Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Preventivka

#1 Příspěvek od ivankrato »

Logfile of random's system information tool 1.08 (written by random/random)
Run by Roman Kratochvíl at 2011-03-11 21:50:05
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 5 GB (11%) free of 50 GB
Total RAM: 3327 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:50:16, on 11.3.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
K:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\EXPERTool\TBPanel.exe
K:\Program Files\Samsung\Kies\KiesTrayAgent.exe
K:\PROGRA~1\MICROS~2\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
K:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\system32\spoolsv.exe
K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
L:\Program Files\XAMPP\xampp\apache\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dgdersvc.exe
C:\WINDOWS\system32\FsUsbExService.Exe
L:\Program Files\XAMPP\xampp\apache\bin\httpd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
K:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
L:\Program Files\XAMPP\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Skype\Phone\Skype.exe
K:\Program Files\Activision\Modern Warfare 2\mw2admintool.exe
C:\Program Files\Opera\opera.exe
K:\Program Files\World of Warcraft\Launcher.exe
C:\Documents and Settings\Roman Kratochvíl\Local Settings\Data aplikací\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\Roman Kratochvíl.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: HyperCam Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\HyperCam Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] "K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "L:\Program Files\sony ericsson\pcsuite\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [USBToolTip] K:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [aswAhAScr.dll] "C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe" "C:\Program Files\Alwil Software\Avast5\AhAScr.dll"
O4 - HKCU\..\Run: [GAINWARD] C:\Program Files\EXPERTool\TBPanel.exe /A
O4 - HKCU\..\Run: [KiesTrayAgent] K:\Program Files\Samsung\Kies\/\KiesTrayAgent.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "K:\PROGRA~1\MICROS~2\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [avast! Antivirus] C:\Program Files\Alwil Software\Avast5\AvastUI.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10m_Plugin.exe -update plugin
O4 - S-1-5-18 Startup: Picture Motion Browser Media Check Tool.lnk = L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: thg_clock.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Picture Motion Browser Media Check Tool.lnk = L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe (User 'Default user')
O4 - .DEFAULT Startup: thg_clock.exe (User 'Default user')
O4 - .DEFAULT Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: thg_clock.exe
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Link to &MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
O8 - Extra context menu item: Subscribe in Desktop Sidebar - res://C:\Program Files\Desktop Sidebar\sbhelp.dll/menuhandler.html
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - K:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - K:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - K:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - K:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - K:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.5.7.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{39202F08-1F8C-4236-B51E-00147A0BFA40}: NameServer = 10.255.255.10,10.255.255.20
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apache2.2 - Apache Software Foundation - L:\Program Files\XAMPP\xampp\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - L:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\WINDOWS\system32\dgdersvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate1c98ec4c25c7746) (gupdate1c98ec4c25c7746) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - K:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: MySQL - MySQL AB - L:\Program Files\XAMPP\xampp\mysql\bin\mysqld.exe
O23 - Service: MySQL501 - Unknown owner - K:\Program.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Procedure Call (TPM) (RPCT) - Unknown owner - C:\Program Files\Common Files\System\mstinit.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe

--
End of file - 13480 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\OGALogon.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 54248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45AD732C-2CE2-4666-B366-B2214AD57A49}]
Idea2 SidebarBrowserMonitor Class - C:\Program Files\Desktop Sidebar\sbhelp.dll [2004-09-04 233472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-11-24 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-11-24 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.2.dll [2009-05-18 1039000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EBE9E2B5-B526-48BC-AD46-687263EDCB0E}]
Kwyshell MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll [2004-12-03 100864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
SMTTB2009 Class - C:\Program Files\HyperCam Toolbar\tbcore3.dll [2010-02-16 2495488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - Kwyshell MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll [2004-12-03 100864]
{338B4DFE-2E2C-4338-9E41-E176D497299E} - HyperCam Toolbar - C:\Program Files\HyperCam Toolbar\tbcore3.dll [2010-02-16 2495488]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SteelSeries World of Warcraft MMO Gaming Mouse"=K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe [2010-12-23 1644032]
"SoundMAXPnP"=C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [2003-05-29 790528]
"Sony Ericsson PC Suite"=L:\Program Files\sony ericsson\pcsuite\Application Launcher\Application Launcher.exe [2005-10-26 159744]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2011-01-22 2548552]
"USBToolTip"=K:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2011-01-07 111208]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-01-07 13880424]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-11-04 1753192]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"aswAhAScr.dll"=C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe [2010-09-07 22016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GAINWARD"=C:\Program Files\EXPERTool\TBPanel.exe [2009-02-03 2181672]
"KiesTrayAgent"=K:\Program Files\Samsung\Kies\/\KiesTrayAgent.exe [2010-03-01 3404600]
"H/PC Connection Agent"=K:\PROGRA~1\MICROS~2\wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"avast! Antivirus"=C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2011-01-13 3396624]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\WINDOWS\system32\Macromed\Flash\FlashUtil10m_Plugin.exe [2011-02-13 234656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Místní vyhledávání.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Roman Kratochvíl^Nabídka Start^Programy^Po spuštění^nod32.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MySQL4"=2

C:\Documents and Settings\Roman Kratochvíl\Nabídka Start\Programy\Po spuštění
Picture Motion Browser Media Check Tool.lnk - L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe
thg_clock.exe
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoSecCpl"=0
"DisableChangePassword"=0
"DisableLockWorkstation"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoStartMenuPinnedList"=0
"NoStartMenuMFUprogramsList"=0
"NoStartMenuSubFolders"=0
"NoCommonGroups"=0
"NoPrinterTabs"=0
"NoDeletePrinter"=0
"NoAddPrinter"=0
"NoPrinters"=0
"NoFavoritesMenu"=0
"NoDrives"=0
"NoRecentDocsNetHood"=0
"NoChangeAnimation"=0
"NoChangeKeyboardNavigationIndicators"=0
"NoInstrumentation"=1
"NoDriveTypeAutoRun"=323
"MaxRecentDocs"=11
"NoUserNameInStartMenu"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\InterVideo\DVD7\WinDVD.exe"="C:\Program Files\InterVideo\DVD7\WinDVD.exe:*:Enabled:WinDVD"
"E:\Program Files\GOTCHA!\Gotcha.exe"="E:\Program Files\GOTCHA!\Gotcha.exe:*:Enabled:Gotcha!"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"L:\xampp\apache\bin\apache.exe"="L:\xampp\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"L:\Program Files\Azureus\Azureus.exe"="L:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"K:\Program Files\Unreal Tournament 3\Binaries\UT3.exe"="K:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:*:Enabled:Unreal Tournament 3"
"L:\Program Files\CyberLink\PowerDVD\PowerDVD.exe"="L:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"
"K:\Team17\Worms2\frontend.exe"="K:\Team17\Worms2\frontend.exe:*:Enabled:Worms 2 Frontend"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"L:\Program Files\Adobe\Adobe Photoshop CS3\dice_game_assets\photoproto.exe"="L:\Program Files\Adobe\Adobe Photoshop CS3\dice_game_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\Runtime Files\photoproto.exe"="L:\Program Files\Altia\PhotoProto\Runtime Files\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\kostky_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\kostky_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"E:\Program Files\worms 4\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE"="E:\Program Files\worms 4\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE:*:Enabled:Worms 4 Mayhem"
"L:\Program Files\Altia\PhotoProto\Atomovka_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\Atomovka_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\Nase_fotoalbum_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\Nase_fotoalbum_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"L:\Program Files\Altia\PhotoProto\mountfield1_assets\photoproto.exe"="L:\Program Files\Altia\PhotoProto\mountfield1_assets\photoproto.exe:*:Enabled:Altia PhotoProto Version 8.0.0.5"
"K:\Program Files\Warcraft III\Warcraft III.exe"="K:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"K:\Program Files\Autodesk\3ds Max 9\3dsmax.exe"="K:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit"
"C:\Program Files\Autodesk\Backburner\monitor.exe"="C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\Backburner\manager.exe"="C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\Backburner\server.exe"="C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"K:\Program Files\Outspark\Project Powder\Run.exe"="K:\Program Files\Outspark\Project Powder\Run.exe:*:Enabled:ProjectPowder"
"L:\Program Files\Gumboy Tournament\Gumboy Tournament.exe"="L:\Program Files\Gumboy Tournament\Gumboy Tournament.exe:*:Enabled:Gumboy Tournament"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"L:\Program Files\Microsoft Games\MechWarrior Vengeance\MW4.ICD"="L:\Program Files\Microsoft Games\MechWarrior Vengeance\MW4.ICD:*:Enabled:MechWarrior IV"
"L:\Program Files\Microsoft Games\MechWarrior Vengeance\mw4.exe"="L:\Program Files\Microsoft Games\MechWarrior Vengeance\mw4.exe:*:Enabled:MechWarrior IV"
"C:\xampp\apache\bin\apache.exe"="C:\xampp\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"L:\Program Files\TrackMania Sunrise\TmSunrise.exe"="L:\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Enabled:TmSunrise"
"\\Loznice\l\Program Files\TrackMania Sunrise\TmSunrise.exe"="\\Loznice\l\Program Files\TrackMania Sunrise\TmSunrise.exe:*:Enabled:TmSunrise"
"K:\Program Files\GameSpy\Comrade\Comrade.exe"="K:\Program Files\GameSpy\Comrade\Comrade.exe:*:Enabled:Comrade"
"K:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="K:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe"="K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe"="K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe"="K:\Program Files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:*:Enabled:Burnout(TM) Paradise The Ultimate Box"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"K:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe"="K:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:*:Enabled:Far Cry 2"
"K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe"="K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater"
"K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe"="K:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:*:Enabled:Editor"
"K:\Program Files\Steam\Steam.exe"="K:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"L:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="L:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaW.exe"="L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaW.exe:*:Enabled:Call of Duty(R) - World at War(TM) "
"L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaWmp.exe"="L:\Program Files\Activision\Call of Duty 5 - World at War\CoDWaWmp.exe:*:Enabled:Call of Duty(R) - World at War(TM) "
"K:\Program Files\Empire Interactive\FlatOut Ultimate Carnage\Fouc.exe"="K:\Program Files\Empire Interactive\FlatOut Ultimate Carnage\Fouc.exe:*:Enabled:FlatOut Ultimate Carnage"
"L:\Program Files\Dragon Age\bin_ship\daorigins.exe"="L:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Prameny Hra"
"L:\Program Files\Dragon Age\DAOriginsLauncher.exe"="L:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Prameny Spustit"
"L:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe"="L:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Prameny Aktualizovat"
"K:\Program Files\ICQ7.1\ICQ.exe"="K:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"K:\Program Files\ICQ7.1\aolload.exe"="K:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"K:\Program Files\Steam\steamapps\ivnakrato\dedicated server\hlds.exe"="K:\Program Files\Steam\steamapps\ivnakrato\dedicated server\hlds.exe:*:Enabled:Dedicated Server"
"K:\Program Files\Steam\steamapps\common\alien swarm\srcds.exe"="K:\Program Files\Steam\steamapps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server"
"L:\UDK\UDK-2010-08\Binaries\Win32\UDK.exe"="L:\UDK\UDK-2010-08\Binaries\Win32\UDK.exe:*:Enabled:UDK"
"K:\Program Files\Microsoft ActiveSync\rapimgr.exe"="K:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"K:\Program Files\Microsoft ActiveSync\wcescomm.exe"="K:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"K:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="K:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Common Files\Microsoft Shared\XNA\XnaTrans\v3.0\XnaTransX.exe"="C:\Program Files\Common Files\Microsoft Shared\XNA\XnaTrans\v3.0\XnaTransX.exe:LocalSubNet:Enabled:XNA Game Studio 3.1 Transport"
"K:\Program Files\Steam\steamapps\common\alien swarm\swarm.exe"="K:\Program Files\Steam\steamapps\common\alien swarm\swarm.exe:*:Enabled:Alien Swarm"
"L:\Program Files\Pinnacle\Studio 14\Programs\RM.exe"="L:\Program Files\Pinnacle\Studio 14\Programs\RM.exe:*:Enabled:Render Manager"
"L:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe"="L:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe:*:Enabled:Studio"
"L:\Program Files\Pinnacle\Studio 14\Programs\umi.exe"="L:\Program Files\Pinnacle\Studio 14\Programs\umi.exe:*:Enabled:umi"
"K:\Program Files\Steam\steamapps\ivnakrato\counter-strike\hl.exe"="K:\Program Files\Steam\steamapps\ivnakrato\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"K:\Program Files\Steam\steamapps\ivnakrato\condition zero\hl.exe"="K:\Program Files\Steam\steamapps\ivnakrato\condition zero\hl.exe:*:Enabled:Counter-Strike: Condition Zero"
"K:\Program Files\Steam\steamapps\ivnakrato\garrysmod\hl2.exe"="K:\Program Files\Steam\steamapps\ivnakrato\garrysmod\hl2.exe:*:Enabled:Garry's Mod"
"L:\Program Files\Electronic Arts\Crytek\Crysis 2 Demo\bin32\Crysis2Launcher.exe"="L:\Program Files\Electronic Arts\Crytek\Crysis 2 Demo\bin32\Crysis2Launcher.exe:*:Enabled:Crysis® 2 Demo"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"K:\Program Files\ICQ7.1\ICQ.exe"="K:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"K:\Program Files\ICQ7.1\aolload.exe"="K:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"K:\Program Files\Microsoft ActiveSync\rapimgr.exe"="K:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"K:\Program Files\Microsoft ActiveSync\wcescomm.exe"="K:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"K:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="K:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======File associations======

.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-03-11 21:50:05 ----D---- C:\rsit
2011-03-11 20:01:08 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-03-01 15:53:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\EA Core
2011-02-27 12:26:05 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\VBA-M
2011-02-23 14:24:37 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Toolbar4
2011-02-23 14:24:35 ----D---- C:\Program Files\HyperCam Toolbar

======List of files/folders modified in the last 1 months======

2011-03-11 21:50:11 ----D---- C:\WINDOWS\Prefetch
2011-03-11 21:50:06 ----D---- C:\Program Files\trend micro
2011-03-11 21:40:04 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Skype
2011-03-11 20:09:28 ----D---- C:\WINDOWS\temp
2011-03-11 20:01:08 ----D---- C:\WINDOWS\system32\drivers
2011-03-11 20:01:05 ----D---- C:\WINDOWS
2011-03-11 20:01:05 ----AD---- C:\WINDOWS\system32
2011-03-11 19:59:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-11 19:54:26 ----D---- C:\WINDOWS\system32\CatRoot2
2011-03-04 23:15:01 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-03-04 22:05:29 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Hamachi
2011-03-03 21:11:03 ----A---- C:\WINDOWS\#1 Video Converter.INI
2011-03-03 18:08:19 ----SHD---- C:\WINDOWS\Installer
2011-03-03 18:08:19 ----D---- C:\Config.Msi
2011-03-03 18:08:14 ----RD---- C:\Program Files\Skype
2011-03-03 18:08:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-03-02 20:14:34 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\ICQ
2011-03-02 15:24:16 ----A---- C:\WINDOWS\NeroDigital.ini
2011-03-01 21:51:51 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2011-03-01 15:53:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2011-03-01 15:51:40 ----D---- C:\WINDOWS\system32\DirectX
2011-03-01 15:51:38 ----HD---- C:\WINDOWS\inf
2011-02-23 21:33:59 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\vlc
2011-02-23 16:04:17 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-02-23 14:24:35 ----RD---- C:\Program Files
2011-02-21 20:23:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
2011-02-18 17:33:36 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Adobe
2011-02-16 20:09:21 ----D---- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\HLSW
2011-02-16 13:52:49 ----D---- C:\Program Files\Microsoft Silverlight
2011-02-13 21:50:23 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2005-04-25 159616]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 Inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\System32\DRIVERS\inspect.sys [2011-01-22 94784]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 Pnp680r;Silicon Image SiI 0680 Medley Raid Controller; C:\WINDOWS\system32\DRIVERS\pnp680r.sys [2002-05-31 76976]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-08-20 44944]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\WINDOWS\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-09-13 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-02-23 30680]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2011-01-22 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2011-01-22 27576]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 prodrv03;Star Force copy protection driver v3; C:\WINDOWS\System32\drivers\prodrv03.sys [2008-03-31 115968]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 sf;SFI Service; C:\WINDOWS\system32\drivers\sf.sys [2003-05-09 33248]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B}; \??\L:\Program Files\CyberLink\PowerDVD\000.fcl []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-02-23 102232]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2006-12-26 15440]
R2 TBPanel;TBPanel; C:\WINDOWS\system32\drivers\TBPanel.sys [2007-03-16 12256]
R3 dgderdrv;dgderdrv; C:\WINDOWS\System32\drivers\dgderdrv.sys [2010-02-04 18136]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2006-12-26 34760]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-08-17 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-10-12 4609024]
R3 Ma730Pt;MA730 Bluetooth VCOM Driver; C:\WINDOWS\system32\DRIVERS\Ma730Pt.sys [2005-12-22 102720]
R3 Ma730Vad;MA730 Bluetooth Audio; C:\WINDOWS\system32\DRIVERS\Ma730Vad.sys [2005-11-22 23376]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 Mo3Fltr;MMO Mouse; C:\WINDOWS\system32\drivers\Mo3Fltr.sys [2010-08-11 11136]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-01-08 9888672]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2007-05-05 47360]
R3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [2004-01-21 5915]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 PID_08A0;Labtec WebCam Pro(PID_08A0); C:\WINDOWS\system32\DRIVERS\LV302AV.SYS [2004-01-21 271360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-12 94592]
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-10-14 36484]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM); C:\WINDOWS\system32\DRIVERS\zebrceb.sys [2006-02-01 41792]
S1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-02-23 371544]
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter; \??\C:\WINDOWS\system32\drivers\NSDriver.sys []
S3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2003-03-14 100224]
S3 AgereSoftModem;Microcom InPorte Home; C:\WINDOWS\system32\DRIVERS\AGRSM.sys []
S3 arih3gp3;arih3gp3; C:\WINDOWS\system32\drivers\arih3gp3.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 Cardex;Cardex; \??\C:\WINDOWS\system32\drivers\TBPANEL.SYS []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DCamUSBEMPIA;USB 2861 Video; C:\WINDOWS\system32\DRIVERS\emDevice.sys [2005-10-29 169984]
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2003-03-04 145408]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 FiltUSBEMPIA;USB Device Lower Filter; C:\WINDOWS\system32\DRIVERS\emFilter.sys [2005-10-29 5248]
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\ROMANK~1\LOCALS~1\Temp\EGC1F8B.tmp []
S3 ggsemc;Sony Ericsson USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2006-03-01 8704]
S3 GMSIPCI;GMSIPCI; C:\WINDOWS\system32\drivers\GMSIPCI.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-06-03 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2005-06-03 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys [2005-06-03 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2005-06-03 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys [2005-06-03 79488]
S3 Love01;Love01; \??\E:\Ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys []
S3 MidiSyn;MidiSyn; C:\WINDOWS\system32\drivers\MidiSyn.sys [2002-09-20 235100]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MSICPL;MSICPL; C:\WINDOWS\system32\drivers\MSICPL.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-09-15 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-09-15 22016]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 8320]
S3 npkcrypt;npkcrypt; \??\K:\Program Files\Lineage II\system\npkcrypt.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\WINDOWS\system32\npptNT2.sys []
S3 NTACCESS;NTACCESS; C:\WINDOWS\system32\drivers\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 ScanUSBEMPIA;USB Still Image Capture Device; C:\WINDOWS\system32\DRIVERS\emScan.sys [2005-10-29 5120]
S3 SetupNTGLM7X;SetupNTGLM7X; C:\WINDOWS\system32\drivers\SetupNTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-06-02 578304]
S3 sony_ssm.sys;sony_ssm.sys; C:\WINDOWS\system32\drivers\sony_ssm.sys.sys []
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 SoRa01;SoRa01; \??\E:\Ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys []
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 syscom1;syscom1; \??\E:\Ivan\ostatni\XTK2175\XTK2175.sys []
S3 tap0901_2gm;VPN Anonymizer Adapter; C:\WINDOWS\system32\DRIVERS\tap0901_2gm.sys [2007-06-21 30720]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2008-09-15 8064]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2008-11-11 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2008-11-11 19968]
S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2008-11-11 24832]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2008-09-15 8064]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S3 XDva359;XDva359; \??\C:\WINDOWS\system32\XDva359.sys []
S3 XDva362;XDva362; \??\C:\WINDOWS\system32\XDva362.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apache2.2;Apache2.2; L:\Program Files\XAMPP\xampp\apache\bin\httpd.exe [2009-12-19 29416]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-10 116040]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-06-03 72704]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2011-01-22 1803224]
R2 dgdersvc;Device Error Recovery Service; C:\WINDOWS\system32\dgdersvc.exe [2010-02-04 95568]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-12-22 217088]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-12 153376]
R2 mi-raysat_3dsmax9_32;mental ray 3.5 Satellite (32-bit); K:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe [2006-09-29 65536]
R2 MySQL;MySQL; L:\Program Files\XAMPP\xampp\mysql\bin\mysqld.exe [2009-12-19 6095504]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2011-01-07 156776]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-02-03 75136]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2005-01-31 49152]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2007-09-03 122880]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate1c98ec4c25c7746;Služba Google Update (gupdate1c98ec4c25c7746); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-08-26 136176]
S2 RPCT;Remote Procedure Call (TPM); C:\Program Files\Common Files\System\mstinit.exe []
S3 aawservice;Ad-Aware 2007 Service; C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe [2007-06-05 561152]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; L:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-10-06 1045256]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MySQL501;MySQL501; K:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=K:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL501 []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-11-11 620544]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-10-09 360192]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-02-07 173616]
S4 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-10-09 603904]

-----------------EOF-----------------



Dekuji za kontrolu :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#2 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Preventivka

#3 Příspěvek od ivankrato »

Tak jsem zapnul Combofix, po dokonceni faze 50 se napsalo Mažu Soubory: a nahle modra smrt s napisem BAD_POOL_HEADER.
Divny je, ze se mi tohle stava pokazde, kdyz zapinam Combofix (samozrejme pouze kdyz mi to rekne nejaky radce :) )
Log neni nikde.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#4 Příspěvek od Rudy »

Zkuste to v nouz. režimu. CF někdy reaguje takto na něco, co se mu nelíbí.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Preventivka

#5 Příspěvek od ivankrato »

:arrow:
ComboFix 11-03-11.02 - Roman Kratochvíl 12.03.2011 14:28:28.15.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2934 [GMT 1:00]
Spuštěný z: c:\documents and settings\Roman Kratochvíl\Plocha\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\HyperCam Toolbar\tbHElper.dll
c:\windows\system32\midas.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-12 do 2011-03-12 )))))))))))))))))))))))))))))))
.
.
2011-03-11 20:50 . 2011-03-11 20:50 -------- d-----w- C:\rsit
2011-03-11 19:01 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-01 14:53 . 2011-03-01 14:53 -------- d-----w- c:\documents and settings\All Users\Data aplikací\EA Core
2011-02-27 11:26 . 2011-02-27 11:26 -------- d-----w- c:\documents and settings\Roman Kratochvíl\Data aplikací\VBA-M
2011-02-23 13:24 . 2011-02-23 13:24 -------- d-----w- c:\documents and settings\Roman Kratochvíl\Data aplikací\Toolbar4
2011-02-23 13:24 . 2011-03-12 13:36 -------- d-----w- c:\program files\HyperCam Toolbar
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-01 20:52 . 2007-11-13 14:20 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-03-01 20:51 . 2009-11-24 19:59 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-03-01 20:51 . 2007-11-13 14:19 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-03-01 20:50 . 2007-11-13 14:19 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-02-26 18:03 . 2009-02-08 15:15 2150 --sha-w- c:\documents and settings\All Users\Data aplikací\KGyGaAvL.sys
2011-02-23 15:04 . 2010-09-27 10:58 40648 ----a-w- c:\windows\avastSS.scr
2011-02-23 15:04 . 2010-09-27 10:58 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2010-09-27 10:58 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2010-09-27 10:58 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2010-09-27 10:58 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2010-09-27 10:58 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2010-09-27 10:58 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2010-09-27 10:58 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2010-09-27 10:58 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-09 13:53 . 2004-08-17 13:49 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-17 13:49 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-03 16:48 . 2007-11-13 14:19 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-02-02 07:58 . 2007-02-28 21:47 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2007-02-28 21:47 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-22 19:53 . 2010-09-10 21:41 285480 ----a-w- c:\windows\system32\guard32.dll
2011-01-22 19:53 . 2010-09-10 21:40 94784 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-01-22 19:53 . 2010-09-10 21:40 27576 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-01-22 19:53 . 2010-09-10 21:40 239368 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-01-22 19:53 . 2010-09-10 21:40 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-01-21 14:44 . 2004-08-17 13:49 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-08 03:27 . 2011-01-24 15:45 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-01-08 03:27 . 2011-01-24 15:45 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-01-08 03:27 . 2010-06-29 11:20 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-01-08 03:27 . 2010-06-29 11:20 13004800 ----a-w- c:\windows\system32\nvcompiler.dll
2011-01-08 03:27 . 2009-04-30 20:02 2916968 ----a-w- c:\windows\system32\nvcuvid.dll
2011-01-08 03:27 . 2009-04-30 20:02 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-01-08 03:27 . 2009-02-19 09:26 4980736 ----a-w- c:\windows\system32\nvcuda.dll
2011-01-08 03:27 . 2009-02-19 09:26 1958400 ----a-w- c:\windows\system32\nvapi.dll
2011-01-08 03:27 . 2009-02-19 09:26 14671872 ----a-w- c:\windows\system32\nvoglnt.dll
2011-01-08 03:27 . 2007-02-28 21:10 9888672 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-01-08 03:27 . 2007-02-28 21:10 6397824 ----a-w- c:\windows\system32\nv4_disp.dll
2011-01-07 18:58 . 2011-01-07 18:58 282624 ----a-w- c:\windows\system32\nvrsel.dll
2011-01-07 18:58 . 2011-01-07 18:58 274432 ----a-w- c:\windows\system32\nvrsesm.dll
2011-01-07 18:58 . 2011-01-07 18:58 253952 ----a-w- c:\windows\system32\nvrsth.dll
2011-01-07 18:58 . 2011-01-07 18:58 249856 ----a-w- c:\windows\system32\nvrseng.dll
2011-01-07 18:58 . 2011-01-07 18:58 126976 ----a-w- c:\windows\system32\nvrszht.dll
2011-01-07 18:58 . 2011-01-07 18:58 331776 ----a-w- c:\windows\system32\nvrshe.dll
2011-01-07 18:58 . 2011-01-07 18:58 286720 ----a-w- c:\windows\system32\nvrsfr.dll
2011-01-07 18:58 . 2011-01-07 18:58 274432 ----a-w- c:\windows\system32\nvrsnl.dll
2011-01-07 18:58 . 2011-01-07 18:58 270336 ----a-w- c:\windows\system32\nvrsru.dll
2011-01-07 18:58 . 2011-01-07 18:58 262144 ----a-w- c:\windows\system32\nvrshu.dll
2011-01-07 18:58 . 2011-01-07 18:58 258048 ----a-w- c:\windows\system32\nvrssl.dll
2011-01-07 18:58 . 2011-01-07 18:58 253952 ----a-w- c:\windows\system32\nvrsda.dll
2011-01-07 18:58 . 2011-01-07 18:58 249856 ----a-w- c:\windows\system32\nvrsfi.dll
2011-01-07 18:58 . 2011-01-07 18:58 229376 ----a-w- c:\windows\system32\nvrszhc.dll
2011-01-07 18:58 . 2011-01-07 18:58 335872 ----a-w- c:\windows\system32\nvrsar.dll
2011-01-07 18:58 . 2011-01-07 18:58 282624 ----a-w- c:\windows\system32\nvrses.dll
2011-01-07 18:58 . 2011-01-07 18:58 278528 ----a-w- c:\windows\system32\nvrsde.dll
2011-01-07 18:58 . 2011-01-07 18:58 270336 ----a-w- c:\windows\system32\nvrsptb.dll
2011-01-07 18:58 . 2011-01-07 18:58 266240 ----a-w- c:\windows\system32\nvrsko.dll
2011-01-07 18:58 . 2011-01-07 18:58 258048 ----a-w- c:\windows\system32\nvrstr.dll
2011-01-07 18:58 . 2011-01-07 18:58 258048 ----a-w- c:\windows\system32\nvrssk.dll
2011-01-07 18:58 . 2011-01-07 18:58 253952 ----a-w- c:\windows\system32\nvrssv.dll
2011-01-07 18:58 . 2011-01-07 18:58 253952 ----a-w- c:\windows\system32\nvrsno.dll
2011-01-07 18:58 . 2011-01-07 18:58 249856 ----a-w- c:\windows\system32\nvrscs.dll
2011-01-07 18:58 . 2011-01-07 18:58 282624 ----a-w- c:\windows\system32\nvrsit.dll
2011-01-07 18:58 . 2011-01-07 18:58 274432 ----a-w- c:\windows\system32\nvrspt.dll
2011-01-07 18:58 . 2011-01-07 18:58 270336 ----a-w- c:\windows\system32\nvrsja.dll
2011-01-07 18:58 . 2011-01-07 18:58 258048 ----a-w- c:\windows\system32\nvrspl.dll
2011-01-07 18:58 . 2011-01-07 18:58 81920 ----a-w- c:\windows\system32\nvwddi.dll
2011-01-07 18:58 . 2011-01-07 18:58 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-01-07 18:58 . 2011-01-07 18:58 277608 ----a-w- c:\windows\system32\nvmccs.dll
2011-01-07 18:58 . 2011-01-07 18:58 156776 ----a-w- c:\windows\system32\nvsvc32.exe
2011-01-07 18:58 . 2011-01-07 18:58 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-01-07 18:58 . 2011-01-07 18:58 13880424 ----a-w- c:\windows\system32\nvcpl.dll
2011-01-07 18:58 . 2011-01-07 18:58 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-01-07 14:09 . 2004-08-17 13:48 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2004-08-17 13:44 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-17 13:49 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:52 . 2004-08-17 13:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2004-08-17 13:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:52 . 2004-08-17 13:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 17:25 . 2004-08-17 13:49 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-08-17 13:44 385024 ----a-w- c:\windows\system32\html.iec
2007-08-02 10:56 . 2007-08-02 10:56 774144 ----a-w- c:\program files\RngInterstitial.dll
2003-06-16 13:35 . 2003-06-16 13:35 1216512 ----a-w- c:\program files\Img2ozf.exe
2003-02-01 22:00 . 2003-02-01 22:00 86356 ----a-w- c:\program files\unins000.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2008-12-24 18:18 73728 ------w- c:\windows\system32\VirtualExpander\VEShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesTrayAgent"="k:\program files\Samsung\Kies\" [X]
"GAINWARD"="c:\program files\EXPERTool\TBPanel.exe" [2009-02-03 2181672]
"avast! Antivirus"="c:\program files\Alwil Software\Avast5\AvastUI.exe" [2011-02-23 3451496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SteelSeries World of Warcraft MMO Gaming Mouse"="k:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe" [2010-12-23 1644032]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"Sony Ericsson PC Suite"="l:\program files\sony ericsson\pcsuite\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-22 2548552]
"USBToolTip"="k:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
.
c:\documents and settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - l:\program files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]
.
c:\documents and settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - l:\program files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]
.
c:\documents and settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - l:\program files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]
.
c:\documents and settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - l:\program files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"MaxRecentDocs"= 11 (0xb)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Místní vyhledávání.lnk]
backup=c:\windows\pss\Místní vyhledávání.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Roman Kratochvíl^Nabídka Start^Programy^Po spuštění^nod32.lnk]
backup=c:\windows\pss\nod32.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MySQL4"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Power2GoExpress"="k:\program files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" -silent
"Seznam Postak"="c:\program files\Seznam.cz\postak.exe" -s
"CamSpace"="k:\program files\CamSpace\CamSpaceAgent.exe"
"DAEMON Tools Lite"="k:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Recordpad"="c:\program files\NCH Swift Sound\Recordpad\recordpad.exe" -logon
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe"
"PCSuiteTrayApplication"=c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"e:\\Program Files\\GOTCHA!\\Gotcha.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"l:\\xampp\\apache\\bin\\apache.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"l:\\Program Files\\Azureus\\Azureus.exe"=
"k:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"l:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"k:\\Team17\\Worms2\\frontend.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"l:\\Program Files\\Adobe\\Adobe Photoshop CS3\\dice_game_assets\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\Runtime Files\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\kostky_assets\\photoproto.exe"=
"e:\\Program Files\\worms 4\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"l:\\Program Files\\Altia\\PhotoProto\\Atomovka_assets\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\Nase_fotoalbum_assets\\photoproto.exe"=
"l:\\Program Files\\Altia\\PhotoProto\\mountfield1_assets\\photoproto.exe"=
"k:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"k:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"k:\\Program Files\\Outspark\\Project Powder\\Run.exe"=
"l:\\Program Files\\Gumboy Tournament\\Gumboy Tournament.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"l:\\Program Files\\Microsoft Games\\MechWarrior Vengeance\\MW4.ICD"=
"l:\\Program Files\\Microsoft Games\\MechWarrior Vengeance\\mw4.exe"=
"c:\\xampp\\apache\\bin\\apache.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"l:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"\\\\Loznice\\l\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"k:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"k:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"k:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"k:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"k:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutParadise.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"k:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"k:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"k:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"k:\\Program Files\\Steam\\Steam.exe"=
"l:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"l:\\Program Files\\Activision\\Call of Duty 5 - World at War\\CoDWaW.exe"=
"l:\\Program Files\\Activision\\Call of Duty 5 - World at War\\CoDWaWmp.exe"=
"k:\\Program Files\\Empire Interactive\\FlatOut Ultimate Carnage\\Fouc.exe"=
"l:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"l:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"l:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"k:\\Program Files\\ICQ7.1\\ICQ.exe"=
"k:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"k:\\Program Files\\Steam\\steamapps\\ivnakrato\\dedicated server\\hlds.exe"=
"k:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\srcds.exe"=
"l:\\UDK\\UDK-2010-08\\Binaries\\Win32\\UDK.exe"=
"k:\program files\Microsoft ActiveSync\rapimgr.exe"= k:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"k:\program files\Microsoft ActiveSync\wcescomm.exe"= k:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"k:\program files\Microsoft ActiveSync\WCESMgr.exe"= k:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Opera\\opera.exe"=
"k:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\swarm.exe"=
"l:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"l:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"l:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"k:\\Program Files\\Steam\\steamapps\\ivnakrato\\counter-strike\\hl.exe"=
"k:\\Program Files\\Steam\\steamapps\\ivnakrato\\condition zero\\hl.exe"=
"k:\\Program Files\\Steam\\steamapps\\ivnakrato\\garrysmod\\hl2.exe"=
"l:\\Program Files\\Electronic Arts\\Crytek\\Crysis 2 Demo\\bin32\\Crysis2Launcher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14174:TCP"= 14174:TCP:BitComet 14174 TCP
"14174:UDP"= 14174:UDP:BitComet 14174 UDP
"2710:TCP"= 2710:TCP:BitComet 2710 TCP
"2710:UDP"= 2710:UDP:BitComet 2710 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"49000:TCP"= 49000:TCP:azures
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"57508:TCP"= 57508:TCP:Pando Media Booster
"57508:UDP"= 57508:UDP:Pando Media Booster
"3306:TCP"= 3306:TCP:MySQL Server
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [1.3.2007 16:56 159616]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [1.3.2007 16:56 5248]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R3 Mo3Fltr;MMO Mouse;c:\windows\system32\drivers\Mo3Fltr.sys [6.1.2011 20:38 11136]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.3.2009 20:26 691696]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11.3.2011 20:01 371544]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [27.9.2010 11:58 301528]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [10.9.2010 22:40 239368]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [10.9.2010 22:40 27576]
S1 prodrv03;Star Force copy protection driver v3;c:\windows\system32\drivers\prodrv03.sys [31.3.2008 16:02 115968]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 19:25 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 19:41 67656]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27.9.2010 11:58 19544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [4.2.2010 12:00 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [12.5.2010 13:04 217088]
S2 gupdate1c98ec4c25c7746;Služba Google Update (gupdate1c98ec4c25c7746);c:\program files\Google\Update\GoogleUpdate.exe [26.8.2010 18:00 136176]
S2 RPCM;Remote Procedure Manager(TPM); [x]
S2 RPCT;Remote Procedure Call (TPM);c:\program files\Common Files\System\mstinit.exe --> c:\program files\Common Files\System\mstinit.exe [?]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;l:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12.1.2010 18:34 25832]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [4.2.2010 12:00 18136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [12.5.2010 13:04 36640]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ROMANK~1\LOCALS~1\Temp\EGC1F8B.tmp --> c:\docume~1\ROMANK~1\LOCALS~1\Temp\EGC1F8B.tmp [?]
S3 Love01;Love01;\??\e:\ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys --> e:\ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys [?]
S3 Ma730Pt;MA730 Bluetooth VCOM Driver;c:\windows\system32\drivers\ma730pt.sys [23.3.2007 19:18 102720]
S3 Ma730Vad;MA730 Bluetooth Audio;c:\windows\system32\drivers\Ma730Vad.sys [23.3.2007 19:18 23376]
S3 MySQL501;MySQL501;"k:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="k:\program files\MySQL\MySQL Server 5.0\my.ini" MySQL501 --> k:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [1.5.2009 8:29 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [1.5.2009 8:29 8320]
S3 SetupNTGLM7X;SetupNTGLM7X; [x]
S3 SoRa01;SoRa01;\??\e:\ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys --> e:\ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys [?]
S3 syscom1;syscom1;\??\e:\ivan\ostatni\XTK2175\XTK2175.sys --> e:\ivan\ostatni\XTK2175\XTK2175.sys [?]
S3 tap0901_2gm;VPN Anonymizer Adapter;c:\windows\system32\drivers\tap0901_2gm.sys [21.6.2007 15:21 30720]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
S3 XDva359;XDva359;\??\c:\windows\system32\XDva359.sys --> c:\windows\system32\XDva359.sys [?]
S3 XDva362;XDva362;\??\c:\windows\system32\XDva362.sys --> c:\windows\system32\XDva362.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-12 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
.
2011-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-26 16:59]
.
2011-03-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-26 16:59]
.
2011-03-12 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://live.com/
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = local;*.local
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel
IE: Link to &MidpX - c:\program files\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
IE: Subscribe in Desktop Sidebar - c:\program files\Desktop Sidebar\sbhelp.dll/menuhandler.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - k:\program files\ICQ7.1\ICQ.exe
TCP: {39202F08-1F8C-4236-B51E-00147A0BFA40} = 10.255.255.10,10.255.255.20
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-12 14:36
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ROMANK~1\LOCALS~1\Temp\EGC1F8B.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL501]
"ImagePath"="\"k:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"k:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL501"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\l:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1960408961-1979792683-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1960408961-1979792683-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"="c:\\WINDOWS\\System32\\shell32.dll,15"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="c:\\WINDOWS\\system32\\SHELL32.dll,17"
"{208D2C60-3AEA-1069-A2D7-08002B30309D}"="c:\\WINDOWS\\system32\\SHELL32.dll,17"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="c:\\WINDOWS\\system32\\shell32.dll,22"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="c:\\WINDOWS\\system32\\shell32.dll,23"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="c:\\WINDOWS\\system32\\shell32.dll,24"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="c:\\WINDOWS\\system32\\shell32.dll,-175"
"{21EC2020-3AEA-1069-A2DD-08002B30309D}"="c:\\WINDOWS\\System32\\shell32.dll,-137"
"{2227A280-3AEA-1069-A2DE-08002B30309D}"="c:\\WINDOWS\\System32\\shell32.dll,-138"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="c:\\WINDOWS\\system32\\shell32.dll,38"
"AudioCD"="c:\\WINDOWS\\System32\\shell32.dll,40"
"{FBF23B42-E3F0-101B-8488-00AA003E56F8}"="c:\\WINDOWS\\system32\\shell32.dll,220"
"{450D8FBA-AD25-11D0-98A8-0800361B1103}"="c:\\WINDOWS\\system32\\mydocs.dll,0"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="c:\\WINDOWS\\system32\\main.cpl,10"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="c:\\WINDOWS\\system32\\wiashext.dll,0"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="c:\\WINDOWS\\system32\\mstask.dll,-100"
"{88C6C381-2E85-11D0-94DE-444553540000}"="c:\\WINDOWS\\System32\\occache.dll,0"
"{BDEADF00-C265-11d0-BCED-00A0C90AB50F}"="c:\\Program Files\\COMMON~1\\MICROS~1\\WEBFOL~1\\MSONSEXT.DLL,0"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="c:\\WINDOWS\\System32\\shdocvw.dll,-20785"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="c:\\WINDOWS\\System32\\webcheck.dll,0"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="c:\\WINDOWS\\system32\\syncui.dll,0"
.
[HKEY_USERS\S-1-5-21-1960408961-1979792683-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:06,d5,39,22,1e,1e,a1,73,d1,9e,ee,bc,c5,bb,c5,b1,14,76,bb,7f,bf,88,6a,
93,d7,40,1f,14,32,94,9f,5e,7e,b3,d4,45,25,6f,1b,c1,4c,8c,61,b8,70,b4,23,90,\
"??"=hex:f0,20,e4,8a,f4,16,40,03,25,ec,bd,c9,5e,e6,25,ce
.
[HKEY_USERS\S-1-5-21-1960408961-1979792683-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:8d,a1,f9,56,69,c4,8f,d4,a7,e4,28,81,ba,c5,24,db,73,78,a8,24,67,
7c,67,a2,6f,9a,cb,9a,66,07,f6,0b,37,1d,ed,6c,dc,35,db,90,0f,3f,9b,72,63,70,\
"rkeysecu"=hex:19,e2,15,05,0e,15,8b,bc,dc,12,a0,93,53,f7,51,a4
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(324)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Celkový čas: 2011-03-12 14:39:42
ComboFix-quarantined-files.txt 2011-03-12 13:39
.
Před spuštěním: 5 191 237 632
Po spuštění: 5 122 347 008
.
- - End Of File - - 403EF5098B09103329CE8B23AE616FFB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#6 Příspěvek od Rudy »

Ještě dočistíme. Otevřrte poznámkový blok a zkopírujte do něj:
Collect::
c:\windows\system32\XDva359.sys
c:\windows\system32\XDva362.sys

Driver::
XDva359
XDva362
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Preventivka

#7 Příspěvek od ivankrato »

Takze jsem script spustil radsi v nouzovem rezimu, asi pri fazy 3 script z plochy zmizel. Po dokonceni faze 50 se PC restartovalo do normalniho rezimu a CF psal, ze pripravuje log. Za chvili uz CF psal temer hotovo a pak BSOD s napisem BAD_POOL_HEADER. Po restartu neni log nikde...

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Preventivka

#8 Příspěvek od ivankrato »

Takze jsem nasel slozku C:/ComboFix a v ni nejaky ComboFix.txt. Vypadato jako log:

ComboFix 11-03-11.02 - Roman Kratochvíl 12.03.2011 19:44:31.16.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2937 [GMT 1:00]
Spuštěný z: C:\Documents and Settings\Roman Kratochvíl\Plocha\ComboFix.exe
Použité ovládací přepínače :: C:\Documents and Settings\Roman Kratochvíl\Plocha\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}


((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))



((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_XDVA359
-------\Legacy_XDVA362
-------\Service_XDva359
-------\Service_XDva362


((((((((((((((((((((((((( Soubory vytvořené od 2011-02-12 do 2011-03-12 )))))))))))))))))))))))))))))))


2011-03-11 20:50:05 . 2011-03-11 20:50:20 -------- d-----w- C:\rsit
2011-03-11 19:01:08 . 2011-02-23 14:56:55 371544 ----a-w- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-03-01 14:53:29 . 2011-03-01 14:53:29 -------- d-----w- C:\Documents and Settings\All Users\Data aplikací\EA Core
2011-02-27 11:26:05 . 2011-02-27 11:26:05 -------- d-----w- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\VBA-M
2011-02-23 13:24:37 . 2011-02-23 13:24:37 -------- d-----w- C:\Documents and Settings\Roman Kratochvíl\Data aplikací\Toolbar4
2011-02-23 13:24:35 . 2011-03-12 13:36:07 -------- d-----w- C:\Program Files\HyperCam Toolbar


(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))

2011-03-12 15:51:05 . 2007-11-13 14:20:02 138160 ----a-w- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2011-03-12 15:50:40 . 2009-11-24 19:59:47 271200 ----a-w- C:\WINDOWS\system32\PnkBstrB.xtr
2011-03-12 15:50:40 . 2007-11-13 14:19:49 271200 ----a-w- C:\WINDOWS\system32\PnkBstrB.exe
2011-03-01 20:51:51 . 2007-11-13 14:19:49 271200 ----a-w- C:\WINDOWS\system32\PnkBstrB.ex0
2011-02-26 18:03:10 . 2009-02-08 15:15:58 2150 --sha-w- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
2011-02-23 15:04:21 . 2010-09-27 10:58:26 40648 ----a-w- C:\WINDOWS\avastSS.scr
2011-02-23 15:04:17 . 2010-09-27 10:58:26 190016 ----a-w- C:\WINDOWS\system32\aswBoot.exe
2011-02-23 14:56:45 . 2010-09-27 10:58:43 301528 ----a-w- C:\WINDOWS\system32\drivers\aswSP.sys
2011-02-23 14:55:49 . 2010-09-27 10:58:40 49240 ----a-w- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-02-23 14:55:47 . 2010-09-27 10:58:38 102232 ----a-w- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-02-23 14:55:44 . 2010-09-27 10:58:38 96344 ----a-w- C:\WINDOWS\system32\drivers\aswmon.sys
2011-02-23 14:55:10 . 2010-09-27 10:58:42 25432 ----a-w- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-02-23 14:54:57 . 2010-09-27 10:58:37 30680 ----a-w- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-02-23 14:54:55 . 2010-09-27 10:58:44 19544 ----a-w- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-02-09 13:53:50 . 2004-08-17 13:49:18 270848 ----a-w- C:\WINDOWS\system32\sbe.dll
2011-02-09 13:53:50 . 2004-08-17 13:49:08 186880 ----a-w- C:\WINDOWS\system32\encdec.dll
2011-02-03 16:48:49 . 2007-11-13 14:19:46 75136 ----a-w- C:\WINDOWS\system32\PnkBstrA.exe
2011-02-02 07:58:33 . 2007-02-28 21:47:50 2067456 ----a-w- C:\WINDOWS\system32\mstscax.dll
2011-01-27 11:57:06 . 2007-02-28 21:47:50 677888 ----a-w- C:\WINDOWS\system32\mstsc.exe
2011-01-22 19:53:39 . 2010-09-10 21:41:40 285480 ----a-w- C:\WINDOWS\system32\guard32.dll
2011-01-22 19:53:39 . 2010-09-10 21:40:54 94784 ----a-w- C:\WINDOWS\system32\drivers\inspect.sys
2011-01-22 19:53:38 . 2010-09-10 21:40:52 27576 ----a-w- C:\WINDOWS\system32\drivers\cmdhlp.sys
2011-01-22 19:53:38 . 2010-09-10 21:40:52 239368 ----a-w- C:\WINDOWS\system32\drivers\cmdGuard.sys
2011-01-22 19:53:38 . 2010-09-10 21:40:48 15592 ----a-w- C:\WINDOWS\system32\drivers\cmderd.sys
2011-01-21 14:44:07 . 2004-08-17 13:49:18 440320 ----a-w- C:\WINDOWS\system32\shimgvw.dll
2011-01-08 03:27:00 . 2011-01-24 15:45:38 941160 ----a-w- C:\WINDOWS\system32\nvdispco322090.dll
2011-01-08 03:27:00 . 2011-01-24 15:45:38 837736 ----a-w- C:\WINDOWS\system32\nvgenco322040.dll
2011-01-08 03:27:00 . 2010-06-29 11:20:50 61440 ----a-w- C:\WINDOWS\system32\OpenCL.dll
2011-01-08 03:27:00 . 2010-06-29 11:20:48 13004800 ----a-w- C:\WINDOWS\system32\nvcompiler.dll
2011-01-08 03:27:00 . 2009-04-30 20:02:00 2916968 ----a-w- C:\WINDOWS\system32\nvcuvid.dll
2011-01-08 03:27:00 . 2009-04-30 20:02:00 2251368 ----a-w- C:\WINDOWS\system32\nvcuvenc.dll
2011-01-08 03:27:00 . 2009-02-19 09:26:38 4980736 ----a-w- C:\WINDOWS\system32\nvcuda.dll
2011-01-08 03:27:00 . 2009-02-19 09:26:38 1958400 ----a-w- C:\WINDOWS\system32\nvapi.dll
2011-01-08 03:27:00 . 2009-02-19 09:26:38 14671872 ----a-w- C:\WINDOWS\system32\nvoglnt.dll
2011-01-08 03:27:00 . 2007-02-28 21:10:33 9888672 ----a-w- C:\WINDOWS\system32\drivers\nv4_mini.sys
2011-01-08 03:27:00 . 2007-02-28 21:10:33 6397824 ----a-w- C:\WINDOWS\system32\nv4_disp.dll
2011-01-07 18:58:36 . 2011-01-07 18:58:36 282624 ----a-w- C:\WINDOWS\system32\nvrsel.dll
2011-01-07 18:58:36 . 2011-01-07 18:58:36 274432 ----a-w- C:\WINDOWS\system32\nvrsesm.dll
2011-01-07 18:58:36 . 2011-01-07 18:58:36 253952 ----a-w- C:\WINDOWS\system32\nvrsth.dll
2011-01-07 18:58:36 . 2011-01-07 18:58:36 249856 ----a-w- C:\WINDOWS\system32\nvrseng.dll
2011-01-07 18:58:36 . 2011-01-07 18:58:36 126976 ----a-w- C:\WINDOWS\system32\nvrszht.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 331776 ----a-w- C:\WINDOWS\system32\nvrshe.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 286720 ----a-w- C:\WINDOWS\system32\nvrsfr.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 274432 ----a-w- C:\WINDOWS\system32\nvrsnl.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 270336 ----a-w- C:\WINDOWS\system32\nvrsru.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 262144 ----a-w- C:\WINDOWS\system32\nvrshu.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 258048 ----a-w- C:\WINDOWS\system32\nvrssl.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 253952 ----a-w- C:\WINDOWS\system32\nvrsda.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 249856 ----a-w- C:\WINDOWS\system32\nvrsfi.dll
2011-01-07 18:58:34 . 2011-01-07 18:58:34 229376 ----a-w- C:\WINDOWS\system32\nvrszhc.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 335872 ----a-w- C:\WINDOWS\system32\nvrsar.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 282624 ----a-w- C:\WINDOWS\system32\nvrses.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 278528 ----a-w- C:\WINDOWS\system32\nvrsde.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 270336 ----a-w- C:\WINDOWS\system32\nvrsptb.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 266240 ----a-w- C:\WINDOWS\system32\nvrsko.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 258048 ----a-w- C:\WINDOWS\system32\nvrstr.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 258048 ----a-w- C:\WINDOWS\system32\nvrssk.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 253952 ----a-w- C:\WINDOWS\system32\nvrssv.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 253952 ----a-w- C:\WINDOWS\system32\nvrsno.dll
2011-01-07 18:58:32 . 2011-01-07 18:58:32 249856 ----a-w- C:\WINDOWS\system32\nvrscs.dll
2011-01-07 18:58:30 . 2011-01-07 18:58:30 282624 ----a-w- C:\WINDOWS\system32\nvrsit.dll
2011-01-07 18:58:30 . 2011-01-07 18:58:30 274432 ----a-w- C:\WINDOWS\system32\nvrspt.dll
2011-01-07 18:58:30 . 2011-01-07 18:58:30 270336 ----a-w- C:\WINDOWS\system32\nvrsja.dll
2011-01-07 18:58:30 . 2011-01-07 18:58:30 258048 ----a-w- C:\WINDOWS\system32\nvrspl.dll
2011-01-07 18:58:20 . 2011-01-07 18:58:20 81920 ----a-w- C:\WINDOWS\system32\nvwddi.dll
2011-01-07 18:58:14 . 2011-01-07 18:58:14 580200 ----a-w- C:\WINDOWS\system32\easyUpdatusAPIU.dll
2011-01-07 18:58:12 . 2011-01-07 18:58:12 277608 ----a-w- C:\WINDOWS\system32\nvmccs.dll
2011-01-07 18:58:12 . 2011-01-07 18:58:12 156776 ----a-w- C:\WINDOWS\system32\nvsvc32.exe
2011-01-07 18:58:12 . 2011-01-07 18:58:12 145000 ----a-w- C:\WINDOWS\system32\nvcolor.exe
2011-01-07 18:58:12 . 2011-01-07 18:58:12 13880424 ----a-w- C:\WINDOWS\system32\nvcpl.dll
2011-01-07 18:58:12 . 2011-01-07 18:58:12 111208 ----a-w- C:\WINDOWS\system32\nvmctray.dll
2011-01-07 14:09:02 . 2004-08-17 13:48:06 290048 ----a-w- C:\WINDOWS\system32\atmfd.dll
2010-12-31 14:04:07 . 2004-08-17 13:44:44 1854976 ----a-w- C:\WINDOWS\system32\win32k.sys
2010-12-22 12:34:22 . 2004-08-17 13:49:10 301568 ----a-w- C:\WINDOWS\system32\kerberos.dll
2010-12-20 23:52:37 . 2004-08-17 13:49:22 916480 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-12-20 23:52:36 . 2004-08-17 13:49:30 1469440 ------w- C:\WINDOWS\system32\inetcpl.cpl
2010-12-20 23:52:36 . 2004-08-17 13:49:10 43520 ----a-w- C:\WINDOWS\system32\licmgr10.dll
2010-12-20 17:25:50 . 2004-08-17 13:49:12 729088 ----a-w- C:\WINDOWS\system32\lsasrv.dll
2010-12-20 12:55:37 . 2004-08-17 13:44:08 385024 ----a-w- C:\WINDOWS\system32\html.iec
2007-08-02 10:56:49 . 2007-08-02 10:56:53 774144 ----a-w- C:\Program Files\RngInterstitial.dll
2003-06-16 13:35:19 . 2003-06-16 13:35:19 1216512 ----a-w- C:\Program Files\Img2ozf.exe
2003-02-01 22:00:00 . 2003-02-01 22:00:00 86356 ----a-w- C:\Program Files\unins000.exe


(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))


*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04:11 122512 ----a-w- C:\Program Files\Alwil Software\Avast5\ashShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 18:12:54 86280 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2008-12-24 18:18:37 73728 ------w- C:\WINDOWS\system32\VirtualExpander\VEShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesTrayAgent"="K:\Program Files\Samsung\Kies\" [X]
"GAINWARD"="C:\Program Files\EXPERTool\TBPanel.exe" [2009-02-03 15:28:24 2181672]
"avast! Antivirus"="C:\Program Files\Alwil Software\Avast5\AvastUI.exe" [2011-02-23 15:04:20 3451496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SteelSeries World of Warcraft MMO Gaming Mouse"="K:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe" [2010-12-23 13:26:38 1644032]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 14:28:32 790528]
"Sony Ericsson PC Suite"="L:\Program Files\sony ericsson\pcsuite\Application Launcher\Application Launcher.exe" [2005-10-26 14:17:24 159744]
"COMODO Internet Security"="C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" [2011-01-22 19:52:42 2548552]
"USBToolTip"="K:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 10:07:40 199752]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2011-01-07 18:58:12 111208]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2011-01-07 18:58:12 13880424]
"nwiz"="C:\Program Files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 07:51:42 1753192]

C:\Documents and Settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]

C:\Documents and Settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]

C:\Documents and Settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]

C:\Documents and Settings\Roman Kratochvˇl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - L:\Program Files\VolumeWatcher\SPUVolumeWatcher.exe [2008-4-19 344064]
thg_clock.exe [2007-11-19 49152]
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2008-12-24 474808]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"MaxRecentDocs"= 11 (0xb)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 17:13:36 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\Documents and Settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21:41 548352 ----a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Místní vyhledávání.lnk]
backup=C:\WINDOWS\pss\Místní vyhledávání.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Roman Kratochvíl^Nabídka Start^Programy^Po spuštění^nod32.lnk]
backup=C:\WINDOWS\pss\nod32.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MySQL4"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"Power2GoExpress"="K:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" -s
"CamSpace"="K:\Program Files\CamSpace\CamSpaceAgent.exe"
"DAEMON Tools Lite"="K:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Recordpad"="C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe" -logon
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"E:\\Program Files\\GOTCHA!\\Gotcha.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"L:\\xampp\\apache\\bin\\apache.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"L:\\Program Files\\Azureus\\Azureus.exe"=
"K:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"L:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"K:\\Team17\\Worms2\\frontend.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"L:\\Program Files\\Adobe\\Adobe Photoshop CS3\\dice_game_assets\\photoproto.exe"=
"L:\\Program Files\\Altia\\PhotoProto\\Runtime Files\\photoproto.exe"=
"L:\\Program Files\\Altia\\PhotoProto\\kostky_assets\\photoproto.exe"=
"E:\\Program Files\\worms 4\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"L:\\Program Files\\Altia\\PhotoProto\\Atomovka_assets\\photoproto.exe"=
"L:\\Program Files\\Altia\\PhotoProto\\Nase_fotoalbum_assets\\photoproto.exe"=
"L:\\Program Files\\Altia\\PhotoProto\\mountfield1_assets\\photoproto.exe"=
"K:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"K:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"C:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"K:\\Program Files\\Outspark\\Project Powder\\Run.exe"=
"L:\\Program Files\\Gumboy Tournament\\Gumboy Tournament.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"L:\\Program Files\\Microsoft Games\\MechWarrior Vengeance\\MW4.ICD"=
"L:\\Program Files\\Microsoft Games\\MechWarrior Vengeance\\mw4.exe"=
"C:\\xampp\\apache\\bin\\apache.exe"=
"C:\\totalcmd\\TOTALCMD.EXE"=
"L:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"\\\\Loznice\\l\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"K:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"K:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"K:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"K:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"K:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutParadise.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"K:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"K:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"K:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"K:\\Program Files\\Steam\\Steam.exe"=
"L:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"L:\\Program Files\\Activision\\Call of Duty 5 - World at War\\CoDWaW.exe"=
"L:\\Program Files\\Activision\\Call of Duty 5 - World at War\\CoDWaWmp.exe"=
"K:\\Program Files\\Empire Interactive\\FlatOut Ultimate Carnage\\Fouc.exe"=
"L:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"L:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"L:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"K:\\Program Files\\ICQ7.1\\ICQ.exe"=
"K:\\Program Files\\ICQ7.1\\aolload.exe"=
"C:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"K:\\Program Files\\Steam\\steamapps\\ivnakrato\\dedicated server\\hlds.exe"=
"K:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\srcds.exe"=
"L:\\UDK\\UDK-2010-08\\Binaries\\Win32\\UDK.exe"=
"K:\Program Files\Microsoft ActiveSync\rapimgr.exe"= K:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"K:\Program Files\Microsoft ActiveSync\wcescomm.exe"= K:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"K:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= K:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Opera\\opera.exe"=
"K:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\swarm.exe"=
"L:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"L:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"L:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"K:\\Program Files\\Steam\\steamapps\\ivnakrato\\counter-strike\\hl.exe"=
"K:\\Program Files\\Steam\\steamapps\\ivnakrato\\condition zero\\hl.exe"=
"K:\\Program Files\\Steam\\steamapps\\ivnakrato\\garrysmod\\hl2.exe"=
"L:\\Program Files\\Electronic Arts\\Crytek\\Crysis 2 Demo\\bin32\\Crysis2Launcher.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14174:TCP"= 14174:TCP:BitComet 14174 TCP
"14174:UDP"= 14174:UDP:BitComet 14174 UDP
"2710:TCP"= 2710:TCP:BitComet 2710 TCP
"2710:UDP"= 2710:UDP:BitComet 2710 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"49000:TCP"= 49000:TCP:azures
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"57508:TCP"= 57508:TCP:Pando Media Booster
"57508:UDP"= 57508:UDP:Pando Media Booster
"3306:TCP"= 3306:TCP:MySQL Server
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 a347bus;a347bus;C:\WINDOWS\system32\drivers\a347bus.sys [1.3.2007 16:56:41 159616]
R0 a347scsi;a347scsi;C:\WINDOWS\system32\drivers\a347scsi.sys [1.3.2007 16:56:41 5248]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys [5.7.2006 13:46:06 63352]
R0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [9.3.2009 20:26:44 691696]
R1 aswSnx;aswSnx;C:\WINDOWS\system32\drivers\aswSnx.sys [11.3.2011 20:01:08 371544]
R1 aswSP;aswSP;C:\WINDOWS\system32\drivers\aswSP.sys [27.9.2010 11:58:43 301528]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\WINDOWS\system32\drivers\cmdGuard.sys [10.9.2010 22:40:52 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\WINDOWS\system32\drivers\cmdhlp.sys [10.9.2010 22:40:52 27576]
R1 prodrv03;Star Force copy protection driver v3;C:\WINDOWS\system32\drivers\prodrv03.sys [31.3.2008 16:02:23 115968]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 19:25:48 12872]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 19:41:30 67656]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [27.9.2010 11:58:44 19544]
R2 dgdersvc;Device Error Recovery Service;C:\WINDOWS\system32\dgdersvc.exe [4.2.2010 12:00:26 95568]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [12.5.2010 13:04:53 217088]
R3 dgderdrv;dgderdrv;C:\WINDOWS\system32\drivers\dgderdrv.sys [4.2.2010 12:00:26 18136]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [12.5.2010 13:04:53 36640]
R3 Ma730Pt;MA730 Bluetooth VCOM Driver;C:\WINDOWS\system32\drivers\ma730pt.sys [23.3.2007 19:18:07 102720]
R3 Ma730Vad;MA730 Bluetooth Audio;C:\WINDOWS\system32\drivers\Ma730Vad.sys [23.3.2007 19:18:07 23376]
R3 Mo3Fltr;MMO Mouse;C:\WINDOWS\system32\drivers\Mo3Fltr.sys [6.1.2011 20:38:33 11136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16:28 130384]
S2 gupdate1c98ec4c25c7746;Služba Google Update (gupdate1c98ec4c25c7746);C:\Program Files\Google\Update\GoogleUpdate.exe [26.8.2010 18:00:15 136176]
S2 RPCM;Remote Procedure Manager(TPM); [x]
S2 RPCT;Remote Procedure Call (TPM);C:\Program Files\Common Files\System\mstinit.exe --> C:\Program Files\Common Files\System\mstinit.exe [?]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;L:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe [12.1.2010 18:34:29 25832]
S3 GarenaPEngine;GarenaPEngine;\??\C:\DOCUME~1\ROMANK~1\LOCALS~1\Temp\EGC1F8B.tmp --> C:\DOCUME~1\ROMANK~1\LOCALS~1\Temp\EGC1F8B.tmp [?]
S3 Love01;Love01;\??\E:\Ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys --> E:\Ivan\Love Engine0.3\Engine\Love Engine0.3\Loveliss.sys [?]
S3 MySQL501;MySQL501;"K:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="K:\Program Files\MySQL\MySQL Server 5.0\my.ini" MySQL501 --> K:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [1.5.2009 8:29:23 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [1.5.2009 8:29:28 8320]
S3 SetupNTGLM7X;SetupNTGLM7X; [x]
S3 SoRa01;SoRa01;\??\E:\Ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys --> E:\Ivan\Love Engine0.3\Engine\SoRa 2.6\SoRa.sys [?]
S3 syscom1;syscom1;\??\E:\Ivan\ostatni\XTK2175\XTK2175.sys --> E:\Ivan\ostatni\XTK2175\XTK2175.sys [?]
S3 tap0901_2gm;VPN Anonymizer Adapter;C:\WINDOWS\system32\drivers\tap0901_2gm.sys [21.6.2007 15:21:58 30720]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16:28 753504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

Obsah adresáře 'Naplánované úlohy'

2011-03-12 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36:18 . 2008-12-11 19:36:18]

2011-03-12 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-08-26 17:00:15 . 2010-08-26 16:59:38]

2011-03-12 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-08-26 17:00:15 . 2010-08-26 16:59:38]

2011-03-12 C:\WINDOWS\Tasks\OGALogon.job
- C:\WINDOWS\system32\OGAEXEC.exe [2009-08-03 13:07:42 . 2009-08-03 13:07:42]


------- Doplňkový sken -------

uStart Page = hxxp://live.com/
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = local;*.local
IE: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm
IE: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel
IE: Link to &MidpX - C:\Program Files\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
IE: Subscribe in Desktop Sidebar - C:\Program Files\Desktop Sidebar\sbhelp.dll/menuhandler.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - K:\Program Files\ICQ7.1\ICQ.exe
TCP: {39202F08-1F8C-4236-B51E-00147A0BFA40} = 10.255.255.10,10.255.255.20
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab


**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-12 19:58:20
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...


Vic nic.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#9 Příspěvek od Rudy »

Smazáno, log již vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ivankrato
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 77
Registrován: 13 bře 2009 14:08

Re: Preventivka

#10 Příspěvek od ivankrato »

V tom pripade dekuji :)
:worship:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivka

#11 Příspěvek od Rudy »

Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět