Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Virus? Zdvojený kurzor myši, pomalý notebook

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
info
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 30 čer 2010 09:30

Virus? Zdvojený kurzor myši, pomalý notebook

#1 Příspěvek od info »

AHoj, kamarád mi dal na starost jeho naťas...

Logfile of random's system information tool 1.07 (written by random/random)
Run by user at 2010-06-30 10:33:11
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 57 GB (60%) free of 95 GB
Total RAM: 1014 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:34:22, on 30.6.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\mmrtkrnl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\MP3Dancer\MP3Dancer.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\user\Desktop\RSIT.exe
C:\Program Files\trend micro\user.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatche ... tbid=66022
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2475029
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\RunServices: [SSDPSRV] C:\Windows\system32\ssdpsrv.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MP3 Dancer.lnk = C:\Program Files\MP3Dancer\MP3Dancer.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - (no file)
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - (no file)
O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?CZ (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - (no file)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/red ... &site=home (file missing)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?CZ (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = tomi
O17 - HKLM\Software\..\Telephony: DomainName = tomi
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E164699-9B77-C0FE-23BB-4C770C3B53FE}: NameServer = 62.141.0.1 213.162.65.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = tomi
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E164699-9B77-C0FE-23BB-4C770C3B53FE}: NameServer = 62.141.0.1 213.162.65.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = tomi
O17 - HKLM\System\CS2\Services\Tcpip\..\{0E164699-9B77-C0FE-23BB-4C770C3B53FE}: NameServer = 62.141.0.1 213.162.65.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate1ca054e2ff903e8) (gupdate1ca054e2ff903e8) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11210 bytes

======Scheduled tasks folder======

C:\Windows\tasks\1-Click Maintenance.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{06899141-CAEE-4AF6-ABB7-FD5CFD8BFDB4}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\ctbr.dll [2008-02-29 1142784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-28 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{855F3B16-6D32-4fe6-8A56-BBB695989046}
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\ctbr.dll [2008-02-29 1142784]
{D4027C7F-154A-4066-A1AD-4243D8127440}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-09-03 4702208]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-10-24 178712]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-11-29 1029416]
"Realtime Audio Engine"=mmrtkrnl.exe /i []
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-03-29 2145000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-07-15 39408]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2009-11-20 434176]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MP3 Dancer.lnk - C:\Program Files\MP3Dancer\MP3Dancer.exe
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2007-09-13 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Windows\system32\psqlpwd.dll [2006-12-03 90112]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableCAD"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
shell\AutoRun\command - G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d43c531-7376-11de-a04d-00037a8228d4}]
shell\AutoRun\command - D:\Setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d43c695-7376-11de-a04d-00037a8228d4}]
shell\AutoRun\command - D:\Setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3530af71-aa09-11de-8fce-806e6f6e6963}]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a8f4ed4-d43e-11de-8dbb-806e6f6e6963}]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69d3cf67-64b3-11df-b774-001e686f206f}]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69d3cf6a-64b3-11df-b774-001e686f206f}]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f1d0026-92f4-11de-a0e6-806e6f6e6963}]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86f90c52-18c0-11df-af87-806e6f6e6963}]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d83744a1-8d8c-11de-8f11-001644ca13b7}]
shell\AutoRun\command - D:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d83744d5-8d8c-11de-8f11-001644ca13b7}]
shell\AutoRun\command - G:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dffa31b3-115b-11df-84b6-806e6f6e6963}]
shell\AutoRun\command - D:\AutoRun.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-06-30 10:33:12 ----D---- C:\Program Files\trend micro
2010-06-30 10:33:11 ----D---- C:\rsit
2010-06-30 10:09:50 ----D---- C:\Program Files\ESET
2010-06-30 09:51:56 ----A---- C:\Windows\ntbtlog.txt
2010-06-30 09:41:16 ----A---- C:\Windows\_MSRSTRT.EXE
2010-06-30 09:18:44 ----D---- C:\Program Files\CCleaner
2010-06-22 21:56:20 ----D---- C:\Program Files\Spyware Doctor
2010-06-22 17:19:27 ----D---- C:\Users\user\AppData\Roaming\MAGIX
2010-06-22 17:17:29 ----A---- C:\Windows\system32\TTIC32.dll
2010-06-22 17:17:29 ----A---- C:\Windows\system32\TTI32.dll
2010-06-22 17:17:29 ----A---- C:\Windows\system32\MXRestore.exe
2010-06-22 17:17:29 ----A---- C:\Windows\system32\mgxasio2.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\STRING32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\mgxcdr.txt
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLTPO32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLRES32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLRD32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLPTL32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLPRJ32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLPRF32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLPNT32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLMSC32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLIX.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLISO32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLIO32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLIMG32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLDRV32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLDIR32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLDEV32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLCPY32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLCDF32.dll
2010-06-22 17:17:28 ----A---- C:\Windows\system32\DLLCDA32.dll
2010-06-22 17:17:27 ----A---- C:\Windows\system32\DLLAV32.dll
2010-06-22 17:16:29 ----D---- C:\ProgramData\MAGIX
2010-06-22 17:15:47 ----D---- C:\Program Files\MAGIX
2010-06-22 17:15:47 ----A---- C:\Windows\system32\DLLDEV32i.dll
2010-06-22 17:14:41 ----D---- C:\Windows\system32\MAGIX
2010-06-22 17:14:41 ----A---- C:\Windows\system32\mgxoschk.dll
2010-06-22 17:14:41 ----A---- C:\Windows\mgxoschk.ini
2010-06-22 13:02:18 ----D---- C:\Program Files\Common Files\Totem Shared
2010-06-22 13:01:24 ----D---- C:\Program Files\MP3Dancer
2010-06-22 11:18:34 ----N---- C:\Windows\Setup1.exe
2010-06-22 11:18:32 ----A---- C:\Windows\ST6UNST.EXE
2010-06-22 11:17:46 ----D---- C:\ProgramData\Pianosoft
2010-06-22 11:17:46 ----D---- C:\Program Files\DJ Mix Master
2010-06-22 10:58:01 ----D---- C:\Users\user\AppData\Roaming\DiscoSW
2010-06-22 10:57:43 ----D---- C:\Program Files\Disco XT Demo
2010-06-22 10:48:53 ----D---- C:\Users\user\AppData\Roaming\New Folder
2010-06-22 10:46:40 ----D---- C:\Users\user\AppData\Roaming\AlcaTech
2010-06-22 10:46:27 ----A---- C:\Windows\system32\Setup.dll
2010-06-22 10:46:17 ----D---- C:\ProgramData\AlcaTech
2010-06-22 10:46:15 ----D---- C:\Program Files\AlcaTech
2010-06-21 17:43:38 ----D---- C:\Users\user\AppData\Roaming\Songbird2
2010-06-21 17:43:26 ----A---- C:\Windows\system32\GEARAspi.dll
2010-06-21 17:43:04 ----D---- C:\Program Files\Songbird
2010-06-21 17:09:57 ----D---- C:\Program Files\Common Files\ConvexSoft
2010-06-21 17:04:32 ----A---- C:\Windows\DJ Music Mixer Uninstaller.exe
2010-06-21 17:04:13 ----D---- C:\Program Files\DJ Music Mixer
2010-06-21 12:24:15 ----D---- C:\Users\user\AppData\Roaming\Panda Security
2010-06-21 12:22:03 ----D---- C:\ProgramData\Panda Security
2010-06-20 18:47:43 ----A---- C:\Windows\system32\msxml4a.dll
2010-06-17 19:49:42 ----D---- C:\Program Files\Mockba to Berlin
2010-06-16 18:02:50 ----D---- C:\Program Files\NCH Swift Sound
2010-06-16 17:34:42 ----D---- C:\Users\user\AppData\Roaming\Mp3 Editor for Free
2010-06-16 17:32:45 ----D---- C:\Program Files\Moo0
2010-06-16 17:14:32 ----D---- C:\Program Files\Aktiv MP3 Recorder
2010-06-16 17:06:04 ----D---- C:\Users\user\AppData\Roaming\Audio Record Edit Toolbox Pro
2010-06-16 17:04:58 ----D---- C:\Users\user\AppData\Roaming\Audio Recorder for Free
2010-06-16 17:04:11 ----A---- C:\Windows\system32\NCTTextToAudio2.dll
2010-06-16 16:03:56 ----D---- C:\Program Files\Mixxx
2010-06-16 16:02:48 ----D---- C:\Program Files\Fake Voice
2010-06-16 15:51:18 ----D---- C:\Program Files\MediaMonkey
2010-06-14 14:53:13 ----D---- C:\Program Files\Kramware
2010-06-13 18:44:45 ----D---- C:\Windows\system32\EXP
2010-06-12 23:30:15 ----D---- C:\Program Files\Alternate
2010-06-11 08:08:59 ----A---- C:\Windows\system32\mshtml.dll
2010-06-11 08:08:54 ----A---- C:\Windows\system32\ieframe.dll
2010-06-11 08:08:52 ----A---- C:\Windows\system32\urlmon.dll
2010-06-11 08:08:52 ----A---- C:\Windows\system32\iertutil.dll
2010-06-11 08:08:51 ----A---- C:\Windows\system32\wininet.dll
2010-06-11 08:08:50 ----A---- C:\Windows\system32\occache.dll
2010-06-11 08:08:50 ----A---- C:\Windows\system32\msfeeds.dll
2010-06-11 08:08:49 ----A---- C:\Windows\system32\mstime.dll
2010-06-11 08:08:49 ----A---- C:\Windows\system32\iedkcs32.dll
2010-06-11 08:08:47 ----A---- C:\Windows\system32\ieui.dll
2010-06-11 08:08:47 ----A---- C:\Windows\system32\iepeers.dll
2010-06-11 08:08:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-06-11 08:08:46 ----A---- C:\Windows\system32\jsproxy.dll
2010-06-11 08:08:46 ----A---- C:\Windows\system32\ieUnatt.exe
2010-06-11 08:08:46 ----A---- C:\Windows\system32\iesysprep.dll
2010-06-11 08:08:39 ----A---- C:\Windows\system32\msfeedssync.exe
2010-06-11 08:08:39 ----A---- C:\Windows\system32\ie4uinit.exe
2010-06-11 08:08:38 ----A---- C:\Windows\system32\iesetup.dll
2010-06-11 08:08:38 ----A---- C:\Windows\system32\iernonce.dll
2010-06-11 07:27:00 ----A---- C:\Windows\system32\atmfd.dll
2010-06-11 07:26:54 ----A---- C:\Windows\system32\atmlib.dll
2010-06-11 07:25:48 ----A---- C:\Windows\system32\asycfilt.dll
2010-06-11 06:18:37 ----D---- C:\Program Files\Sorades - Die Befreiung
2010-06-11 06:08:02 ----D---- C:\Program Files\3D MP3 Sound Recorder G2
2010-06-10 20:12:34 ----D---- C:\OtsLabs
2010-06-10 17:59:32 ----D---- C:\ProgramData\SRS Labs
2010-06-09 17:43:48 ----D---- C:\Program Files\SeaMonkey
2010-06-09 16:41:19 ----D---- C:\ProgramData\Alternate
2010-06-09 16:36:53 ----A---- C:\Windows\Talkative Uninstaller.exe
2010-06-09 16:36:50 ----D---- C:\Users\user\AppData\Roaming\River Past G5
2010-06-09 16:36:50 ----D---- C:\ProgramData\River Past G5
2010-06-09 16:36:49 ----D---- C:\Program Files\River Past
2010-06-09 16:26:06 ----D---- C:\Users\user\AppData\Roaming\tunebite
2010-06-09 16:17:12 ----D---- C:\Program Files\Dexster
2010-06-09 16:01:38 ----A---- C:\Windows\system32\WNASPINT.DLL
2010-06-09 15:58:01 ----D---- C:\Windows\uninstall
2010-06-09 15:33:23 ----D---- C:\Program Files\Bonjour
2010-06-08 11:53:59 ----D---- C:\ProgramData\Alwil Software
2010-06-08 11:53:59 ----D---- C:\Program Files\Alwil Software
2010-06-07 17:35:06 ----D---- C:\Program Files\Recuva
2010-06-07 17:02:15 ----D---- C:\Users\user\AppData\Roaming\MxBoost
2010-06-07 17:01:55 ----D---- C:\Users\user\AppData\Roaming\Maxthon2
2010-06-07 14:46:27 ----D---- C:\Users\user\AppData\Roaming\iolo
2010-06-07 14:46:27 ----D---- C:\ProgramData\iolo
2010-06-05 11:08:29 ----D---- C:\Program Files\Winamp Detect
2010-06-04 22:29:21 ----A---- C:\ProgramData\hpe364B.dll
2010-06-04 18:31:48 ----A---- C:\Windows\system32\MSVCP50.DLL
2010-06-04 16:30:57 ----D---- C:\Program Files\TalonSoft
2010-06-04 11:51:29 ----D---- C:\Program Files\Dostihy 3000 Deluxe
2010-06-03 17:21:15 ----D---- C:\Program Files\REAPER
2010-06-03 16:21:48 ----D---- C:\Program Files\Speeditup Free
2010-06-03 15:55:18 ----D---- C:\Program Files\MyRealGames.com
2010-06-03 15:47:34 ----D---- C:\Program Files\MyPlayCity.com
2010-06-03 11:05:46 ----D---- C:\Users\user\AppData\Roaming\MtStudio
2010-06-03 10:46:33 ----D---- C:\Users\user\AppData\Roaming\REAPER
2010-06-03 09:38:28 ----D---- C:\Program Files\Native Instruments
2010-06-02 23:38:57 ----D---- C:\Program Files\Take2
2010-06-02 23:04:23 ----D---- C:\Users\user\AppData\Roaming\fltk.org
2010-06-02 23:02:59 ----D---- C:\Users\user\AppData\Roaming\flightgear.org
2010-06-02 22:58:29 ----D---- C:\Program Files\FlightGear
2010-06-02 22:50:43 ----D---- C:\Users\user\AppData\Roaming\MusicLab
2010-06-02 21:33:56 ----D---- C:\Users\user\AppData\Roaming\Screaming Bee
2010-06-02 21:32:47 ----D---- C:\ProgramData\Screaming Bee
2010-06-02 20:16:35 ----D---- C:\Program Files\Audacity
2010-06-02 17:45:39 ----A---- C:\Windows\system32\CmdLineExt.dll
2010-06-02 17:40:17 ----D---- C:\Program Files\Cenega
2010-06-02 15:24:29 ----D---- C:\dsp_sps
2010-06-01 10:26:04 ----D---- C:\Program Files\Blaze Audio
2010-05-31 18:46:21 ----A---- C:\Windows\system32\NCTAudioVisualization2.dll
2010-05-31 18:46:12 ----A---- C:\Windows\system32\NCTAudioTransform2.dll
2010-05-31 18:46:12 ----A---- C:\Windows\system32\NCTAudioRecord2.dll
2010-05-31 18:46:12 ----A---- C:\Windows\system32\NCTAudioPlayer2.dll
2010-05-31 18:46:12 ----A---- C:\Windows\system32\NCTAudioInformation2.dll
2010-05-31 18:46:12 ----A---- C:\Windows\system32\NCTAudioFile2.dll
2010-05-31 18:46:12 ----A---- C:\Windows\system32\NCTAudioEditor2.dll
2010-05-31 18:46:03 ----A---- C:\Windows\system32\NCTAudioDisplay2.dll
2010-05-31 18:45:54 ----A---- C:\Windows\system32\NCTAudioDesign2.dll
2010-05-31 18:45:43 ----A---- C:\Windows\system32\NCTAudioCDGrabber2.dll
2010-05-31 18:45:19 ----A---- C:\Windows\system32\NMSDVDXU.dll
2010-05-31 18:45:18 ----A---- C:\Windows\system32\msvcr71d.dll
2010-05-31 18:45:18 ----A---- C:\Windows\system32\msvcr70.dll
2010-05-31 17:55:14 ----D---- C:\Users\user\AppData\Roaming\NCH Software
2010-05-31 17:55:13 ----D---- C:\ProgramData\NCH Software
2010-05-31 17:15:16 ----D---- C:\Program Files\Crawler
2010-05-31 16:56:57 ----D---- C:\ProgramData\DrivingSpeed2
2010-05-31 14:35:58 ----D---- C:\TEXCACHE

======List of files/folders modified in the last 1 months======

2010-06-30 10:34:15 ----D---- C:\Windows\Temp
2010-06-30 10:33:24 ----D---- C:\Windows\Prefetch
2010-06-30 10:33:12 ----D---- C:\Program Files
2010-06-30 10:22:58 ----SHD---- C:\Windows\Installer
2010-06-30 10:21:39 ----D---- C:\Windows\System32
2010-06-30 10:21:35 ----A---- C:\Windows\system32\agremove.exe
2010-06-30 10:18:01 ----D---- C:\Windows\system32\drivers
2010-06-30 10:08:21 ----SHD---- C:\System Volume Information
2010-06-30 09:51:56 ----D---- C:\Windows
2010-06-30 09:51:52 ----D---- C:\Program Files\Common Files
2010-06-30 09:32:18 ----D---- C:\Users\user\AppData\Roaming\Media Player Classic
2010-06-30 09:31:45 ----D---- C:\Windows\Minidump
2010-06-30 09:31:45 ----D---- C:\Windows\Debug
2010-06-30 09:17:49 ----AD---- C:\ProgramData\TEMP
2010-06-30 09:17:11 ----HD---- C:\ProgramData
2010-06-28 21:45:14 ----D---- C:\Windows\system32\catroot
2010-06-28 21:45:13 ----D---- C:\Windows\system32\catroot2
2010-06-28 21:45:06 ----D---- C:\Windows\winsxs
2010-06-23 13:44:13 ----D---- C:\Users\user\AppData\Roaming\Skype
2010-06-22 17:20:19 ----RSD---- C:\Windows\Fonts
2010-06-22 17:18:55 ----D---- C:\Windows\Help
2010-06-22 17:18:53 ----D---- C:\Program Files\Common Files\microsoft shared
2010-06-22 17:15:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-06-22 17:15:17 ----D---- C:\Windows\inf
2010-06-21 20:00:35 ----D---- C:\Program Files\GameSpy Arcade
2010-06-21 17:04:44 ----D---- C:\Program Files\Common Files\Program4Pc
2010-06-21 12:19:35 ----D---- C:\ProgramData\ESET
2010-06-21 11:30:09 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-20 12:22:46 ----D---- C:\Windows\system32\Tasks
2010-06-16 18:02:58 ----D---- C:\Users\user\AppData\Roaming\NCH Swift Sound
2010-06-16 18:02:56 ----D---- C:\ProgramData\NCH Swift Sound
2010-06-12 05:35:36 ----D---- C:\Program Files\OpenOffice.org 3
2010-06-11 12:44:13 ----D---- C:\Windows\Microsoft.NET
2010-06-11 12:43:57 ----RSD---- C:\Windows\assembly
2010-06-11 12:29:59 ----D---- C:\Program Files\Windows Mail
2010-06-11 12:29:59 ----D---- C:\Program Files\Internet Explorer
2010-06-11 12:29:58 ----D---- C:\Windows\system32\migration
2010-06-11 12:04:33 ----D---- C:\Windows\system32\wbem
2010-06-11 05:44:08 ----D---- C:\Program Files\Counter-Strike 1.6
2010-06-09 16:48:42 ----D---- C:\Program Files\Common Files\Apple
2010-06-08 12:24:58 ----HD---- C:\Ad Adware 8
2010-06-07 16:39:22 ----SD---- C:\Users\user\AppData\Roaming\Microsoft
2010-06-05 12:07:22 ----D---- C:\Program Files\CDBurnerXP
2010-06-05 11:08:44 ----D---- C:\Program Files\Winamp
2010-06-04 20:29:25 ----D---- C:\ProgramData\BVRP Software
2010-06-04 20:25:59 ----D---- C:\Program Files\Protector Suite QL
2010-06-04 19:35:57 ----D---- C:\Program Files\YouTube Video Downloader
2010-06-04 19:35:57 ----D---- C:\Program Files\WinRAR
2010-06-04 19:35:42 ----D---- C:\Program Files\uTorrent
2010-06-04 19:35:42 ----D---- C:\Program Files\Uloz.to Uploader
2010-06-04 19:35:27 ----D---- C:\Program Files\TuneUp Utilities 2009
2010-06-04 19:35:23 ----D---- C:\Program Files\Trojan Remover
2010-06-04 19:35:23 ----D---- C:\Program Files\Toshiba TEMPRO
2010-06-04 19:35:10 ----D---- C:\Program Files\TNod User & Password Finder
2010-06-04 19:35:10 ----D---- C:\Program Files\The KMPlayer
2010-06-04 19:35:06 ----RD---- C:\Program Files\Skype
2010-06-04 19:35:03 ----D---- C:\Program Files\Realtek WLAN driver
2010-06-04 19:35:03 ----D---- C:\Program Files\QuickTime
2010-06-04 19:34:48 ----D---- C:\Program Files\O2Micro Flash Memory Card Driver
2010-06-04 19:34:47 ----D---- C:\Program Files\myWIFIzone
2010-06-04 19:34:29 ----D---- C:\Program Files\ltmoh
2010-06-04 19:34:29 ----D---- C:\Program Files\K-Lite Codec Pack
2010-06-04 19:34:24 ----D---- C:\Program Files\ICQ6Toolbar
2010-06-04 19:34:24 ----D---- C:\Program Files\ICQ6.5
2010-06-04 19:34:01 ----D---- C:\Program Files\FLV Player
2010-06-04 19:34:01 ----D---- C:\Program Files\DivX
2010-06-04 19:34:01 ----D---- C:\Program Files\data
2010-06-04 19:34:01 ----D---- C:\Program Files\DAEMON Tools
2010-06-04 19:34:01 ----D---- C:\Program Files\Connection Manager
2010-06-04 19:34:00 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-06-04 19:34:00 ----D---- C:\Program Files\Common Files\Toshiba Shared
2010-06-04 19:34:00 ----D---- C:\Program Files\Common Files\Services
2010-06-04 19:34:00 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-06-04 19:33:59 ----D---- C:\Program Files\Common Files\DESIGNER
2010-06-04 19:33:59 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-06-04 19:33:59 ----D---- C:\Program Files\Common Files\ACD Systems
2010-06-04 19:33:58 ----D---- C:\Program Files\Camera Assistant Software for Toshiba
2010-06-04 19:33:58 ----D---- C:\Program Files\Ares
2010-06-04 19:33:57 ----D---- C:\Program Files\Apple Software Update
2010-06-04 19:33:57 ----D---- C:\Program Files\AGEIA Technologies
2010-06-04 18:16:52 ----D---- C:\Windows\system32\config
2010-06-04 18:16:44 ----D---- C:\Windows\Tasks
2010-06-04 18:16:44 ----D---- C:\Windows\system32\spool
2010-06-04 18:16:44 ----D---- C:\Windows\system32\Msdtc
2010-06-04 18:16:44 ----D---- C:\Users\user\AppData\Roaming\Winamp
2010-06-04 18:16:44 ----D---- C:\Users\user\AppData\Roaming\vlc
2010-06-04 18:16:44 ----D---- C:\Users\user\AppData\Roaming\dvdcss
2010-06-04 18:16:41 ----D---- C:\Windows\registration
2010-06-04 18:14:31 ----D---- C:\Windows\system32\LogFiles
2010-06-04 18:07:08 ----D---- C:\Program Files\Capcom
2010-06-03 09:30:59 ----D---- C:\Windows\system32\WDI
2010-06-02 15:33:06 ----D---- C:\Users\user\AppData\Roaming\uTorrent
2010-06-01 09:56:53 ----D---- C:\ProgramData\Avanquest Bluetooth SDK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-03-29 114984]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-02-19 63872]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-03-29 134024]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-02-26 134488]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-02-26 41312]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-03-29 96896]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-18 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-17 8704]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-10-28 188416]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-12-23 15664]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-13 1925632]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2008-01-15 48472]
R3 pfc;Padus ASPI Shell; C:\Windows\system32\drivers\pfc.sys [2009-09-27 10368]
R3 QIOMem;Generic IO & Memory Access; C:\Windows\system32\DRIVERS\QIOMem.sys [2007-04-09 8192]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-19 8192]
R3 RTL8187B;Síťový adaptér Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0; C:\Windows\system32\DRIVERS\RTL8187B.sys [2009-02-23 344064]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-11-29 196144]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2008-03-25 41472]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 9216]
R3 usbvideo;Chicony USB 2.0 Camera; C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
R3 UVCFTR;UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [2007-04-16 11776]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-28 298496]
S3 afj83n8g;afj83n8g; C:\Windows\system32\drivers\afj83n8g.sys []
S3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-11-28 1161888]
S3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 467456]
S3 Axtmvflt;Axesstel USB Filter Service; C:\Windows\system32\DRIVERS\Axtmvflt.sys [2007-03-22 3456]
S3 Axtmvmdm;Axesstel USB Modem; C:\Windows\system32\DRIVERS\Axtmvmdm.sys [2007-03-26 40064]
S3 Axtmvprt;Axesstel Diagnostic Port; C:\Windows\System32\Drivers\Axtmvprt.sys [2007-03-26 38784]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-11-01 985600]
S3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-11-01 208896]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-09-05 1953944]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-04-30 81408]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\Windows\system32\drivers\ScreamingBAudio.sys [2009-11-26 34384]
S3 SRS_SSCFilter;SRS Labs Audio Sandbox (WDM); C:\Windows\system32\drivers\srs_sscfilter_i386.sys [2009-12-15 268912]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\Windows\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\Windows\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 sscdserd;SAMSUNG Mobile Modem Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\sscdserd.sys [2008-02-22 94336]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 tifm21;tifm21; C:\Windows\system32\drivers\tifm21.sys [2007-01-24 290304]
S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2008-10-06 137984]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-03-03 36864]
S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-03-05 74368]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-03-12 16128]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2009-03-23 54272]
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2009-03-19 43264]
S3 TpChoice;Touch Pad Detection Filter driver; C:\Windows\system32\DRIVERS\TpChoice.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-11-01 661504]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 CplIR;Embedded IR Driver; C:\Windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
S4 KR10I;KR10I; C:\Windows\system32\drivers\kr10i.sys [2007-01-18 219392]
S4 KR10N;KR10N; C:\Windows\system32\drivers\kr10n.sys [2007-01-18 211072]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Ad-Aware 2007 Service; C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe [2008-01-04 587096]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-04-16 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-04-08 345376]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 CFSvcs;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2006-11-14 40960]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-03-29 810120]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-10-08 794624]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2007-10-24 358936]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 o2flash;O2Micro Flash Memory Card Service; C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [2007-02-12 65536]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-10-08 483328]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [2009-07-21 116104]
R2 TNaviSrv;TOSHIBA Navi Support Service; C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [2007-09-19 77824]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2006-05-25 114688]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2007-03-29 427576]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2009-03-17 144752]
R2 TuneUp.ProgramStatisticsSvc;@%SystemRoot%\System32\TUProgSt.exe,-1; C:\Windows\System32\TUProgSt.exe [2010-01-21 603904]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2006-08-23 49152]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-17 386560]
S2 gupdate1ca054e2ff903e8;Služba Google Update (gupdate1ca054e2ff903e8); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-03-29 33560]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE []
S3 SmartFaceVWatchSrv;SmartFaceVWatchSrv; C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [2008-08-25 77824]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2010-01-21 360192]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15662
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Virus? Zdvojený kurzor myši, pomalý notebook

#2 Příspěvek od JaRon »

stiahni a uloz na plochu ComboFix

potom spust pod uctom s administratorskym opravnenim


akcia trva cca. 5-10 minut, niekedy i dlhsie -, Pocas scanu nespustaj ziadne ine aplikacie

Nie je dovod na paniku ak stroj bude restartovany
upozornenie: ak pouzivas antispyware s rezidentnim stitem, ten pred scanom vypni.

po restarte aplikacie vytvori log, ulozeny na C:\Combofix.txt (jeho obsah vloz sem)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

info
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 30 čer 2010 09:30

Re: Virus? Zdvojený kurzor myši, pomalý notebook

#3 Příspěvek od info »

ComboFix 10-06-29.03 - user 30.06.2010 11:37:40.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.1014.222 [GMT 2:00]
Spuštěný z: c:\users\user\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\DaemonTools_WhenUSave_Installer
c:\programdata\hpe364B.dll
c:\programdata\hpe8FC9.dll
c:\windows\system32\agremove.exe
c:\windows\system32\vbzlib1.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-28 do 2010-06-30 )))))))))))))))))))))))))))))))
.

2010-06-30 09:48 . 2010-06-30 09:49 -------- d-----w- c:\users\user\AppData\Local\temp
2010-06-30 09:48 . 2010-06-30 09:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-30 09:34 . 2010-06-30 09:34 17408 ----a-w- c:\windows\system32\rpcnetp.dll
2010-06-30 09:33 . 2010-06-30 09:33 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2010-06-30 08:33 . 2010-06-30 08:34 -------- d-----w- c:\program files\trend micro
2010-06-30 08:33 . 2010-06-30 08:34 -------- d-----w- C:\rsit
2010-06-30 08:09 . 2010-06-30 08:09 -------- d-----w- c:\program files\ESET
2010-06-30 07:41 . 2010-06-30 07:41 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-06-30 07:29 . 2010-06-30 07:29 -------- d-----w- c:\users\user\AppData\Local\WindowsUpdate
2010-06-30 07:18 . 2010-06-30 07:18 -------- d-----w- c:\program files\CCleaner
2010-06-22 19:56 . 2010-06-30 07:51 -------- d-----w- c:\program files\Spyware Doctor
2010-06-22 15:19 . 2010-06-22 15:19 -------- d-----w- c:\users\user\AppData\Roaming\MAGIX
2010-06-22 15:15 . 2007-04-27 08:43 120200 ----a-w- c:\windows\system32\DLLDEV32i.dll
2010-06-22 15:14 . 2010-06-22 15:18 -------- d-----w- c:\windows\system32\MAGIX
2010-06-22 15:14 . 2008-04-15 14:14 700416 ----a-w- c:\windows\system32\mgxoschk.dll
2010-06-22 11:02 . 2010-06-22 11:02 -------- d-----w- c:\program files\Common Files\Totem Shared
2010-06-22 11:01 . 2010-06-22 11:09 -------- d-----w- c:\program files\MP3Dancer
2010-06-22 09:18 . 2010-06-22 11:00 245760 ------w- c:\windows\Setup1.exe
2010-06-22 09:18 . 2010-06-22 11:00 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-06-22 09:17 . 2010-06-23 09:44 -------- d-----w- c:\program files\DJ Mix Master
2010-06-22 09:17 . 2010-06-22 09:17 -------- d-----w- c:\programdata\Pianosoft
2010-06-22 08:58 . 2010-06-22 08:58 -------- d-----w- c:\users\user\AppData\Roaming\DiscoSW
2010-06-22 08:57 . 2010-06-22 08:57 -------- d-----w- c:\program files\Disco XT Demo
2010-06-22 08:48 . 2010-06-22 08:48 -------- d-----w- c:\users\user\AppData\Roaming\New Folder
2010-06-22 08:46 . 2010-06-22 08:46 -------- d-----w- c:\users\user\AppData\Roaming\AlcaTech
2010-06-22 08:46 . 2010-06-22 08:46 126464 ----a-w- c:\windows\system32\Setup.dll
2010-06-22 08:46 . 2010-06-22 08:46 -------- d-----w- c:\programdata\AlcaTech
2010-06-22 08:46 . 2010-06-22 08:46 -------- d-----w- c:\program files\AlcaTech
2010-06-21 15:43 . 2010-06-21 15:43 -------- d-----w- c:\users\user\AppData\Local\Songbird2
2010-06-21 15:43 . 2010-06-21 15:43 -------- d-----w- c:\users\user\AppData\Roaming\Songbird2
2010-06-21 15:43 . 2009-12-23 11:03 15664 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-21 15:43 . 2009-12-23 11:03 109360 ----a-w- c:\windows\system32\GEARAspi.dll
2010-06-21 15:43 . 2010-06-21 15:43 -------- d-----w- c:\program files\Songbird
2010-06-21 15:09 . 2010-06-21 15:12 -------- d-----w- c:\program files\Common Files\ConvexSoft
2010-06-21 15:04 . 2010-06-21 15:04 274409 ----a-w- c:\windows\DJ Music Mixer Uninstaller.exe
2010-06-21 15:04 . 2010-06-21 15:09 -------- d-----w- c:\program files\DJ Music Mixer
2010-06-21 10:24 . 2010-06-21 10:24 -------- d-----w- c:\users\user\AppData\Roaming\Panda Security
2010-06-21 10:22 . 2010-06-30 07:52 -------- d-----w- c:\programdata\Panda Security
2010-06-20 16:47 . 2003-04-18 14:29 44544 ----a-w- c:\windows\system32\msxml4a.dll
2010-06-17 17:49 . 2010-06-20 16:27 -------- d-----w- c:\program files\Mockba to Berlin
2010-06-16 16:02 . 2010-06-16 16:02 -------- d-----w- c:\program files\NCH Swift Sound
2010-06-16 15:34 . 2010-06-16 15:47 806 ----a-w- c:\users\user\AppData\Roaming\Mp3 Editor for Free\mef.dll
2010-06-16 15:34 . 2010-06-16 15:34 -------- d-----w- c:\users\user\AppData\Roaming\Mp3 Editor for Free
2010-06-16 15:32 . 2010-06-17 18:58 -------- d-----w- c:\program files\Moo0
2010-06-16 15:14 . 2010-06-21 09:48 -------- d-----w- c:\program files\Aktiv MP3 Recorder
2010-06-16 15:06 . 2010-06-16 15:13 -------- d-----w- c:\users\user\AppData\Roaming\Audio Record Edit Toolbox Pro
2010-06-16 15:04 . 2010-06-16 15:04 -------- d-----w- c:\users\user\AppData\Roaming\Audio Recorder for Free
2010-06-16 15:04 . 2005-03-28 13:52 417792 ----a-w- c:\windows\system32\NCTTextToAudio2.dll
2010-06-16 14:03 . 2010-06-16 14:04 -------- d-----w- c:\program files\Mixxx
2010-06-16 14:02 . 2010-06-16 15:02 -------- d-----w- c:\program files\Fake Voice
2010-06-16 13:51 . 2010-06-22 19:25 -------- d-----w- c:\users\user\AppData\Local\MediaMonkey
2010-06-16 13:51 . 2010-06-16 13:51 -------- d-----w- c:\program files\MediaMonkey
2010-06-14 12:55 . 2010-06-14 12:55 -------- d-----w- c:\users\user\AppData\Local\djDecks
2010-06-14 12:53 . 2010-06-14 12:54 -------- d-----w- c:\program files\Kramware
2010-06-13 16:44 . 2010-06-16 15:56 -------- d-----w- c:\windows\system32\EXP
2010-06-12 21:30 . 2010-06-12 21:30 -------- d-----w- c:\program files\Alternate
2010-06-12 04:01 . 2010-06-12 04:01 1 ----a-w- c:\users\user\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-11 05:27 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-11 05:26 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-11 05:25 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-11 05:24 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-06-11 04:18 . 2010-06-11 04:19 -------- d-----w- c:\program files\Sorades - Die Befreiung
2010-06-11 04:08 . 2010-06-16 15:50 -------- d-----w- c:\program files\3D MP3 Sound Recorder G2
2010-06-10 18:12 . 2010-06-22 11:21 -------- d-----w- C:\OtsLabs
2010-06-10 18:02 . 2010-06-16 15:55 -------- d-----w- c:\users\user\AppData\Local\Ashampoo Music Studio 3
2010-06-10 18:02 . 2010-01-20 10:19 101376 ----a-w- c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sazc27cy.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}\components\RadioWMPCore.dll
2010-06-10 18:02 . 2010-01-20 10:19 52224 ----a-w- c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sazc27cy.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}\components\FFExternalAlert.dll
2010-06-10 15:59 . 2010-06-10 15:59 -------- d-----w- c:\users\user\AppData\Local\SRS Labs
2010-06-10 15:59 . 2010-06-10 15:59 -------- d-----w- c:\programdata\SRS Labs
2010-06-10 15:58 . 2009-12-15 12:41 268912 ----a-w- c:\windows\system32\drivers\SRS_SSCFilter_i386.sys
2010-06-09 15:43 . 2010-06-30 07:16 -------- d-----w- c:\program files\SeaMonkey
2010-06-09 14:41 . 2010-06-12 21:58 -------- d-----w- c:\users\user\AppData\Local\Alternate
2010-06-09 14:41 . 2010-06-12 21:58 -------- d-----w- c:\programdata\Alternate
2010-06-09 14:36 . 2010-06-09 14:36 163258 ----a-w- c:\windows\Talkative Uninstaller.exe
2010-06-09 14:36 . 2010-06-09 14:36 -------- d-----w- c:\programdata\River Past G5
2010-06-09 14:36 . 2010-06-09 14:36 -------- d-----w- c:\users\user\AppData\Roaming\River Past G5
2010-06-09 14:36 . 2010-06-09 14:36 -------- d-----w- c:\program files\River Past
2010-06-09 14:26 . 2010-06-12 21:54 -------- d-----w- c:\users\user\AppData\Roaming\tunebite
2010-06-09 14:24 . 2010-06-09 14:24 -------- d-----w- c:\users\user\Praat
2010-06-09 14:17 . 2010-06-12 22:17 -------- d-----w- c:\program files\Dexster
2010-06-09 14:01 . 2005-08-24 22:00 57344 ----a-w- c:\windows\system32\WNASPINT.DLL
2010-06-09 13:58 . 2010-06-10 17:37 -------- d-----w- c:\windows\uninstall
2010-06-09 13:42 . 2010-06-09 13:42 -------- d-----w- c:\users\user\.scorched3d
2010-06-09 13:33 . 2010-06-09 13:33 -------- d-----w- c:\program files\Bonjour
2010-06-09 13:29 . 2010-06-09 13:29 -------- d-----w- c:\users\user\AppData\Local\Application Data
2010-06-08 09:53 . 2010-06-08 09:53 -------- d-----w- c:\programdata\Alwil Software
2010-06-08 09:53 . 2010-06-08 09:53 -------- d-----w- c:\program files\Alwil Software
2010-06-07 15:35 . 2010-06-07 15:35 -------- d-----w- c:\program files\Recuva
2010-06-07 15:02 . 2010-06-08 16:23 -------- d-----w- c:\users\user\AppData\Roaming\MxBoost
2010-06-07 15:01 . 2010-06-13 16:43 -------- d-----w- c:\users\user\AppData\Roaming\Maxthon2
2010-06-07 14:39 . 2010-06-07 14:39 165232 ---ha-w- c:\users\user\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2010-06-07 12:46 . 2010-06-07 12:46 -------- d-----w- c:\users\user\AppData\Roaming\iolo
2010-06-07 12:46 . 2010-06-07 12:46 -------- d-----w- c:\programdata\iolo
2010-06-05 09:08 . 2010-06-05 09:08 -------- d-----w- c:\program files\Winamp Detect
2010-06-04 18:29 . 2010-06-04 18:29 -------- d-----w- c:\users\user\AppData\Local\BVRP Software
2010-06-04 16:32 . 2010-06-04 16:33 231 ----a-w- c:\windows\PowerReg.dat
2010-06-04 16:31 . 1997-01-22 19:26 565760 ----a-w- c:\windows\system32\MSVCP50.DLL
2010-06-04 15:55 . 2010-06-04 15:55 -------- d-----w- c:\users\user\AppData\Local\CAPCOM
2010-06-04 14:30 . 2010-06-04 14:35 -------- d-----w- c:\program files\TalonSoft
2010-06-04 09:51 . 2010-06-04 17:34 -------- d-----w- c:\program files\Dostihy 3000 Deluxe
2010-06-03 15:21 . 2010-06-04 17:35 -------- d-----w- c:\program files\REAPER
2010-06-03 14:21 . 2010-06-04 17:35 -------- d-----w- c:\program files\Speeditup Free
2010-06-03 13:55 . 2010-06-22 11:23 -------- d-----w- c:\program files\MyRealGames.com
2010-06-03 13:47 . 2010-06-17 18:58 -------- d-----w- c:\program files\MyPlayCity.com
2010-06-03 09:05 . 2010-06-03 15:14 -------- d-----w- c:\users\user\AppData\Roaming\MtStudio
2010-06-03 08:46 . 2010-06-04 16:16 -------- d-----w- c:\users\user\AppData\Roaming\REAPER
2010-06-03 07:38 . 2010-06-03 09:32 -------- d-----w- c:\program files\Native Instruments
2010-06-02 21:38 . 2010-06-02 21:38 -------- d-----w- c:\program files\Take2
2010-06-02 21:04 . 2010-06-02 21:04 -------- d-----w- c:\users\user\AppData\Roaming\fltk.org
2010-06-02 21:02 . 2010-06-02 21:03 -------- d-----w- c:\users\user\AppData\Roaming\flightgear.org
2010-06-02 20:58 . 2010-06-02 21:49 -------- d-----w- c:\program files\FlightGear
2010-06-02 20:50 . 2010-06-02 20:50 -------- d-----w- c:\users\user\AppData\Roaming\MusicLab
2010-06-02 19:33 . 2010-06-02 19:33 -------- d-----w- c:\users\user\AppData\Roaming\Screaming Bee
2010-06-02 19:32 . 2010-06-02 19:33 -------- d-----w- c:\programdata\Screaming Bee
2010-06-02 18:16 . 2010-06-05 17:42 -------- d-----w- c:\program files\Audacity
2010-06-02 15:45 . 2010-06-02 15:45 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-06-02 15:40 . 2010-06-17 18:41 -------- d-----w- c:\program files\Cenega
2010-06-02 13:24 . 2010-06-02 13:24 -------- d-----w- C:\dsp_sps
2010-06-01 08:26 . 2010-06-10 17:24 -------- d-----w- c:\program files\Blaze Audio
2010-05-31 16:46 . 2005-03-28 13:54 479232 ----a-w- c:\windows\system32\NCTAudioVisualization2.dll
2010-05-31 16:46 . 2005-05-18 09:52 1212416 ----a-w- c:\windows\system32\NCTAudioInformation2.dll
2010-05-31 16:46 . 2005-05-17 10:37 1986560 ----a-w- c:\windows\system32\NCTAudioFile2.dll
2010-05-31 16:46 . 2005-04-25 11:01 458752 ----a-w- c:\windows\system32\NCTAudioRecord2.dll
2010-05-31 16:46 . 2005-04-25 11:01 458752 ----a-w- c:\windows\system32\NCTAudioPlayer2.dll
2010-05-31 16:46 . 2005-04-15 10:08 880640 ----a-w- c:\windows\system32\NCTAudioEditor2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-30 09:32 . 2009-07-10 17:40 12 ----a-w- c:\windows\bthservsdp.dat
2010-06-30 07:32 . 2009-09-16 05:27 -------- d-----w- c:\users\user\AppData\Roaming\Media Player Classic
2010-06-23 11:44 . 2009-07-15 13:14 -------- d-----w- c:\users\user\AppData\Roaming\Skype
2010-06-22 18:05 . 2009-07-09 19:10 112184 ----a-w- c:\users\user\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-22 15:17 . 2010-06-22 15:16 -------- d-----w- c:\programdata\MAGIX
2010-06-22 15:17 . 2010-06-22 15:15 -------- d-----w- c:\program files\MAGIX
2010-06-22 15:15 . 2007-01-08 21:09 598838 ----a-w- c:\windows\system32\perfh005.dat
2010-06-22 15:15 . 2007-01-08 21:09 115014 ----a-w- c:\windows\system32\perfc005.dat
2010-06-21 18:00 . 2010-02-08 00:05 -------- d-----w- c:\program files\GameSpy Arcade
2010-06-21 15:04 . 2009-10-10 18:59 -------- d-----w- c:\program files\Common Files\Program4Pc
2010-06-21 09:30 . 2007-04-27 07:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 16:02 . 2010-05-22 18:04 -------- d-----w- c:\users\user\AppData\Roaming\NCH Swift Sound
2010-06-16 16:02 . 2010-05-22 18:04 -------- d-----w- c:\programdata\NCH Swift Sound
2010-06-16 16:02 . 2010-06-16 16:02 -------- d-----w- c:\program files\NCH Swift Sound
2010-06-12 03:35 . 2009-09-30 14:50 -------- d-----w- c:\program files\OpenOffice.org 3
2010-06-11 10:29 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-11 03:44 . 2010-05-23 16:19 -------- d-----w- c:\program files\Counter-Strike 1.6
2010-06-09 14:48 . 2010-01-02 14:56 -------- d-----w- c:\program files\Common Files\Apple
2010-06-05 10:07 . 2010-05-27 16:05 -------- d-----w- c:\program files\CDBurnerXP
2010-06-05 09:08 . 2009-07-18 16:41 -------- d-----w- c:\program files\Winamp
2010-06-04 18:29 . 2010-05-27 07:37 -------- d-----w- c:\programdata\BVRP Software
2010-06-04 18:25 . 2009-07-09 19:36 -------- d-----w- c:\program files\Protector Suite QL
2010-06-04 17:35 . 2009-07-15 19:22 -------- d-----w- c:\program files\YouTube Video Downloader
2010-06-04 17:35 . 2009-09-10 13:04 -------- d-----w- c:\program files\Uloz.to Uploader
2010-06-04 17:35 . 2009-09-05 12:45 -------- d-----w- c:\program files\uTorrent
2010-06-04 17:35 . 2009-09-20 10:40 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-06-04 17:35 . 2009-09-27 14:42 -------- d-----w- c:\program files\Trojan Remover
2010-06-04 17:35 . 2009-07-10 15:16 -------- d-----w- c:\program files\Toshiba TEMPRO
2010-06-04 17:35 . 2010-04-08 09:37 -------- d-----w- c:\program files\TNod User & Password Finder
2010-06-04 17:35 . 2009-07-15 18:29 -------- d-----w- c:\program files\The KMPlayer
2010-06-04 17:35 . 2009-07-15 13:13 -------- d-----r- c:\program files\Skype
2010-06-04 17:35 . 2010-03-13 19:15 -------- d-----w- c:\program files\QuickTime
2010-06-04 17:35 . 2009-07-13 08:59 -------- d-----w- c:\program files\Realtek WLAN driver
2010-06-04 17:33 . 2010-01-27 15:30 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-04 17:33 . 2009-09-27 19:21 -------- d-----w- c:\program files\Common Files\ACD Systems
2010-06-04 17:33 . 2009-07-15 13:58 -------- d-----w- c:\program files\Ares
2010-06-04 17:33 . 2009-07-09 18:58 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
2010-06-04 17:33 . 2010-01-02 14:55 -------- d-----w- c:\program files\Apple Software Update
2010-06-04 17:33 . 2009-12-26 15:44 -------- d-----w- c:\program files\AGEIA Technologies
2010-06-04 16:16 . 2010-05-28 16:22 -------- d-----w- c:\users\user\AppData\Roaming\dvdcss
2010-06-04 16:16 . 2010-05-28 14:40 -------- d-----w- c:\users\user\AppData\Roaming\vlc
2010-06-04 16:16 . 2009-07-18 16:41 -------- d-----w- c:\users\user\AppData\Roaming\Winamp
2010-06-04 16:07 . 2009-08-28 17:59 -------- d-----w- c:\program files\Capcom
2010-06-02 13:33 . 2009-09-05 12:42 -------- d-----w- c:\users\user\AppData\Roaming\uTorrent
2010-06-01 07:56 . 2010-05-27 16:50 -------- d-----w- c:\programdata\Avanquest Bluetooth SDK
2010-05-31 15:55 . 2010-05-31 15:55 -------- d-----w- c:\users\user\AppData\Roaming\NCH Software
2010-05-28 14:39 . 2010-05-28 14:39 -------- d-----w- c:\program files\VideoLAN
2010-05-27 16:06 . 2010-05-27 16:06 -------- d-----w- c:\users\user\AppData\Roaming\Canneverbe Limited
2010-05-27 16:05 . 2010-05-27 16:05 -------- d-----w- c:\programdata\Canneverbe Limited
2010-05-27 12:46 . 2010-05-27 12:41 -------- d-----w- c:\users\user\AppData\Roaming\gtk-2.0
2010-05-27 07:31 . 2010-05-27 07:31 -------- d-----w- c:\programdata\Sony Ericsson
2010-05-27 07:31 . 2010-05-27 07:31 -------- d-----w- c:\program files\Sony Ericsson
2010-05-23 16:05 . 2010-05-23 16:05 -------- d-----w- c:\programdata\Trymedia
2010-05-22 12:42 . 2010-05-22 12:42 -------- d-----w- c:\program files\Artificial
2010-05-22 05:15 . 2009-08-20 13:28 -------- d-----w- c:\program files\O2 Mobilni internet
2010-05-21 12:14 . 2009-10-03 07:49 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-10 09:08 . 2010-05-10 09:08 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-10 09:08 . 2010-05-10 09:05 -------- d-----w- c:\users\user\AppData\Roaming\PC Suite
2010-05-10 09:07 . 2010-05-10 09:05 -------- d-----w- c:\users\user\AppData\Roaming\Nokia
2010-05-10 09:07 . 2010-05-10 09:05 -------- d-----w- c:\programdata\PC Suite
2010-05-10 09:07 . 2010-05-10 09:07 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-05-10 09:06 . 2009-07-09 19:32 -------- d-----w- c:\program files\DIFX
2010-05-10 09:00 . 2010-05-10 09:00 95232 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-05-10 09:00 . 2010-05-10 09:00 61440 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-05-10 09:00 . 2010-05-10 09:00 8192 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-05-10 09:00 . 2010-05-10 09:00 10240 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-05-10 08:59 . 2010-05-10 08:59 -------- d-----w- c:\programdata\Installations
2010-05-10 08:35 . 2010-05-10 09:00 34701512 ----a-w- c:\programdata\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_cze_web.exe
2010-05-08 11:40 . 2009-07-15 13:52 -------- d-----w- c:\users\user\AppData\Roaming\skypePM
2010-05-04 05:59 . 2010-06-11 06:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-11 06:08 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 05:55 . 2010-06-11 06:08 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 04:31 . 2010-06-11 06:08 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 14:15 . 2010-04-09 18:47 -------- d-----w- c:\programdata\HP
2010-05-01 14:14 . 2010-04-09 19:02 -------- d-----w- c:\program files\HP
2010-04-29 18:20 . 2010-04-29 18:20 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-04-23 14:13 . 2010-05-27 12:17 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-08 11:20 . 2010-04-08 11:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 11:20 . 2010-04-08 11:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2006-12-03 15:03 2854912 ----a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2006-12-03 15:03 2854912 ----a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-15 39408]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-11-20 434176]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 4702208]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-24 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-29 1029416]
"Realtime Audio Engine"="mmrtkrnl.exe" [2009-11-23 70144]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-03-29 2145000]

c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MP3 Dancer.lnk - c:\program files\MP3Dancer\MP3Dancer.exe [2010-6-22 229376]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-10-4 393216]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2009-3-19 2532680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-12-03 14:50 90112 ----a-w- c:\windows\System32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"TOSCDSPD"=c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Toshiba Registration"=c:\program files\Toshiba\Registration\ToshibaRegistration.exe
"myWIFIzone"=c:\program files\myWIFIzone\myWIFIzone.exe
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe"
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" -lang 1033
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"KeNotify"=c:\program files\TOSHIBA\Utilities\KeNotify.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"Persistence"=c:\windows\system32\igfxpers.exe
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" /startup
"Desktop SMS"=c:\program files\IDM\Desktop SMS\DesktopSMS.exe /auto
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
"NDSTray.exe"=NDSTray.exe
"SVPWUTIL"=c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
"00TCrdMain"=%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
"TPwrMain"=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
"Toshiba TEMPRO"=c:\program files\Toshiba TEMPRO\TemproTray.exe
"HSON"=%ProgramFiles%\TOSHIBA\TBS\HSON.exe
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"topi"=c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b0,50,1d,6f,b7,30,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1783066571-3708218058-760853201-1000]
"EnableNotificationsRef"=dword:00000001

R0 rpcnetp;rpcnetp; [x]
R2 gupdate1ca054e2ff903e8;Služba Google Update (gupdate1ca054e2ff903e8);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\DRIVERS\Axtmvflt.sys [2007-03-22 3456]
R3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\DRIVERS\Axtmvmdm.sys [2007-03-26 40064]
R3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\Drivers\Axtmvprt.sys [2007-03-26 38784]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
R4 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-03-29 114984]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-03-29 134024]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-03-29 810120]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-02-26 41312]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-03-29 96896]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2008-01-15 48472]
S3 QIOMem;Generic IO & Memory Access;c:\windows\system32\DRIVERS\QIOMem.sys [2007-04-09 8192]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-06-30 c:\windows\Tasks\User_Feed_Synchronization-{06899141-CAEE-4AF6-ABB7-FD5CFD8BFDB4}.job
- c:\windows\system32\msfeedssync.exe [2010-06-11 04:30]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029
uInternet Settings,ProxyOverride = *.local
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?CZ
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/red ... &site=home
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?CZ
TCP: {0E164699-9B77-C0FE-23BB-4C770C3B53FE} = 62.141.0.1 213.162.65.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-InstallShield_{491DD193-1B57-4D1C-8B14-18B96992A89F} - c:\progra~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} - c:\progra~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{52573F8D-F099-4CB5-9EDE-5C27ECB4A02B} - c:\progra~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3} - c:\progra~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF} - c:\program files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe
AddRemove-InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E} - c:\progra~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{A6D4234C-CB02-4048-AC3E-AD09404FA35A} - c:\progra~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe
AddRemove-InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B} - c:\program files\InstallShield Installation Information\{C730E42C-935A-45BB-A0C5-37E5234D111B}\setup.exe
AddRemove-InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93} - c:\program files\InstallShield Installation Information\{DB780B85-B4B5-4864-A49C-9B706B169C93}\setup.exe
AddRemove-InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8} - c:\program files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe
AddRemove-{2290A680-4083-410A-ADCC-7092C67FC052} - c:\program files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe
AddRemove-{2492ACEF-8CB8-4AB7-8E60-4F89D701EAA1} - c:\program files\InstallShield Installation Information\{2492ACEF-8CB8-4AB7-8E60-4F89D701EAA1}\setup.exe
AddRemove-{37C866E4-AA67-4725-9E95-A39968DD7960} - c:\program files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe
AddRemove-{60DE4033-9503-48D1-A483-7846BD217CA9} - c:\program files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe
AddRemove-{6C5F3BDC-0A1B-4436-A696-5939629D5C31} - c:\program files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe
AddRemove-{78C6A78A-8B03-48C8-A47C-78BA1FCA2307} - c:\program files\InstallShield Installation Information\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}\setup.exe
AddRemove-{8833FFB6-5B0C-4764-81AA-06DFEED9A476} - c:\program files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe
AddRemove-{895722FE-25FE-4854-95AC-B0C42F9DBEDA} - c:\program files\InstallShield Installation Information\{895722FE-25FE-4854-95AC-B0C42F9DBEDA}\Install.exe
AddRemove-{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D} - c:\program files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe
AddRemove-{A644254B-92F6-4970-8635-AB0775371E72} - c:\program files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe
AddRemove-uTorrent - c:\program files\uTorrent\uTorrent.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-30 11:49
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1783066571-3708218058-760853201-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{232868A2-C9C1-273E-4921-1425EDAB9A86}*]
"paoehilhekbnnpffokcfnpmmfnkhpace"=hex:64,61,64,70,68,66,68,64,00,c5
"pakfdpgjaflhcdlojplfllcdilffdhom"=hex:69,61,70,6f,6e,66,69,67,62,6b,6e,69,66,
6f,66,70,68,67,00,00
"oaegjgnoihenibabhnlfpfclfocedf"=hex:69,61,70,6f,6e,66,69,67,62,6b,6e,69,66,6f,
66,70,68,67,00,00

[HKEY_USERS\S-1-5-21-1783066571-3708218058-760853201-1000_Classes\CLSID\{40f379ca-6384-4649-b34b-73fe2f580af2}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000e5
"Therad"=dword:00000028
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,2b,36,a2,df,c9,de,7b,8d,97,c1,1d,74,f7,a8,\

[HKEY_USERS\S-1-5-21-1783066571-3708218058-760853201-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):42,a4,ba,82,fe,f5,4f,d3,96,ba,2a,f5,f1,bd,fc,59,ac,81,08,fa,a4,
4e,bf,91,22,6e,72,28,6e,c9,b3,e5,f1,a1,36,71,5f,c4,b4,9b,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'lsass.exe'(704)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
.
Celkový čas: 2010-06-30 11:53:50
ComboFix-quarantined-files.txt 2010-06-30 09:53

Před spuštěním: Volných bajtů: 58 908 721 152
Po spuštění: Volných bajtů: 58 649 763 840

- - End Of File - - 1C4238686BB084C281F694D2A5EFBBEB

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15662
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Virus? Zdvojený kurzor myši, pomalý notebook

#4 Příspěvek od JaRon »

kedze pojdem na obed, dostanes zopar uloh :)
1, vycisti PC s MBAM
2. odinstaluj vsetky prebytocne antiSpy programy - nechaj iba jeden
3. vycisti PC s CCleanerom
4. restart a napis ako sa sprava PC ?
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět