Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pro Motji

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Pro Motji

#1 Příspěvek od Paulie0001 »

Zdravím mého oblíbeného sloníčka :iefox: tak jsme se dlouho neviděli :D
Ale nebojte, katastrofa PC ještě nepřišla :D
Chci Vás jen poprosit o maličkost -> Teď jsem na počítači mého bráchy, schizofrenního bráchy který před chvíli odjel do Běloruska a netuším kdy se vrátí. Nicméně chci pročistit jeho počítat, vymazat spoustu zbytečností a programy, které tu nemají co dělat...... A než se pustím do úklidu, zajímá mě názor odborníka, Vás :oops: jak moc je tento počítač zavirovaný, :D Zajímá mě totiž, jak se můj brácha o ten PC staral, abych ho pak moh za něco seřvat až se vrátí :) A jestli byste mi mohla pomoci to očistit, vlastně ani nevím kde začít.
Jediný ale, co mu nesmím smazat je program Garena. Ostatní rádci už radili, že to mám smazat, ale to se bráchovi vůbec nelíbilo :(
No, tady je už ten log, tak mrkněte prosím na to ;) a přeji hezký slunečný den.

Logfile of random's system information tool 1.09 (written by random/random)
Run by pavel at 2014-05-10 12:13:45
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (2%) free of 182 GB
Total RAM: 2046 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:13:49, on 10.5.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\P R O G R A M Y\avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\P R O G R A M Y\avast\AvastUI.exe
C:\Program Files\OSCAR Editor\OscarEditor.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Garena Plus\GarenaMessenger.exe
C:\Program Files\Steam\steam.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
C:\WINDOWS\system32\CNAB4RPK.EXE
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Dokumenty\Downloads\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\pavel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.claro-search.com/?affID=1166 ... ffe98be087
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll
O2 - BHO: VoAuDix - {6BE55258-55BE-ACBB-A065-6DC23F641B33} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\VoAuDix\8L0ii.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\P R O G R A M Y\avast\aswWebRepIE.dll
O2 - BHO: FunDeAls - {905B7F54-2BB5-33A4-C01C-3C6797C0E587} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\FunDeAls\UluMRmFdy.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\P R O G R A M Y\avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AMBDef] AMBDef.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "D:\P R O G R A M Y\avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files\OSCAR Editor\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [GarenaPlus] "C:\Program Files\Garena Plus\GarenaMessenger.exe" -autolaunch
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search - http://tbedits.videodownloadconverter.c ... 72810&cv=1
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\pavel\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\pavel\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\docume~1\alluse~1.win\dataap~1\browse~1\25986~1.67\{c16c1~1\browse~1.dll c:\progra~1\sw5067~1.boo
O20 - Winlogon Notify: !SASWinLogon - D:\P R O G R A M Y\SuperAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - D:\P R O G R A M Y\avast\AvastSvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: mental ray 3.10 Satellite for Autodesk 3ds Max 2013 32-bit (mi-raysat_3dsmax2013_32) - Unknown owner - D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sound Blaster X-Fi MB Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe
O23 - Service: Web Assistant - Unknown owner - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe

--
End of file - 11046 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-343818398-839522115-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-343818398-839522115-1003UA.job
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1343024091-343818398-839522115-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1343024091-343818398-839522115-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-06-23 386264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
Web Assistant - C:\Program Files\Web Assistant\Extension32.dll [2013-06-30 170840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6BE55258-55BE-ACBB-A065-6DC23F641B33}]
VoAuDix - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\VoAuDix\8L0ii.dll [2012-10-23 264192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-07-05 453544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}]
FunDeAls - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\FunDeAls\UluMRmFdy.dll [2014-04-12 425472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-07-05 157616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AMBDef"=C:\WINDOWS\AMBDef.exe [2008-01-24 53248]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-11-04 1753192]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2011-02-17 20029032]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"AvastUI.exe"=D:\P R O G R A M [2012-12-08 6527128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"=C:\Program Files\OSCAR Editor\OscarEditor.exe [2009-08-31 4053504]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-08-22 136176]
"GarenaPlus"=C:\Program Files\Garena Plus\GarenaMessenger.exe [2014-02-26 9899312]
"Steam"=C:\Program Files\Steam\steam.exe [2014-04-24 1825984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2006-09-13 139264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncService]
C:\Program Files\InstallShield Installation Information\{EC6D5F08-1694-431F-8200-3B0A8A61AC5A}\AMBSPISyncService.exe [2008-08-12 1233199]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-08-22 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\program files\real\realplayer\update\realsched.exe -osboot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2011-03-09 247728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [2008-07-10 225396]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WiseStubReboot]
MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI TRANSFORMS=C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST WISE_SETUP_EXE_PATH=e:\driver\2k_xp\191.07\PhysX_9.09.0814_SystemSoftware.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^pavel^Nabídka Start^Programy^Po spuštění^hamachi.lnk]
D:\PROGRA~1\hamachi.exe [2010-11-17 625952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\docume~1\alluse~1.win\dataap~1\browse~1\25986~1.67\{c16c1~1\browse~1.dll c:\progra~1\sw5067~1.boo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Šikovné programy\Steam\Steam.exe"="D:\Šikovné programy\Steam\Steam.exe:*:Enabled:Steam"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Rage of Mages 2\rom2.exe"="C:\Rage of Mages 2\rom2.exe:*:Enabled:rom2"
"D:\Rage of Mages 2\rom2.exe"="D:\Rage of Mages 2\rom2.exe:*:Enabled:rom2"
"F:\CRACK\STARCRAFT II.EXE"="F:\CRACK\STARCRAFT II.EXE:*:Enabled:Blizzard Launcher"
"D:\Hry\StarCraft II\StarCraft II.exe"="D:\Hry\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher"
"D:\Hry\StarCraft II\Versions\Base15405\SC2.exe"="D:\Hry\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\StarCraft II\Versions\Base16561\SC2.exe"="D:\Hry\StarCraft II\Versions\Base16561\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\Counter strike 1.6\hl.exe"="D:\Hry\Counter strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"D:\P R O G R A M Y\QIP\qip.exe"="D:\P R O G R A M Y\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"D:\P R O G R A M Y\utorrent\uTorrent.exe"="D:\P R O G R A M Y\utorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\CNAB4RPK.EXE"="C:\WINDOWS\system32\CNAB4RPK.EXE:*:Enabled:Canon LBP2900 RPC Server Process"
"D:\Hry\Counter strike Source\Counter Strike Source 2010\hl2.exe"="D:\Hry\Counter strike Source\Counter Strike Source 2010\hl2.exe:*:Enabled:hl2"
"D:\Hry\Counter strike 1.6\hlds.exe"="D:\Hry\Counter strike 1.6\hlds.exe:*:Enabled:HLDS Launcher"
"D:\Hry\NFS Hot Pursuit\Launcher.exe"="D:\Hry\NFS Hot Pursuit\Launcher.exe:*:Enabled:Need for Speed(TM) Hot Pursuit"
"D:\Hry\NFS Hot Pursuit\NFS11.exe"="D:\Hry\NFS Hot Pursuit\NFS11.exe:*:Enabled:Need for Speed(TM) Hot Pursuit Application"
"D:\P R O G R A M Y\Garena\Garena.exe"="D:\P R O G R A M Y\Garena\Garena.exe:*:Enabled:Garena"
"D:\Hry\Call of Duty 2\CoD2MP_s.exe"="D:\Hry\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"D:\Hry\Team Fortress 2\hl2.exe"="D:\Hry\Team Fortress 2\hl2.exe:*:Enabled:hl2"
"D:\Hry\TF2\Team Fortress 2\hl2.exe"="D:\Hry\TF2\Team Fortress 2\hl2.exe:*:Enabled:hl2"
"D:\Hry\Team Fortress NS\hl2.exe"="D:\Hry\Team Fortress NS\hl2.exe:*:Enabled:hl2"
"D:\Hry\StarCraft II\Versions\Base16939\SC2.exe"="D:\Hry\StarCraft II\Versions\Base16939\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\StarCraft II\Versions\Base17326\SC2.exe"="D:\Hry\StarCraft II\Versions\Base17326\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\BaboViolent 2\bv2Dedicated.exe"="D:\Hry\BaboViolent 2\bv2Dedicated.exe:*:Enabled:bv2Dedicated"
"D:\Hry\BaboViolent 2\bv2.exe"="D:\Hry\BaboViolent 2\bv2.exe:*:Enabled:bv2"
"D:\Hry\BaboViolent 2\bv2Dedicated_v2_11fpro.exe"="D:\Hry\BaboViolent 2\bv2Dedicated_v2_11fpro.exe:*:Enabled:bv2Dedicated_v2_11fpro"
"D:\Hry\FixKorea\tacint\ti.exe"="D:\Hry\FixKorea\tacint\ti.exe:*:Enabled:ti"
"C:\Documents and Settings\pavel\Plocha\RGC\Ranked Gaming Client\rgc.exe"="C:\Documents and Settings\pavel\Plocha\RGC\Ranked Gaming Client\rgc.exe:*:Enabled:rgc"
"D:\Hry\Dead Space 2\deadspace2.exe"="D:\Hry\Dead Space 2\deadspace2.exe:*:Enabled:Dead Space™ 2"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"D:\Hry\Diablo II\Diablo II.exe"="D:\Hry\Diablo II\Diablo II.exe:*:Enabled:Diablo II - Lord of Destruction"
"D:\Hry\StarCraft II\Versions\Base18092\SC2.exe"="D:\Hry\StarCraft II\Versions\Base18092\SC2.exe:*:Enabled:StarCraft II"
"H:\WinDVD.exe"="H:\WinDVD.exe:*:Enabled:WinDVD"
"D:\Hry\Warcraft III\Warcraft III.exe"="D:\Hry\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
"D:\P R O G R A M Y\hamachi.exe"="D:\P R O G R A M Y\hamachi.exe:*:Enabled:Hamachi Client"
"C:\Documents and Settings\pavel\Local Settings\Temp\Rar$EX00.468\WoW-BurningCrusade-enGBdownloader.exe"="C:\Documents and Settings\pavel\Local Settings\Temp\Rar$EX00.468\WoW-BurningCrusade-enGBdownloader.exe:*:Enabled:Blizzard Downloader"
"D:\World Of Warcraft Classic\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"="D:\World Of Warcraft Classic\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\World Of Warcraft Classic\Launcher.exe"="D:\World Of Warcraft Classic\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\World Of Warcraft Classic\Launcher.patch.exe"="D:\World Of Warcraft Classic\Launcher.patch.exe:*:Enabled:Blizzard Launcher"
"D:\Hry\World of Warcraft\Launcher.exe"="D:\Hry\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\Hry\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"="D:\Hry\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Documents and Settings\pavel\Plocha\WoW-3.2.0-enGB-downloader.exe"="C:\Documents and Settings\pavel\Plocha\WoW-3.2.0-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Hry\Portal 2\portal2.exe"="D:\Hry\Portal 2\portal2.exe:*:Enabled:portal2"
"D:\Hry\GTA IV\Grand Theft Auto IV\GTAIV.exe"="D:\Hry\GTA IV\Grand Theft Auto IV\GTAIV.exe:*:Disabled:Grand Theft Auto IV"
"D:\Hry\NHL 09\nhl2009.exe"="D:\Hry\NHL 09\nhl2009.exe:*:Disabled:nhl2009"
"D:\Hry\NHL08\nhl2008.exe"="D:\Hry\NHL08\nhl2008.exe:*:Enabled:nhl2008"
"D:\Hry\nhl04\nhl2004.exe"="D:\Hry\nhl04\nhl2004.exe:*:Enabled:nhl2004"
"D:\Hry\Heroes2\HEROES2W.EXE"="D:\Hry\Heroes2\HEROES2W.EXE:*:Enabled:HEROES2W"
"D:\Hry\StarCraft II\Versions\Base18574\SC2.exe"="D:\Hry\StarCraft II\Versions\Base18574\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\Witcher 2\bin\witcher2.exe"="D:\Hry\Witcher 2\bin\witcher2.exe:*:Enabled:The Witcher 2: Assasins of Kings"
"D:\Hry\Commandos 2\comm2.exe"="D:\Hry\Commandos 2\comm2.exe:*:Enabled:comm2"
"D:\Hry\Fifa 11\Game\fifa.exe"="D:\Hry\Fifa 11\Game\fifa.exe:*:Enabled:FIFA 11"
"D:\Hry\L4D2\Left 4 Dead 2\left4dead2.exe"="D:\Hry\L4D2\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"H:\L4D2\Left 4 Dead 2\left4dead2.exe"="H:\L4D2\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"D:\Hry\Left 4 Dead 2\L4D2\Left 4 Dead 2\left4dead2.exe"="D:\Hry\Left 4 Dead 2\L4D2\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"D:\Hry\FEAR3\F.E.A.R. 3\F.E.A.R. 3.exe"="D:\Hry\FEAR3\F.E.A.R. 3\F.E.A.R. 3.exe:*:Enabled:F.E.A.R. 3"
"D:\Hry\BorderLands\Gearbox Software\Borderlands\Binaries\Borderlands.exe"="D:\Hry\BorderLands\Gearbox Software\Borderlands\Binaries\Borderlands.exe:*:Enabled:Borderlands"
"D:\P R O G R A M Y\Steam\Steam.exe"="D:\P R O G R A M Y\Steam\Steam.exe:*:Enabled:Steam"
"D:\Hry\F.E.A.R. 3\F.E.A.R. 3.exe"="D:\Hry\F.E.A.R. 3\F.E.A.R. 3.exe:*:Enabled:F.E.A.R. 3"
"D:\Hry\Titan Quest\Titan Quest.exe"="D:\Hry\Titan Quest\Titan Quest.exe:*:Enabled:Titan Quest"
"D:\Hry\Titan Quest IT\Tqit.exe"="D:\Hry\Titan Quest IT\Tqit.exe:*:Enabled:Tqit"
"D:\Hry\TQ IT\Tqit.exe"="D:\Hry\TQ IT\Tqit.exe:*:Enabled:Tqit"
"D:\Hry\StarCraft II\Versions\Base19132\SC2.exe"="D:\Hry\StarCraft II\Versions\Base19132\SC2.exe:*:Enabled:StarCraft II"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Hry\BF4free\BFP4f.exe"="D:\Hry\BF4free\BFP4f.exe:*:Enabled:BFP4f"
"D:\Program Files\Capcom\Bionic Commando\bionic_commando.exe"="D:\Program Files\Capcom\Bionic Commando\bionic_commando.exe:*:Enabled:Bionic Commando"
"D:\Hry\Re-Volt\revolt.exe"="D:\Hry\Re-Volt\revolt.exe:*:Enabled:revolt"
"D:\P R O G R A M Y\Steam\steamapps\paulie0001\team fortress 2\hl2.exe"="D:\P R O G R A M Y\Steam\steamapps\paulie0001\team fortress 2\hl2.exe:*:Enabled:hl2"
"D:\Hry\Dead Island\Dead Island\deadislandgame.exe"="D:\Hry\Dead Island\Dead Island\deadislandgame.exe:*:Enabled:DeadIsland"
"D:\Hry\Driver San Francisko\Driver.exe"="D:\Hry\Driver San Francisko\Driver.exe:*:Enabled:Driver San Francisco"
"D:\Hry\Assassins Creed 3\ACBMP.exe"="D:\Hry\Assassins Creed 3\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.439\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.439\Agent.exe:*:Enabled:Blizzard Agent"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.440\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.440\Agent.exe:*:Enabled:Blizzard Agent"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"D:\P R O G R A M Y\Steam\SmartSteam\Steam.exe"="D:\P R O G R A M Y\Steam\SmartSteam\Steam.exe:*:Enabled:Steam"
"D:\Hry\Warcraft III\gproxy.exe"="D:\Hry\Warcraft III\gproxy.exe:*:Enabled:gproxy Application"
"D:\Hry\Warcraft III\war3.exe"="D:\Hry\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"\\ZEM-FC29537D19D\Jirsoun (D)\Age Of Empires 2\empires2.exe"="\\ZEM-FC29537D19D\Jirsoun (D)\Age Of Empires 2\empires2.exe:*:Enabled:empires2.exe"
"D:\P R O G R A M Y\ParadiseCasino\casino.exe"="D:\P R O G R A M Y\ParadiseCasino\casino.exe:*:Enabled:casino"
"D:\Hry\Age of Empires 3\age3y.exe"="D:\Hry\Age of Empires 3\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"D:\Hry\Crysis 2\bin32\Crysis2.exe"="D:\Hry\Crysis 2\bin32\Crysis2.exe:*:Enabled:Crysis2"
"\\ZEM-FC29537D19D\JIRSOUN (D)\MOHAA\MOHAA.exe"="\\ZEM-FC29537D19D\JIRSOUN (D)\MOHAA\MOHAA.exe:*:Enabled:MOHAA.exe"
"D:\Hry\StarCraft II\Versions\Base21029\SC2.exe"="D:\Hry\StarCraft II\Versions\Base21029\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\Age of Empires 3\age3x.exe"="D:\Hry\Age of Empires 3\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"
"D:\Max Payne 3\MaxPayne3.exe"="D:\Max Payne 3\MaxPayne3.exe:*:Enabled:Max Payne 3"
"D:\Hry\StarCraft II\sc2-x.x.x.x-1.5.0.22342-enUS-Downloader.exe"="D:\Hry\StarCraft II\sc2-x.x.x.x-1.5.0.22342-enUS-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1199\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1199\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Hry\StarCraft II\StarCraft II Public Test.exe"="D:\Hry\StarCraft II\StarCraft II Public Test.exe:*:Enabled:StarCraft II Public Test"
"C:\Program Files\Garena Plus\Room\garena_room.exe"="C:\Program Files\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1267\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1267\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe"="D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe:*:Enabled:mental ray satellite server for Autodesk 3ds Max Design 2013 32-bit"
"D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32.exe"="D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32.exe:*:Enabled:mental ray satellite for Autodesk 3ds Max Design 2013 32-bit"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"msacm.lhacm"=lhacm.acm
"VIDC.FFDS"=ff_vfw.dll
"msacm.avis"=ff_acm.acm
"SENTINEL"=snti386.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.iv50"=ir50_32.dll
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"VIDC.IV41"=IR41_32.AX
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.vorbis"=vorbis.acm

======List of files/folders created in the last 1 month======

2014-04-29 20:05:54 ----D---- C:\Documents and Settings\pavel\Data aplikací\e-academy Inc
2014-04-28 11:20:58 ----D---- C:\Program Files\Common Files\Skype
2014-04-28 11:20:57 ----RD---- C:\Program Files\Skype
2014-04-22 16:31:09 ----D---- C:\Program Files\NNextCoup
2014-04-22 16:31:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NNextCoup
2014-04-22 16:30:57 ----A---- C:\WINDOWS\wininit.ini
2014-04-22 16:26:18 ----RA---- C:\WINDOWS\system32\tmp242.tmp
2014-04-12 11:02:20 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\FunDeAls
2014-04-11 10:53:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$

======List of files/folders modified in the last 1 month======

2014-05-10 12:13:48 ----D---- C:\Program Files\trend micro
2014-05-10 11:38:51 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\GarenaMessenger
2014-05-10 11:38:50 ----D---- C:\Documents and Settings\pavel\Data aplikací\GarenaPlus
2014-05-10 11:36:47 ----D---- C:\WINDOWS\system32\CatRoot2
2014-05-10 11:36:00 ----D---- C:\WINDOWS\Temp
2014-05-10 11:35:35 ----D---- C:\Program Files\Steam
2014-05-10 11:11:18 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-05-09 17:18:37 ----D---- C:\WINDOWS\Prefetch
2014-05-06 17:19:14 ----D---- C:\Documents and Settings\pavel\Data aplikací\Skype
2014-05-04 09:27:34 ----D---- C:\WINDOWS
2014-05-04 09:26:56 ----D---- C:\WINDOWS\system32
2014-05-03 23:07:05 ----HD---- C:\WINDOWS\inf
2014-05-03 23:07:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-05-03 23:06:58 ----D---- C:\WINDOWS\ie8updates
2014-04-30 10:12:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-04-29 21:00:47 ----RD---- C:\Program Files
2014-04-29 20:05:55 ----SHD---- C:\WINDOWS\Installer
2014-04-29 20:05:55 ----SD---- C:\Documents and Settings\pavel\Data aplikací\Microsoft
2014-04-28 23:15:09 ----D---- C:\Documents and Settings\pavel\Data aplikací\uTorrent
2014-04-28 11:21:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Skype
2014-04-28 11:20:58 ----D---- C:\Program Files\Common Files
2014-04-24 11:19:12 ----D---- C:\Documents and Settings\pavel\Data aplikací\vlc
2014-04-22 16:32:35 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\safoeweb
2014-04-22 16:31:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\7bbf9f6402f92a59
2014-04-22 16:30:54 ----D---- C:\Program Files\CCleaner
2014-04-22 16:27:12 ----D---- C:\Program Files\Real
2014-04-22 16:27:03 ----D---- C:\Documents and Settings\pavel\Data aplikací\Real
2014-04-22 16:26:08 ----D---- C:\WINDOWS\system32\drivers
2014-04-22 16:21:09 ----D---- C:\Documents and Settings\pavel\Data aplikací\Kastner software
2014-04-22 16:21:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\KASTNER software
2014-04-22 15:57:04 ----D---- C:\Program Files\VstPlugins
2014-04-22 15:55:22 ----HD---- C:\Program Files\InstallShield Installation Information
2014-04-22 09:59:11 ----SD---- C:\WINDOWS\Tasks
2014-04-11 10:53:13 ----A---- C:\WINDOWS\imsins.BAK
2014-04-11 10:48:30 ----D---- C:\WINDOWS\system32\MRT
2014-04-11 10:48:03 ----A---- C:\WINDOWS\system32\MRT.exe
2014-04-11 10:47:25 ----D---- C:\Program Files\Internet Explorer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2013-12-06 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2013-12-06 178304]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-02-04 717296]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2012-10-31 20624]
R1 aswRdr;aswRdr; \??\C:\WINDOWS\system32\drivers\aswRdr.sys []
R1 aswSnx;aswSnx; \??\C:\WINDOWS\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; \??\C:\WINDOWS\system32\drivers\aswSP.sys []
R1 aswTdi;aswTdi; \??\C:\WINDOWS\system32\drivers\aswTdi.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\D:\P R O G R A M Y\SuperAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\D:\P R O G R A M Y\SuperAntiSpyware\SASKUTIL.SYS []
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2009-03-15 56268]
R2 aswFsBlk;aswFsBlk; \??\C:\WINDOWS\system32\drivers\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-10-09 279712]
R2 hardlock;hardlock; C:\WINDOWS\System32\DRIVERS\hardlock.sys [2004-01-31 420000]
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 ithsgt;ithsgt; C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2011-09-14 162432]
R2 lilsgt;lilsgt; C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2011-09-14 12032]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-10-09 25888]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2004-05-17 76288]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-11-17 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-02-24 6340200]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2010-05-03 225232]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 abjxovb3;abjxovb3; C:\WINDOWS\system32\drivers\abjxovb3.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 GGSAFERDriver;GGSAFER Driver; \??\D:\P R O G R A M Y\Garena\safedrv.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2011-08-17 23168]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-11-12 100456]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-10-21 47360]
S3 SECUSB2;SECUSB2.sys, SEC SOC USBD Driver; C:\WINDOWS\System32\Drivers\SECUSB2.sys [2008-04-16 10528]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-16 104576]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; D:\P R O G R A M [2012-12-08 6527128]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\System32\CTsvcCDA.exe [1999-12-12 44032]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-04-30 417792]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [2012-07-05 161704]
R2 mi-raysat_3dsmax2013_32;mental ray 3.10 Satellite for Autodesk 3ds Max 2013 32-bit; D:\P R O G R A M [2012-12-08 6527128]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592]
R2 Web Assistant;Web Assistant; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [2013-06-30 188760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-25 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-08-19 79360]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2014-04-10 1044816]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-25 136176]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2010-08-19 79360]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2013-03-15 543656]
S3 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2013-11-06 758224]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 avast! Firewall;avast! Firewall; D:\P R O G R A M [2012-12-08 6527128]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pro Motji

#2 Příspěvek od motji »

Zdravím :)
No nevím, jestli Vás brácha za očistu pc pochválí :D .
Kromě Gareny a torentů tam nic zásadního škodlivého nevidím.

:arrow: Stáhněte Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
-Uložte program na plochu a spusťte . Pak se zobrazí se licenční podminky - potvrďte start libovolnou klávesou.
- vytvoří se záloha a proběhne skenování.
Po skončení skenování na Vás vyběhne log (bude uložen v c:\JRT jako JRT.txt) - zkopírujte jej sem

:arrow: Stáhněte AdwCleaner http://www.bleepingcomputer.com/download/adwcleaner/
-Uložte program na plochu a ukončete všechny spuštěné programy .
-spusťte AdwCleaner, klikněte na Scan a po dokončení skenu na Clean
- provede se oprava, restartuje se pc - (případně restartujte) a objeví se log C:\AdwCleaner\AdwCleaner.txt , obsah logu zkopírujte zde.

:arrow: Použijte :arrow: CCleaner http://forum.viry.cz/viewtopic.php?f=46&t=7478
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Re: Pro Motji

#3 Příspěvek od Paulie0001 »

No, já si myslím že škodlivého tu bude hodně věcí :D Kdybyste si sedla sem k počítači, tak byste je jistě hned našla ;) nejvíce mě štvou reklamy, některé jsem pročistil přes ADWcleaner již ráno ;)

posílám log z JRT, níže jsou logy z AdwCleaner, tak je nepřehlídněte ;):
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Microsoft Windows XP x86
Ran by pavel on ne 11.05.2014 at 15:38:17,42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1343024091-343818398-839522115-1003\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{11B9DA8B-6C56-4216-86AC-ABC6E5501A9D}



~~~ Files



~~~ Folders





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 11.05.2014 at 15:42:02,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Z adwCleaneru se mi vytvořily 2 logy, posílám tedy oba:

# AdwCleaner v3.207 - Report created 11/05/2014 at 12:32:11
# Updated 05/05/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : pavel - PRVN-4WVTXYCSU1
# Running from : C:\Documents and Settings\pavel\Dokumenty\Downloads\adwcleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : Web Assistant

***** [ Files / Folders ] *****

File Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\bProtector Web Data
File Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\bprotectorpreferences
File Found : C:\Program Files\Mozilla Firefox\user.js
Folder Found : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
Folder Found : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
Folder Found : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
Folder Found : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\torch
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Ask
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Babylon
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\FunDeAls
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Premium
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\safoeweb
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\VoAuDix
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\WinterSoft
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\YoutubeAdblocker
Folder Found : C:\Documents and Settings\All Users.WINDOWS\Dokumenty\AlawarWrapper
Folder Found : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
Folder Found : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
Folder Found : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
Folder Found : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\torch
Folder Found : C:\Documents and Settings\Guest\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
Folder Found : C:\Documents and Settings\Guest\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
Folder Found : C:\Documents and Settings\Guest\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
Folder Found : C:\Documents and Settings\Guest\Local Settings\Data aplikací\torch
Folder Found : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
Folder Found : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
Folder Found : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
Folder Found : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\torch
Folder Found : C:\Documents and Settings\pavel\Data aplikací\Babylon
Folder Found : C:\Documents and Settings\pavel\Data aplikací\dvdvideosoftiehelpers
Folder Found : C:\Documents and Settings\pavel\Data aplikací\PriceGong
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\apn
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Conduit
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gdimdeboeckhbipeopidijpabnhlafdo
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
Folder Found : C:\Documents and Settings\pavel\Local Settings\Data aplikací\torch
Folder Found : C:\Documents and Settings\pavel\Nabídka Start\Programy\BrowserProtect
Folder Found : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
Folder Found : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
Folder Found : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
Folder Found : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\torch
Folder Found : C:\Program Files\Perion
Folder Found : C:\Program Files\safoeweb
Folder Found : C:\Program Files\Web Assistant
Folder Found : C:\Program Files\YoutubeAdblocker

***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\docume~1\alluse~1.win\dataap~1\browse~1\25986~1.67\{c16c1~1\browse~1.dll
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\SProtector
Key Found : HKCU\Software\BFlix
Key Found : HKCU\Software\d68dd8b438ee15
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\IM
Key Found : HKCU\Software\ImInstaller
Key Found : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF6E4B1C-DBDE-457E-9CEF-AB8ECAC8A5E8}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0C9F4179-6CE2-4C6A-A3E5-67FF3592A12E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0C9F4179-6CE2-4C6A-A3E5-67FF3592A12E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Key Found : HKCU\Software\PriceGong
Key Found : HKCU\Software\RegisteredApplicationsEx
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\Web Assistant
Key Found : HKCU\Software\YahooPartnerToolbar
Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Found : HKLM\Software\Babylon
Key Found : HKLM\Software\BFlix
Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Key Found : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Key Found : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Key Found : HKLM\SOFTWARE\Classes\FunDEalS.FunDEalS
Key Found : HKLM\SOFTWARE\Classes\FunDEalS.FunDEalS.2.2
Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\Classes\VaudiX.VaudiX
Key Found : HKLM\SOFTWARE\Classes\VaudiX.VaudiX.1.3
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\d68dd8b438ee15
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF6E4B1C-DBDE-457E-9CEF-AB8ECAC8A5E8}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{069b290f-5398-4629-a009-85b4bcb4b1b9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IM
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\incredibar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VideoDownloadConverter_4zbar Uninstall
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IM
Key Found : HKLM\Software\SProtector
Key Found : HKLM\Software\Web Assistant
Value Found : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{58BD07EB-0EE0-4DF0-8121-DC9B693373DF}]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.claro-search.com/?affID=116677&tt=5 ... ffe98be087
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://home.sweetim.com
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] - hxxp://www.claro-search.com/?affID=116677&tt=5 ... ffe98be087

-\\ Google Chrome v

[ File : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]

Found [Extension] : jifflliplgeajjdhmkcfnngfpgbjonjg

*************************

AdwCleaner[R0].txt - [18693 octets] - [11/05/2014 12:32:11]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [18754 octets] ##########


a druhý log :
# AdwCleaner v3.207 - Report created 11/05/2014 at 12:33:54
# Updated 05/05/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : pavel - PRVN-4WVTXYCSU1
# Running from : C:\Documents and Settings\pavel\Dokumenty\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : Web Assistant

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Ask
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Babylon
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Premium
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\WinterSoft
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AlawarWrapper
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\FunDeAls
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\safoeweb
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\VoAuDix
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Data aplikací\YoutubeAdblocker
Folder Deleted : C:\Program Files\Perion
Folder Deleted : C:\Program Files\Web Assistant
Folder Deleted : C:\Program Files\safoeweb
Folder Deleted : C:\Program Files\YoutubeAdblocker
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\torch
Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Dokumenty\AlawarWrapper
Folder Deleted : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\torch
Folder Deleted : C:\Documents and Settings\Guest\Local Settings\Data aplikací\torch
Folder Deleted : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\torch
Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\apn
Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Conduit
Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\torch
Folder Deleted : C:\Documents and Settings\pavel\Data aplikací\Babylon
Folder Deleted : C:\Documents and Settings\pavel\Data aplikací\dvdvideosoftiehelpers
Folder Deleted : C:\Documents and Settings\pavel\Data aplikací\PriceGong
Folder Deleted : C:\Documents and Settings\pavel\Nabídka Start\Programy\BrowserProtect
Folder Deleted : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\torch
[!] Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[!] Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
[!] Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
[!] Folder Deleted : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
[!] Folder Deleted : C:\Documents and Settings\Guest\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
[!] Folder Deleted : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
[!] Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
[!] Folder Deleted : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jccfbkphjafnkcemgfmidaomhdfaeagh
[!] Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
[!] Folder Deleted : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
[!] Folder Deleted : C:\Documents and Settings\Guest\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
[!] Folder Deleted : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
[!] Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
[!] Folder Deleted : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lhbmojliagbancdcmookpmaaoipjifmc
[!] Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
[!] Folder Deleted : C:\Documents and Settings\ASPNET\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
[!] Folder Deleted : C:\Documents and Settings\Guest\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
[!] Folder Deleted : C:\Documents and Settings\HelpAssistant\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
[!] Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
[!] Folder Deleted : C:\Documents and Settings\SUPPORT_388945a0\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\poimimobbmkpceodbkacdhjgmcfgolej
[!] Folder Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gdimdeboeckhbipeopidijpabnhlafdo
File Deleted : C:\Program Files\Mozilla Firefox\user.js
File Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\bProtector Web Data
File Deleted : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\bprotectorpreferences

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{58BD07EB-0EE0-4DF0-8121-DC9B693373DF}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\VaudiX.VaudiX
Key Deleted : HKLM\SOFTWARE\Classes\VaudiX.VaudiX.1.3
Key Deleted : HKLM\SOFTWARE\Classes\FunDEalS.FunDEalS
Key Deleted : HKLM\SOFTWARE\Classes\FunDEalS.FunDEalS.2.2
Key Deleted : HKCU\Software\d68dd8b438ee15
Key Deleted : HKLM\SOFTWARE\d68dd8b438ee15
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2269050
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0C9F4179-6CE2-4C6A-A3E5-67FF3592A12E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0C9F4179-6CE2-4C6A-A3E5-67FF3592A12E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6BE55258-55BE-ACBB-A065-6DC23F641B33}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{905B7F54-2BB5-33A4-C01C-3C6797C0E587}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF6E4B1C-DBDE-457E-9CEF-AB8ECAC8A5E8}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CF6E4B1C-DBDE-457E-9CEF-AB8ECAC8A5E8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Key Deleted : HKCU\Software\BFlix
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\PriceGong
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Web Assistant
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\BFlix
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\Software\Web Assistant
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IM
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{069b290f-5398-4629-a009-85b4bcb4b1b9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IM
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\incredibar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\VideoDownloadConverter_4zbar Uninstall
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\docume~1\alluse~1.win\dataap~1\browse~1\25986~1.67\{c16c1~1\browse~1.dll
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

-\\ Google Chrome v

[ File : C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&AF=100888&babsrc=SP_ss&mntrId=f0c1042d00000000000000241ddfe751
Deleted [Search Provider] : hxxp://www.claro-search.com/?q={searchTerms}&a ... ffe98be087
Deleted [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=27EE0EB6-C507-456E-BB38-CBA82AAD98A0&apn_ptnrs=U3&apn_sauid=31D93698-AE54-4A7D-A99D-6A9FCACB21D6&apn_dtid=OSJ000YYCZ&q={searchTerms}
Deleted [Search Provider] : hxxp://search.incredibar.com/?q={searchTerms}&lang=czech&cid=2&source=370&uloc=MB190&u=92262134874538702&a=6OyOCElUhU&gc=cz&acr=451365
Deleted [Extension] : jifflliplgeajjdhmkcfnngfpgbjonjg

*************************

AdwCleaner[R0].txt - [18835 octets] - [11/05/2014 12:32:11]
AdwCleaner[S0].txt - [19583 octets] - [11/05/2014 12:33:54]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19644 octets] ##########

Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Re: Pro Motji

#4 Příspěvek od Paulie0001 »

nooo :) to je změna teda :D hned se po internetu surfuje 1000x líp a příjemněji :D konečně to šlape jako hodinky, děkuju :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pro Motji

#5 Příspěvek od motji »

No vidíte, ono toho v logu tolik vidět nebylo, ale máme šikovné prográmky :D .
tak aby to šlo ještě líp :D

http://forum.viry.cz/viewtopic.php?f=29&t=115222
A poprosím o log :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Re: Pro Motji

#6 Příspěvek od Paulie0001 »

a já slušně poprosím o kontrolu logu ;)

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.05.11.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
pavel :: PRVN-4WVTXYCSU1 [administrátor]

Ochrana: Povolena

11.5.2014 21:03:39
MBAM-log-2014-05-11 (23-00-00).txt

Typ: Kompletní kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 596543
Uplynulý čas: 1 hodin, 55 minut, 36 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 3
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\MADOWN (Worm.Magania) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd (PUP.Optional.Incredibar.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 32
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users.WINDOWS\Data aplikací\FunDeAls\UluMRmFdy.dll.vir (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users.WINDOWS\Data aplikací\VoAuDix\8L0ii.dll.vir (PUP.Optional.Multiplug) -> Nebyla provedena žádná instrukce.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users.WINDOWS\Data aplikací\VoAuDix\zP5WIw.exe.vir (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users.WINDOWS\Data aplikací\YoutubeAdblocker\d_WRh0J19.exe.vir (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\AdwCleaner\Quarantine\C\Program Files\Web Assistant\ExtensionUpdaterService.exe.vir (PUP.Optional.SweetPacks.A) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\File System\001\t\00\00000000 (PUP.Optional.Installrex) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Temp\{5E940992-A90C-4AE1-A80A-E12E85772B64}\Addons\assistant_v3.exe (PUP.Optional.SProtect.A) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Temp\{5E940992-A90C-4AE1-A80A-E12E85772B64}\Addons\helper_setup.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Temp\{5E940992-A90C-4AE1-A80A-E12E85772B64}\Addons\vaudix_extension.exe (PUP.Optional.BundleLoader.A) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Temp\{6845A168-1A15-4ADF-A834-5237B3A6839E}\Addons\assistant_v3.exe (Trojan.SProtector) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Temp\{6845A168-1A15-4ADF-A834-5237B3A6839E}\Addons\browsecoupon_setup.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Temp\{6845A168-1A15-4ADF-A834-5237B3A6839E}\Addons\ext_setup.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Temp\{6845A168-1A15-4ADF-A834-5237B3A6839E}\Addons\ytab_setup.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\Program Files\CCleaner\setup.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1394\A0324781.dll (PUP.Optional.Montera.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1394\A0324782.dll (PUP.Optional.Montera.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1394\A0324783.dll (PUP.Optional.Montera.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1394\A0324784.dll (PUP.Optional.Montera.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1394\A0324786.exe (PUP.Optional.Incredibar.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1394\A0326103.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1411\A0327528.dll (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1411\A0327530.dll (PUP.Optional.Multiplug) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1411\A0327533.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1411\A0327536.exe (PUP.Optional.SweetPacks.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1422\A0333977.exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1422\A0334001.exe (PUP.Optional.Smart) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{BC77BCD6-517A-4C76-B9EA-F83B2E1B82FA}\RP1422\A0334002.exe (PUP.Optional.Installrex) -> Nebyla provedena žádná instrukce.
C:\TEMP\CLP-300\XP64\DATA\Ssopen.exe (Trojan.FakePDF) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage (PUP.Optional.Incredibar.A) -> Nebyla provedena žádná instrukce.

(konec)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pro Motji

#7 Příspěvek od motji »

Vše smažte, a ještě vypněte obnovu systému, restart pc a zase ji můžete zapnout.
A poprosím o nový log ze rsitu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Re: Pro Motji

#8 Příspěvek od Paulie0001 »

Jak to vypadá teď? :)
Logfile of random's system information tool 1.09 (written by random/random)
Run by pavel at 2014-05-12 14:06:52
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 7 GB (4%) free of 182 GB
Total RAM: 2046 MB (35% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:07:01, on 12.5.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\P R O G R A M Y\avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\CNAB4RPK.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\P R O G R A M Y\avast\AvastUI.exe
C:\Program Files\OSCAR Editor\OscarEditor.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Garena Plus\GarenaMessenger.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pavel\Dokumenty\Downloads\RSIT (1).exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\pavel.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\P R O G R A M Y\avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\P R O G R A M Y\avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AMBDef] AMBDef.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "D:\P R O G R A M Y\avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files\OSCAR Editor\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [GarenaPlus] "C:\Program Files\Garena Plus\GarenaMessenger.exe" -autolaunch
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\pavel\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\pavel\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\P R O G R A M Y\SuperAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - D:\P R O G R A M Y\avast\AvastSvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sound Blaster X-Fi MB Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe

--
End of file - 9396 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-343818398-839522115-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-343818398-839522115-1003UA.job
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1343024091-343818398-839522115-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1343024091-343818398-839522115-1003.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-06-23 386264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-07-05 453544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-07-05 157616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AMBDef"=C:\WINDOWS\AMBDef.exe [2008-01-24 53248]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-11-04 1753192]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2011-02-17 20029032]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"AvastUI.exe"=D:\P R O G R A M [2012-12-08 6527128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"=C:\Program Files\OSCAR Editor\OscarEditor.exe [2009-08-31 4053504]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-08-22 136176]
"GarenaPlus"=C:\Program Files\Garena Plus\GarenaMessenger.exe [2014-02-26 9899312]
"Steam"=C:\Program Files\Steam\steam.exe [2014-04-24 1825984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2006-09-13 139264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncService]
C:\Program Files\InstallShield Installation Information\{EC6D5F08-1694-431F-8200-3B0A8A61AC5A}\AMBSPISyncService.exe [2008-08-12 1233199]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\pavel\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-08-22 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\program files\real\realplayer\update\realsched.exe -osboot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
C:\Program Files\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [2008-07-10 225396]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WiseStubReboot]
MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI TRANSFORMS=C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST WISE_SETUP_EXE_PATH=e:\driver\2k_xp\191.07\PhysX_9.09.0814_SystemSoftware.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^pavel^Nabídka Start^Programy^Po spuštění^hamachi.lnk]
D:\PROGRA~1\hamachi.exe [2010-11-17 625952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=D:\P R O G R A M [2012-12-08 6527128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Šikovné programy\Steam\Steam.exe"="D:\Šikovné programy\Steam\Steam.exe:*:Enabled:Steam"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Rage of Mages 2\rom2.exe"="C:\Rage of Mages 2\rom2.exe:*:Enabled:rom2"
"D:\Rage of Mages 2\rom2.exe"="D:\Rage of Mages 2\rom2.exe:*:Enabled:rom2"
"F:\CRACK\STARCRAFT II.EXE"="F:\CRACK\STARCRAFT II.EXE:*:Enabled:Blizzard Launcher"
"D:\Hry\StarCraft II\StarCraft II.exe"="D:\Hry\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher"
"D:\Hry\StarCraft II\Versions\Base15405\SC2.exe"="D:\Hry\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\StarCraft II\Versions\Base16561\SC2.exe"="D:\Hry\StarCraft II\Versions\Base16561\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\Counter strike 1.6\hl.exe"="D:\Hry\Counter strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"D:\P R O G R A M Y\QIP\qip.exe"="D:\P R O G R A M Y\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"D:\P R O G R A M Y\utorrent\uTorrent.exe"="D:\P R O G R A M Y\utorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\WINDOWS\system32\CNAB4RPK.EXE"="C:\WINDOWS\system32\CNAB4RPK.EXE:*:Enabled:Canon LBP2900 RPC Server Process"
"D:\Hry\Counter strike Source\Counter Strike Source 2010\hl2.exe"="D:\Hry\Counter strike Source\Counter Strike Source 2010\hl2.exe:*:Enabled:hl2"
"D:\Hry\Counter strike 1.6\hlds.exe"="D:\Hry\Counter strike 1.6\hlds.exe:*:Enabled:HLDS Launcher"
"D:\Hry\NFS Hot Pursuit\Launcher.exe"="D:\Hry\NFS Hot Pursuit\Launcher.exe:*:Enabled:Need for Speed(TM) Hot Pursuit"
"D:\Hry\NFS Hot Pursuit\NFS11.exe"="D:\Hry\NFS Hot Pursuit\NFS11.exe:*:Enabled:Need for Speed(TM) Hot Pursuit Application"
"D:\P R O G R A M Y\Garena\Garena.exe"="D:\P R O G R A M Y\Garena\Garena.exe:*:Enabled:Garena"
"D:\Hry\Call of Duty 2\CoD2MP_s.exe"="D:\Hry\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"D:\Hry\Team Fortress 2\hl2.exe"="D:\Hry\Team Fortress 2\hl2.exe:*:Enabled:hl2"
"D:\Hry\TF2\Team Fortress 2\hl2.exe"="D:\Hry\TF2\Team Fortress 2\hl2.exe:*:Enabled:hl2"
"D:\Hry\Team Fortress NS\hl2.exe"="D:\Hry\Team Fortress NS\hl2.exe:*:Enabled:hl2"
"D:\Hry\StarCraft II\Versions\Base16939\SC2.exe"="D:\Hry\StarCraft II\Versions\Base16939\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\StarCraft II\Versions\Base17326\SC2.exe"="D:\Hry\StarCraft II\Versions\Base17326\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\BaboViolent 2\bv2Dedicated.exe"="D:\Hry\BaboViolent 2\bv2Dedicated.exe:*:Enabled:bv2Dedicated"
"D:\Hry\BaboViolent 2\bv2.exe"="D:\Hry\BaboViolent 2\bv2.exe:*:Enabled:bv2"
"D:\Hry\BaboViolent 2\bv2Dedicated_v2_11fpro.exe"="D:\Hry\BaboViolent 2\bv2Dedicated_v2_11fpro.exe:*:Enabled:bv2Dedicated_v2_11fpro"
"D:\Hry\FixKorea\tacint\ti.exe"="D:\Hry\FixKorea\tacint\ti.exe:*:Enabled:ti"
"C:\Documents and Settings\pavel\Plocha\RGC\Ranked Gaming Client\rgc.exe"="C:\Documents and Settings\pavel\Plocha\RGC\Ranked Gaming Client\rgc.exe:*:Enabled:rgc"
"D:\Hry\Dead Space 2\deadspace2.exe"="D:\Hry\Dead Space 2\deadspace2.exe:*:Enabled:Dead Space™ 2"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"D:\Hry\Diablo II\Diablo II.exe"="D:\Hry\Diablo II\Diablo II.exe:*:Enabled:Diablo II - Lord of Destruction"
"D:\Hry\StarCraft II\Versions\Base18092\SC2.exe"="D:\Hry\StarCraft II\Versions\Base18092\SC2.exe:*:Enabled:StarCraft II"
"H:\WinDVD.exe"="H:\WinDVD.exe:*:Enabled:WinDVD"
"D:\Hry\Warcraft III\Warcraft III.exe"="D:\Hry\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
"D:\P R O G R A M Y\hamachi.exe"="D:\P R O G R A M Y\hamachi.exe:*:Enabled:Hamachi Client"
"C:\Documents and Settings\pavel\Local Settings\Temp\Rar$EX00.468\WoW-BurningCrusade-enGBdownloader.exe"="C:\Documents and Settings\pavel\Local Settings\Temp\Rar$EX00.468\WoW-BurningCrusade-enGBdownloader.exe:*:Enabled:Blizzard Downloader"
"D:\World Of Warcraft Classic\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"="D:\World Of Warcraft Classic\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\World Of Warcraft Classic\Launcher.exe"="D:\World Of Warcraft Classic\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\World Of Warcraft Classic\Launcher.patch.exe"="D:\World Of Warcraft Classic\Launcher.patch.exe:*:Enabled:Blizzard Launcher"
"D:\Hry\World of Warcraft\Launcher.exe"="D:\Hry\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"D:\Hry\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"="D:\Hry\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Documents and Settings\pavel\Plocha\WoW-3.2.0-enGB-downloader.exe"="C:\Documents and Settings\pavel\Plocha\WoW-3.2.0-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Hry\Portal 2\portal2.exe"="D:\Hry\Portal 2\portal2.exe:*:Enabled:portal2"
"D:\Hry\GTA IV\Grand Theft Auto IV\GTAIV.exe"="D:\Hry\GTA IV\Grand Theft Auto IV\GTAIV.exe:*:Disabled:Grand Theft Auto IV"
"D:\Hry\NHL 09\nhl2009.exe"="D:\Hry\NHL 09\nhl2009.exe:*:Disabled:nhl2009"
"D:\Hry\NHL08\nhl2008.exe"="D:\Hry\NHL08\nhl2008.exe:*:Enabled:nhl2008"
"D:\Hry\nhl04\nhl2004.exe"="D:\Hry\nhl04\nhl2004.exe:*:Enabled:nhl2004"
"D:\Hry\Heroes2\HEROES2W.EXE"="D:\Hry\Heroes2\HEROES2W.EXE:*:Enabled:HEROES2W"
"D:\Hry\StarCraft II\Versions\Base18574\SC2.exe"="D:\Hry\StarCraft II\Versions\Base18574\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\Witcher 2\bin\witcher2.exe"="D:\Hry\Witcher 2\bin\witcher2.exe:*:Enabled:The Witcher 2: Assasins of Kings"
"D:\Hry\Commandos 2\comm2.exe"="D:\Hry\Commandos 2\comm2.exe:*:Enabled:comm2"
"D:\Hry\Fifa 11\Game\fifa.exe"="D:\Hry\Fifa 11\Game\fifa.exe:*:Enabled:FIFA 11"
"D:\Hry\L4D2\Left 4 Dead 2\left4dead2.exe"="D:\Hry\L4D2\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"H:\L4D2\Left 4 Dead 2\left4dead2.exe"="H:\L4D2\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"D:\Hry\Left 4 Dead 2\L4D2\Left 4 Dead 2\left4dead2.exe"="D:\Hry\Left 4 Dead 2\L4D2\Left 4 Dead 2\left4dead2.exe:*:Enabled:left4dead2"
"D:\Hry\FEAR3\F.E.A.R. 3\F.E.A.R. 3.exe"="D:\Hry\FEAR3\F.E.A.R. 3\F.E.A.R. 3.exe:*:Enabled:F.E.A.R. 3"
"D:\Hry\BorderLands\Gearbox Software\Borderlands\Binaries\Borderlands.exe"="D:\Hry\BorderLands\Gearbox Software\Borderlands\Binaries\Borderlands.exe:*:Enabled:Borderlands"
"D:\P R O G R A M Y\Steam\Steam.exe"="D:\P R O G R A M Y\Steam\Steam.exe:*:Enabled:Steam"
"D:\Hry\F.E.A.R. 3\F.E.A.R. 3.exe"="D:\Hry\F.E.A.R. 3\F.E.A.R. 3.exe:*:Enabled:F.E.A.R. 3"
"D:\Hry\Titan Quest\Titan Quest.exe"="D:\Hry\Titan Quest\Titan Quest.exe:*:Enabled:Titan Quest"
"D:\Hry\Titan Quest IT\Tqit.exe"="D:\Hry\Titan Quest IT\Tqit.exe:*:Enabled:Tqit"
"D:\Hry\TQ IT\Tqit.exe"="D:\Hry\TQ IT\Tqit.exe:*:Enabled:Tqit"
"D:\Hry\StarCraft II\Versions\Base19132\SC2.exe"="D:\Hry\StarCraft II\Versions\Base19132\SC2.exe:*:Enabled:StarCraft II"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Hry\BF4free\BFP4f.exe"="D:\Hry\BF4free\BFP4f.exe:*:Enabled:BFP4f"
"D:\Program Files\Capcom\Bionic Commando\bionic_commando.exe"="D:\Program Files\Capcom\Bionic Commando\bionic_commando.exe:*:Enabled:Bionic Commando"
"D:\Hry\Re-Volt\revolt.exe"="D:\Hry\Re-Volt\revolt.exe:*:Enabled:revolt"
"D:\P R O G R A M Y\Steam\steamapps\paulie0001\team fortress 2\hl2.exe"="D:\P R O G R A M Y\Steam\steamapps\paulie0001\team fortress 2\hl2.exe:*:Enabled:hl2"
"D:\Hry\Dead Island\Dead Island\deadislandgame.exe"="D:\Hry\Dead Island\Dead Island\deadislandgame.exe:*:Enabled:DeadIsland"
"D:\Hry\Driver San Francisko\Driver.exe"="D:\Hry\Driver San Francisko\Driver.exe:*:Enabled:Driver San Francisco"
"D:\Hry\Assassins Creed 3\ACBMP.exe"="D:\Hry\Assassins Creed 3\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.439\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.439\Agent.exe:*:Enabled:Blizzard Agent"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.440\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.440\Agent.exe:*:Enabled:Blizzard Agent"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"D:\P R O G R A M Y\Steam\SmartSteam\Steam.exe"="D:\P R O G R A M Y\Steam\SmartSteam\Steam.exe:*:Enabled:Steam"
"D:\Hry\Warcraft III\gproxy.exe"="D:\Hry\Warcraft III\gproxy.exe:*:Enabled:gproxy Application"
"D:\Hry\Warcraft III\war3.exe"="D:\Hry\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"\\ZEM-FC29537D19D\Jirsoun (D)\Age Of Empires 2\empires2.exe"="\\ZEM-FC29537D19D\Jirsoun (D)\Age Of Empires 2\empires2.exe:*:Enabled:empires2.exe"
"D:\P R O G R A M Y\ParadiseCasino\casino.exe"="D:\P R O G R A M Y\ParadiseCasino\casino.exe:*:Enabled:casino"
"D:\Hry\Age of Empires 3\age3y.exe"="D:\Hry\Age of Empires 3\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"D:\Hry\Crysis 2\bin32\Crysis2.exe"="D:\Hry\Crysis 2\bin32\Crysis2.exe:*:Enabled:Crysis2"
"\\ZEM-FC29537D19D\JIRSOUN (D)\MOHAA\MOHAA.exe"="\\ZEM-FC29537D19D\JIRSOUN (D)\MOHAA\MOHAA.exe:*:Enabled:MOHAA.exe"
"D:\Hry\StarCraft II\Versions\Base21029\SC2.exe"="D:\Hry\StarCraft II\Versions\Base21029\SC2.exe:*:Enabled:StarCraft II"
"D:\Hry\Age of Empires 3\age3x.exe"="D:\Hry\Age of Empires 3\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"
"D:\Max Payne 3\MaxPayne3.exe"="D:\Max Payne 3\MaxPayne3.exe:*:Enabled:Max Payne 3"
"D:\Hry\StarCraft II\sc2-x.x.x.x-1.5.0.22342-enUS-Downloader.exe"="D:\Hry\StarCraft II\sc2-x.x.x.x-1.5.0.22342-enUS-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1199\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1199\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\Hry\StarCraft II\StarCraft II Public Test.exe"="D:\Hry\StarCraft II\StarCraft II Public Test.exe:*:Enabled:StarCraft II Public Test"
"C:\Program Files\Garena Plus\Room\garena_room.exe"="C:\Program Files\Garena Plus\Room\garena_room.exe:*:Enabled:Garena"
"C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1267\Agent.exe"="C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Battle.net\Agent\Agent.1267\Agent.exe:*:Enabled:Battle.net Update Agent"
"D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe"="D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32server.exe:*:Enabled:mental ray satellite server for Autodesk 3ds Max Design 2013 32-bit"
"D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32.exe"="D:\P R O G R A M Y\AutoDesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_32.exe:*:Enabled:mental ray satellite for Autodesk 3ds Max Design 2013 32-bit"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"msacm.lhacm"=lhacm.acm
"VIDC.FFDS"=ff_vfw.dll
"msacm.avis"=ff_acm.acm
"SENTINEL"=snti386.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.iv50"=ir50_32.dll
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"VIDC.IV41"=IR41_32.AX
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.vorbis"=vorbis.acm
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux1"=wdmaud.drv

======List of files/folders created in the last 1 month======

2014-05-11 21:01:20 ----D---- C:\Documents and Settings\pavel\Data aplikací\Malwarebytes
2014-05-11 21:01:01 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2014-05-11 21:01:01 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2014-05-11 18:42:15 ----D---- C:\Program Files\WebbIng
2014-05-11 18:42:15 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\WebbIng
2014-05-11 15:38:15 ----D---- C:\WINDOWS\ERUNT
2014-05-11 12:45:44 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2014-05-11 12:33:02 ----A---- C:\WINDOWS\system32\sqlite3.dll
2014-05-11 12:32:08 ----D---- C:\AdwCleaner
2014-04-29 20:05:54 ----D---- C:\Documents and Settings\pavel\Data aplikací\e-academy Inc
2014-04-28 11:20:58 ----D---- C:\Program Files\Common Files\Skype
2014-04-28 11:20:57 ----RD---- C:\Program Files\Skype
2014-04-22 16:31:09 ----D---- C:\Program Files\NNextCoup
2014-04-22 16:31:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\NNextCoup
2014-04-22 16:30:57 ----A---- C:\WINDOWS\wininit.ini
2014-04-22 16:26:18 ----RA---- C:\WINDOWS\system32\tmp242.tmp

======List of files/folders modified in the last 1 month======

2014-05-12 14:07:01 ----D---- C:\WINDOWS\Prefetch
2014-05-12 14:06:55 ----D---- C:\Program Files\trend micro
2014-05-12 14:05:49 ----D---- C:\Documents and Settings\pavel\Data aplikací\GarenaPlus
2014-05-12 14:05:49 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\GarenaMessenger
2014-05-12 14:04:22 ----D---- C:\Documents and Settings\pavel\Data aplikací\Skype
2014-05-12 14:02:53 ----D---- C:\WINDOWS\system32\CatRoot2
2014-05-12 14:02:34 ----D---- C:\Program Files\Steam
2014-05-12 14:02:20 ----D---- C:\WINDOWS\Temp
2014-05-12 13:59:42 ----D---- C:\WINDOWS\system32\drivers
2014-05-12 13:59:01 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-05-12 13:58:17 ----D---- C:\Documents and Settings\pavel\Data aplikací\uTorrent
2014-05-12 13:57:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219$
2014-05-12 13:57:02 ----D---- C:\Program Files\CCleaner
2014-05-12 13:56:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-05-12 13:56:06 ----HD---- C:\WINDOWS\inf
2014-05-12 13:56:06 ----D---- C:\WINDOWS
2014-05-11 21:01:01 ----RD---- C:\Program Files
2014-05-11 18:42:15 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\7bbf9f6402f92a59
2014-05-11 18:40:33 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2014-05-11 18:20:45 ----SHD---- C:\WINDOWS\Installer
2014-05-11 18:20:10 ----D---- C:\Program Files\TomTom HOME 2
2014-05-11 18:19:45 ----SD---- C:\Documents and Settings\pavel\Data aplikací\Microsoft
2014-05-11 16:05:48 ----D---- C:\Program Files\Common Files
2014-05-11 16:05:48 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Autodesk
2014-05-11 16:00:10 ----D---- C:\WINDOWS\Minidump
2014-05-11 16:00:10 ----D---- C:\WINDOWS\Logs
2014-05-11 16:00:10 ----D---- C:\WINDOWS\Debug
2014-05-11 14:57:43 ----D---- C:\Documents and Settings\pavel\Data aplikací\Autodesk
2014-05-11 13:21:23 ----D---- C:\Program Files\Autodesk
2014-05-11 12:34:11 ----D---- C:\Program Files\Mozilla Firefox
2014-05-11 12:33:02 ----D---- C:\WINDOWS\system32
2014-05-10 14:04:48 ----D---- C:\Documents and Settings\pavel\Data aplikací\vlc
2014-05-03 23:06:58 ----D---- C:\WINDOWS\ie8updates
2014-04-30 10:12:55 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-04-28 11:21:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Skype
2014-04-22 16:27:12 ----D---- C:\Program Files\Real
2014-04-22 16:27:03 ----D---- C:\Documents and Settings\pavel\Data aplikací\Real
2014-04-22 16:21:09 ----D---- C:\Documents and Settings\pavel\Data aplikací\Kastner software
2014-04-22 16:21:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\KASTNER software
2014-04-22 15:57:04 ----D---- C:\Program Files\VstPlugins
2014-04-22 15:55:22 ----HD---- C:\Program Files\InstallShield Installation Information
2014-04-22 09:59:11 ----SD---- C:\WINDOWS\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2013-12-06 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2013-12-06 178304]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-02-04 717296]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2012-10-31 20624]
R1 aswRdr;aswRdr; \??\C:\WINDOWS\system32\drivers\aswRdr.sys []
R1 aswSnx;aswSnx; \??\C:\WINDOWS\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; \??\C:\WINDOWS\system32\drivers\aswSP.sys []
R1 aswTdi;aswTdi; \??\C:\WINDOWS\system32\drivers\aswTdi.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASDIFSV;SASDIFSV; \??\D:\P R O G R A M Y\SuperAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\D:\P R O G R A M Y\SuperAntiSpyware\SASKUTIL.SYS []
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2009-03-15 56268]
R2 aswFsBlk;aswFsBlk; \??\C:\WINDOWS\system32\drivers\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-10-09 279712]
R2 hardlock;hardlock; C:\WINDOWS\System32\DRIVERS\hardlock.sys [2004-01-31 420000]
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 ithsgt;ithsgt; C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2011-09-14 162432]
R2 lilsgt;lilsgt; C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2011-09-14 12032]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-10-09 25888]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2004-05-17 76288]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-11-17 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-02-24 6340200]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys [2010-05-03 225232]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-07-17 60160]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 a7aph01g;a7aph01g; C:\WINDOWS\system32\drivers\a7aph01g.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 GGSAFERDriver;GGSAFER Driver; \??\D:\P R O G R A M Y\Garena\safedrv.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2011-08-17 23168]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda32.sys [2010-11-12 100456]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-10-21 47360]
S3 SECUSB2;SECUSB2.sys, SEC SOC USBD Driver; C:\WINDOWS\System32\Drivers\SECUSB2.sys [2008-04-16 10528]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-16 104576]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; D:\P R O G R A M [2012-12-08 6527128]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\System32\CTsvcCDA.exe [1999-12-12 44032]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-04-30 417792]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [2012-07-05 161704]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-25 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-08-19 79360]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-05-25 136176]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2010-08-19 79360]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2013-03-15 543656]
S3 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2013-11-06 758224]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 avast! Firewall;avast! Firewall; D:\P R O G R A M [2012-12-08 6527128]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pro Motji

#9 Příspěvek od motji »

Lepší, ještě vyházejte spouštění některých programů po startu, třeba přes ccleaner.
Tuto složku znáte?
C:\Program Files\WebbIng
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Re: Pro Motji

#10 Příspěvek od Paulie0001 »

nene neznám, mám s tím něco udělat? ;)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pro Motji

#11 Příspěvek od motji »

Podívat se co v ní je :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Re: Pro Motji

#12 Příspěvek od Paulie0001 »

Je prádná :D 0 bajtů ;)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pro Motji

#13 Příspěvek od motji »

Smazat
C:\Program Files\WebbIng
C:\Documents and Settings\All Users.WINDOWS\Data aplikací\WebbIng

A jinak to vypadá jak? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Paulie0001
Návštěvník
Návštěvník
Příspěvky: 234
Registrován: 05 led 2008 15:17

Re: Pro Motji

#14 Příspěvek od Paulie0001 »

Rozhodně to vypadá daleko lépe než předtím :) Děkuji.
Brzy by se mi měl vrátit brácha tak určitě bude mít velkou radost :happy:
tak děkuji za pomoc, brzy se ozvu s mým počítačem, ať ho taky omrknem :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pro Motji

#15 Příspěvek od motji »

:D No, aby ji měl, pařmeni se většinou zajímají jen o to, zda jim nezmizela nějaká hra :D
Mějte se hezky a ozvěte se :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět