Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
1mrna
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 10 lis 2012 19:13

Prosím o kontrolu logu

#1 Příspěvek od 1mrna »

Dobrý den Comodo mi často detekuje: backdoor.win32.pcclient
Vždy ho uloží do karanteny a za nějaký čas ho detekuje znovu.

Log zde:

Logfile of random's system information tool 1.09 (written by random/random)
Run by ABC at 2014-02-02 20:35:43
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (58%) free of 38 GB
Total RAM: 1151 MB (35% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:36:12, on 2.2.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
C:\Program Files\IObit\Advanced SystemCare 7\DiskDefrag.exe
C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
C:\Program Files\IObit\Advanced SystemCare 7\Asc.exe
C:\Program Files\IObit\Advanced SystemCare 7\RealtimeProtector.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
D:\Downloads\RSIT.exe
C:\Program Files\trend micro\ABC.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sk27211/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll
O2 - BHO: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll
O2 - BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll
O3 - Toolbar: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{39C8A154-EBF0-467C-A71E-4A0B8CB581C6}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files\Comodo\Dragon\dragon_updater.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 8156 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\ASC7_PerformanceMonitor.job
C:\WINDOWS\tasks\Driver Booster Scan.job
C:\WINDOWS\tasks\Driver Booster Update.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default

prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "browser.startup.homepage" - "http://start.icq.com/sk27211/"
prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =402027&p="

"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsRLCT4Player.xpt

C:\Program Files\Mozilla Firefox\plugins\
CrazyTalk4Native.dll
ctdomemhelper.dll
ctframeplayerobject.dll
ctplayerobject.dll
imagickrt.dll
NPOFF12.DLL
npRLCT4Player.dll
npwachk.dll
rlcontentclass.dll
RLMusicPacker.dll
RLMusicUnpacker.dll
RLVoicePacker.dll
RLVoiceUnpacker.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\extensions\
ascsurfingprotection@iobit.com
savingsslider@mybrowserbar.com
{58d2a791-6199-482f-a9aa-9b725ec61362}
{800b5000-a755-47e1-992b-48a1c1357f07}

C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\searchplugins\
icqplugin.xml
yahoo_ff.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
IObit Apps Toolbar - C:\Program Files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll [2014-01-16 1398080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-02-02 752448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-09-29 668992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - IObit Apps Toolbar - C:\Program Files\IObit Apps Toolbar\IE\8.6\iobitappsToolbarIE.dll [2014-01-16 1398080]
{10921475-03CE-4E04-90CE-E2E7EF20C814} - ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-02-02 752448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AudioDeck"=C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe [2007-08-09 528384]
"PAC207_Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-11-07 6756048]
"SearchSettings"=C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe [2014-01-16 1384256]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2014-01-15 5625624]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Advanced SystemCare 7"=C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2013-09-29 2326848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2013-09-29 2326848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-09-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe /autostart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2013-06-07 774680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2004-11-04 258048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Rychlé spuštění aplikace HP Image Zone.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2004-11-04 53248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2014-01-04 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-04-27 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\ICQ7M\ICQ.exe"="C:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7M\ICQ.exe"="C:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.LEAD"=LCODCCMP.DLL

======List of files/folders created in the last 1 month======

2014-02-02 20:35:43 ----D---- C:\rsit
2014-01-30 16:55:58 ----A---- C:\WINDOWS\system32\certsentry.dll
2014-01-20 17:20:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-01-18 14:06:30 ----D---- C:\Program Files\Machinarium
2014-01-18 09:57:58 ----D---- C:\Documents and Settings\ABC\Data aplikací\IObit Apps
2014-01-17 13:01:55 ----N---- C:\WINDOWS\SchedLgU.Txt
2014-01-17 09:08:25 ----D---- C:\Documents and Settings\ABC\Data aplikací\Search Settings
2014-01-17 09:06:30 ----D---- C:\Program Files\Application Updater
2014-01-17 09:06:18 ----D---- C:\Program Files\IObit Apps Toolbar
2014-01-17 09:06:18 ----D---- C:\Program Files\Common Files\Spigot
2014-01-15 11:16:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-01-10 16:41:25 ----D---- C:\Program Files\Common Files\Adobe
2014-01-09 17:05:24 ----D---- C:\first_launch
2014-01-04 17:38:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2808679$
2014-01-04 17:34:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2492386$
2014-01-04 17:32:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2014-01-04 17:32:10 ----HDC---- C:\WINDOWS\$NtUninstallbasecsp$
2014-01-04 16:58:35 ----A---- C:\WINDOWS\eReg.dat
2014-01-04 16:26:49 ----D---- C:\Program Files\EA GAMES
2014-01-04 13:48:09 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2014-01-04 13:48:09 ----A---- C:\WINDOWS\system32\drivers\Rtnicxp.sys
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\atitvo32.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atioglxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atioglx1.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atikvmag.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ATIDEMGR.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2014-01-04 12:34:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2014-01-04 12:33:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2014-01-04 12:33:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2014-01-04 12:33:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2014-01-04 12:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2014-01-04 12:32:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2014-01-04 12:32:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2014-01-04 12:32:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2834886$
2014-01-04 12:32:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2014-01-04 12:31:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2014-01-04 12:31:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2014-01-04 12:31:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2014-01-04 12:31:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2014-01-04 12:30:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2847311$
2014-01-04 12:30:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2014-01-04 12:30:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2802968$
2014-01-04 12:29:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2014-01-04 12:29:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2014-01-04 12:28:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2014-01-04 12:28:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2014-01-04 12:28:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2014-01-04 12:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2862335$
2014-01-04 12:27:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2014-01-04 12:27:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2014-01-04 12:27:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2780091$
2014-01-04 12:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2845187$
2014-01-04 12:27:09 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2014-01-04 12:26:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2014-01-04 12:26:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2876217$
2014-01-04 12:26:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2864063$
2014-01-04 12:26:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2014-01-04 12:26:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2014-01-04 12:25:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2014-01-04 12:25:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2014-01-04 12:25:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2014-01-04 12:25:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2850869$
2014-01-04 12:25:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
2014-01-04 12:24:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2859537$
2014-01-04 12:24:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2014-01-04 12:24:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2014-01-04 12:24:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2884256$
2014-01-04 12:24:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2868038$
2014-01-04 12:18:57 ----D---- C:\WINDOWS\system32\MRT
2014-01-04 12:18:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2820917$
2014-01-04 12:17:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2014-01-04 12:17:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2014-01-04 12:17:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2014-01-04 12:17:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2014-01-04 12:17:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2014-01-04 12:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2014-01-04 12:16:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2014-01-04 12:16:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2014-01-04 12:15:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2893984$
2014-01-04 11:57:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2014-01-04 11:57:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2014-01-04 11:57:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2014-01-04 11:56:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2014-01-04 11:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2014-01-04 11:56:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2014-01-04 11:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2862330$
2014-01-04 11:53:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2813345$
2014-01-04 11:53:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2014-01-04 11:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2014-01-04 11:51:28 ----D---- C:\Program Files\MSXML 4.0
2014-01-04 11:51:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2014-01-04 11:50:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2014-01-04 11:50:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2014-01-04 11:50:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2014-01-03 16:36:52 ----N---- C:\WINDOWS\system32\iacenc.dll
2014-01-03 12:27:46 ----A---- C:\WINDOWS\system32\SET12E.tmp
2014-01-03 12:27:46 ----A---- C:\WINDOWS\system32\SET108.tmp
2014-01-03 12:27:44 ----A---- C:\WINDOWS\system32\atiicdxx.dat
2014-01-03 12:27:43 ----A---- C:\WINDOWS\system32\SET12D.tmp
2014-01-03 12:27:43 ----A---- C:\WINDOWS\system32\SET106.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET129.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET128.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET103.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET101.tmp
2014-01-03 12:17:00 ----A---- C:\WINDOWS\system32\RegistryDefragBootTime.exe
2014-01-03 11:22:21 ----A---- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys
2014-01-03 11:16:33 ----D---- C:\Documents and Settings\ABC\Data aplikací\Apple Computer
2014-01-03 11:16:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\ProductData
2014-01-03 11:14:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-01-03 11:14:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-01-03 11:14:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2014-01-03 11:14:30 ----D---- C:\Documents and Settings\ABC\Data aplikací\IObit
2014-01-03 11:14:08 ----D---- C:\Program Files\IObit
2014-01-03 10:50:02 ----A---- C:\WINDOWS\system32\hidserv.dll
2014-01-03 10:49:55 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2014-01-03 10:49:43 ----A---- C:\WINDOWS\system32\drivers\usbvideo.sys

======List of files/folders modified in the last 1 month======

2014-02-02 20:36:12 ----D---- C:\Program Files\trend micro
2014-02-02 20:35:50 ----D---- C:\WINDOWS\Prefetch
2014-02-02 19:52:39 ----D---- C:\WINDOWS
2014-02-02 19:24:54 ----D---- C:\WINDOWS\system32\CatRoot2
2014-02-02 19:24:54 ----D---- C:\WINDOWS\system32
2014-02-02 19:24:47 ----SD---- C:\WINDOWS\Downloaded Program Files
2014-02-02 19:14:56 ----D---- C:\WINDOWS\system32\config
2014-02-02 19:06:22 ----D---- C:\WINDOWS\Temp
2014-02-02 19:03:03 ----SD---- C:\WINDOWS\Tasks
2014-02-02 15:53:50 ----RD---- C:\Program Files
2014-02-01 19:43:50 ----D---- C:\WINDOWS\pss
2014-01-31 17:29:56 ----D---- C:\Documents and Settings\ABC\Data aplikací\Winamp
2014-01-31 17:29:07 ----D---- C:\Program Files\CCleaner
2014-01-30 21:42:23 ----SHD---- C:\WINDOWS\CSC
2014-01-30 16:55:39 ----D---- C:\Program Files\COMODO
2014-01-29 22:33:11 ----D---- C:\Documents and Settings\ABC\Data aplikací\Skype
2014-01-28 03:02:13 ----D---- C:\Documents and Settings\ABC\Data aplikací\vlc
2014-01-21 08:38:17 ----D---- C:\WINDOWS\SoftwareDistribution
2014-01-21 08:36:10 ----D---- C:\WINDOWS\Debug
2014-01-20 16:55:00 ----HD---- C:\WINDOWS\inf
2014-01-18 10:18:04 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-01-17 09:08:42 ----SHD---- C:\WINDOWS\Installer
2014-01-17 09:07:45 ----D---- C:\Config.Msi
2014-01-17 09:06:18 ----D---- C:\Program Files\Common Files
2014-01-15 11:23:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-01-15 11:16:56 ----A---- C:\WINDOWS\system32\MRT.exe
2014-01-15 11:16:26 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-01-15 11:16:26 ----D---- C:\WINDOWS\system32\drivers
2014-01-15 09:07:59 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-10 16:17:58 ----SD---- C:\Documents and Settings\ABC\Data aplikací\Microsoft
2014-01-06 13:04:18 ----D---- C:\Program Files\Microsoft Office
2014-01-04 17:37:11 ----HD---- C:\WINDOWS\$hf_mig$
2014-01-04 17:36:50 ----D---- C:\Program Files\Internet Explorer
2014-01-04 17:34:13 ----D---- C:\WINDOWS\AppPatch
2014-01-04 17:32:33 ----D---- C:\WINDOWS\security
2014-01-04 17:06:45 ----HD---- C:\Program Files\InstallShield Installation Information
2014-01-04 13:50:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ati3duag.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2014-01-04 12:33:13 ----D---- C:\WINDOWS\WinSxS
2014-01-04 12:07:17 ----RSD---- C:\WINDOWS\Fonts
2014-01-04 12:06:09 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-01-04 12:06:04 ----D---- C:\Program Files\Microsoft Works
2014-01-04 11:52:16 ----D---- C:\WINDOWS\ie8updates
2014-01-04 08:38:27 ----D---- C:\WINDOWS\system32\CatRoot
2014-01-03 16:06:07 ----D---- C:\WINDOWS\Help
2014-01-03 14:21:24 ----D---- C:\Program Files\Ashampoo
2014-01-03 13:33:12 ----D---- C:\WINDOWS\system32\wbem
2014-01-03 13:33:10 ----D---- C:\WINDOWS\Registration
2014-01-03 11:21:38 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-01-03 11:17:28 ----SHD---- C:\System Volume Information
2014-01-03 11:17:28 ----D---- C:\WINDOWS\system32\Restore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hotcore3;hc3ServiceName; C:\WINDOWS\system32\DRIVERS\hotcore3.sys [2010-01-17 40560]
R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2012-11-07 99080]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2013-05-22 14776]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-02-04 691696]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2011-01-29 27904]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2014-01-04 13976]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-04-27 77568]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-27 41600]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2012-11-07 18096]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2012-11-07 497952]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2012-11-07 32640]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\WINDOWS\System32\Drivers\Uim_IM.sys [2010-01-17 385544]
R1 UimBus;Universal Image Mounter Controller; C:\WINDOWS\system32\DRIVERS\UimBus.sys [2010-01-17 34392]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R3 admjoy;Aureal Game Port Enumerator; C:\WINDOWS\system32\DRIVERS\admjoy.sys [2008-04-13 10880]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2014-01-04 1540608]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-27 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2014-01-04 130432]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2013-07-17 123008]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2007-06-27 207488]
S3 an2mgb0u;an2mgb0u; C:\WINDOWS\system32\drivers\an2mgb0u.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-27 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-12-15 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-12-15 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-12-15 21744]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-27 61824]
S3 PAC207;Eye 110; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-04-27 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-04-27 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2012-07-11 116608]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [2013-09-29 962880]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2014-01-16 807800]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2014-01-04 413696]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-11-07 1990464]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2014-01-28 2135232]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-04 153376]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-02 2151232]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-18 257928]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-24 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119533
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#2 Příspěvek od Rudy »

Zdravím!
Doporučil bych odinstalovat AdvancedSystemCare. Důvod: http://forum.viry.cz/viewtopic.php?f=14 ... ilit=iobit . Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

1mrna
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 10 lis 2012 19:13

Re: Prosím o kontrolu logu

#3 Příspěvek od 1mrna »

# AdwCleaner v3.018 - Report created 02/02/2014 at 20:59:25
# Updated 28/01/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : ABC - ABCPC
# Running from : C:\Documents and Settings\ABC\Plocha\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : Application Updater

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\Application Updater
Folder Deleted : C:\Program Files\IObit Apps Toolbar
Folder Deleted : C:\Program Files\Common Files\spigot
Folder Deleted : C:\Documents and Settings\ABC\Data aplikací\Search Settings
Folder Deleted : C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
File Deleted : C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\searchplugins\icqplugin.xml
File Deleted : C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\user.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchSettings]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\Search Settings
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKLM\Software\Application Updater
Key Deleted : HKLM\Software\Search Settings

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

-\\ Mozilla Firefox v16.0.2 (cs)

[ File : C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\prefs.js ]

Line Deleted : user_pref("icqtoolbar.skip_default_search", "yes");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://start.icq.com/sk27211/");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://start.icq.com/");
Line Deleted : user_pref("icqtoolbar.showPc", true);
Line Deleted : user_pref("icqtoolbar.installsource", "1");

*************************

AdwCleaner[R0].txt - [3378 octets] - [02/02/2014 20:58:17]
AdwCleaner[S0].txt - [3264 octets] - [02/02/2014 20:59:25]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3324 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119533
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

1mrna
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 10 lis 2012 19:13

Re: Prosím o kontrolu logu

#5 Příspěvek od 1mrna »

Logfile of random's system information tool 1.09 (written by random/random)
Run by ABC at 2014-02-02 21:13:09
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (58%) free of 38 GB
Total RAM: 1151 MB (13% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:13:33, on 2.2.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\IObit\Advanced SystemCare 7\RealTimeProtector.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
D:\Downloads\RSIT (1).exe
C:\Program Files\trend micro\ABC.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sk27211/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{39C8A154-EBF0-467C-A71E-4A0B8CB581C6}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files\Comodo\Dragon\dragon_updater.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 7333 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\ASC7_PerformanceMonitor.job
C:\WINDOWS\tasks\Driver Booster Scan.job
C:\WINDOWS\tasks\Driver Booster Update.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default

prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =402027&p="

"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsRLCT4Player.xpt

C:\Program Files\Mozilla Firefox\plugins\
CrazyTalk4Native.dll
ctdomemhelper.dll
ctframeplayerobject.dll
ctplayerobject.dll
imagickrt.dll
NPOFF12.DLL
npRLCT4Player.dll
npwachk.dll
rlcontentclass.dll
RLMusicPacker.dll
RLMusicUnpacker.dll
RLVoicePacker.dll
RLVoiceUnpacker.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\extensions\
ascsurfingprotection@iobit.com
savingsslider@mybrowserbar.com
{58d2a791-6199-482f-a9aa-9b725ec61362}

C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\searchplugins\
yahoo_ff.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-02-02 752448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-09-29 668992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{10921475-03CE-4E04-90CE-E2E7EF20C814} - ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-02-02 752448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AudioDeck"=C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe [2007-08-09 528384]
"PAC207_Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-11-07 6756048]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2014-01-15 5625624]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Advanced SystemCare 7"=C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2013-09-29 2326848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2013-09-29 2326848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-09-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe /autostart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2013-06-07 774680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2004-11-04 258048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Rychlé spuštění aplikace HP Image Zone.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2004-11-04 53248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2014-01-04 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-04-27 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\ICQ7M\ICQ.exe"="C:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7M\ICQ.exe"="C:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.LEAD"=LCODCCMP.DLL

======List of files/folders created in the last 1 month======

2014-02-02 21:01:32 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-02-02 21:01:15 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2014-02-02 20:58:13 ----D---- C:\AdwCleaner
2014-02-02 20:35:43 ----D---- C:\rsit
2014-01-30 16:55:58 ----A---- C:\WINDOWS\system32\certsentry.dll
2014-01-20 17:20:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-01-18 14:06:30 ----D---- C:\Program Files\Machinarium
2014-01-18 09:57:58 ----D---- C:\Documents and Settings\ABC\Data aplikací\IObit Apps
2014-01-15 11:16:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-01-10 16:41:25 ----D---- C:\Program Files\Common Files\Adobe
2014-01-09 17:05:24 ----D---- C:\first_launch
2014-01-04 17:38:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2808679$
2014-01-04 17:34:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2492386$
2014-01-04 17:32:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2014-01-04 17:32:10 ----HDC---- C:\WINDOWS\$NtUninstallbasecsp$
2014-01-04 16:58:35 ----A---- C:\WINDOWS\eReg.dat
2014-01-04 16:26:49 ----D---- C:\Program Files\EA GAMES
2014-01-04 13:48:09 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2014-01-04 13:48:09 ----A---- C:\WINDOWS\system32\drivers\Rtnicxp.sys
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\atitvo32.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atioglxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atioglx1.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atikvmag.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ATIDEMGR.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2014-01-04 12:34:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2014-01-04 12:33:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2014-01-04 12:33:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2014-01-04 12:33:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2014-01-04 12:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2014-01-04 12:32:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2014-01-04 12:32:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2014-01-04 12:32:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2834886$
2014-01-04 12:32:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2014-01-04 12:31:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2014-01-04 12:31:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2014-01-04 12:31:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2014-01-04 12:31:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2014-01-04 12:30:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2847311$
2014-01-04 12:30:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2014-01-04 12:30:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2802968$
2014-01-04 12:29:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2014-01-04 12:29:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2014-01-04 12:28:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2014-01-04 12:28:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2014-01-04 12:28:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2014-01-04 12:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2862335$
2014-01-04 12:27:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2014-01-04 12:27:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2014-01-04 12:27:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2780091$
2014-01-04 12:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2845187$
2014-01-04 12:27:09 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2014-01-04 12:26:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2014-01-04 12:26:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2876217$
2014-01-04 12:26:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2864063$
2014-01-04 12:26:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2014-01-04 12:26:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2014-01-04 12:25:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2014-01-04 12:25:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2014-01-04 12:25:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2014-01-04 12:25:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2850869$
2014-01-04 12:25:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
2014-01-04 12:24:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2859537$
2014-01-04 12:24:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2014-01-04 12:24:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2014-01-04 12:24:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2884256$
2014-01-04 12:24:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2868038$
2014-01-04 12:18:57 ----D---- C:\WINDOWS\system32\MRT
2014-01-04 12:18:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2820917$
2014-01-04 12:17:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2014-01-04 12:17:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2014-01-04 12:17:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2014-01-04 12:17:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2014-01-04 12:17:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2014-01-04 12:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2014-01-04 12:16:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2014-01-04 12:16:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2014-01-04 12:15:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2893984$
2014-01-04 11:57:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2014-01-04 11:57:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2014-01-04 11:57:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2014-01-04 11:56:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2014-01-04 11:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2014-01-04 11:56:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2014-01-04 11:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2862330$
2014-01-04 11:53:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2813345$
2014-01-04 11:53:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2014-01-04 11:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2014-01-04 11:51:28 ----D---- C:\Program Files\MSXML 4.0
2014-01-04 11:51:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2014-01-04 11:50:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2014-01-04 11:50:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2014-01-04 11:50:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2014-01-03 16:36:52 ----N---- C:\WINDOWS\system32\iacenc.dll
2014-01-03 12:27:46 ----A---- C:\WINDOWS\system32\SET12E.tmp
2014-01-03 12:27:46 ----A---- C:\WINDOWS\system32\SET108.tmp
2014-01-03 12:27:44 ----A---- C:\WINDOWS\system32\atiicdxx.dat
2014-01-03 12:27:43 ----A---- C:\WINDOWS\system32\SET12D.tmp
2014-01-03 12:27:43 ----A---- C:\WINDOWS\system32\SET106.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET129.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET128.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET103.tmp
2014-01-03 12:27:42 ----A---- C:\WINDOWS\system32\SET101.tmp
2014-01-03 12:17:00 ----A---- C:\WINDOWS\system32\RegistryDefragBootTime.exe
2014-01-03 11:22:21 ----A---- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys
2014-01-03 11:16:33 ----D---- C:\Documents and Settings\ABC\Data aplikací\Apple Computer
2014-01-03 11:16:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\ProductData
2014-01-03 11:14:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-01-03 11:14:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-01-03 11:14:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2014-01-03 11:14:30 ----D---- C:\Documents and Settings\ABC\Data aplikací\IObit
2014-01-03 11:14:08 ----D---- C:\Program Files\IObit
2014-01-03 10:50:02 ----A---- C:\WINDOWS\system32\hidserv.dll
2014-01-03 10:49:55 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2014-01-03 10:49:43 ----A---- C:\WINDOWS\system32\drivers\usbvideo.sys

======List of files/folders modified in the last 1 month======

2014-02-02 21:13:17 ----D---- C:\Program Files\trend micro
2014-02-02 21:13:15 ----D---- C:\WINDOWS\Prefetch
2014-02-02 21:06:51 ----D---- C:\WINDOWS\system32\CatRoot2
2014-02-02 21:02:33 ----D---- C:\WINDOWS\SoftwareDistribution
2014-02-02 21:02:24 ----D---- C:\WINDOWS\Temp
2014-02-02 21:01:53 ----D---- C:\WINDOWS
2014-02-02 21:01:21 ----D---- C:\WINDOWS\Debug
2014-02-02 21:01:15 ----D---- C:\WINDOWS\system32
2014-02-02 20:59:30 ----D---- C:\Program Files\Common Files
2014-02-02 20:59:28 ----RD---- C:\Program Files
2014-02-02 19:24:47 ----SD---- C:\WINDOWS\Downloaded Program Files
2014-02-02 19:14:56 ----D---- C:\WINDOWS\system32\config
2014-02-02 19:03:03 ----SD---- C:\WINDOWS\Tasks
2014-02-01 19:43:50 ----D---- C:\WINDOWS\pss
2014-01-31 17:29:56 ----D---- C:\Documents and Settings\ABC\Data aplikací\Winamp
2014-01-31 17:29:07 ----D---- C:\Program Files\CCleaner
2014-01-30 21:42:23 ----SHD---- C:\WINDOWS\CSC
2014-01-30 16:55:39 ----D---- C:\Program Files\COMODO
2014-01-29 22:33:11 ----D---- C:\Documents and Settings\ABC\Data aplikací\Skype
2014-01-28 03:02:13 ----D---- C:\Documents and Settings\ABC\Data aplikací\vlc
2014-01-20 16:55:00 ----HD---- C:\WINDOWS\inf
2014-01-18 10:18:04 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-01-17 09:08:42 ----SHD---- C:\WINDOWS\Installer
2014-01-17 09:07:45 ----D---- C:\Config.Msi
2014-01-15 11:23:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-01-15 11:16:56 ----A---- C:\WINDOWS\system32\MRT.exe
2014-01-15 11:16:26 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-01-15 11:16:26 ----D---- C:\WINDOWS\system32\drivers
2014-01-15 09:07:59 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-10 16:17:58 ----SD---- C:\Documents and Settings\ABC\Data aplikací\Microsoft
2014-01-06 13:04:18 ----D---- C:\Program Files\Microsoft Office
2014-01-04 17:37:11 ----HD---- C:\WINDOWS\$hf_mig$
2014-01-04 17:36:50 ----D---- C:\Program Files\Internet Explorer
2014-01-04 17:34:13 ----D---- C:\WINDOWS\AppPatch
2014-01-04 17:32:33 ----D---- C:\WINDOWS\security
2014-01-04 17:06:45 ----HD---- C:\Program Files\InstallShield Installation Information
2014-01-04 13:50:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ati3duag.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2014-01-04 12:33:13 ----D---- C:\WINDOWS\WinSxS
2014-01-04 12:07:17 ----RSD---- C:\WINDOWS\Fonts
2014-01-04 12:06:09 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-01-04 12:06:04 ----D---- C:\Program Files\Microsoft Works
2014-01-04 11:52:16 ----D---- C:\WINDOWS\ie8updates
2014-01-04 08:38:27 ----D---- C:\WINDOWS\system32\CatRoot
2014-01-03 16:06:07 ----D---- C:\WINDOWS\Help
2014-01-03 14:21:24 ----D---- C:\Program Files\Ashampoo
2014-01-03 13:33:12 ----D---- C:\WINDOWS\system32\wbem
2014-01-03 13:33:10 ----D---- C:\WINDOWS\Registration
2014-01-03 11:21:38 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-01-03 11:17:28 ----SHD---- C:\System Volume Information
2014-01-03 11:17:28 ----D---- C:\WINDOWS\system32\Restore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hotcore3;hc3ServiceName; C:\WINDOWS\system32\DRIVERS\hotcore3.sys [2010-01-17 40560]
R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2012-11-07 99080]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2013-05-22 14776]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-02-04 691696]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2011-01-29 27904]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2014-01-04 13976]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-04-27 77568]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-27 41600]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2012-11-07 18096]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2012-11-07 497952]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2012-11-07 32640]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\WINDOWS\System32\Drivers\Uim_IM.sys [2010-01-17 385544]
R1 UimBus;Universal Image Mounter Controller; C:\WINDOWS\system32\DRIVERS\UimBus.sys [2010-01-17 34392]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R3 admjoy;Aureal Game Port Enumerator; C:\WINDOWS\system32\DRIVERS\admjoy.sys [2008-04-13 10880]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2014-01-04 1540608]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-27 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2014-01-04 130432]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2013-07-17 123008]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2007-06-27 207488]
S3 afhjoq63;afhjoq63; C:\WINDOWS\system32\drivers\afhjoq63.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-27 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-12-15 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-12-15 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-12-15 21744]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-27 61824]
S3 PAC207;Eye 110; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-04-27 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-04-27 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2012-07-11 116608]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [2013-09-29 962880]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2014-01-04 413696]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-11-07 1990464]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2014-01-28 2135232]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-04 153376]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-02 2151232]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-18 257928]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-24 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119533
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\WINDOWS\system32\SET*.tmp

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

1mrna
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 10 lis 2012 19:13

Re: Prosím o kontrolu logu

#7 Příspěvek od 1mrna »

Logfile of random's system information tool 1.09 (written by random/random)
Run by ABC at 2014-02-02 22:10:35
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (58%) free of 38 GB
Total RAM: 1151 MB (25% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:10:49, on 2.2.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\IObit\Advanced SystemCare 7\RealTimeProtector.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Program Files\COMODO\Dragon\dragon.exe
C:\Documents and Settings\ABC\Plocha\RSIT.exe
C:\Program Files\trend micro\ABC.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sk27211/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{39C8A154-EBF0-467C-A71E-4A0B8CB581C6}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files\Comodo\Dragon\dragon_updater.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 7281 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\ASC7_PerformanceMonitor.job
C:\WINDOWS\tasks\Driver Booster Scan.job
C:\WINDOWS\tasks\Driver Booster Update.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default

prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "extensions.enabledItems" - "jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3, {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.13"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =402027&p="

"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsRLCT4Player.xpt

C:\Program Files\Mozilla Firefox\plugins\
CrazyTalk4Native.dll
ctdomemhelper.dll
ctframeplayerobject.dll
ctplayerobject.dll
imagickrt.dll
NPOFF12.DLL
npRLCT4Player.dll
npwachk.dll
rlcontentclass.dll
RLMusicPacker.dll
RLMusicUnpacker.dll
RLVoicePacker.dll
RLVoiceUnpacker.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\extensions\
ascsurfingprotection@iobit.com
savingsslider@mybrowserbar.com
{58d2a791-6199-482f-a9aa-9b725ec61362}

C:\Documents and Settings\ABC\Data aplikací\Mozilla\Firefox\Profiles\4ohacy60.default\searchplugins\
yahoo_ff.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-02-02 752448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-09-29 668992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-04 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{10921475-03CE-4E04-90CE-E2E7EF20C814} - ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-02-02 752448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AudioDeck"=C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe [2007-08-09 528384]
"PAC207_Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-11-07 6756048]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2014-01-15 5625624]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Advanced SystemCare 7"=C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2013-09-29 2326848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2013-09-29 2326848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-09-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe /autostart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2012-11-09 17877168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zoner Photo Studio Autoupdate]
C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2013-06-07 774680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2004-11-04 258048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Rychlé spuštění aplikace HP Image Zone.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2004-11-04 53248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2014-01-04 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-04-27 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\ICQ7M\ICQ.exe"="C:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7M\ICQ.exe"="C:\Program Files\ICQ7M\ICQ.exe:*:Enabled:ICQ7M"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"midi"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.LEAD"=LCODCCMP.DLL

======List of files/folders created in the last 1 month======

2014-02-02 22:03:12 ----D---- C:\_OTM
2014-02-02 21:01:32 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-02-02 21:01:15 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2014-02-02 20:58:13 ----D---- C:\AdwCleaner
2014-02-02 20:35:43 ----D---- C:\rsit
2014-01-30 16:55:58 ----A---- C:\WINDOWS\system32\certsentry.dll
2014-01-20 17:20:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-01-18 14:06:30 ----D---- C:\Program Files\Machinarium
2014-01-18 09:57:58 ----D---- C:\Documents and Settings\ABC\Data aplikací\IObit Apps
2014-01-15 11:16:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2014-01-10 16:41:25 ----D---- C:\Program Files\Common Files\Adobe
2014-01-09 17:05:24 ----D---- C:\first_launch
2014-01-04 17:38:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2808679$
2014-01-04 17:34:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2492386$
2014-01-04 17:32:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2014-01-04 17:32:10 ----HDC---- C:\WINDOWS\$NtUninstallbasecsp$
2014-01-04 16:58:35 ----A---- C:\WINDOWS\eReg.dat
2014-01-04 16:26:49 ----D---- C:\Program Files\EA GAMES
2014-01-04 13:48:09 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
2014-01-04 13:48:09 ----A---- C:\WINDOWS\system32\drivers\Rtnicxp.sys
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\atitvo32.dll
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atioglxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atioglx1.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atikvmag.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ATIDEMGR.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\drivers\ati2erec.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2014-01-04 12:34:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2014-01-04 12:33:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2014-01-04 12:33:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2014-01-04 12:33:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2014-01-04 12:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2564958$
2014-01-04 12:32:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2758857$
2014-01-04 12:32:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893-v2$
2014-01-04 12:32:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2834886$
2014-01-04 12:32:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2014-01-04 12:31:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2585542$
2014-01-04 12:31:42 ----HDC---- C:\WINDOWS\$NtUninstallKB2631813$
2014-01-04 12:31:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2014-01-04 12:31:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2014-01-04 12:30:58 ----HDC---- C:\WINDOWS\$NtUninstallKB2847311$
2014-01-04 12:30:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2014-01-04 12:30:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2802968$
2014-01-04 12:29:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2014-01-04 12:29:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2014-01-04 12:28:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2485663$
2014-01-04 12:28:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2598479$
2014-01-04 12:28:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2014-01-04 12:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2862335$
2014-01-04 12:27:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2014-01-04 12:27:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2014-01-04 12:27:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2780091$
2014-01-04 12:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2845187$
2014-01-04 12:27:09 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2014-01-04 12:26:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2014-01-04 12:26:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2876217$
2014-01-04 12:26:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2864063$
2014-01-04 12:26:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2014-01-04 12:26:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2014-01-04 12:25:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2592799$
2014-01-04 12:25:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2014-01-04 12:25:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2014-01-04 12:25:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2850869$
2014-01-04 12:25:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
2014-01-04 12:24:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2859537$
2014-01-04 12:24:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2014-01-04 12:24:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2570947$
2014-01-04 12:24:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2884256$
2014-01-04 12:24:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2868038$
2014-01-04 12:18:57 ----D---- C:\WINDOWS\system32\MRT
2014-01-04 12:18:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2820917$
2014-01-04 12:17:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2603381$
2014-01-04 12:17:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2014-01-04 12:17:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2014-01-04 12:17:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2508429$
2014-01-04 12:17:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2653956$
2014-01-04 12:16:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2014-01-04 12:16:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2014-01-04 12:16:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2506212$
2014-01-04 12:15:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2893984$
2014-01-04 11:57:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2014-01-04 11:57:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2014-01-04 11:57:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2619339$
2014-01-04 11:56:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2014-01-04 11:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2014-01-04 11:56:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2014-01-04 11:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2862330$
2014-01-04 11:53:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2813345$
2014-01-04 11:53:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2509553$
2014-01-04 11:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$
2014-01-04 11:51:28 ----D---- C:\Program Files\MSXML 4.0
2014-01-04 11:51:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2620712$
2014-01-04 11:50:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2014-01-04 11:50:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2661637$
2014-01-04 11:50:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2584146$
2014-01-03 16:36:52 ----N---- C:\WINDOWS\system32\iacenc.dll
2014-01-03 12:27:44 ----A---- C:\WINDOWS\system32\atiicdxx.dat
2014-01-03 12:17:00 ----A---- C:\WINDOWS\system32\RegistryDefragBootTime.exe
2014-01-03 11:22:21 ----A---- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys
2014-01-03 11:16:33 ----D---- C:\Documents and Settings\ABC\Data aplikací\Apple Computer
2014-01-03 11:16:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\ProductData
2014-01-03 11:14:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\{D76294E6-03B8-4971-AF2E-3F846161A690}
2014-01-03 11:14:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}
2014-01-03 11:14:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2014-01-03 11:14:30 ----D---- C:\Documents and Settings\ABC\Data aplikací\IObit
2014-01-03 11:14:08 ----D---- C:\Program Files\IObit
2014-01-03 10:50:02 ----A---- C:\WINDOWS\system32\hidserv.dll
2014-01-03 10:49:55 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2014-01-03 10:49:43 ----A---- C:\WINDOWS\system32\drivers\usbvideo.sys

======List of files/folders modified in the last 1 month======

2014-02-02 22:10:45 ----D---- C:\WINDOWS\Prefetch
2014-02-02 22:10:41 ----D---- C:\Program Files\trend micro
2014-02-02 22:08:25 ----D---- C:\WINDOWS\Temp
2014-02-02 22:08:09 ----D---- C:\WINDOWS\system32\CatRoot2
2014-02-02 22:03:24 ----D---- C:\WINDOWS\system32
2014-02-02 21:02:33 ----D---- C:\WINDOWS\SoftwareDistribution
2014-02-02 21:01:53 ----D---- C:\WINDOWS
2014-02-02 21:01:21 ----D---- C:\WINDOWS\Debug
2014-02-02 20:59:30 ----D---- C:\Program Files\Common Files
2014-02-02 20:59:28 ----RD---- C:\Program Files
2014-02-02 19:24:47 ----SD---- C:\WINDOWS\Downloaded Program Files
2014-02-02 19:14:56 ----D---- C:\WINDOWS\system32\config
2014-02-02 19:03:03 ----SD---- C:\WINDOWS\Tasks
2014-02-01 19:43:50 ----D---- C:\WINDOWS\pss
2014-01-31 17:29:56 ----D---- C:\Documents and Settings\ABC\Data aplikací\Winamp
2014-01-31 17:29:07 ----D---- C:\Program Files\CCleaner
2014-01-30 21:42:23 ----SHD---- C:\WINDOWS\CSC
2014-01-30 16:55:39 ----D---- C:\Program Files\COMODO
2014-01-29 22:33:11 ----D---- C:\Documents and Settings\ABC\Data aplikací\Skype
2014-01-28 03:02:13 ----D---- C:\Documents and Settings\ABC\Data aplikací\vlc
2014-01-20 16:55:00 ----HD---- C:\WINDOWS\inf
2014-01-18 10:18:04 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2014-01-17 09:08:42 ----SHD---- C:\WINDOWS\Installer
2014-01-17 09:07:45 ----D---- C:\Config.Msi
2014-01-15 11:23:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2014-01-15 11:16:56 ----A---- C:\WINDOWS\system32\MRT.exe
2014-01-15 11:16:26 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-01-15 11:16:26 ----D---- C:\WINDOWS\system32\drivers
2014-01-15 09:07:59 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-10 16:17:58 ----SD---- C:\Documents and Settings\ABC\Data aplikací\Microsoft
2014-01-06 13:04:18 ----D---- C:\Program Files\Microsoft Office
2014-01-04 17:37:11 ----HD---- C:\WINDOWS\$hf_mig$
2014-01-04 17:36:50 ----D---- C:\Program Files\Internet Explorer
2014-01-04 17:34:13 ----D---- C:\WINDOWS\AppPatch
2014-01-04 17:32:33 ----D---- C:\WINDOWS\security
2014-01-04 17:06:45 ----HD---- C:\Program Files\InstallShield Installation Information
2014-01-04 13:50:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2014-01-04 13:46:15 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2014-01-04 13:46:14 ----A---- C:\WINDOWS\system32\ati3duag.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2014-01-04 13:46:13 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2014-01-04 12:33:13 ----D---- C:\WINDOWS\WinSxS
2014-01-04 12:07:17 ----RSD---- C:\WINDOWS\Fonts
2014-01-04 12:06:09 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-01-04 12:06:04 ----D---- C:\Program Files\Microsoft Works
2014-01-04 11:52:16 ----D---- C:\WINDOWS\ie8updates
2014-01-04 08:38:27 ----D---- C:\WINDOWS\system32\CatRoot
2014-01-03 16:06:07 ----D---- C:\WINDOWS\Help
2014-01-03 14:21:24 ----D---- C:\Program Files\Ashampoo
2014-01-03 13:33:12 ----D---- C:\WINDOWS\system32\wbem
2014-01-03 13:33:10 ----D---- C:\WINDOWS\Registration
2014-01-03 11:21:38 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2014-01-03 11:17:28 ----SHD---- C:\System Volume Information
2014-01-03 11:17:28 ----D---- C:\WINDOWS\system32\Restore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hotcore3;hc3ServiceName; C:\WINDOWS\system32\DRIVERS\hotcore3.sys [2010-01-17 40560]
R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2012-11-07 99080]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2013-05-22 14776]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-02-04 691696]
R0 viaagp1;VIA AGP Filter; C:\WINDOWS\system32\DRIVERS\viaagp1.sys [2011-01-29 27904]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2014-01-04 13976]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-04-27 77568]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-27 41600]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2012-11-07 18096]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2012-11-07 497952]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2012-11-07 32640]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\WINDOWS\System32\Drivers\Uim_IM.sys [2010-01-17 385544]
R1 UimBus;Universal Image Mounter Controller; C:\WINDOWS\system32\DRIVERS\UimBus.sys [2010-01-17 34392]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R3 admjoy;Aureal Game Port Enumerator; C:\WINDOWS\system32\DRIVERS\admjoy.sys [2008-04-13 10880]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2014-01-04 1540608]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-27 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2014-01-04 130432]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2013-07-17 123008]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2007-06-27 207488]
R3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-04-27 38528]
R3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-04-27 82944]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-27 60800]
S3 axtr70x6;axtr70x6; C:\WINDOWS\system32\drivers\axtr70x6.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-12-15 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-12-15 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-12-15 21744]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-27 61824]
S3 PAC207;Eye 110; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2012-07-11 116608]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [2013-09-29 962880]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2014-01-04 413696]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-11-07 1990464]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2014-01-28 2135232]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-02-04 153376]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-02 2151232]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-18 257928]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-24 115168]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119533
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#8 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\ABC.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/sk27211/
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

1mrna
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 10 lis 2012 19:13

Re: Prosím o kontrolu logu

#9 Příspěvek od 1mrna »

Provedeno, děkuji.
Ještě bych měl dotaz, jaký optimalizační program by jste doporučil místo Advanced systemCare?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119533
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#10 Příspěvek od Rudy »

Nemáte zač! Zeptám se ještě, zda byl problém vyřešen? Místo ASC zkuste CCleaner: http://forum.viry.cz/viewtopic.php?f=46&t=7478 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

1mrna
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 10 lis 2012 19:13

Re: Prosím o kontrolu logu

#11 Příspěvek od 1mrna »

Ano problém vyřešen Comodo nic nedetekuje :thumbsup: Ccleaner používám, jako čistič, ASC docela dobře zrychluje jak PC tak Internet, bez nějje můj starý stoj tak trochu lenochd :D

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119533
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#12 Příspěvek od Rudy »

OK, nutit vás nemohu. Podle našeho názoru to ale není bezpečný sw pro laiky. Jinak jsem rád, že se problém vyřešil! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět