Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Chabadaj
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 02 srp 2010 15:55

Prosím o kontrolu

#1 Příspěvek od Chabadaj »

Dobrý den,byl bych rád kdybyste se na to koukli,děkuji

Logfile of random's system information tool 1.09 (written by random/random)
Run by Elmo at 2012-08-07 01:54:46
Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 2 GB (13%) free of 13 GB
Total RAM: 3327 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:55:12, on 7.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\PnkBstrA.exe
D:\Program Files\Tunngle\TnglCtrl.exe
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\WINDOWS\system32\ctfmon.exe
C:\Catalyst\ATI.ACE\Core-Static\MOM.exe
C:\Catalyst\ATI.ACE\Core-Static\ccc.exe
D:\Program Files\SpeedFan\speedfan.exe
F:\Download\HiPatchService.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Elmo\Dokumenty\Downloads\RSIT.exe
D:\Program Files\trend micro\Elmo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dts.search-results.com/sidebar.h ... d=406&sr=0
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dts.search-results.com/sr?src=ie ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dts.search-results.com/sr?src=ie ... earchTerms}
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Catalyst\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [MSConfig] D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Search the Web - D:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - F:\Download\HiPatchService.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - D:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Program Files\Tunngle\TnglCtrl.exe

--
End of file - 5956 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Adobe Flash Player Updater.job
D:\WINDOWS\tasks\avast! Emergency Update.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-329068152-725345543-1003Core.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-329068152-725345543-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04 453504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04 157576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EEE6C35B-6118-11DC-9C72-001320C79847}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=D:\WINDOWS\system32\dumprep 0 -k []
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2011-12-05 20065384]
"Adobe ARM"=D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"StartCCC"=C:\Catalyst\ATI.ACE\Core-Static\CLIStart.exe [2012-03-09 98304]
"SunJavaUpdateSched"=D:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
"avast"=D:\Program Files\AVAST Software\Avast\avastUI.exe [2012-07-03 4273976]
"MSConfig"=D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-14 171008]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
D:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
D:\Program Files\Electronic Arts\EADM\Core.exe [2009-09-03 3342336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
D:\Documents and Settings\Elmo\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-05-16 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2012-02-28 1987976]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
D:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
D:\Program Files\SweetIM\Messenger\SweetIM.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamersFirst LIVE!.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^SlimStar 330.lnk]
D:\PROGRA~1\SLIMST~1\MagicKey.exe [2007-12-14 172032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wlidsvc"=2
"JavaQuickStarterService"=2
"IDriverT"=3
"Hamachi2Svc"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2012-03-09 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\WINDOWS\system32\dpvsetup.exe"="D:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"D:\WINDOWS\system32\rundll32.exe"="D:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"F:\Elmo\Call of Duty 5-World at War\CoDWaW.exe"="F:\Elmo\Call of Duty 5-World at War\CoDWaW.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Counter Strike 1.6\hl.exe"="C:\Counter Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program Files\Steam\Steam.exe"="D:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"F:\GTA4\Call of Duty Modern Warfare 2\iw4sp.exe"="F:\GTA4\Call of Duty Modern Warfare 2\iw4sp.exe:*:Enabled:iw4sp"
"F:\GTA4\Call of Duty Modern Warfare 2\iw4mp.exe"="F:\GTA4\Call of Duty Modern Warfare 2\iw4mp.exe:*:Enabled:iw4mp"
"D:\WINDOWS\system32\PnkBstrA.exe"="D:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"D:\WINDOWS\system32\PnkBstrB.exe"="D:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"F:\Elmo\ARMA2\Bohemia Interactive\arma2.exe"="F:\Elmo\ARMA2\Bohemia Interactive\arma2.exe:*:Enabled:ArmA 2"
"F:\Instalačky\Pes10\pes\pes2010.exe"="F:\Instalačky\Pes10\pes\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"F:\Instalačky\GTA4\Rockstar Games Social Club\RGSCLauncher.exe"="F:\Instalačky\GTA4\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"F:\Instalačky\GTA4\Grand Theft Auto IV\LaunchGTAIV.exe"="F:\Instalačky\GTA4\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"F:\Instalačky\GTA4\Grand Theft Auto IV\GTAIV.exe"="F:\Instalačky\GTA4\Grand Theft Auto IV\GTAIV.exe:*:Enabled:Grand Theft Auto IV"
"F:\Elmo\pes\pes2010.exe"="F:\Elmo\pes\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"F:\Elmo\GTA4\Grand Theft Auto IV\GTAIV.exe"="F:\Elmo\GTA4\Grand Theft Auto IV\GTAIV.exe:*:Enabled:Grand Theft Auto IV"
"F:\Elmo\FIFA11\Game\fifa.exe"="F:\Elmo\FIFA11\Game\fifa.exe:*:Enabled:FIFA 11"
"F:\Elmo\Call of Duty 4\iw3mp.exe"="F:\Elmo\Call of Duty 4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"F:\Elmo\Age Of Empires II CZ\empires2.exe"="F:\Elmo\Age Of Empires II CZ\empires2.exe:*:Enabled:Age of Empires II"
"F:\Elmo\Age Of Empires II CZ\age2_x1.exe"="F:\Elmo\Age Of Empires II CZ\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"D:\Program Files\Age of Empires II\empires2.exe"="D:\Program Files\Age of Empires II\empires2.exe:*:Enabled:Age of Empires II"
"D:\WINDOWS\system32\dplaysvr.exe"="D:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"F:\Elmo\Age Of Empires II\empires2.EXE"="F:\Elmo\Age Of Empires II\empires2.EXE:*:Enabled:Age of Empires II"
"F:\Elmo\Left 4 Dead\left4dead.exe"="F:\Elmo\Left 4 Dead\left4dead.exe:*:Enabled:left4dead"
"F:\Elmo\Age of Empires III\Age3.exe"="F:\Elmo\Age of Empires III\Age3.exe:*:Enabled:Age of Empires 3"
"C:\Program Files\fifa11\pes2010.exe"="C:\Program Files\fifa11\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"D:\Documents and Settings\Elmo\Data aplikací\GameRanger\GameRanger\GameRanger.exe"="D:\Documents and Settings\Elmo\Data aplikací\GameRanger\GameRanger\GameRanger.exe:*:Enabled:GameRanger"
"F:\Elmo\GamersFirst\APB Reloaded\Binaries\APB.exe"="F:\Elmo\GamersFirst\APB Reloaded\Binaries\APB.exe:*:Enabled:APB: APB.exe"
"F:\Elmo\GamersFirst\APB Reloaded\Binaries\VivoxVoiceService.exe"="F:\Elmo\GamersFirst\APB Reloaded\Binaries\VivoxVoiceService.exe:*:Enabled:APB: VivoxVoiceService.exe"
"C:\Program Files\PROEVO 10\pes2010.exe"="C:\Program Files\PROEVO 10\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
"F:\Elmo\HellGate London\nwn2main.exe"="F:\Elmo\HellGate London\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"F:\Elmo\HellGate London\nwn2main_amdxp.exe"="F:\Elmo\HellGate London\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"F:\Elmo\HellGate London\nwupdate.exe"="F:\Elmo\HellGate London\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"F:\Elmo\HellGate London\nwn2server.exe"="F:\Elmo\HellGate London\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"F:\Elmo\Nová složka\Call of Duty Modern Warfare 2\iw4sp.exe"="F:\Elmo\Nová složka\Call of Duty Modern Warfare 2\iw4sp.exe:*:Enabled:iw4sp"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"F:\Elmo\Assassins Creed-Brotherhood\ACBSP.exe"="F:\Elmo\Assassins Creed-Brotherhood\ACBSP.exe:*:Enabled:Assassin's Creed Brotherhood"
"F:\Elmo\Assassins Creed-Brotherhood\ACBMP.exe"="F:\Elmo\Assassins Creed-Brotherhood\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"F:\Elmo\Assassins Creed-Brotherhood\AssassinsCreedBrotherhood.exe"="F:\Elmo\Assassins Creed-Brotherhood\AssassinsCreedBrotherhood.exe:*:Enabled:Assassin's Creed Brotherhood Update"
"F:\Elmo\Assassins Creed-Brotherhood\UPlayBrowser.exe"="F:\Elmo\Assassins Creed-Brotherhood\UPlayBrowser.exe:*:Enabled:Assassin's Creed Brotherhood Uplay"
"F:\Crysis2\bin32\Crysis2.exe"="F:\Crysis2\bin32\Crysis2.exe:*:Enabled:Crysis2"
"C:\Program Files\Crysis2\bin32\Crysis2.exe"="C:\Program Files\Crysis2\bin32\Crysis2.exe:*:Enabled:Crysis2"
"C:\Program Files\LoL\League of Legends\lol.launcher.exe"="C:\Program Files\LoL\League of Legends\lol.launcher.exe:*:Enabled:Play League of Legends"
"C:\Program Files\GamersFirst\APB Reloaded\Binaries\APB.exe"="C:\Program Files\GamersFirst\APB Reloaded\Binaries\APB.exe:*:Enabled:APB: APB.exe"
"C:\Program Files\GamersFirst\APB Reloaded\Binaries\VivoxVoiceService.exe"="C:\Program Files\GamersFirst\APB Reloaded\Binaries\VivoxVoiceService.exe:*:Enabled:APB: VivoxVoiceService.exe"
"C:\Program Files\New Folder\pes2011.exe"="C:\Program Files\New Folder\pes2011.exe:*:Enabled:Pro Evolution Soccer 2011"
"D:\Program Files\Steam\steamapps\chabadaj\counter-strike\hl.exe"="D:\Program Files\Steam\steamapps\chabadaj\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"F:\Steam\steamapps\chabadaj\team fortress 2\hl2.exe"="F:\Steam\steamapps\chabadaj\team fortress 2\hl2.exe:*:Enabled:hl2"
"F:\Tom Clancys\Tom Clancyˇs\src\system\conviction_game.exe"="F:\Tom Clancys\Tom Clancyˇs\src\system\conviction_game.exe:*:Enabled:conviction_game"
"F:\DDO\DDO Unlimited\dndclient.exe"="F:\DDO\DDO Unlimited\dndclient.exe:*:Enabled:dndclient"
"F:\AoEO\AOEOnlineReplace.exe"="F:\AoEO\AOEOnlineReplace.exe:*:Enabled:AOEOnlineReplace"
"D:\Program Files\Microsoft Games for Windows - LIVE\Client\GFWLClient.exe"="D:\Program Files\Microsoft Games for Windows - LIVE\Client\GFWLClient.exe:*:Enabled:GFWLClient"
"D:\Program Files\AVAST Software\Avast\AvastUI.exe"="D:\Program Files\AVAST Software\Avast\AvastUI.exe:*:Enabled:avast! Free Antivirus"
"D:\Program Files\Microsoft Games for Windows - LIVE\Client\GFWLive.exe"="D:\Program Files\Microsoft Games for Windows - LIVE\Client\GFWLive.exe:*:Disabled:Games for Windows Marketplace"
"F:\Steam\Steam.exe"="F:\Steam\Steam.exe:*:Enabled:Steam"
"F:\Dead Island\Nová složka\Hra\Dead Island\deadislandgame.exe"="F:\Dead Island\Nová složka\Hra\Dead Island\deadislandgame.exe:*:Enabled:DeadIsland"
"D:\Program Files\Java\jre6\bin\javaw.exe"="D:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"F:\AoEO\AOEOnline.exe"="F:\AoEO\AOEOnline.exe:*:Enabled:Age of Empires Online"
"F:\Call of Duty Black Ops\Call of Duty - Black Ops\BlackOps.exe"="F:\Call of Duty Black Ops\Call of Duty - Black Ops\BlackOps.exe:*:Enabled:BlackOps"
"F:\FIFA 12\FIFA 12\Game\fifa.exe"="F:\FIFA 12\FIFA 12\Game\fifa.exe:*:Enabled:FIFA 12"
"F:\COD4\iw3mp.exe"="F:\COD4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"F:\Splinter Cell\[ www.Torrenting.com ] - Grave.Encounters.2011.DVDSCR.XviD-SiC\Stronghold 3\bin\win32_release\Stronghold3.exe"="F:\Splinter Cell\[ www.Torrenting.com ] - Grave.Encounters.2011.DVDSCR.XviD-SiC\Stronghold 3\bin\win32_release\Stronghold3.exe:*:Enabled:Stronghold3"
"F:\WoW\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="F:\WoW\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"F:\WoW\World of Warcraft\Launcher.exe"="F:\WoW\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"F:\WoW\World of Warcraft\Launcher.patch.exe"="F:\WoW\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher"
"F:\WoW\World of Warcraft\BackgroundDownloader.exe"="F:\WoW\World of Warcraft\BackgroundDownloader.exe:*:Enabled:BackgroundDownloader"
"F:\WoW\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"="F:\WoW\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Program Files\Tunngle\TnglCtrl.exe"="D:\Program Files\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service"
"D:\Program Files\Tunngle\Tunngle.exe"="D:\Program Files\Tunngle\Tunngle.exe:*:Enabled:Tunngle Client"
"D:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="D:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"F:\Assassins Creed\ACRMP.exe"="F:\Assassins Creed\ACRMP.exe:*:Enabled:Assassin's Creed Revelations Multiplayer"
"F:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe"="F:\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"F:\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe"="F:\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"D:\Program Files\Ventrilo\Ventrilo.exe"="D:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"F:\Star Wars-The Old Republic\launcher.exe"="F:\Star Wars-The Old Republic\launcher.exe:*:Enabled:Star Wars - The Old Republic"
"D:\Program Files\Bonjour\mDNSResponder.exe"="D:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"F:\Splinter Cell\Excalibur WoW - 3.3.5a - enUS (No Install)\Launcher.exe"="F:\Splinter Cell\Excalibur WoW - 3.3.5a - enUS (No Install)\Launcher.exe:*:Enabled:World of Warcraft"
"F:\Splinter Cell\Excalibur WoW - 3.3.5a - enUS (No Install)\BackgroundDownloader.exe"="F:\Splinter Cell\Excalibur WoW - 3.3.5a - enUS (No Install)\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"F:\Splinter Cell\Excalibur WoW - 3.3.5a - enUS (No Install)\Launcher.patch.exe"="F:\Splinter Cell\Excalibur WoW - 3.3.5a - enUS (No Install)\Launcher.patch.exe:*:Enabled:Blizzard Launcher"
"F:\Splinter Cell\World of Warcraft\Launcher.exe"="F:\Splinter Cell\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"F:\Splinter Cell\World of Warcraft\Launcher.patch.exe"="F:\Splinter Cell\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher"
"F:\Splinter Cell\World of Warcraft\BackgroundDownloader.exe"="F:\Splinter Cell\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"F:\World of Warcraft\Launcher.patch.exe"="F:\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher"
"F:\World of Warcraft\Launcher.exe"="F:\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\Program Files\Pando Networks\Media Booster\PMB.exe"="D:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"D:\Documents and Settings\All Users\Data aplikací\NexonUS\NGM\NGM.exe"="D:\Documents and Settings\All Users\Data aplikací\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"D:\Documents and Settings\All Users\Data aplikací\NexonEU\NGM\NGM.exe"="D:\Documents and Settings\All Users\Data aplikací\NexonEU\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"F:\Combat Arms\Combat Arms EU\CombatArms.exe"="F:\Combat Arms\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"F:\Combat Arms\Combat Arms EU\NMService.exe"="F:\Combat Arms\Combat Arms EU\NMService.exe:*:Enabled:Nexon Messenger Core"
"F:\Combat Arms\Combat Arms EU\Engine.exe"="F:\Combat Arms\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"F:\Hry\Far Cry 2\bin\FarCry2.exe"="F:\Hry\Far Cry 2\bin\FarCry2.exe:*:Enabled:Far Cry 2"
"F:\Hry\Far Cry 2\bin\FC2Launcher.exe"="F:\Hry\Far Cry 2\bin\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater"
"F:\Hry\Far Cry 2\bin\FC2Editor.exe"="F:\Hry\Far Cry 2\bin\FC2Editor.exe:*:Enabled:Editor"
"F:\Steam\steamapps\chabadaj\counter-strike\hl.exe"="F:\Steam\steamapps\chabadaj\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"D:\Documents and Settings\Elmo\Dokumenty\Downloads\Spoutcraft.jar"="D:\Documents and Settings\Elmo\Dokumenty\Downloads\Spoutcraft.jar:*:Enabled:Spoutcraft"
"F:\Bf3\Battlefield 3™\bf3.exe"="F:\Bf3\Battlefield 3™\bf3.exe:*:Enabled:Battlefield 3™"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"F:\Star Wars-The Old Republic\launcher.exe"="F:\Star Wars-The Old Republic\launcher.exe:*:Enabled:Star Wars - The Old Republic"
"D:\Program Files\Pando Networks\Media Booster\PMB.exe"="D:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"F:\Combat Arms\Combat Arms EU\CombatArms.exe"="F:\Combat Arms\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"F:\Combat Arms\Combat Arms EU\Engine.exe"="F:\Combat Arms\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=D:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=D:\WINDOWS\system32\l3codeca.acm
"msacm.lhacm"=lhacm.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-08-03 01:00:09 ----D---- D:\WINDOWS\system32\Adobe
2012-08-03 00:11:52 ----A---- D:\WINDOWS\system32\FlashPlayerApp.exe
2012-07-27 21:36:33 ----D---- D:\ProgramData
2012-07-27 21:19:57 ----D---- D:\Documents and Settings\Elmo\Data aplikací\Command and Conquer 4
2012-07-27 20:44:16 ----D---- D:\Program Files\Electronic Arts
2012-07-23 18:14:35 ----A---- D:\WINDOWS\system32\drivers\aswSP.sys
2012-07-23 18:14:35 ----A---- D:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-07-23 18:14:32 ----A---- D:\WINDOWS\system32\drivers\aswRdr.sys
2012-07-23 18:14:31 ----A---- D:\WINDOWS\system32\drivers\aswTdi.sys
2012-07-23 18:14:30 ----A---- D:\WINDOWS\system32\drivers\aswSnx.sys
2012-07-23 18:14:29 ----A---- D:\WINDOWS\system32\drivers\aswmon2.sys
2012-07-23 18:14:29 ----A---- D:\WINDOWS\system32\drivers\aswmon.sys
2012-07-23 18:14:28 ----A---- D:\WINDOWS\system32\drivers\aavmker4.sys
2012-07-23 18:12:57 ----A---- D:\WINDOWS\avastSS.scr
2012-07-23 18:12:55 ----A---- D:\WINDOWS\system32\aswBoot.exe
2012-07-13 22:36:30 ----A---- D:\WINDOWS\system32\pbsvc_blr.exe
2012-07-13 14:55:27 ----D---- D:\Documents and Settings\Elmo\Data aplikací\Firefly Studios
2012-07-11 10:33:40 ----HD---- D:\Program Files\Common Files\EAInstaller

======List of files/folders modified in the last 1 month======

2012-08-07 01:54:55 ----D---- D:\WINDOWS\Prefetch
2012-08-07 01:54:52 ----D---- D:\Program Files\trend micro
2012-08-07 00:42:48 ----D---- D:\WINDOWS\Temp
2012-08-07 00:21:59 ----D---- D:\WINDOWS\system32\config
2012-08-06 22:11:22 ----D---- D:\Documents and Settings\Elmo\Data aplikací\Mumble
2012-08-06 21:25:18 ----D---- D:\Documents and Settings\Elmo\Data aplikací\Skype
2012-08-06 16:45:58 ----D---- D:\Documents and Settings\All Users\Data aplikací\PMB Files
2012-08-06 13:15:12 ----D---- D:\WINDOWS\system32\LogFiles
2012-08-06 13:15:04 ----D---- D:\WINDOWS
2012-08-06 12:51:27 ----D---- D:\WINDOWS\system32
2012-08-06 12:51:24 ----A---- D:\WINDOWS\system32\PnkBstrB.exe
2012-08-06 12:47:50 ----D---- D:\WINDOWS\system32\CatRoot2
2012-08-06 12:27:37 ----D---- D:\Program Files\SpeedFan
2012-08-06 01:48:06 ----N---- D:\WINDOWS\SchedLgU.Txt
2012-08-05 18:25:35 ----D---- D:\Documents and Settings\Elmo\Data aplikací\.minecraft
2012-08-05 14:51:56 ----D---- D:\Documents and Settings\Elmo\Data aplikací\uTorrent
2012-08-05 12:34:56 ----A---- D:\WINDOWS\win.ini
2012-08-05 12:34:56 ----A---- D:\WINDOWS\system.ini
2012-08-03 01:00:34 ----SHD---- D:\WINDOWS\Installer
2012-08-03 00:50:45 ----D---- D:\Documents and Settings\Elmo\Data aplikací\TS3Client
2012-08-03 00:12:25 ----SD---- D:\WINDOWS\Tasks
2012-08-01 01:08:00 ----D---- D:\Documents and Settings\All Users\Data aplikací\SweetIM
2012-08-01 00:51:14 ----RSHDC---- D:\WINDOWS\system32\dllcache
2012-07-31 02:36:58 ----D---- D:\WINDOWS\Logs
2012-07-27 21:36:33 ----D---- D:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2012-07-27 20:44:16 ----RD---- D:\Program Files
2012-07-27 20:29:47 ----D---- D:\WINDOWS\system32\DirectX
2012-07-27 20:29:42 ----HD---- D:\WINDOWS\inf
2012-07-26 19:19:01 ----D---- D:\Program Files\TeamSpeak 3 Client
2012-07-23 18:14:35 ----D---- D:\WINDOWS\system32\drivers
2012-07-23 18:13:38 ----D---- D:\WINDOWS\WinSxS
2012-07-23 18:11:10 ----D---- D:\Program Files\AVAST Software
2012-07-23 18:11:10 ----D---- D:\Documents and Settings\All Users\Data aplikací\AVAST Software
2012-07-22 10:26:54 ----RSD---- D:\WINDOWS\assembly
2012-07-14 11:16:19 ----A---- D:\WINDOWS\system32\PnkBstrA.exe
2012-07-13 22:36:13 ----D---- D:\Program Files\Common Files\Wise Installation Wizard
2012-07-11 10:33:40 ----D---- D:\Program Files\Common Files
2012-07-09 21:10:37 ----SD---- D:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-07-09 14:39:49 ----D---- D:\Documents and Settings\Elmo\Data aplikací\.spoutcraft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; D:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 speedfan;speedfan; D:\WINDOWS\system32\speedfan.sys [2011-03-18 25240]
R1 330Fltr;WayTechUSBFilterDriver; D:\WINDOWS\system32\drivers\330Fltr.sys [2007-12-13 9344]
R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2012-07-03 25256]
R1 AswRdr;aswRdr; D:\WINDOWS\system32\drivers\AswRdr.sys [2012-07-03 35928]
R1 aswSnx;aswSnx; D:\WINDOWS\system32\drivers\aswSnx.sys [2012-07-03 721000]
R1 aswSP;aswSP; D:\WINDOWS\system32\drivers\aswSP.sys [2012-07-03 353688]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2012-07-03 54232]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; D:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-05-23 218688]
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-07-03 21256]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2012-07-03 97608]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; D:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; D:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; D:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 ati2mtag;ati2mtag; D:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2012-03-09 7586304]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; D:\WINDOWS\system32\drivers\AtihdXP3.sys [2011-12-20 100368]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-12-13 7069288]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NWRDR;NetWare Rdr; D:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-14 163584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; D:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2009-10-30 176768]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); D:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 wceusbsh;Windows CE USB Serial Host Driver; D:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S3 Ambfilt;Ambfilt; D:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 DualCoreCenter;DualCoreCenter; \??\D:\Program Files\MSI\OverclockingCenter\NTGLM7X.sys []
S3 EagleXNt;EagleXNt; \??\D:\WINDOWS\system32\drivers\EagleXNt.sys []
S3 hamachi;Hamachi Network Interface; D:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 Monfilt;Monfilt; D:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 RushTopDevice_J;RushTopDevice_J; \??\D:\Program Files\MSI\OverclockingCenter\RushJ.sys []
S3 RushTopDevice2;RushTopDevice2; \??\D:\Program Files\MSI\OverclockingCenter\RushTop.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\system32\Ati2evxx.exe [2012-03-09 643072]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-07-03 44808]
R2 Bonjour Service;Bonjour Service; D:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 390504]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; F:\Download\HiPatchService.exe [2012-07-12 8704]
R2 NWCWorkstation;Klient systému NetWare; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; D:\WINDOWS\system32\PnkBstrA.exe [2012-07-14 76888]
R2 TunngleService;TunngleService; D:\Program Files\Tunngle\TnglCtrl.exe [2011-10-14 745832]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; D:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 250056]
S3 aspnet_state;Stavová služba ASP.NET; D:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; D:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Steam Client Service;Steam Client Service; D:\Program Files\Common Files\Steam\SteamService.exe [2012-03-30 489256]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; D:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; D:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; D:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 1373576]
S4 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [2012-05-04 161664]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 wlidsvc;Windows Live ID Sign-in Assistant; D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu

#2 Příspěvek od Márty84 »

Zdravim :)

Na logu se pracuje, bude to nejakou dobu trvat.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu

#3 Příspěvek od Márty84 »

:arrow: Mate dost malo mista na disku


:arrow: Aktualizujte Internet Explorer. Mate verzi 6, ale uz je verze 8




:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Najdete tento soubor D:\Program Files\trend micro\Elmo.exe a spustte ho.
Kliknete na Main menu a na Do a system scan only
U techto radku dejte vlevo zatrzitko

Kód: Vybrat vše

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dts.search-results.com/sidebar.h ... d=406&sr=0
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dts.search-results.com/sr?src=ie ... 06&sr=0&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dts.search-results.com/sr?src=ie ... 06&sr=0&q={searchTerms}
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
O8 - Extra context menu item: Search the Web - D:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
Kliknete na nápis Fix checked a potvrdte




:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe , ulozte nejlepe na plochu a spustte.
Do leveho okna zkopirujte tento skript (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]

:services
SkypeUpdate
AdobeFlashPlayerUpdateSvc

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
D:\WINDOWS\tasks\Adobe Flash Player Updater.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-329068152-725345543-1003Core.job
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-329068152-725345543-1003UA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=-
"Adobe ARM"=-
"StartCCC"=-
"SunJavaUpdateSched"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamersFirst LIVE!.lnk]
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery na vas vyskoci, nebo bude zde C:\_OTM\MovedFiles\xxxxxxxx_xxxxxx (misto tech x budou cisla, predstavujici datum a cas spusteni)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Chabadaj
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 02 srp 2010 15:55

Re: Prosím o kontrolu

#4 Příspěvek od Chabadaj »

Omlouvám se za spoždění..

Trend micro jsem spustil a zaškrtal.

A zde je log:


All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Elmo
->Temp folder emptied: 13298404 bytes
->Temporary Internet Files folder emptied: 529407 bytes
->Java cache emptied: 1 bytes
->Google Chrome cache emptied: 24738070 bytes
->Flash cache emptied: 528 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 653234 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2114584 bytes
%systemroot%\System32 .tmp files removed: 1784152 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 21746 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 41,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: Elmo
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb

D:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
========== SERVICES/DRIVERS ==========
Service SkypeUpdate stopped successfully!
Service SkypeUpdate deleted successfully!
Service AdobeFlashPlayerUpdateSvc stopped successfully!
Service AdobeFlashPlayerUpdateSvc deleted successfully!
========== FILES ==========
File/Folder D:\WINDOWS\system32\*.tmp.dll not found.
File/Folder D:\WINDOWS\system32\SET*.tmp not found.
File/Folder D:\WINDOWS\*.tmp not found.
D:\WINDOWS\tasks\Adobe Flash Player Updater.job moved successfully.
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-329068152-725345543-1003Core.job moved successfully.
D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-220523388-329068152-725345543-1003UA.job moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\StartCCC deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GamersFirst LIVE!.lnk\ deleted successfully.

OTM by OldTimer - Version 3.1.21.0 log created on 08082012_140106

Files moved on Reboot...
File move failed. D:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu

#5 Příspěvek od Márty84 »

Fajn, OTM provedlo co melo.

:???: Slo jen o preventivku, nebo je s pc nejaky problem?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Chabadaj
Návštěvník
Návštěvník
Příspěvky: 35
Registrován: 02 srp 2010 15:55

Re: Prosím o kontrolu

#6 Příspěvek od Chabadaj »

Zatim spíše jen preventivka..
Je trošku pomalejší,ale to je způsobeno hlavně nedostatkem místa v PC..
A ještě k tomu mam Win XP .. :)
Jinak zatim děkuju .

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu

#7 Příspěvek od Márty84 »

:arrow: Stahnete OTC http://oldtimer.geekstogo.com/OTC.exe , ulozte a spustte.
Kliknete na napis CleanUp a pote OK - Po uklidu dojde k restartu pc.

:arrow: Stahnete TFC http://oldtimer.geekstogo.com/TFC.exe , ulozte a spustte
Kliknete na START a pote OK - Po uklidu dojde k restartu pc.
Po pouziti muzete programek smazat

:arrow: Stahnete Ccleaner http://www.stahuj.centrum.cz/utility_a_ ... /ccleaner/ a spustte.
Pri instalaci pozor na toolbar, jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete :)
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!

:arrow: Defragmentujte disk
Stahnete napriklad program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci opet pozor na toolbar
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci :)



Pak dejte vedet, jestli se to zlepsilo
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu

#8 Příspěvek od motji »

Jak to tu vypadá? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Prosím o kontrolu

#9 Příspěvek od motji »

Dobrý den,
pro neaktivitu je toto téma uzamknuto.
Pokud ho budete chtít odemknout, kontaktujte mě na email nebo některého z mých kolegů.
Děkujeme za pochopení :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Zamčeno