Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

vytížení cpu na 100%

Máte problém s virem? Vložte sem log z FRST nebo RSIT.
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Moody
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 31 bře 2011 16:23

vytížení cpu na 100%

#1 Příspěvek od Moody »

omlouvám se že se vracím k mému starému dotazu http://www.viry.cz/forum/viewtopic.php?f=13&t=110694&
ale když CF odstranil infikovaný soubor svchost.exe - od té doby se často vytěžuje CPU - klidně i na 100% . ale žádný z puštěných procesů to není. Po hardwarové stránce je vše v pořádku , ovladače aktualizovány , registry jsou pročištěny v CC...
Používám MSEssentials + ZoneAlarm firewall. Dnes jsem provedl kompletní scan spyware terminatorovi a nic to nenašlo , jen nějaké sledovací cookies. Jinak svchost.exe se nachází v standartním umístění v Windows/System32 ale i v dalších umístěních.
když pustím svchost.exe v umístění Windows/System32 , tak se nepřidá do běžících procesů.. Už si nevím rady :?:
_____________________________
Mám přiložit log z CF?

Děkuji za všechny rady...
:worship:

Moody
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 31 bře 2011 16:23

Re: vytížení cpu na 100%

#2 Příspěvek od Moody »

nikdo neví co s tím? :(

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: vytížení cpu na 100%

#3 Příspěvek od chodnik74 »

1) udělej snímek obrazovky Správce úloh,kde půjde vidět které procesy nejvíce vytěžují procesor

Jak udělat snímek :???:
http://www.viry.cz/forum/viewtopic.php?f=11&t=14114

2) soubor,který svchost.exe uploadni na VIRUSTOTAL a vlož sem odkaz :)
http://www.virustotal.com/index.html
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Moody
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 31 bře 2011 16:23

Re: vytížení cpu na 100%

#4 Příspěvek od Moody »

VT:
http://www.virustotal.com/file-scan/rep ... 1303399870#

IMGShack:

http://img810.imageshack.us/g/ulohy.jpg/
(nyní bylo vytížení procesoru v klidu na 82 %)

PS: při hledání svchost.exe mi našlo několik svchost.exe , ale v jiných umístěních..

filip544
3. Stupeň Varování
Příspěvky: 250
Registrován: 25 led 2011 19:14
Bydliště: Vesmír

Re: vytížení cpu na 100%

#5 Příspěvek od filip544 »

Záskok než se chodnik74 objevý.

V jakých umístěních jste našel svchost.exe?

+ Dejte Log z RSIT http://www.viry.cz/forum/viewtopic.php?f=24&t=81939 pro Rádce. :)
Vypadá to že máte opravdu zavirovaný PC. :o

Moody
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 31 bře 2011 16:23

Re: vytížení cpu na 100%

#6 Příspěvek od Moody »

takže umístění :

1.C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356
2. C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356
3. C:/Windows/ERDNT/Cache64
3. C:/Windows/ERDNT/Cache86
4. C:/Windows/SysWOW64
5. C:/Windows/System32 - zde bývá podle Windows stardatně..

Díky za rady :)

filip544
3. Stupeň Varování
Příspěvky: 250
Registrován: 25 led 2011 19:14
Bydliště: Vesmír

Re: vytížení cpu na 100%

#7 Příspěvek od filip544 »

OK.Věděl bych jak to napravit ale nejsem rádce takže nemohu používat programy v podobě CF atd.
Dejte sem ten log z RSIT a pak se uvidí dál.

Moody
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 31 bře 2011 16:23

Re: vytížení cpu na 100%

#8 Příspěvek od Moody »

Logfile of random's system information tool 1.08 (written by random/random)
Run by Petr at 2011-04-21 18:13:10
Microsoft Windows 7 Ultimate
System drive C: has 27 GB (27%) free of 100 GB
Total RAM: 2046 MB (24% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:13:43, on 21.4.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Razer\Abyssus\razerhid.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Razer\Abyssus\razertra.exe
C:\Program Files (x86)\Razer\Abyssus\razerofa.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files\trend micro\Petr.exe
C:\Program Files (x86)\Winamp\winamp.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2645238
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: &Crawler Toolbar Helper - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FBLayouts Plugin - {FF4E1D1D-705B-4379-AB33-22D98C1ABF55} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: HopSurf toolbar - {E9FAB13D-4600-49E1-90D1-EE961C859D39} - C:\Program Files (x86)\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O3 - Toolbar: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Abyssus] C:\Program Files (x86)\Razer\Abyssus\razerhid.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-3571306171-2943904893-4274187742-1008\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3571306171-2943904893-4274187742-1008\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\iobit\advanced systemcare 3\spictrl.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} (Active602XMLFiller Control) - https://www.mojedatovaschranka.cz/stati ... ?3,16,13,0
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{94B0A123-6D1F-49EA-8810-E21AA1CEE75C}: NameServer = 213.46.172.36,213.46.172.37
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TUNEUPUTILITIESSERVICE64.EXE
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11481 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\SysWOW64\ZoneLabs\vsmon.exe -service
"C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {FC911B3D-2B90-462F-8D2B-2AB9700EDA25}
"C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe"
C:\Windows\system32\rundll32.exe "C:\Windows\SysWOW64\rdpd3d9.dll",kfojbxjp
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
"C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe"
"C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe" -Embedding
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TUNEUPUTILITIESSERVICE64.EXE"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
WLIDSvcM.exe 2176
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
"C:\Program Files (x86)\Razer\Abyssus\razerhid.exe"
"C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
"C:\Program Files (x86)\Razer\Abyssus\razertra.exe"
"C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /set_event="FFAPI_StartEvent_b7c_1206b" /icon="hidden"
"C:\Program Files (x86)\Razer\Abyssus\razerofa.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TuneUpUtilitiesApp64.EXE" /TUStart /pid:2148
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe31_ Global\UsGthrCtrlFltPipeMssGthrPipe31 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 592 596 604 65536 600
"C:\Users\Petr\Desktop\RSITx64 (1).exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files (x86)\Winamp\winamp.exe" -Embedding

======Scheduled tasks folder======

C:\Windows\tasks\At1.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3571306171-2943904893-4274187742-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3571306171-2943904893-4274187742-1000UA.job
C:\Windows\tasks\ParetoLogic Registration3.job
C:\Windows\tasks\ParetoLogic Update Version3.job
C:\Windows\tasks\PC Health Advisor Defrag.job
C:\Windows\tasks\PC Health Advisor.job
C:\Windows\tasks\Sttnlnqy.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Security Engine Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 903672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-04-12 43520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
&Crawler Toolbar Helper - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll [2011-04-08 1236104]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Security Engine Registrar - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 599544]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
ZoneAlarm Security Toolbar - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll [2010-12-01 2735200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF4E1D1D-705B-4379-AB33-22D98C1ABF55}]
FBLayouts Plugin

