Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu po nalezení a odstranění TR/Dropper.MSIL.Gen8

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
lastsaves
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 17 zář 2007 16:43

Kontrola logu po nalezení a odstranění TR/Dropper.MSIL.Gen8

#1 Příspěvek od lastsaves »

Logfile of random's system information tool 1.06 (written by random/random)
Run by Martin at 2013-01-24 21:34:07
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 853 MB (2%) free of 50 GB
Total RAM: 3326 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:34:27, on 24.1.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Apps\USB Safely Remove\USBSRService.exe
C:\WINDOWS\system32\svchost.exe
C:\Apps\Sandboxie\SbieSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Online Armor\OAcat.exe
C:\Program Files\Online Armor\oasrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Apps\SUPERAntispyware\SASCORE.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Apps\FlashFolder\FlashFolder.exe
C:\Apps\GoodSync\Gs-Server.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Secunia PSI\PSIA.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Apps\Spyware Terminator\sp_rsser.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Online Armor\oaui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Apps\Everything\Everything-1.2.1.371.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\Apps\Spyware Terminator\SpywareTerminatorShield.exe
C:\Apps\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Apps\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Online Armor\OAhlp.exe
C:\Apps\USB Safely Remove\USBSafelyRemove.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Apps\Taskbar Shuffle\taskbarshuffle.exe
C:\Apps\Grindstone 2\Grindstone 2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Apps\GoodSync\GoodSync.exe
C:\Apps\Sandboxie\SbieCtrl.exe
C:\Apps\OpenHardwareMonitor\OpenHardwareMonitor.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Apps\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Secunia PSI\psi_tray.exe
C:\Apps\4t Tray Minimizer\4t-min.exe
C:\Apps\Crystal Disk Info\DiskInfo.exe
C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe
C:\Apps\Networx\networx.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\APPS - PORTABLE\PhraseExpress\phraseexpress.exe
C:\Apps\TClock Lite\tclock.exe
C:\Apps\Volume2\Volume2.exe
C:\WINDOWS\System32\svchost.exe
C:\Apps\Mozilla Firefox\firefox.exe
C:\Apps\Mozilla Firefox\plugin-container.exe
C:\Apps\Total Commander\TOTALCMD.EXE
C:\Apps\BackUp Maker\bkmaker.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Apps\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Martin\Plocha\RSIT.exe
C:\Program Files\trend micro\Martin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://maxibps.postovnisporitelna.cz/? ... banking+PS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" //mailurl:mailto:support@kcsoftwares.com?subject=%5BSUMo%5D%20Error%20Report%20for%20WD%20Drive%20Manager%20by%20WDC%20v%202.0.115.0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Everything] "C:\Apps\Everything\Everything-1.2.1.371.exe" -startup
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Apps\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Apps\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Apps\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [USB Safely Remove] C:\Apps\USB Safely Remove\USBSafelyRemove.exe /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Taskbar Shuffle] c:\Apps\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [Grindstone 2] "C:\Apps\Grindstone 2\Grindstone 2.exe"
O4 - HKCU\..\Run: [GoodSync] "C:\Apps\GoodSync\GoodSync.exe" /min
O4 - HKCU\..\Run: [SandboxieControl] "C:\Apps\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [OpenHardwareMonitor] c:\Apps\OpenHardwareMonitor\OpenHardwareMonitor.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Apps\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: 4t Tray Minimizer.lnk = C:\Apps\4t Tray Minimizer\4t-min.exe
O4 - Startup: Backup Maker (Auto It).lnk = C:\Apps\_AutoIt Macros\bmaker-CL.exe
O4 - Startup: Crystal Disk Info.lnk = C:\Apps\Crystal Disk Info\DiskInfo.exe
O4 - Startup: Dropbox.lnk = ?
O4 - Startup: Networx.lnk = C:\Apps\Networx\networx.exe
O4 - Startup: PhraseExpress.lnk = C:\APPS - PORTABLE\PhraseExpress\phraseexpress.exe
O4 - Startup: TClock Lite.lnk = C:\Apps\TClock Lite\tclock.exe
O4 - Startup: Volume2.lnk = C:\Apps\Volume2\Volume2.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: BackUp Maker.lnk = C:\Apps\BackUp Maker\bkmaker.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia PSI\psi_tray.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\Apps\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Apps\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {682C59F5-478C-4421-9070-AD170D143B77} (Launcher Class) - http://dell.com/support/troubleshooting ... /pcd86.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7386171578
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - https://support.dell.com/systemprofiler ... emLite.CAB
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Apps\SUPERAntispyware\SASCORE.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: FlashFolder - zett42 - C:\Apps\FlashFolder\FlashFolder.exe
O23 - Service: GoodSync Server (GsServer) - Unknown owner - C:\Apps\GoodSync\Gs-Server.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Online Armor Helper Service (OAcat) - Emsisoft GmbH - C:\Program Files\Online Armor\OAcat.exe
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Apps\Sandboxie\SbieSvc.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia PSI\PSIA.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Apps\Spyware Terminator\sp_rsser.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Emsisoft GmbH - C:\Program Files\Online Armor\oasrv.exe
O23 - Service: USB Safely Remove Assistant (USBSafelyRemoveService) - Unknown owner - C:\Apps\USB Safely Remove\USBSRService.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
O24 - Desktop Component AutorunsDisabled: (no name) - (no file)

--
End of file - 13857 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Backup.job
C:\WINDOWS\tasks\videopadShakeIcon.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Apps\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04 453504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-08-13 4120256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04 157576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-18 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-08-03 1044480]
"@OnlineArmor GUI"=C:\Program Files\Online Armor\oaui.exe [2012-10-03 2415104]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2012-07-31 348664]
"Everything"=C:\Apps\Everything\Everything-1.2.1.371.exe [2009-03-13 602624]
"CoolSwitch"=C:\WINDOWS\system32\taskswitch.exe [2002-03-19 45632]
"WD Drive Manager"=C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe [2009-06-26 450560]
"SpywareTerminator"=C:\Apps\Spyware Terminator\SpywareTerminatorShield.exe [2012-01-30 2216960]
"Acrobat Assistant 7.0"=C:\Apps\Acrobat 7.0\Distillr\Acrotray.exe [2008-04-23 483328]
""= []
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-11-28 59280]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2012-09-23 15512424]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2012-09-23 1634112]
"iTunesHelper"=C:\Apps\iTunes\iTunesHelper.exe [2012-12-12 152544]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"USB Safely Remove"=C:\Apps\USB Safely Remove\USBSafelyRemove.exe [2011-08-04 1839448]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Taskbar Shuffle"=c:\Apps\Taskbar Shuffle\taskbarshuffle.exe [2008-04-17 818176]
"Grindstone 2"=C:\Apps\Grindstone 2\Grindstone 2.exe [2012-04-02 1555968]
"GoodSync"=C:\Apps\GoodSync\GoodSync.exe [2012-09-10 7089880]
"SandboxieControl"=C:\Apps\Sandboxie\SbieCtrl.exe [2012-12-16 545552]
"OpenHardwareMonitor"=c:\Apps\OpenHardwareMonitor\OpenHardwareMonitor.exe [2012-07-26 483328]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]
"DAEMON Tools Lite"=C:\Apps\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
BackUp Maker.lnk - C:\Apps\BackUp Maker\bkmaker.exe
Secunia PSI Tray.lnk - C:\Program Files\Secunia PSI\psi_tray.exe

C:\Documents and Settings\Martin\Nabídka Start\Programy\Po spuštění
4t Tray Minimizer.lnk - C:\Apps\4t Tray Minimizer\4t-min.exe
Backup Maker (Auto It).lnk - C:\Apps\_AutoIt Macros\bmaker-CL.exe
Crystal Disk Info.lnk - C:\Apps\Crystal Disk Info\DiskInfo.exe
Dropbox.lnk - C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe
Networx.lnk - C:\Apps\Networx\networx.exe
PhraseExpress.lnk - C:\APPS - PORTABLE\PhraseExpress\phraseexpress.exe
TClock Lite.lnk - C:\Apps\TClock Lite\tclock.exe
Volume2.lnk - C:\Apps\Volume2\Volume2.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"=C:\PROGRA~1\ONLINE~2\oaevent.dll [2012-10-03 366440]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Apps\SUPERAntispyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=FFFFFF03

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Apps\Skype\Phone\Skype.exe"="C:\Apps\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\APPS - SHARE\uTorrent\uTorrent.exe"="C:\APPS - SHARE\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\Apps\GoodSync\GoodSync.exe"="C:\Apps\GoodSync\GoodSync.exe:*:Enabled:GoodSync"
"C:\Apps\GoodSync\GsExplorer.exe"="C:\Apps\GoodSync\GsExplorer.exe:*:Enabled:GoodSync Explorer"
"C:\Apps\GoodSync\Gs-Server.exe"="C:\Apps\GoodSync\Gs-Server.exe:*:Enabled:GoodSync Server"
"F:\Games\Mass Effect 2\Binaries\MassEffect2.exe"="F:\Games\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Game"
"F:\Games\Mass Effect 2\MassEffect2Launcher.exe"="F:\Games\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Launcher"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"F:\Games\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe"="F:\Games\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe:*:Enabled:Call of Juarez - Bound in Blood"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Apps\iTunes\iTunes.exe"="C:\Apps\iTunes\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2013-01-24 21:34:08 ----D---- C:\Program Files\trend micro
2013-01-24 21:34:07 ----D---- C:\rsit
2013-01-24 19:13:31 ----A---- C:\WINDOWS\system32\MovieCollector.exe
2013-01-24 19:12:39 ----A---- C:\WINDOWS\system32\moviecollectorsetup.exe
2013-01-15 07:37:31 ----A---- C:\WINDOWS\system32\javaws.exe
2013-01-15 07:36:55 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-01-15 07:36:55 ----A---- C:\WINDOWS\system32\javaw.exe
2013-01-15 07:36:55 ----A---- C:\WINDOWS\system32\java.exe
2013-01-09 10:45:23 ----A---- C:\WINDOWS\imsins.BAK
2013-01-09 10:45:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2013-01-07 08:24:50 ----D---- C:\Program Files\iPod
2013-01-07 08:24:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-01-06 23:55:57 ----D---- C:\Program Files\Common Files\ODBC
2013-01-04 19:11:03 ----A---- C:\WINDOWS\du.ini
2013-01-04 19:07:34 ----A---- C:\WINDOWS\DUO.INI
2013-01-04 09:31:10 ----D---- C:\Program Files\MSXML 4.0
2013-01-03 22:36:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\firebird
2013-01-03 22:02:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\CIGLER SOFTWARE
2013-01-03 19:27:12 ----A---- C:\WINDOWS\system32\GDS32.DLL
2013-01-03 19:27:09 ----D---- C:\Program Files\Firebird
2012-12-27 21:20:09 ----D---- C:\Program Files\Dropbox
2012-12-27 18:38:10 ----A---- C:\sound_bank_log.txt
2012-12-27 18:37:06 ----A---- C:\bink_log.txt
2012-12-27 18:31:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Pendulo Studios

======List of files/folders modified in the last 1 months======

2013-01-24 21:34:16 ----D---- C:\WINDOWS\Temp
2013-01-24 21:34:08 ----RD---- C:\Program Files
2013-01-24 21:32:16 ----D---- C:\Documents and Settings\Martin\Data aplikací\Grindstone 2
2013-01-24 21:30:39 ----D---- C:\Documents and Settings\Martin\Data aplikací\Skype
2013-01-24 21:26:20 ----D---- C:\WINDOWS\system32\NtmsData
2013-01-24 21:08:19 ----D---- C:\Program Files\Secunia PSI
2013-01-24 19:44:41 ----D---- C:\WINDOWS\Registration
2013-01-24 19:42:12 ----SHD---- C:\WINDOWS\Installer
2013-01-24 19:42:03 ----D---- C:\Program Files\Common Files
2013-01-24 19:42:03 ----D---- C:\Apps
2013-01-24 19:20:26 ----D---- C:\WINDOWS\system32
2013-01-24 19:13:50 ----D---- C:\WINDOWS\Prefetch
2013-01-24 19:12:37 ----D---- C:\WINDOWS\system32\CatRoot2
2013-01-24 18:45:44 ----AD---- C:\Zotero
2013-01-24 18:30:48 ----D---- C:\Documents and Settings\Martin\Data aplikací\Dropbox
2013-01-24 07:56:59 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-01-24 07:06:37 ----D---- C:\Documents and Settings\Martin\Data aplikací\GoodSync
2013-01-24 00:30:23 ----D---- C:\TEMP
2013-01-20 10:01:45 ----AD---- C:\WINDOWS
2013-01-20 10:01:43 ----A---- C:\WINDOWS\Sandboxie.ini
2013-01-19 09:44:13 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-01-16 22:17:44 ----D---- C:\WINDOWS\WinSxS
2013-01-16 20:12:08 ----D---- C:\Program Files\Common Files\Adobe
2013-01-15 07:36:39 ----A---- C:\WINDOWS\system32\npdeployJava1.dll
2013-01-15 07:36:39 ----A---- C:\WINDOWS\system32\deployJava1.dll
2013-01-15 07:05:29 ----HD---- C:\WINDOWS\inf
2013-01-15 07:05:14 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-01-15 07:05:08 ----D---- C:\WINDOWS\ie8updates
2013-01-15 07:05:03 ----HD---- C:\WINDOWS\$hf_mig$
2013-01-13 00:02:28 ----D---- C:\Documents and Settings\Martin\Data aplikací\UHS Reader
2013-01-11 17:51:03 ----SD---- C:\WINDOWS\Tasks
2013-01-11 17:50:58 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-01-11 17:45:35 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-01-11 17:40:57 ----D---- C:\WINDOWS\system32\drivers
2013-01-09 12:57:59 ----RSD---- C:\WINDOWS\assembly
2013-01-09 12:57:59 ----D---- C:\WINDOWS\Microsoft.NET
2013-01-09 11:56:47 ----A---- C:\WINDOWS\VACCA.INI
2013-01-09 11:14:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-01-09 10:56:15 ----D---- C:\WINDOWS\pchealth
2013-01-09 10:40:31 ----D---- C:\WINDOWS\Debug
2013-01-09 10:40:29 ----A---- C:\WINDOWS\system32\MRT.exe
2013-01-07 22:05:24 ----D---- C:\Program Files\Amazon
2013-01-07 20:43:41 ----A---- C:\WINDOWS\DTLite.INI
2013-01-07 19:41:13 ----D---- C:\Documents and Settings\Martin\Data aplikací\uTorrent
2013-01-07 08:24:48 ----D---- C:\Program Files\Common Files\Apple
2013-01-07 08:24:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2013-01-07 08:21:00 ----DC---- C:\WINDOWS\system32\DRVSTORE
2013-01-07 08:18:17 ----D---- C:\iTunes Library
2013-01-06 06:33:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2013-01-05 16:23:44 ----D---- C:\WINDOWS\system32\CatRoot
2013-01-05 12:44:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2013-01-04 09:16:20 ----D---- C:\WINDOWS\system32\spool
2013-01-03 22:29:09 ----D---- C:\WINDOWS\system32\oobe
2013-01-03 22:29:09 ----D---- C:\WINDOWS\system32\mui
2013-01-03 22:29:08 ----D---- C:\WINDOWS\SoftwareDistribution
2013-01-03 22:29:08 ----D---- C:\WINDOWS\security
2013-01-03 22:29:04 ----D---- C:\WINDOWS\ime
2013-01-03 22:29:03 ----D---- C:\Program Files\Windows Media Player
2013-01-03 22:29:01 ----D---- C:\Program Files\Online Armor
2013-01-03 22:28:59 ----D---- C:\Program Files\Internet Explorer
2013-01-03 22:28:47 ----D---- C:\Documents and Settings
2012-12-31 13:14:06 ----D---- C:\Documents and Settings\Martin\Data aplikací\Audacity
2012-12-30 23:42:22 ----D---- C:\Documents and Settings\Martin\Data aplikací\Media Player Classic
2012-12-29 23:19:58 ----D---- C:\Documents and Settings\Martin\Data aplikací\Winamp
2012-12-27 18:06:24 ----D---- C:\WINDOWS\system32\DirectX
2012-12-25 09:57:19 ----D---- C:\Documents and Settings\Martin\Data aplikací\PhraseExpress

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [2002-07-17 16877]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2012-05-08 137928]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2011-12-15 36000]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 OADevice;OADriver; \??\C:\WINDOWS\system32\drivers\OADriver.sys []
R1 oahlpXX;Online Armor helper driver; \??\C:\WINDOWS\system32\drivers\oahlp32.sys []
R1 OAmon;OAmon; \??\C:\WINDOWS\system32\drivers\OAmon.sys []
R1 OAnet;OAnet; \??\C:\WINDOWS\system32\drivers\OAnet.sys []
R1 SASDIFSV;SASDIFSV; \??\C:\Apps\SUPERAntispyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Apps\SUPERAntispyware\SASKUTIL.SYS []
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2012-02-10 231760]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2012-07-08 271360]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2012-05-08 83392]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2012-07-08 18048]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2009-07-20 339456]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2007-06-06 161792]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2012-09-23 12557728]
R3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
R3 SbieDrv;SbieDrv; \??\C:\Apps\Sandboxie\SbieDrv.sys []
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Documents and Settings\Martin\Local Settings\Temp\tmp1.tmp []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 apu9pdzu;apu9pdzu; C:\WINDOWS\system32\drivers\apu9pdzu.sys []
S3 epmntdrv;epmntdrv; \??\C:\WINDOWS\system32\epmntdrv.sys []
S3 EuGdiDrv;EuGdiDrv; \??\C:\WINDOWS\system32\EuGdiDrv.sys []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
S3 PROCEXP151;PROCEXP151; \??\C:\WINDOWS\system32\Drivers\PROCEXP151.SYS []
S3 RivaTuner32;RivaTuner32; \??\C:\Apps\RivaTuner\RivaTuner32.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2008-05-12 11520]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Apps\SUPERAntispyware\SASCORE.EXE [2012-07-11 116608]
R2 AntiVirService;Avira Realtime Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2012-05-08 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe [2007-12-12 65536]
R2 FlashFolder;FlashFolder; C:\Apps\FlashFolder\FlashFolder.exe [2008-03-21 71680]
R2 GsServer;GoodSync Server; C:\Apps\GoodSync\Gs-Server.exe [2012-09-10 3472088]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [2012-05-04 161664]
R2 nlsX86cc;NLS Service; C:\WINDOWS\system32\NLSSRV32.EXE [2011-11-02 68896]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2012-09-23 164200]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2009-04-08 1377536]
R2 OAcat;Online Armor Helper Service; C:\Program Files\Online Armor\OAcat.exe [2012-10-03 216072]
R2 SbieSvc;Sandboxie Service; C:\Apps\Sandboxie\SbieSvc.exe [2012-12-16 85776]
R2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files\Secunia PSI\PSIA.exe [2012-11-26 1225312]
R2 Skype C2C Service;Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Apps\Spyware Terminator\sp_rsser.exe [2012-01-30 496128]
R2 SvcOnlineArmor;Online Armor; C:\Program Files\Online Armor\oasrv.exe [2012-10-03 4463864]
R2 USBSafelyRemoveService;USB Safely Remove Assistant; C:\Apps\USB Safely Remove\USBSRService.exe [2011-08-04 257880]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service; C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2009-06-26 102400]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe [2007-12-12 1531989]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-12-12 553440]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-09-23 1258856]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2012-01-30 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-01-18 115608]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
Win10 Pro = Avast Free = Comodo Firewall Free

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu po nalezení a odstranění TR/Dropper.MSIL.G

#2 Příspěvek od Rudy »

Zdravím!
Log vypadá čistý, až na pár zbytečností, které dočistíme. Další problém je kritický nedostatek místa na disku.

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Skype\Toolbars

:services
Skype C2C Service

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

lastsaves
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 17 zář 2007 16:43

Re: Kontrola logu po nalezení a odstranění TR/Dropper.MSIL.G

#3 Příspěvek od lastsaves »

Provedeno, log zde:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Martin at 2013-01-26 13:56:15
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (7%) free of 50 GB
Total RAM: 3326 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:56:27, on 26.1.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Apps\USB Safely Remove\USBSRService.exe
C:\WINDOWS\system32\svchost.exe
C:\Apps\Sandboxie\SbieSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Online Armor\OAcat.exe
C:\Program Files\Online Armor\oasrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Apps\SUPERAntispyware\SASCORE.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Apps\FlashFolder\FlashFolder.exe
C:\Apps\GoodSync\Gs-Server.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Secunia PSI\PSIA.exe
C:\Apps\Spyware Terminator\sp_rsser.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Online Armor\oaui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Apps\Everything\Everything-1.2.1.371.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\Apps\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Online Armor\OAhlp.exe
C:\Apps\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Apps\USB Safely Remove\USBSafelyRemove.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Apps\Taskbar Shuffle\taskbarshuffle.exe
C:\Apps\Grindstone 2\Grindstone 2.exe
C:\Apps\GoodSync\GoodSync.exe
C:\Apps\Sandboxie\SbieCtrl.exe
C:\Apps\OpenHardwareMonitor\OpenHardwareMonitor.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Apps\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Apps\BackUp Maker\bkmaker.exe
C:\Program Files\Secunia PSI\psi_tray.exe
C:\Apps\4t Tray Minimizer\4t-min.exe
C:\Apps\Crystal Disk Info\DiskInfo.exe
C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe
C:\Apps\Networx\networx.exe
C:\Apps\Mozilla Firefox\firefox.exe
C:\APPS - PORTABLE\PhraseExpress\phraseexpress.exe
C:\Apps\TClock Lite\tclock.exe
C:\Apps\Volume2\Volume2.exe
C:\WINDOWS\System32\svchost.exe
C:\Apps\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Martin\Plocha\RSIT.exe
C:\Program Files\trend micro\Martin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://maxibps.postovnisporitelna.cz/? ... banking+PS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" //mailurl:mailto:support@kcsoftwares.com?subject=%5BSUMo%5D%20Error%20Report%20for%20WD%20Drive%20Manager%20by%20WDC%20v%202.0.115.0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Everything] "C:\Apps\Everything\Everything-1.2.1.371.exe" -startup
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Apps\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Apps\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Apps\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [USB Safely Remove] C:\Apps\USB Safely Remove\USBSafelyRemove.exe /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Taskbar Shuffle] c:\Apps\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [Grindstone 2] "C:\Apps\Grindstone 2\Grindstone 2.exe"
O4 - HKCU\..\Run: [GoodSync] "C:\Apps\GoodSync\GoodSync.exe" /min
O4 - HKCU\..\Run: [SandboxieControl] "C:\Apps\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [OpenHardwareMonitor] c:\Apps\OpenHardwareMonitor\OpenHardwareMonitor.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Apps\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: 4t Tray Minimizer.lnk = C:\Apps\4t Tray Minimizer\4t-min.exe
O4 - Startup: Backup Maker (Auto It).lnk = C:\Apps\_AutoIt Macros\bmaker-CL.exe
O4 - Startup: Crystal Disk Info.lnk = C:\Apps\Crystal Disk Info\DiskInfo.exe
O4 - Startup: Dropbox.lnk = ?
O4 - Startup: Networx.lnk = C:\Apps\Networx\networx.exe
O4 - Startup: PhraseExpress.lnk = C:\APPS - PORTABLE\PhraseExpress\phraseexpress.exe
O4 - Startup: TClock Lite.lnk = C:\Apps\TClock Lite\tclock.exe
O4 - Startup: Volume2.lnk = C:\Apps\Volume2\Volume2.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: BackUp Maker.lnk = C:\Apps\BackUp Maker\bkmaker.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia PSI\psi_tray.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\Apps\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Apps\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {682C59F5-478C-4421-9070-AD170D143B77} (Launcher Class) - http://dell.com/support/troubleshooting ... /pcd86.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7386171578
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - https://support.dell.com/systemprofiler ... emLite.CAB
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Apps\SUPERAntispyware\SASCORE.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: FlashFolder - zett42 - C:\Apps\FlashFolder\FlashFolder.exe
O23 - Service: GoodSync Server (GsServer) - Unknown owner - C:\Apps\GoodSync\Gs-Server.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Online Armor Helper Service (OAcat) - Emsisoft GmbH - C:\Program Files\Online Armor\OAcat.exe
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Apps\Sandboxie\SbieSvc.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia PSI\PSIA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Apps\Spyware Terminator\sp_rsser.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Emsisoft GmbH - C:\Program Files\Online Armor\oasrv.exe
O23 - Service: USB Safely Remove Assistant (USBSafelyRemoveService) - Unknown owner - C:\Apps\USB Safely Remove\USBSRService.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
O24 - Desktop Component AutorunsDisabled: (no name) - (no file)

--
End of file - 13068 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Backup.job
C:\WINDOWS\tasks\videopadShakeIcon.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Apps\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04 453504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04 157576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Apps\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-18 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-08-03 1044480]
"@OnlineArmor GUI"=C:\Program Files\Online Armor\oaui.exe [2012-10-03 2415104]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2012-07-31 348664]
"Everything"=C:\Apps\Everything\Everything-1.2.1.371.exe [2009-03-13 602624]
"CoolSwitch"=C:\WINDOWS\system32\taskswitch.exe [2002-03-19 45632]
"WD Drive Manager"=C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe [2009-06-26 450560]
"SpywareTerminator"=C:\Apps\Spyware Terminator\SpywareTerminatorShield.exe [2012-01-30 2216960]
"Acrobat Assistant 7.0"=C:\Apps\Acrobat 7.0\Distillr\Acrotray.exe [2008-04-23 483328]
""= []
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-11-28 59280]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2012-09-23 15512424]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2012-09-23 1634112]
"iTunesHelper"=C:\Apps\iTunes\iTunesHelper.exe [2012-12-12 152544]
"USB Safely Remove"=C:\Apps\USB Safely Remove\USBSafelyRemove.exe [2011-08-04 1839448]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Taskbar Shuffle"=c:\Apps\Taskbar Shuffle\taskbarshuffle.exe [2008-04-17 818176]
"Grindstone 2"=C:\Apps\Grindstone 2\Grindstone 2.exe [2012-04-02 1555968]
"GoodSync"=C:\Apps\GoodSync\GoodSync.exe [2012-09-10 7089880]
"SandboxieControl"=C:\Apps\Sandboxie\SbieCtrl.exe [2012-12-16 545552]
"OpenHardwareMonitor"=c:\Apps\OpenHardwareMonitor\OpenHardwareMonitor.exe [2012-07-26 483328]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]
"DAEMON Tools Lite"=C:\Apps\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
BackUp Maker.lnk - C:\Apps\BackUp Maker\bkmaker.exe
Secunia PSI Tray.lnk - C:\Program Files\Secunia PSI\psi_tray.exe

C:\Documents and Settings\Martin\Nabídka Start\Programy\Po spuštění
4t Tray Minimizer.lnk - C:\Apps\4t Tray Minimizer\4t-min.exe
Backup Maker (Auto It).lnk - C:\Apps\_AutoIt Macros\bmaker-CL.exe
Crystal Disk Info.lnk - C:\Apps\Crystal Disk Info\DiskInfo.exe
Dropbox.lnk - C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe
Networx.lnk - C:\Apps\Networx\networx.exe
PhraseExpress.lnk - C:\APPS - PORTABLE\PhraseExpress\phraseexpress.exe
TClock Lite.lnk - C:\Apps\TClock Lite\tclock.exe
Volume2.lnk - C:\Apps\Volume2\Volume2.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"=C:\PROGRA~1\ONLINE~2\oaevent.dll [2012-10-03 366440]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Apps\SUPERAntispyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=FFFFFF03

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Apps\Skype\Phone\Skype.exe"="C:\Apps\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\APPS - SHARE\uTorrent\uTorrent.exe"="C:\APPS - SHARE\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Martin\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\Apps\GoodSync\GoodSync.exe"="C:\Apps\GoodSync\GoodSync.exe:*:Enabled:GoodSync"
"C:\Apps\GoodSync\GsExplorer.exe"="C:\Apps\GoodSync\GsExplorer.exe:*:Enabled:GoodSync Explorer"
"C:\Apps\GoodSync\Gs-Server.exe"="C:\Apps\GoodSync\Gs-Server.exe:*:Enabled:GoodSync Server"
"F:\Games\Mass Effect 2\Binaries\MassEffect2.exe"="F:\Games\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Game"
"F:\Games\Mass Effect 2\MassEffect2Launcher.exe"="F:\Games\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Launcher"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"F:\Games\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe"="F:\Games\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe:*:Enabled:Call of Juarez - Bound in Blood"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Apps\iTunes\iTunes.exe"="C:\Apps\iTunes\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2013-01-26 13:29:07 ----D---- C:\_OTM
2013-01-24 21:34:08 ----D---- C:\Program Files\trend micro
2013-01-24 21:34:07 ----D---- C:\rsit
2013-01-24 19:13:31 ----A---- C:\WINDOWS\system32\MovieCollector.exe
2013-01-24 19:12:39 ----A---- C:\WINDOWS\system32\moviecollectorsetup.exe
2013-01-15 07:37:31 ----A---- C:\WINDOWS\system32\javaws.exe
2013-01-15 07:36:55 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-01-15 07:36:55 ----A---- C:\WINDOWS\system32\javaw.exe
2013-01-15 07:36:55 ----A---- C:\WINDOWS\system32\java.exe
2013-01-07 08:24:50 ----D---- C:\Program Files\iPod
2013-01-07 08:24:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-01-06 23:55:57 ----D---- C:\Program Files\Common Files\ODBC
2013-01-04 19:11:03 ----A---- C:\WINDOWS\du.ini
2013-01-04 19:07:34 ----A---- C:\WINDOWS\DUO.INI
2013-01-04 09:31:10 ----D---- C:\Program Files\MSXML 4.0
2013-01-03 22:36:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\firebird
2013-01-03 22:02:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\CIGLER SOFTWARE
2013-01-03 19:27:12 ----A---- C:\WINDOWS\system32\GDS32.DLL
2013-01-03 19:27:09 ----D---- C:\Program Files\Firebird
2012-12-27 21:20:09 ----D---- C:\Program Files\Dropbox
2012-12-27 18:38:10 ----A---- C:\sound_bank_log.txt
2012-12-27 18:37:06 ----A---- C:\bink_log.txt
2012-12-27 18:31:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Pendulo Studios

======List of files/folders modified in the last 1 months======

2013-01-26 13:56:18 ----D---- C:\WINDOWS\Temp
2013-01-26 13:55:49 ----D---- C:\Documents and Settings\Martin\Data aplikací\Grindstone 2
2013-01-26 13:41:47 ----D---- C:\Documents and Settings\Martin\Data aplikací\Dropbox
2013-01-26 13:40:39 ----D---- C:\Documents and Settings\Martin\Data aplikací\Skype
2013-01-26 13:37:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-01-26 13:31:16 ----D---- C:\WINDOWS\system32
2013-01-26 13:31:16 ----AD---- C:\WINDOWS
2013-01-26 13:29:49 ----RD---- C:\Program Files\Skype
2013-01-26 12:51:07 ----D---- C:\Program Files\Secunia PSI
2013-01-26 09:40:44 ----AD---- C:\Zotero
2013-01-26 09:35:09 ----D---- C:\Documents and Settings\Martin\Data aplikací\GoodSync
2013-01-26 00:50:58 ----A---- C:\WINDOWS\VACCA.INI
2013-01-25 21:51:03 ----D---- C:\Documents and Settings\Martin\Data aplikací\uTorrent
2013-01-25 00:06:13 ----D---- C:\WINDOWS\system32\CatRoot2
2013-01-24 23:51:33 ----D---- C:\Apps
2013-01-24 23:13:46 ----D---- C:\WINDOWS\Debug
2013-01-24 21:34:08 ----RD---- C:\Program Files
2013-01-24 21:26:20 ----D---- C:\WINDOWS\system32\NtmsData
2013-01-24 19:44:41 ----D---- C:\WINDOWS\Registration
2013-01-24 19:42:12 ----SHD---- C:\WINDOWS\Installer
2013-01-24 19:42:03 ----D---- C:\Program Files\Common Files
2013-01-24 19:13:50 ----D---- C:\WINDOWS\Prefetch
2013-01-24 00:30:23 ----D---- C:\TEMP
2013-01-20 10:01:43 ----A---- C:\WINDOWS\Sandboxie.ini
2013-01-19 09:44:13 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-01-16 22:17:44 ----D---- C:\WINDOWS\WinSxS
2013-01-16 20:12:08 ----D---- C:\Program Files\Common Files\Adobe
2013-01-15 07:36:39 ----A---- C:\WINDOWS\system32\npdeployJava1.dll
2013-01-15 07:36:39 ----A---- C:\WINDOWS\system32\deployJava1.dll
2013-01-15 07:05:29 ----HD---- C:\WINDOWS\inf
2013-01-15 07:05:14 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-01-15 07:05:08 ----D---- C:\WINDOWS\ie8updates
2013-01-15 07:05:03 ----HD---- C:\WINDOWS\$hf_mig$
2013-01-13 00:02:28 ----D---- C:\Documents and Settings\Martin\Data aplikací\UHS Reader
2013-01-11 17:51:03 ----SD---- C:\WINDOWS\Tasks
2013-01-11 17:50:58 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-01-11 17:45:35 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-01-11 17:40:57 ----D---- C:\WINDOWS\system32\drivers
2013-01-09 12:57:59 ----RSD---- C:\WINDOWS\assembly
2013-01-09 12:57:59 ----D---- C:\WINDOWS\Microsoft.NET
2013-01-09 11:14:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-01-09 10:56:15 ----D---- C:\WINDOWS\pchealth
2013-01-09 10:40:29 ----A---- C:\WINDOWS\system32\MRT.exe
2013-01-07 22:05:24 ----D---- C:\Program Files\Amazon
2013-01-07 20:43:41 ----A---- C:\WINDOWS\DTLite.INI
2013-01-07 08:24:48 ----D---- C:\Program Files\Common Files\Apple
2013-01-07 08:24:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2013-01-07 08:21:00 ----DC---- C:\WINDOWS\system32\DRVSTORE
2013-01-07 08:18:17 ----D---- C:\iTunes Library
2013-01-06 06:33:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2013-01-05 16:23:44 ----D---- C:\WINDOWS\system32\CatRoot
2013-01-05 12:44:05 ----SD---- C:\WINDOWS\Downloaded Program Files
2013-01-04 09:16:20 ----D---- C:\WINDOWS\system32\spool
2013-01-03 22:29:09 ----D---- C:\WINDOWS\system32\oobe
2013-01-03 22:29:09 ----D---- C:\WINDOWS\system32\mui
2013-01-03 22:29:08 ----D---- C:\WINDOWS\SoftwareDistribution
2013-01-03 22:29:08 ----D---- C:\WINDOWS\security
2013-01-03 22:29:04 ----D---- C:\WINDOWS\ime
2013-01-03 22:29:03 ----D---- C:\Program Files\Windows Media Player
2013-01-03 22:29:01 ----D---- C:\Program Files\Online Armor
2013-01-03 22:28:59 ----D---- C:\Program Files\Internet Explorer
2013-01-03 22:28:47 ----D---- C:\Documents and Settings
2012-12-31 13:14:06 ----D---- C:\Documents and Settings\Martin\Data aplikací\Audacity
2012-12-30 23:42:22 ----D---- C:\Documents and Settings\Martin\Data aplikací\Media Player Classic
2012-12-29 23:19:58 ----D---- C:\Documents and Settings\Martin\Data aplikací\Winamp
2012-12-27 18:06:24 ----D---- C:\WINDOWS\system32\DirectX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [2002-07-17 16877]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2012-05-08 137928]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2011-12-15 36000]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 OADevice;OADriver; \??\C:\WINDOWS\system32\drivers\OADriver.sys []
R1 oahlpXX;Online Armor helper driver; \??\C:\WINDOWS\system32\drivers\oahlp32.sys []
R1 OAmon;OAmon; \??\C:\WINDOWS\system32\drivers\OAmon.sys []
R1 OAnet;OAnet; \??\C:\WINDOWS\system32\drivers\OAnet.sys []
R1 SASDIFSV;SASDIFSV; \??\C:\Apps\SUPERAntispyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Apps\SUPERAntispyware\SASKUTIL.SYS []
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2012-02-10 231760]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2012-07-08 271360]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2012-05-08 83392]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2012-07-08 18048]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2009-07-20 339456]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2007-06-06 161792]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2012-09-23 12557728]
R3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
R3 SbieDrv;SbieDrv; \??\C:\Apps\Sandboxie\SbieDrv.sys []
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Documents and Settings\Martin\Local Settings\Temp\tmp1.tmp []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 a0to8klv;a0to8klv; C:\WINDOWS\system32\drivers\a0to8klv.sys []
S3 epmntdrv;epmntdrv; \??\C:\WINDOWS\system32\epmntdrv.sys []
S3 EuGdiDrv;EuGdiDrv; \??\C:\WINDOWS\system32\EuGdiDrv.sys []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
S3 PROCEXP151;PROCEXP151; \??\C:\WINDOWS\system32\Drivers\PROCEXP151.SYS []
S3 RivaTuner32;RivaTuner32; \??\C:\Apps\RivaTuner\RivaTuner32.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2008-05-12 11520]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Apps\SUPERAntispyware\SASCORE.EXE [2012-07-11 116608]
R2 AntiVirService;Avira Realtime Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2012-05-08 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2012-05-08 86224]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe [2007-12-12 65536]
R2 FlashFolder;FlashFolder; C:\Apps\FlashFolder\FlashFolder.exe [2008-03-21 71680]
R2 GsServer;GoodSync Server; C:\Apps\GoodSync\Gs-Server.exe [2012-09-10 3472088]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [2012-05-04 161664]
R2 nlsX86cc;NLS Service; C:\WINDOWS\system32\NLSSRV32.EXE [2011-11-02 68896]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2012-09-23 164200]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2009-04-08 1377536]
R2 OAcat;Online Armor Helper Service; C:\Program Files\Online Armor\OAcat.exe [2012-10-03 216072]
R2 SbieSvc;Sandboxie Service; C:\Apps\Sandboxie\SbieSvc.exe [2012-12-16 85776]
R2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files\Secunia PSI\PSIA.exe [2012-11-26 1225312]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Apps\Spyware Terminator\sp_rsser.exe [2012-01-30 496128]
R2 SvcOnlineArmor;Online Armor; C:\Program Files\Online Armor\oasrv.exe [2012-10-03 4463864]
R2 USBSafelyRemoveService;USB Safely Remove Assistant; C:\Apps\USB Safely Remove\USBSRService.exe [2011-08-04 257880]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service; C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2009-06-26 102400]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe [2007-12-12 1531989]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-09-23 1258856]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2012-01-30 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-12-12 553440]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-01-18 115608]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
Win10 Pro = Avast Free = Comodo Firewall Free

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu po nalezení a odstranění TR/Dropper.MSIL.G

#4 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\Martin.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

lastsaves
Návštěvník
Návštěvník
Příspěvky: 113
Registrován: 17 zář 2007 16:43

Re: Kontrola logu po nalezení a odstranění TR/Dropper.MSIL.G

#5 Příspěvek od lastsaves »

Provedeno, díky za pomoc!
Win10 Pro = Avast Free = Comodo Firewall Free

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu po nalezení a odstranění TR/Dropper.MSIL.G

#6 Příspěvek od Rudy »

Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno