
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Vzorný návštěvník
- Příspěvky: 115
- Registrován: 30 bře 2011 16:41
- Kontaktovat uživatele:
Prosim o kontrolu
Prosim, o kontrolu ...dekuji
Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-03-30 18:03:33
Microsoft Windows 7 Home Premium
System drive C: has 24 GB (24%) free of 103 GB
Total RAM: 3071 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:03:44, on 30.3.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2207613
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - F:\download\Jeuties.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9805 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Soluto\soluto.exe" /userinit
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {161854F0-8304-4A88-BBC4-7B222CCF84F0}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Soluto\SolutoService.exe"
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe"
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/npn_with_spdy/ --channel=2068.02834180.170085916 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/npn_with_spdy/ --channel=2068.027ADA80.676379449 /prefetch:3 --ignored=" --type=renderer "
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=2068.0657CE00.803840999 /prefetch:4
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=2068.069C0E00.1381878079 /prefetch:4 --flash-broker=3916
C:\Windows\system32\wbem\wmiprvse.exe
"F:\download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE [2006-10-23 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update
2011-03-03 16:46:42 ----N---- C:\Windows\UniFISH.exe
======List of files/folders modified in the last 1 months======
2011-03-30 18:03:39 ----D---- C:\Windows\temp
2011-03-30 18:02:34 ----D---- C:\ProgramData\NVIDIA
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:53 ----D---- C:\Windows
2011-03-30 18:01:29 ----SHD---- C:\System Volume Information
2011-03-30 18:01:29 ----RD---- C:\Program Files (x86)
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 18:00:26 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-03-30 17:59:50 ----SHD---- C:\Windows\Installer
2011-03-30 17:58:47 ----D---- C:\Windows\SysWOW64
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:51:26 ----D---- C:\Windows\winsxs
2011-03-30 17:51:04 ----D---- C:\Windows\system32\config
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 16:02:58 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-30 15:53:06 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-25 00:14:42 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 23:00:23 ----D---- C:\ProgramData\Adobe
2011-03-23 22:57:32 ----D---- C:\Program Files (x86)\Adobe
2011-03-23 17:00:33 ----D---- C:\Windows\system32\NDF
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-20 21:23:59 ----D---- C:\Windows\Prefetch
2011-03-20 15:11:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer
2011-03-04 15:10:57 ----D---- C:\Program Files (x86)\ICQ7.4
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 as4bwim3;as4bwim3; C:\Windows\system32\drivers\as4bwim3.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-19 2011944]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S2 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-03-30 18:03:33
Microsoft Windows 7 Home Premium
System drive C: has 24 GB (24%) free of 103 GB
Total RAM: 3071 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:03:44, on 30.3.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2207613
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - F:\download\Jeuties.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9805 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Soluto\soluto.exe" /userinit
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {161854F0-8304-4A88-BBC4-7B222CCF84F0}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Soluto\SolutoService.exe"
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe"
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/npn_with_spdy/ --channel=2068.02834180.170085916 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/DnsParallelism/parallel_7/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin16/SpdyImpact/npn_with_spdy/ --channel=2068.027ADA80.676379449 /prefetch:3 --ignored=" --type=renderer "
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=2068.0657CE00.803840999 /prefetch:4
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=2068.069C0E00.1381878079 /prefetch:4 --flash-broker=3916
C:\Windows\system32\wbem\wmiprvse.exe
"F:\download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE [2006-10-23 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update
2011-03-03 16:46:42 ----N---- C:\Windows\UniFISH.exe
======List of files/folders modified in the last 1 months======
2011-03-30 18:03:39 ----D---- C:\Windows\temp
2011-03-30 18:02:34 ----D---- C:\ProgramData\NVIDIA
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:53 ----D---- C:\Windows
2011-03-30 18:01:29 ----SHD---- C:\System Volume Information
2011-03-30 18:01:29 ----RD---- C:\Program Files (x86)
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 18:00:26 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-03-30 17:59:50 ----SHD---- C:\Windows\Installer
2011-03-30 17:58:47 ----D---- C:\Windows\SysWOW64
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:51:26 ----D---- C:\Windows\winsxs
2011-03-30 17:51:04 ----D---- C:\Windows\system32\config
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 16:02:58 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-30 15:53:06 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-25 00:14:42 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 23:00:23 ----D---- C:\ProgramData\Adobe
2011-03-23 22:57:32 ----D---- C:\Program Files (x86)\Adobe
2011-03-23 17:00:33 ----D---- C:\Windows\system32\NDF
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-20 21:23:59 ----D---- C:\Windows\Prefetch
2011-03-20 15:11:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer
2011-03-04 15:10:57 ----D---- C:\Program Files (x86)\ICQ7.4
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 as4bwim3;as4bwim3; C:\Windows\system32\drivers\as4bwim3.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-19 2011944]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S2 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: Prosim o kontrolu
Zdravím, tyhle zbytečnosti fixni v HJT :
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2207613
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
HJT najdeš zde :
C:\Program Files\trend micro\Michal.exe
Fix znamená že spustíš HJT
jako admin
v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Odinstaluj ICQ6Toolbar
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Jinak nic špatného nevidím.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2207613
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
HJT najdeš zde :
C:\Program Files\trend micro\Michal.exe
Fix znamená že spustíš HJT

v okně které se ti otevře klikneš na Do a system scan only
v dalším okně najdeš řádky které jsem ti vypsal,
vedle nich je čtvereček do kterého uděláš zatržítko,
pak klikneš na Fix checked které je vlevo dole,
program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.
Odinstaluj ICQ6Toolbar
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Jinak nic špatného nevidím.
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Prosim o kontrolu
neni zbytecny i skype toolsbar a plugin v IE? 

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
-
- Vzorný návštěvník
- Příspěvky: 115
- Registrován: 30 bře 2011 16:41
- Kontaktovat uživatele:
Re: Prosim o kontrolu
jj odpoledne to fixnu ... dik



- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Prosim o kontrolu
Roli píše:Je, ale není to takové zlo jako ICQ6Toolbarchodnik74 píše:neni zbytecny i skype toolsbar a plugin v IE?
Jasny


jinak neni zbytecna i sluzba:
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Prosim o kontrolu
chodnik74 píše:jinak neni zbytecna i sluzba:
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
No pokud se používá jako prohlížeč Chrome, tak by měla zůstat spuštěná.
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Prosim o kontrolu
Ja ji mel taky spustenou a tady v preventivkach mam take log a admin mi ji radil vypnout,ze je zbytecna..ze se i bez ni aktualizuje sam =)
Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
Re: Prosim o kontrolu
To jo jenže ona se většinou spustí znovu.chodnik74 píše:Ja ji mel taky spustenou a tady v preventivkach mam take log a admin mi ji radil vypnout,ze je zbytecna..ze se i bez ni aktualizuje sam =)
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Prosim o kontrolu
jakoze ikdyz ji zakazu rucne tak se sama znova obnovi 

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2
-
- Vzorný návštěvník
- Příspěvky: 115
- Registrován: 30 bře 2011 16:41
- Kontaktovat uživatele:
Re: Prosim o kontrolu
Zde přikládám log po provedených změnách. Prosím o kontrolu tohoto logu ... děkuji
Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-04-04 15:33:48
Microsoft Windows 7 Home Premium
System drive C: has 23 GB (22%) free of 103 GB
Total RAM: 3071 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:33:50, on 4.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\CCleaner\CCleaner.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9351 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {646FC814-C724-4A13-A221-F518D8764494}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Program Files (x86)\CCleaner\CCleaner.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02261600.629724800 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.021FD900.822386861 /prefetch:3 --ignored=" --type=renderer "
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.0689F000.1598941708 /prefetch:4
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.06854C00.1114752745 /prefetch:4 --flash-broker=312
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.0A18AD80.1464293168 /prefetch:3
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
"F:\download\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-04-03 00:16:10 ----D---- C:\Program Files (x86)\GIANTS Software
2011-04-02 16:25:01 ----D---- C:\Program Files (x86)\Landwirtschafts Simulator 2011
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update
======List of files/folders modified in the last 1 months======
2011-04-04 15:33:39 ----D---- C:\Windows\system32\config
2011-04-04 15:32:49 ----D---- C:\Windows
2011-04-04 15:32:48 ----D---- C:\Windows\temp
2011-04-04 15:30:33 ----D---- C:\ProgramData\NVIDIA
2011-04-04 15:21:42 ----SHD---- C:\Windows\Installer
2011-04-04 15:20:51 ----D---- C:\Windows\SysWOW64
2011-04-04 15:17:51 ----D---- C:\Windows\Prefetch
2011-04-03 21:07:31 ----D---- C:\ProgramData\Adobe
2011-04-03 15:14:39 ----D---- C:\Windows\winsxs
2011-04-03 15:07:13 ----SD---- C:\Users\Michal\AppData\Roaming\Microsoft
2011-04-03 15:05:29 ----SHD---- C:\System Volume Information
2011-04-03 15:05:19 ----D---- C:\Program Files (x86)\Adobe
2011-04-03 00:16:10 ----RD---- C:\Program Files (x86)
2011-04-02 22:17:26 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-04-01 20:45:39 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-04-01 17:40:00 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-31 21:07:38 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-31 17:22:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-30 20:26:54 ----D---- C:\Windows\system32\NDF
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 awlgqige;awlgqige; C:\Windows\system32\drivers\awlgqige.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-04-04 15:33:48
Microsoft Windows 7 Home Premium
System drive C: has 23 GB (22%) free of 103 GB
Total RAM: 3071 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:33:50, on 4.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\CCleaner\CCleaner.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9351 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {646FC814-C724-4A13-A221-F518D8764494}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
"C:\Program Files (x86)\CCleaner\CCleaner.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02261600.629724800 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.021FD900.822386861 /prefetch:3 --ignored=" --type=renderer "
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.0689F000.1598941708 /prefetch:4
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.06854C00.1114752745 /prefetch:4 --flash-broker=312
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.0A18AD80.1464293168 /prefetch:3
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
"F:\download\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-04-03 00:16:10 ----D---- C:\Program Files (x86)\GIANTS Software
2011-04-02 16:25:01 ----D---- C:\Program Files (x86)\Landwirtschafts Simulator 2011
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update
======List of files/folders modified in the last 1 months======
2011-04-04 15:33:39 ----D---- C:\Windows\system32\config
2011-04-04 15:32:49 ----D---- C:\Windows
2011-04-04 15:32:48 ----D---- C:\Windows\temp
2011-04-04 15:30:33 ----D---- C:\ProgramData\NVIDIA
2011-04-04 15:21:42 ----SHD---- C:\Windows\Installer
2011-04-04 15:20:51 ----D---- C:\Windows\SysWOW64
2011-04-04 15:17:51 ----D---- C:\Windows\Prefetch
2011-04-03 21:07:31 ----D---- C:\ProgramData\Adobe
2011-04-03 15:14:39 ----D---- C:\Windows\winsxs
2011-04-03 15:07:13 ----SD---- C:\Users\Michal\AppData\Roaming\Microsoft
2011-04-03 15:05:29 ----SHD---- C:\System Volume Information
2011-04-03 15:05:19 ----D---- C:\Program Files (x86)\Adobe
2011-04-03 00:16:10 ----RD---- C:\Program Files (x86)
2011-04-02 22:17:26 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-04-01 20:45:39 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-04-01 17:40:00 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-31 21:07:38 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-31 17:22:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-30 20:26:54 ----D---- C:\Windows\system32\NDF
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 awlgqige;awlgqige; C:\Windows\system32\drivers\awlgqige.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: Prosim o kontrolu
ICQ Toolbar tam sice není ale ten fix nějak nevyšel.
Tak zkus znovu tohle fixnout :
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
jak na to jsem již psal.
Ještě bych rád kdybys použil Mbam z mého podpisu a del mi sem z něj log, předem nic nemazat !!!
Tak zkus znovu tohle fixnout :
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
jak na to jsem již psal.
Ještě bych rád kdybys použil Mbam z mého podpisu a del mi sem z něj log, předem nic nemazat !!!
-
- Vzorný návštěvník
- Příspěvky: 115
- Registrován: 30 bře 2011 16:41
- Kontaktovat uživatele:
Re: Prosim o kontrolu
takže log po fixnutí:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-04-04 16:32:08
Microsoft Windows 7 Home Premium
System drive C: has 23 GB (22%) free of 103 GB
Total RAM: 3071 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:32:12, on 4.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9180 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {646FC814-C724-4A13-A221-F518D8764494}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02261600.629724800 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.021FD900.822386861 /prefetch:3 --ignored=" --type=renderer "
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.0689F000.1598941708 /prefetch:4
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.06854C00.1114752745 /prefetch:4 --flash-broker=312
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02287600.666679802 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.0A5ED480.448304604 /prefetch:3
taskeng.exe {7C714F3B-6716-4D6F-B6B9-8BFFBE99265D}
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe /c
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.09E9AC00.1102599991 /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"F:\download\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-04-03 00:16:10 ----D---- C:\Program Files (x86)\GIANTS Software
2011-04-02 16:25:01 ----D---- C:\Program Files (x86)\Landwirtschafts Simulator 2011
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update
======List of files/folders modified in the last 1 months======
2011-04-04 15:45:14 ----D---- C:\Windows\temp
2011-04-04 15:43:42 ----D---- C:\Windows\system32\config
2011-04-04 15:32:49 ----D---- C:\Windows
2011-04-04 15:30:33 ----D---- C:\ProgramData\NVIDIA
2011-04-04 15:21:42 ----SHD---- C:\Windows\Installer
2011-04-04 15:20:51 ----D---- C:\Windows\SysWOW64
2011-04-04 15:17:51 ----D---- C:\Windows\Prefetch
2011-04-03 21:07:31 ----D---- C:\ProgramData\Adobe
2011-04-03 15:14:39 ----D---- C:\Windows\winsxs
2011-04-03 15:07:13 ----SD---- C:\Users\Michal\AppData\Roaming\Microsoft
2011-04-03 15:05:29 ----SHD---- C:\System Volume Information
2011-04-03 15:05:19 ----D---- C:\Program Files (x86)\Adobe
2011-04-03 00:16:10 ----RD---- C:\Program Files (x86)
2011-04-02 22:17:26 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-04-01 20:45:39 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-04-01 17:40:00 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-31 21:07:38 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-31 17:22:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-30 20:26:54 ----D---- C:\Windows\system32\NDF
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 awlgqige;awlgqige; C:\Windows\system32\drivers\awlgqige.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Mbam log přidám jakmile bude dokončen scan
Logfile of random's system information tool 1.08 (written by random/random)
Run by Michal at 2011-04-04 16:32:08
Microsoft Windows 7 Home Premium
System drive C: has 23 GB (22%) free of 103 GB
Total RAM: 3071 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:32:12, on 4.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Michal.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R3 - URLSearchHook: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Softonic English FF - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: Softonic English FF Toolbar - {ffa0793e-3980-4be4-8234-048fa665f700} - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files (x86)\ICQ7.4\ICQ.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9180 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {646FC814-C724-4A13-A221-F518D8764494}
"C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\Windows\system32\lxbkcoms.exe -service
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02261600.629724800 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=extension --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.021FD900.822386861 /prefetch:3 --ignored=" --type=renderer "
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.0.0.6907_0\npSkypeChromePlugin.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.0689F000.1598941708 /prefetch:4
C:\Windows\system32\rundll32.exe "C:\Users\Michal\AppData\Local\Google\Chrome\APPLIC~1\100648~1.204\gcswf32.dll",BrokerMain browser=chrome
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Michal\AppData\Local\Google\Chrome\Application\10.0.648.204\gcswf32.dll" --lang=cs --plugin-data-dir="C:\Users\Michal\AppData\Local\Google\Chrome\User Data\Default" --channel=3256.06854C00.1114752745 /prefetch:4 --flash-broker=312
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.02287600.666679802 /prefetch:3
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.0A5ED480.448304604 /prefetch:3
taskeng.exe {7C714F3B-6716-4D6F-B6B9-8BFFBE99265D}
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe /c
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Michal\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_4/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_750ms_queue_prefetch/DnsParallelism/parallel_9/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SpdyCwnd/cwndMin10/SpdyImpact/npn_with_spdy/ --channel=3256.09E9AC00.1102599991 /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"F:\download\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2010-10-19 325408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-10-19 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffa0793e-3980-4be4-8234-048fa665f700}]
Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-02-23 972280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{ffa0793e-3980-4be4-8234-048fa665f700} - Softonic English FF Toolbar - C:\Program Files (x86)\Softonic_English_FF\prxtbSof0.dll [2011-01-17 175912]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-02-23 814160]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7.4\ICQ.exe [2011-03-01 119608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxbkbmgr.exe]
C:\Program Files (x86)\Lexmark X1100 Series\lxbkbmgr.exe [2008-02-28 74408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
C:\Windows\System32\StikyNot.exe [2009-07-14 427520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-26 15026056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\READER~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
C:\PROGRA~2\Adobe\READER~2.0\Reader\ADOBEC~1.EXE []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-02-23 3451496]
C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-04-03 00:16:10 ----D---- C:\Program Files (x86)\GIANTS Software
2011-04-02 16:25:01 ----D---- C:\Program Files (x86)\Landwirtschafts Simulator 2011
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-03-30 17:51:42 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-03-30 17:51:40 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-03-30 17:51:39 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-03-30 17:51:38 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-03-30 17:51:34 ----A---- C:\Windows\system32\aswBoot.exe
2011-03-30 17:50:33 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-03-30 17:50:30 ----D---- C:\ProgramData\AVAST Software
2011-03-30 17:50:30 ----D---- C:\Program Files\AVAST Software
2011-03-30 15:58:11 ----D---- C:\Windows\pss
2011-03-30 15:41:47 ----D---- C:\rsit
2011-03-30 15:41:47 ----D---- C:\Program Files\trend micro
2011-03-30 15:39:59 ----A---- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2011-03-30 15:37:49 ----A---- C:\Windows\system32\drivers\Soluto.sys
2011-03-30 15:37:47 ----D---- C:\Program Files\Soluto
2011-03-30 15:36:51 ----D---- C:\ProgramData\Soluto
2011-03-29 19:03:29 ----D---- C:\Users\Michal\AppData\Roaming\Registry Mechanic
2011-03-29 14:48:11 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 16:19:39 ----A---- C:\Windows\SYSWOW64\ConduitEngine.tmp
2011-03-28 16:16:18 ----AD---- C:\ProgramData\TEMP
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidvfw.dll
2011-03-25 07:21:08 ----A---- C:\Windows\system32\xvidcore.dll
2011-03-25 07:17:20 ----D---- C:\Program Files (x86)\aTube Catcher
2011-03-25 07:12:29 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-03-23 21:06:09 ----D---- C:\ProgramData\MySQL
2011-03-23 16:59:54 ----D---- C:\Users\Michal\AppData\Roaming\GitExtensions
2011-03-23 16:55:37 ----D---- C:\Program Files (x86)\KDiff3
2011-03-22 21:07:28 ----D---- C:\Program Files (x86)\THQ
2011-03-22 20:53:56 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2011-03-22 20:52:33 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-03-22 20:52:33 ----A---- C:\Windows\system32\d3dx10.dll
2011-03-22 20:52:31 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-03-22 20:52:31 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-03-22 20:52:20 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-03-22 20:52:20 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-03-17 17:14:34 ----D---- C:\Users\Michal\AppData\Roaming\Ulead Systems
2011-03-17 17:13:10 ----D---- C:\ProgramData\InterVideo
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeW7.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizePX.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeP6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeM6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresizeA6.dll
2011-03-17 17:13:09 ----A---- C:\Windows\SYSWOW64\IVIresize.dll
2011-03-17 17:12:38 ----D---- C:\Program Files (x86)\Windows Media Components
2011-03-17 17:11:56 ----D---- C:\ProgramData\Ulead Systems
2011-03-17 17:11:55 ----D---- C:\Program Files (x86)\Ulead Systems
2011-03-17 16:51:09 ----D---- C:\Program Files (x86)\Movie Maker 2.6
2011-03-16 16:31:56 ----D---- C:\Program Files (x86)\Conduit
2011-03-16 16:31:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-03-16 16:31:42 ----D---- C:\Program Files (x86)\Softonic_English_FF
2011-03-16 16:29:37 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2011-03-16 16:20:11 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomwave.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomtran.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomrmencoder.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomqtde.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscommpgdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomframe.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflvdec.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomflashenc.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata2.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomdata1.dll
2011-03-16 16:18:30 ----A---- C:\Windows\SYSWOW64\viscomaudioencoder.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\viscomaudiodata.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videotrans.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videoformat.dll
2011-03-16 16:18:29 ----A---- C:\Windows\SYSWOW64\videocore.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\imgscaler.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\img_utils.dll
2011-03-16 16:18:28 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2011-03-16 16:18:26 ----D---- C:\Program Files (x86)\Zealot Software
2011-03-16 16:18:26 ----A---- C:\Windows\SYSWOW64\xvid.dll
2011-03-16 07:48:51 ----D---- C:\Users\Michal\AppData\Roaming\Crystal Player
2011-03-16 07:46:28 ----D---- C:\Users\Michal\AppData\Roaming\GHISLER
2011-03-16 07:44:24 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2011-03-16 07:42:36 ----D---- C:\Program Files (x86)\VideoLAN
2011-03-16 07:37:31 ----D---- C:\Program Files (x86)\Webteh
2011-03-16 07:32:55 ----D---- C:\Program Files (x86)\Xvid
2011-03-15 18:00:05 ----A---- C:\unetbtin.exe
2011-03-14 18:00:56 ----D---- C:\Program Files (x86)\Google
2011-03-11 20:17:31 ----D---- C:\Program Files (x86)\Cheat Engine 6
2011-03-11 16:31:02 ----D---- C:\Users\Michal\AppData\Roaming\DAEMON Tools Lite
2011-03-11 15:41:11 ----D---- C:\Users\Michal\AppData\Roaming\Adobe
2011-03-09 20:37:47 ----A---- C:\Windows\my.ini.old
2011-03-09 20:36:15 ----A---- C:\Windows\my.ini
2011-03-09 19:06:34 ----D---- C:\Program Files\photoshop
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 15:56:52 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 15:56:51 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 15:56:50 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 15:56:50 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 15:56:48 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 15:56:47 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 15:56:47 ----A---- C:\Windows\system32\mstsc.exe
2011-03-07 20:04:28 ----D---- C:\ProgramData\Apple Computer
2011-03-07 20:04:28 ----D---- C:\Program Files (x86)\QuickTime
2011-03-07 20:03:01 ----D---- C:\ProgramData\Apple
2011-03-07 20:03:01 ----D---- C:\Program Files (x86)\Apple Software Update
======List of files/folders modified in the last 1 months======
2011-04-04 15:45:14 ----D---- C:\Windows\temp
2011-04-04 15:43:42 ----D---- C:\Windows\system32\config
2011-04-04 15:32:49 ----D---- C:\Windows
2011-04-04 15:30:33 ----D---- C:\ProgramData\NVIDIA
2011-04-04 15:21:42 ----SHD---- C:\Windows\Installer
2011-04-04 15:20:51 ----D---- C:\Windows\SysWOW64
2011-04-04 15:17:51 ----D---- C:\Windows\Prefetch
2011-04-03 21:07:31 ----D---- C:\ProgramData\Adobe
2011-04-03 15:14:39 ----D---- C:\Windows\winsxs
2011-04-03 15:07:13 ----SD---- C:\Users\Michal\AppData\Roaming\Microsoft
2011-04-03 15:05:29 ----SHD---- C:\System Volume Information
2011-04-03 15:05:19 ----D---- C:\Program Files (x86)\Adobe
2011-04-03 00:16:10 ----RD---- C:\Program Files (x86)
2011-04-02 22:17:26 ----D---- C:\Users\Michal\AppData\Roaming\uTorrent
2011-04-01 20:45:39 ----D---- C:\Users\Michal\AppData\Roaming\Skype
2011-04-01 17:40:00 ----D---- C:\Users\Michal\AppData\Roaming\skypePM
2011-03-31 21:07:38 ----D---- C:\Users\Michal\AppData\Roaming\ICQ
2011-03-31 17:22:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-30 20:26:54 ----D---- C:\Windows\system32\NDF
2011-03-30 18:02:14 ----D---- C:\Windows\Tasks
2011-03-30 18:01:29 ----D---- C:\Windows\System32
2011-03-30 18:01:29 ----D---- C:\ProgramData\Norton
2011-03-30 18:01:27 ----D---- C:\Program Files (x86)\Common Files
2011-03-30 17:58:47 ----D---- C:\Windows\system32\Tasks
2011-03-30 17:58:09 ----D---- C:\Windows\system32\catroot2
2011-03-30 17:51:42 ----D---- C:\Windows\system32\drivers
2011-03-30 17:50:30 ----RD---- C:\Program Files
2011-03-30 17:50:30 ----HD---- C:\ProgramData
2011-03-30 17:46:28 ----D---- C:\Program Files\Common Files
2011-03-30 15:39:34 ----RSD---- C:\Windows\assembly
2011-03-30 15:37:55 ----D---- C:\Windows\system32\catroot
2011-03-30 15:37:49 ----DC---- C:\Windows\system32\DRVSTORE
2011-03-30 14:49:04 ----D---- C:\Windows\inf
2011-03-30 14:49:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-03-28 18:04:26 ----D---- C:\Users\Michal\AppData\Roaming\SQLyog
2011-03-27 21:26:43 ----D---- C:\Windows\SYSWOW64\Macromed
2011-03-24 18:26:17 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-24 15:55:25 ----D---- C:\Windows\Microsoft.NET
2011-03-23 23:36:36 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-03-23 23:31:31 ----D---- C:\Windows\SYSWOW64\en-US
2011-03-23 23:31:31 ----D---- C:\Windows\system32\en-US
2011-03-23 16:58:11 ----D---- C:\Program Files (x86)\Git
2011-03-23 16:54:30 ----D---- C:\Program Files (x86)\GitExtensions
2011-03-17 17:12:36 ----RSD---- C:\Windows\Fonts
2011-03-13 12:05:01 ----A---- C:\Windows\Lexstat.ini
2011-03-11 22:00:52 ----D---- C:\ProgramData\Blizzard Entertainment
2011-03-11 15:29:51 ----D---- C:\Windows\debug
2011-03-09 22:09:57 ----A---- C:\Windows\system32\MRT.exe
2011-03-09 19:51:10 ----RD---- C:\Users
2011-03-07 20:05:07 ----D---- C:\Program Files (x86)\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 Soluto;Soluto; C:\Windows\system32\DRIVERS\Soluto.sys [2011-03-27 54728]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-19 834544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-02-23 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-02-23 505176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-02-23 280408]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-02-23 53592]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-02-23 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-02-23 64344]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-06-22 131688]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 awlgqige;awlgqige; C:\Windows\system32\drivers\awlgqige.sys []
S3 dump_wmimmc;dump_wmimmc; \??\C:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-02 4682]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-02-23 42184]
R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 565928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-31 159336]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2011-03-27 335904]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-31 235624]
R2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-14 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-12-14 128928]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-10-21 3966416]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-21 1255736]
S4 mysql;mysql; F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\mysqld-nt --defaults-file=F:\download\Jeuties Blizzlike Repack 8.1.1\Jeuties Blizzlike Repack 8.1.1\_Server\mysql\bin\my.cnf mysql []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Mbam log přidám jakmile bude dokončen scan