
13:19:10.0427 1132 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
13:19:10.0429 1132 WfpLwf - ok
13:19:10.0456 1132 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
13:19:10.0457 1132 WIMMount - ok
13:19:10.0613 1132 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
13:19:10.0614 1132 WinUsb - ok
13:19:10.0658 1132 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
13:19:10.0658 1132 WmiAcpi - ok
13:19:10.0716 1132 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
13:19:10.0718 1132 ws2ifsl - ok
13:19:10.0831 1132 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
13:19:10.0833 1132 WudfPf - ok
13:19:10.0877 1132 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:19:10.0880 1132 WUDFRd - ok
13:19:10.0921 1132 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:19:10.0983 1132 \Device\Harddisk0\DR0 - ok
13:19:10.0986 1132 Boot (0x1200) (e2be9c0672d6c2b1900624d67601729b) \Device\Harddisk0\DR0\Partition0
13:19:10.0988 1132 \Device\Harddisk0\DR0\Partition0 - ok
13:19:11.0011 1132 Boot (0x1200) (a6bcf21f2978f4a8ae22bfbff8934783) \Device\Harddisk0\DR0\Partition1
13:19:11.0011 1132 \Device\Harddisk0\DR0\Partition1 - ok
13:19:11.0014 1132 ============================================================
13:19:11.0014 1132 Scan finished
13:19:11.0014 1132 ============================================================
13:19:11.0027 1644 Detected object count: 1
13:19:11.0027 1644 Actual detected object count: 1
13:20:06.0575 1644 sptd ( LockedFile.Multi.Generic ) - skipped by user
13:20:06.0575 1644 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
- Mc_Murphy
- VIP in memoriam

- Příspěvky: 6706
- Registrován: 03 Lis 2008 15:55
- Místo/Bydliště: Plzeň [ZČ]
- Kontaktovat uživatele:
Re: Facebook virus
OK, provedl jsi to správně. 
Postup s baťákem jsem měl samozřejmě také v záloze, vím o něm. 
Kolega Stell si Tě tedy převezme, když už tu do toho vstoupil. 
- Pavuk29
- VIP in memoriam

- Příspěvky: 6952
- Registrován: 31 Říj 2003 08:26
- Místo/Bydliště: Banská Bystrica
- Kontaktovat uživatele:
Re: Facebook virus
Chlapi, nelezte si do kapustystell napsal:Ak mozem,, sprav takto,
1:Prikaz zadaj do prikazoveho riadku, tak ako tu to mam napisane, alebo s[rav batak.
Prikazovy riadok
------------------------------------------------------------------------------------------------------------------------------
PLS NEPISTE MI SZ, NA ICQ A MAILY S OTAZKAMI, PISTE DO FORA

------------------------------------------------------------------------------------------------------------------------------
V pripadne akutnych problemov s chodom fora,
pripadne s inymi uzivatelmi,
kontaktujte ma na ICQ alebo mailom
na pavuk29 zavinac forum.viry.cz. Byvam pri pocitaci casto aj ked nie som online na fore.
http://www.icq.com/people/267560078/
hotline: http://forum.viry.cz/viewtopic.php?f=12&t=116821
pravidla fora: http://forum.viry.cz/viewtopic.php?f=12&t=5601
------------------------------------------------------------------------------------------------------------------------------
V pripadne akutnych problemov s chodom fora,
http://www.icq.com/people/267560078/
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Facebook virus
Ok, pokracujes somnou,,
mas tam kopec Rootkit driverov, vloz sem log z combofixu.
http://www.bleepingcomputer.com/combofi ... t-combofix
mas tam kopec Rootkit driverov, vloz sem log z combofixu.
http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Facebook virus
ComboFix 12-01-10.02 - Masrtin Šrut 11.01.2012 17:22:39.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2375 [GMT 1:00]
Spuštěný z: c:\users\Masrtin Šrut\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\defaults\preferences\prefs.js
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\chrome.manifest
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\chrome\scanquery.jar
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\install.rdf
c:\program files (x86)\QIP 2010\Core\MousePhone.dll
c:\program files (x86)\ShopperReports3
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\CmndFF.dll
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.dll
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.xpt
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome.manifest
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\install.rdf
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\link.ico
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\CmndFF.dll
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.dll
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.xpt
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\chrome.manifest
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\install.rdf
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\link.ico
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\About Us.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\Customer Support.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\ShopperReports Uninstall Instructions.lnk
c:\programdata\TorrentEasy\fdmbtsupp.dll
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\winnt
c:\windows\SysWow64\winnt\atl.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-11 do 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-11 08:15 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 08:15 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 08:15 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 08:15 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 08:14 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 08:14 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 08:14 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 08:14 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 14:07 . 2012-01-10 14:07 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-01-10 12:37 . 2012-01-10 22:47 -------- d-----w- c:\program files\trend micro
2012-01-10 12:37 . 2012-01-10 12:37 -------- d-----w- C:\rsit
2012-01-08 14:09 . 2012-01-08 14:09 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-08 14:09 . 2012-01-08 14:09 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-08 14:09 . 2012-01-08 14:09 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-08 14:09 . 2012-01-08 14:09 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-07 17:29 . 2012-01-07 17:29 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Graboid
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\programdata\Graboid Inc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Geckofx
2012-01-02 21:44 . 2012-01-10 14:06 -------- d-----w- c:\program files (x86)\Graboid
2011-12-26 12:23 . 2011-12-28 13:54 -------- d-----w- C:\WinSetupFromUSB
2011-12-26 12:18 . 2011-12-26 12:21 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 18:10 . 2011-12-25 18:18 -------- d---a-w- C:\makebootable
2011-12-18 09:44 . 2011-12-18 09:44 -------- d-----w- c:\windows\system32\SPReview
2011-12-18 09:09 . 2011-12-18 09:09 -------- d-----w- c:\windows\system32\EventProviders
2011-12-15 14:26 . 2011-12-15 14:26 20480 ----a-w- c:\windows\SysWow64\maplecompat.dll
2011-12-15 14:26 . 2011-12-15 14:26 40960 ----a-w- c:\windows\SysWow64\maplec.dll
2011-12-15 14:26 . 2011-12-15 14:26 212992 ----a-w- c:\windows\SysWow64\WMIMPLEX.dll
2011-12-15 14:26 . 2011-12-15 14:26 -------- d-----w- C:\watcom-1.3
2011-12-15 14:23 . 2011-12-15 14:27 -------- d-----w- c:\program files (x86)\Maple 12
2011-12-15 14:23 . 2011-12-15 14:26 -------- d--h--w- c:\program files (x86)\Zero G Registry
2011-12-15 07:20 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 07:20 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 07:20 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 07:20 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 07:20 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 09:57 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-18 09:57 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-10-26 14:38 . 2011-05-30 20:11 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe" [2009-07-23 185688]
"LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-07-23 124248]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-07-28 875808]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2009-07-01 37888]
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2009-12-11 198160]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-2-17 1083680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 ctojhfpr;ctojhfpr;c:\windows\system32\drivers\ctojhfpr.sys [x]
R1 ghqmnmzn;ghqmnmzn;c:\windows\system32\drivers\ghqmnmzn.sys [x]
R1 otlezioe;otlezioe;c:\windows\system32\drivers\otlezioe.sys [x]
R1 uwfaxxfb;uwfaxxfb;c:\windows\system32\drivers\uwfaxxfb.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 ApRunSvc;Alps Application Launcher Service;c:\program files\Apoint2K\ApRunSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [x]
S2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
S2 UpekSrvc;Upek Service;c:\program files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [x]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2011-12-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
2012-01-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2009-03-05 228128]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 109608]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"nwiz"="nwiz.exe" [2009-08-26 1712672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-05 16336488]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-13 36864]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-09-09 245760]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"EPSON Stylus DX6000 Series"="c:\windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.EXE" [2006-02-13 131072]
"combofix"="c:\combofix\CF22173.3XE" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://startsear.ch/?aff=2&cf=b044dd4c-2376-11e1-a473-001c259274bf
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
TCP: Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} - hxxp://mhd.frag.cz/loadgame_et.cab
FF - ProfilePath - c:\users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\
FF - prefs.js: browser.search.selectedEngine - Google CZ
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q=
.
.
------- Asociace souborů -------
.
txtfile=c:\windows\NOTEPAD.EXE %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-TorrentEasy_a947c5ada5068d58c8fd584efffe15d34926567a - c:\users\Masrtin Šrut\Downloads\TorrentEasy-cadence-orcad-v16-3-shooters.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{184E4FA0-DE8C26D4-06000000}_0]
"ImagePath"="\??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
c:\program files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\Lenovo\Access Connections\AcSvc.exe
c:\program files (x86)\Lenovo\System Update\SUService.exe
c:\cadence\LicenseManager\cdslmd.exe
c:\program files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
c:\program files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
c:\program files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
c:\windows\SysWOW64\rundll32.exe
.
**************************************************************************
.
Celkový čas: 2012-01-11 17:41:17 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-11 16:41
.
Před spuštěním: Volných bajtů: 16 062 935 040
Po spuštění: Volných bajtů: 15 026 085 888
.
- - End Of File - - 919C27D5C190B3397987AB67858D8834
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2375 [GMT 1:00]
Spuštěný z: c:\users\Masrtin Šrut\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\defaults\preferences\prefs.js
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\chrome.manifest
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\chrome\scanquery.jar
c:\program files (x86)\Mozilla Firefox\extensions\{DE9265D8-D55D-4286-9DC4-F8D8A0CA2F64}\install.rdf
c:\program files (x86)\QIP 2010\Core\MousePhone.dll
c:\program files (x86)\ShopperReports3
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\CmndFF.dll
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.dll
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.xpt
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome.manifest
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\install.rdf
c:\program files (x86)\ShopperReports3\bin\3.1.69.0\link.ico
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\CmndFF.dll
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.dll
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\components\BrowserExtensionFF.xpt
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\chrome.manifest
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\firefox\firefoxtoolbar\extensions\install.rdf
c:\program files (x86)\ShopperReports3\bin\3.2.11.0\link.ico
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\About Us.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\Customer Support.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ShopperReports\ShopperReports Uninstall Instructions.lnk
c:\programdata\TorrentEasy\fdmbtsupp.dll
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\SysWow64\winnt
c:\windows\SysWow64\winnt\atl.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-11 do 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-11 08:15 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 08:15 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 08:15 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 08:15 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 08:14 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 08:14 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 08:14 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 08:14 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 14:07 . 2012-01-10 14:07 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-01-10 12:37 . 2012-01-10 22:47 -------- d-----w- c:\program files\trend micro
2012-01-10 12:37 . 2012-01-10 12:37 -------- d-----w- C:\rsit
2012-01-08 14:09 . 2012-01-08 14:09 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-08 14:09 . 2012-01-08 14:09 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-08 14:09 . 2012-01-08 14:09 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-08 14:09 . 2012-01-08 14:09 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-07 17:29 . 2012-01-07 17:29 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Graboid
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\programdata\Graboid Inc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Geckofx
2012-01-02 21:44 . 2012-01-10 14:06 -------- d-----w- c:\program files (x86)\Graboid
2011-12-26 12:23 . 2011-12-28 13:54 -------- d-----w- C:\WinSetupFromUSB
2011-12-26 12:18 . 2011-12-26 12:21 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 18:10 . 2011-12-25 18:18 -------- d---a-w- C:\makebootable
2011-12-18 09:44 . 2011-12-18 09:44 -------- d-----w- c:\windows\system32\SPReview
2011-12-18 09:09 . 2011-12-18 09:09 -------- d-----w- c:\windows\system32\EventProviders
2011-12-15 14:26 . 2011-12-15 14:26 20480 ----a-w- c:\windows\SysWow64\maplecompat.dll
2011-12-15 14:26 . 2011-12-15 14:26 40960 ----a-w- c:\windows\SysWow64\maplec.dll
2011-12-15 14:26 . 2011-12-15 14:26 212992 ----a-w- c:\windows\SysWow64\WMIMPLEX.dll
2011-12-15 14:26 . 2011-12-15 14:26 -------- d-----w- C:\watcom-1.3
2011-12-15 14:23 . 2011-12-15 14:27 -------- d-----w- c:\program files (x86)\Maple 12
2011-12-15 14:23 . 2011-12-15 14:26 -------- d--h--w- c:\program files (x86)\Zero G Registry
2011-12-15 07:20 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 07:20 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 07:20 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 07:20 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 07:20 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 09:57 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-18 09:57 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-10-26 14:38 . 2011-05-30 20:11 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe" [2009-07-23 185688]
"LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-07-23 124248]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-07-28 875808]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2009-07-01 37888]
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2009-12-11 198160]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-2-17 1083680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 ctojhfpr;ctojhfpr;c:\windows\system32\drivers\ctojhfpr.sys [x]
R1 ghqmnmzn;ghqmnmzn;c:\windows\system32\drivers\ghqmnmzn.sys [x]
R1 otlezioe;otlezioe;c:\windows\system32\drivers\otlezioe.sys [x]
R1 uwfaxxfb;uwfaxxfb;c:\windows\system32\drivers\uwfaxxfb.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 ApRunSvc;Alps Application Launcher Service;c:\program files\Apoint2K\ApRunSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [x]
S2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
S2 UpekSrvc;Upek Service;c:\program files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [x]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2011-12-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
2012-01-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2009-03-05 228128]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 109608]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"nwiz"="nwiz.exe" [2009-08-26 1712672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-05 16336488]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-13 36864]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-09-09 245760]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"EPSON Stylus DX6000 Series"="c:\windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.EXE" [2006-02-13 131072]
"combofix"="c:\combofix\CF22173.3XE" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://startsear.ch/?aff=2&cf=b044dd4c-2376-11e1-a473-001c259274bf
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
TCP: Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} - hxxp://mhd.frag.cz/loadgame_et.cab
FF - ProfilePath - c:\users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\
FF - prefs.js: browser.search.selectedEngine - Google CZ
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q=
.
.
------- Asociace souborů -------
.
txtfile=c:\windows\NOTEPAD.EXE %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-TorrentEasy_a947c5ada5068d58c8fd584efffe15d34926567a - c:\users\Masrtin Šrut\Downloads\TorrentEasy-cadence-orcad-v16-3-shooters.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{184E4FA0-DE8C26D4-06000000}_0]
"ImagePath"="\??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
c:\program files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files (x86)\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\Lenovo\Access Connections\AcSvc.exe
c:\program files (x86)\Lenovo\System Update\SUService.exe
c:\cadence\LicenseManager\cdslmd.exe
c:\program files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
c:\program files (x86)\ThinkVantage\PrdCtr\LPMGR.EXE
c:\program files (x86)\ThinkVantage\PrdCtr\LPMLCHK.EXE
c:\windows\SysWOW64\rundll32.exe
.
**************************************************************************
.
Celkový čas: 2012-01-11 17:41:17 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-11 16:41
.
Před spuštěním: Volných bajtů: 16 062 935 040
Po spuštění: Volných bajtů: 15 026 085 888
.
- - End Of File - - 919C27D5C190B3397987AB67858D8834
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Facebook virus
Pri tejto akcii je nutné mať ComboFix na ploche.
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log čo ComboFix vytvori.
Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.
Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:
Kód: Vybrat vše
KILLALL::
Driver::
ctojhfpr
ghqmnmzn
otlezioe
uwfaxxfb
Rootkit::
c:\windows\system32\drivers\ctojhfpr.sys
c:\windows\system32\drivers\ghqmnmzn.sys
c:\windows\system32\drivers\otlezioe.sys
c:\windows\system32\drivers\uwfaxxfb.sys
DDS::
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://startsear.ch/?aff=2&cf=b044dd4c- ... 1c259274bf
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
Extra::
FireFox::
FF - ProfilePath - c:\users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q=
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
ClearJavaCache::
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho na plochu> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :

Po skonceni skenu vlož log čo ComboFix vytvori.
Re: Facebook virus
ComboFix 12-01-10.02 - Masrtin Šrut 11.01.2012 18:21:12.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2636 [GMT 1:00]
Spuštěný z: c:\users\Masrtin Őrut\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Masrtin Őrut\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-11 do 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-11 17:51 . 2012-01-11 17:51 -------- d-----w- c:\users\MASRTI~2\AppData\Local\temp
2012-01-11 17:51 . 2012-01-11 17:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-11 16:58 . 2012-01-11 16:57 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7001843-A239-4445-B629-753F8079BB5F}\gapaengine.dll
2012-01-11 16:58 . 2012-01-11 16:58 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8EEC6C3A-A354-4AF7-ABEC-9C9EBB7E2099}\offreg.dll
2012-01-11 16:57 . 2011-11-21 02:40 8822856 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8EEC6C3A-A354-4AF7-ABEC-9C9EBB7E2099}\mpengine.dll
2012-01-11 16:51 . 2012-01-11 16:51 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-01-11 16:51 . 2012-01-11 16:52 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-11 16:49 . 2012-01-11 16:49 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2012-01-11 16:49 . 2012-01-11 16:49 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2012-01-11 16:49 . 2012-01-11 16:49 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2012-01-11 16:49 . 2012-01-11 16:49 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2012-01-11 08:15 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 08:15 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 08:15 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 08:15 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 08:14 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 08:14 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 08:14 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 08:14 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 14:07 . 2012-01-10 14:07 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-01-10 12:37 . 2012-01-10 22:47 -------- d-----w- c:\program files\trend micro
2012-01-10 12:37 . 2012-01-10 12:37 -------- d-----w- C:\rsit
2012-01-08 14:09 . 2012-01-08 14:09 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-08 14:09 . 2012-01-08 14:09 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-08 14:09 . 2012-01-08 14:09 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-08 14:09 . 2012-01-08 14:09 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-07 17:29 . 2012-01-07 17:29 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Graboid
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\programdata\Graboid Inc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Geckofx
2012-01-02 21:44 . 2012-01-10 14:06 -------- d-----w- c:\program files (x86)\Graboid
2011-12-26 12:23 . 2011-12-28 13:54 -------- d-----w- C:\WinSetupFromUSB
2011-12-26 12:18 . 2011-12-26 12:21 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 18:10 . 2011-12-25 18:18 -------- d---a-w- C:\makebootable
2011-12-18 09:44 . 2011-12-18 09:44 -------- d-----w- c:\windows\system32\SPReview
2011-12-18 09:09 . 2011-12-18 09:09 -------- d-----w- c:\windows\system32\EventProviders
2011-12-15 14:26 . 2011-12-15 14:26 20480 ----a-w- c:\windows\SysWow64\maplecompat.dll
2011-12-15 14:26 . 2011-12-15 14:26 40960 ----a-w- c:\windows\SysWow64\maplec.dll
2011-12-15 14:26 . 2011-12-15 14:26 212992 ----a-w- c:\windows\SysWow64\WMIMPLEX.dll
2011-12-15 14:26 . 2011-12-15 14:26 -------- d-----w- C:\watcom-1.3
2011-12-15 14:23 . 2011-12-15 14:27 -------- d-----w- c:\program files (x86)\Maple 12
2011-12-15 14:23 . 2011-12-15 14:26 -------- d--h--w- c:\program files (x86)\Zero G Registry
2011-12-15 07:20 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 07:20 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 07:20 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 07:20 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 07:20 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 09:57 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-18 09:57 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-10-26 14:38 . 2011-05-30 20:11 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-11_16.35.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-10 10:37 . 2012-01-11 16:51 48354 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-11 16:51 49888 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-10-10 10:29 . 2012-01-11 16:51 18268 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2007378548-3922879206-3042236909-1000_UserData.bin
+ 2011-04-27 14:25 . 2011-04-27 14:25 84864 c:\windows\system32\drivers\NisDrvWFP.sys
+ 2011-04-18 12:18 . 2011-04-18 12:18 40832 c:\windows\system32\drivers\MpNWMon.sys
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-15 16:03 . 2012-01-11 16:50 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 16:50 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 16:50 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-10 11:19 . 2012-01-11 17:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-10 11:19 . 2012-01-11 17:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 75264 c:\windows\Installer\23616.msi
+ 2011-06-15 13:55 . 2011-06-15 13:55 32256 c:\windows\Installer\23609.msi
+ 2009-10-16 13:01 . 2012-01-11 16:48 3636 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-01-11 16:49 . 2012-01-11 16:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-11 16:49 . 2012-01-11 16:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-01-11 16:51 618370 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 633654 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-11 16:51 107650 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 123176 c:\windows\system32\perfc005.dat
+ 2011-04-18 12:18 . 2011-04-18 12:18 189440 c:\windows\system32\drivers\MpFilter.sys
+ 2009-07-14 04:46 . 2012-01-11 16:44 104400 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-07-14 05:01 . 2012-01-11 16:48 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-01-11 16:32 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-10-10 12:42 . 2012-01-11 16:48 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-10-10 12:42 . 2012-01-11 16:32 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-03-30 21:18 . 2012-01-11 11:50 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
+ 2011-03-30 21:18 . 2012-01-11 16:48 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 2708992 c:\windows\Installer\2360f.msi
+ 2011-06-15 13:51 . 2011-06-15 13:51 1911808 c:\windows\Installer\23602.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe" [2009-07-23 185688]
"LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-07-23 124248]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-07-28 875808]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2009-07-01 37888]
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2009-12-11 198160]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-2-17 1083680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 ctojhfpr;ctojhfpr;c:\windows\system32\drivers\ctojhfpr.sys [x]
R1 ghqmnmzn;ghqmnmzn;c:\windows\system32\drivers\ghqmnmzn.sys [x]
R1 otlezioe;otlezioe;c:\windows\system32\drivers\otlezioe.sys [x]
R1 uwfaxxfb;uwfaxxfb;c:\windows\system32\drivers\uwfaxxfb.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 ApRunSvc;Alps Application Launcher Service;c:\program files\Apoint2K\ApRunSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [x]
S2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
S2 UpekSrvc;Upek Service;c:\program files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [x]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPFILTER
*NewlyCreated* - MPNWMON
*NewlyCreated* - NISDRV
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2011-12-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
2012-01-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2009-03-05 228128]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 109608]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"nwiz"="nwiz.exe" [2009-08-26 1712672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-05 16336488]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-13 36864]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-09-09 245760]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"EPSON Stylus DX6000 Series"="c:\windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.EXE" [2006-02-13 131072]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://startsear.ch/?aff=2&cf=b044dd4c-2376-11e1-a473-001c259274bf
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
TCP: Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} - hxxp://mhd.frag.cz/loadgame_et.cab
FF - ProfilePath - c:\users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\
FF - prefs.js: browser.search.selectedEngine - Google CZ
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q=
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{184E4FA0-DE8C26D4-06000000}_0]
"ImagePath"="\??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-01-11 18:53:48
ComboFix-quarantined-files.txt 2012-01-11 17:53
ComboFix2.txt 2012-01-11 16:41
.
Před spuštěním: Volných bajtů: 17 792 458 752
Po spuštění: Volných bajtů: 17 493 291 008
.
- - End Of File - - EDA98AD9D31B85AC27299FBE67AA05E5
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.2636 [GMT 1:00]
Spuštěný z: c:\users\Masrtin Őrut\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Masrtin Őrut\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-11 do 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-11 17:51 . 2012-01-11 17:51 -------- d-----w- c:\users\MASRTI~2\AppData\Local\temp
2012-01-11 17:51 . 2012-01-11 17:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-11 16:58 . 2012-01-11 16:57 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7001843-A239-4445-B629-753F8079BB5F}\gapaengine.dll
2012-01-11 16:58 . 2012-01-11 16:58 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8EEC6C3A-A354-4AF7-ABEC-9C9EBB7E2099}\offreg.dll
2012-01-11 16:57 . 2011-11-21 02:40 8822856 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8EEC6C3A-A354-4AF7-ABEC-9C9EBB7E2099}\mpengine.dll
2012-01-11 16:51 . 2012-01-11 16:51 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-01-11 16:51 . 2012-01-11 16:52 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-11 16:49 . 2012-01-11 16:49 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2012-01-11 16:49 . 2012-01-11 16:49 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2012-01-11 16:49 . 2012-01-11 16:49 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2012-01-11 16:49 . 2012-01-11 16:49 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2012-01-11 08:15 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 08:15 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 08:15 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 08:15 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 08:14 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 08:14 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 08:14 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 08:14 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 14:07 . 2012-01-10 14:07 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-01-10 12:37 . 2012-01-10 22:47 -------- d-----w- c:\program files\trend micro
2012-01-10 12:37 . 2012-01-10 12:37 -------- d-----w- C:\rsit
2012-01-08 14:09 . 2012-01-08 14:09 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-08 14:09 . 2012-01-08 14:09 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-08 14:09 . 2012-01-08 14:09 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-08 14:09 . 2012-01-08 14:09 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-07 17:29 . 2012-01-07 17:29 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Graboid
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\programdata\Graboid Inc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Geckofx
2012-01-02 21:44 . 2012-01-10 14:06 -------- d-----w- c:\program files (x86)\Graboid
2011-12-26 12:23 . 2011-12-28 13:54 -------- d-----w- C:\WinSetupFromUSB
2011-12-26 12:18 . 2011-12-26 12:21 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 18:10 . 2011-12-25 18:18 -------- d---a-w- C:\makebootable
2011-12-18 09:44 . 2011-12-18 09:44 -------- d-----w- c:\windows\system32\SPReview
2011-12-18 09:09 . 2011-12-18 09:09 -------- d-----w- c:\windows\system32\EventProviders
2011-12-15 14:26 . 2011-12-15 14:26 20480 ----a-w- c:\windows\SysWow64\maplecompat.dll
2011-12-15 14:26 . 2011-12-15 14:26 40960 ----a-w- c:\windows\SysWow64\maplec.dll
2011-12-15 14:26 . 2011-12-15 14:26 212992 ----a-w- c:\windows\SysWow64\WMIMPLEX.dll
2011-12-15 14:26 . 2011-12-15 14:26 -------- d-----w- C:\watcom-1.3
2011-12-15 14:23 . 2011-12-15 14:27 -------- d-----w- c:\program files (x86)\Maple 12
2011-12-15 14:23 . 2011-12-15 14:26 -------- d--h--w- c:\program files (x86)\Zero G Registry
2011-12-15 07:20 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 07:20 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 07:20 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 07:20 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 07:20 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 09:57 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-18 09:57 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-10-26 14:38 . 2011-05-30 20:11 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-11_16.35.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-10 10:37 . 2012-01-11 16:51 48354 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-11 16:51 49888 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-10-10 10:29 . 2012-01-11 16:51 18268 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2007378548-3922879206-3042236909-1000_UserData.bin
+ 2011-04-27 14:25 . 2011-04-27 14:25 84864 c:\windows\system32\drivers\NisDrvWFP.sys
+ 2011-04-18 12:18 . 2011-04-18 12:18 40832 c:\windows\system32\drivers\MpNWMon.sys
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-15 16:03 . 2012-01-11 16:50 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 16:50 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 16:50 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-10 11:19 . 2012-01-11 17:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-10 11:19 . 2012-01-11 17:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 75264 c:\windows\Installer\23616.msi
+ 2011-06-15 13:55 . 2011-06-15 13:55 32256 c:\windows\Installer\23609.msi
+ 2009-10-16 13:01 . 2012-01-11 16:48 3636 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-01-11 16:49 . 2012-01-11 16:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-11 16:49 . 2012-01-11 16:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-01-11 16:51 618370 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 633654 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-11 16:51 107650 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 123176 c:\windows\system32\perfc005.dat
+ 2011-04-18 12:18 . 2011-04-18 12:18 189440 c:\windows\system32\drivers\MpFilter.sys
+ 2009-07-14 04:46 . 2012-01-11 16:44 104400 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-07-14 05:01 . 2012-01-11 16:48 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-01-11 16:32 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-10-10 12:42 . 2012-01-11 16:48 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-10-10 12:42 . 2012-01-11 16:32 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-03-30 21:18 . 2012-01-11 11:50 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
+ 2011-03-30 21:18 . 2012-01-11 16:48 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 2708992 c:\windows\Installer\2360f.msi
+ 2011-06-15 13:51 . 2011-06-15 13:51 1911808 c:\windows\Installer\23602.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe" [2009-07-23 185688]
"LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-07-23 124248]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-07-28 875808]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2009-07-01 37888]
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2009-12-11 198160]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-2-17 1083680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 ctojhfpr;ctojhfpr;c:\windows\system32\drivers\ctojhfpr.sys [x]
R1 ghqmnmzn;ghqmnmzn;c:\windows\system32\drivers\ghqmnmzn.sys [x]
R1 otlezioe;otlezioe;c:\windows\system32\drivers\otlezioe.sys [x]
R1 uwfaxxfb;uwfaxxfb;c:\windows\system32\drivers\uwfaxxfb.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 ApRunSvc;Alps Application Launcher Service;c:\program files\Apoint2K\ApRunSvc.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [x]
S2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
S2 UpekSrvc;Upek Service;c:\program files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [x]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPFILTER
*NewlyCreated* - MPNWMON
*NewlyCreated* - NISDRV
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2011-12-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
2012-01-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2009-03-05 228128]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 109608]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"nwiz"="nwiz.exe" [2009-08-26 1712672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-05 16336488]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-13 36864]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-09-09 245760]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 660360]
"EPSON Stylus DX6000 Series"="c:\windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.EXE" [2006-02-13 131072]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://startsear.ch/?aff=2&cf=b044dd4c-2376-11e1-a473-001c259274bf
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
TCP: Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} - hxxp://mhd.frag.cz/loadgame_et.cab
FF - ProfilePath - c:\users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\
FF - prefs.js: browser.search.selectedEngine - Google CZ
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q=
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{184E4FA0-DE8C26D4-06000000}_0]
"ImagePath"="\??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-01-11 18:53:48
ComboFix-quarantined-files.txt 2012-01-11 17:53
ComboFix2.txt 2012-01-11 16:41
.
Před spuštěním: Volných bajtů: 17 792 458 752
Po spuštění: Volných bajtů: 17 493 291 008
.
- - End Of File - - EDA98AD9D31B85AC27299FBE67AA05E5
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: Facebook virus
Mas tam dajaku divnu cestu k combofixu
c:\users\Masrtin Őrut\Desktop\ComboFix.exe
No nic.
Premiestni ikonu combofixu priamo na disk C:\
Restartujes pc do nudzoveho rezimu, a zopakuj akciu s CFScriptom.
CFScript.txt
c:\users\Masrtin Őrut\Desktop\ComboFix.exe
No nic.
Premiestni ikonu combofixu priamo na disk C:\
Restartujes pc do nudzoveho rezimu, a zopakuj akciu s CFScriptom.
CFScript.txt
Re: Facebook virus
ComboFix 12-01-10.02 - Masrtin Šrut 11.01.2012 19:43:44.3.2 - x64 MINIMAL
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.3035 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ctojhfpr
-------\Service_ghqmnmzn
-------\Service_otlezioe
-------\Service_uwfaxxfb
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-11 do 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-11 18:53 . 2012-01-11 18:53 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{977BED12-B411-4114-B9D1-BB8C310AFB2B}\offreg.dll
2012-01-11 18:51 . 2012-01-11 18:51 -------- d-----w- c:\users\MASRTI~2\AppData\Local\temp
2012-01-11 18:51 . 2012-01-11 18:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-11 18:24 . 2012-01-11 18:24 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-01-11 18:16 . 2011-11-21 02:40 8822856 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{977BED12-B411-4114-B9D1-BB8C310AFB2B}\mpengine.dll
2012-01-11 16:58 . 2012-01-11 16:57 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7001843-A239-4445-B629-753F8079BB5F}\gapaengine.dll
2012-01-11 16:51 . 2012-01-11 16:51 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-01-11 16:51 . 2012-01-11 16:52 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-11 08:15 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 08:15 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 08:15 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 08:15 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 08:14 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 08:14 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 08:14 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 08:14 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 14:07 . 2012-01-10 14:07 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-01-10 12:37 . 2012-01-10 22:47 -------- d-----w- c:\program files\trend micro
2012-01-10 12:37 . 2012-01-10 12:37 -------- d-----w- C:\rsit
2012-01-08 14:09 . 2012-01-08 14:09 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-08 14:09 . 2012-01-08 14:09 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-08 14:09 . 2012-01-08 14:09 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-08 14:09 . 2012-01-08 14:09 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-07 17:29 . 2012-01-07 17:29 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Graboid
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\programdata\Graboid Inc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Geckofx
2012-01-02 21:44 . 2012-01-10 14:06 -------- d-----w- c:\program files (x86)\Graboid
2011-12-26 12:23 . 2011-12-28 13:54 -------- d-----w- C:\WinSetupFromUSB
2011-12-26 12:18 . 2011-12-26 12:21 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 18:10 . 2011-12-25 18:18 -------- d---a-w- C:\makebootable
2011-12-18 09:44 . 2011-12-18 09:44 -------- d-----w- c:\windows\system32\SPReview
2011-12-18 09:09 . 2011-12-18 09:09 -------- d-----w- c:\windows\system32\EventProviders
2011-12-15 14:26 . 2011-12-15 14:26 20480 ----a-w- c:\windows\SysWow64\maplecompat.dll
2011-12-15 14:26 . 2011-12-15 14:26 40960 ----a-w- c:\windows\SysWow64\maplec.dll
2011-12-15 14:26 . 2011-12-15 14:26 212992 ----a-w- c:\windows\SysWow64\WMIMPLEX.dll
2011-12-15 14:26 . 2011-12-15 14:26 -------- d-----w- C:\watcom-1.3
2011-12-15 14:23 . 2011-12-15 14:27 -------- d-----w- c:\program files (x86)\Maple 12
2011-12-15 14:23 . 2011-12-15 14:26 -------- d--h--w- c:\program files (x86)\Zero G Registry
2011-12-15 07:20 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 07:20 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 07:20 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 07:20 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 07:20 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 09:57 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-18 09:57 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-10 04:54 . 2011-05-05 09:31 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-10-26 14:38 . 2011-05-30 20:11 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-11_16.35.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-10 10:37 . 2012-01-11 18:37 48752 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-11 18:37 50336 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-10-10 10:29 . 2012-01-11 18:32 18276 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2007378548-3922879206-3042236909-1000_UserData.bin
+ 2011-04-27 14:25 . 2011-04-27 14:25 84864 c:\windows\system32\drivers\NisDrvWFP.sys
+ 2011-04-18 12:18 . 2011-04-18 12:18 40832 c:\windows\system32\drivers\MpNWMon.sys
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-15 16:03 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 18:36 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-10 11:19 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-10 11:19 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 75264 c:\windows\Installer\23616.msi
+ 2011-06-15 13:55 . 2011-06-15 13:55 32256 c:\windows\Installer\23609.msi
+ 2009-10-16 13:01 . 2012-01-11 16:48 3636 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-01-11 18:53 . 2012-01-11 18:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-11 18:53 . 2012-01-11 18:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-11 18:24 . 2011-11-10 04:54 157472 c:\windows\SysWOW64\javaws.exe
+ 2012-01-11 18:24 . 2011-11-10 04:54 149280 c:\windows\SysWOW64\javaw.exe
+ 2012-01-11 18:24 . 2011-11-10 04:54 149280 c:\windows\SysWOW64\java.exe
+ 2009-07-14 02:36 . 2012-01-11 16:51 618370 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 633654 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-11 16:51 107650 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 123176 c:\windows\system32\perfc005.dat
+ 2011-04-18 12:18 . 2011-04-18 12:18 189440 c:\windows\system32\drivers\MpFilter.sys
+ 2009-07-14 04:46 . 2012-01-11 16:44 104400 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2009-07-14 05:01 . 2012-01-11 16:32 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-11 18:39 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-01-11 18:24 . 2012-01-11 18:24 207360 c:\windows\Installer\15b1d9.msi
+ 2009-10-10 12:42 . 2012-01-11 18:39 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-10-10 12:42 . 2012-01-11 16:32 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-03-30 21:18 . 2012-01-11 18:39 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
- 2011-03-30 21:18 . 2012-01-11 11:50 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 2708992 c:\windows\Installer\2360f.msi
+ 2011-06-15 13:51 . 2011-06-15 13:51 1911808 c:\windows\Installer\23602.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe" [2009-07-23 185688]
"LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-07-23 124248]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-07-28 875808]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-2-17 1083680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
R2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
R2 UpekSrvc;Upek Service;c:\program files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 ApRunSvc;Alps Application Launcher Service;c:\program files\Apoint2K\ApRunSvc.exe [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2011-12-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
2012-01-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2009-03-05 228128]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 109608]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"nwiz"="nwiz.exe" [2009-08-26 1712672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-05 16336488]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-13 36864]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-09-09 245760]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
"combofix"="c:\combofix\CF18485.3XE" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"combofix"="c:\combofix\CF18485.3XE" [2010-11-20 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mLocal Page = %SystemRoot%\system32\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
TCP: Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} - hxxp://mhd.frag.cz/loadgame_et.cab
FF - ProfilePath - c:\users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\
FF - prefs.js: browser.search.selectedEngine - Google CZ
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
------- Asociace souborů -------
.
txtfile=c:\windows\NOTEPAD.EXE %1
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{184E4FA0-DE8C26D4-06000000}_0]
"ImagePath"="\??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
.
**************************************************************************
.
Celkový čas: 2012-01-11 19:58:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-11 18:58
ComboFix2.txt 2012-01-11 17:53
ComboFix3.txt 2012-01-11 16:41
.
Před spuštěním: Volných bajtů: 18 277 769 216
Po spuštění: Volných bajtů: 18 055 286 784
.
- - End Of File - - F14BF4114B0D39C482EA4F414C3524CA
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.4094.3035 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ctojhfpr
-------\Service_ghqmnmzn
-------\Service_otlezioe
-------\Service_uwfaxxfb
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-11 do 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-11 18:53 . 2012-01-11 18:53 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{977BED12-B411-4114-B9D1-BB8C310AFB2B}\offreg.dll
2012-01-11 18:51 . 2012-01-11 18:51 -------- d-----w- c:\users\MASRTI~2\AppData\Local\temp
2012-01-11 18:51 . 2012-01-11 18:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-11 18:24 . 2012-01-11 18:24 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-01-11 18:16 . 2011-11-21 02:40 8822856 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{977BED12-B411-4114-B9D1-BB8C310AFB2B}\mpengine.dll
2012-01-11 16:58 . 2012-01-11 16:57 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C7001843-A239-4445-B629-753F8079BB5F}\gapaengine.dll
2012-01-11 16:51 . 2012-01-11 16:51 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-01-11 16:51 . 2012-01-11 16:52 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-11 08:15 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 08:15 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 08:15 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 08:15 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 08:14 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 08:14 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 08:14 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 08:14 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-10 14:07 . 2012-01-10 14:07 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-01-10 12:37 . 2012-01-10 22:47 -------- d-----w- c:\program files\trend micro
2012-01-10 12:37 . 2012-01-10 12:37 -------- d-----w- C:\rsit
2012-01-08 14:09 . 2012-01-08 14:09 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-08 14:09 . 2012-01-08 14:09 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-08 14:09 . 2012-01-08 14:09 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-08 14:09 . 2012-01-08 14:09 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-07 17:29 . 2012-01-07 17:29 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\avidemux
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\vlc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Graboid
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\programdata\Graboid Inc
2012-01-02 21:57 . 2012-01-02 21:57 -------- d-----w- c:\users\Masrtin Šrut\AppData\Local\Geckofx
2012-01-02 21:44 . 2012-01-10 14:06 -------- d-----w- c:\program files (x86)\Graboid
2011-12-26 12:23 . 2011-12-28 13:54 -------- d-----w- C:\WinSetupFromUSB
2011-12-26 12:18 . 2011-12-26 12:21 -------- d-----w- c:\users\Masrtin Šrut\AppData\Roaming\Ipswitch
2011-12-25 18:10 . 2011-12-25 18:18 -------- d---a-w- C:\makebootable
2011-12-18 09:44 . 2011-12-18 09:44 -------- d-----w- c:\windows\system32\SPReview
2011-12-18 09:09 . 2011-12-18 09:09 -------- d-----w- c:\windows\system32\EventProviders
2011-12-15 14:26 . 2011-12-15 14:26 20480 ----a-w- c:\windows\SysWow64\maplecompat.dll
2011-12-15 14:26 . 2011-12-15 14:26 40960 ----a-w- c:\windows\SysWow64\maplec.dll
2011-12-15 14:26 . 2011-12-15 14:26 212992 ----a-w- c:\windows\SysWow64\WMIMPLEX.dll
2011-12-15 14:26 . 2011-12-15 14:26 -------- d-----w- C:\watcom-1.3
2011-12-15 14:23 . 2011-12-15 14:27 -------- d-----w- c:\program files (x86)\Maple 12
2011-12-15 14:23 . 2011-12-15 14:26 -------- d--h--w- c:\program files (x86)\Zero G Registry
2011-12-15 07:20 . 2011-11-24 04:52 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 07:20 . 2011-10-15 06:31 723456 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 07:20 . 2011-10-15 05:38 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 07:20 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 07:20 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 09:57 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-12-18 09:57 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-10 04:54 . 2011-05-05 09:31 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-10-26 14:38 . 2011-05-30 20:11 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-11_16.35.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-10 10:37 . 2012-01-11 18:37 48752 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-11 18:37 50336 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-10-10 10:29 . 2012-01-11 18:32 18276 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2007378548-3922879206-3042236909-1000_UserData.bin
+ 2011-04-27 14:25 . 2011-04-27 14:25 84864 c:\windows\system32\drivers\NisDrvWFP.sys
+ 2011-04-18 12:18 . 2011-04-18 12:18 40832 c:\windows\system32\drivers\MpNWMon.sys
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-12-15 16:03 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 18:36 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-15 16:03 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-12-15 16:03 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-10 11:19 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-10 11:19 . 2012-01-11 16:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-10 11:19 . 2012-01-11 18:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 75264 c:\windows\Installer\23616.msi
+ 2011-06-15 13:55 . 2011-06-15 13:55 32256 c:\windows\Installer\23609.msi
+ 2009-10-16 13:01 . 2012-01-11 16:48 3636 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-01-11 18:53 . 2012-01-11 18:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-11 18:53 . 2012-01-11 18:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-11 16:33 . 2012-01-11 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-11 18:24 . 2011-11-10 04:54 157472 c:\windows\SysWOW64\javaws.exe
+ 2012-01-11 18:24 . 2011-11-10 04:54 149280 c:\windows\SysWOW64\javaw.exe
+ 2012-01-11 18:24 . 2011-11-10 04:54 149280 c:\windows\SysWOW64\java.exe
+ 2009-07-14 02:36 . 2012-01-11 16:51 618370 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 633654 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-11 16:51 107650 c:\windows\system32\perfc009.dat
+ 2009-07-14 15:18 . 2012-01-11 16:51 123176 c:\windows\system32\perfc005.dat
+ 2011-04-18 12:18 . 2011-04-18 12:18 189440 c:\windows\system32\drivers\MpFilter.sys
+ 2009-07-14 04:46 . 2012-01-11 16:44 104400 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2009-07-14 05:01 . 2012-01-11 16:32 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-11 18:39 274604 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-01-11 18:24 . 2012-01-11 18:24 207360 c:\windows\Installer\15b1d9.msi
+ 2009-10-10 12:42 . 2012-01-11 18:39 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-10-10 12:42 . 2012-01-11 16:32 3264672 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-03-30 21:18 . 2012-01-11 18:39 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
- 2011-03-30 21:18 . 2012-01-11 11:50 1074580 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2007378548-3922879206-3042236909-1000-12288.dat
+ 2011-05-19 16:23 . 2011-05-19 16:23 2708992 c:\windows\Installer\2360f.msi
+ 2011-06-15 13:51 . 2011-06-15 13:51 1911808 c:\windows\Installer\23602.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"TVT Scheduler Proxy"="c:\program files (x86)\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"LPManager"="c:\progra~2\THINKV~1\PrdCtr\LPMGR.exe" [2009-07-23 185688]
"LPMailChecker"="c:\progra~2\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-07-23 124248]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2009-07-28 875808]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-2-17 1083680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
R2 Cadence License Manager;Cadence License Manager;c:\cadence\LicenseManager\lmgrd.exe [2007-10-12 1370752]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2009-07-03 45424]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
R2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2009-07-15 62320]
R2 UpekSrvc;Upek Service;c:\program files\ThinkVantage Fingerprint Software\upeksrvc.exe [2009-05-21 54536]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 136176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\nmwcdx64.sys [x]
R3 PCDSRVC{127174DC-C366ED8B-06000000}_0;PCDSRVC{127174DC-C366ED8B-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0;PCDSRVC{184E4FA0-DE8C26D4-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2009-08-18 23536]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2009-07-28 75040]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 ApRunSvc;Alps Application Launcher Service;c:\program files\Apoint2K\ApRunSvc.exe [x]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2012-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-04 20:15]
.
2011-12-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
2012-01-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdr5cuiw32.exe [2009-10-08 21:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2009-03-05 228128]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 109608]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"nwiz"="nwiz.exe" [2009-08-26 1712672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-05 16336488]
"AcWin7Hlpr"="c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe" [2009-10-13 36864]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-09-09 245760]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
"combofix"="c:\combofix\CF18485.3XE" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"combofix"="c:\combofix\CF18485.3XE" [2010-11-20 345088]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://seznam.cz/
mLocal Page = %SystemRoot%\system32\blank.htm
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
TCP: Interfaces\{7645D7F5-53DA-482C-811D-CB8D530BB609}: NameServer = 10.20.100.1
DPF: {26ACAE6F-BC95-44B4-9150-61E4D20D5C2E} - hxxp://mhd.frag.cz/loadgame_et.cab
FF - ProfilePath - c:\users\Masrtin Šrut\AppData\Roaming\Mozilla\Firefox\Profiles\1niyqzh9.default\
FF - prefs.js: browser.search.selectedEngine - Google CZ
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
.
------- Asociace souborů -------
.
txtfile=c:\windows\NOTEPAD.EXE %1
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06000000}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{184E4FA0-DE8C26D4-06000000}_0]
"ImagePath"="\??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe
.
**************************************************************************
.
Celkový čas: 2012-01-11 19:58:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-11 18:58
ComboFix2.txt 2012-01-11 17:53
ComboFix3.txt 2012-01-11 16:41
.
Před spuštěním: Volných bajtů: 18 277 769 216
Po spuštění: Volných bajtů: 18 055 286 784
.
- - End Of File - - F14BF4114B0D39C482EA4F414C3524CA






Přispějete na provoz fóra?