Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o prev. kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Prosím o prev. kontrolu

#1 Příspěvek od jindra5 »

Sice nemám žádný výraznější problém s PC, ale i tak prosím o preventivní kontrolu logu... Díky :wink:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Takitos at 2010-01-28 14:10:25
Microsoft Windows 7 Ultimate Service Pack 2
System drive C: has 70 GB (29%) free of 238 GB
Total RAM: 3327 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:10:50, on 28.1.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\SoundMAX.exe
C:\Program Files\OO Software\Defrag\oodtray.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVerMedia\AVerTV\AVerTV.exe
C:\Users\Takitos\Desktop\RSIT.exe
C:\Program Files\trend micro\Takitos.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: HopSurf toolbar - {E9FAB13D-4600-49E1-90D1-EE961C859D39} - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe /tray
O4 - HKLM\..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout s IDM obsah FLV videa - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM všechny odkazy - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: HopSurf - {ED98F8D1-09AC-4107-B2FF-91DBE011B0C5} - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E62A8B6B-D91C-457C-B1FB-20CC2D96B4EC} (Comodo AV Scanner ActiveX) - http://eu2.download.comodo.com/avs/ComodoAVScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3702C02A-DDF5-4073-8DF6-99FB6A8407A7}: NameServer = 78.156.32.2,84.244.102.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{3702C02A-DDF5-4073-8DF6-99FB6A8407A7}: NameServer = 78.156.32.2,84.244.102.11
O17 - HKLM\System\CS2\Services\Tcpip\..\{3702C02A-DDF5-4073-8DF6-99FB6A8407A7}: NameServer = 78.156.32.2,84.244.102.11
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 10669 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-04-02 169392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-08-04 1586472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]

{E9FAB13D-4600-49E1-90D1-EE961C859D39} - HopSurf toolbar - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll [2010-01-27 1122496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=C:\Program Files\Alwil Software\Avast4\ashDisp.exe [2009-11-25 81000]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-02-07 54832]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-06-05 1310720]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe [2009-09-12 2524416]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-01-27 1800464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-10-20 2794928]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"NokiaOviSuite2"=C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [2009-12-10 401728]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-08-20 2363392]
""= []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\Windows\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-01-28 14:09:41 ----D---- C:\Program Files\trend micro
2010-01-28 14:09:38 ----D---- C:\rsit
2010-01-27 20:13:30 ----D---- C:\Users\Takitos\AppData\Roaming\Comodo
2010-01-27 20:09:41 ----D---- C:\ProgramData\Comodo
2010-01-27 20:09:40 ----A---- C:\Windows\system32\guard32.dll
2010-01-27 20:09:39 ----D---- C:\Program Files\COMODO
2010-01-27 19:16:10 ----D---- C:\Users\Takitos\AppData\Roaming\Malwarebytes
2010-01-27 19:16:06 ----D---- C:\ProgramData\Malwarebytes
2010-01-27 19:16:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-27 12:52:43 ----A---- C:\Windows\explorer.exe
2010-01-27 12:52:42 ----A---- C:\Windows\system32\winlogon.exe
2010-01-25 16:42:28 ----D---- C:\ProgramData\FLEXnet
2010-01-25 16:38:41 ----D---- C:\Program Files\Adobe Media Player
2010-01-25 16:37:06 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-01-25 16:35:07 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-01-23 14:02:22 ----D---- C:\Program Files\Mass Effect 2
2010-01-22 23:29:39 ----D---- C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2010-01-22 23:18:14 ----D---- C:\Program Files\Common Files\BioWare
2010-01-22 22:49:09 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 22:49:09 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 22:49:08 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 22:49:08 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 22:49:05 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 22:49:05 ----A---- C:\Windows\system32\ieframe.dll
2010-01-21 00:03:00 ----D---- C:\Program Files\Adobe
2010-01-20 00:21:08 ----D---- C:\Windows\Sun
2010-01-19 15:18:22 ----D---- C:\Program Files\AGEIA Technologies
2010-01-19 12:48:19 ----D---- C:\Program Files\Mindware Studios
2010-01-19 03:54:31 ----D---- C:\Windows\system32\oodag
2010-01-19 03:52:38 ----D---- C:\Program Files\OO Software
2010-01-18 18:19:23 ----D---- C:\Users\Takitos\AppData\Roaming\skypePM
2010-01-18 18:17:22 ----D---- C:\Users\Takitos\AppData\Roaming\Skype
2010-01-18 18:17:07 ----D---- C:\Program Files\Common Files\Skype
2010-01-18 18:17:06 ----RD---- C:\Program Files\Skype
2010-01-18 18:17:04 ----D---- C:\ProgramData\Skype
2010-01-18 16:02:57 ----A---- C:\odkazy.txt
2010-01-17 01:19:01 ----A---- C:\Windows\system32\t2embed.dll
2010-01-17 01:19:01 ----A---- C:\Windows\system32\fontsub.dll
2010-01-15 22:27:57 ----D---- C:\ProgramData\Solidshield
2010-01-12 01:10:48 ----D---- C:\Program Files\Electronic Arts
2010-01-07 12:22:58 ----D---- C:\ProgramData\Codemasters
2010-01-07 12:15:58 ----A---- C:\Windows\system32\mkl_vml_p4.dll
2010-01-07 12:15:58 ----A---- C:\Windows\system32\mkl_vml_p3.dll
2010-01-07 12:15:58 ----A---- C:\Windows\system32\mkl_vml_def.dll
2010-01-07 12:15:57 ----A---- C:\Windows\system32\rapture3d_oal.dll
2010-01-07 12:15:57 ----A---- C:\Windows\system32\mkl_p4.dll
2010-01-07 12:15:57 ----A---- C:\Windows\system32\mkl_p3.dll
2010-01-07 12:15:57 ----A---- C:\Windows\system32\mkl_lapack64.dll
2010-01-07 12:15:57 ----A---- C:\Windows\system32\mkl_lapack32.dll
2010-01-07 12:15:57 ----A---- C:\Windows\system32\mkl_def.dll
2010-01-07 12:15:57 ----A---- C:\Windows\system32\libguide40.dll
2010-01-07 12:15:55 ----D---- C:\Program Files\BRS
2010-01-07 12:15:33 ----D---- C:\Windows\system32\xlive
2010-01-07 12:15:33 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2010-01-07 12:15:17 ----RA---- C:\Windows\system32\tmp774D.tmp
2010-01-07 12:14:17 ----RA---- C:\Windows\system32\tmp773D.tmp
2010-01-05 21:26:46 ----A---- C:\Windows\system32\OpenCL.dll
2010-01-05 21:26:45 ----A---- C:\Windows\system32\nvoglv32.dll
2010-01-05 21:26:45 ----A---- C:\Windows\system32\nvencodemft.dll
2010-01-05 21:26:45 ----A---- C:\Windows\system32\nvdecodemft.dll
2010-01-05 21:26:45 ----A---- C:\Windows\system32\nvcuvid.dll
2010-01-05 21:26:45 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-01-05 21:26:45 ----A---- C:\Windows\system32\nvcuda.dll
2010-01-05 21:26:43 ----A---- C:\Windows\system32\nvcompiler.dll
2010-01-05 21:26:43 ----A---- C:\Windows\system32\nvcod178.dll
2010-01-05 21:26:43 ----A---- C:\Windows\system32\nvcod.dll
2010-01-05 20:54:09 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-01-05 20:54:09 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-01-05 20:54:08 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-12-30 16:52:09 ----D---- C:\Program Files\GSC World Publishing

======List of files/folders modified in the last 1 months======

2010-01-28 14:10:44 ----D---- C:\Windows\Temp
2010-01-28 14:10:03 ----D---- C:\Windows\Prefetch
2010-01-28 14:09:41 ----RD---- C:\Program Files
2010-01-28 12:42:45 ----D---- C:\Program Files\SpeedFan
2010-01-28 10:38:03 ----D---- C:\Windows\system32\config
2010-01-28 03:16:39 ----D---- C:\Users\Takitos\AppData\Roaming\DMCache
2010-01-28 03:16:30 ----D---- C:\Windows\winsxs
2010-01-28 03:16:25 ----D---- C:\ProgramData\NVIDIA
2010-01-28 03:15:14 ----D---- C:\Windows\System32
2010-01-28 03:15:14 ----D---- C:\Windows
2010-01-28 02:34:51 ----D---- C:\Windows\Downloaded Program Files
2010-01-27 23:35:29 ----D---- C:\Program Files\Share Rapid Uploader
2010-01-27 21:39:11 ----D---- C:\Program Files\Internet Explorer
2010-01-27 21:39:02 ----SHD---- C:\System Volume Information
2010-01-27 20:22:06 ----D---- C:\Windows\system32\drivers
2010-01-27 20:17:23 ----D---- C:\Users\Takitos\AppData\Roaming\Adobe
2010-01-27 20:13:21 ----D---- C:\Windows\inf
2010-01-27 20:13:19 ----D---- C:\Windows\system32\DriverStore
2010-01-27 20:13:19 ----D---- C:\Windows\system32\catroot
2010-01-27 20:09:41 ----HD---- C:\ProgramData
2010-01-27 12:52:38 ----D---- C:\Windows\system32\catroot2
2010-01-27 10:58:57 ----SHD---- C:\Windows\Installer
2010-01-27 10:58:33 ----RSD---- C:\Windows\assembly
2010-01-26 19:03:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-25 16:39:46 ----D---- C:\ProgramData\Adobe
2010-01-25 16:39:14 ----D---- C:\Program Files\Common Files\Adobe
2010-01-25 16:38:21 ----RSD---- C:\Windows\Fonts
2010-01-25 16:37:06 ----D---- C:\Program Files\Common Files
2010-01-24 22:10:57 ----D---- C:\Program Files\Mozilla Firefox
2010-01-23 00:02:07 ----D---- C:\HRY
2010-01-22 23:29:34 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-22 22:48:25 ----D---- C:\Windows\SoftwareDistribution
2010-01-22 20:12:40 ----A---- C:\Windows\AVerText.ini
2010-01-22 15:31:21 ----SD---- C:\Users\Takitos\AppData\Roaming\Microsoft
2010-01-19 20:41:40 ----D---- C:\Program Files\ICQ6.5
2010-01-19 20:05:07 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-01-19 15:18:22 ----D---- C:\Program Files\NVIDIA Corporation
2010-01-19 03:57:58 ----D---- C:\Windows\debug
2010-01-18 21:47:38 ----D---- C:\Users\Takitos\AppData\Roaming\ICQ
2010-01-18 18:17:20 ----D---- C:\Windows\system32\Tasks
2010-01-15 22:21:37 ----D---- C:\Program Files\Ubisoft
2010-01-15 22:21:35 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-12 00:41:41 ----D---- C:\Program Files\F.E.A.R. 2
2010-01-10 23:20:40 ----D---- C:\Program Files\Common Files\Logitech
2010-01-07 12:15:17 ----D---- C:\Program Files\OpenAL
2010-01-07 12:15:17 ----A---- C:\Windows\system32\wrap_oal.dll
2010-01-07 12:15:17 ----A---- C:\Windows\system32\OpenAL32.dll
2010-01-07 12:03:16 ----D---- C:\Program Files\Codemasters
2010-01-07 01:44:13 ----D---- C:\Program Files\Internet Download Manager
2010-01-05 22:06:24 ----D---- C:\ProgramData\AVerTV
2010-01-05 21:36:27 ----D---- C:\Windows\Driver Cache
2010-01-05 01:17:46 ----A---- C:\Windows\system32\MRT.exe
2010-01-03 02:49:34 ----D---- C:\Program Files\Activision
2010-01-03 02:48:20 ----D---- C:\Program Files\GRETECH
2010-01-03 02:48:15 ----D---- C:\Users\Takitos\AppData\Roaming\GRETECH
2010-01-03 02:48:07 ----AD---- C:\ProgramData\TEMP
2010-01-01 22:58:06 ----A---- C:\Windows\BlendSettings.ini
2010-01-01 02:17:40 ----D---- C:\Windows\system32\wdi

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-11-25 23120]
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 blbdrive;blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys [2009-07-14 35328]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2010-01-27 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2010-01-27 29520]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 DfsC;@%systemroot%\system32\drivers\dfsc.sys,-101; C:\Windows\System32\Drivers\dfsc.sys [2009-07-14 78336]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2010-01-27 74328]
R1 nsiproxy;@%SystemRoot%\system32\drivers\nsiproxy.sys,-2; C:\Windows\system32\drivers\nsiproxy.sys [2009-07-14 16896]
R1 RDPENCDD;@%systemroot%\system32\drivers\RDPENCDD.sys,-101; C:\Windows\system32\drivers\rdpencdd.sys [2009-07-14 6656]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 tdx;@%SystemRoot%\system32\tcpipcfg.dll,-50004; C:\Windows\system32\DRIVERS\tdx.sys [2009-07-14 74240]
R1 Wanarpv6;@%systemroot%\system32\rascfg.dll,-32012; C:\Windows\system32\DRIVERS\wanarp.sys [2009-07-14 63488]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B}; \??\C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 13560]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-11-25 53328]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-20 281760]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-20 25888]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver; C:\Windows\system32\DRIVERS\lltdio.sys [2009-07-14 48128]
R2 luafv;@%systemroot%\system32\drivers\luafv.sys,-100; C:\Windows\system32\drivers\luafv.sys [2009-07-14 86528]
R2 PEAUTH;PEAUTH; C:\Windows\system32\drivers\peauth.sys [2009-07-14 586752]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\Windows\system32\DRIVERS\rspndr.sys [2009-07-14 60928]
R2 tcpipreg;TCP/IP Registry Compatibility; C:\Windows\System32\drivers\tcpipreg.sys [2009-07-14 34816]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-06-05 380416]
R3 AVerA706;AVerMedia A706 BDA Service; C:\Windows\system32\DRIVERS\AVerA706.sys [2009-06-10 1169920]
R3 bowser;@%systemroot%\system32\browser.dll,-102; C:\Windows\system32\DRIVERS\bowser.sys [2009-07-14 69632]
R3 CompositeBus;Ovladač rozpoznávacího modulu složené sběrnice; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 DXGKrnl;LDDM Graphics Subsystem; C:\Windows\System32\drivers\dxgkrnl.sys [2009-10-02 728648]
R3 HDAudBus;Ovladač sběrnice Microsoft UAA pro zvuk High Definition Audio; C:\Windows\system32\DRIVERS\HDAudBus.sys [2009-07-14 108544]
R3 HidUsb;Ovladač třídy standardu HID Microsoft; C:\Windows\system32\DRIVERS\hidusb.sys [2009-07-14 24064]
R3 intelppm;Ovladač procesoru Intel; C:\Windows\system32\DRIVERS\intelppm.sys [2009-07-14 53760]
R3 kbdhid;Ovladač klávesnice standardu HID; C:\Windows\system32\DRIVERS\kbdhid.sys [2009-07-14 28160]
R3 monitor;Služba ovladače funkce třídy monitorů Microsoft; C:\Windows\system32\DRIVERS\monitor.sys [2009-07-14 23552]
R3 mouhid;Ovladač myši standardu HID; C:\Windows\system32\DRIVERS\mouhid.sys [2009-07-14 26112]
R3 mpsdrv;@%SystemRoot%\system32\FirewallAPI.dll,-23092; C:\Windows\System32\drivers\mpsdrv.sys [2009-07-14 60416]
R3 mrxsmb10;@%systemroot%\system32\wkssvc.dll,-1004; C:\Windows\system32\DRIVERS\mrxsmb10.sys [2009-07-14 221184]
R3 mrxsmb20;@%systemroot%\system32\wkssvc.dll,-1006; C:\Windows\system32\DRIVERS\mrxsmb20.sys [2009-07-14 95744]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-11-21 11515752]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2009-10-25 47360]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 RasSstp;@%systemroot%\system32\sstpsvc.dll,-202; C:\Windows\system32\DRIVERS\rassstp.sys [2009-07-14 75264]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 srv2;@%systemroot%\system32\srvsvc.dll,-104; C:\Windows\System32\DRIVERS\srv2.sys [2009-07-14 306688]
R3 srvnet;srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [2009-07-14 113664]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver; C:\Windows\system32\DRIVERS\tunnel.sys [2009-07-14 108544]
R3 umbus;Ovladač sběrnice UMBus Enumerator; C:\Windows\system32\DRIVERS\umbus.sys [2009-07-14 39936]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\Windows\system32\DRIVERS\usbccgp.sys [2009-07-14 75264]
R3 usbehci;Ovladač miniportu vylepšeného hostitelského řadiče Microsoft USB 2.0; C:\Windows\system32\DRIVERS\usbehci.sys [2009-07-14 41472]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\Windows\system32\DRIVERS\usbhub.sys [2009-07-14 258560]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\Windows\system32\DRIVERS\USBSTOR.SYS [2009-07-14 74752]
R3 usbuhci;Ovladač miniportu univerzálního hostitelského řadiče Microsoft USB; C:\Windows\system32\DRIVERS\usbuhci.sys [2009-07-14 24064]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2009-09-11 22792]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2009-09-11 66056]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
R3 yukonw7;Ovladač NDIS6.2 Miniport pro řadič Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
S2 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Users\Takitos\AppData\Local\Temp\Rar$EX00.164\HWiNFO32.SYS []
S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
S3 a929up05;a929up05; C:\Windows\system32\drivers\a929up05.sys []
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 adp94xx;adp94xx; C:\Windows\system32\DRIVERS\adp94xx.sys [2009-07-14 422976]
S3 adpahci;adpahci; C:\Windows\system32\DRIVERS\adpahci.sys [2009-07-14 297552]
S3 adpu320;adpu320; C:\Windows\system32\DRIVERS\adpu320.sys [2009-07-14 146512]
S3 agp440;Intel AGP Bus Filter; C:\Windows\system32\DRIVERS\agp440.sys [2009-07-14 53312]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 amdide;amdide; C:\Windows\system32\DRIVERS\amdide.sys [2009-07-14 14912]
S3 AmdK8;AMD K8 Processor Driver; C:\Windows\system32\DRIVERS\amdk8.sys [2009-07-14 55296]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 arc;arc; C:\Windows\system32\DRIVERS\arc.sys [2009-07-14 76368]
S3 arcsas;arcsas; C:\Windows\system32\DRIVERS\arcsas.sys [2009-07-14 86608]
S3 AVerBDA3x;AVerMedia SAA713x BDA Service; C:\Windows\system32\DRIVERS\AVerBDA3x.sys [2007-05-21 1180672]
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver; C:\Windows\system32\DRIVERS\BrFiltLo.sys [2009-07-13 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver; C:\Windows\system32\DRIVERS\BrFiltUp.sys [2009-07-13 5248]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM); C:\Windows\System32\Drivers\Brserid.sys [2009-07-14 272128]
S3 BrSerWdm;Brother WDM Serial driver; C:\Windows\System32\Drivers\BrSerWdm.sys [2009-07-13 62336]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem; C:\Windows\System32\Drivers\BrUsbMdm.sys [2009-07-13 12160]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\Windows\System32\Drivers\BrUsbSer.sys [2009-07-13 11904]
S3 BTHMODEM;Bluetooth Serial Communications Driver; C:\Windows\system32\DRIVERS\bthmodem.sys [2009-07-14 56320]
S3 circlass;Consumer IR Devices; C:\Windows\system32\DRIVERS\circlass.sys [2009-07-14 37888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 Compbatt;Compbatt; C:\Windows\system32\DRIVERS\compbatt.sys [2009-07-14 19024]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 elxstor;elxstor; C:\Windows\system32\DRIVERS\elxstor.sys [2009-07-14 453712]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 exfat;exFAT File System Driver; C:\Windows\system32\drivers\exfat.sys [2009-07-14 142336]
S3 Filetrace;@%SystemRoot%\system32\drivers\filetrace.sys,-10001; C:\Windows\system32\drivers\filetrace.sys [2009-07-14 28160]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\Windows\system32\DRIVERS\gagp30kx.sys [2009-07-14 57936]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HidBth;Microsoft Bluetooth HID Miniport; C:\Windows\system32\DRIVERS\hidbth.sys [2009-07-14 91136]
S3 HidIr;Microsoft Infrared HID Driver; C:\Windows\system32\DRIVERS\hidir.sys [2009-07-14 37888]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 iaStorV;iaStorV; C:\Windows\system32\DRIVERS\iaStorV.sys [2009-07-14 332352]
S3 iirsp;iirsp; C:\Windows\system32\DRIVERS\iirsp.sys [2009-07-14 41040]
S3 intelide;intelide; C:\Windows\system32\DRIVERS\intelide.sys [2009-07-14 15424]
S3 IPMIDRV;IPMIDRV; C:\Windows\system32\DRIVERS\IPMIDrv.sys [2009-07-14 65536]
S3 isapnp;isapnp; C:\Windows\system32\DRIVERS\isapnp.sys [2009-07-14 46656]
S3 iScsiPrt;iScsiPort Driver; C:\Windows\system32\DRIVERS\msiscsi.sys [2009-07-14 186960]
S3 LSI_FC;LSI_FC; C:\Windows\system32\DRIVERS\lsi_fc.sys [2009-07-14 95824]
S3 LSI_SAS;LSI_SAS; C:\Windows\system32\DRIVERS\lsi_sas.sys [2009-07-14 89168]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 LSI_SCSI;LSI_SCSI; C:\Windows\system32\DRIVERS\lsi_scsi.sys [2009-07-14 96848]
S3 megasas;megasas; C:\Windows\system32\DRIVERS\megasas.sys [2009-07-14 30800]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mpio;mpio; C:\Windows\system32\DRIVERS\mpio.sys [2009-07-14 130624]
S3 msahci;msahci; C:\Windows\system32\DRIVERS\msahci.sys [2009-07-14 27712]
S3 msdsm;msdsm; C:\Windows\system32\DRIVERS\msdsm.sys [2009-07-14 115792]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MsRPC;MsRPC; C:\Windows\system32\drivers\MsRPC.sys [2009-07-14 162896]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NativeWifiP;NativeWiFi Filter; C:\Windows\system32\DRIVERS\nwifi.sys [2009-07-14 267264]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 nfrd960;nfrd960; C:\Windows\system32\DRIVERS\nfrd960.sys [2009-07-14 44624]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2009-10-06 17664]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2009-10-06 22016]
S3 nv_agp;NVIDIA nForce AGP Bus Filter; C:\Windows\system32\DRIVERS\nv_agp.sys [2009-07-14 105024]
S3 nvraid;nvraid; C:\Windows\system32\DRIVERS\nvraid.sys [2009-07-14 117312]
S3 nvstor;nvstor; C:\Windows\system32\DRIVERS\nvstor.sys [2009-07-14 142416]
S3 ohci1394;1394 OHCI Compliant Host Controller (Legacy); C:\Windows\system32\DRIVERS\ohci1394.sys [2009-07-14 62464]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 ql2300;ql2300; C:\Windows\system32\DRIVERS\ql2300.sys [2009-07-14 1383488]
S3 ql40xx;ql40xx; C:\Windows\system32\DRIVERS\ql40xx.sys [2009-07-14 106064]
S3 QWAVEdrv;@%SystemRoot%\system32\drivers\qwavedrv.sys,-1; C:\Windows\system32\drivers\qwavedrv.sys [2009-07-14 31744]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sbp2port;sbp2port; C:\Windows\system32\DRIVERS\sbp2port.sys [2009-07-14 85568]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 sermouse;Serial Mouse Driver; C:\Windows\system32\DRIVERS\sermouse.sys [2009-07-14 19968]
S3 sffdisk;SFF Storage Class Driver; C:\Windows\system32\DRIVERS\sffdisk.sys [2009-07-14 11264]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC; C:\Windows\system32\DRIVERS\sffp_mmc.sys [2009-07-14 12288]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\Windows\system32\DRIVERS\sffp_sd.sys [2009-07-14 12800]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SiSRaid2;SiSRaid2; C:\Windows\system32\DRIVERS\SiSRaid2.sys [2009-07-14 40016]
S3 SiSRaid4;SiSRaid4; C:\Windows\system32\DRIVERS\sisraid4.sys [2009-07-14 77888]
S3 Smb;@%SystemRoot%\system32\tcpipcfg.dll,-50005; C:\Windows\system32\DRIVERS\smb.sys [2009-07-14 71168]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 TCPIP6;Microsoft IPv6 Protocol Driver; C:\Windows\system32\DRIVERS\tcpip.sys [2009-07-14 1285712]
S3 tssecsrv;@%SystemRoot%\System32\DRIVERS\tssecsrv.sys,-101; C:\Windows\System32\DRIVERS\tssecsrv.sys [2009-07-14 30208]
S3 uagp35;Microsoft AGPv3.5 Filter; C:\Windows\system32\DRIVERS\uagp35.sys [2009-07-14 55888]
S3 uliagpkx;Uli AGP Bus Filter; C:\Windows\system32\DRIVERS\uliagpkx.sys [2009-07-14 57424]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-10-06 7936]
S3 usbcir;eHome Infrared Receiver (USBCIR); C:\Windows\system32\DRIVERS\usbcir.sys [2009-07-14 86016]
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\Windows\system32\DRIVERS\usbohci.sys [2009-07-14 20480]
S3 usbprint;Microsoft USB PRINTER Class; C:\Windows\system32\DRIVERS\usbprint.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-07-14 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-10-06 7936]
S3 vga;vga; C:\Windows\system32\DRIVERS\vgapnp.sys [2009-07-14 26112]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vsmraid;vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys [2009-07-14 141904]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WacomPen;Wacom Serial Pen HID Driver; C:\Windows\system32\DRIVERS\wacompen.sys [2009-07-14 21632]
S3 Wd;Wd; C:\Windows\system32\DRIVERS\wd.sys [2009-07-14 19024]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2009-09-11 35592]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2009-09-11 14984]
S4 crcdisk;Crcdisk Filter Driver; C:\Windows\system32\DRIVERS\crcdisk.sys [2009-07-14 22096]
S4 ws2ifsl;@%systemroot%\System32\drivers\ws2ifsl.sys,-1000; C:\Windows\system32\drivers\ws2ifsl.sys [2009-07-14 16384]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2009-06-05 90112]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 AudioEndpointBuilder;@%SystemRoot%\system32\audiosrv.dll,-204; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 AVerRemote;AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [2009-04-09 344064]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [2008-12-10 405504]
R2 BFE;@%SystemRoot%\system32\bfe.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-01-27 723632]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DPS;@%systemroot%\system32\dps.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 FDResPub;@%systemroot%\system32\fdrespub.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 gpsvc;@gpapi.dll,-112; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 iphlpsvc;@%SystemRoot%\system32\iphlpsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 MMCSS;@%systemroot%\system32\mmcss.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 MpsSvc;@%SystemRoot%\system32\FirewallAPI.dll,-23090; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
R2 NlaSvc;@%SystemRoot%\System32\nlasvc.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nsi;@%SystemRoot%\system32\nsisvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-11-20 122984]
R2 O&O Defrag;O&O Defrag; C:\Program Files\OO Software\Defrag\oodag.exe [2009-09-12 1488128]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ProfSvc;@%systemroot%\system32\profsvc.dll,-300; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2007-05-14 272024]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
R2 SysMain;@%SystemRoot%\system32\sysmain.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 UxSms;@%SystemRoot%\system32\dwm.exe,-2000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WinDefend;@%ProgramFiles%\Windows Defender\MsMpRes.dll,-103; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 WMPNetworkSvc;@%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101; C:\Program Files\Windows Media Player\wmpnetwk.exe [2009-07-14 1121280]
R2 WSearch;@%systemroot%\system32\SearchIndexer.exe,-103; C:\Windows\system32\SearchIndexer.exe [2009-07-14 428032]
R2 wudfsvc;@%SystemRoot%\system32\wudfsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 AeLookupSvc;@%SystemRoot%\system32\aelupsvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
R3 netprofm;@%SystemRoot%\system32\netprofm.dll,-202; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 PcaSvc;@%SystemRoot%\system32\pcasvc.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
R3 SstpSvc;@%SystemRoot%\system32\sstpsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 WdiServiceHost;@%systemroot%\system32\wdi.dll,-502; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WerSvc;@%SystemRoot%\System32\wersvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 WinHttpAutoProxySvc;@%SystemRoot%\system32\winhttp.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 WPDBusEnum;@%SystemRoot%\system32\wpdbusenum.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Appinfo;@%systemroot%\system32\appinfo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 CertPropSvc;@%SystemRoot%\System32\certprop.dll,-11; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 clr_optimization_v2.0.50727_32;Microsoft .NET Framework NGEN v2.0.50727_X86; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2009-06-10 66384]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 ehRecvr;@%SystemRoot%\ehome\ehrecvr.exe,-101; C:\Windows\ehome\ehRecvr.exe [2009-07-14 557056]
S3 ehSched;@%SystemRoot%\ehome\ehsched.exe,-101; C:\Windows\ehome\ehsched.exe [2009-07-14 94720]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 fdPHost;@%systemroot%\system32\fdPHost.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-01-25 655624]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2009-06-10 42856]
S3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 idsvc;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2009-06-10 878416]
S3 IKEEXT;@%SystemRoot%\system32\ikeext.dll,-501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 IPBusEnum;@%systemroot%\system32\IPBusEnum.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 KeyIso;@keyiso.dll,-100; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 KtmRm;@comres.dll,-2946; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 lltdsvc;@%SystemRoot%\system32\lltdres.dll,-1; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 MSiSCSI;@%SystemRoot%\system32\iscsidsc.dll,-5000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 p2pimsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8004; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 p2psvc;@%SystemRoot%\system32\p2psvc.dll,-8006; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 pla;@%systemroot%\system32\pla.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPAutoReg;@%SystemRoot%\system32\pnrpauto.dll,-8002; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 PNRPsvc;@%SystemRoot%\system32\pnrpsvc.dll,-8000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 QWAVE;@%SystemRoot%\system32\qwave.dll,-1; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SCPolicySvc;@%SystemRoot%\System32\certprop.dll,-13; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SDRSVC;@%SystemRoot%\system32\sdrsvc.dll,-107; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 SessionEnv;@%SystemRoot%\System32\SessEnv.dll,-1026; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SNMPTRAP;@%SystemRoot%\system32\snmptrap.exe,-3; C:\Windows\System32\snmptrap.exe [2009-07-14 12800]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TabletInputService;@%SystemRoot%\system32\TabSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TBS;@%SystemRoot%\system32\tbssvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 THREADORDER;@%systemroot%\system32\mmcss.dll,-102; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 TrustedInstaller;@%SystemRoot%\servicing\TrustedInstaller.exe,-100; C:\Windows\servicing\TrustedInstaller.exe [2009-07-14 204800]
S3 UI0Detect;@%SystemRoot%\system32\ui0detect.exe,-101; C:\Windows\system32\UI0Detect.exe [2009-07-14 35840]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 vds;@%SystemRoot%\system32\vds.exe,-100; C:\Windows\System32\vds.exe [2009-07-14 452608]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wcncsvc;@%SystemRoot%\system32\wcncsvc.dll,-3; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WcsPlugInService;@%SystemRoot%\system32\WcsPlugInService.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WdiSystemHost;@%systemroot%\system32\wdi.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Wecsvc;@%SystemRoot%\system32\wecsvc.dll,-200; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 wercplsupport;@%SystemRoot%\System32\wercplsupport.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WinRM;@%Systemroot%\system32\wsmsvc.dll,-101; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Wlansvc;@%SystemRoot%\System32\wlansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WPCSvc;@%SystemRoot%\system32\wpcsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 Mcx2Svc;@%SystemRoot%\ehome\ehres.dll,-15501; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S4 NetTcpPortSharing;@%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2009-06-10 128848]

-----------------EOF-----------------

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o prev. kontrolu

#2 Příspěvek od Unlimited_Killer »

Na logu se pracuje. :welcome:
inactive

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o prev. kontrolu

#3 Příspěvek od Unlimited_Killer »

Jdeme na to.

~~~

Stáhněte OTM na Plochu. Spusťte ho dvojklikem na OTM.exe, pokud máte Vistu, pravým tlačítkem na soubor -> Run as Administrator [spustit jako administrátor].
Do levého okna 'Paste Instructions for Items to be Moved' vkopírujte následující skript:

Kód: Vybrat vše

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"=-
"SunJavaUpdateSched"=-
"Adobe Reader Speed Launcher"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""=-

:files
C:\Program Files\DAEMON Tools Toolbar

:commands
[emptytemp]
[reboot]
Poté klikněte na červené tlačítko 'MoveIt!'.
V zeleném okně vpravo by se měl zobrazit log, ten vkopírujete sem do fóra. Pokud se zobrazí hláška k restartování, klikněte na Yes. Po restartu log najdete v C:\_OTM\MovedFiles

~~~

Spusťte přejmenované HiJackThis - C:\Program Files\Trend Micro\HijackThis\jmeno_usera.exe
Klikněte na 'Do a system scan only'.
U níže uvedených položek udělejte fajfku do čtverečku a poté klikněte na 'Fix Checked'.
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: HopSurf - {ED98F8D1-09AC-4107-B2FF-91DBE011B0C5} - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
Pokud by tam nějaká položka nebyla, vynechte ji.

~~~

Vložte sem log z ComboFix.

Stáhněte a uložte na Plochu ComboFix, poté ho spusťte s administrátorským oprávněním.
Ještě před spuštěním vypněte rezidentní štít antiviru, či antispywaru.
Po spuštění se Vám zobrazí licenční podmínky, klikněte na 'Ano'. Budete také dotázán na instalaci konzole pro zotavení, klikněte na 'Ano'.
Celý sken bude trvat tak 5-10 minut, v závislosti na tom, kolika soubory se bude CF prodírat. Váš PC bude pravděpodobně restartován, tak se toho neděste. Než úplně skončí sken, nic nedělejte, hlavně neklikejte do spuštěného okna s ComboFixem.
Po skončení skenu na Vás vypadne log, který vkopírujete sem.
inactive

jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Re: Prosím o prev. kontrolu

#4 Příspěvek od jindra5 »

Tady je log z OTM a jdu na další... :wink:
All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RemoteControl deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
========== FILES ==========
C:\Program Files\DAEMON Tools Toolbar\Resources folder moved successfully.
C:\Program Files\DAEMON Tools Toolbar folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Takitos
->Temp folder emptied: 3033330 bytes
->Temporary Internet Files folder emptied: 82077765 bytes
->Java cache emptied: 49679523 bytes
->FireFox cache emptied: 41141180 bytes

User: user

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 557056 bytes
%systemroot%\System32 .tmp files removed: 1619120 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 88798 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 170,00 mb


OTM by OldTimer - Version 3.1.7.0 log created on 01282010_205435

Files moved on Reboot...
File C:\Windows\temp\_avast4_\Webshlock.txt not found!

Registry entries deleted on Reboot...

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o prev. kontrolu

#5 Příspěvek od Unlimited_Killer »

0K, jinak máte novou SZ ;)
inactive

jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Re: Prosím o prev. kontrolu

#6 Příspěvek od jindra5 »

V HJT jsem vše fixnul

log z combofix
ComboFix 10-01-27.06 - Takitos 28.01.2010 21:06:48.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3327.2317 [GMT 1:00]
Spuštěný z: c:\users\Takitos\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AVerQuick.lnk
c:\users\Takitos\AppData\Roaming\inst.exe
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\pthreadVC.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-28 do 2010-01-28 )))))))))))))))))))))))))))))))
.

2010-01-28 20:14 . 2010-01-28 20:14 -------- d-----w- c:\users\Takitos\AppData\Local\temp
2010-01-28 20:14 . 2010-01-28 20:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-28 19:54 . 2010-01-28 19:54 -------- d-----w- C:\_OTM
2010-01-28 13:09 . 2010-01-28 20:01 -------- d-----w- c:\program files\trend micro
2010-01-28 13:09 . 2010-01-28 13:11 -------- d-----w- C:\rsit
2010-01-27 19:13 . 2010-01-28 01:34 -------- d-----w- c:\users\Takitos\AppData\Roaming\Comodo
2010-01-27 19:09 . 2010-01-28 01:34 -------- d-----w- c:\programdata\Comodo
2010-01-27 19:09 . 2010-01-27 19:09 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-01-27 19:09 . 2010-01-27 19:09 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-01-27 19:09 . 2010-01-27 19:09 171552 ----a-w- c:\windows\system32\guard32.dll
2010-01-27 19:09 . 2010-01-27 19:09 128376 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-01-27 19:09 . 2010-01-28 01:34 -------- d-----w- c:\program files\COMODO
2010-01-27 18:16 . 2010-01-27 18:16 -------- d-----w- c:\users\Takitos\AppData\Roaming\Malwarebytes
2010-01-27 18:16 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-27 18:16 . 2010-01-27 18:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 18:16 . 2010-01-27 18:16 -------- d-----w- c:\programdata\Malwarebytes
2010-01-27 18:16 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-27 11:52 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-01-27 11:52 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-01-25 15:42 . 2010-01-25 15:42 -------- d-----w- c:\programdata\FLEXnet
2010-01-25 15:38 . 2010-01-25 15:38 -------- d-----w- c:\program files\Adobe Media Player
2010-01-25 15:37 . 2010-01-25 15:37 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-25 15:35 . 2010-01-25 15:35 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-01-23 13:02 . 2010-01-27 12:15 -------- d-----w- c:\program files\Mass Effect 2
2010-01-22 22:18 . 2010-01-23 13:11 -------- d-----w- c:\program files\Common Files\BioWare
2010-01-22 21:49 . 2009-12-19 09:02 977920 ----a-w- c:\windows\system32\wininet.dll
2010-01-19 23:21 . 2010-01-19 23:21 -------- d-----w- c:\windows\Sun
2010-01-19 14:18 . 2010-01-19 14:18 -------- d-----w- c:\program files\AGEIA Technologies
2010-01-19 11:48 . 2010-01-19 11:48 -------- d-----w- c:\program files\Mindware Studios
2010-01-19 02:54 . 2010-01-19 02:54 -------- d-----w- c:\windows\system32\oodag
2010-01-19 02:53 . 2010-01-19 02:53 -------- d-----w- c:\users\Takitos\AppData\Local\O&O
2010-01-19 02:52 . 2010-01-19 02:52 -------- d-----w- c:\program files\OO Software
2010-01-18 17:19 . 2010-01-18 17:19 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-18 17:19 . 2010-01-28 15:06 -------- d-----w- c:\users\Takitos\AppData\Roaming\skypePM
2010-01-18 17:17 . 2010-01-28 20:03 -------- d-----w- c:\users\Takitos\AppData\Roaming\Skype
2010-01-18 17:17 . 2010-01-18 17:17 -------- d-----w- c:\program files\Common Files\Skype
2010-01-18 17:17 . 2010-01-18 17:17 -------- d-----r- c:\program files\Skype
2010-01-18 17:17 . 2010-01-18 17:17 -------- d-----w- c:\programdata\Skype
2010-01-17 00:19 . 2009-10-19 14:10 108544 ----a-w- c:\windows\system32\t2embed.dll
2010-01-17 00:19 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-01-15 21:27 . 2010-01-15 21:27 -------- d-----w- c:\programdata\Solidshield
2010-01-12 00:10 . 2010-01-12 00:10 -------- d-----w- c:\program files\Electronic Arts
2010-01-07 11:22 . 2010-01-07 11:22 -------- d-----w- c:\programdata\Codemasters
2010-01-05 20:26 . 2009-11-21 02:34 76392 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-05 20:26 . 2009-11-21 02:34 11515752 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-05 20:26 . 2009-11-21 02:34 4147816 ----a-w- c:\windows\system32\nvencodemft.dll
2010-01-05 20:26 . 2009-11-21 02:34 4001384 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-05 20:26 . 2009-11-21 02:34 289384 ----a-w- c:\windows\system32\nvdecodemft.dll
2010-01-05 20:26 . 2009-11-21 02:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-05 20:26 . 2009-11-21 02:34 1989224 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-05 20:26 . 2009-11-21 02:34 14064232 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-05 20:26 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod178.dll
2010-01-05 20:26 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod.dll
2010-01-05 20:26 . 2009-11-21 02:34 11381352 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-05 19:54 . 2008-07-12 07:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-01-05 19:54 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-01-05 19:54 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2009-12-30 15:52 . 2009-12-30 15:52 -------- d-----w- c:\program files\GSC World Publishing

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 20:05 . 2009-10-19 22:55 -------- d-----w- c:\programdata\NVIDIA
2010-01-28 20:04 . 2009-10-20 07:46 -------- d-----w- c:\users\Takitos\AppData\Roaming\DMCache
2010-01-28 11:42 . 2009-10-19 23:40 -------- d-----w- c:\program files\SpeedFan
2010-01-27 22:35 . 2009-11-14 18:59 -------- d-----w- c:\program files\Share Rapid Uploader
2010-01-26 18:03 . 2009-07-14 08:44 625676 ----a-w- c:\windows\system32\perfh005.dat
2010-01-26 18:03 . 2009-07-14 08:44 119794 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 15:41 . 2009-10-19 23:55 112000 ----a-w- c:\users\Takitos\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-25 15:39 . 2009-10-20 09:16 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-22 22:29 . 2009-10-19 22:54 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-19 19:41 . 2009-11-01 11:55 -------- d-----w- c:\program files\ICQ6.5
2010-01-19 19:05 . 2009-10-27 21:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-19 14:18 . 2009-10-19 22:55 -------- d-----w- c:\program files\NVIDIA Corporation
2010-01-18 20:47 . 2009-11-01 11:55 -------- d-----w- c:\users\Takitos\AppData\Roaming\ICQ
2010-01-15 21:21 . 2009-11-15 21:20 -------- d-----w- c:\program files\Ubisoft
2010-01-15 21:21 . 2009-10-20 10:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-14 10:12 . 2009-10-19 23:18 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-11 23:41 . 2009-12-19 22:36 -------- d-----w- c:\program files\F.E.A.R. 2
2010-01-10 22:20 . 2009-11-15 12:07 -------- d-----w- c:\program files\Common Files\Logitech
2010-01-07 11:15 . 2010-01-07 11:15 -------- d-----w- c:\program files\BRS
2010-01-07 11:15 . 2010-01-07 11:15 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-01-07 11:15 . 2009-10-26 13:17 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2010-01-07 11:15 . 2009-10-26 13:17 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-07 11:15 . 2009-10-26 13:17 -------- d-----w- c:\program files\OpenAL
2010-01-07 11:03 . 2009-10-20 16:04 -------- d-----w- c:\program files\Codemasters
2010-01-07 00:44 . 2009-10-20 07:46 -------- d-----w- c:\program files\Internet Download Manager
2010-01-05 21:06 . 2009-12-22 23:08 -------- d-----w- c:\programdata\AVerTV
2010-01-03 01:49 . 2009-10-21 13:03 -------- d-----w- c:\program files\Activision
2010-01-03 01:48 . 2009-10-22 17:41 -------- d-----w- c:\program files\GRETECH
2010-01-03 01:48 . 2009-10-22 17:43 -------- d-----w- c:\users\Takitos\AppData\Roaming\GRETECH
2009-12-29 14:25 . 2009-12-29 14:25 1143056 ----a-w- c:\programdata\Comodo\AVScanner\DB\mach32.dll
2009-12-23 21:24 . 2009-12-22 23:01 -------- d-----w- c:\programdata\SonicFocus
2009-12-23 21:24 . 2009-12-22 23:01 -------- d-----w- c:\program files\Analog Devices
2009-12-22 23:08 . 2009-12-22 23:08 -------- d-----w- c:\programdata\AVerMedia
2009-12-22 23:08 . 2009-12-22 23:07 -------- d-----w- c:\program files\AVerMedia
2009-12-22 23:07 . 2009-12-22 23:07 -------- d-----w- c:\program files\Common Files\AVerMedia
2009-12-22 23:02 . 2009-12-22 23:02 -------- d-----w- c:\program files\Creative
2009-12-22 23:01 . 2009-12-22 23:01 -------- d-----w- c:\users\Takitos\AppData\Roaming\InstallShield
2009-12-22 22:56 . 2009-12-22 22:56 -------- d-----w- c:\program files\Intel
2009-12-22 13:52 . 2009-10-20 07:46 -------- d-----w- c:\users\Takitos\AppData\Roaming\IDM
2009-12-22 13:52 . 2009-10-19 23:47 -------- d-----w- c:\program files\Nokia
2009-12-22 13:46 . 2009-10-22 22:00 -------- d-----w- c:\users\Takitos\AppData\Roaming\Nokia Ovi Suite
2009-12-19 12:47 . 2009-10-19 23:48 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-19 00:08 . 2009-10-19 23:47 -------- d-----w- c:\programdata\OviInstallerCache
2009-12-19 00:07 . 2009-12-19 00:07 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-19 00:06 . 2009-12-19 00:06 77824 ----a-w- c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\Run_XML6_SP1.exe
2009-12-19 00:06 . 2009-12-19 00:06 50000 ----a-w- c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\pcswpc.exe
2009-12-17 19:57 . 2009-10-20 14:24 -------- d-----w- c:\users\Takitos\AppData\Roaming\Any Video Converter Professional
2009-12-17 15:16 . 2009-12-19 00:06 61789728 ----a-w- c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\NokiaOviSuite2Installer.exe
2009-12-17 15:16 . 2009-12-17 15:16 61789728 ----a-w- c:\users\Takitos\AppData\Roaming\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
2009-12-11 11:44 . 2009-12-11 11:39 -------- d-----w- c:\program files\DVDConverterPortable
2009-12-08 14:50 . 2009-10-25 00:47 -------- d-----w- c:\users\Takitos\AppData\Roaming\Vso
2009-12-06 10:14 . 2009-10-21 19:40 -------- d-----w- c:\program files\Java
2009-11-25 09:25 . 2009-11-25 09:25 295184 ----a-w- c:\programdata\Comodo\AVScanner\DB\pkann.dll
2009-11-24 23:54 . 2009-10-19 22:58 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2009-10-19 22:58 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-10-19 22:58 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-10-19 22:58 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2009-10-19 22:58 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-10-19 22:58 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-10-19 22:58 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-21 02:34 . 2009-09-27 14:12 592488 ----a-w- c:\windows\system32\nvudisp.exe
2009-11-21 02:34 . 2009-09-27 14:12 1249896 ----a-w- c:\windows\system32\nvapi.dll
2009-11-21 02:34 . 2009-07-13 22:09 4241000 ----a-w- c:\windows\system32\nvwgf2um.dll
2009-11-21 02:34 . 2009-06-10 21:19 9333352 ----a-w- c:\windows\system32\nvd3dum.dll
2009-11-20 19:33 . 2009-11-20 19:33 812648 ----a-w- c:\windows\system32\nvsvc.dll
2009-11-20 19:33 . 2009-11-20 19:33 1323624 ----a-w- c:\windows\system32\nvsvcr.dll
2009-11-20 19:33 . 2009-11-20 19:33 12685928 ----a-w- c:\windows\system32\nvcpl.dll
2009-11-20 19:33 . 2009-11-20 19:33 122984 ----a-w- c:\windows\system32\nvvsvc.exe
2009-11-20 19:33 . 2009-11-20 19:33 110184 ----a-w- c:\windows\system32\nvmctray.dll
2009-11-19 20:42 . 2009-10-19 22:54 592488 ----a-w- c:\windows\system32\nvuninst.exe
2009-11-15 11:12 . 2009-11-03 22:48 53319 ----a-w- c:\programdata\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-11-14 19:23 . 2009-11-14 19:23 108336 ----a-w- c:\windows\system32\MSWINSCK.EXE
2009-11-06 09:59 . 2009-11-06 09:59 15406728 ----a-w- c:\windows\system32\xlive.dll
2009-11-06 09:59 . 2009-11-06 09:59 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-11-03 22:50 . 2009-11-03 22:50 53319 ----a-w- c:\programdata\TEMP\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exe
2009-11-02 17:05 . 2009-11-02 17:05 167064 ----a-w- c:\windows\system32\xliveinstall.dll
2009-11-02 17:05 . 2009-11-02 17:05 71832 ----a-w- c:\windows\system32\xliveinstallhost.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-10-20 2794928]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2009-12-10 401728]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-08-20 2363392]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"avast!"="c:\program files\Alwil Software\Avast4\ashDisp.exe" [2009-11-24 81000]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-05 1310720]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2009-09-11 2524416]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-01-27 1800464]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AVer HID Receiver.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2009-12-23 159744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [19.10.2009 23:58 114768]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [27.1.2010 20:09 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [27.1.2010 20:09 29520]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [19.10.2009 23:58 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [19.10.2009 23:58 53328]
R2 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [23.12.2009 0:07 344064]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [20.11.2009 19:17 240232]
R3 AVerA706;AVerMedia A706 BDA Service;c:\windows\System32\drivers\AVerA706.sys [21.12.2009 18:12 1169920]
R3 yukonw7;Ovladač NDIS6.2 Miniport pro řadič Marvell Yukon Ethernet Controller;c:\windows\System32\drivers\yk62x86.sys [13.7.2009 23:02 311296]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [20.10.2009 10:30 721904]
S2 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [23.12.2009 0:07 405504]
S3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\System32\drivers\AVerBDA3x.sys [22.12.2009 11:58 1180672]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 12:24 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files\Internet Download Manager\IEGetAll.htm
TCP: {3702C02A-DDF5-4073-8DF6-99FB6A8407A7} = 78.156.32.2,84.244.102.11
DPF: {E62A8B6B-D91C-457C-B1FB-20CC2D96B4EC} - hxxp://eu2.download.comodo.com/avs/ComodoAVScanner.cab
FF - ProfilePath - c:\users\Takitos\AppData\Roaming\Mozilla\Firefox\Profiles\sqyty4mp.default\
FF - component: c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: c:\users\Takitos\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



[HKEY_LOCAL_MACHINE\system\ControlSet001\services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-531632240-3606155352-1123787172-1000_Classes\CLSID\{60875b64-f27f-4c19-ba48-4366650e09be}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:0000016a
"Therad"=dword:0000000f
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

[HKEY_USERS\S-1-5-21-531632240-3606155352-1123787172-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):1c,ad,17,75,c9,4e,53,03,9e,ab,eb,f0,35,95,36,43,68,cb,77,9b,53,
48,9c,24,cc,41,bb,a2,08,83,af,1b,8d,c1,9b,70,0e,1c,a8,0b,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(592)
c:\windows\system32\guard32.dll

- - - - - - - > 'lsass.exe'(520)
c:\windows\system32\guard32.dll
.
Celkový čas: 2010-01-28 21:16:30
ComboFix-quarantined-files.txt 2010-01-28 20:16

Před spuštěním: Volných bajtů: 89 289 302 016
Po spuštění: Volných bajtů: 94 010 638 336

- - End Of File - - 1E2DC4431A01F8BE5A7B34C418D77F59

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o prev. kontrolu

#7 Příspěvek od Unlimited_Killer »

Ještě něco. :)

~~~

Otevřete si Poznámkový blok a vkopírujte do něj

Kód: Vybrat vše

KillAll::

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

RegLockDel::
[HKEY_USERS\S-1-5-21-531632240-3606155352-1123787172-1000_Classes\CLSID\{60875b64-f27f-4c19-ba48-4366650e09be}]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

Reboot::
uložte to na Plochu jako CFScript.txt Pak jej myší přetáhněte nad ComboFix (musí být na Ploše) a pusťte (vizte obrázek).

Obrázek

ComboFix vykoná příkazy ze skriptu, PC může být opět restartován.
Po skončení mi sem vložte log, který na Vás po dočistění vybafne.

~~~

Stáhněte MbAM a postupujte podle popisu. Zatím nic nemažte, MbAM má občas falešné detekce.
Potom mi sem vložte log.
inactive

jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Re: Prosím o prev. kontrolu

#8 Příspěvek od jindra5 »

Tak tady je po menších problémech log z combofix a z mbam za chvilku...
ComboFix 10-01-27.06 - Takitos 28.01.2010 21:41:50.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3327.2352 [GMT 1:00]
Spuštěný z: c:\users\Takitos\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Takitos\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Soubory vytvořené od 2009-12-28 do 2010-01-28 )))))))))))))))))))))))))))))))
.

2010-01-28 20:49 . 2010-01-28 20:51 -------- d-----w- c:\users\Takitos\AppData\Local\temp
2010-01-28 20:49 . 2010-01-28 20:49 -------- d-----w- c:\users\user\AppData\Local\temp
2010-01-28 20:49 . 2010-01-28 20:49 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-28 20:49 . 2010-01-28 20:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-28 19:54 . 2010-01-28 19:54 -------- d-----w- C:\_OTM
2010-01-28 13:09 . 2010-01-28 20:01 -------- d-----w- c:\program files\trend micro
2010-01-28 13:09 . 2010-01-28 13:11 -------- d-----w- C:\rsit
2010-01-27 19:13 . 2010-01-28 01:34 -------- d-----w- c:\users\Takitos\AppData\Roaming\Comodo
2010-01-27 19:09 . 2010-01-28 01:34 -------- d-----w- c:\programdata\Comodo
2010-01-27 19:09 . 2010-01-27 19:09 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-01-27 19:09 . 2010-01-27 19:09 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-01-27 19:09 . 2010-01-27 19:09 171552 ----a-w- c:\windows\system32\guard32.dll
2010-01-27 19:09 . 2010-01-27 19:09 128376 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-01-27 19:09 . 2010-01-28 01:34 -------- d-----w- c:\program files\COMODO
2010-01-27 18:16 . 2010-01-27 18:16 -------- d-----w- c:\users\Takitos\AppData\Roaming\Malwarebytes
2010-01-27 18:16 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-27 18:16 . 2010-01-27 18:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 18:16 . 2010-01-27 18:16 -------- d-----w- c:\programdata\Malwarebytes
2010-01-27 18:16 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-27 11:52 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-01-27 11:52 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-01-25 15:42 . 2010-01-25 15:42 -------- d-----w- c:\programdata\FLEXnet
2010-01-25 15:38 . 2010-01-25 15:38 -------- d-----w- c:\program files\Adobe Media Player
2010-01-25 15:37 . 2010-01-25 15:37 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-25 15:35 . 2010-01-25 15:35 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-01-23 13:02 . 2010-01-27 12:15 -------- d-----w- c:\program files\Mass Effect 2
2010-01-22 22:18 . 2010-01-23 13:11 -------- d-----w- c:\program files\Common Files\BioWare
2010-01-22 21:49 . 2009-12-19 09:02 977920 ----a-w- c:\windows\system32\wininet.dll
2010-01-19 23:21 . 2010-01-19 23:21 -------- d-----w- c:\windows\Sun
2010-01-19 14:18 . 2010-01-19 14:18 -------- d-----w- c:\program files\AGEIA Technologies
2010-01-19 11:48 . 2010-01-19 11:48 -------- d-----w- c:\program files\Mindware Studios
2010-01-19 02:54 . 2010-01-19 02:54 -------- d-----w- c:\windows\system32\oodag
2010-01-19 02:53 . 2010-01-19 02:53 -------- d-----w- c:\users\Takitos\AppData\Local\O&O
2010-01-19 02:52 . 2010-01-19 02:52 -------- d-----w- c:\program files\OO Software
2010-01-18 17:19 . 2010-01-18 17:19 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-18 17:19 . 2010-01-28 15:06 -------- d-----w- c:\users\Takitos\AppData\Roaming\skypePM
2010-01-18 17:17 . 2010-01-28 20:51 -------- d-----w- c:\users\Takitos\AppData\Roaming\Skype
2010-01-18 17:17 . 2010-01-18 17:17 -------- d-----w- c:\program files\Common Files\Skype
2010-01-18 17:17 . 2010-01-18 17:17 -------- d-----r- c:\program files\Skype
2010-01-18 17:17 . 2010-01-18 17:17 -------- d-----w- c:\programdata\Skype
2010-01-17 00:19 . 2009-10-19 14:10 108544 ----a-w- c:\windows\system32\t2embed.dll
2010-01-17 00:19 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-01-15 21:27 . 2010-01-15 21:27 -------- d-----w- c:\programdata\Solidshield
2010-01-12 00:10 . 2010-01-12 00:10 -------- d-----w- c:\program files\Electronic Arts
2010-01-07 11:22 . 2010-01-07 11:22 -------- d-----w- c:\programdata\Codemasters
2010-01-05 20:26 . 2009-11-21 02:34 76392 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-05 20:26 . 2009-11-21 02:34 11515752 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-01-05 20:26 . 2009-11-21 02:34 4147816 ----a-w- c:\windows\system32\nvencodemft.dll
2010-01-05 20:26 . 2009-11-21 02:34 4001384 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-05 20:26 . 2009-11-21 02:34 289384 ----a-w- c:\windows\system32\nvdecodemft.dll
2010-01-05 20:26 . 2009-11-21 02:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-05 20:26 . 2009-11-21 02:34 1989224 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-05 20:26 . 2009-11-21 02:34 14064232 ----a-w- c:\windows\system32\nvoglv32.dll
2010-01-05 20:26 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod178.dll
2010-01-05 20:26 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod.dll
2010-01-05 20:26 . 2009-11-21 02:34 11381352 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-05 19:54 . 2008-07-12 07:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-01-05 19:54 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-01-05 19:54 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2009-12-30 15:52 . 2009-12-30 15:52 -------- d-----w- c:\program files\GSC World Publishing

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 20:51 . 2009-10-20 07:46 -------- d-----w- c:\users\Takitos\AppData\Roaming\DMCache
2010-01-28 20:50 . 2009-10-19 22:55 -------- d-----w- c:\programdata\NVIDIA
2010-01-28 11:42 . 2009-10-19 23:40 -------- d-----w- c:\program files\SpeedFan
2010-01-27 22:35 . 2009-11-14 18:59 -------- d-----w- c:\program files\Share Rapid Uploader
2010-01-26 18:03 . 2009-07-14 08:44 625676 ----a-w- c:\windows\system32\perfh005.dat
2010-01-26 18:03 . 2009-07-14 08:44 119794 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 15:41 . 2009-10-19 23:55 112000 ----a-w- c:\users\Takitos\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-25 15:39 . 2009-10-20 09:16 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-22 22:29 . 2009-10-19 22:54 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-19 19:41 . 2009-11-01 11:55 -------- d-----w- c:\program files\ICQ6.5
2010-01-19 19:05 . 2009-10-27 21:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-19 14:18 . 2009-10-19 22:55 -------- d-----w- c:\program files\NVIDIA Corporation
2010-01-18 20:47 . 2009-11-01 11:55 -------- d-----w- c:\users\Takitos\AppData\Roaming\ICQ
2010-01-15 21:21 . 2009-11-15 21:20 -------- d-----w- c:\program files\Ubisoft
2010-01-15 21:21 . 2009-10-20 10:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-14 10:12 . 2009-10-19 23:18 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-11 23:41 . 2009-12-19 22:36 -------- d-----w- c:\program files\F.E.A.R. 2
2010-01-10 22:20 . 2009-11-15 12:07 -------- d-----w- c:\program files\Common Files\Logitech
2010-01-07 11:15 . 2010-01-07 11:15 -------- d-----w- c:\program files\BRS
2010-01-07 11:15 . 2010-01-07 11:15 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-01-07 11:15 . 2009-10-26 13:17 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2010-01-07 11:15 . 2009-10-26 13:17 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-07 11:15 . 2009-10-26 13:17 -------- d-----w- c:\program files\OpenAL
2010-01-07 11:03 . 2009-10-20 16:04 -------- d-----w- c:\program files\Codemasters
2010-01-07 00:44 . 2009-10-20 07:46 -------- d-----w- c:\program files\Internet Download Manager
2010-01-05 21:06 . 2009-12-22 23:08 -------- d-----w- c:\programdata\AVerTV
2010-01-03 01:49 . 2009-10-21 13:03 -------- d-----w- c:\program files\Activision
2010-01-03 01:48 . 2009-10-22 17:41 -------- d-----w- c:\program files\GRETECH
2010-01-03 01:48 . 2009-10-22 17:43 -------- d-----w- c:\users\Takitos\AppData\Roaming\GRETECH
2009-12-29 14:25 . 2009-12-29 14:25 1143056 ----a-w- c:\programdata\Comodo\AVScanner\DB\mach32.dll
2009-12-23 21:24 . 2009-12-22 23:01 -------- d-----w- c:\programdata\SonicFocus
2009-12-23 21:24 . 2009-12-22 23:01 -------- d-----w- c:\program files\Analog Devices
2009-12-22 23:08 . 2009-12-22 23:08 -------- d-----w- c:\programdata\AVerMedia
2009-12-22 23:08 . 2009-12-22 23:07 -------- d-----w- c:\program files\AVerMedia
2009-12-22 23:07 . 2009-12-22 23:07 -------- d-----w- c:\program files\Common Files\AVerMedia
2009-12-22 23:02 . 2009-12-22 23:02 -------- d-----w- c:\program files\Creative
2009-12-22 23:01 . 2009-12-22 23:01 -------- d-----w- c:\users\Takitos\AppData\Roaming\InstallShield
2009-12-22 22:56 . 2009-12-22 22:56 -------- d-----w- c:\program files\Intel
2009-12-22 13:52 . 2009-10-20 07:46 -------- d-----w- c:\users\Takitos\AppData\Roaming\IDM
2009-12-22 13:52 . 2009-10-19 23:47 -------- d-----w- c:\program files\Nokia
2009-12-22 13:46 . 2009-10-22 22:00 -------- d-----w- c:\users\Takitos\AppData\Roaming\Nokia Ovi Suite
2009-12-19 12:47 . 2009-10-19 23:48 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-19 00:08 . 2009-10-19 23:47 -------- d-----w- c:\programdata\OviInstallerCache
2009-12-19 00:07 . 2009-12-19 00:07 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-19 00:06 . 2009-12-19 00:06 77824 ----a-w- c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\Run_XML6_SP1.exe
2009-12-19 00:06 . 2009-12-19 00:06 50000 ----a-w- c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\pcswpc.exe
2009-12-17 19:57 . 2009-10-20 14:24 -------- d-----w- c:\users\Takitos\AppData\Roaming\Any Video Converter Professional
2009-12-17 15:16 . 2009-12-19 00:06 61789728 ----a-w- c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\NokiaOviSuite2Installer.exe
2009-12-17 15:16 . 2009-12-17 15:16 61789728 ----a-w- c:\users\Takitos\AppData\Roaming\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
2009-12-11 11:44 . 2009-12-11 11:39 -------- d-----w- c:\program files\DVDConverterPortable
2009-12-08 14:50 . 2009-10-25 00:47 -------- d-----w- c:\users\Takitos\AppData\Roaming\Vso
2009-12-06 10:14 . 2009-10-21 19:40 -------- d-----w- c:\program files\Java
2009-11-25 09:25 . 2009-11-25 09:25 295184 ----a-w- c:\programdata\Comodo\AVScanner\DB\pkann.dll
2009-11-24 23:54 . 2009-10-19 22:58 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2009-10-19 22:58 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-10-19 22:58 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-10-19 22:58 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2009-10-19 22:58 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-10-19 22:58 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-10-19 22:58 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-21 02:34 . 2009-09-27 14:12 592488 ----a-w- c:\windows\system32\nvudisp.exe
2009-11-21 02:34 . 2009-09-27 14:12 1249896 ----a-w- c:\windows\system32\nvapi.dll
2009-11-21 02:34 . 2009-07-13 22:09 4241000 ----a-w- c:\windows\system32\nvwgf2um.dll
2009-11-21 02:34 . 2009-06-10 21:19 9333352 ----a-w- c:\windows\system32\nvd3dum.dll
2009-11-20 19:33 . 2009-11-20 19:33 812648 ----a-w- c:\windows\system32\nvsvc.dll
2009-11-20 19:33 . 2009-11-20 19:33 1323624 ----a-w- c:\windows\system32\nvsvcr.dll
2009-11-20 19:33 . 2009-11-20 19:33 12685928 ----a-w- c:\windows\system32\nvcpl.dll
2009-11-20 19:33 . 2009-11-20 19:33 122984 ----a-w- c:\windows\system32\nvvsvc.exe
2009-11-20 19:33 . 2009-11-20 19:33 110184 ----a-w- c:\windows\system32\nvmctray.dll
2009-11-19 20:42 . 2009-10-19 22:54 592488 ----a-w- c:\windows\system32\nvuninst.exe
2009-11-15 11:12 . 2009-11-03 22:48 53319 ----a-w- c:\programdata\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-11-14 19:23 . 2009-11-14 19:23 108336 ----a-w- c:\windows\system32\MSWINSCK.EXE
2009-11-06 09:59 . 2009-11-06 09:59 15406728 ----a-w- c:\windows\system32\xlive.dll
2009-11-06 09:59 . 2009-11-06 09:59 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-11-03 22:50 . 2009-11-03 22:50 53319 ----a-w- c:\programdata\TEMP\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exe
2009-11-02 17:05 . 2009-11-02 17:05 167064 ----a-w- c:\windows\system32\xliveinstall.dll
2009-11-02 17:05 . 2009-11-02 17:05 71832 ----a-w- c:\windows\system32\xliveinstallhost.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-10-20 2794928]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2009-12-10 401728]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-08-20 2363392]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"avast!"="c:\program files\Alwil Software\Avast4\ashDisp.exe" [2009-11-24 81000]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-05 1310720]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2009-09-11 2524416]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-01-27 1800464]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AVer HID Receiver.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2009-12-23 159744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [19.10.2009 23:58 114768]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [27.1.2010 20:09 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [27.1.2010 20:09 29520]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [19.10.2009 23:58 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [19.10.2009 23:58 53328]
R2 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [23.12.2009 0:07 344064]
R2 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [23.12.2009 0:07 405504]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [20.11.2009 19:17 240232]
R3 AVerA706;AVerMedia A706 BDA Service;c:\windows\System32\drivers\AVerA706.sys [21.12.2009 18:12 1169920]
R3 yukonw7;Ovladač NDIS6.2 Miniport pro řadič Marvell Yukon Ethernet Controller;c:\windows\System32\drivers\yk62x86.sys [13.7.2009 23:02 311296]
S3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\System32\drivers\AVerBDA3x.sys [22.12.2009 11:58 1180672]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 12:24 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files\Internet Download Manager\IEGetAll.htm
TCP: {3702C02A-DDF5-4073-8DF6-99FB6A8407A7} = 78.156.32.2,84.244.102.11
DPF: {E62A8B6B-D91C-457C-B1FB-20CC2D96B4EC} - hxxp://eu2.download.comodo.com/avs/ComodoAVScanner.cab
FF - ProfilePath - c:\users\Takitos\AppData\Roaming\Mozilla\Firefox\Profiles\sqyty4mp.default\
FF - component: c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: c:\users\Takitos\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x859431F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xe5726854
SecurityProcedure -> 0x1
QueryNameProcedure -> 0x8ce05cf6
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-531632240-3606155352-1123787172-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):1c,ad,17,75,c9,4e,53,03,9e,ab,eb,f0,35,95,36,43,68,cb,77,9b,53,
48,9c,24,cc,41,bb,a2,08,83,af,1b,8d,c1,9b,70,0e,1c,a8,0b,00,00,00,00,00,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\AEADISRV.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\OO Software\Defrag\oodag.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\conhost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\program files\Common Files\Nokia\NoA\nokiaaserver.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2010-01-28 21:55:05 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-28 20:55
ComboFix2.txt 2010-01-28 20:16

Před spuštěním: Volných bajtů: 94 063 419 392
Po spuštění: Volných bajtů: 94 011 813 888

- - End Of File - - B5C2FC1ED7DA9A676A0A23381F06698E
Naposledy upravil(a) jindra5 dne 28 led 2010 22:17, celkem upraveno 1 x.

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o prev. kontrolu

#9 Příspěvek od Unlimited_Killer »

Omylem jste vložil OTM log. :)
inactive

jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Re: Prosím o prev. kontrolu

#10 Příspěvek od jindra5 »

jj :oops: opraveno

a z MBAM
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3646
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

28.1.2010 22:18:58
mbam-log-2010-01-28 (22-18-53).txt

Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 110045
Uplynulý čas: 3 minute(s), 11 second(s)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 1

Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)

Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)

Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)

Infikované soubory:
C:\Program Files\Internet Explorer\Patch 5.xx (2008-12-06).exe (Trojan.Agent) -> No action taken.

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o prev. kontrolu

#11 Příspěvek od Unlimited_Killer »

Ještě se ujistíme, zda není něco na MBR (ComboFixu se něco nezdá).

~~~

Odinstalujte všechny virtuální mechaniky (Daemon, Alcohol atp.)

~~~

Stáhněte SPTD
  • Vyberte verzi podle svého operačního systému. SPTD for Windows - 32 bit nebo 64b.
  • Uložte soubor na Plochu a spusťte.
  • Zvolte možnost Uninstall
  • Restartujte PC.
~~~

Stáhněte MBR.exe
Uložte tuto utilitu na Plochu.
Stiskněte Start -> Spustit [Win+R] -> zadejte / vkopírujte následující:

Kód: Vybrat vše

"%userprofile%\plocha\mbr" -t
a stiskněte Enter.
Na ploše se vytvoří textový soubor s názvem mbr.log, jehož obsah mi sem vkopírujete.

~~~

Stáhněte GMER a dvojklikem spusťte.
Několik sekund bude skenovat. Poté klikněte na 'Save' v pravém dolním rohu a uložte první log - ten vložte sem do fóra.
Poté vytvořte druhý log, přičemž se budete řídit tímto návodem. Tento log sem také vložte.
inactive

jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Re: Prosím o prev. kontrolu

#12 Příspěvek od jindra5 »

Když okopíruju to u MBR ak mi vyskočí toto
Obrázek

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o prev. kontrolu

#13 Příspěvek od Unlimited_Killer »

Zkuste MBR.exe dát na C: a do Spustit vkopírujete toto:

Kód: Vybrat vše

"C:\mbr" -t
inactive

jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Re: Prosím o prev. kontrolu

#14 Příspěvek od jindra5 »

log z MBR
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
kernel: MBR read successfully
user & kernel MBR OK

jindra5
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 28 led 2010 13:25

Re: Prosím o prev. kontrolu

#15 Příspěvek od jindra5 »

první log z GMER
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-01-28 22:39:20
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Takitos\AppData\Local\Temp\fxtdrfod.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

---- EOF - GMER 1.0.15 ----
log2 z GMER
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-28 22:45:59
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Takitos\AppData\Local\Temp\fxtdrfod.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0x83205F80]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAlpcConnectPort [0x83206F4E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAlpcCreatePort [0x83206166]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0x832053EC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0x83205BE6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0x832052CE]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0x83205A74]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0x83206C08]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0x83204E94]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThreadEx [0x83206272]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDuplicateObject [0x83204CC6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0x8320688A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0x83205670]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0x83205DC2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenProcess [0x832049F6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0x83205900]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenThread [0x83204B6E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0x832073B8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0x83206626]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0x83206A38]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0x8320560A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0x832057F4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateProcess [0x83205198]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0x83205066]

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C36AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C36104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C363F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C1E634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C1E898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C361DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C36958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C366F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C36F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82C371A8

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C96579 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CBAF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 220 82CC2720 4 Bytes [80, 5F, 20, 83] {SBB BYTE [EDI+0x20], 0x83}
.text ntkrnlpa.exe!RtlSidHashLookup + 248 82CC2748 8 Bytes [4E, 6F, 20, 83, 66, 61, 20, ...] {DEC ESI; OUTSD ; AND [EBX-0x7cdf9e9a], AL}
.text ntkrnlpa.exe!RtlSidHashLookup + 2DC 82CC27DC 4 Bytes [EC, 53, 20, 83]
.text ntkrnlpa.exe!RtlSidHashLookup + 2F8 82CC27F8 4 Bytes [E6, 5B, 20, 83]
.text ntkrnlpa.exe!RtlSidHashLookup + 324 82CC2824 4 Bytes [CE, 52, 20, 83]
.text ...
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0x98B76300, 0x3B6D8, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x98BB9300, 0x1BEE, 0xE8000020]
.text peauth.sys A221AC9D 28 Bytes [1E, A6, 81, 0B, 1D, 38, 9E, ...]
.text peauth.sys A221ACC1 28 Bytes [1E, A6, 81, 0B, 1D, 38, 9E, ...]
PAGE peauth.sys A2220E20 82 Bytes [26, 0F, C0, 76, 4C, 7F, 7A, ...]
PAGE peauth.sys A2220E73 18 Bytes [3B, A8, 95, 95, 7D, FD, 63, ...] {CMP EBP, [EAX-0x2826a6b]; ARPL [EBP+0x5f2c3007], BX; AAM 0x2d; INTO ; RET 0x38b6}
PAGE peauth.sys A222102C 102 Bytes [41, 7B, 22, 1D, AC, 02, 6F, ...]
? C:\Users\Takitos\AppData\Local\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[840] ntdll.dll!NtAllocateVirtualMemory 77764720 5 Bytes JMP 0040F940 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[2412] ntdll.dll!NtAllocateVirtualMemory 77764720 5 Bytes JMP 0050DF00 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!UnhookWindowsHookEx 774FCC7B 5 Bytes JMP 6BFD81D8 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!CallNextHookEx 774FCC8F 5 Bytes JMP 6BFB9A6C C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!CreateWindowExW 77500E51 5 Bytes JMP 6BFC801F C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!SetWindowsHookExW 7750210A 5 Bytes JMP 6BF746DB C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!DialogBoxIndirectParamW 77524AA7 5 Bytes JMP 6C0EEDC0 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!DialogBoxParamW 7752564A 5 Bytes JMP 6BEE4D5B C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!DialogBoxParamA 7753CF6A 5 Bytes JMP 6C0EED5D C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!DialogBoxIndirectParamA 7753D29C 5 Bytes JMP 6C0EEE23 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!MessageBoxIndirectA 7754E8C9 5 Bytes JMP 6C0EECF2 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!MessageBoxIndirectW 7754E9C3 5 Bytes JMP 6C0EEC87 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!MessageBoxExA 7754EA29 5 Bytes JMP 6C0EEC25 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] USER32.dll!MessageBoxExW 7754EA4D 5 Bytes JMP 6C0EEBC3 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] ole32.dll!OleLoadFromStream 76145B88 5 Bytes JMP 6C0EF137 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4324] ole32.dll!CoCreateInstance 761957FC 5 Bytes JMP 6BFC8B0D C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!CreateWindowExW 77500E51 5 Bytes JMP 6BFC801F C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!DialogBoxIndirectParamW 77524AA7 5 Bytes JMP 6C0EEDC0 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!DialogBoxParamW 7752564A 5 Bytes JMP 6BEE4D5B C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!DialogBoxParamA 7753CF6A 5 Bytes JMP 6C0EED5D C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!DialogBoxIndirectParamA 7753D29C 5 Bytes JMP 6C0EEE23 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!MessageBoxIndirectA 7754E8C9 5 Bytes JMP 6C0EECF2 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!MessageBoxIndirectW 7754E9C3 5 Bytes JMP 6C0EEC87 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!MessageBoxExA 7754EA29 5 Bytes JMP 6C0EEC25 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4840] USER32.dll!MessageBoxExW 7754EA4D 5 Bytes JMP 6C0EEBC3 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!UnhookWindowsHookEx 774FCC7B 5 Bytes JMP 6BFD81D8 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!CallNextHookEx 774FCC8F 5 Bytes JMP 6BFB9A6C C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!CreateWindowExW 77500E51 5 Bytes JMP 6BFC801F C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!SetWindowsHookExW 7750210A 5 Bytes JMP 6BF746DB C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!DialogBoxIndirectParamW 77524AA7 5 Bytes JMP 6C0EEDC0 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!DialogBoxParamW 7752564A 5 Bytes JMP 6BEE4D5B C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!DialogBoxParamA 7753CF6A 5 Bytes JMP 6C0EED5D C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!DialogBoxIndirectParamA 7753D29C 5 Bytes JMP 6C0EEE23 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!MessageBoxIndirectA 7754E8C9 5 Bytes JMP 6C0EECF2 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!MessageBoxIndirectW 7754E9C3 5 Bytes JMP 6C0EEC87 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!MessageBoxExA 7754EA29 5 Bytes JMP 6C0EEC25 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] USER32.dll!MessageBoxExW 7754EA4D 5 Bytes JMP 6C0EEBC3 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] ole32.dll!OleLoadFromStream 76145B88 5 Bytes JMP 6C0EF137 C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5244] ole32.dll!CoCreateInstance 761957FC 5 Bytes JMP 6BFC8B0D C:\Windows\system32\IEFRAME.dll (Internetový prohlížeč/Microsoft Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [743A2494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74385624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [743856E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [743A250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74398573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74394D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [743950CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [743951A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [743966D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [743982CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74398819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7439907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7439E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1840] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74394C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlReAllocateHeap] [728C9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlSizeHeap] [728CA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlLockHeap] [728C94D8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlUnlockHeap] [728C94E8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlAllocateHeap] [728C92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlDestroyHeap] [728C94B8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlCreateHeap] [728C94A8] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\kernel32.dll [ntdll.dll!RtlExitUserProcess] [728CAA9E] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlSizeHeap] [728CA27D] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlReAllocateHeap] [728C9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlAllocateHeap] [728C92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\USER32.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [757C5D3D] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlAllocateHeap] [728C92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\GDI32.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [757C5D3D] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlAllocateHeap] [728C92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\ole32.dll [ntdll.dll!RtlReAllocateHeap] [728C9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\RPCRT4.dll [ntdll.dll!RtlAllocateHeap] [728C92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [757C5D3D] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlAllocateHeap] [728C92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\ADVAPI32.dll [ntdll.dll!RtlReAllocateHeap] [728C9832] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [757C5D3D] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlFreeHeap] [728C9E78] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\CRYPT32.dll [ntdll.dll!RtlAllocateHeap] [728C92CD] C:\Windows\AppPatch\AcXtrnal.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe[2732] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [757C5D3D] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device \Driver\ACPI_HAL \Device\00000052 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xDF 0xA9 0x3C 0x28 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xDF 0xA9 0x3C 0x28 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL F09A7FC02B36FB64FCFC27D66E51A0A75B47815C66967C7A72FD60C0037601BC0C893A9B0F5E75600A1DF05829CF3F80A672A2B1D23849C3C45016FE06A5EB10D8E52E4FE2C86E91D5EDF259683F9511B1ACA5B4403CC09078B6E5E719F39946ED876DC2905BCFE33FEBD28EACBC6C9FC6BA5E086815AD25DF5AF52B4FC5F344471E8E52221443F28B6BB521197A4FA714322640A8491CFBB2376F6C5D97AA1CC22B2C4EC982B813619249ADF83D0E5AA881FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3D8EDD5E5BE2F6E667A2D97226D213B55539B6B65E771F16E693203B0313D12697D3AEDFE23A668B2B446BCEBB8059379B2493DED69BCBFBC06BC78D1EB316DA85238A86F842ADCBF44A0840020259270E4D38A882E9B193F00A47DA443E7C0CD2EA526D34AF4EF04A8978495008F8AA65E62D9AE9685C5B15B1F2C3B31AEE22609CCB6DA6EAAA6D72450A9C2D1DBBDDEFA8EEE0296309B89F2C148E3DF207E9E6B32A85F5215C178A47818FB40E5540CD4BECCA6F68AA75D9C268A146B91516722B98D6DD43AFA8045E961E956E30B3768E0CCC824C683BDBC6208B47A19CBBE18335272B86A540225CF2689294E980B236237EBA261C1C958AE07DCDA3D353EA421261C06472600095B5AE83995

---- EOF - GMER 1.0.15 ----
Naposledy upravil(a) jindra5 dne 28 led 2010 22:46, celkem upraveno 1 x.

Odpovědět