Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
petr_2
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 19 črc 2008 08:39

Kontrola logu

#1 Příspěvek od petr_2 »

prosím o kontrolu logu, myslím ale, že spíš než honění nějaké havěti bude třeba po dvou letech reinstal, poslední dobou je to zdechlé a často mlátí disketovou mechanikou i když nemá důvod
log přikládám a díky předem za radu
Logfile of random's system information tool 1.06 (written by random/random)
Run by Já at 2010-03-31 19:28:38
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 118 GB (39%) free of 305 GB
Total RAM: 3071 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:28:43, on 31.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ASUS\Asus Probe\AsusProb.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\HDD Health\HDDHealth.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Documents and Settings\Já\Local Settings\Data aplikací\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Já\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Já.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Asus Probe\AsusProb.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\HDDHealth.exe -wl
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Já\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7234612750
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 9859 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-651377827-839522115-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-651377827-839522115-1003UA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-651377827-839522115-1003UA1cac78b5dd64cec.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-02-18 13680640]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-02-18 86016]
"Launch LGDCore"=C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe [2006-07-23 1126400]
"Launch LCDMon"=C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe []
"Share-to-Web Namespace Daemon"=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [2002-04-17 69632]
"ASUS Probe"=C:\Program Files\ASUS\Asus Probe\AsusProb.exe [2002-12-06 617984]
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-06-21 90112]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2005-07-13 2806272]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
""= []
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-04-23 228088]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-01-22 141608]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-03-11 1800464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe ASO-616B5711-6DAE-4795-A05F-39A1E5104020 []
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden []
"HDDHealth"=C:\Program Files\HDD Health\HDDHealth.exe [2008-06-15 1692672]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"Google Update"=C:\Documents and Settings\Já\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-12-23 135664]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\setup\HPZNET01.EXE"="D:\setup\HPZNET01.EXE:*:Enabled:hpznet01.exe"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe"="C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"
"C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe"="C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe:*:Enabled:umi"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\Anno4.exe"="C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\Anno4.exe:*:Enabled:ANNO 1404 (Demo)"
"C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\tools\Benchmark.exe"="C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\tools\Benchmark.exe:*:Enabled:ANNO 1404 (Demo) Setup Benchmark"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\RpcSandraSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\sandra.mui"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\sandra.mui:*:Enabled:SiSoftware Sandra Agent Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-03-31 19:26:04 ----D---- C:\Program Files\trend micro
2010-03-31 19:25:54 ----D---- C:\rsit
2010-03-31 18:53:32 ----D---- C:\Documents and Settings\Já\Data aplikací\DVD Flick
2010-03-31 18:21:40 ----D---- C:\WINDOWS\system32\appmgmt
2010-03-21 17:49:14 ----D---- C:\never say never
2010-03-11 19:38:02 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml32.tmp
2010-03-11 19:38:01 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml31.tmp
2010-03-11 19:38:00 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml30.tmp
2010-03-11 19:34:26 ----N---- C:\WINDOWS\system32\XAudio2_6.dll
2010-03-11 19:34:26 ----N---- C:\WINDOWS\system32\XAPOFX1_4.dll
2010-03-11 19:33:25 ----N---- C:\WINDOWS\system32\xactengine3_6.dll
2010-03-11 19:32:24 ----N---- C:\WINDOWS\system32\X3DAudio1_7.dll
2010-03-11 19:31:24 ----N---- C:\WINDOWS\system32\XAudio2_5.dll
2010-03-11 19:30:23 ----N---- C:\WINDOWS\system32\xactengine3_5.dll
2010-03-11 19:29:23 ----N---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-03-11 19:28:22 ----N---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-03-11 19:27:21 ----N---- C:\WINDOWS\system32\d3dx11_42.dll
2010-03-11 19:26:21 ----N---- C:\WINDOWS\system32\d3dx10_42.dll
2010-03-11 19:25:20 ----N---- C:\WINDOWS\system32\D3DX9_42.dll
2010-03-11 19:23:57 ----HD---- C:\WINDOWS\msdownld.tmp
2010-03-11 19:22:02 ----D---- C:\Program Files\SiSoftware
2010-03-11 18:20:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo
2010-03-11 18:20:40 ----N---- C:\WINDOWS\system32\guard32.dll
2010-03-11 18:20:38 ----D---- C:\Program Files\COMODO
2010-03-10 22:56:48 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-03-08 22:06:59 ----D---- C:\Documents and Settings\Já\Data aplikací\Ubisoft
2010-03-08 22:05:57 ----N---- C:\WINDOWS\system32\D3DX9_41.dll
2010-03-08 22:05:57 ----N---- C:\WINDOWS\system32\d3dx10_41.dll
2010-03-08 22:05:57 ----N---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-03-08 22:05:56 ----N---- C:\WINDOWS\system32\XAudio2_4.dll
2010-03-08 22:05:56 ----N---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-03-08 22:05:55 ----N---- C:\WINDOWS\system32\xactengine3_4.dll
2010-03-08 22:05:55 ----N---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-03-08 22:05:54 ----N---- C:\WINDOWS\system32\d3dx10_40.dll
2010-03-08 22:05:54 ----N---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-03-08 22:05:53 ----N---- C:\WINDOWS\system32\XAudio2_3.dll
2010-03-08 22:05:53 ----N---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-03-08 22:05:53 ----N---- C:\WINDOWS\system32\D3DX9_40.dll
2010-03-08 22:05:52 ----N---- C:\WINDOWS\system32\xactengine3_3.dll
2010-03-08 22:05:52 ----N---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-03-08 22:05:51 ----N---- C:\WINDOWS\system32\XAudio2_2.dll
2010-03-08 22:05:51 ----N---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-03-08 22:05:51 ----N---- C:\WINDOWS\system32\xactengine3_2.dll
2010-03-08 22:05:50 ----N---- C:\WINDOWS\system32\d3dx10_39.dll
2010-03-08 22:05:50 ----N---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-03-08 22:05:49 ----N---- C:\WINDOWS\system32\XAudio2_1.dll
2010-03-08 22:05:49 ----N---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-03-08 22:05:49 ----N---- C:\WINDOWS\system32\D3DX9_39.dll
2010-03-08 22:05:48 ----N---- C:\WINDOWS\system32\xactengine3_1.dll
2010-03-08 22:05:48 ----N---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-03-08 22:05:47 ----N---- C:\WINDOWS\system32\d3dx10_38.dll
2010-03-08 22:05:47 ----N---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-03-08 22:05:46 ----N---- C:\WINDOWS\system32\XAudio2_0.dll
2010-03-08 22:05:46 ----N---- C:\WINDOWS\system32\D3DX9_38.dll
2010-03-08 22:05:45 ----N---- C:\WINDOWS\system32\xactengine3_0.dll
2010-03-08 22:05:45 ----N---- C:\WINDOWS\system32\X3DAudio1_3.dll
2010-03-08 22:05:44 ----N---- C:\WINDOWS\system32\D3DX9_37.dll
2010-03-08 22:05:44 ----N---- C:\WINDOWS\system32\d3dx10_37.dll
2010-03-08 22:05:44 ----N---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-03-08 22:05:43 ----N---- C:\WINDOWS\system32\xactengine2_10.dll
2010-03-08 22:05:42 ----N---- C:\WINDOWS\system32\d3dx9_36.dll
2010-03-08 22:05:42 ----N---- C:\WINDOWS\system32\d3dx10_36.dll
2010-03-08 22:05:42 ----N---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-03-08 22:05:41 ----N---- C:\WINDOWS\system32\xactengine2_9.dll
2010-03-08 22:05:40 ----N---- C:\WINDOWS\system32\d3dx9_35.dll
2010-03-08 22:05:40 ----N---- C:\WINDOWS\system32\d3dx10_35.dll
2010-03-08 22:05:40 ----N---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-03-08 22:05:39 ----N---- C:\WINDOWS\system32\xactengine2_8.dll
2010-03-08 22:05:39 ----N---- C:\WINDOWS\system32\X3DAudio1_2.dll
2010-03-08 22:05:39 ----N---- C:\WINDOWS\system32\d3dx10_34.dll
2010-03-08 22:05:38 ----N---- C:\WINDOWS\system32\xinput1_3.dll
2010-03-08 22:05:38 ----N---- C:\WINDOWS\system32\d3dx9_34.dll
2010-03-08 22:05:38 ----N---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-03-08 22:05:37 ----N---- C:\WINDOWS\system32\xactengine2_7.dll
2010-03-08 22:05:36 ----N---- C:\WINDOWS\system32\d3dx10_33.dll
2010-03-08 22:05:36 ----N---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-03-08 22:05:35 ----N---- C:\WINDOWS\system32\d3dx9_33.dll
2010-03-08 22:05:34 ----N---- C:\WINDOWS\system32\xactengine2_6.dll
2010-03-08 22:05:34 ----N---- C:\WINDOWS\system32\xactengine2_5.dll
2010-03-08 22:05:33 ----N---- C:\WINDOWS\system32\xactengine2_4.dll
2010-03-08 22:05:33 ----N---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-03-08 22:05:33 ----N---- C:\WINDOWS\system32\d3dx9_32.dll
2010-03-08 22:05:32 ----N---- C:\WINDOWS\system32\xinput1_2.dll
2010-03-08 22:05:32 ----N---- C:\WINDOWS\system32\xactengine2_3.dll
2010-03-08 22:05:32 ----N---- C:\WINDOWS\system32\d3dx9_31.dll
2010-03-08 22:05:31 ----N---- C:\WINDOWS\system32\xinput1_1.dll
2010-03-08 22:05:31 ----N---- C:\WINDOWS\system32\xactengine2_2.dll
2010-03-08 22:05:30 ----N---- C:\WINDOWS\system32\xactengine2_1.dll
2010-03-08 22:05:21 ----N---- C:\WINDOWS\system32\xactengine2_0.dll
2010-03-08 22:05:21 ----N---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-03-08 22:05:20 ----N---- C:\WINDOWS\system32\d3dx9_29.dll
2010-03-08 22:05:19 ----N---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-03-08 22:05:19 ----N---- C:\WINDOWS\system32\d3dx9_27.dll
2010-03-08 22:05:16 ----N---- C:\WINDOWS\system32\d3dx9_24.dll
2010-03-08 22:04:54 ----D---- C:\WINDOWS\Logs
2010-03-08 22:02:49 ----D---- C:\Program Files\Ubisoft
2010-03-08 17:33:04 ----D---- C:\Documents and Settings\Já\Data aplikací\PCToolsFirewallPlus
2010-03-08 17:30:08 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-03-08 17:29:02 ----D---- C:\Program Files\Common Files\PC Tools
2010-03-08 17:28:09 ----D---- C:\Program Files\PC Tools Firewall Plus
2010-03-08 17:20:04 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-03-08 17:17:56 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-08 17:15:20 ----D---- C:\Program Files\Microsoft Security Essentials

======List of files/folders modified in the last 1 months======

2010-03-31 19:28:40 ----D---- C:\WINDOWS\Temp
2010-03-31 19:27:47 ----D---- C:\Program Files\The FilmMachine
2010-03-31 19:26:26 ----D---- C:\WINDOWS\Prefetch
2010-03-31 19:26:04 ----RD---- C:\Program Files
2010-03-31 18:50:12 ----D---- C:\Program Files\DVD Flick
2010-03-31 18:49:47 ----SD---- C:\WINDOWS\Tasks
2010-03-31 18:44:29 ----D---- C:\Documents and Settings\Já\Data aplikací\ICQ
2010-03-31 18:44:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-31 18:43:52 ----D---- C:\Program Files\Common Files\Panasonic
2010-03-31 18:42:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-31 18:41:38 ----SHD---- C:\WINDOWS\Installer
2010-03-31 18:41:38 ----SD---- C:\Documents and Settings\Já\Data aplikací\Microsoft
2010-03-31 18:41:38 ----HD---- C:\Config.Msi
2010-03-31 18:41:37 ----HD---- C:\WINDOWS\inf
2010-03-31 18:41:37 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-31 18:21:40 ----D---- C:\WINDOWS\system32
2010-03-31 18:21:37 ----D---- C:\WINDOWS\WinSxS
2010-03-31 18:18:20 ----D---- C:\Program Files\Pinnacle
2010-03-31 18:18:20 ----D---- C:\Program Files\Common Files
2010-03-31 18:06:31 ----D---- C:\WINDOWS\system32\drivers
2010-03-31 16:53:10 ----N---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-28 17:15:00 ----D---- C:\Documents and Settings\Já\Data aplikací\dvdcss
2010-03-26 18:43:58 ----D---- C:\Program Files\Mozilla Firefox
2010-03-21 17:48:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\DVD Shrink
2010-03-12 16:53:15 ----D---- C:\WINDOWS
2010-03-11 19:35:27 ----D---- C:\WINDOWS\system32\DirectX
2010-03-11 18:32:03 ----D---- C:\Documents and Settings\Já\Data aplikací\Hamachi
2010-03-10 22:57:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-03-10 22:56:50 ----DC---- C:\WINDOWS\system32\dllcache
2010-03-10 22:56:49 ----D---- C:\Program Files\Movie Maker
2010-03-10 22:56:28 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-10 16:45:49 ----A---- C:\WINDOWS\win.ini
2010-03-08 22:05:30 ----RSD---- C:\WINDOWS\assembly
2010-03-08 22:02:47 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-08 17:29:23 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-08 17:14:48 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-03-08 17:14:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee
2010-03-03 19:02:22 ----D---- C:\Documents and Settings\Já\Data aplikací\Skype
2010-03-02 07:30:12 ----N---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2009-03-15 82380]
R1 aslm75;aslm75; \??\C:\WINDOWS\system32\drivers\aslm75.sys []
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-03-11 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-03-11 25160]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-09-16 214664]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-03-08 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-03-08 25888]
R2 nvcap;nVidia WDM Video Capture (universal); C:\WINDOWS\system32\DRIVERS\nvcap.sys [2005-04-14 141582]
R2 NVXBAR;nVidia WDM A/V Crossbar; C:\WINDOWS\system32\DRIVERS\NVxbar.sys [2005-04-14 16496]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-12-27 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-07-13 3851264]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-02-18 6308224]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-18 5888]
R3 SAA7146n;TT DVB-PCI driver (SAA7146n); C:\WINDOWS\system32\DRIVERS\saa7146n.sys [2004-04-26 65856]
R3 TTLOOPHE;Virtual DVB-S/-C/-T Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\ttloophe.sys [2004-02-03 39984]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2004-10-27 223104]
S3 61883;61883 Unit Device; C:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-14 48128]
S3 anek0pr9;anek0pr9; C:\WINDOWS\system32\drivers\anek0pr9.sys []
S3 Avc;AVC Device; C:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-14 38912]
S3 awrepv17;awrepv17; C:\WINDOWS\system32\drivers\awrepv17.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2009-09-16 79816]
S3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2009-09-16 35272]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2009-09-16 34248]
S3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2009-09-16 40552]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2008-04-14 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 RimUsb;Zařízení BlackBerry; C:\WINDOWS\System32\Drivers\RimUsb.sys [2006-11-07 22272]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\Sandra.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 sonypvs1;Sony Digital Imaging Video2; C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 102220]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 TfNetMon;TfNetMon; \??\C:\WINDOWS\system32\drivers\TfNetMon.sys []
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-03-11 723632]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-02-25 73728]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-02-18 163908]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-01-22 545576]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-04-22 359160]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2007-04-23 310008]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-04-23 166648]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 HP Port Resolver;HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [2005-05-20 81920]
S3 HP Status Server;HP Status Server; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE [2004-10-16 73728]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-04-22 88824]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-04-23 1010424]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe [2009-08-24 93336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Kontrola logu

#2 Příspěvek od motji »

Hezké odpoledne :)

A můžu na to před reinstalem ještě kouknout? :)

:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe

-souhlaste s instalací konzole pro zotavení

- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

petr_2
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 19 črc 2008 08:39

Re: Kontrola logu

#3 Příspěvek od petr_2 »

tak tohle vám to po proběhnutí vytvořilo:

ComboFix 10-03-29.04 - Já 01.04.2010 15:31:14.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3071.2611 [GMT 2:00]
Spuštěný z: c:\documents and settings\Já\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-03-01 do 2010-04-01 )))))))))))))))))))))))))))))))
.

2010-03-31 17:26 . 2010-03-31 17:28 -------- d-----w- c:\program files\trend micro
2010-03-31 17:25 . 2010-03-31 17:26 -------- d-----w- C:\rsit
2010-03-11 17:34 . 2010-02-04 09:01 74072 ------w- c:\windows\system32\XAPOFX1_4.dll
2010-03-11 17:34 . 2010-02-04 09:01 528216 ------w- c:\windows\system32\XAudio2_6.dll
2010-03-11 17:33 . 2010-02-04 09:01 238936 ------w- c:\windows\system32\xactengine3_6.dll
2010-03-11 17:32 . 2010-02-04 09:01 22360 ------w- c:\windows\system32\X3DAudio1_7.dll
2010-03-11 17:31 . 2009-09-04 16:44 515416 ------w- c:\windows\system32\XAudio2_5.dll
2010-03-11 17:30 . 2009-09-04 16:44 238936 ------w- c:\windows\system32\xactengine3_5.dll
2010-03-11 17:29 . 2009-09-04 16:29 1974616 ------w- c:\windows\system32\D3DCompiler_42.dll
2010-03-11 17:28 . 2009-09-04 16:29 5501792 ------w- c:\windows\system32\d3dcsx_42.dll
2010-03-11 17:27 . 2009-09-04 16:29 235344 ------w- c:\windows\system32\d3dx11_42.dll
2010-03-11 17:26 . 2009-09-04 16:29 453456 ------w- c:\windows\system32\d3dx10_42.dll
2010-03-11 17:25 . 2009-09-04 16:29 1892184 ------w- c:\windows\system32\D3DX9_42.dll
2010-03-11 17:23 . 2010-03-11 17:24 -------- d--h--w- c:\windows\msdownld.tmp
2010-03-11 17:22 . 2010-03-11 17:22 -------- d-----w- c:\program files\SiSoftware
2010-03-11 16:20 . 2010-03-11 16:20 87104 ------w- c:\windows\system32\drivers\inspect.sys
2010-03-11 16:20 . 2010-03-11 16:20 25160 ------w- c:\windows\system32\drivers\cmdhlp.sys
2010-03-11 16:20 . 2010-03-11 16:20 171552 ------w- c:\windows\system32\guard32.dll
2010-03-11 16:20 . 2010-03-11 16:20 134344 ------w- c:\windows\system32\drivers\cmdguard.sys
2010-03-11 16:20 . 2010-03-11 16:20 -------- d-----w- c:\program files\COMODO
2010-03-10 14:38 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-08 20:06 . 2010-03-08 20:06 281760 ------w- c:\windows\system32\drivers\atksgt.sys
2010-03-08 20:04 . 2010-03-08 20:04 -------- d-----w- c:\windows\Logs
2010-03-08 20:02 . 2010-03-08 20:02 -------- d-----w- c:\program files\Ubisoft
2010-03-08 15:29 . 2010-03-11 16:04 -------- d-----w- c:\program files\Common Files\PC Tools
2010-03-08 15:28 . 2010-03-11 16:04 -------- d-----w- c:\program files\PC Tools Firewall Plus
2010-03-08 15:20 . 2010-02-24 09:16 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-03-08 15:17 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-08 15:15 . 2010-03-08 15:15 -------- d-----w- c:\program files\Microsoft Security Essentials

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-31 17:27 . 2009-03-20 14:41 -------- d-----w- c:\program files\The FilmMachine
2010-03-31 16:50 . 2009-03-15 17:30 -------- d-----w- c:\program files\DVD Flick
2010-03-31 16:43 . 2010-01-23 09:48 -------- d-----w- c:\program files\Common Files\Panasonic
2010-03-31 16:18 . 2010-02-13 18:25 -------- d-----w- c:\program files\Pinnacle
2010-03-31 14:53 . 2004-08-18 12:00 78030 ------w- c:\windows\system32\perfc005.dat
2010-03-31 14:53 . 2004-08-18 12:00 429018 ------w- c:\windows\system32\perfh005.dat
2010-03-08 20:05 . 2010-03-08 20:05 25888 ------w- c:\windows\system32\drivers\lirsgt.sys
2010-03-08 20:02 . 2009-03-15 14:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-13 18:33 . 2010-02-13 18:33 -------- d-----w- c:\program files\Common Files\Pinnacle
2010-02-13 09:51 . 2009-03-19 15:18 -------- d-----w- c:\program files\Ulead Systems
2010-02-13 09:51 . 2009-03-19 15:18 -------- d-----w- c:\program files\Common Files\Ulead Systems
2010-02-12 15:03 . 2010-02-12 15:02 -------- d-----w- c:\program files\iTunes
2010-02-12 15:02 . 2010-02-12 15:02 -------- d-----w- c:\program files\iPod
2010-02-12 15:02 . 2010-02-12 14:56 -------- d-----w- c:\program files\Common Files\Apple
2010-02-12 15:01 . 2010-02-12 15:01 -------- d-----w- c:\program files\Bonjour
2010-02-12 15:01 . 2010-02-12 14:59 -------- d-----w- c:\program files\QuickTime
2010-02-05 16:05 . 2010-02-05 16:05 -------- d-----w- c:\program files\Opera
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"HDDHealth"="c:\program files\HDD Health\HDDHealth.exe" [2008-06-15 1692672]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"Google Update"="c:\documents and settings\Já\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-12-23 135664]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"nwiz"="nwiz.exe" [2009-02-18 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"Launch LGDCore"="c:\program files\Common Files\Logitech\G-series Software\LGDCore.exe" [2006-07-23 1126400]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"ASUS Probe"="c:\program files\ASUS\Asus Probe\AsusProb.exe" [2002-12-06 617984]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"SoundMan"="SOUNDMAN.EXE" [2005-06-21 90112]
"AlcWzrd"="ALCWZRD.EXE" [2005-07-13 2806272]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-04-23 228088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-03-11 1800464]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404 (Demo)\\Anno4.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404 (Demo)\\tools\\Benchmark.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010c\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010c\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010c\\WNt500x86\\sandra.mui"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [15.3.2009 16:12 25423]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [11.3.2010 18:20 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [11.3.2010 18:20 25160]
R3 SAA7146n;TT DVB-PCI driver (SAA7146n);c:\windows\system32\drivers\saa7146n.sys [15.3.2009 10:57 65856]
R3 TTLOOPHE;Virtual DVB-S/-C/-T Network Adapter Driver;c:\windows\system32\drivers\ttloophe.sys [15.3.2009 10:57 39984]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.3.2009 20:41 721904]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe [11.3.2010 19:22 93336]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
.
Obsah adresáře 'Naplánované úlohy'

2010-04-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 17:02]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Já\Data aplikací\Mozilla\Firefox\Profiles\s10u0lew.default\
FF - component: c:\documents and settings\Já\Data aplikací\Mozilla\Firefox\Profiles\s10u0lew.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-LightScribe Control Panel - c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
HKLM-Run-Launch LCDMon - c:\program files\Common Files\Logitech\LCD Manager\lcdmon.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-01 15:36
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
Celkový čas: 2010-04-01 15:38:38
ComboFix-quarantined-files.txt 2010-04-01 13:38

Před spuštěním: Volných bajtů: 123 817 230 336
Po spuštění: Volných bajtů: 124 386 357 248

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - A97D4347F8E08A3F94D5AB0D33749C6F

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Kontrola logu

#4 Příspěvek od motji »

NIc závadného jsme nemašla ani já, ani combofix.
Zkusíme počítač trochu pročistit, jestli to pomůže :o :)

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech

***********
:arrow: start-spustit - napište chkdsk /f/r
-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat

:arrow: defragmentace disku
- start - ovládací panely - nástroje pro správu - správa počítače - defragmentace disku

-- můžete použít i jiný nástroj na defragmentaci, ten ve windows není nic moc

ObrázekZa sebe můžu doporučit JK defrag, který se neinstaluje
http://www.slunecnice.cz/sw/jkdefrag/


***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

petr_2
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 19 črc 2008 08:39

Re: Kontrola logu

#5 Příspěvek od petr_2 »

tak vsechno provedeno, i kdyz teda ty domácí úkoly byly dneska na dýl :-) vse vypadá ok, log přikládám, jen dvě připomínky, link na doporučený soft na defrag je mrtvý, tak jsem to spáchal sw v WXP :-( a dále procedura odstrelila Daemon tool neboli SW na virtuální mechaniky, ale zjistil jsem , že už se to tu na foru řešilo tak ho nainstalím znova, myslim, že chcípnul při odinstalaci combofix, zapoměl jsem ho shodit úplně a už to bylo :-)

Tak ještě jednou díky dobrá vílo

Logfile of random's system information tool 1.06 (written by random/random)
Run by Já at 2010-04-02 22:02:15
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 129 GB (42%) free of 305 GB
Total RAM: 3071 MB (78% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:02:36, on 2.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ASUS\Asus Probe\AsusProb.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\HDD Health\HDDHealth.exe
C:\Documents and Settings\Já\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Documents and Settings\Já\Local Settings\Data aplikací\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Já\Plocha\RSIT.exe
C:\Program Files\trend micro\Já.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Asus Probe\AsusProb.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\HDDHealth.exe -wl
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Já\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7234612750
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 9112 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-02-18 13680640]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-02-18 86016]
"Launch LGDCore"=C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe [2006-07-23 1126400]
"Share-to-Web Namespace Daemon"=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [2002-04-17 69632]
"ASUS Probe"=C:\Program Files\ASUS\Asus Probe\AsusProb.exe [2002-12-06 617984]
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-06-21 90112]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2005-07-13 2806272]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-04-23 228088]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-01-22 141608]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-03-11 1800464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]
"HDDHealth"=C:\Program Files\HDD Health\HDDHealth.exe [2008-06-15 1692672]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"Google Update"=C:\Documents and Settings\Já\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-12-23 135664]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe"="C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"
"C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe"="C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\Anno4.exe"="C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\Anno4.exe:*:Enabled:ANNO 1404 (Demo)"
"C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\tools\Benchmark.exe"="C:\Program Files\Ubisoft\Related Designs\ANNO 1404 (Demo)\tools\Benchmark.exe:*:Enabled:ANNO 1404 (Demo) Setup Benchmark"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\RpcSandraSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\sandra.mui"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\sandra.mui:*:Enabled:SiSoftware Sandra Agent Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-04-02 22:02:15 ----D---- C:\rsit
2010-04-02 15:42:45 ----SHD---- C:\RECYCLER
2010-04-02 15:41:14 ----D---- C:\Program Files\CCleaner
2010-04-01 15:38:40 ----D---- C:\WINDOWS\temp
2010-04-01 15:28:45 ----A---- C:\Boot.bak
2010-04-01 15:28:39 ----RASHD---- C:\cmdcons
2010-04-01 15:20:05 ----N---- C:\WINDOWS\system32\iepeers.dll
2010-04-01 15:20:05 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2010-04-01 15:19:52 ----N---- C:\WINDOWS\system32\occache.dll
2010-04-01 15:19:46 ----N---- C:\WINDOWS\system32\jsproxy.dll
2010-04-01 15:19:44 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2010-03-31 19:26:04 ----D---- C:\Program Files\trend micro
2010-03-31 18:53:32 ----D---- C:\Documents and Settings\Já\Data aplikací\DVD Flick
2010-03-31 18:21:40 ----D---- C:\WINDOWS\system32\appmgmt
2010-03-21 17:49:14 ----D---- C:\never say never
2010-03-11 19:38:02 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml32.tmp
2010-03-11 19:38:01 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml31.tmp
2010-03-11 19:38:00 ----A---- C:\Documents and Settings\All Users\Data aplikací\xml30.tmp
2010-03-11 19:34:26 ----N---- C:\WINDOWS\system32\XAudio2_6.dll
2010-03-11 19:34:26 ----N---- C:\WINDOWS\system32\XAPOFX1_4.dll
2010-03-11 19:33:25 ----N---- C:\WINDOWS\system32\xactengine3_6.dll
2010-03-11 19:32:24 ----N---- C:\WINDOWS\system32\X3DAudio1_7.dll
2010-03-11 19:31:24 ----N---- C:\WINDOWS\system32\XAudio2_5.dll
2010-03-11 19:30:23 ----N---- C:\WINDOWS\system32\xactengine3_5.dll
2010-03-11 19:29:23 ----N---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-03-11 19:28:22 ----N---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-03-11 19:27:21 ----N---- C:\WINDOWS\system32\d3dx11_42.dll
2010-03-11 19:26:21 ----N---- C:\WINDOWS\system32\d3dx10_42.dll
2010-03-11 19:25:20 ----N---- C:\WINDOWS\system32\D3DX9_42.dll
2010-03-11 19:23:57 ----HD---- C:\WINDOWS\msdownld.tmp
2010-03-11 19:22:02 ----D---- C:\Program Files\SiSoftware
2010-03-11 18:20:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo
2010-03-11 18:20:40 ----N---- C:\WINDOWS\system32\guard32.dll
2010-03-11 18:20:38 ----D---- C:\Program Files\COMODO
2010-03-10 22:56:48 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-03-08 22:06:59 ----D---- C:\Documents and Settings\Já\Data aplikací\Ubisoft
2010-03-08 22:05:57 ----N---- C:\WINDOWS\system32\D3DX9_41.dll
2010-03-08 22:05:57 ----N---- C:\WINDOWS\system32\d3dx10_41.dll
2010-03-08 22:05:57 ----N---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-03-08 22:05:56 ----N---- C:\WINDOWS\system32\XAudio2_4.dll
2010-03-08 22:05:56 ----N---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-03-08 22:05:55 ----N---- C:\WINDOWS\system32\xactengine3_4.dll
2010-03-08 22:05:55 ----N---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-03-08 22:05:54 ----N---- C:\WINDOWS\system32\d3dx10_40.dll
2010-03-08 22:05:54 ----N---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-03-08 22:05:53 ----N---- C:\WINDOWS\system32\XAudio2_3.dll
2010-03-08 22:05:53 ----N---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-03-08 22:05:53 ----N---- C:\WINDOWS\system32\D3DX9_40.dll
2010-03-08 22:05:52 ----N---- C:\WINDOWS\system32\xactengine3_3.dll
2010-03-08 22:05:52 ----N---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-03-08 22:05:51 ----N---- C:\WINDOWS\system32\XAudio2_2.dll
2010-03-08 22:05:51 ----N---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-03-08 22:05:51 ----N---- C:\WINDOWS\system32\xactengine3_2.dll
2010-03-08 22:05:50 ----N---- C:\WINDOWS\system32\d3dx10_39.dll
2010-03-08 22:05:50 ----N---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-03-08 22:05:49 ----N---- C:\WINDOWS\system32\XAudio2_1.dll
2010-03-08 22:05:49 ----N---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-03-08 22:05:49 ----N---- C:\WINDOWS\system32\D3DX9_39.dll
2010-03-08 22:05:48 ----N---- C:\WINDOWS\system32\xactengine3_1.dll
2010-03-08 22:05:48 ----N---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-03-08 22:05:47 ----N---- C:\WINDOWS\system32\d3dx10_38.dll
2010-03-08 22:05:47 ----N---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-03-08 22:05:46 ----N---- C:\WINDOWS\system32\XAudio2_0.dll
2010-03-08 22:05:46 ----N---- C:\WINDOWS\system32\D3DX9_38.dll
2010-03-08 22:05:45 ----N---- C:\WINDOWS\system32\xactengine3_0.dll
2010-03-08 22:05:45 ----N---- C:\WINDOWS\system32\X3DAudio1_3.dll
2010-03-08 22:05:44 ----N---- C:\WINDOWS\system32\D3DX9_37.dll
2010-03-08 22:05:44 ----N---- C:\WINDOWS\system32\d3dx10_37.dll
2010-03-08 22:05:44 ----N---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-03-08 22:05:43 ----N---- C:\WINDOWS\system32\xactengine2_10.dll
2010-03-08 22:05:42 ----N---- C:\WINDOWS\system32\d3dx9_36.dll
2010-03-08 22:05:42 ----N---- C:\WINDOWS\system32\d3dx10_36.dll
2010-03-08 22:05:42 ----N---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-03-08 22:05:41 ----N---- C:\WINDOWS\system32\xactengine2_9.dll
2010-03-08 22:05:40 ----N---- C:\WINDOWS\system32\d3dx9_35.dll
2010-03-08 22:05:40 ----N---- C:\WINDOWS\system32\d3dx10_35.dll
2010-03-08 22:05:40 ----N---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-03-08 22:05:39 ----N---- C:\WINDOWS\system32\xactengine2_8.dll
2010-03-08 22:05:39 ----N---- C:\WINDOWS\system32\X3DAudio1_2.dll
2010-03-08 22:05:39 ----N---- C:\WINDOWS\system32\d3dx10_34.dll
2010-03-08 22:05:38 ----N---- C:\WINDOWS\system32\xinput1_3.dll
2010-03-08 22:05:38 ----N---- C:\WINDOWS\system32\d3dx9_34.dll
2010-03-08 22:05:38 ----N---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-03-08 22:05:37 ----N---- C:\WINDOWS\system32\xactengine2_7.dll
2010-03-08 22:05:36 ----N---- C:\WINDOWS\system32\d3dx10_33.dll
2010-03-08 22:05:36 ----N---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-03-08 22:05:35 ----N---- C:\WINDOWS\system32\d3dx9_33.dll
2010-03-08 22:05:34 ----N---- C:\WINDOWS\system32\xactengine2_6.dll
2010-03-08 22:05:34 ----N---- C:\WINDOWS\system32\xactengine2_5.dll
2010-03-08 22:05:33 ----N---- C:\WINDOWS\system32\xactengine2_4.dll
2010-03-08 22:05:33 ----N---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-03-08 22:05:33 ----N---- C:\WINDOWS\system32\d3dx9_32.dll
2010-03-08 22:05:32 ----N---- C:\WINDOWS\system32\xinput1_2.dll
2010-03-08 22:05:32 ----N---- C:\WINDOWS\system32\xactengine2_3.dll
2010-03-08 22:05:32 ----N---- C:\WINDOWS\system32\d3dx9_31.dll
2010-03-08 22:05:31 ----N---- C:\WINDOWS\system32\xinput1_1.dll
2010-03-08 22:05:31 ----N---- C:\WINDOWS\system32\xactengine2_2.dll
2010-03-08 22:05:30 ----N---- C:\WINDOWS\system32\xactengine2_1.dll
2010-03-08 22:05:21 ----N---- C:\WINDOWS\system32\xactengine2_0.dll
2010-03-08 22:05:21 ----N---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-03-08 22:05:20 ----N---- C:\WINDOWS\system32\d3dx9_29.dll
2010-03-08 22:05:19 ----N---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-03-08 22:05:19 ----N---- C:\WINDOWS\system32\d3dx9_27.dll
2010-03-08 22:05:16 ----N---- C:\WINDOWS\system32\d3dx9_24.dll
2010-03-08 22:04:54 ----D---- C:\WINDOWS\Logs
2010-03-08 22:02:49 ----D---- C:\Program Files\Ubisoft
2010-03-08 17:33:04 ----D---- C:\Documents and Settings\Já\Data aplikací\PCToolsFirewallPlus
2010-03-08 17:30:08 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-03-08 17:29:02 ----D---- C:\Program Files\Common Files\PC Tools
2010-03-08 17:28:09 ----D---- C:\Program Files\PC Tools Firewall Plus
2010-03-08 17:20:04 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-03-08 17:17:56 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-08 17:15:20 ----D---- C:\Program Files\Microsoft Security Essentials

======List of files/folders modified in the last 1 months======

2010-04-02 22:02:23 ----D---- C:\WINDOWS\Prefetch
2010-04-02 21:59:03 ----D---- C:\Program Files\Mozilla Firefox
2010-04-02 17:39:39 ----SD---- C:\WINDOWS\Tasks
2010-04-02 17:34:55 ----D---- C:\Documents and Settings\Já\Data aplikací\ICQ
2010-04-02 17:34:22 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-02 15:59:52 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-02 15:53:16 ----D---- C:\WINDOWS
2010-04-02 15:42:46 ----D---- C:\WINDOWS\Debug
2010-04-02 15:41:14 ----RD---- C:\Program Files
2010-04-02 15:36:20 ----D---- C:\WINDOWS\Minidump
2010-04-02 15:30:49 ----SHD---- C:\System Volume Information
2010-04-02 15:30:43 ----D---- C:\WINDOWS\system32\Restore
2010-04-02 15:17:34 ----D---- C:\WINDOWS\system32
2010-04-01 20:22:56 ----HD---- C:\WINDOWS\inf
2010-04-01 20:07:47 ----DC---- C:\WINDOWS\system32\dllcache
2010-04-01 19:54:45 ----D---- C:\Program Files\Internet Explorer
2010-04-01 19:46:35 ----D---- C:\WINDOWS\ie8updates
2010-04-01 19:46:16 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-01 15:36:05 ----A---- C:\WINDOWS\system.ini
2010-04-01 15:33:22 ----D---- C:\WINDOWS\system32\drivers
2010-04-01 15:33:22 ----D---- C:\WINDOWS\AppPatch
2010-04-01 15:33:16 ----D---- C:\Program Files\Common Files
2010-04-01 15:28:45 ----RASH---- C:\boot.ini
2010-03-31 19:27:47 ----D---- C:\Program Files\The FilmMachine
2010-03-31 18:50:12 ----D---- C:\Program Files\DVD Flick
2010-03-31 18:43:52 ----D---- C:\Program Files\Common Files\Panasonic
2010-03-31 18:41:38 ----SHD---- C:\WINDOWS\Installer
2010-03-31 18:41:38 ----SD---- C:\Documents and Settings\Já\Data aplikací\Microsoft
2010-03-31 18:41:38 ----D---- C:\Config.Msi
2010-03-31 18:41:37 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-31 18:21:37 ----D---- C:\WINDOWS\WinSxS
2010-03-31 18:18:20 ----D---- C:\Program Files\Pinnacle
2010-03-31 18:18:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
2010-03-31 16:53:10 ----N---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-28 17:15:00 ----D---- C:\Documents and Settings\Já\Data aplikací\dvdcss
2010-03-21 17:48:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\DVD Shrink
2010-03-11 19:35:27 ----D---- C:\WINDOWS\system32\DirectX
2010-03-11 18:32:03 ----D---- C:\Documents and Settings\Já\Data aplikací\Hamachi
2010-03-10 22:57:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-03-10 22:56:49 ----D---- C:\Program Files\Movie Maker
2010-03-10 16:45:49 ----A---- C:\WINDOWS\win.ini
2010-03-08 22:05:30 ----RSD---- C:\WINDOWS\assembly
2010-03-08 22:02:47 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-08 17:29:23 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-08 17:14:48 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-03-08 17:14:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee
2010-03-03 19:02:22 ----D---- C:\Documents and Settings\Já\Data aplikací\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2009-03-15 82380]
R1 aslm75;aslm75; \??\C:\WINDOWS\system32\drivers\aslm75.sys []
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-03-11 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-03-11 25160]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-09-16 214664]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-03-08 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-03-08 25888]
R2 nvcap;nVidia WDM Video Capture (universal); C:\WINDOWS\system32\DRIVERS\nvcap.sys [2005-04-14 141582]
R2 NVXBAR;nVidia WDM A/V Crossbar; C:\WINDOWS\system32\DRIVERS\NVxbar.sys [2005-04-14 16496]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-12-27 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-07-13 3851264]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-02-18 6308224]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-18 5888]
R3 SAA7146n;TT DVB-PCI driver (SAA7146n); C:\WINDOWS\system32\DRIVERS\saa7146n.sys [2004-04-26 65856]
R3 TTLOOPHE;Virtual DVB-S/-C/-T Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\ttloophe.sys [2004-02-03 39984]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2004-10-27 223104]
S3 61883;61883 Unit Device; C:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-14 48128]
S3 Avc;AVC Device; C:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-14 38912]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2009-09-16 79816]
S3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2009-09-16 35272]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2009-09-16 34248]
S3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2009-09-16 40552]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2008-04-14 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 RimUsb;Zařízení BlackBerry; C:\WINDOWS\System32\Drivers\RimUsb.sys [2006-11-07 22272]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\Sandra.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 sonypvs1;Sony Digital Imaging Video2; C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 102220]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 TfNetMon;TfNetMon; \??\C:\WINDOWS\system32\drivers\TfNetMon.sys []
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-05-24 721904]
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-03-11 723632]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-02-25 73728]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-02-18 163908]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-01-22 545576]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-04-22 359160]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2007-04-23 310008]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-04-23 166648]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 HP Port Resolver;HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [2005-05-20 81920]
S3 HP Status Server;HP Status Server; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE [2004-10-16 73728]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-04-22 88824]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-04-23 1010424]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\RpcAgentSrv.exe [2009-08-24 93336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Kontrola logu

#6 Příspěvek od motji »

:arrow: Za odkaz se omlouvám, už ho mám dlouho a neověřovala jsem ho :oops: , zkuste odtud
http://www.stahuj.centrum.cz/utility_a_ ... g[oz]=3.36

:arrow: Daemona přeinstalujte. Ale máte i Alcohol, já bych Vám nedoporučovala mít na jednom systému oba, využívají podobnou techniku a mohou spolu kolidovat.

Jsou s počítačem nějaké problémy?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

petr_2
Návštěvník
Návštěvník
Příspěvky: 66
Registrován: 19 črc 2008 08:39

Re: Kontrola logu

#7 Příspěvek od petr_2 »

:-) vypadá to dobře , docela to ožilo, tak to domácí cvičení bylo určitě užitečné.
Díky a pěkný prodloužený víkend a velikonoční svátky

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Kontrola logu

#8 Příspěvek od motji »

Není zač, Vám také hezké Velikonoce :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět