

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Preventívka, divné súbory v tempe... -pre motji
Moderátor: Moderátoři
Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Re: Preventívka, divné súbory v tempe... -pre motji
Tak ho killnem
. už jsi dělal ten skript do OTL? Pokud ne, tak nedělej, napíšu Ti druhý

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka, divné súbory v tempe... -pre motji
Nie, ešte som ho nerobil. Ale ak by sa dalo, tak rýchlo pls 
Lebo oco už kričí že mám vypnuť PC

Lebo oco už kričí že mám vypnuť PC

Re: Preventívka, divné súbory v tempe... -pre motji
Tak to udělej až zítra.
Použij tento skript do OTL
Použij tento skript do OTL
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\ProgramData\ezsidmv.dat
C:\Windows\System32\nlmsprepu.dll
:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka, divné súbory v tempe... -pre motji
a mám Dať Run Scan ? alebo Fix ? alebo ktoré ? lebo to mám ENG jazyku
Re: Preventívka, divné súbory v tempe... -pre motji
fix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka, divné súbory v tempe... -pre motji
Nech sa páči:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//about.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Exclude.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//LanguageSelection.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Message.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//MyAgttryCmd.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//MyAgttryNag.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//MyNotification.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//NOCLessUpdate.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//quarantine.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//ScanNow.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//strings.vbs/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Template.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Update.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//VirFound.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafeeasap.com\betavscan\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafeeasap.com\vs\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafeeasap.com\www\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
ADS C:\ProgramData\TEMP:888AFB86 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1E13.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6584.tmp folder moved successfully.
C:\WINDOWS\Installer\MSI76CC.tmp moved successfully.
C:\WINDOWS\Installer\MSI9709.tmp moved successfully.
C:\WINDOWS\temp\Cab26D3.tmp moved successfully.
C:\WINDOWS\temp\CabAFD6.tmp moved successfully.
C:\WINDOWS\temp\CabB00B.tmp moved successfully.
C:\WINDOWS\temp\CabB8A4.tmp moved successfully.
C:\WINDOWS\temp\CabC62C.tmp moved successfully.
C:\WINDOWS\temp\NOD14FC.tmp moved successfully.
C:\WINDOWS\temp\NOD14FD.tmp moved successfully.
C:\WINDOWS\temp\NOD14FE.tmp moved successfully.
C:\WINDOWS\temp\NOD14FF.tmp moved successfully.
C:\WINDOWS\temp\NOD1500.tmp moved successfully.
C:\WINDOWS\temp\NOD1501.tmp moved successfully.
C:\WINDOWS\temp\NOD1502.tmp moved successfully.
C:\WINDOWS\temp\NOD1503.tmp moved successfully.
C:\WINDOWS\temp\NOD1504.tmp moved successfully.
C:\WINDOWS\temp\NOD1505.tmp moved successfully.
C:\WINDOWS\temp\NOD1506.tmp moved successfully.
C:\WINDOWS\temp\NOD1536.tmp moved successfully.
C:\WINDOWS\temp\NOD1537.tmp moved successfully.
C:\WINDOWS\temp\NOD1538.tmp moved successfully.
C:\WINDOWS\temp\NOD1539.tmp moved successfully.
C:\WINDOWS\temp\NOD153A.tmp moved successfully.
C:\WINDOWS\temp\NOD153B.tmp moved successfully.
C:\WINDOWS\temp\NOD153C.tmp moved successfully.
C:\WINDOWS\temp\NOD158B.tmp moved successfully.
C:\WINDOWS\temp\NOD158C.tmp moved successfully.
C:\WINDOWS\temp\NOD159D.tmp moved successfully.
C:\WINDOWS\temp\NOD159E.tmp moved successfully.
C:\WINDOWS\temp\NOD159F.tmp moved successfully.
C:\WINDOWS\temp\NOD15A0.tmp moved successfully.
C:\WINDOWS\temp\NOD15A1.tmp moved successfully.
C:\WINDOWS\temp\NOD15A2.tmp moved successfully.
C:\WINDOWS\temp\NOD15A3.tmp moved successfully.
C:\WINDOWS\temp\NOD15A4.tmp moved successfully.
C:\WINDOWS\temp\NOD15A5.tmp moved successfully.
C:\WINDOWS\temp\NOD15A6.tmp moved successfully.
C:\WINDOWS\temp\NOD15A7.tmp moved successfully.
C:\WINDOWS\temp\NOD15A8.tmp moved successfully.
C:\WINDOWS\temp\NOD15A9.tmp moved successfully.
C:\WINDOWS\temp\NOD15AA.tmp moved successfully.
C:\WINDOWS\temp\NOD15AB.tmp moved successfully.
C:\WINDOWS\temp\NOD15AC.tmp moved successfully.
C:\WINDOWS\temp\NOD461E.tmp moved successfully.
C:\WINDOWS\temp\NOD9961.tmp moved successfully.
C:\WINDOWS\temp\NODA2BD.tmp moved successfully.
C:\WINDOWS\temp\NODF3DE.tmp moved successfully.
C:\WINDOWS\temp\NODF3DF.tmp moved successfully.
C:\WINDOWS\temp\NODF3E0.tmp moved successfully.
C:\WINDOWS\temp\NODF3E1.tmp moved successfully.
C:\WINDOWS\temp\NODF3E2.tmp moved successfully.
C:\WINDOWS\temp\NODF3E3.tmp moved successfully.
C:\WINDOWS\temp\NODF3E4.tmp moved successfully.
C:\WINDOWS\temp\NODF3E5.tmp moved successfully.
C:\WINDOWS\temp\NODF3F6.tmp moved successfully.
C:\WINDOWS\temp\NODF3F7.tmp moved successfully.
C:\WINDOWS\temp\NODF3F8.tmp moved successfully.
C:\WINDOWS\temp\NODF3F9.tmp moved successfully.
C:\WINDOWS\temp\NODF3FA.tmp moved successfully.
C:\WINDOWS\temp\NODF3FB.tmp moved successfully.
C:\WINDOWS\temp\NODF3FC.tmp moved successfully.
C:\WINDOWS\temp\NODF3FD.tmp moved successfully.
C:\WINDOWS\temp\NODF40D.tmp moved successfully.
C:\WINDOWS\temp\NODF40E.tmp moved successfully.
C:\WINDOWS\temp\NODF40F.tmp moved successfully.
C:\WINDOWS\temp\NODF410.tmp moved successfully.
C:\WINDOWS\temp\NODF430.tmp moved successfully.
C:\WINDOWS\temp\NODF431.tmp moved successfully.
C:\WINDOWS\temp\NODF432.tmp moved successfully.
C:\WINDOWS\temp\NODF433.tmp moved successfully.
C:\WINDOWS\temp\NODF434.tmp moved successfully.
C:\WINDOWS\temp\NODF435.tmp moved successfully.
C:\WINDOWS\temp\NODF436.tmp moved successfully.
C:\WINDOWS\temp\NODF437.tmp moved successfully.
C:\WINDOWS\temp\NODF438.tmp moved successfully.
C:\WINDOWS\temp\NODF439.tmp moved successfully.
C:\WINDOWS\temp\NODF44A.tmp moved successfully.
C:\WINDOWS\temp\NODF44B.tmp moved successfully.
C:\WINDOWS\temp\NODF49A.tmp moved successfully.
C:\WINDOWS\temp\NODF49B.tmp moved successfully.
C:\WINDOWS\temp\NODF49C.tmp moved successfully.
C:\WINDOWS\temp\NODF49D.tmp moved successfully.
C:\WINDOWS\temp\NODF49E.tmp moved successfully.
C:\WINDOWS\temp\NODF49F.tmp moved successfully.
C:\WINDOWS\temp\NODF4A0.tmp moved successfully.
C:\WINDOWS\temp\NODF4A1.tmp moved successfully.
C:\WINDOWS\temp\NODF4A2.tmp moved successfully.
C:\WINDOWS\temp\NODF4A3.tmp moved successfully.
C:\WINDOWS\temp\NODF4A4.tmp moved successfully.
C:\WINDOWS\temp\NODF4A5.tmp moved successfully.
C:\WINDOWS\temp\NODF4A6.tmp moved successfully.
C:\WINDOWS\temp\NODF4A7.tmp moved successfully.
C:\WINDOWS\temp\NODF4A8.tmp moved successfully.
C:\WINDOWS\temp\NODF4A9.tmp moved successfully.
C:\WINDOWS\temp\NODF4AA.tmp moved successfully.
C:\WINDOWS\temp\NODF4AB.tmp moved successfully.
C:\WINDOWS\temp\NODF4AC.tmp moved successfully.
C:\WINDOWS\temp\NODF4AD.tmp moved successfully.
C:\WINDOWS\temp\NODF4AE.tmp moved successfully.
C:\WINDOWS\temp\NODF4AF.tmp moved successfully.
C:\WINDOWS\temp\NODF4B0.tmp moved successfully.
C:\WINDOWS\temp\NODF4B1.tmp moved successfully.
C:\WINDOWS\temp\NODF4B2.tmp moved successfully.
C:\WINDOWS\temp\NODF4B3.tmp moved successfully.
C:\WINDOWS\temp\NODF4B4.tmp moved successfully.
C:\WINDOWS\temp\NODF4B5.tmp moved successfully.
C:\WINDOWS\temp\NODF4B6.tmp moved successfully.
C:\WINDOWS\temp\NODF4B7.tmp moved successfully.
C:\WINDOWS\temp\NODF4B8.tmp moved successfully.
C:\WINDOWS\temp\NODF4B9.tmp moved successfully.
C:\WINDOWS\temp\Tar26D4.tmp moved successfully.
C:\WINDOWS\temp\TarAFD7.tmp moved successfully.
C:\WINDOWS\temp\TarB00C.tmp moved successfully.
C:\WINDOWS\temp\TarB8A5.tmp moved successfully.
C:\WINDOWS\temp\TarC62D.tmp moved successfully.
C:\ProgramData\ezsidmv.dat moved successfully.
C:\Windows\System32\nlmsprepu.dll moved successfully.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 52516 bytes
->Temporary Internet Files folder emptied: 6449500 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 99350626 bytes
->Flash cache emptied: 7691 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 14648 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 77167 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 4263406 bytes
Total Files Cleaned = 105.00 mb
[EMPTYFLASH]
User: Admin
->Flash cache emptied: 0 bytes
User: All Users
User: Default
User: Default User
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.20.6 log created on 02082011_213730
Files\Folders moved on Reboot...
File\Folder C:\Users\Admin\AppData\Local\Temp\WERF193.tmp.resp.erc.xml not found!
Registry entries deleted on Reboot...
Snáď to už neni také hrozné
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//about.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Exclude.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//LanguageSelection.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Message.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//MyAgttryCmd.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//MyAgttryNag.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//MyNotification.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//NOCLessUpdate.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//quarantine.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//ScanNow.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//strings.vbs/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Template.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//Update.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//VirFound.htm/\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafeeasap.com\betavscan\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafeeasap.com\vs\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafeeasap.com\www\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
ADS C:\ProgramData\TEMP:888AFB86 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1E13.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6584.tmp folder moved successfully.
C:\WINDOWS\Installer\MSI76CC.tmp moved successfully.
C:\WINDOWS\Installer\MSI9709.tmp moved successfully.
C:\WINDOWS\temp\Cab26D3.tmp moved successfully.
C:\WINDOWS\temp\CabAFD6.tmp moved successfully.
C:\WINDOWS\temp\CabB00B.tmp moved successfully.
C:\WINDOWS\temp\CabB8A4.tmp moved successfully.
C:\WINDOWS\temp\CabC62C.tmp moved successfully.
C:\WINDOWS\temp\NOD14FC.tmp moved successfully.
C:\WINDOWS\temp\NOD14FD.tmp moved successfully.
C:\WINDOWS\temp\NOD14FE.tmp moved successfully.
C:\WINDOWS\temp\NOD14FF.tmp moved successfully.
C:\WINDOWS\temp\NOD1500.tmp moved successfully.
C:\WINDOWS\temp\NOD1501.tmp moved successfully.
C:\WINDOWS\temp\NOD1502.tmp moved successfully.
C:\WINDOWS\temp\NOD1503.tmp moved successfully.
C:\WINDOWS\temp\NOD1504.tmp moved successfully.
C:\WINDOWS\temp\NOD1505.tmp moved successfully.
C:\WINDOWS\temp\NOD1506.tmp moved successfully.
C:\WINDOWS\temp\NOD1536.tmp moved successfully.
C:\WINDOWS\temp\NOD1537.tmp moved successfully.
C:\WINDOWS\temp\NOD1538.tmp moved successfully.
C:\WINDOWS\temp\NOD1539.tmp moved successfully.
C:\WINDOWS\temp\NOD153A.tmp moved successfully.
C:\WINDOWS\temp\NOD153B.tmp moved successfully.
C:\WINDOWS\temp\NOD153C.tmp moved successfully.
C:\WINDOWS\temp\NOD158B.tmp moved successfully.
C:\WINDOWS\temp\NOD158C.tmp moved successfully.
C:\WINDOWS\temp\NOD159D.tmp moved successfully.
C:\WINDOWS\temp\NOD159E.tmp moved successfully.
C:\WINDOWS\temp\NOD159F.tmp moved successfully.
C:\WINDOWS\temp\NOD15A0.tmp moved successfully.
C:\WINDOWS\temp\NOD15A1.tmp moved successfully.
C:\WINDOWS\temp\NOD15A2.tmp moved successfully.
C:\WINDOWS\temp\NOD15A3.tmp moved successfully.
C:\WINDOWS\temp\NOD15A4.tmp moved successfully.
C:\WINDOWS\temp\NOD15A5.tmp moved successfully.
C:\WINDOWS\temp\NOD15A6.tmp moved successfully.
C:\WINDOWS\temp\NOD15A7.tmp moved successfully.
C:\WINDOWS\temp\NOD15A8.tmp moved successfully.
C:\WINDOWS\temp\NOD15A9.tmp moved successfully.
C:\WINDOWS\temp\NOD15AA.tmp moved successfully.
C:\WINDOWS\temp\NOD15AB.tmp moved successfully.
C:\WINDOWS\temp\NOD15AC.tmp moved successfully.
C:\WINDOWS\temp\NOD461E.tmp moved successfully.
C:\WINDOWS\temp\NOD9961.tmp moved successfully.
C:\WINDOWS\temp\NODA2BD.tmp moved successfully.
C:\WINDOWS\temp\NODF3DE.tmp moved successfully.
C:\WINDOWS\temp\NODF3DF.tmp moved successfully.
C:\WINDOWS\temp\NODF3E0.tmp moved successfully.
C:\WINDOWS\temp\NODF3E1.tmp moved successfully.
C:\WINDOWS\temp\NODF3E2.tmp moved successfully.
C:\WINDOWS\temp\NODF3E3.tmp moved successfully.
C:\WINDOWS\temp\NODF3E4.tmp moved successfully.
C:\WINDOWS\temp\NODF3E5.tmp moved successfully.
C:\WINDOWS\temp\NODF3F6.tmp moved successfully.
C:\WINDOWS\temp\NODF3F7.tmp moved successfully.
C:\WINDOWS\temp\NODF3F8.tmp moved successfully.
C:\WINDOWS\temp\NODF3F9.tmp moved successfully.
C:\WINDOWS\temp\NODF3FA.tmp moved successfully.
C:\WINDOWS\temp\NODF3FB.tmp moved successfully.
C:\WINDOWS\temp\NODF3FC.tmp moved successfully.
C:\WINDOWS\temp\NODF3FD.tmp moved successfully.
C:\WINDOWS\temp\NODF40D.tmp moved successfully.
C:\WINDOWS\temp\NODF40E.tmp moved successfully.
C:\WINDOWS\temp\NODF40F.tmp moved successfully.
C:\WINDOWS\temp\NODF410.tmp moved successfully.
C:\WINDOWS\temp\NODF430.tmp moved successfully.
C:\WINDOWS\temp\NODF431.tmp moved successfully.
C:\WINDOWS\temp\NODF432.tmp moved successfully.
C:\WINDOWS\temp\NODF433.tmp moved successfully.
C:\WINDOWS\temp\NODF434.tmp moved successfully.
C:\WINDOWS\temp\NODF435.tmp moved successfully.
C:\WINDOWS\temp\NODF436.tmp moved successfully.
C:\WINDOWS\temp\NODF437.tmp moved successfully.
C:\WINDOWS\temp\NODF438.tmp moved successfully.
C:\WINDOWS\temp\NODF439.tmp moved successfully.
C:\WINDOWS\temp\NODF44A.tmp moved successfully.
C:\WINDOWS\temp\NODF44B.tmp moved successfully.
C:\WINDOWS\temp\NODF49A.tmp moved successfully.
C:\WINDOWS\temp\NODF49B.tmp moved successfully.
C:\WINDOWS\temp\NODF49C.tmp moved successfully.
C:\WINDOWS\temp\NODF49D.tmp moved successfully.
C:\WINDOWS\temp\NODF49E.tmp moved successfully.
C:\WINDOWS\temp\NODF49F.tmp moved successfully.
C:\WINDOWS\temp\NODF4A0.tmp moved successfully.
C:\WINDOWS\temp\NODF4A1.tmp moved successfully.
C:\WINDOWS\temp\NODF4A2.tmp moved successfully.
C:\WINDOWS\temp\NODF4A3.tmp moved successfully.
C:\WINDOWS\temp\NODF4A4.tmp moved successfully.
C:\WINDOWS\temp\NODF4A5.tmp moved successfully.
C:\WINDOWS\temp\NODF4A6.tmp moved successfully.
C:\WINDOWS\temp\NODF4A7.tmp moved successfully.
C:\WINDOWS\temp\NODF4A8.tmp moved successfully.
C:\WINDOWS\temp\NODF4A9.tmp moved successfully.
C:\WINDOWS\temp\NODF4AA.tmp moved successfully.
C:\WINDOWS\temp\NODF4AB.tmp moved successfully.
C:\WINDOWS\temp\NODF4AC.tmp moved successfully.
C:\WINDOWS\temp\NODF4AD.tmp moved successfully.
C:\WINDOWS\temp\NODF4AE.tmp moved successfully.
C:\WINDOWS\temp\NODF4AF.tmp moved successfully.
C:\WINDOWS\temp\NODF4B0.tmp moved successfully.
C:\WINDOWS\temp\NODF4B1.tmp moved successfully.
C:\WINDOWS\temp\NODF4B2.tmp moved successfully.
C:\WINDOWS\temp\NODF4B3.tmp moved successfully.
C:\WINDOWS\temp\NODF4B4.tmp moved successfully.
C:\WINDOWS\temp\NODF4B5.tmp moved successfully.
C:\WINDOWS\temp\NODF4B6.tmp moved successfully.
C:\WINDOWS\temp\NODF4B7.tmp moved successfully.
C:\WINDOWS\temp\NODF4B8.tmp moved successfully.
C:\WINDOWS\temp\NODF4B9.tmp moved successfully.
C:\WINDOWS\temp\Tar26D4.tmp moved successfully.
C:\WINDOWS\temp\TarAFD7.tmp moved successfully.
C:\WINDOWS\temp\TarB00C.tmp moved successfully.
C:\WINDOWS\temp\TarB8A5.tmp moved successfully.
C:\WINDOWS\temp\TarC62D.tmp moved successfully.
C:\ProgramData\ezsidmv.dat moved successfully.
C:\Windows\System32\nlmsprepu.dll moved successfully.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 52516 bytes
->Temporary Internet Files folder emptied: 6449500 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 99350626 bytes
->Flash cache emptied: 7691 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 14648 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 77167 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 4263406 bytes
Total Files Cleaned = 105.00 mb
[EMPTYFLASH]
User: Admin
->Flash cache emptied: 0 bytes
User: All Users
User: Default
User: Default User
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.20.6 log created on 02082011_213730
Files\Folders moved on Reboot...
File\Folder C:\Users\Admin\AppData\Local\Temp\WERF193.tmp.resp.erc.xml not found!
Registry entries deleted on Reboot...
Snáď to už neni také hrozné

-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka, divné súbory v tempe... -pre motji
Teraz už musím ísť off, zajtra vykonám ďalšie inštrukcie.
Dobrú noc a ďakujem za pomoc !
Dobrú noc a ďakujem za pomoc !

Re: Preventívka, divné súbory v tempe... -pre motji
Fajn, poprosím o nový log ze Rsitu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka, divné súbory v tempe... -pre motji
Prosím ťa drž ma, lebo odpadnem !!!
S PREPÁČENÍM
Ten vyjebaný NOD, mi až teraz zahlásil, že v ten zložke kde dal OTL je vírus !! (ten nlmsprepu.dll)
Keď mi skončí licencia prejdem budem na MSE alebo avast! alebo na Aviru ! Končim s NODOM!
RSIT bude dnes dodaný.
S PREPÁČENÍM
Ten vyjebaný NOD, mi až teraz zahlásil, že v ten zložke kde dal OTL je vírus !! (ten nlmsprepu.dll)
Keď mi skončí licencia prejdem budem na MSE alebo avast! alebo na Aviru ! Končim s NODOM!
RSIT bude dnes dodaný.
Re: Preventívka, divné súbory v tempe... -pre motji




Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka, divné súbory v tempe... -pre motji
Sorry, ale inými slovami som to vtedy opísať nemohol
.
A tiež sorry za neprítomnosť (zlé známky v škole = zaheslovanie PC do opravenia známky :/ )
log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2011-02-11 21:25:04
Microsoft Windows 7 Home Premium
System drive C: has 21 GB (41%) free of 50 GB
Total RAM: 2991 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:08, on 11. 2. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\windows\explorer.exe
D:\Program Files\Image-Line\FL Studio 9\FL.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\RSIT.exe
C:\windows\system32\DllHost.exe
C:\Program Files\trend micro\Admin.exe
C:\windows\system32\DllHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jumpstyle.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [DTRun] c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Hercules DJ Series] D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe /boot
O4 - HKLM\..\Run: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\system32\flcdlock.exe
O23 - Service: Hercules DJ Control MP3 (HerculesDJControlMP3) - Unknown owner - D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system32\uArcCapture.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
--
End of file - 11157 bytes
======Scheduled tasks folder======
C:\windows\tasks\HPCeeScheduleForAdmin.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-12-12 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-09-23 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-01-05 254520]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2009-12-16 8192]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-12-12 11265536]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-12-03 495711]
"DTRun"=c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2009-11-19 518656]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-06-25 98304]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-04-09 2029640]
"Hercules DJ Series"=D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe [2009-07-09 505128]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2010-08-23 1691192]
"Windows Mobile Device Center"=C:\windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-09-23 4240760]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-17 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-02-09 13:31:54 ----A---- C:\windows\system32\win32k.sys
2011-02-09 13:31:52 ----A---- C:\windows\system32\kerberos.dll
2011-02-09 13:31:49 ----A---- C:\windows\system32\jscript.dll
2011-02-09 13:31:48 ----A---- C:\windows\system32\vbscript.dll
2011-02-09 13:31:43 ----A---- C:\windows\system32\mshtml.dll
2011-02-09 13:31:29 ----A---- C:\windows\system32\msfeeds.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\mstime.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\mshtmled.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\msfeedssync.exe
2011-02-09 13:31:28 ----A---- C:\windows\system32\msfeedsbs.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\licmgr10.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\iertutil.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\iepeers.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\iedkcs32.dll
2011-02-09 13:31:24 ----A---- C:\windows\system32\atmlib.dll
2011-02-09 13:31:24 ----A---- C:\windows\system32\atmfd.dll
2011-02-09 13:31:23 ----A---- C:\windows\system32\ntdll.dll
2011-02-09 13:31:22 ----A---- C:\windows\system32\ntoskrnl.exe
2011-02-09 13:31:22 ----A---- C:\windows\system32\ntkrnlpa.exe
2011-02-09 13:31:18 ----A---- C:\windows\system32\upnp.dll
2011-02-09 13:31:17 ----A---- C:\windows\system32\urlmon.dll
2011-02-09 13:31:16 ----A---- C:\windows\system32\msxml6.dll
2011-02-09 13:31:15 ----A---- C:\windows\system32\wininet.dll
2011-02-09 13:31:15 ----A---- C:\windows\system32\msxml3.dll
2011-02-09 13:31:14 ----A---- C:\windows\system32\ieframe.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\wscsvc.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\wscapi.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\winhttp.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\WebClnt.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\slwga.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\davclnt.dll
2011-02-09 13:31:12 ----A---- C:\windows\system32\drivers\dxgmms1.sys
2011-02-08 21:37:30 ----D---- C:\_OTL
2011-02-07 17:07:25 ----D---- C:\windows\temp
2011-02-07 17:07:23 ----A---- C:\ComboFix.txt
2011-02-07 17:07:01 ----SHD---- C:\$RECYCLE.BIN
2011-02-07 17:04:44 ----A---- C:\windows\SWXCACLS.exe
2011-02-07 17:03:37 ----D---- C:\OTLko
2011-02-07 16:51:53 ----A---- C:\windows\ntbtlog.txt
2011-02-05 09:38:22 ----D---- C:\Users\Admin\AppData\Roaming\Malwarebytes
2011-02-05 09:38:18 ----D---- C:\ProgramData\Malwarebytes
2011-02-05 09:38:18 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2011-02-05 09:38:15 ----A---- C:\windows\system32\drivers\mbam.sys
2011-02-02 21:40:38 ----D---- C:\Program Files\Vstplugins
2011-01-29 11:42:50 ----A---- C:\pagesfile.sys
2011-01-18 19:21:14 ----D---- C:\Users\Admin\AppData\Roaming\Sony Creative Software
2011-01-12 14:04:13 ----A---- C:\windows\system32\FntCache.dll
2011-01-12 14:04:13 ----A---- C:\windows\system32\DWrite.dll
2011-01-12 14:04:13 ----A---- C:\windows\system32\d3d10warp.dll
2011-01-12 14:04:13 ----A---- C:\windows\system32\d2d1.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\XpsPrint.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\XpsGdiConverter.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2011-01-12 14:04:12 ----A---- C:\windows\system32\d3d10_1core.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\cdd.dll
2011-01-12 14:04:11 ----A---- C:\windows\system32\XpsRasterService.dll
2011-01-12 14:04:11 ----A---- C:\windows\system32\ExplorerFrame.dll
2011-01-12 14:04:11 ----A---- C:\windows\system32\d3d10_1.dll
2011-01-12 13:42:57 ----A---- C:\windows\system32\odbc32.dll
======List of files/folders modified in the last 1 months======
2011-02-11 21:25:06 ----D---- C:\Program Files\trend micro
2011-02-11 19:01:36 ----D---- C:\windows\System32
2011-02-11 19:01:36 ----D---- C:\windows\inf
2011-02-11 19:01:36 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-02-11 19:00:54 ----SHD---- C:\System Volume Information
2011-02-11 18:57:28 ----D---- C:\windows\system32\config
2011-02-11 18:57:26 ----D---- C:\ProgramData\HPQLOG
2011-02-11 18:57:23 ----A---- C:\windows\system32\log.txt
2011-02-09 17:36:33 ----D---- C:\windows\Prefetch
2011-02-09 17:35:55 ----D---- C:\windows\winsxs
2011-02-09 17:34:44 ----D---- C:\Program Files\Internet Explorer
2011-02-09 16:49:48 ----D---- C:\Users\Admin\AppData\Roaming\Skype
2011-02-09 16:49:43 ----AD---- C:\ProgramData\TEMP
2011-02-09 16:01:24 ----D---- C:\Users\Admin\AppData\Roaming\skypePM
2011-02-09 16:00:35 ----D---- C:\Temp
2011-02-09 14:11:34 ----D---- C:\ProgramData
2011-02-09 14:03:59 ----D---- C:\windows\system32\drivers
2011-02-09 13:31:57 ----D---- C:\windows\debug
2011-02-09 13:31:57 ----A---- C:\windows\system32\MRT.exe
2011-02-09 13:31:11 ----D---- C:\windows\system32\catroot
2011-02-09 13:31:10 ----D---- C:\windows\system32\catroot2
2011-02-08 21:38:09 ----D---- C:\windows\system32\drivers\etc
2011-02-08 21:37:38 ----SHD---- C:\windows\Installer
2011-02-07 17:07:25 ----D---- C:\Windows
2011-02-07 17:07:25 ----D---- C:\Qoobox
2011-02-07 17:06:27 ----A---- C:\windows\system.ini
2011-02-07 17:02:24 ----D---- C:\windows\Tasks
2011-02-07 17:01:35 ----D---- C:\Users\Admin\AppData\Roaming\hpqLog
2011-02-06 21:17:21 ----D---- C:\Users\Admin\AppData\Roaming\ICQ
2011-02-05 15:43:54 ----D---- C:\windows\AppPatch
2011-02-05 15:43:53 ----D---- C:\Program Files\Common Files
2011-02-04 14:14:49 ----D---- C:\Users\Admin\AppData\Roaming\Adobe
2011-02-04 14:14:49 ----D---- C:\ProgramData\Adobe
2011-02-02 21:40:38 ----RD---- C:\Program Files
2011-02-02 21:10:39 ----RSD---- C:\windows\assembly
2011-02-02 16:31:30 ----D---- C:\Users\Admin\AppData\Roaming\uTorrent
2011-01-29 18:40:35 ----D---- C:\Users\Admin\AppData\Roaming\Sony
2011-01-18 17:56:03 ----D---- C:\windows\system32\Tasks
2011-01-16 21:10:16 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-14 21:17:20 ----D---- C:\windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SafeBoot;SafeBoot; C:\windows\system32\drivers\SafeBoot.sys [2009-12-16 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-12-16 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-12-16 13256]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-08-08 691696]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
R1 mfehidk;McAfee Inc. mfehidk; C:\windows\system32\drivers\mfehidk.sys [2009-05-16 214024]
R1 mfetdik;McAfee Inc. mfetdik; C:\windows\system32\drivers\mfetdik.sys [2009-05-16 55336]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-12-16 40088]
R1 vmm;Virtual Machine Monitor; \??\C:\windows\system32\Drivers\vmm.sys [2010-11-26 229208]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 eamon;eamon; C:\windows\system32\DRIVERS\eamon.sys [2009-04-09 113960]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2009-04-09 133000]
R2 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2009-04-09 38240]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 Afc;PPdus ASPI Shell; C:\windows\system32\drivers\Afc.sys [2006-11-10 18688]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-06-18 210432]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 29824]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys [2010-05-06 108560]
R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2009-09-17 108072]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
R3 Epfwndis;Eset Personal Firewall; C:\windows\system32\DRIVERS\Epfwndis.sys [2009-04-09 33096]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-07-16 15872]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-12-19 1763968]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-12-03 423424]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-09-28 1303728]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 Bulk;HDJBulk; C:\windows\System32\Drivers\HDJBulk.sys [2009-07-08 126464]
S3 catchme;catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys []
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HDJMidi;DJ Control MP3 e2 MIDI; C:\windows\system32\DRIVERS\HDJMidi.sys [2009-07-08 124416]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 ksaud;Creative USB Audio Driver; C:\windows\system32\drivers\ksaud.sys [2009-08-05 886912]
S3 MfeAVFK;McAfee Inc. MfeAVFK; C:\windows\system32\drivers\MfeAVFK.sys [2009-05-16 79816]
S3 MfeBOPK;McAfee Inc. MfeBOPK; C:\windows\system32\drivers\MfeBOPK.sys [2009-05-16 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK; C:\windows\system32\drivers\MfeRKDK.sys [2009-05-16 34248]
S3 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 181792]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb Driver; C:\windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S4 Ipprgp;Ipprgp; C:\windows\system32\drivers\btwl2cap.sys [2009-09-17 29472]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe [2009-03-03 81920]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-06-18 176128]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-25 300808]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
R2 HerculesDJControlMP3;Hercules DJ Control MP3; D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE [2007-11-21 17408]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-11-15 126520]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-08-23 103992]
R2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-19 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-12-16 102968]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe [2010-01-08 81920]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-01-05 264248]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe [2009-12-03 229461]
R2 TeamViewer5;TeamViewer 5; D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 uArcCapture;ArcCapture; C:\windows\system32\uArcCapture.exe [2009-12-04 506472]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2010-10-14 751672]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-12-14 1639728]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-09-28 68096]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-04-09 20680]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\system32\flcdlock.exe [2009-11-17 362040]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-07-29 1343400]
-----------------EOF-----------------

A tiež sorry za neprítomnosť (zlé známky v škole = zaheslovanie PC do opravenia známky :/ )
log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2011-02-11 21:25:04
Microsoft Windows 7 Home Premium
System drive C: has 21 GB (41%) free of 50 GB
Total RAM: 2991 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:08, on 11. 2. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\windows\explorer.exe
D:\Program Files\Image-Line\FL Studio 9\FL.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\RSIT.exe
C:\windows\system32\DllHost.exe
C:\Program Files\trend micro\Admin.exe
C:\windows\system32\DllHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jumpstyle.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [DTRun] c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Hercules DJ Series] D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe /boot
O4 - HKLM\..\Run: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - D:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\system32\flcdlock.exe
O23 - Service: Hercules DJ Control MP3 (HerculesDJControlMP3) - Unknown owner - D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\system32\uArcCapture.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
--
End of file - 11157 bytes
======Scheduled tasks folder======
C:\windows\tasks\HPCeeScheduleForAdmin.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-12-12 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-12-03 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-09-23 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-01-05 254520]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2009-12-16 8192]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-12-12 11265536]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-12-03 495711]
"DTRun"=c:\Program Files\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2009-11-19 518656]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-06-25 98304]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-04-09 2029640]
"Hercules DJ Series"=D:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe [2009-07-09 505128]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2010-08-23 1691192]
"Windows Mobile Device Center"=C:\windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-09-23 4240760]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-17 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-02-09 13:31:54 ----A---- C:\windows\system32\win32k.sys
2011-02-09 13:31:52 ----A---- C:\windows\system32\kerberos.dll
2011-02-09 13:31:49 ----A---- C:\windows\system32\jscript.dll
2011-02-09 13:31:48 ----A---- C:\windows\system32\vbscript.dll
2011-02-09 13:31:43 ----A---- C:\windows\system32\mshtml.dll
2011-02-09 13:31:29 ----A---- C:\windows\system32\msfeeds.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\mstime.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\mshtmled.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\msfeedssync.exe
2011-02-09 13:31:28 ----A---- C:\windows\system32\msfeedsbs.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\licmgr10.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\iertutil.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\iepeers.dll
2011-02-09 13:31:28 ----A---- C:\windows\system32\iedkcs32.dll
2011-02-09 13:31:24 ----A---- C:\windows\system32\atmlib.dll
2011-02-09 13:31:24 ----A---- C:\windows\system32\atmfd.dll
2011-02-09 13:31:23 ----A---- C:\windows\system32\ntdll.dll
2011-02-09 13:31:22 ----A---- C:\windows\system32\ntoskrnl.exe
2011-02-09 13:31:22 ----A---- C:\windows\system32\ntkrnlpa.exe
2011-02-09 13:31:18 ----A---- C:\windows\system32\upnp.dll
2011-02-09 13:31:17 ----A---- C:\windows\system32\urlmon.dll
2011-02-09 13:31:16 ----A---- C:\windows\system32\msxml6.dll
2011-02-09 13:31:15 ----A---- C:\windows\system32\wininet.dll
2011-02-09 13:31:15 ----A---- C:\windows\system32\msxml3.dll
2011-02-09 13:31:14 ----A---- C:\windows\system32\ieframe.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\wscsvc.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\wscapi.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\winhttp.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\WebClnt.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\slwga.dll
2011-02-09 13:31:13 ----A---- C:\windows\system32\davclnt.dll
2011-02-09 13:31:12 ----A---- C:\windows\system32\drivers\dxgmms1.sys
2011-02-08 21:37:30 ----D---- C:\_OTL
2011-02-07 17:07:25 ----D---- C:\windows\temp
2011-02-07 17:07:23 ----A---- C:\ComboFix.txt
2011-02-07 17:07:01 ----SHD---- C:\$RECYCLE.BIN
2011-02-07 17:04:44 ----A---- C:\windows\SWXCACLS.exe
2011-02-07 17:03:37 ----D---- C:\OTLko
2011-02-07 16:51:53 ----A---- C:\windows\ntbtlog.txt
2011-02-05 09:38:22 ----D---- C:\Users\Admin\AppData\Roaming\Malwarebytes
2011-02-05 09:38:18 ----D---- C:\ProgramData\Malwarebytes
2011-02-05 09:38:18 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2011-02-05 09:38:15 ----A---- C:\windows\system32\drivers\mbam.sys
2011-02-02 21:40:38 ----D---- C:\Program Files\Vstplugins
2011-01-29 11:42:50 ----A---- C:\pagesfile.sys
2011-01-18 19:21:14 ----D---- C:\Users\Admin\AppData\Roaming\Sony Creative Software
2011-01-12 14:04:13 ----A---- C:\windows\system32\FntCache.dll
2011-01-12 14:04:13 ----A---- C:\windows\system32\DWrite.dll
2011-01-12 14:04:13 ----A---- C:\windows\system32\d3d10warp.dll
2011-01-12 14:04:13 ----A---- C:\windows\system32\d2d1.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\XpsPrint.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\XpsGdiConverter.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2011-01-12 14:04:12 ----A---- C:\windows\system32\d3d10_1core.dll
2011-01-12 14:04:12 ----A---- C:\windows\system32\cdd.dll
2011-01-12 14:04:11 ----A---- C:\windows\system32\XpsRasterService.dll
2011-01-12 14:04:11 ----A---- C:\windows\system32\ExplorerFrame.dll
2011-01-12 14:04:11 ----A---- C:\windows\system32\d3d10_1.dll
2011-01-12 13:42:57 ----A---- C:\windows\system32\odbc32.dll
======List of files/folders modified in the last 1 months======
2011-02-11 21:25:06 ----D---- C:\Program Files\trend micro
2011-02-11 19:01:36 ----D---- C:\windows\System32
2011-02-11 19:01:36 ----D---- C:\windows\inf
2011-02-11 19:01:36 ----A---- C:\windows\system32\PerfStringBackup.INI
2011-02-11 19:00:54 ----SHD---- C:\System Volume Information
2011-02-11 18:57:28 ----D---- C:\windows\system32\config
2011-02-11 18:57:26 ----D---- C:\ProgramData\HPQLOG
2011-02-11 18:57:23 ----A---- C:\windows\system32\log.txt
2011-02-09 17:36:33 ----D---- C:\windows\Prefetch
2011-02-09 17:35:55 ----D---- C:\windows\winsxs
2011-02-09 17:34:44 ----D---- C:\Program Files\Internet Explorer
2011-02-09 16:49:48 ----D---- C:\Users\Admin\AppData\Roaming\Skype
2011-02-09 16:49:43 ----AD---- C:\ProgramData\TEMP
2011-02-09 16:01:24 ----D---- C:\Users\Admin\AppData\Roaming\skypePM
2011-02-09 16:00:35 ----D---- C:\Temp
2011-02-09 14:11:34 ----D---- C:\ProgramData
2011-02-09 14:03:59 ----D---- C:\windows\system32\drivers
2011-02-09 13:31:57 ----D---- C:\windows\debug
2011-02-09 13:31:57 ----A---- C:\windows\system32\MRT.exe
2011-02-09 13:31:11 ----D---- C:\windows\system32\catroot
2011-02-09 13:31:10 ----D---- C:\windows\system32\catroot2
2011-02-08 21:38:09 ----D---- C:\windows\system32\drivers\etc
2011-02-08 21:37:38 ----SHD---- C:\windows\Installer
2011-02-07 17:07:25 ----D---- C:\Windows
2011-02-07 17:07:25 ----D---- C:\Qoobox
2011-02-07 17:06:27 ----A---- C:\windows\system.ini
2011-02-07 17:02:24 ----D---- C:\windows\Tasks
2011-02-07 17:01:35 ----D---- C:\Users\Admin\AppData\Roaming\hpqLog
2011-02-06 21:17:21 ----D---- C:\Users\Admin\AppData\Roaming\ICQ
2011-02-05 15:43:54 ----D---- C:\windows\AppPatch
2011-02-05 15:43:53 ----D---- C:\Program Files\Common Files
2011-02-04 14:14:49 ----D---- C:\Users\Admin\AppData\Roaming\Adobe
2011-02-04 14:14:49 ----D---- C:\ProgramData\Adobe
2011-02-02 21:40:38 ----RD---- C:\Program Files
2011-02-02 21:10:39 ----RSD---- C:\windows\assembly
2011-02-02 16:31:30 ----D---- C:\Users\Admin\AppData\Roaming\uTorrent
2011-01-29 18:40:35 ----D---- C:\Users\Admin\AppData\Roaming\Sony
2011-01-18 17:56:03 ----D---- C:\windows\system32\Tasks
2011-01-16 21:10:16 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-14 21:17:20 ----D---- C:\windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SafeBoot;SafeBoot; C:\windows\system32\drivers\SafeBoot.sys [2009-12-16 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-12-16 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-12-16 13256]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-08-08 691696]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
R1 mfehidk;McAfee Inc. mfehidk; C:\windows\system32\drivers\mfehidk.sys [2009-05-16 214024]
R1 mfetdik;McAfee Inc. mfetdik; C:\windows\system32\drivers\mfetdik.sys [2009-05-16 55336]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-12-16 40088]
R1 vmm;Virtual Machine Monitor; \??\C:\windows\system32\Drivers\vmm.sys [2010-11-26 229208]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 eamon;eamon; C:\windows\system32\DRIVERS\eamon.sys [2009-04-09 113960]
R2 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2009-04-09 133000]
R2 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2009-04-09 38240]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 Afc;PPdus ASPI Shell; C:\windows\system32\drivers\Afc.sys [2006-11-10 18688]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-06-18 210432]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2009-12-04 29824]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\windows\system32\drivers\AtiHdmi.sys [2010-05-06 108560]
R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2009-09-17 108072]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
R3 Epfwndis;Eset Personal Firewall; C:\windows\system32\DRIVERS\Epfwndis.sys [2009-04-09 33096]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-07-16 15872]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-12-19 1763968]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-12-03 423424]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-09-28 1303728]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2010-06-18 5586944]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 Bulk;HDJBulk; C:\windows\System32\Drivers\HDJBulk.sys [2009-07-08 126464]
S3 catchme;catchme; \??\C:\Users\Admin\AppData\Local\Temp\catchme.sys []
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HDJMidi;DJ Control MP3 e2 MIDI; C:\windows\system32\DRIVERS\HDJMidi.sys [2009-07-08 124416]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 ksaud;Creative USB Audio Driver; C:\windows\system32\drivers\ksaud.sys [2009-08-05 886912]
S3 MfeAVFK;McAfee Inc. MfeAVFK; C:\windows\system32\drivers\MfeAVFK.sys [2009-05-16 79816]
S3 MfeBOPK;McAfee Inc. MfeBOPK; C:\windows\system32\drivers\MfeBOPK.sys [2009-05-16 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK; C:\windows\system32\drivers\MfeRKDK.sys [2009-05-16 34248]
S3 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 181792]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb Driver; C:\windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S4 Ipprgp;Ipprgp; C:\windows\system32\drivers\btwl2cap.sys [2009-09-17 29472]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\aestsrv.exe [2009-03-03 81920]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-06-18 176128]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-25 300808]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
R2 HerculesDJControlMP3;Hercules DJ Control MP3; D:\Program Files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE [2007-11-21 17408]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-11-15 126520]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2010-08-23 103992]
R2 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-19 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-12-16 102968]
R2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe [2010-01-08 81920]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
R2 HpFkCryptService;Drive Encryption Service; c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-12-16 281192]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-12-12 297984]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-01-05 264248]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-06-17 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9fc8b38ddee9fbba\STacSV.exe [2009-12-03 229461]
R2 TeamViewer5;TeamViewer 5; D:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 uArcCapture;ArcCapture; C:\windows\system32\uArcCapture.exe [2009-12-04 506472]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2010-10-14 751672]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-12-14 1639728]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-09-28 68096]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-04-09 20680]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\system32\flcdlock.exe [2009-11-17 362040]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-07-29 1343400]
-----------------EOF-----------------
Re: Preventívka, divné súbory v tempe... -pre motji


Jak je na tom počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
-
- Vzorný návštěvník
- Příspěvky: 208
- Registrován: 07 čer 2010 17:54
- Bydliště: SK
- Kontaktovat uživatele:
Re: Preventívka, divné súbory v tempe... -pre motji
bez scriptu ?
Re: Preventívka, divné súbory v tempe... -pre motji
bez skriptu 

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.