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E9FAB13D-4600-49E1-90D1-EE961C859D39} - HopSurf toolbar - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll [2011-01-15 1619136]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 903672]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll [2010-09-06 1048888]
{E9FAB13D-4600-49E1-90D1-EE961C859D39} - HopSurf toolbar - C:\Program Files (x86)\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll [2011-01-15 1122496]
{91da5e8a-3318-4f8c-b67e-5964de3ab546} - ZoneAlarm Security Toolbar - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll [2010-12-01 2735200]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll [2011-02-15 599544]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler Toolbar - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll [2011-04-08 1236104]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ISW"=C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [2011-02-15 1123320]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 1436224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminatorUpdate"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-04-21 3318784]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-03-17 2988488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe /s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [2011-01-13 6129496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-03-28 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-30 10806816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files (x86)\Winamp\winampa.exe [2010-12-09 74752]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Abyssus"=C:\Program Files (x86)\Razer\Abyssus\razerhid.exe [2010-05-10 223744]
"ZoneAlarm Client"=C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe [2011-03-18 1043968]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2010-09-01 250368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutorun"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2011-04-21 18:11:49 ----D---- C:\rsit
2011-04-21 15:01:56 ----D---- C:\Users\Petr\AppData\Roaming\.minecraft
2011-04-21 12:25:55 ----D---- C:\Users\Petr\AppData\Roaming\SUPERAntiSpyware.com
2011-04-21 12:25:55 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-04-21 12:25:50 ----D---- C:\ProgramData\!SASCORE
2011-04-21 12:25:45 ----D---- C:\Program Files\SUPERAntiSpyware
2011-04-21 12:03:34 ----D---- C:\Users\Petr\AppData\Roaming\ParetoLogic
2011-04-21 12:03:34 ----D---- C:\Users\Petr\AppData\Roaming\DriverCure
2011-04-21 12:02:52 ----D---- C:\ProgramData\ParetoLogic
2011-04-21 12:02:52 ----D---- C:\Program Files (x86)\ParetoLogic
2011-04-21 10:28:09 ----A---- C:\Windows\system32\TURegOpt.exe
2011-04-21 10:27:22 ----D---- C:\Program Files (x86)\TuneUp Utilities 2011
2011-04-21 08:42:04 ----D---- C:\Program Files (x86)\Crawler
2011-04-21 08:41:52 ----D---- C:\Users\Petr\AppData\Roaming\Spyware Terminator
2011-04-21 08:41:43 ----D---- C:\ProgramData\Spyware Terminator
2011-04-21 08:41:35 ----D---- C:\Program Files (x86)\Spyware Terminator
2011-04-20 19:37:57 ----D---- C:\Program Files (x86)\Microsoft Security Client
2011-04-20 19:37:39 ----D---- C:\Program Files\Microsoft Security Client
2011-04-19 17:37:11 ----D---- C:\Program Files (x86)\Wolfenstein - Enemy Territory
2011-04-19 15:38:34 ----D---- C:\CFLog
2011-04-19 15:07:34 ----D---- C:\Program Files (x86)\Z8Games
2011-04-19 14:19:14 ----D---- C:\Users\Petr\AppData\Roaming\Sierra Entertainment
2011-04-19 14:18:44 ----RHD---- C:\Users\Petr\AppData\Roaming\SecuROM
2011-04-19 14:10:54 ----D---- C:\Windows\85EBB28365AF4C539EBE7C0A232762F7.TMP
2011-04-19 14:01:38 ----D---- C:\Program Files (x86)\Sierra Entertainment
2011-04-19 12:35:54 ----SD---- C:\ComboFix
2011-04-19 11:26:27 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2011-04-19 11:26:27 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\OpenCL.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\nvoglv64.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\nvgenco642060.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\nvdispco6420140.dll
2011-04-19 11:26:27 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-04-19 11:26:26 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2011-04-19 11:26:26 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2011-04-19 11:26:26 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvd3dumx.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvcuvid.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-04-19 11:26:26 ----A---- C:\Windows\system32\nvcuda.dll
2011-04-19 11:26:25 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2011-04-19 11:26:25 ----A---- C:\Windows\system32\nvcompiler.dll
2011-04-18 20:16:17 ----D---- C:\3cda7a0bf8205269000d35336f
2011-04-18 20:15:29 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-18 20:15:29 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-18 20:15:29 ----A---- C:\Windows\system32\atmlib.dll
2011-04-18 20:15:29 ----A---- C:\Windows\system32\atmfd.dll
2011-04-18 20:14:57 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-04-18 20:14:57 ----A---- C:\Windows\system32\inetcomm.dll
2011-04-18 20:14:41 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-04-18 20:14:26 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-18 20:14:07 ----A---- C:\Windows\system32\win32k.sys
2011-04-18 20:13:49 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-18 20:13:49 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-18 20:13:49 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-18 20:13:49 ----A---- C:\Windows\system32\mfc42.dll
2011-04-18 20:13:33 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-04-18 20:13:33 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-04-18 20:13:33 ----A---- C:\Windows\system32\drivers\srv.sys
2011-04-18 20:13:15 ----A---- C:\Windows\system32\kdcom.dll
2011-04-18 20:13:15 ----A---- C:\Windows\system32\kd1394.dll
2011-04-18 20:13:14 ----A---- C:\Windows\system32\winresume.exe
2011-04-18 20:13:14 ----A---- C:\Windows\system32\winload.exe
2011-04-18 20:13:14 ----A---- C:\Windows\system32\kdusb.dll
2011-04-18 20:12:54 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-18 20:12:54 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-18 20:12:28 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-04-18 20:12:28 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-04-18 20:12:28 ----A---- C:\Windows\system32\FntCache.dll
2011-04-18 20:12:28 ----A---- C:\Windows\system32\DWrite.dll
2011-04-18 20:12:28 ----A---- C:\Windows\system32\d2d1.dll
2011-04-18 20:12:17 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-04-18 20:12:17 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-04-18 20:12:17 ----A---- C:\Windows\system32\mstscax.dll
2011-04-18 20:12:17 ----A---- C:\Windows\system32\mstsc.exe
2011-04-18 20:11:32 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-04-18 20:11:32 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-04-18 20:11:32 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-04-18 20:11:32 ----A---- C:\Windows\system32\d3d10_1.dll
2011-04-18 20:11:08 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-04-18 20:11:08 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-04-18 20:11:08 ----A---- C:\Windows\system32\ieui.dll
2011-04-18 20:11:08 ----A---- C:\Windows\system32\ieframe.dll
2011-04-18 20:11:07 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-04-18 20:11:07 ----A---- C:\Windows\system32\mshtml.dll
2011-04-18 20:10:27 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-04-18 20:10:27 ----A---- C:\Windows\system32\wcncsvc.dll
2011-04-18 19:53:40 ----D---- C:\Program Files\IObit
2011-04-18 19:18:36 ----A---- C:\Windows\SYSWOW64\xRaidSetup.exe
2011-04-18 19:18:36 ----A---- C:\Windows\SYSWOW64\xRaidAPI.dll
2011-04-18 19:10:14 ----D---- C:\Program Files (x86)\Driver-Soft
2011-04-18 19:04:15 ----HDC---- C:\ProgramData\{CC51AE54-B346-4954-ADDB-30BD4F138CF2}
2011-04-16 20:56:03 ----A---- C:\VHCSS.dll
2011-04-16 17:38:11 ----D---- C:\ProgramData\boost_interprocess
2011-04-16 17:18:51 ----D---- C:\Users\Petr\AppData\Roaming\TS3Client
2011-04-14 12:47:04 ----D---- C:\RaidTool
2011-04-14 12:43:40 ----D---- C:\Program Files (x86)\GIGABYTE
2011-04-12 18:52:25 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2011-04-12 18:52:01 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-04-12 18:52:01 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-04-12 18:52:01 ----A---- C:\Windows\SYSWOW64\java.exe
2011-04-12 18:35:20 ----D---- C:\Program Files\Intel Corporation
2011-04-12 18:34:06 ----A---- C:\Windows\system32\javaws.exe
2011-04-12 18:34:06 ----A---- C:\Windows\system32\javaw.exe
2011-04-12 18:34:06 ----A---- C:\Windows\system32\java.exe
2011-04-12 18:34:06 ----A---- C:\Windows\system32\deployJava1.dll
2011-04-12 18:33:46 ----D---- C:\Program Files\Java
2011-04-09 15:00:10 ----D---- C:\Program Files (x86)\Game_Maker8
2011-04-07 23:19:16 ----A---- C:\Windows\system32\nvvsvc.exe
2011-04-07 23:19:16 ----A---- C:\Windows\system32\nvsvcr.dll
2011-04-07 23:19:16 ----A---- C:\Windows\system32\nvmctray.dll
2011-04-07 23:19:14 ----A---- C:\Windows\system32\easyUpdatusAPIU64.dll
2011-04-07 23:19:06 ----A---- C:\Windows\system32\nvcpl.dll
2011-04-07 23:18:42 ----A---- C:\Windows\system32\nvsvc64.dll
2011-04-02 10:24:44 ----D---- C:\Program Files (x86)\Activision
2011-04-02 10:20:16 ----A---- C:\Windows\RomeTW.ini
2011-04-02 10:03:43 ----D---- C:\Program Files (x86)\UltraISO
2011-04-01 17:30:44 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-04-01 17:30:44 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-04-01 16:01:08 ----D---- C:\Users\Petr\AppData\Roaming\CheckPoint
2011-04-01 16:00:24 ----D---- C:\Program Files (x86)\Conduit
2011-04-01 16:00:21 ----D---- C:\Program Files (x86)\ZoneAlarm_Security
2011-04-01 16:00:08 ----D---- C:\Program Files\CheckPoint
2011-04-01 15:59:56 ----A---- C:\Windows\SYSWOW64\vsregexp.dll
2011-04-01 15:59:40 ----A---- C:\Windows\system32\drivers\netio.sys
2011-04-01 15:59:00 ----A---- C:\Windows\SYSWOW64\zlcommdb.dll
2011-04-01 15:59:00 ----A---- C:\Windows\SYSWOW64\zlcomm.dll
2011-04-01 15:58:55 ----A---- C:\Windows\SYSWOW64\vswmi.dll
2011-04-01 15:58:46 ----A---- C:\Windows\SYSWOW64\zpeng25.dll
2011-04-01 15:58:46 ----A---- C:\Windows\SYSWOW64\vsxml.dll
2011-04-01 15:58:45 ----D---- C:\Windows\SYSWOW64\ZoneLabs
2011-04-01 15:58:45 ----A---- C:\Windows\SYSWOW64\vspubapi.dll
2011-04-01 15:58:45 ----A---- C:\Windows\SYSWOW64\vsmonapi.dll
2011-04-01 15:58:42 ----A---- C:\Windows\SYSWOW64\vsdata.dll
2011-04-01 15:58:42 ----A---- C:\Windows\system32\drivers\~GLH0023.TMP
2011-04-01 15:58:34 ----N---- C:\Windows\system32\drivers\vsdatant.sys
2011-04-01 15:58:33 ----D---- C:\Program Files (x86)\Zone Labs
2011-04-01 15:58:16 ----D---- C:\ProgramData\CheckPoint
2011-04-01 15:58:15 ----D---- C:\Windows\Internet Logs
2011-04-01 15:58:15 ----A---- C:\Windows\SYSWOW64\vsutil.dll
2011-04-01 15:58:15 ----A---- C:\Windows\SYSWOW64\vsinit.dll
2011-03-31 20:58:35 ----D---- C:\Windows\temp
2011-03-31 20:57:34 ----SHD---- C:\$RECYCLE.BIN
2011-03-31 20:38:30 ----A---- C:\Windows\NIRCMD.exe
2011-03-31 20:37:58 ----A---- C:\Windows\SWXCACLS.exe
2011-03-31 19:05:33 ----A---- C:\Windows\zip.exe
2011-03-31 19:05:33 ----A---- C:\Windows\SWSC.exe
2011-03-31 19:05:33 ----A---- C:\Windows\SWREG.exe
2011-03-31 19:05:33 ----A---- C:\Windows\sed.exe
2011-03-31 19:05:33 ----A---- C:\Windows\PEV.exe
2011-03-31 19:05:33 ----A---- C:\Windows\MBR.exe
2011-03-31 19:05:33 ----A---- C:\Windows\grep.exe
2011-03-31 19:03:32 ----D---- C:\Windows\ERDNT
2011-03-31 19:03:08 ----D---- C:\Qoobox
2011-03-31 17:45:49 ----D---- C:\Program Files\trend micro
2011-03-31 17:41:35 ----D---- C:\Users\Petr\AppData\Roaming\Malwarebytes
2011-03-31 17:41:25 ----D---- C:\ProgramData\Malwarebytes
2011-03-31 17:41:22 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-03-31 17:41:22 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-03-30 15:10:44 ----D---- C:\Windows\SYSWOW64\Wat
2011-03-30 15:10:44 ----D---- C:\Windows\system32\Wat
2011-03-29 22:13:33 ----D---- C:\Program Files\Windows Live
2011-03-29 22:11:49 ----D---- C:\Program Files (x86)\Bing Bar Installer
2011-03-29 21:47:53 ----D---- C:\Windows\system32\SPReview
2011-03-29 21:47:00 ----D---- C:\Windows\system32\EventProviders
2011-03-29 15:46:59 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-03-28 19:31:07 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-03-28 19:31:07 ----A---- C:\Windows\system32\d3d10warp.dll
2011-03-28 19:31:04 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-03-28 19:31:03 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-03-28 19:31:03 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-03-28 19:31:03 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-03-28 19:31:03 ----A---- C:\Windows\system32\cdd.dll
2011-03-28 19:30:42 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-03-28 19:30:42 ----A---- C:\Windows\system32\ntdll.dll
2011-03-28 19:30:41 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-03-28 19:30:41 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-03-28 19:30:40 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-03-28 17:57:44 ----A---- C:\Windows\system32\EncDec.dll
2011-03-28 17:57:44 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-28 17:57:43 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-28 17:57:42 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-28 17:57:41 ----A---- C:\Windows\system32\sbe.dll
2011-03-28 17:57:40 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-28 17:57:11 ----A---- C:\Windows\system32\msxml6.dll
2011-03-28 17:57:11 ----A---- C:\Windows\system32\msxml3.dll
2011-03-28 17:57:10 ----A---- C:\Windows\system32\upnp.dll
2011-03-28 17:57:09 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-03-28 17:57:06 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-03-28 17:57:06 ----A---- C:\Windows\system32\winhttp.dll
2011-03-28 17:56:59 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-03-28 17:56:59 ----A---- C:\Windows\system32\WebClnt.dll
2011-03-28 17:56:59 ----A---- C:\Windows\system32\davclnt.dll
2011-03-28 17:56:58 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-03-28 17:56:58 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-03-28 17:56:58 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-03-28 17:56:58 ----A---- C:\Windows\system32\wscapi.dll
2011-03-28 17:56:57 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-03-28 17:56:57 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-03-28 17:56:57 ----A---- C:\Windows\system32\wscsvc.dll
2011-03-28 17:56:57 ----A---- C:\Windows\system32\slwga.dll
2011-03-28 17:56:46 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-03-28 17:56:46 ----A---- C:\Windows\system32\kerberos.dll
2011-03-28 17:56:14 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-03-28 17:56:13 ----A---- C:\Windows\system32\XpsPrint.dll
2011-03-28 17:56:05 ----A---- C:\Windows\system32\winsrv.dll
2011-03-28 17:41:19 ----D---- C:\ProgramData\AVAST Software
2011-03-28 17:41:19 ----D---- C:\Program Files\AVAST Software
2011-03-27 22:19:01 ----D---- C:\Users\Petr\AppData\Roaming\Opera
2011-03-27 22:10:20 ----D---- C:\Program Files (x86)\Opera
2011-03-27 20:50:55 ----D---- C:\Program Files (x86)\AutoTune Files
2011-03-27 20:50:51 ----D---- C:\Program Files (x86)\Nová složka

======List of files/folders modified in the last 1 months======

2011-04-21 17:56:43 ----D---- C:\Program Files (x86)\Counter-Strike Source
2011-04-21 17:53:59 ----D---- C:\Users\Petr\AppData\Roaming\Skype
2011-04-21 16:07:38 ----D---- C:\Users\Petr\AppData\Roaming\skypePM
2011-04-21 16:03:42 ----D---- C:\Windows\SysWOW64
2011-04-21 16:03:38 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-04-21 14:34:39 ----D---- C:\Windows\system32\config
2011-04-21 12:25:55 ----D---- C:\ProgramData
2011-04-21 12:25:45 ----RD---- C:\Program Files
2011-04-21 12:17:08 ----D---- C:\Windows\Prefetch
2011-04-21 12:16:28 ----D---- C:\ProgramData\NVIDIA
2011-04-21 12:16:25 ----D---- C:\Windows\SYSWOW64\logishrd
2011-04-21 12:16:25 ----D---- C:\Windows\system32\logishrd
2011-04-21 12:16:11 ----AD---- C:\Windows
2011-04-21 12:04:09 ----D---- C:\Windows\system32\Tasks
2011-04-21 12:04:08 ----D---- C:\Windows\Tasks
2011-04-21 12:02:58 ----D---- C:\Program Files (x86)\Common Files
2011-04-21 12:02:52 ----D---- C:\Program Files (x86)
2011-04-21 12:02:52 ----D---- C:\Program Files (x86)
2011-04-21 11:38:16 ----D---- C:\Users\Petr\AppData\Roaming\TuneUp Software
2011-04-21 11:33:09 ----SHD---- C:\System Volume Information
2011-04-21 11:03:13 ----D---- C:\Windows\System32
2011-04-21 10:45:04 ----D---- C:\ProgramData\CyberLink
2011-04-21 10:45:03 ----SHD---- C:\Windows\Installer
2011-04-21 10:37:46 ----D---- C:\Program Files (x86)\Livestream Procaster
2011-04-21 09:33:50 ----DC---- C:\Windows\system32\DRVSTORE
2011-04-21 09:33:49 ----D---- C:\Windows\system32\DriverStore
2011-04-21 09:33:49 ----D---- C:\Windows\system32\catroot
2011-04-21 09:33:49 ----D---- C:\Windows\inf
2011-04-21 09:32:33 ----D---- C:\Windows\system32\drivers
2011-04-21 08:18:42 ----RSD---- C:\Windows\assembly
2011-04-21 08:18:42 ----D---- C:\Windows\Microsoft.NET
2011-04-20 20:39:09 ----D---- C:\Windows\system32\NDF
2011-04-20 19:38:04 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-04-20 18:17:47 ----D---- C:\Windows\system32\oobe
2011-04-20 18:15:06 ----D---- C:\Windows\system32\catroot2
2011-04-20 18:13:33 ----D---- C:\Users\Petr\AppData\Roaming\uTorrent
2011-04-19 21:42:09 ----D---- C:\Stažené Torrenty
2011-04-19 17:47:48 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-04-19 15:36:01 ----D---- C:\Users\Petr\AppData\Roaming\Winamp
2011-04-19 14:02:20 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-04-19 11:31:38 ----D---- C:\Program Files\NVIDIA Corporation
2011-04-19 11:29:56 ----RD---- C:\Users
2011-04-19 11:29:54 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-04-19 09:51:30 ----D---- C:\Windows\system32\drivers\etc
2011-04-19 08:48:43 ----D---- C:\Users\Petr\AppData\Roaming\vlc
2011-04-18 20:29:50 ----D---- C:\Windows\winsxs
2011-04-18 20:27:06 ----D---- C:\Windows\system32\Boot
2011-04-18 20:24:11 ----D---- C:\ProgramData\IObit
2011-04-18 20:18:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-04-18 20:09:07 ----D---- C:\Windows\Logs
2011-04-18 19:52:38 ----D---- C:\Users\Petr\AppData\Roaming\IObit
2011-04-18 19:52:34 ----D---- C:\Program Files (x86)\IObit
2011-04-18 19:25:00 ----A---- C:\Windows\system32\aswBoot.exe
2011-04-18 19:18:37 ----D---- C:\Windows\RaidTool
2011-04-14 18:47:51 ----D---- C:\Windows\system32\wfp
2011-04-14 18:47:47 ----D---- C:\Windows\system32\wbem
2011-04-14 18:47:47 ----D---- C:\Windows\registration
2011-04-14 12:42:30 ----A---- C:\Windows\GSetup.ini
2011-04-12 19:38:47 ----D---- C:\Users\Petr\AppData\Roaming\Audacity
2011-04-12 18:51:45 ----D---- C:\Program Files (x86)\Java
2011-04-11 16:11:41 ----D---- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
2011-04-08 07:14:00 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2011-04-08 07:14:00 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2011-04-08 07:14:00 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2011-04-08 07:14:00 ----A---- C:\Windows\system32\nvwgf2umx.dll
2011-04-08 07:14:00 ----A---- C:\Windows\system32\nvapi64.dll
2011-04-02 16:29:39 ----D---- C:\Program Files (x86)\Garena
2011-04-02 11:14:11 ----D---- C:\Windows\SYSWOW64\directx
2011-04-02 11:11:16 ----D---- C:\Temp
2011-04-02 10:24:52 ----D---- C:\Program Files\Activision
2011-04-01 16:22:51 ----D---- C:\Windows\SYSWOW64\drivers
2011-03-31 20:53:16 ----A---- C:\Windows\system.ini
2011-03-31 20:45:43 ----D---- C:\Windows\AppPatch
2011-03-31 20:45:39 ----D---- C:\Program Files\Common Files
2011-03-31 19:02:43 ----D---- C:\Users\Petr\AppData\Roaming\ICQ
2011-03-30 20:03:52 ----D---- C:\Program Files (x86)\Pando Networks
2011-03-30 19:54:08 ----D---- C:\Program Files (x86)\SlySoft
2011-03-30 19:52:50 ----D---- C:\Program Files (x86)\Fiddler2
2011-03-30 19:52:20 ----D---- C:\Warcraft III
2011-03-30 19:50:31 ----D---- C:\Program Files (x86)\Radical Games
2011-03-30 18:57:50 ----A---- C:\Windows\system32\authuitu.dll
2011-03-30 18:57:48 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2011-03-30 18:57:44 ----A---- C:\Windows\system32\uxtuneup.dll
2011-03-30 18:57:40 ----A---- C:\Windows\SYSWOW64\uxtuneup.dll
2011-03-30 18:36:11 ----HD---- C:\Windows\system32\GroupPolicy
2011-03-30 18:17:56 ----D---- C:\Windows\system32\cs-CZ
2011-03-30 18:16:28 ----RSD---- C:\Windows\Fonts
2011-03-30 18:16:28 ----D---- C:\Windows\SYSWOW64\oobe
2011-03-30 18:16:28 ----D---- C:\Windows\SYSWOW64\migwiz
2011-03-30 18:16:28 ----D---- C:\Windows\SYSWOW64\Dism
2011-03-30 18:16:28 ----D---- C:\Windows\system32\migwiz
2011-03-30 18:16:28 ----D---- C:\Windows\system32\manifeststore
2011-03-30 18:16:28 ----D---- C:\Windows\ehome
2011-03-30 18:16:27 ----D---- C:\Program Files\Windows Media Player
2011-03-30 18:16:27 ----D---- C:\Program Files\DVD Maker
2011-03-30 18:16:27 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-03-30 18:16:27 ----D---- C:\Program Files (x86)\Windows Media Player
2011-03-30 18:16:24 ----D---- C:\Windows\TAPI
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\wbem
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\sppui
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\Setup
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\migration
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\es-ES
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\da-DK
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\cs
2011-03-30 18:16:24 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-03-30 18:16:24 ----D---- C:\Windows\system32\sppui
2011-03-30 18:16:24 ----D---- C:\Windows\system32\Setup
2011-03-30 18:16:24 ----D---- C:\Windows\system32\migration
2011-03-30 18:16:23 ----SHD---- C:\Windows\BitLockerDiscoveryVolumeContents
2011-03-30 18:16:23 ----D---- C:\Windows\system32\es-ES
2011-03-30 18:16:23 ----D---- C:\Windows\system32\en-US
2011-03-30 18:16:23 ----D---- C:\Windows\system32\drivers\UMDF
2011-03-30 18:16:23 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-03-30 18:16:23 ----D---- C:\Windows\system32\Dism
2011-03-30 18:16:23 ----D---- C:\Windows\system32\da-DK
2011-03-30 18:16:23 ----D---- C:\Windows\system32\cs
2011-03-30 18:16:23 ----D---- C:\Windows\system32\AdvancedInstallers
2011-03-30 18:16:23 ----D---- C:\Windows\servicing
2011-03-30 18:16:23 ----D---- C:\Windows\PolicyDefinitions
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Sidebar
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Photo Viewer
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Mail
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Journal
2011-03-30 18:16:23 ----D---- C:\Program Files\Windows Defender
2011-03-30 18:16:23 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-03-30 18:16:23 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-03-30 18:16:23 ----D---- C:\Program Files (x86)\Windows Mail
2011-03-30 18:16:13 ----D---- C:\Windows\SYSWOW64\XPSViewer
2011-03-30 18:16:13 ----D---- C:\Windows\SYSWOW64\Speech
2011-03-30 18:16:12 ----D---- C:\Windows\SYSWOW64\MUI
2011-03-30 18:16:11 ----D---- C:\Windows\system32\spp
2011-03-30 18:16:11 ----D---- C:\Windows\system32\Speech
2011-03-30 18:16:11 ----D---- C:\Windows\system32\MUI
2011-03-30 18:16:10 ----D---- C:\Windows\system32\CodeIntegrity
2011-03-30 18:16:09 ----D---- C:\Windows\security
2011-03-30 18:16:01 ----D---- C:\Program Files (x86)\Windows Live
2011-03-30 18:16:01 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-03-30 18:15:55 ----D---- C:\Program Files\Windows Portable Devices
2011-03-30 18:08:46 ----SD---- C:\ProgramData\Microsoft
2011-03-30 18:08:33 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-03-30 15:10:05 ----D---- C:\Boot
2011-03-29 18:51:36 ----D---- C:\Windows\debug
2011-03-28 21:13:58 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2011-03-28 21:12:18 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-28 18:37:50 ----D---- C:\Program Files\COMODO
2011-03-28 17:48:32 ----D---- C:\Program Files (x86)\VstPlugins
2011-03-27 20:21:40 ----SD---- C:\Users\Petr\AppData\Roaming\Microsoft
2011-03-27 14:49:46 ----D---- C:\ProgramData\Microsoft Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-01-27 115312]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-04-02 526392]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 188928]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2010-05-15 458840]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-12-18 314016]
R2 ISWKL;ZoneAlarm Toolbar ISWKL; \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [2011-02-15 33528]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-12-18 43680]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2010-07-07 50696]
R3 Abyssus;Razer Abyssus; C:\Windows\system32\drivers\Abyssus.sys [2009-10-30 10880]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-04-30 2359200]
R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2010-05-07 30304]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2010-11-10 341856]
R3 LVUVC64;Logitech Webcam C210(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2010-11-10 4162784]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 72064]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TuneUpUtilitiesDriver64.sys [2011-02-10 11856]
R3 vhidmini;Razer Gaming Device; C:\Windows\system32\DRIVERS\vHidDev.sys [2009-12-21 7552]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S2 hwpsgt;hwpsgt; C:\Windows\system32\DRIVERS\hwpsgt.sys []
S2 lemsgt;lemsgt; C:\Windows\system32\DRIVERS\lemsgt.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpudrv64;cpudrv64; \??\C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2009-12-18 17864]
S3 cpuz132;cpuz132; \??\C:\Users\Petr\AppData\Local\Temp\cpuz132\cpuz132_x64.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-04-14 20544]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena\safedrv.sys []
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2010-12-27 30528]
S3 LVPr2Mon;LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2010-05-07 30304]
S3 MarkFun_NT;MarkFun_NT; \??\C:\Program Files (x86)\GIGABYTE\ET5Pro\markfun.a64 []
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 40832]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 ScreamBAudioSvc;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys [2009-11-26 38992]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys []
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2010-08-05 144720]
S3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
R2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-04-14 352144]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-03-28 2111368]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-09-06 247096]
R2 IswSvc;ZoneAlarm Toolbar IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [2011-02-15 822264]
R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [2010-05-07 197976]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 12784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-04-07 1012328]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-04-19 75136]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe [2011-04-21 948775]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-07 378472]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2011\TUNEUPUTILITIESSERVICE64.EXE [2011-03-30 2026304]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\SysWOW64\ZoneLabs\vsmon.exe [2011-03-18 2435592]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-08 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-08 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-18 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Uživatelský avatar
chodnik74
Přítel fóra
Přítel fóra
Příspěvky: 4975
Registrován: 13 zář 2010 21:30
Bydliště: Napajedla
Kontaktovat uživatele:

Re: vytížení cpu na 100%

#9 Příspěvek od chodnik74 »

Děkuji filip544 za doplnění a spolupráci :) Čili asi to vážně vypadá,že máme svchost i tam kde být nemá..upozorním někoho z Rádců,aby se na to podíval :)
Napiš mi: chodnik74@gmail.com nebo Obrázek

>RSIT<>MBAM<>VirusTotal

Doporučuji:
Obrázek | Obrázek

:!: Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte. ;-) Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! :!:

:!: Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!

:idea: Jste s naší pomocí spokojeni :???: Neváhejte a podpořte forum ZDE.

Pravidla fora: č.1 a č.2

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: vytížení cpu na 100%

#10 Příspěvek od Roli »

Zdravím, tohle fixni v HJT :

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT2645238
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll


HJT najdeš zde :

C:\Program Files\trend micro\Petr.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

Google Update Service

Služba Google Update

ICQ Service


klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.


Odinstaluj ICQ6Toolbar


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Moody
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 31 bře 2011 16:23

Re: vytížení cpu na 100%

#11 Příspěvek od Moody »

Zde je log z CB2.txt
http://textsave.de/?p=59572

(text překročil množství znaků zde na foru)

jinak služba google update nešla zakázat , ani po restartu..

Moody
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 31 bře 2011 16:23

Re: vytížení cpu na 100%

#12 Příspěvek od Moody »


Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: vytížení cpu na 100%

#13 Příspěvek od Roli »

Mě to nejde stáhnout můžeš to nahodit třeba SEM, dík.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět